{"record":{"id":"7785a79e7c20f8de","repo":"gofiber/fiber","slug":"csrf-token-not-found","errorCode":null,"errorMessage":"csrf: token not found","messagePattern":"csrf: token not found","errorType":"http","errorClass":null,"httpStatus":403,"severity":"warning","filePath":"middleware/csrf/csrf.go","lineNumber":24,"sourceCode":"\t\"net/url\"\n\t\"slices\"\n\t\"strings\"\n\t\"sync\"\n\t\"time\"\n\n\t\"github.com/gofiber/utils/v2\"\n\tutilsstrings \"github.com/gofiber/utils/v2/strings\"\n\n\t\"github.com/gofiber/fiber/v3\"\n\t\"github.com/gofiber/fiber/v3/extractors\"\n\t\"github.com/gofiber/fiber/v3/internal/headerlookup\"\n\t\"github.com/gofiber/fiber/v3/internal/redact\"\n\t\"github.com/gofiber/fiber/v3/internal/schemehost\"\n\t\"github.com/gofiber/fiber/v3/middleware/logger\"\n)\n\nvar (\n\tErrTokenNotFound    = errors.New(\"csrf: token not found\")\n\tErrTokenInvalid     = errors.New(\"csrf: token invalid\")\n\tErrFetchSiteInvalid = errors.New(\"csrf: sec-fetch-site header invalid\")\n\tErrRefererNotFound  = errors.New(\"csrf: referer header missing\")\n\tErrRefererInvalid   = errors.New(\"csrf: referer header invalid\")\n\tErrRefererNoMatch   = errors.New(\"csrf: referer does not match host or trusted origins\")\n\tErrOriginInvalid    = errors.New(\"csrf: origin header invalid\")\n\tErrOriginNoMatch    = errors.New(\"csrf: origin does not match host or trusted origins\")\n\terrOriginNotFound   = errors.New(\"origin not supplied or is null\") // internal error, will not be returned to the user\n\tdummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.\n\n)\n\nvar registerLogContextTagsOnce sync.Once\n\n// Handler for CSRF middleware\ntype Handler struct {\n\tsessionManager *sessionManager\n\tstorageManager *storageManager","sourceCodeStart":6,"sourceCodeEnd":42,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/csrf.go#L6-L42","documentation":"Returned by middleware/csrf when no valid CSRF token can be found for an unsafe (state-changing) request. It fires in three spots: the configured Extractor returns extractors.ErrNotFound, the extracted token is the empty string, or the token is not present in storage (raw == nil) after extraction. The middleware also expires the cookie in the storage-miss case so the client rotates.","triggerScenarios":"A POST/PUT/DELETE/PATCH request with no token in the configured source (header/query/param/form), a blank token value, or a token that was never stored or has expired from storage.","commonSituations":"Frontend forgot to send the CSRF token header; the cookie holding the token expired or was blocked by SameSite/Secure settings; the token was consumed by SingleUseToken=true on a prior request; misconfigured Extractor reading from the wrong field.","solutions":["Ensure the client fetches the token (cookie or TokenFromContext on a prior GET) and resubmits it via the configured channel.","Verify the Extractor config points at the header/form field your client actually sends.","If SingleUseToken is enabled, fetch a fresh token after each mutation.","Check that CookieName, SameSite, Secure, and Domain let the cookie reach the browser so a token exists to submit."],"exampleFix":"// before: client sends mutation with no token\n// after: fetch token on GET, echo it back\ntoken := csrf.TokenFromContext(c.Context())\n// send token in the header configured by csrf.Extractor\nreq.Header.Set(\"X-CSRF-Token\", token)","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"if err := csrfHandler(c); err != nil {\n    if errors.Is(err, csrf.ErrTokenNotFound) {\n        return c.Status(fiber.StatusForbidden).SendString(\"csrf token required\")\n    }\n    return err\n}","preventionTips":["Fetch a token on a GET before any mutation.","Keep CookieName/SameSite/Secure aligned so the cookie actually reaches the browser.","If SingleUseToken is on, refresh the token after every successful mutation.","Make sure the Extractor reads from a field the client populates."],"tags":["csrf","security","auth"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}