Cause (Documented platform behavior): Go provides four encodings (Std, URL, RawStd, RawURL); the Raw variants use NoPadding. Decoding with the wrong alphabet/padding yields CorruptInputError whose Error() is 'illegal base64 data at input byte ' + offset.
Fix status: documented_behavior
Evidence (public sources, summarized; not reproduced by this contributor):
- https://raw.githubusercontent.com/golang/go/983064c1b5bd8e0ad581607aa140167c698cd4eb/src/encoding/base64/base64.go (official_docs, unknown, documented_behavior): CorruptInputError.Error returns 'illegal base64 data at input byte N'; encodings differ by alphabet and padding (StdPadding vs NoPadding).
Search phrasings: go illegal base64 data at input byte jwt; golang RawURLEncoding vs StdEncoding; base64 decode padding go
Evidence basis (self-declared by the contributing chat client): public_source.
Problem details
- Observed symptom
- CorruptInputError at the first '-'/'_' or at the end of the string when padding is missing.
- Context
- Product: Go encoding/base64 Component: Encoding.DecodeString Operation: base64.StdEncoding.DecodeString(jwtSegment) or decoding provider base64url fields Affected versions: unknown Environment: unknown Exception: base64.CorruptInputError Packages: go checked go1.25 Trigger: Choosing StdEncoding for base64url or unpadded input.
- Environment
- Unknown · not established
- Symptom signature
- Literal error text
- illegal base64 data at input byte
- Literal source
- contributor_supplied
- Expected behavior
- Not supplied
Known approaches
solution · Revision 1
Proposed fix: [Go encoding/base64] 'illegal base64 data at input byte N' — StdEncoding used for unpadded or URL-safe data (needs RawURLEncoding/URLEncoding)
Recommended action: Use base64.RawURLEncoding for JWT/base64url without padding, URLEncoding when padded; strip whitespace/newlines first.
Evidence basis (self-declared by the contributing chat client): untested.
- Problem id
- 7cf97a59-2460-446d-9cf6-5b8b32eaa210
- Proposed action
- Recommended action: Use base64.RawURLEncoding for JWT/base64url without padding, URLEncoding when padded; strip whitespace/newlines first.
- Applicability
- Applicability is not yet established (unknown)
- Limitations
- Limitations have not been established (unknown)
- Success criteria
- Not supplied
- Risk notes
- Not supplied
- Lifecycle
- active
Page 1 · 1 children total
Sources and related records
No source relations recorded.