{"record":{"id":"03c044cb4beb19ef","repo":"gofiber/fiber","slug":"helmet-hstspreloadenabled-requires-hstsexcludesub","errorCode":null,"errorMessage":"helmet: HSTSPreloadEnabled requires HSTSExcludeSubdomains to be false","messagePattern":"helmet: HSTSPreloadEnabled requires HSTSExcludeSubdomains to be false","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/helmet/config.go","lineNumber":114,"sourceCode":"\tXPermittedCrossDomain:     \"none\",\n}\n\n// Helper function to set default values\nfunc configDefault(config ...Config) Config {\n\t// Return default config if nothing provided\n\tif len(config) < 1 {\n\t\treturn ConfigDefault\n\t}\n\n\t// Override default config\n\tcfg := config[0]\n\n\tif cfg.HSTSMaxAge < 0 {\n\t\tpanic(\"helmet: HSTSMaxAge must be greater than or equal to 0\")\n\t}\n\n\tif cfg.HSTSPreloadEnabled && cfg.HSTSExcludeSubdomains {\n\t\tpanic(\"helmet: HSTSPreloadEnabled requires HSTSExcludeSubdomains to be false\")\n\t}\n\n\t// Set default values\n\tif cfg.XSSProtection == \"\" {\n\t\tcfg.XSSProtection = ConfigDefault.XSSProtection\n\t}\n\n\tif cfg.ContentTypeNosniff == \"\" {\n\t\tcfg.ContentTypeNosniff = ConfigDefault.ContentTypeNosniff\n\t}\n\n\tif cfg.XFrameOptions == \"\" {\n\t\tcfg.XFrameOptions = ConfigDefault.XFrameOptions\n\t}\n\n\tif cfg.ReferrerPolicy == \"\" {\n\t\tcfg.ReferrerPolicy = ConfigDefault.ReferrerPolicy\n\t}","sourceCodeStart":96,"sourceCodeEnd":132,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/helmet/config.go#L96-L132","documentation":"helmet rejects the combination HSTSPreloadEnabled=true and HSTSExcludeSubdomains=true. Submission to the HSTS preload list (hstspreload.org) requires includeSubDomains; ExcludeSubdomains is the opposite knob, so enabling both is self-contradictory and would make the site ineligible for preloading. helmet surfaces the inconsistency at construction time.","triggerScenarios":"helmet.New(helmet.Config{HSTSPreloadEnabled: true, HSTSExcludeSubdomains: true}). Also reached when both flags are pulled from a feature-flag/config map that was edited without considering their relationship.","commonSituations":"Enabling preload because a checklist said to, while leaving an old ExcludeSubdomains=true from a previous subdomain-isolation policy; merging two config sources where one sets preload and the other sets exclude; misunderstanding ExcludeSubdomains as 'only apply to apex' rather than 'omit the includeSubDomains directive'.","solutions":["If you want preload submission eligibility, set HSTSExcludeSubdomains: false (and keep HSTSPreloadEnabled: true).","If you genuinely must exclude subdomains from HSTS, set HSTSPreloadEnabled: false.","Audit the config source (env/flags/YAML) that populates both fields so they cannot both be true — encode the constraint at the config layer."],"exampleFix":"// before\napp.Use(helmet.New(helmet.Config{\n    HSTSPreloadEnabled:    true,\n    HSTSExcludeSubdomains: true,\n}))\n\n// after — preload requires includeSubDomains\napp.Use(helmet.New(helmet.Config{\n    HSTSPreloadEnabled:    true,\n    HSTSExcludeSubdomains: false,\n}))","handlingStrategy":"validation","validationCode":"func validateHelmetPreload(cfg helmet.Config) error {\n    if cfg.HSTSPreloadEnabled && cfg.HSTSExcludeSubdomains {\n        return errors.New(\"preload requires includeSubDomains (ExcludeSubdomains=false)\")\n    }\n    return nil\n}\n\nif err := validateHelmetPreload(cfg); err != nil {\n    log.Fatal(err)\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Treat HSTSPreloadEnabled and HSTSExcludeSubdomains as mutually constrained flags at the config layer.","Document the preload requirement (includeSubDomains) next to the config field that toggles it.","Add a config-validator test asserting the forbidden combination is rejected."],"tags":["helmet","hsts","preload","config","security-header","startup-panic"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}