gofiber/fiber · error
hostauthorization: host
Error message
hostauthorization: host %q exceeds RFC 1035 maximum of %d characters (%d chars)
What it means
hostauthorization enforces RFC 1035: a fully-qualified domain name must not exceed 253 characters. validateHostLength panics when len(host) > maxDomainLength (253). The check runs at startup against each normalized AllowedHosts entry so an over-long hostname never silently fails to match a real (shorter) request Host.
Solutions
- Trim the entry to just the host (strip scheme, path, port) so it is a real hostname.
- If the hostname genuinely is long, shorten it — anything over 253 chars is not a legal DNS name and will not resolve.
- Sanitize host config at load time: reject or truncate entries exceeding 253 chars before passing to New().
Example fix
// before
hostauthorization.New(hostauthorization.Config{
AllowedHosts: []string{"https://app.example.com/some/very/long/path/..."},
})
// after
hostauthorization.New(hostauthorization.Config{
AllowedHosts: []string{"app.example.com"},
}) Defensive patterns
Strategy: validation
Validate before calling
func sanitizeHostList(in []string) ([]string, error) {
out := make([]string, 0, len(in))
for _, h := range in {
h = strings.TrimSpace(h)
if len(h) > 253 {
return nil, fmt.Errorf("host too long (%d chars): %q", len(h), h)
}
if h != "" {
out = append(out, h)
}
}
return out, nil
} Prevention
- Store only bare hostnames in AllowedHosts, never full URLs.
- Reject over-long host entries at config load rather than letting the middleware panic.
- Audit config sources that concatenate user input into hostname fields.
When it happens
Trigger: An AllowedHosts entry whose normalized form exceeds 253 bytes, e.g. a deeply-nested subdomain chain or a hostname accidentally concatenated with a path/query string. Also reachable if a config source injects an unbounded user-controlled string into AllowedHosts.
Common situations: Pasting a full URL (https://...path) into AllowedHosts instead of the bare host; a misconfigured template/concatenation producing an enormous domain; test fixtures generated with long random suffixes.
Related errors
- hostauthorization: host
- hostauthorization: invalid host
- hostauthorization: AllowedHosts or AllowedHostsFunc is…
- ErrTagInvalid
- ErrUnknownTag
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/d6db4be22766518a.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/hostauthorization/hostauthorization.go:69
continue
}
validateHostLength(h)
if isWildcard {
// Stored with leading dot so the hot-path HasSuffix check stays alloc-free.
parsed.wildcardSuffixes = append(parsed.wildcardSuffixes, "."+h)
} else {
parsed.exact[h] = struct{}{}
}
}
return parsed
}
func validateHostLength(host string) {
if len(host) > maxDomainLength {
panic(fmt.Sprintf("hostauthorization: host %q exceeds RFC 1035 maximum of %d characters (%d chars)",
host, maxDomainLength, len(host)))
}
// IPv6 hosts contain colons and aren't dotted labels.
if strings.IndexByte(host, ':') >= 0 {
return
}
for label := range strings.SplitSeq(host, ".") {
if len(label) > maxLabelLength {
panic(fmt.Sprintf("hostauthorization: host %q has label %q exceeding RFC 1035 limit of %d characters (%d chars)",
host, label, maxLabelLength, len(label)))
}
}
}
// normalizeHost strips port, trailing dot, and IPv6 brackets, lowercases,
// and converts IDN labels to Punycode (matching what browsers send).
func normalizeHost(host string) string {
// Fast path for plain hostnames — avoids net.SplitHostPort's error allocation.View on GitHub (pinned to a105acad6c)