gofiber/fiber · warning

csrf: referer does not match host or trusted origins

Error message

csrf: referer does not match host or trusted origins

What it means

Returned by middleware/csrf.refererMatchesHost when the Referer is present and parseable but its scheme+host does not match the request host and is not in TrustedOrigins or a TrustedSubOrigin. It is the HTTPS fallback for requests lacking Origin; the referer's source authority is untrusted.

Solutions

  1. Add the legitimate external origin to Config.TrustedOrigins.
  2. Register covering subdomains via TrustedSubOrigins instead of listing each host.
  3. Ensure the client's Origin header is sent so the primary origin check runs (and is matched against the same lists).
  4. Verify scheme/host normalization: the comparison is scheme+host, case-insensitive on host.

Example fix

// before
csrf.New(csrf.Config{ /* no TrustedOrigins */ })
// after
csrf.New(csrf.Config{
  TrustedOrigins: []string{"https://partner.example.com"},
})
Defensive patterns

Strategy: try-catch

Validate before calling

hostOK := func(origin string) bool {
    u, err := url.Parse(origin)
    return err == nil && slices.Contains(trusted, u.Scheme+"://"+u.Host)
}

Try / catch

if errors.Is(err, csrf.ErrRefererNoMatch) {
    return c.Status(fiber.StatusForbidden).SendString("referer not allowed")
}

Prevention

When it happens

Trigger: An HTTPS unsafe request with no Origin whose Referer points at a different scheme/host than the target, and that origin was not registered as trusted.

Common situations: Cross-site form posts without an Origin header; a deployment behind a different external domain than the app expects; TrustedOrigins not updated after a domain migration; subdomain not covered by TrustedSubOrigins.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/864a0c78907e0fe6. Report an issue: GitHub.

Appendix: source

Thrown at middleware/csrf/csrf.go:29

	"github.com/gofiber/utils/v2"
	utilsstrings "github.com/gofiber/utils/v2/strings"

	"github.com/gofiber/fiber/v3"
	"github.com/gofiber/fiber/v3/extractors"
	"github.com/gofiber/fiber/v3/internal/headerlookup"
	"github.com/gofiber/fiber/v3/internal/redact"
	"github.com/gofiber/fiber/v3/internal/schemehost"
	"github.com/gofiber/fiber/v3/middleware/logger"
)

var (
	ErrTokenNotFound    = errors.New("csrf: token not found")
	ErrTokenInvalid     = errors.New("csrf: token invalid")
	ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
	ErrRefererNotFound  = errors.New("csrf: referer header missing")
	ErrRefererInvalid   = errors.New("csrf: referer header invalid")
	ErrRefererNoMatch   = errors.New("csrf: referer does not match host or trusted origins")
	ErrOriginInvalid    = errors.New("csrf: origin header invalid")
	ErrOriginNoMatch    = errors.New("csrf: origin does not match host or trusted origins")
	errOriginNotFound   = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
	dummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.

)

var registerLogContextTagsOnce sync.Once

// Handler for CSRF middleware
type Handler struct {
	sessionManager *sessionManager
	storageManager *storageManager
	config         Config
}

// The contextKey type is unexported to prevent collisions with context keys defined in
// other packages.

View on GitHub (pinned to a105acad6c)