{"record":{"id":"d6db4be22766518a","repo":"gofiber/fiber","slug":"hostauthorization-host-q-exceeds-rfc-1035-maximu","errorCode":null,"errorMessage":"hostauthorization: host %q exceeds RFC 1035 maximum of %d characters (%d chars)","messagePattern":"hostauthorization: host %q exceeds RFC 1035 maximum of (.+?) characters \\((.+?) chars\\)","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/hostauthorization/hostauthorization.go","lineNumber":69,"sourceCode":"\t\t\tcontinue\n\t\t}\n\n\t\tvalidateHostLength(h)\n\n\t\tif isWildcard {\n\t\t\t// Stored with leading dot so the hot-path HasSuffix check stays alloc-free.\n\t\t\tparsed.wildcardSuffixes = append(parsed.wildcardSuffixes, \".\"+h)\n\t\t} else {\n\t\t\tparsed.exact[h] = struct{}{}\n\t\t}\n\t}\n\n\treturn parsed\n}\n\nfunc validateHostLength(host string) {\n\tif len(host) > maxDomainLength {\n\t\tpanic(fmt.Sprintf(\"hostauthorization: host %q exceeds RFC 1035 maximum of %d characters (%d chars)\",\n\t\t\thost, maxDomainLength, len(host)))\n\t}\n\t// IPv6 hosts contain colons and aren't dotted labels.\n\tif strings.IndexByte(host, ':') >= 0 {\n\t\treturn\n\t}\n\tfor label := range strings.SplitSeq(host, \".\") {\n\t\tif len(label) > maxLabelLength {\n\t\t\tpanic(fmt.Sprintf(\"hostauthorization: host %q has label %q exceeding RFC 1035 limit of %d characters (%d chars)\",\n\t\t\t\thost, label, maxLabelLength, len(label)))\n\t\t}\n\t}\n}\n\n// normalizeHost strips port, trailing dot, and IPv6 brackets, lowercases,\n// and converts IDN labels to Punycode (matching what browsers send).\nfunc normalizeHost(host string) string {\n\t// Fast path for plain hostnames — avoids net.SplitHostPort's error allocation.","sourceCodeStart":51,"sourceCodeEnd":87,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/hostauthorization/hostauthorization.go#L51-L87","documentation":"hostauthorization enforces RFC 1035: a fully-qualified domain name must not exceed 253 characters. validateHostLength panics when len(host) > maxDomainLength (253). The check runs at startup against each normalized AllowedHosts entry so an over-long hostname never silently fails to match a real (shorter) request Host.","triggerScenarios":"An AllowedHosts entry whose normalized form exceeds 253 bytes, e.g. a deeply-nested subdomain chain or a hostname accidentally concatenated with a path/query string. Also reachable if a config source injects an unbounded user-controlled string into AllowedHosts.","commonSituations":"Pasting a full URL (https://...path) into AllowedHosts instead of the bare host; a misconfigured template/concatenation producing an enormous domain; test fixtures generated with long random suffixes.","solutions":["Trim the entry to just the host (strip scheme, path, port) so it is a real hostname.","If the hostname genuinely is long, shorten it — anything over 253 chars is not a legal DNS name and will not resolve.","Sanitize host config at load time: reject or truncate entries exceeding 253 chars before passing to New()."],"exampleFix":"// before\nhostauthorization.New(hostauthorization.Config{\n    AllowedHosts: []string{\"https://app.example.com/some/very/long/path/...\"},\n})\n\n// after\nhostauthorization.New(hostauthorization.Config{\n    AllowedHosts: []string{\"app.example.com\"},\n})","handlingStrategy":"validation","validationCode":"func sanitizeHostList(in []string) ([]string, error) {\n    out := make([]string, 0, len(in))\n    for _, h := range in {\n        h = strings.TrimSpace(h)\n        if len(h) > 253 {\n            return nil, fmt.Errorf(\"host too long (%d chars): %q\", len(h), h)\n        }\n        if h != \"\" {\n            out = append(out, h)\n        }\n    }\n    return out, nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Store only bare hostnames in AllowedHosts, never full URLs.","Reject over-long host entries at config load rather than letting the middleware panic.","Audit config sources that concatenate user input into hostname fields."],"tags":["hostauthorization","dns","rfc-1035","config","startup-panic"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}