{"record":{"id":"b8b741e0121e3d83","repo":"actix/actix-web","slug":"invalid-header-name","errorCode":null,"errorMessage":"Invalid header name","messagePattern":"Invalid header name","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"actix-web/src/middleware/default_headers.rs","lineNumber":91,"sourceCode":"        self\n    }\n\n    #[doc(hidden)]\n    #[deprecated(\n        since = \"4.0.0\",\n        note = \"Prefer `.add((key, value))`. Will be removed in v5.\"\n    )]\n    pub fn header<K, V>(self, key: K, value: V) -> Self\n    where\n        HeaderName: TryFrom<K>,\n        <HeaderName as TryFrom<K>>::Error: Into<HttpError>,\n        HeaderValue: TryFrom<V>,\n        <HeaderValue as TryFrom<V>>::Error: Into<HttpError>,\n    {\n        self.add((\n            HeaderName::try_from(key)\n                .map_err(Into::into)\n                .expect(\"Invalid header name\"),\n            HeaderValue::try_from(value)\n                .map_err(Into::into)\n                .expect(\"Invalid header value\"),\n        ))\n    }\n\n    /// Adds a default *Content-Type* header if response does not contain one.\n    ///\n    /// Default is `application/octet-stream`.\n    pub fn add_content_type(self) -> Self {\n        #[allow(clippy::declare_interior_mutable_const)]\n        const HV_MIME: HeaderValue = HeaderValue::from_static(\"application/octet-stream\");\n        self.add((CONTENT_TYPE, HV_MIME))\n    }\n}\n\nimpl<S, B> Transform<S, ServiceRequest> for DefaultHeaders\nwhere","sourceCodeStart":73,"sourceCodeEnd":109,"githubUrl":"https://github.com/actix/actix-web/blob/4d435abc281842f3cbee165b6cde739e001d3a25/actix-web/src/middleware/default_headers.rs#L73-L109","documentation":"This is a runtime panic from the deprecated `DefaultHeaders::header()` method. When the provided key cannot be converted into a valid `HeaderName` via `HeaderName::try_from(key)`, the `.expect(\"Invalid header name\")` at line 91 panics. Header names must be valid ASCII tokens without spaces, colons, or other invalid characters.","triggerScenarios":"Calling the deprecated `.header(key, value)` method with an invalid header name such as `\":\"`, `\"hello world\"`, `\"Content-Type:\"` (trailing colon), or a non-ASCII string. The `http` crate's `HeaderName` type has strict validation rules.","commonSituations":"Using the old `.header()` API instead of the preferred `.add()` method, or dynamically constructing header names from user input without validation.","solutions":["Migrate to the `.add((key, value))` API which panics with a more descriptive message but is the current API","Validate header names before passing them: use `HeaderName::try_from(key)` and handle the error gracefully","Ensure header names are valid RFC 7230 tokens: ASCII letters, digits, and the characters `!#$%&'*+-.^_`|~`","Avoid using the deprecated `.header()` method; use `.add()` instead"],"exampleFix":"// before (deprecated, panics on invalid name)\nlet mw = DefaultHeaders::new().header(\":\", \"hello\");\n\n// after (validated, does not panic)\nlet mw = DefaultHeaders::new();\nif let Ok(name) = HeaderName::try_from(\"x-valid-name\") {\n    let mw = mw.add((name, \"hello\"));\n}","handlingStrategy":"validation","validationCode":"// Validate header names before passing to the middleware.\nuse actix_web::http::header::HeaderName;\n\nfn safe_add(mw: DefaultHeaders, name: &str, value: &str) -> DefaultHeaders {\n    match (HeaderName::try_from(name), value.try_into()) {\n        (Ok(n), Ok(v)) => mw.add((n, v)),\n        _ => mw, // skip invalid header\n    }\n}","typeGuard":"use actix_web::http::header::HeaderName;\n\nfn is_valid_header_name(name: &str) -> bool {\n    HeaderName::try_from(name).is_ok()\n}","tryCatchPattern":"// Do not use the deprecated .header() method. Use .add() which validates at construction.\n// For dynamic header names, validate first:\nlet mw = DefaultHeaders::new();\nfor (name, value) in user_headers {\n    if is_valid_header_name(name) {\n        mw.add((name, value));\n    }\n}","preventionTips":["Migrate from the deprecated .header() to the .add((key, value)) API","Validate header names with HeaderName::try_from() before passing user-supplied values","Header names must be valid RFC 7230 tokens: ASCII letters, digits, and specific special characters","Add unit tests with invalid header names to verify your validation logic"],"tags":["rust","actix-web","middleware","runtime-panic","headers","deprecated"],"backgroundTag":null,"analyzedSha":"4d435abc281842f3cbee165b6cde739e001d3a25","analyzedAt":"2026-08-09T01:01:40.926Z","contentChangedAt":"2026-08-09T01:01:40.926Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}