gofiber/fiber · error

hostauthorization: host

Error message

hostauthorization: host %q exceeds RFC 1035 maximum of %d characters (%d chars)

What it means

hostauthorization enforces RFC 1035: a fully-qualified domain name must not exceed 253 characters. validateHostLength panics when len(host) > maxDomainLength (253). The check runs at startup against each normalized AllowedHosts entry so an over-long hostname never silently fails to match a real (shorter) request Host.

Solutions

  1. Trim the entry to just the host (strip scheme, path, port) so it is a real hostname.
  2. If the hostname genuinely is long, shorten it — anything over 253 chars is not a legal DNS name and will not resolve.
  3. Sanitize host config at load time: reject or truncate entries exceeding 253 chars before passing to New().

Example fix

// before
hostauthorization.New(hostauthorization.Config{
    AllowedHosts: []string{"https://app.example.com/some/very/long/path/..."},
})

// after
hostauthorization.New(hostauthorization.Config{
    AllowedHosts: []string{"app.example.com"},
})
Defensive patterns

Strategy: validation

Validate before calling

func sanitizeHostList(in []string) ([]string, error) {
    out := make([]string, 0, len(in))
    for _, h := range in {
        h = strings.TrimSpace(h)
        if len(h) > 253 {
            return nil, fmt.Errorf("host too long (%d chars): %q", len(h), h)
        }
        if h != "" {
            out = append(out, h)
        }
    }
    return out, nil
}

Prevention

When it happens

Trigger: An AllowedHosts entry whose normalized form exceeds 253 bytes, e.g. a deeply-nested subdomain chain or a hostname accidentally concatenated with a path/query string. Also reachable if a config source injects an unbounded user-controlled string into AllowedHosts.

Common situations: Pasting a full URL (https://...path) into AllowedHosts instead of the bare host; a misconfigured template/concatenation producing an enormous domain; test fixtures generated with long random suffixes.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/d6db4be22766518a. Report an issue: GitHub.

Appendix: source

Thrown at middleware/hostauthorization/hostauthorization.go:69

			continue
		}

		validateHostLength(h)

		if isWildcard {
			// Stored with leading dot so the hot-path HasSuffix check stays alloc-free.
			parsed.wildcardSuffixes = append(parsed.wildcardSuffixes, "."+h)
		} else {
			parsed.exact[h] = struct{}{}
		}
	}

	return parsed
}

func validateHostLength(host string) {
	if len(host) > maxDomainLength {
		panic(fmt.Sprintf("hostauthorization: host %q exceeds RFC 1035 maximum of %d characters (%d chars)",
			host, maxDomainLength, len(host)))
	}
	// IPv6 hosts contain colons and aren't dotted labels.
	if strings.IndexByte(host, ':') >= 0 {
		return
	}
	for label := range strings.SplitSeq(host, ".") {
		if len(label) > maxLabelLength {
			panic(fmt.Sprintf("hostauthorization: host %q has label %q exceeding RFC 1035 limit of %d characters (%d chars)",
				host, label, maxLabelLength, len(label)))
		}
	}
}

// normalizeHost strips port, trailing dot, and IPv6 brackets, lowercases,
// and converts IDN labels to Punycode (matching what browsers send).
func normalizeHost(host string) string {
	// Fast path for plain hostnames — avoids net.SplitHostPort's error allocation.

View on GitHub (pinned to a105acad6c)