gofiber/fiber · warning
csrf: origin does not match host or trusted origins
Error message
csrf: origin does not match host or trusted origins
What it means
Returned by middleware/csrf.originMatchesHost when the Origin header is valid but its scheme+host does not match the request host and is not in TrustedOrigins or covered by a TrustedSubOrigin. This is the actual cross-origin rejection: the source origin is known but untrusted.
Solutions
- Add the legitimate external origin to Config.TrustedOrigins (include scheme, e.g. "https://partner.example.com").
- Use TrustedSubOrigins to allow a whole subdomain tree instead of enumerating each host.
- Make sure scheme matches (the comparison is scheme-aware); serve the app on the scheme the client declares.
- If the mismatch is unexpected, treat it as a possible CSRF attempt and log it for investigation.
Example fix
// before
csrf.New(csrf.Config{ /* TrustedOrigins empty */ })
// after
csrf.New(csrf.Config{
TrustedOrigins: []string{"https://app.example.com"},
TrustedSubOrigins: []string{"https://*.example.com"},
}) Defensive patterns
Strategy: try-catch
Validate before calling
originAllowed := func(o string) bool {
return slices.Contains(trustedOrigins, o) || matchSubdomain(trustedSubs, o)
} Try / catch
if errors.Is(err, csrf.ErrOriginNoMatch) {
return c.Status(fiber.StatusForbidden).SendString("origin not allowed")
} Prevention
- Register every legitimate external origin (with scheme) in TrustedOrigins.
- Keep scheme consistent between Origin and the routed request.
- Log unexpected origin mismatches; they may indicate a real CSRF attempt.
When it happens
Trigger: An unsafe request carrying an Origin that points at a different scheme/host than the target, where that origin was not registered as trusted.
Common situations: A legitimate partner frontend on a different domain that was not added to TrustedOrigins; scheme mismatch (http vs https) between Origin and the routed request; subdomain traffic not covered by TrustedSubOrigins; a real cross-site attack.
Related errors
- [CSRF] Invalid origin format in configuration:
- csrf: origin header invalid
- csrf: referer does not match host or trusted origins
- [CORS] Invalid origin format in configuration:
- CSRF: Chained extractor reads from the same cookie
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/7b9fcb19e5330ada.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/csrf/csrf.go:31
utilsstrings "github.com/gofiber/utils/v2/strings"
"github.com/gofiber/fiber/v3"
"github.com/gofiber/fiber/v3/extractors"
"github.com/gofiber/fiber/v3/internal/headerlookup"
"github.com/gofiber/fiber/v3/internal/redact"
"github.com/gofiber/fiber/v3/internal/schemehost"
"github.com/gofiber/fiber/v3/middleware/logger"
)
var (
ErrTokenNotFound = errors.New("csrf: token not found")
ErrTokenInvalid = errors.New("csrf: token invalid")
ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
ErrRefererNotFound = errors.New("csrf: referer header missing")
ErrRefererInvalid = errors.New("csrf: referer header invalid")
ErrRefererNoMatch = errors.New("csrf: referer does not match host or trusted origins")
ErrOriginInvalid = errors.New("csrf: origin header invalid")
ErrOriginNoMatch = errors.New("csrf: origin does not match host or trusted origins")
errOriginNotFound = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
dummyValue = []byte{'+'} // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.
)
var registerLogContextTagsOnce sync.Once
// Handler for CSRF middleware
type Handler struct {
sessionManager *sessionManager
storageManager *storageManager
config Config
}
// The contextKey type is unexported to prevent collisions with context keys defined in
// other packages.
type contextKey int
View on GitHub (pinned to a105acad6c)