{"record":{"id":"a28f8d6f06c3e018","repo":"gofiber/fiber","slug":"hostauthorization-host-q-has-label-q-exceeding","errorCode":null,"errorMessage":"hostauthorization: host %q has label %q exceeding RFC 1035 limit of %d characters (%d chars)","messagePattern":"hostauthorization: host %q has label %q exceeding RFC 1035 limit of (.+?) characters \\((.+?) chars\\)","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/hostauthorization/hostauthorization.go","lineNumber":78,"sourceCode":"\t\t\tparsed.exact[h] = struct{}{}\n\t\t}\n\t}\n\n\treturn parsed\n}\n\nfunc validateHostLength(host string) {\n\tif len(host) > maxDomainLength {\n\t\tpanic(fmt.Sprintf(\"hostauthorization: host %q exceeds RFC 1035 maximum of %d characters (%d chars)\",\n\t\t\thost, maxDomainLength, len(host)))\n\t}\n\t// IPv6 hosts contain colons and aren't dotted labels.\n\tif strings.IndexByte(host, ':') >= 0 {\n\t\treturn\n\t}\n\tfor label := range strings.SplitSeq(host, \".\") {\n\t\tif len(label) > maxLabelLength {\n\t\t\tpanic(fmt.Sprintf(\"hostauthorization: host %q has label %q exceeding RFC 1035 limit of %d characters (%d chars)\",\n\t\t\t\thost, label, maxLabelLength, len(label)))\n\t\t}\n\t}\n}\n\n// normalizeHost strips port, trailing dot, and IPv6 brackets, lowercases,\n// and converts IDN labels to Punycode (matching what browsers send).\nfunc normalizeHost(host string) string {\n\t// Fast path for plain hostnames — avoids net.SplitHostPort's error allocation.\n\tif host != \"\" && host[0] != '[' && strings.IndexByte(host, ':') < 0 {\n\t\thost = trimOneTrailingDot(host)\n\t\thost = utilsstrings.ToLower(host)\n\t\treturn toPunycode(host)\n\t}\n\n\tif h, _, err := net.SplitHostPort(host); err == nil {\n\t\thost = h\n\t} else {","sourceCodeStart":60,"sourceCodeEnd":96,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/hostauthorization/hostauthorization.go#L60-L96","documentation":"hostauthorization enforces RFC 1035 per-label length: each dot-separated label of a hostname must be at most 63 characters. validateHostLength splits the host on '.' and panics when any single label exceeds maxLabelLength (63). This catches a single over-long segment even when the total domain length is within the 253-char budget.","triggerScenarios":"An AllowedHosts entry containing a label longer than 63 chars, e.g. a slug or token accidentally used as a subdomain label. IPv6 hosts (which contain ':') are skipped by this check; it only applies to dotted DNS names.","commonSituations":"Using a tenant UUID or long opaque token as a hostname label (e.g. aaaa...63chars....example.com); pasting a URL-encoded value as a label; generating hostnames programmatically without label-length awareness.","solutions":["Shorten the offending label to 63 characters or fewer (DNS will reject anything longer anyway).","If the long value is an identifier, move it into a path or query parameter rather than a DNS label.","Validate each label at config-load time and reject entries with any label > 63 chars before constructing the middleware."],"exampleFix":"// before — tenant ID is 72 chars, used as a label\nhostauthorization.New(hostauthorization.Config{\n    AllowedHosts: []string{\"<72-char-tenant-id>.example.com\"},\n})\n\n// after — keep tenants out of DNS labels\nhostauthorization.New(hostauthorization.Config{\n    AllowedHosts: []string{\" tenants.example.com\"},\n}) // route by /t/<tenant-id> instead","handlingStrategy":"validation","validationCode":"func validateHostLabels(host string) error {\n    for _, label := range strings.Split(host, \".\") {\n        if len(label) > 63 {\n            return fmt.Errorf(\"label %q exceeds 63 chars\", label)\n        }\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Do not put opaque IDs/tokens in DNS labels — move them to path/query.","Validate each label length when generating hostnames programmatically.","Reject over-long labels at the config boundary."],"tags":["hostauthorization","dns","rfc-1035","config","startup-panic"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}