gofiber/fiber · warning

csrf: origin does not match host or trusted origins

Error message

csrf: origin does not match host or trusted origins

What it means

Returned by middleware/csrf.originMatchesHost when the Origin header is valid but its scheme+host does not match the request host and is not in TrustedOrigins or covered by a TrustedSubOrigin. This is the actual cross-origin rejection: the source origin is known but untrusted.

Solutions

  1. Add the legitimate external origin to Config.TrustedOrigins (include scheme, e.g. "https://partner.example.com").
  2. Use TrustedSubOrigins to allow a whole subdomain tree instead of enumerating each host.
  3. Make sure scheme matches (the comparison is scheme-aware); serve the app on the scheme the client declares.
  4. If the mismatch is unexpected, treat it as a possible CSRF attempt and log it for investigation.

Example fix

// before
csrf.New(csrf.Config{ /* TrustedOrigins empty */ })
// after
csrf.New(csrf.Config{
  TrustedOrigins:   []string{"https://app.example.com"},
  TrustedSubOrigins: []string{"https://*.example.com"},
})
Defensive patterns

Strategy: try-catch

Validate before calling

originAllowed := func(o string) bool {
    return slices.Contains(trustedOrigins, o) || matchSubdomain(trustedSubs, o)
}

Try / catch

if errors.Is(err, csrf.ErrOriginNoMatch) {
    return c.Status(fiber.StatusForbidden).SendString("origin not allowed")
}

Prevention

When it happens

Trigger: An unsafe request carrying an Origin that points at a different scheme/host than the target, where that origin was not registered as trusted.

Common situations: A legitimate partner frontend on a different domain that was not added to TrustedOrigins; scheme mismatch (http vs https) between Origin and the routed request; subdomain traffic not covered by TrustedSubOrigins; a real cross-site attack.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/7b9fcb19e5330ada. Report an issue: GitHub.

Appendix: source

Thrown at middleware/csrf/csrf.go:31

	utilsstrings "github.com/gofiber/utils/v2/strings"

	"github.com/gofiber/fiber/v3"
	"github.com/gofiber/fiber/v3/extractors"
	"github.com/gofiber/fiber/v3/internal/headerlookup"
	"github.com/gofiber/fiber/v3/internal/redact"
	"github.com/gofiber/fiber/v3/internal/schemehost"
	"github.com/gofiber/fiber/v3/middleware/logger"
)

var (
	ErrTokenNotFound    = errors.New("csrf: token not found")
	ErrTokenInvalid     = errors.New("csrf: token invalid")
	ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
	ErrRefererNotFound  = errors.New("csrf: referer header missing")
	ErrRefererInvalid   = errors.New("csrf: referer header invalid")
	ErrRefererNoMatch   = errors.New("csrf: referer does not match host or trusted origins")
	ErrOriginInvalid    = errors.New("csrf: origin header invalid")
	ErrOriginNoMatch    = errors.New("csrf: origin does not match host or trusted origins")
	errOriginNotFound   = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
	dummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.

)

var registerLogContextTagsOnce sync.Once

// Handler for CSRF middleware
type Handler struct {
	sessionManager *sessionManager
	storageManager *storageManager
	config         Config
}

// The contextKey type is unexported to prevent collisions with context keys defined in
// other packages.
type contextKey int

View on GitHub (pinned to a105acad6c)