gofiber/fiber · error
hostauthorization: forbidden host
Error message
hostauthorization: forbidden host
What it means
Returned by middleware/hostauthorization when the request Host header does not match any allowed host (or cannot be parsed into a normalized authority). The middleware normalizes the Host (port stripped, trailing dot removed, IPv6 brackets removed, lowercased), checks the static AllowedHosts list, then the AllowedHostsFunc, and rejects on no match. It is delivered via Config.ErrorHandler so the response shape is configurable.
Solutions
- Add the legitimate hostname to Config.AllowedHosts.
- Provide Config.AllowedHostsFunc for dynamic validation (e.g. a wildcard or DB lookup).
- Use cfg.Next to exempt health-check or internal endpoints that come in with a different Host.
- Verify the Host header your proxy forwards (preserve original Host via X-Forwarded-Host handling as needed).
Example fix
// before
hostauthorization.New(hostauthorization.Config{
AllowedHosts: []string{"example.com"},
})
// after
hostauthorization.New(hostauthorization.Config{
AllowedHosts: []string{"example.com", "www.example.com", "api.example.com"},
}) Defensive patterns
Strategy: validation
Validate before calling
func hostAllowed(host string, allowed []string, fn func(string) bool) bool {
h := normalizeAuthority(host)
if slices.Contains(allowed, h) { return true }
return fn != nil && fn(h)
} Try / catch
if errors.Is(err, hostauthorization.ErrForbiddenHost) {
return c.Status(fiber.StatusForbidden).SendString("host not allowed")
} Prevention
- Keep AllowedHosts in sync with every domain served.
- Use AllowedHostsFunc for dynamic or wildcard rules.
- Use cfg.Next to exempt internal/health endpoints that use a different Host.
- Verify the Host header your proxy forwards.
When it happens
Trigger: An inbound request whose Host header is not in AllowedHosts, not accepted by AllowedHostsFunc, or syntactically unparseable (parseNormalizedAuthority returns false). Affects every request unless cfg.Next skips it.
Common situations: A new domain/alias not added to AllowedHosts; an IP-based request to a host-name-only allowlist; a load balancer forwarding an unexpected Host; Host header injection attempts; IPv6 or port-bearing hosts that need exact normalization.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- hostauthorization: AllowedHosts or AllowedHostsFunc is…
- [CORS] Invalid origin format in configuration:
- [CSRF] Invalid origin format in configuration:
- csrf: origin does not match host or trusted origins
- csrf: origin header invalid
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/7ef52d2e6594d7b8.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/hostauthorization/config.go:10
package hostauthorization
import (
"errors"
"github.com/gofiber/fiber/v3"
)
// ErrForbiddenHost is returned when the Host header does not match any allowed host.
var ErrForbiddenHost = errors.New("hostauthorization: forbidden host")
// Config defines the config for the host authorization middleware.
type Config struct {
// Next defines a function to skip this middleware when returned true.
// Use this to exclude health check endpoints or other paths from host validation.
//
// Optional. Default: nil
Next func(c fiber.Ctx) bool
// AllowedHostsFunc is a dynamic validator called only when no static
// AllowedHosts rule matches. Receives the normalized hostname: port stripped,
// trailing dot removed, IPv6 brackets removed, lowercased.
// Return true to allow.
//
// Optional. Default: nil
AllowedHostsFunc func(host string) bool
// ErrorHandler is called when a request is rejected.View on GitHub (pinned to a105acad6c)