{"record":{"id":"864a0c78907e0fe6","repo":"gofiber/fiber","slug":"csrf-referer-does-not-match-host-or-trusted-origi","errorCode":null,"errorMessage":"csrf: referer does not match host or trusted origins","messagePattern":"csrf: referer does not match host or trusted origins","errorType":"http","errorClass":null,"httpStatus":403,"severity":"warning","filePath":"middleware/csrf/csrf.go","lineNumber":29,"sourceCode":"\n\t\"github.com/gofiber/utils/v2\"\n\tutilsstrings \"github.com/gofiber/utils/v2/strings\"\n\n\t\"github.com/gofiber/fiber/v3\"\n\t\"github.com/gofiber/fiber/v3/extractors\"\n\t\"github.com/gofiber/fiber/v3/internal/headerlookup\"\n\t\"github.com/gofiber/fiber/v3/internal/redact\"\n\t\"github.com/gofiber/fiber/v3/internal/schemehost\"\n\t\"github.com/gofiber/fiber/v3/middleware/logger\"\n)\n\nvar (\n\tErrTokenNotFound    = errors.New(\"csrf: token not found\")\n\tErrTokenInvalid     = errors.New(\"csrf: token invalid\")\n\tErrFetchSiteInvalid = errors.New(\"csrf: sec-fetch-site header invalid\")\n\tErrRefererNotFound  = errors.New(\"csrf: referer header missing\")\n\tErrRefererInvalid   = errors.New(\"csrf: referer header invalid\")\n\tErrRefererNoMatch   = errors.New(\"csrf: referer does not match host or trusted origins\")\n\tErrOriginInvalid    = errors.New(\"csrf: origin header invalid\")\n\tErrOriginNoMatch    = errors.New(\"csrf: origin does not match host or trusted origins\")\n\terrOriginNotFound   = errors.New(\"origin not supplied or is null\") // internal error, will not be returned to the user\n\tdummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.\n\n)\n\nvar registerLogContextTagsOnce sync.Once\n\n// Handler for CSRF middleware\ntype Handler struct {\n\tsessionManager *sessionManager\n\tstorageManager *storageManager\n\tconfig         Config\n}\n\n// The contextKey type is unexported to prevent collisions with context keys defined in\n// other packages.","sourceCodeStart":11,"sourceCodeEnd":47,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/csrf.go#L11-L47","documentation":"Returned by middleware/csrf.refererMatchesHost when the Referer is present and parseable but its scheme+host does not match the request host and is not in TrustedOrigins or a TrustedSubOrigin. It is the HTTPS fallback for requests lacking Origin; the referer's source authority is untrusted.","triggerScenarios":"An HTTPS unsafe request with no Origin whose Referer points at a different scheme/host than the target, and that origin was not registered as trusted.","commonSituations":"Cross-site form posts without an Origin header; a deployment behind a different external domain than the app expects; TrustedOrigins not updated after a domain migration; subdomain not covered by TrustedSubOrigins.","solutions":["Add the legitimate external origin to Config.TrustedOrigins.","Register covering subdomains via TrustedSubOrigins instead of listing each host.","Ensure the client's Origin header is sent so the primary origin check runs (and is matched against the same lists).","Verify scheme/host normalization: the comparison is scheme+host, case-insensitive on host."],"exampleFix":"// before\ncsrf.New(csrf.Config{ /* no TrustedOrigins */ })\n// after\ncsrf.New(csrf.Config{\n  TrustedOrigins: []string{\"https://partner.example.com\"},\n})","handlingStrategy":"try-catch","validationCode":"hostOK := func(origin string) bool {\n    u, err := url.Parse(origin)\n    return err == nil && slices.Contains(trusted, u.Scheme+\"://\"+u.Host)\n}","typeGuard":null,"tryCatchPattern":"if errors.Is(err, csrf.ErrRefererNoMatch) {\n    return c.Status(fiber.StatusForbidden).SendString(\"referer not allowed\")\n}","preventionTips":["Keep TrustedOrigins in sync with real external frontends.","Use TrustedSubOrigins for subdomain trees instead of enumerating hosts.","Prefer Origin-based validation; populate Origin from the client."],"tags":["csrf","security","referer","config"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}