hostguard

package
v0.0.26 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: MIT Imports: 2 Imported by: 0

README

Host Guard Middleware

What it does

Rejects requests with unexpected Host headers. This mitigates host-header attacks and accidental traffic for wrong domains.

How to implement

package main

import (
	"github.com/oarkflow/fh"
	"github.com/oarkflow/fh/mw/hostguard"
)

func main() {
	app := fh.New()
	app.Use(hostguard.New(hostguard.Config{Allowed: []string{"api.example.com"}}))

	app.Get("/", func(c fh.Ctx) error {
		return c.Status(fh.StatusOK).SendString("ok")
	})
}

Impact

Low overhead. Prevents cache poisoning, bad redirects, and routing confusion caused by forged Host headers.

Ordering guidance

Run very early, after trusted proxy normalization if Host is rewritten by infrastructure.

Production considerations

Configure every legitimate domain, including internal health-check names if used. Be careful with wildcard hosts.

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func New

func New(cfg Config) fh.HandlerFunc

Types

type Config

type Config struct {
	Allowed    []string
	Denied     []string
	AllowEmpty bool
	Reject     RejectHandler
}

type RejectHandler

type RejectHandler func(fh.Ctx, string) error

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL