{"record":{"id":"7b9fcb19e5330ada","repo":"gofiber/fiber","slug":"csrf-origin-does-not-match-host-or-trusted-origin","errorCode":null,"errorMessage":"csrf: origin does not match host or trusted origins","messagePattern":"csrf: origin does not match host or trusted origins","errorType":"http","errorClass":null,"httpStatus":403,"severity":"warning","filePath":"middleware/csrf/csrf.go","lineNumber":31,"sourceCode":"\tutilsstrings \"github.com/gofiber/utils/v2/strings\"\n\n\t\"github.com/gofiber/fiber/v3\"\n\t\"github.com/gofiber/fiber/v3/extractors\"\n\t\"github.com/gofiber/fiber/v3/internal/headerlookup\"\n\t\"github.com/gofiber/fiber/v3/internal/redact\"\n\t\"github.com/gofiber/fiber/v3/internal/schemehost\"\n\t\"github.com/gofiber/fiber/v3/middleware/logger\"\n)\n\nvar (\n\tErrTokenNotFound    = errors.New(\"csrf: token not found\")\n\tErrTokenInvalid     = errors.New(\"csrf: token invalid\")\n\tErrFetchSiteInvalid = errors.New(\"csrf: sec-fetch-site header invalid\")\n\tErrRefererNotFound  = errors.New(\"csrf: referer header missing\")\n\tErrRefererInvalid   = errors.New(\"csrf: referer header invalid\")\n\tErrRefererNoMatch   = errors.New(\"csrf: referer does not match host or trusted origins\")\n\tErrOriginInvalid    = errors.New(\"csrf: origin header invalid\")\n\tErrOriginNoMatch    = errors.New(\"csrf: origin does not match host or trusted origins\")\n\terrOriginNotFound   = errors.New(\"origin not supplied or is null\") // internal error, will not be returned to the user\n\tdummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.\n\n)\n\nvar registerLogContextTagsOnce sync.Once\n\n// Handler for CSRF middleware\ntype Handler struct {\n\tsessionManager *sessionManager\n\tstorageManager *storageManager\n\tconfig         Config\n}\n\n// The contextKey type is unexported to prevent collisions with context keys defined in\n// other packages.\ntype contextKey int\n","sourceCodeStart":13,"sourceCodeEnd":49,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/csrf.go#L13-L49","documentation":"Returned by middleware/csrf.originMatchesHost when the Origin header is valid but its scheme+host does not match the request host and is not in TrustedOrigins or covered by a TrustedSubOrigin. This is the actual cross-origin rejection: the source origin is known but untrusted.","triggerScenarios":"An unsafe request carrying an Origin that points at a different scheme/host than the target, where that origin was not registered as trusted.","commonSituations":"A legitimate partner frontend on a different domain that was not added to TrustedOrigins; scheme mismatch (http vs https) between Origin and the routed request; subdomain traffic not covered by TrustedSubOrigins; a real cross-site attack.","solutions":["Add the legitimate external origin to Config.TrustedOrigins (include scheme, e.g. \"https://partner.example.com\").","Use TrustedSubOrigins to allow a whole subdomain tree instead of enumerating each host.","Make sure scheme matches (the comparison is scheme-aware); serve the app on the scheme the client declares.","If the mismatch is unexpected, treat it as a possible CSRF attempt and log it for investigation."],"exampleFix":"// before\ncsrf.New(csrf.Config{ /* TrustedOrigins empty */ })\n// after\ncsrf.New(csrf.Config{\n  TrustedOrigins:   []string{\"https://app.example.com\"},\n  TrustedSubOrigins: []string{\"https://*.example.com\"},\n})","handlingStrategy":"try-catch","validationCode":"originAllowed := func(o string) bool {\n    return slices.Contains(trustedOrigins, o) || matchSubdomain(trustedSubs, o)\n}","typeGuard":null,"tryCatchPattern":"if errors.Is(err, csrf.ErrOriginNoMatch) {\n    return c.Status(fiber.StatusForbidden).SendString(\"origin not allowed\")\n}","preventionTips":["Register every legitimate external origin (with scheme) in TrustedOrigins.","Keep scheme consistent between Origin and the routed request.","Log unexpected origin mismatches; they may indicate a real CSRF attempt."],"tags":["csrf","security","origin","config"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}