package config import ( "encoding/hex" "errors" "fmt" ) // errKeyLength is returned for a well-formed hex string of the wrong // length, so decodeHex has one error type for both ways of being wrong. var errKeyLength = errors.New("wrong key length") // decodeHex decodes exactly csrfKeyBytes bytes of hex. It exists as its // own function so that the length rule and the encoding rule are // enforced in one place, and so that the caller never has to decide // what a short-but-valid key means. func decodeHex(s string) ([]byte, error) { b, err := hex.DecodeString(s) if err != nil { return nil, fmt.Errorf("decoding hex: %w", err) } if len(b) != csrfKeyBytes { return nil, fmt.Errorf("%w: got %d bytes, want %d", errKeyLength, len(b), csrfKeyBytes) } return b, nil }