gofiber/fiber · error
set boundary error
Error message
set boundary error: %w
What it means
parserRequestBodyFile creates a multipart.Writer over the request's body writer and immediately calls SetBoundary with req.boundary. This error wraps mime/multipart's rejection: the boundary string contains invalid characters or is too short/long (RFC 2046 limits it to 1–70 chars of allowed runes).
Solutions
- Use a boundary made only of letters, digits, and '-', 1–70 characters long.
- Let the client auto-generate the boundary (omit SetBoundary) unless you have a specific reason.
- Validate the boundary with a regex like ^[A-Za-z0-9'()+_,\-./:=?]{1,70}$ before setting it.
Example fix
// before
req.SetBoundary("my boundary with spaces")
// after
req.SetBoundary("GoFiberBoundary7MA4YWxk") Defensive patterns
Strategy: validation
Validate before calling
var boundaryRE = regexp.MustCompile(`^[A-Za-z0-9'()+_,\-./:=?]{1,70}$`)
if !boundaryRE.MatchString(b) {
return fmt.Errorf("invalid multipart boundary: %q", b)
}
req.SetBoundary(b) Prevention
- Prefer letting the client generate the boundary automatically.
- If you must set one, use only [A-Za-z0-9-] and keep it 1–70 characters.
- Never accept a boundary from untrusted input without the regex check.
When it happens
Trigger: Calling req.SetBoundary with a custom string containing whitespace, control chars, special RFC characters, or exceeding 70 characters; a boundary that begins/ends with spaces.
Common situations: Hard-coding a boundary copied from a browser/cURL capture that includes quotes or whitespace; programmatically building a boundary from user input without sanitizing; a copy-paste that includes trailing newlines.
Related errors
- boundary generation
- failed to close multipart writer
- file: file header is nil
- rand.Read failed
- the file should have a name
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/9303257bd3c31df9.
Report an issue: GitHub.
Appendix: source
Thrown at client/hooks.go:239
if body, ok := req.body.([]byte); ok { //nolint:revive // ignore simplicity
req.RawRequest.SetBody(body)
} else {
return ErrBodyType
}
case noBody:
// No body to set.
return nil
default:
return ErrBodyTypeNotSupported
}
return nil
}
// parserRequestBodyFile handles the case where the request contains files to be uploaded.
func parserRequestBodyFile(req *Request) error {
mw := multipart.NewWriter(req.RawRequest.BodyWriter())
if err := mw.SetBoundary(req.boundary); err != nil {
return fmt.Errorf("set boundary error: %w", err)
}
if err := writeMultipartBody(mw, req); err != nil {
mw.Close() //nolint:errcheck // the body write already failed; surface that error instead
return err
}
// Close writes the trailing boundary; if it fails the multipart body is
// incomplete, so surface the error instead of sending a malformed request.
if err := mw.Close(); err != nil {
return fmt.Errorf("failed to close multipart writer: %w", err)
}
return nil
}
// writeMultipartBody writes the form fields and files of req to mw.
func writeMultipartBody(mw *multipart.Writer, req *Request) error {View on GitHub (pinned to a105acad6c)