Skip to content

fix(middleware): match WWW redirects case-insensitively - #3151

Open
lowgame wants to merge 1 commit into
labstack:masterfrom
lowgame:fix-www-redirect-case-4448a3cd
Open

lowgame wants to merge 1 commit into
labstack:masterfrom
lowgame:fix-www-redirect-case-4448a3cd

Conversation

@lowgame

@lowgame lowgame commented Oct 4, 2026

Copy link
Copy Markdown

Reproduction

The WWW redirect helpers compare the www. host label case-sensitively. Since DNS hostnames are case-insensitive, an HTTPS request for WWW.labstack.com is already on the WWW host, but HTTPSWWWRedirect currently redirects it to https://www.WWW.labstack.com/. Conversely, the non-WWW helpers fail to remove that uppercase label.

The added table cases reproduce this behavior for all four WWW/non-WWW redirect variants; all four fail against the unchanged implementation.

Root cause

The helpers use case-sensitive strings.HasPrefix and strings.TrimPrefix checks for the hostname label.

Solution

Recognize the bounded www. prefix with strings.EqualFold, and remove the matched four-byte label while preserving the rest of the original host.

Tests

  • Before the production fix: go test ./middleware -run 'TestRedirect(HTTPSWWW|HTTPSNonWWW|WWW|NonWWW)Redirect$' -count=1 — failed in all four new WWW.labstack.com cases.
  • After the fix: go test ./middleware -run 'TestRedirect(HTTPSWWW|HTTPSNonWWW|WWW|NonWWW)Redirect$' -count=1 — passed.
  • go test -race ./... -count=1 — passed (3 packages).
  • go vet ./... — passed.
  • make lint — passed (staticcheck and golint).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant