{"record":{"id":"595658bd924d6083","repo":"gofiber/fiber","slug":"csrf-referer-header-invalid","errorCode":null,"errorMessage":"csrf: referer header invalid","messagePattern":"csrf: referer header invalid","errorType":"http","errorClass":null,"httpStatus":403,"severity":"warning","filePath":"middleware/csrf/csrf.go","lineNumber":28,"sourceCode":"\t\"time\"\n\n\t\"github.com/gofiber/utils/v2\"\n\tutilsstrings \"github.com/gofiber/utils/v2/strings\"\n\n\t\"github.com/gofiber/fiber/v3\"\n\t\"github.com/gofiber/fiber/v3/extractors\"\n\t\"github.com/gofiber/fiber/v3/internal/headerlookup\"\n\t\"github.com/gofiber/fiber/v3/internal/redact\"\n\t\"github.com/gofiber/fiber/v3/internal/schemehost\"\n\t\"github.com/gofiber/fiber/v3/middleware/logger\"\n)\n\nvar (\n\tErrTokenNotFound    = errors.New(\"csrf: token not found\")\n\tErrTokenInvalid     = errors.New(\"csrf: token invalid\")\n\tErrFetchSiteInvalid = errors.New(\"csrf: sec-fetch-site header invalid\")\n\tErrRefererNotFound  = errors.New(\"csrf: referer header missing\")\n\tErrRefererInvalid   = errors.New(\"csrf: referer header invalid\")\n\tErrRefererNoMatch   = errors.New(\"csrf: referer does not match host or trusted origins\")\n\tErrOriginInvalid    = errors.New(\"csrf: origin header invalid\")\n\tErrOriginNoMatch    = errors.New(\"csrf: origin does not match host or trusted origins\")\n\terrOriginNotFound   = errors.New(\"origin not supplied or is null\") // internal error, will not be returned to the user\n\tdummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.\n\n)\n\nvar registerLogContextTagsOnce sync.Once\n\n// Handler for CSRF middleware\ntype Handler struct {\n\tsessionManager *sessionManager\n\tstorageManager *storageManager\n\tconfig         Config\n}\n\n// The contextKey type is unexported to prevent collisions with context keys defined in","sourceCodeStart":10,"sourceCodeEnd":46,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/csrf.go#L10-L46","documentation":"Returned by middleware/csrf.refererMatchesHost when the Referer header is either absent (headerlookup reports not-ok) or fails to parse as a URL. It is the HTTPS fallback when Origin is missing; a malformed Referer cannot be trusted to identify the source origin, so the request is rejected. Note the absent-but-not-empty distinction: a missing header yields ErrRefererInvalid, while a present-but-empty one yields ErrRefererNotFound.","triggerScenarios":"An HTTPS unsafe request with no Origin and either no Referer header at all or a Referer that url.Parse rejects (control characters, malformed scheme).","commonSituations":"A client/scraper that omits Referer entirely; a proxy stripping Referer; a malformed Referer injected by a buggy intermediate; Referrer-Policy set to no-referrer combined with an absent Origin.","solutions":["Send a syntactically valid, non-empty Referer from the client on state-changing requests.","Stop stripping Referer in intermediaries for same-site requests.","Add the trusted upstream origin to TrustedOrigins so the Origin path is used and Referer is not consulted."],"exampleFix":"// before: no Referer, no Origin on HTTPS POST\n// after\nReferer: https://app.example.com/form\nOrigin: https://app.example.com","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":"if errors.Is(err, csrf.ErrRefererInvalid) {\n    // Referer absent or malformed on HTTPS with no Origin\n    return c.Status(fiber.StatusForbidden).SendString(\"valid referer required\")\n}","preventionTips":["Forward Referer through proxies for same-site requests.","Send a syntactically valid Referer (or better, an Origin) on state-changing requests.","Register trusted origins so the Origin path handles legitimate cross-site traffic."],"tags":["csrf","security","headers","referer"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}