{"record":{"id":"752303f73a6ed116","repo":"gofiber/fiber","slug":"csrf-referer-header-missing","errorCode":null,"errorMessage":"csrf: referer header missing","messagePattern":"csrf: referer header missing","errorType":"http","errorClass":null,"httpStatus":403,"severity":"warning","filePath":"middleware/csrf/csrf.go","lineNumber":27,"sourceCode":"\t\"sync\"\n\t\"time\"\n\n\t\"github.com/gofiber/utils/v2\"\n\tutilsstrings \"github.com/gofiber/utils/v2/strings\"\n\n\t\"github.com/gofiber/fiber/v3\"\n\t\"github.com/gofiber/fiber/v3/extractors\"\n\t\"github.com/gofiber/fiber/v3/internal/headerlookup\"\n\t\"github.com/gofiber/fiber/v3/internal/redact\"\n\t\"github.com/gofiber/fiber/v3/internal/schemehost\"\n\t\"github.com/gofiber/fiber/v3/middleware/logger\"\n)\n\nvar (\n\tErrTokenNotFound    = errors.New(\"csrf: token not found\")\n\tErrTokenInvalid     = errors.New(\"csrf: token invalid\")\n\tErrFetchSiteInvalid = errors.New(\"csrf: sec-fetch-site header invalid\")\n\tErrRefererNotFound  = errors.New(\"csrf: referer header missing\")\n\tErrRefererInvalid   = errors.New(\"csrf: referer header invalid\")\n\tErrRefererNoMatch   = errors.New(\"csrf: referer does not match host or trusted origins\")\n\tErrOriginInvalid    = errors.New(\"csrf: origin header invalid\")\n\tErrOriginNoMatch    = errors.New(\"csrf: origin does not match host or trusted origins\")\n\terrOriginNotFound   = errors.New(\"origin not supplied or is null\") // internal error, will not be returned to the user\n\tdummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.\n\n)\n\nvar registerLogContextTagsOnce sync.Once\n\n// Handler for CSRF middleware\ntype Handler struct {\n\tsessionManager *sessionManager\n\tstorageManager *storageManager\n\tconfig         Config\n}\n","sourceCodeStart":9,"sourceCodeEnd":45,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/csrf.go#L9-L45","documentation":"Returned by middleware/csrf.refererMatchesHost when the Referer header is present but empty. It is the HTTPS fallback path: when an unsafe request has no Origin, CSRF validates Referer instead, and an empty-but-present Referer is treated as missing rather than invalid. This fires only for HTTPS requests without an Origin header.","triggerScenarios":"An HTTPS POST/PUT/etc. that carries no Origin header and whose Referer header is the empty string. Browsers normally send a non-empty Referer, so this typically indicates a privacy-stripped or crafted request.","commonSituations":"A browser with strict Referrer-Policy that strips the value but keeps the header; a non-browser client sending an empty Referer; a proxy that blanks Referer for privacy.","solutions":["Ensure the client sends a non-empty, valid Referer on cross-origin state changes when Origin is absent.","Relax an over-aggressive Referrer-Policy (e.g. no-referrer) for same-site navigations that perform mutations.","Add the legitimate origin to TrustedOrigins so the origin check succeeds and the referer fallback is not reached."],"exampleFix":"// before: client sends empty Referer, no Origin\nReferer:\n// after: send a real Referer matching the host\nReferer: https://app.example.com/dashboard","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":"if errors.Is(err, csrf.ErrRefererNotFound) {\n    // empty Referer on HTTPS with no Origin: reject and ask client to send a real Referer\n    return c.Status(fiber.StatusForbidden).SendString(\"referer required\")\n}","preventionTips":["Send a non-empty Referer on cross-origin state changes.","Relax blanket no-referrer policies for same-site navigations that mutate state.","Prefer sending an Origin header so the primary check is used."],"tags":["csrf","security","headers","referer"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}