gofiber/fiber · error

hostauthorization: forbidden host

Error message

hostauthorization: forbidden host

What it means

Returned by middleware/hostauthorization when the request Host header does not match any allowed host (or cannot be parsed into a normalized authority). The middleware normalizes the Host (port stripped, trailing dot removed, IPv6 brackets removed, lowercased), checks the static AllowedHosts list, then the AllowedHostsFunc, and rejects on no match. It is delivered via Config.ErrorHandler so the response shape is configurable.

Solutions

  1. Add the legitimate hostname to Config.AllowedHosts.
  2. Provide Config.AllowedHostsFunc for dynamic validation (e.g. a wildcard or DB lookup).
  3. Use cfg.Next to exempt health-check or internal endpoints that come in with a different Host.
  4. Verify the Host header your proxy forwards (preserve original Host via X-Forwarded-Host handling as needed).

Example fix

// before
hostauthorization.New(hostauthorization.Config{
  AllowedHosts: []string{"example.com"},
})
// after
hostauthorization.New(hostauthorization.Config{
  AllowedHosts: []string{"example.com", "www.example.com", "api.example.com"},
})
Defensive patterns

Strategy: validation

Validate before calling

func hostAllowed(host string, allowed []string, fn func(string) bool) bool {
    h := normalizeAuthority(host)
    if slices.Contains(allowed, h) { return true }
    return fn != nil && fn(h)
}

Try / catch

if errors.Is(err, hostauthorization.ErrForbiddenHost) {
    return c.Status(fiber.StatusForbidden).SendString("host not allowed")
}

Prevention

When it happens

Trigger: An inbound request whose Host header is not in AllowedHosts, not accepted by AllowedHostsFunc, or syntactically unparseable (parseNormalizedAuthority returns false). Affects every request unless cfg.Next skips it.

Common situations: A new domain/alias not added to AllowedHosts; an IP-based request to a host-name-only allowlist; a load balancer forwarding an unexpected Host; Host header injection attempts; IPv6 or port-bearing hosts that need exact normalization.

Understand the failure class

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/7ef52d2e6594d7b8. Report an issue: GitHub.

Appendix: source

Thrown at middleware/hostauthorization/config.go:10

package hostauthorization

import (
	"errors"

	"github.com/gofiber/fiber/v3"
)

// ErrForbiddenHost is returned when the Host header does not match any allowed host.
var ErrForbiddenHost = errors.New("hostauthorization: forbidden host")

// Config defines the config for the host authorization middleware.
type Config struct {
	// Next defines a function to skip this middleware when returned true.
	// Use this to exclude health check endpoints or other paths from host validation.
	//
	// Optional. Default: nil
	Next func(c fiber.Ctx) bool

	// AllowedHostsFunc is a dynamic validator called only when no static
	// AllowedHosts rule matches. Receives the normalized hostname: port stripped,
	// trailing dot removed, IPv6 brackets removed, lowercased.
	// Return true to allow.
	//
	// Optional. Default: nil
	AllowedHostsFunc func(host string) bool

	// ErrorHandler is called when a request is rejected.

View on GitHub (pinned to a105acad6c)