gofiber/fiber · error
hostauthorization: AllowedHosts or AllowedHostsFunc is…
Error message
hostauthorization: AllowedHosts or AllowedHostsFunc is required
What it means
The hostauthorization middleware requires at least one host-authorization mechanism. configDefault panics when AllowedHosts is empty AND AllowedHostsFunc is nil, because a host-authorization middleware that authorizes nothing is a no-op that would either reject every request or, worse, silently pass through. You must supply one of the two.
Solutions
- Provide a non-empty AllowedHosts slice, e.g. hostauthorization.New(hostauthorization.Config{AllowedHosts: []string{"app.example.com", "*.app.example.com"}}).
- Provide an AllowedHostsFunc if the allowed set is dynamic, e.g. AllowedHostsFunc: func(h string) bool { return allowlist.Contains(h) }.
- If host authorization is optional in some environments, guard the app.Use(hostauthorization.New(...)) call itself rather than passing an empty config.
Example fix
// before
app.Use(hostauthorization.New(hostauthorization.Config{}))
// after
app.Use(hostauthorization.New(hostauthorization.Config{
AllowedHosts: []string{"app.example.com", "*.app.example.com"},
})) Defensive patterns
Strategy: validation
Validate before calling
func buildHostAuthCfg(hosts []string, fn func(string) bool) (hostauthorization.Config, error) {
if len(hosts) == 0 && fn == nil {
return hostauthorization.Config{}, errors.New("AllowedHosts or AllowedHostsFunc required")
}
return hostauthorization.Config{AllowedHosts: hosts, AllowedHostsFunc: fn}, nil
} Type guard
func hasHostAuthSource(hosts []string, fn func(string) bool) bool {
return len(hosts) > 0 || fn != nil
} Prevention
- Make host-authorization registration conditional on having at least one allow source.
- Fail config loading loudly when the allowed-hosts env var is empty in production.
- Prefer AllowedHostsFunc for dynamic sets, but always assign a non-nil function.
When it happens
Trigger: hostauthorization.New() with no args, or hostauthorization.New(hostauthorization.Config{}) (zero-value config). Also triggered by constructing Config from a struct literal where AllowedHosts is conditionally populated but the condition leaves it nil.
Common situations: Reading allowed hosts from an env var that is empty in dev; building Config in a helper that returns an empty Config when the feature flag is off, then still wiring New() unconditionally; refactoring away a static list in favor of AllowedHostsFunc but forgetting to assign the func.
Related errors
- ErrUpstreamSchemeNotAllowed
- fiber: keyauth middleware requires a validator function
- hostauthorization: forbidden host
- hostauthorization: host
- hostauthorization: host
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/6dd646d19b4ae8b3.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/hostauthorization/config.go:57
// Entries are normalized at startup: port stripped, trailing dot removed,
// lowercased, IDN labels converted to Punycode, RFC 1035 length limits enforced
// (≤253 total / ≤63 per-label).
//
// Required if AllowedHostsFunc is nil.
AllowedHosts []string
}
// ConfigDefault is the default config.
var ConfigDefault = Config{}
func configDefault(config ...Config) Config {
cfg := ConfigDefault
if len(config) > 0 {
cfg = config[0]
}
if len(cfg.AllowedHosts) == 0 && cfg.AllowedHostsFunc == nil {
panic("hostauthorization: AllowedHosts or AllowedHostsFunc is required")
}
if cfg.ErrorHandler == nil {
cfg.ErrorHandler = func(c fiber.Ctx, _ error) error {
return c.SendStatus(fiber.StatusForbidden)
}
}
return cfg
}
View on GitHub (pinned to a105acad6c)