{"record":{"id":"6dd646d19b4ae8b3","repo":"gofiber/fiber","slug":"hostauthorization-allowedhosts-or-allowedhostsfun","errorCode":null,"errorMessage":"hostauthorization: AllowedHosts or AllowedHostsFunc is required","messagePattern":"hostauthorization: AllowedHosts or AllowedHostsFunc is required","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/hostauthorization/config.go","lineNumber":57,"sourceCode":"\t// Entries are normalized at startup: port stripped, trailing dot removed,\n\t// lowercased, IDN labels converted to Punycode, RFC 1035 length limits enforced\n\t// (≤253 total / ≤63 per-label).\n\t//\n\t// Required if AllowedHostsFunc is nil.\n\tAllowedHosts []string\n}\n\n// ConfigDefault is the default config.\nvar ConfigDefault = Config{}\n\nfunc configDefault(config ...Config) Config {\n\tcfg := ConfigDefault\n\tif len(config) > 0 {\n\t\tcfg = config[0]\n\t}\n\n\tif len(cfg.AllowedHosts) == 0 && cfg.AllowedHostsFunc == nil {\n\t\tpanic(\"hostauthorization: AllowedHosts or AllowedHostsFunc is required\")\n\t}\n\n\tif cfg.ErrorHandler == nil {\n\t\tcfg.ErrorHandler = func(c fiber.Ctx, _ error) error {\n\t\t\treturn c.SendStatus(fiber.StatusForbidden)\n\t\t}\n\t}\n\n\treturn cfg\n}\n","sourceCodeStart":39,"sourceCodeEnd":68,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/hostauthorization/config.go#L39-L68","documentation":"The hostauthorization middleware requires at least one host-authorization mechanism. configDefault panics when AllowedHosts is empty AND AllowedHostsFunc is nil, because a host-authorization middleware that authorizes nothing is a no-op that would either reject every request or, worse, silently pass through. You must supply one of the two.","triggerScenarios":"hostauthorization.New() with no args, or hostauthorization.New(hostauthorization.Config{}) (zero-value config). Also triggered by constructing Config from a struct literal where AllowedHosts is conditionally populated but the condition leaves it nil.","commonSituations":"Reading allowed hosts from an env var that is empty in dev; building Config in a helper that returns an empty Config when the feature flag is off, then still wiring New() unconditionally; refactoring away a static list in favor of AllowedHostsFunc but forgetting to assign the func.","solutions":["Provide a non-empty AllowedHosts slice, e.g. hostauthorization.New(hostauthorization.Config{AllowedHosts: []string{\"app.example.com\", \"*.app.example.com\"}}).","Provide an AllowedHostsFunc if the allowed set is dynamic, e.g. AllowedHostsFunc: func(h string) bool { return allowlist.Contains(h) }.","If host authorization is optional in some environments, guard the app.Use(hostauthorization.New(...)) call itself rather than passing an empty config."],"exampleFix":"// before\napp.Use(hostauthorization.New(hostauthorization.Config{}))\n\n// after\napp.Use(hostauthorization.New(hostauthorization.Config{\n    AllowedHosts: []string{\"app.example.com\", \"*.app.example.com\"},\n}))","handlingStrategy":"validation","validationCode":"func buildHostAuthCfg(hosts []string, fn func(string) bool) (hostauthorization.Config, error) {\n    if len(hosts) == 0 && fn == nil {\n        return hostauthorization.Config{}, errors.New(\"AllowedHosts or AllowedHostsFunc required\")\n    }\n    return hostauthorization.Config{AllowedHosts: hosts, AllowedHostsFunc: fn}, nil\n}","typeGuard":"func hasHostAuthSource(hosts []string, fn func(string) bool) bool {\n    return len(hosts) > 0 || fn != nil\n}","tryCatchPattern":null,"preventionTips":["Make host-authorization registration conditional on having at least one allow source.","Fail config loading loudly when the allowed-hosts env var is empty in production.","Prefer AllowedHostsFunc for dynamic sets, but always assign a non-nil function."],"tags":["hostauthorization","config","required-field","startup-panic","security"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}