{"record":{"id":"7ef52d2e6594d7b8","repo":"gofiber/fiber","slug":"hostauthorization-forbidden-host","errorCode":null,"errorMessage":"hostauthorization: forbidden host","messagePattern":"hostauthorization: forbidden host","errorType":"http","errorClass":null,"httpStatus":403,"severity":"error","filePath":"middleware/hostauthorization/config.go","lineNumber":10,"sourceCode":"package hostauthorization\n\nimport (\n\t\"errors\"\n\n\t\"github.com/gofiber/fiber/v3\"\n)\n\n// ErrForbiddenHost is returned when the Host header does not match any allowed host.\nvar ErrForbiddenHost = errors.New(\"hostauthorization: forbidden host\")\n\n// Config defines the config for the host authorization middleware.\ntype Config struct {\n\t// Next defines a function to skip this middleware when returned true.\n\t// Use this to exclude health check endpoints or other paths from host validation.\n\t//\n\t// Optional. Default: nil\n\tNext func(c fiber.Ctx) bool\n\n\t// AllowedHostsFunc is a dynamic validator called only when no static\n\t// AllowedHosts rule matches. Receives the normalized hostname: port stripped,\n\t// trailing dot removed, IPv6 brackets removed, lowercased.\n\t// Return true to allow.\n\t//\n\t// Optional. Default: nil\n\tAllowedHostsFunc func(host string) bool\n\n\t// ErrorHandler is called when a request is rejected.","sourceCodeStart":1,"sourceCodeEnd":28,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/hostauthorization/config.go#L1-L28","documentation":"Returned by middleware/hostauthorization when the request Host header does not match any allowed host (or cannot be parsed into a normalized authority). The middleware normalizes the Host (port stripped, trailing dot removed, IPv6 brackets removed, lowercased), checks the static AllowedHosts list, then the AllowedHostsFunc, and rejects on no match. It is delivered via Config.ErrorHandler so the response shape is configurable.","triggerScenarios":"An inbound request whose Host header is not in AllowedHosts, not accepted by AllowedHostsFunc, or syntactically unparseable (parseNormalizedAuthority returns false). Affects every request unless cfg.Next skips it.","commonSituations":"A new domain/alias not added to AllowedHosts; an IP-based request to a host-name-only allowlist; a load balancer forwarding an unexpected Host; Host header injection attempts; IPv6 or port-bearing hosts that need exact normalization.","solutions":["Add the legitimate hostname to Config.AllowedHosts.","Provide Config.AllowedHostsFunc for dynamic validation (e.g. a wildcard or DB lookup).","Use cfg.Next to exempt health-check or internal endpoints that come in with a different Host.","Verify the Host header your proxy forwards (preserve original Host via X-Forwarded-Host handling as needed)."],"exampleFix":"// before\nhostauthorization.New(hostauthorization.Config{\n  AllowedHosts: []string{\"example.com\"},\n})\n// after\nhostauthorization.New(hostauthorization.Config{\n  AllowedHosts: []string{\"example.com\", \"www.example.com\", \"api.example.com\"},\n})","handlingStrategy":"validation","validationCode":"func hostAllowed(host string, allowed []string, fn func(string) bool) bool {\n    h := normalizeAuthority(host)\n    if slices.Contains(allowed, h) { return true }\n    return fn != nil && fn(h)\n}","typeGuard":null,"tryCatchPattern":"if errors.Is(err, hostauthorization.ErrForbiddenHost) {\n    return c.Status(fiber.StatusForbidden).SendString(\"host not allowed\")\n}","preventionTips":["Keep AllowedHosts in sync with every domain served.","Use AllowedHostsFunc for dynamic or wildcard rules.","Use cfg.Next to exempt internal/health endpoints that use a different Host.","Verify the Host header your proxy forwards."],"tags":["hostauthorization","security","config","headers"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}