{"record":{"id":"55c820003c9c22bb","repo":"gofiber/fiber","slug":"csrf-origin-header-invalid","errorCode":null,"errorMessage":"csrf: origin header invalid","messagePattern":"csrf: origin header invalid","errorType":"http","errorClass":null,"httpStatus":403,"severity":"warning","filePath":"middleware/csrf/csrf.go","lineNumber":30,"sourceCode":"\t\"github.com/gofiber/utils/v2\"\n\tutilsstrings \"github.com/gofiber/utils/v2/strings\"\n\n\t\"github.com/gofiber/fiber/v3\"\n\t\"github.com/gofiber/fiber/v3/extractors\"\n\t\"github.com/gofiber/fiber/v3/internal/headerlookup\"\n\t\"github.com/gofiber/fiber/v3/internal/redact\"\n\t\"github.com/gofiber/fiber/v3/internal/schemehost\"\n\t\"github.com/gofiber/fiber/v3/middleware/logger\"\n)\n\nvar (\n\tErrTokenNotFound    = errors.New(\"csrf: token not found\")\n\tErrTokenInvalid     = errors.New(\"csrf: token invalid\")\n\tErrFetchSiteInvalid = errors.New(\"csrf: sec-fetch-site header invalid\")\n\tErrRefererNotFound  = errors.New(\"csrf: referer header missing\")\n\tErrRefererInvalid   = errors.New(\"csrf: referer header invalid\")\n\tErrRefererNoMatch   = errors.New(\"csrf: referer does not match host or trusted origins\")\n\tErrOriginInvalid    = errors.New(\"csrf: origin header invalid\")\n\tErrOriginNoMatch    = errors.New(\"csrf: origin does not match host or trusted origins\")\n\terrOriginNotFound   = errors.New(\"origin not supplied or is null\") // internal error, will not be returned to the user\n\tdummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.\n\n)\n\nvar registerLogContextTagsOnce sync.Once\n\n// Handler for CSRF middleware\ntype Handler struct {\n\tsessionManager *sessionManager\n\tstorageManager *storageManager\n\tconfig         Config\n}\n\n// The contextKey type is unexported to prevent collisions with context keys defined in\n// other packages.\ntype contextKey int","sourceCodeStart":12,"sourceCodeEnd":48,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/csrf.go#L12-L48","documentation":"Returned by middleware/csrf.originMatchesHost when the Origin header is missing entirely, or is present but fails to parse as a URL. Origin is the primary trust signal for unsafe requests; a missing or syntactically broken Origin cannot be verified, so the request is rejected. Note: an Origin of \"null\" or empty is mapped to errOriginNotFound (internal) and falls through to the Referer fallback on HTTPS, not to this error.","triggerScenarios":"Any unsafe request whose Origin header is absent or unparseable. The missing-header case is the common one for non-browser clients; the parse-failure case indicates a crafted header with control characters or a bad scheme.","commonSituations":"Server-to-server API clients that omit Origin; a proxy stripping Origin; a bug injecting a malformed Origin; older clients that never set it.","solutions":["Have the client send a valid Origin header matching the app host or a TrustedOrigins entry.","Stop stripping the Origin header in front-line proxies for state-changing requests.","If the client genuinely has no origin (API token auth), exempt its route via cfg.Next or rely on keyauth/session instead of CSRF."],"exampleFix":"// before: cross-site POST with no Origin\n// after\nOrigin: https://app.example.com","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":"if errors.Is(err, csrf.ErrOriginInvalid) {\n    return c.Status(fiber.StatusForbidden).SendString(\"valid origin required\")\n}","preventionTips":["Send a syntactically valid Origin header on state-changing requests.","Do not strip Origin in front-line proxies.","For API-only clients, exempt the route via cfg.Next and use token auth instead."],"tags":["csrf","security","headers","origin"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}