gofiber/fiber · error

hostauthorization: AllowedHosts or AllowedHostsFunc is…

Error message

hostauthorization: AllowedHosts or AllowedHostsFunc is required

What it means

The hostauthorization middleware requires at least one host-authorization mechanism. configDefault panics when AllowedHosts is empty AND AllowedHostsFunc is nil, because a host-authorization middleware that authorizes nothing is a no-op that would either reject every request or, worse, silently pass through. You must supply one of the two.

Solutions

  1. Provide a non-empty AllowedHosts slice, e.g. hostauthorization.New(hostauthorization.Config{AllowedHosts: []string{"app.example.com", "*.app.example.com"}}).
  2. Provide an AllowedHostsFunc if the allowed set is dynamic, e.g. AllowedHostsFunc: func(h string) bool { return allowlist.Contains(h) }.
  3. If host authorization is optional in some environments, guard the app.Use(hostauthorization.New(...)) call itself rather than passing an empty config.

Example fix

// before
app.Use(hostauthorization.New(hostauthorization.Config{}))

// after
app.Use(hostauthorization.New(hostauthorization.Config{
    AllowedHosts: []string{"app.example.com", "*.app.example.com"},
}))
Defensive patterns

Strategy: validation

Validate before calling

func buildHostAuthCfg(hosts []string, fn func(string) bool) (hostauthorization.Config, error) {
    if len(hosts) == 0 && fn == nil {
        return hostauthorization.Config{}, errors.New("AllowedHosts or AllowedHostsFunc required")
    }
    return hostauthorization.Config{AllowedHosts: hosts, AllowedHostsFunc: fn}, nil
}

Type guard

func hasHostAuthSource(hosts []string, fn func(string) bool) bool {
    return len(hosts) > 0 || fn != nil
}

Prevention

When it happens

Trigger: hostauthorization.New() with no args, or hostauthorization.New(hostauthorization.Config{}) (zero-value config). Also triggered by constructing Config from a struct literal where AllowedHosts is conditionally populated but the condition leaves it nil.

Common situations: Reading allowed hosts from an env var that is empty in dev; building Config in a helper that returns an empty Config when the feature flag is off, then still wiring New() unconditionally; refactoring away a static list in favor of AllowedHostsFunc but forgetting to assign the func.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/6dd646d19b4ae8b3. Report an issue: GitHub.

Appendix: source

Thrown at middleware/hostauthorization/config.go:57

	// Entries are normalized at startup: port stripped, trailing dot removed,
	// lowercased, IDN labels converted to Punycode, RFC 1035 length limits enforced
	// (≤253 total / ≤63 per-label).
	//
	// Required if AllowedHostsFunc is nil.
	AllowedHosts []string
}

// ConfigDefault is the default config.
var ConfigDefault = Config{}

func configDefault(config ...Config) Config {
	cfg := ConfigDefault
	if len(config) > 0 {
		cfg = config[0]
	}

	if len(cfg.AllowedHosts) == 0 && cfg.AllowedHostsFunc == nil {
		panic("hostauthorization: AllowedHosts or AllowedHostsFunc is required")
	}

	if cfg.ErrorHandler == nil {
		cfg.ErrorHandler = func(c fiber.Ctx, _ error) error {
			return c.SendStatus(fiber.StatusForbidden)
		}
	}

	return cfg
}

View on GitHub (pinned to a105acad6c)