gofiber/fiber · warning
csrf: referer does not match host or trusted origins
Error message
csrf: referer does not match host or trusted origins
What it means
Returned by middleware/csrf.refererMatchesHost when the Referer is present and parseable but its scheme+host does not match the request host and is not in TrustedOrigins or a TrustedSubOrigin. It is the HTTPS fallback for requests lacking Origin; the referer's source authority is untrusted.
Solutions
- Add the legitimate external origin to Config.TrustedOrigins.
- Register covering subdomains via TrustedSubOrigins instead of listing each host.
- Ensure the client's Origin header is sent so the primary origin check runs (and is matched against the same lists).
- Verify scheme/host normalization: the comparison is scheme+host, case-insensitive on host.
Example fix
// before
csrf.New(csrf.Config{ /* no TrustedOrigins */ })
// after
csrf.New(csrf.Config{
TrustedOrigins: []string{"https://partner.example.com"},
}) Defensive patterns
Strategy: try-catch
Validate before calling
hostOK := func(origin string) bool {
u, err := url.Parse(origin)
return err == nil && slices.Contains(trusted, u.Scheme+"://"+u.Host)
} Try / catch
if errors.Is(err, csrf.ErrRefererNoMatch) {
return c.Status(fiber.StatusForbidden).SendString("referer not allowed")
} Prevention
- Keep TrustedOrigins in sync with real external frontends.
- Use TrustedSubOrigins for subdomain trees instead of enumerating hosts.
- Prefer Origin-based validation; populate Origin from the client.
When it happens
Trigger: An HTTPS unsafe request with no Origin whose Referer points at a different scheme/host than the target, and that origin was not registered as trusted.
Common situations: Cross-site form posts without an Origin header; a deployment behind a different external domain than the app expects; TrustedOrigins not updated after a domain migration; subdomain not covered by TrustedSubOrigins.
Related errors
- [CSRF] Invalid origin format in configuration:
- csrf: origin does not match host or trusted origins
- csrf: referer header invalid
- csrf: referer header missing
- [CORS] Invalid origin format in configuration:
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/864a0c78907e0fe6.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/csrf/csrf.go:29
"github.com/gofiber/utils/v2"
utilsstrings "github.com/gofiber/utils/v2/strings"
"github.com/gofiber/fiber/v3"
"github.com/gofiber/fiber/v3/extractors"
"github.com/gofiber/fiber/v3/internal/headerlookup"
"github.com/gofiber/fiber/v3/internal/redact"
"github.com/gofiber/fiber/v3/internal/schemehost"
"github.com/gofiber/fiber/v3/middleware/logger"
)
var (
ErrTokenNotFound = errors.New("csrf: token not found")
ErrTokenInvalid = errors.New("csrf: token invalid")
ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
ErrRefererNotFound = errors.New("csrf: referer header missing")
ErrRefererInvalid = errors.New("csrf: referer header invalid")
ErrRefererNoMatch = errors.New("csrf: referer does not match host or trusted origins")
ErrOriginInvalid = errors.New("csrf: origin header invalid")
ErrOriginNoMatch = errors.New("csrf: origin does not match host or trusted origins")
errOriginNotFound = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
dummyValue = []byte{'+'} // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.
)
var registerLogContextTagsOnce sync.Once
// Handler for CSRF middleware
type Handler struct {
sessionManager *sessionManager
storageManager *storageManager
config Config
}
// The contextKey type is unexported to prevent collisions with context keys defined in
// other packages.View on GitHub (pinned to a105acad6c)