gofiber/fiber · warning

csrf: origin header invalid

Error message

csrf: origin header invalid

What it means

Returned by middleware/csrf.originMatchesHost when the Origin header is missing entirely, or is present but fails to parse as a URL. Origin is the primary trust signal for unsafe requests; a missing or syntactically broken Origin cannot be verified, so the request is rejected. Note: an Origin of "null" or empty is mapped to errOriginNotFound (internal) and falls through to the Referer fallback on HTTPS, not to this error.

Solutions

  1. Have the client send a valid Origin header matching the app host or a TrustedOrigins entry.
  2. Stop stripping the Origin header in front-line proxies for state-changing requests.
  3. If the client genuinely has no origin (API token auth), exempt its route via cfg.Next or rely on keyauth/session instead of CSRF.

Example fix

// before: cross-site POST with no Origin
// after
Origin: https://app.example.com
Defensive patterns

Strategy: validation

Try / catch

if errors.Is(err, csrf.ErrOriginInvalid) {
    return c.Status(fiber.StatusForbidden).SendString("valid origin required")
}

Prevention

When it happens

Trigger: Any unsafe request whose Origin header is absent or unparseable. The missing-header case is the common one for non-browser clients; the parse-failure case indicates a crafted header with control characters or a bad scheme.

Common situations: Server-to-server API clients that omit Origin; a proxy stripping Origin; a bug injecting a malformed Origin; older clients that never set it.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/55c820003c9c22bb. Report an issue: GitHub.

Appendix: source

Thrown at middleware/csrf/csrf.go:30

	"github.com/gofiber/utils/v2"
	utilsstrings "github.com/gofiber/utils/v2/strings"

	"github.com/gofiber/fiber/v3"
	"github.com/gofiber/fiber/v3/extractors"
	"github.com/gofiber/fiber/v3/internal/headerlookup"
	"github.com/gofiber/fiber/v3/internal/redact"
	"github.com/gofiber/fiber/v3/internal/schemehost"
	"github.com/gofiber/fiber/v3/middleware/logger"
)

var (
	ErrTokenNotFound    = errors.New("csrf: token not found")
	ErrTokenInvalid     = errors.New("csrf: token invalid")
	ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
	ErrRefererNotFound  = errors.New("csrf: referer header missing")
	ErrRefererInvalid   = errors.New("csrf: referer header invalid")
	ErrRefererNoMatch   = errors.New("csrf: referer does not match host or trusted origins")
	ErrOriginInvalid    = errors.New("csrf: origin header invalid")
	ErrOriginNoMatch    = errors.New("csrf: origin does not match host or trusted origins")
	errOriginNotFound   = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
	dummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.

)

var registerLogContextTagsOnce sync.Once

// Handler for CSRF middleware
type Handler struct {
	sessionManager *sessionManager
	storageManager *storageManager
	config         Config
}

// The contextKey type is unexported to prevent collisions with context keys defined in
// other packages.
type contextKey int

View on GitHub (pinned to a105acad6c)