{"record":{"id":"f26e879139f4da0c","repo":"gofiber/fiber","slug":"domain-pattern-s-exceeds-rfc-1035-maximum-of-25","errorCode":null,"errorMessage":"Domain pattern '%s' exceeds RFC 1035 maximum of 253 characters (%d chars)","messagePattern":"Domain pattern '(.+?)' exceeds RFC 1035 maximum of 253 characters \\((.+?) chars\\)","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"domain.go","lineNumber":68,"sourceCode":"// parseDomainPattern parses a domain pattern like \":subdomain.example.com\"\n// into a domainMatcher. Parameter parts start with \":\".\n// Constant labels are lowercased per RFC 4343 (domain names are case-insensitive),\n// but parameter names are preserved as-is so that DomainParam lookups work with\n// the exact names the caller used (e.g., \":User\" → param name \"User\").\nfunc parseDomainPattern(pattern string) domainMatcher {\n\tpattern = utils.TrimSpace(pattern)\n\t// Trim trailing dot of a fully-qualified domain name (RFC 3986),\n\t// consistent with Fiber's own host normalization in Subdomains().\n\tpattern = utils.TrimRight(pattern, '.')\n\n\t// Validate pattern is not empty after trimming\n\tif pattern == \"\" {\n\t\tpanic(\"Domain pattern cannot be empty\")\n\t}\n\n\t// Enforce RFC 1035 total length limit on patterns\n\tif len(pattern) > 253 {\n\t\tpanic(fmt.Sprintf(\"Domain pattern '%s' exceeds RFC 1035 maximum of 253 characters (%d chars)\",\n\t\t\tpattern, len(pattern)))\n\t}\n\n\tparts := strings.Split(pattern, \".\")\n\n\t// Prevent DoS from patterns with excessive label counts\n\tif len(parts) > maxDomainParts {\n\t\tpanic(fmt.Sprintf(\"Domain pattern '%s' has %d parts, which exceeds the maximum of %d\",\n\t\t\tpattern, len(parts), maxDomainParts))\n\t}\n\n\tm := domainMatcher{\n\t\tparts:    make([]string, len(parts)),\n\t\tnumParts: len(parts),\n\t}\n\n\tfor i, part := range parts {\n\t\t// Validate no empty labels (e.g., \"example..com\" is invalid)","sourceCodeStart":50,"sourceCodeEnd":86,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/domain.go#L50-L86","documentation":"parseDomainPattern enforces the RFC 1035 total length limit (253 octets, leaving room for the root label) on domain patterns. Patterns longer than 253 characters are rejected at registration to keep DNS semantics valid. The pattern length counts after trimming whitespace and the trailing dot.","triggerScenarios":"Passing a domain pattern (possibly with parameter labels like :tenant) whose total character count exceeds 253.","commonSituations":"Dynamically composing a long pattern from many subdomains; copy-pasting a wildcard chain; templating that concatenates without length checks; typo producing a huge pattern.","solutions":["Shorten the pattern to <= 253 characters; split routing across multiple Domain routes if needed.","Validate length before registering: if len(pattern) > 253 { return error }.","Reduce label count or use shorter parameter names."],"exampleFix":"// before\napp.Domain(strings.Repeat(\"sub.\", 60) + \"example.com\")\n\n// after\napp.Domain(\"sub.example.com\")  // collapse redundant labels","handlingStrategy":"validation","validationCode":"const maxDomainPattern = 253\n\nfunc validateDomainLength(p string) error {\n    if len(p) > maxDomainPattern {\n        return fmt.Errorf(\"domain pattern too long: %d > %d\", len(p), maxDomainPattern)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Cap pattern length at the source (config, env).","Split very long patterns into multiple Domain routes.","Add a lint check on dynamic pattern composition."],"tags":["routing","domain","validation","rfc-1035","startup"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}