gofiber/fiber · warning

csrf: referer header invalid

Error message

csrf: referer header invalid

What it means

Returned by middleware/csrf.refererMatchesHost when the Referer header is either absent (headerlookup reports not-ok) or fails to parse as a URL. It is the HTTPS fallback when Origin is missing; a malformed Referer cannot be trusted to identify the source origin, so the request is rejected. Note the absent-but-not-empty distinction: a missing header yields ErrRefererInvalid, while a present-but-empty one yields ErrRefererNotFound.

Solutions

  1. Send a syntactically valid, non-empty Referer from the client on state-changing requests.
  2. Stop stripping Referer in intermediaries for same-site requests.
  3. Add the trusted upstream origin to TrustedOrigins so the Origin path is used and Referer is not consulted.

Example fix

// before: no Referer, no Origin on HTTPS POST
// after
Referer: https://app.example.com/form
Origin: https://app.example.com
Defensive patterns

Strategy: validation

Try / catch

if errors.Is(err, csrf.ErrRefererInvalid) {
    // Referer absent or malformed on HTTPS with no Origin
    return c.Status(fiber.StatusForbidden).SendString("valid referer required")
}

Prevention

When it happens

Trigger: An HTTPS unsafe request with no Origin and either no Referer header at all or a Referer that url.Parse rejects (control characters, malformed scheme).

Common situations: A client/scraper that omits Referer entirely; a proxy stripping Referer; a malformed Referer injected by a buggy intermediate; Referrer-Policy set to no-referrer combined with an absent Origin.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/595658bd924d6083. Report an issue: GitHub.

Appendix: source

Thrown at middleware/csrf/csrf.go:28

	"time"

	"github.com/gofiber/utils/v2"
	utilsstrings "github.com/gofiber/utils/v2/strings"

	"github.com/gofiber/fiber/v3"
	"github.com/gofiber/fiber/v3/extractors"
	"github.com/gofiber/fiber/v3/internal/headerlookup"
	"github.com/gofiber/fiber/v3/internal/redact"
	"github.com/gofiber/fiber/v3/internal/schemehost"
	"github.com/gofiber/fiber/v3/middleware/logger"
)

var (
	ErrTokenNotFound    = errors.New("csrf: token not found")
	ErrTokenInvalid     = errors.New("csrf: token invalid")
	ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
	ErrRefererNotFound  = errors.New("csrf: referer header missing")
	ErrRefererInvalid   = errors.New("csrf: referer header invalid")
	ErrRefererNoMatch   = errors.New("csrf: referer does not match host or trusted origins")
	ErrOriginInvalid    = errors.New("csrf: origin header invalid")
	ErrOriginNoMatch    = errors.New("csrf: origin does not match host or trusted origins")
	errOriginNotFound   = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
	dummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.

)

var registerLogContextTagsOnce sync.Once

// Handler for CSRF middleware
type Handler struct {
	sessionManager *sessionManager
	storageManager *storageManager
	config         Config
}

// The contextKey type is unexported to prevent collisions with context keys defined in

View on GitHub (pinned to a105acad6c)