{"record":{"id":"b763513a2f9ed0c0","repo":"gofiber/fiber","slug":"domain-pattern-s-has-d-parameters-which-excee","errorCode":null,"errorMessage":"Domain pattern '%s' has %d parameters, which exceeds the maximum of %d","messagePattern":"Domain pattern '(.+?)' has (.+?) parameters, which exceeds the maximum of (.+?)","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"domain.go","lineNumber":128,"sourceCode":"\t\t\t// Enforce RFC 1035 per-label length limit (63 characters)\n\t\t\tif len(part) > 63 {\n\t\t\t\tpanic(fmt.Sprintf(\"Domain pattern '%s' has label '%s' exceeding RFC 1035 limit of 63 characters (%d chars)\",\n\t\t\t\t\tpattern, part, len(part)))\n\t\t\t}\n\t\t\t// Validate label contains only valid ASCII domain characters (a-z, 0-9, hyphen).\n\t\t\tnormalized := utilsstrings.ToLower(part)\n\t\t\tfor _, ch := range normalized {\n\t\t\t\tif !isASCIIAlphanumeric(ch) && ch != '-' {\n\t\t\t\t\tpanic(fmt.Sprintf(\"Domain pattern '%s' contains invalid character '%c' in label '%s'\", pattern, ch, part))\n\t\t\t\t}\n\t\t\t}\n\t\t\tm.parts[i] = normalized\n\t\t}\n\t}\n\n\t// Check if the domain pattern has too many parameters\n\tif len(m.paramNames) > maxParams {\n\t\tpanic(fmt.Sprintf(\"Domain pattern '%s' has %d parameters, which exceeds the maximum of %d\",\n\t\t\tpattern, len(m.paramNames), maxParams))\n\t}\n\n\treturn m\n}\n\n// match checks if a hostname matches the domain pattern.\n// It returns true if matched and a slice of parameter values (parallel to paramNames).\n// Uses a stack-allocated buffer to avoid heap allocation for typical domain names.\n// Validates hostname to prevent DoS attacks from malicious input.\nfunc (m *domainMatcher) match(hostname string) (bool, []string) { //nolint:gocritic // unnamedResult: named returns conflict with nonamedreturns linter\n\t// Trim trailing dot of a fully-qualified domain name (RFC 3986),\n\t// consistent with Fiber's own host normalization in Subdomains().\n\thostname = utils.TrimRight(hostname, '.')\n\n\t// Validate hostname is not empty and not excessively long (DoS protection)\n\t// RFC 1035 limits domain names to 253 characters\n\tif hostname == \"\" || len(hostname) > 253 {","sourceCodeStart":110,"sourceCodeEnd":146,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/domain.go#L110-L146","documentation":"The domain pattern declares more parameters (':param' segments) than fiber/v3's internal maxParams cap. Each parameter is tracked in parallel slices (paramIdx, paramNames), and the cap bounds match-time memory and complexity. Exceeding it is treated as a malformed/abusive pattern.","triggerScenarios":"Calling a domain-routing API with a pattern containing more ':param' tokens than maxParams, e.g. \":a.:b.:c.:d.:e...\" with each label as a separate parameter beyond the configured ceiling.","commonSituations":"Dynamically generating a domain pattern from user input where each label becomes a param; overusing capture-everything patterns instead of matching a concrete suffix; porting a wildcard-heavy Express/Fastify route verbatim.","solutions":["Reduce the number of ':param' segments by making low-value labels literal (e.g. keep a fixed TLD like '.com' as a constant label).","Re-design the routing so most labels are matched as a single suffix/wildcard rather than individual params.","Cap and validate the param count on the generated pattern string before passing it to the router."],"exampleFix":"// before\napp.Use(\":a.:b.:c.:d.:e.:f.:g.:h.example.com\", handler) // too many params\n// after\napp.Use(\":tenant.example.com\", handler) // capture only what you need","handlingStrategy":"validation","validationCode":"const maxParams = /* mirror fiber's cap; use a conservative local ceiling */ 8\n\nfunc countParams(pattern string) int {\n    n := 0\n    for _, lbl := range strings.Split(pattern, \".\") {\n        if strings.HasPrefix(lbl, \":\") {\n            n++\n        }\n    }\n    return n\n}\n\nif n := countParams(domainPattern); n > maxParams {\n    return fmt.Errorf(\"pattern has %d params, max %d\", n, maxParams)\n}","typeGuard":null,"tryCatchPattern":"defer func() {\n    if r := recover(); r != nil {\n        log.Fatalf(\"too many domain params: %v\", r)\n    }\n}()\napp.Use(domainPattern, handler)","preventionTips":["Capture only the labels you actually need; make the rest literal.","Cap and validate param count in your pattern-generation helper.","Avoid auto-generated ':a.:b.:c...' patterns from unbounded user input."],"tags":["routing","domain","validation","limits","startup"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}