{"record":{"id":"9303257bd3c31df9","repo":"gofiber/fiber","slug":"set-boundary-error-w","errorCode":null,"errorMessage":"set boundary error: %w","messagePattern":"set boundary error: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"client/hooks.go","lineNumber":239,"sourceCode":"\t\tif body, ok := req.body.([]byte); ok { //nolint:revive // ignore simplicity\n\t\t\treq.RawRequest.SetBody(body)\n\t\t} else {\n\t\t\treturn ErrBodyType\n\t\t}\n\tcase noBody:\n\t\t// No body to set.\n\t\treturn nil\n\tdefault:\n\t\treturn ErrBodyTypeNotSupported\n\t}\n\treturn nil\n}\n\n// parserRequestBodyFile handles the case where the request contains files to be uploaded.\nfunc parserRequestBodyFile(req *Request) error {\n\tmw := multipart.NewWriter(req.RawRequest.BodyWriter())\n\tif err := mw.SetBoundary(req.boundary); err != nil {\n\t\treturn fmt.Errorf(\"set boundary error: %w\", err)\n\t}\n\n\tif err := writeMultipartBody(mw, req); err != nil {\n\t\tmw.Close() //nolint:errcheck // the body write already failed; surface that error instead\n\t\treturn err\n\t}\n\n\t// Close writes the trailing boundary; if it fails the multipart body is\n\t// incomplete, so surface the error instead of sending a malformed request.\n\tif err := mw.Close(); err != nil {\n\t\treturn fmt.Errorf(\"failed to close multipart writer: %w\", err)\n\t}\n\n\treturn nil\n}\n\n// writeMultipartBody writes the form fields and files of req to mw.\nfunc writeMultipartBody(mw *multipart.Writer, req *Request) error {","sourceCodeStart":221,"sourceCodeEnd":257,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/client/hooks.go#L221-L257","documentation":"parserRequestBodyFile creates a multipart.Writer over the request's body writer and immediately calls SetBoundary with req.boundary. This error wraps mime/multipart's rejection: the boundary string contains invalid characters or is too short/long (RFC 2046 limits it to 1–70 chars of allowed runes).","triggerScenarios":"Calling req.SetBoundary with a custom string containing whitespace, control chars, special RFC characters, or exceeding 70 characters; a boundary that begins/ends with spaces.","commonSituations":"Hard-coding a boundary copied from a browser/cURL capture that includes quotes or whitespace; programmatically building a boundary from user input without sanitizing; a copy-paste that includes trailing newlines.","solutions":["Use a boundary made only of letters, digits, and '-', 1–70 characters long.","Let the client auto-generate the boundary (omit SetBoundary) unless you have a specific reason.","Validate the boundary with a regex like ^[A-Za-z0-9'()+_,\\-./:=?]{1,70}$ before setting it."],"exampleFix":"// before\nreq.SetBoundary(\"my boundary with spaces\")\n\n// after\nreq.SetBoundary(\"GoFiberBoundary7MA4YWxk\")","handlingStrategy":"validation","validationCode":"var boundaryRE = regexp.MustCompile(`^[A-Za-z0-9'()+_,\\-./:=?]{1,70}$`)\nif !boundaryRE.MatchString(b) {\n    return fmt.Errorf(\"invalid multipart boundary: %q\", b)\n}\nreq.SetBoundary(b)","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Prefer letting the client generate the boundary automatically.","If you must set one, use only [A-Za-z0-9-] and keep it 1–70 characters.","Never accept a boundary from untrusted input without the regex check."],"tags":["client","multipart","boundary","validation","upload"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}