{"record":{"id":"c9d5cfe7903ec02c","repo":"gofiber/fiber","slug":"csrf-sec-fetch-site-header-invalid","errorCode":null,"errorMessage":"csrf: sec-fetch-site header invalid","messagePattern":"csrf: sec-fetch-site header invalid","errorType":"http","errorClass":null,"httpStatus":403,"severity":"warning","filePath":"middleware/csrf/csrf.go","lineNumber":26,"sourceCode":"\t\"strings\"\n\t\"sync\"\n\t\"time\"\n\n\t\"github.com/gofiber/utils/v2\"\n\tutilsstrings \"github.com/gofiber/utils/v2/strings\"\n\n\t\"github.com/gofiber/fiber/v3\"\n\t\"github.com/gofiber/fiber/v3/extractors\"\n\t\"github.com/gofiber/fiber/v3/internal/headerlookup\"\n\t\"github.com/gofiber/fiber/v3/internal/redact\"\n\t\"github.com/gofiber/fiber/v3/internal/schemehost\"\n\t\"github.com/gofiber/fiber/v3/middleware/logger\"\n)\n\nvar (\n\tErrTokenNotFound    = errors.New(\"csrf: token not found\")\n\tErrTokenInvalid     = errors.New(\"csrf: token invalid\")\n\tErrFetchSiteInvalid = errors.New(\"csrf: sec-fetch-site header invalid\")\n\tErrRefererNotFound  = errors.New(\"csrf: referer header missing\")\n\tErrRefererInvalid   = errors.New(\"csrf: referer header invalid\")\n\tErrRefererNoMatch   = errors.New(\"csrf: referer does not match host or trusted origins\")\n\tErrOriginInvalid    = errors.New(\"csrf: origin header invalid\")\n\tErrOriginNoMatch    = errors.New(\"csrf: origin does not match host or trusted origins\")\n\terrOriginNotFound   = errors.New(\"origin not supplied or is null\") // internal error, will not be returned to the user\n\tdummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.\n\n)\n\nvar registerLogContextTagsOnce sync.Once\n\n// Handler for CSRF middleware\ntype Handler struct {\n\tsessionManager *sessionManager\n\tstorageManager *storageManager\n\tconfig         Config\n}","sourceCodeStart":8,"sourceCodeEnd":44,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/csrf/csrf.go#L8-L44","documentation":"Returned by middleware/csrf.validateSecFetchSite when the Sec-Fetch-Site header is present but malformed. The header either has multiple values (headerlookup reports it as present-but-duplicated) or holds a token other than the four Fetch-standard values (same-origin, same-site, cross-site, none). No real browser sends anything else, so the request is treated as crafted.","triggerScenarios":"A non-safe request with a Sec-Fetch-Site header set to an invalid token, or a Sec-Fetch-Site header duplicated in the request. Runs before origin/referer checks on every unsafe method.","commonSituations":"A non-browser client (curl, a proxy, a security scanner) setting Sec-Fetch-Site to a bogus value; a misconfigured reverse proxy appending a second Sec-Fetch-Site; a testing tool that sets the header to an empty-ish or custom string.","solutions":["If the client is a browser, do nothing: it always sends a valid token.","If the client is a known non-browser, stop sending Sec-Fetch-Site or set one of the four valid tokens.","Fix proxies that append/duplicate the header so only one valid value arrives.","Use cfg.Next to exempt a specific trusted path if a non-browser legitimately needs it."],"exampleFix":"// before: curl sets an invalid token\ncurl -H 'Sec-Fetch-Site: foo' -X POST ...\n// after: omit it or use a valid token\ncurl -H 'Sec-Fetch-Site: same-origin' -X POST ...","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":"if errors.Is(err, csrf.ErrFetchSiteInvalid) {\n    // non-browser client sent a bad Sec-Fetch-Site; reject or fix the client\n    return c.Status(fiber.StatusForbidden).SendString(\"invalid fetch metadata\")\n}","preventionTips":["Do not set Sec-Fetch-Site from non-browser clients; omit it instead.","Ensure proxies forward a single Sec-Fetch-Site value, not duplicates.","Use cfg.Next to exempt specific trusted non-browser endpoints."],"tags":["csrf","security","headers"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}