gofiber/fiber · warning
csrf: referer header invalid
Error message
csrf: referer header invalid
What it means
Returned by middleware/csrf.refererMatchesHost when the Referer header is either absent (headerlookup reports not-ok) or fails to parse as a URL. It is the HTTPS fallback when Origin is missing; a malformed Referer cannot be trusted to identify the source origin, so the request is rejected. Note the absent-but-not-empty distinction: a missing header yields ErrRefererInvalid, while a present-but-empty one yields ErrRefererNotFound.
Solutions
- Send a syntactically valid, non-empty Referer from the client on state-changing requests.
- Stop stripping Referer in intermediaries for same-site requests.
- Add the trusted upstream origin to TrustedOrigins so the Origin path is used and Referer is not consulted.
Example fix
// before: no Referer, no Origin on HTTPS POST // after Referer: https://app.example.com/form Origin: https://app.example.com
Defensive patterns
Strategy: validation
Try / catch
if errors.Is(err, csrf.ErrRefererInvalid) {
// Referer absent or malformed on HTTPS with no Origin
return c.Status(fiber.StatusForbidden).SendString("valid referer required")
} Prevention
- Forward Referer through proxies for same-site requests.
- Send a syntactically valid Referer (or better, an Origin) on state-changing requests.
- Register trusted origins so the Origin path handles legitimate cross-site traffic.
When it happens
Trigger: An HTTPS unsafe request with no Origin and either no Referer header at all or a Referer that url.Parse rejects (control characters, malformed scheme).
Common situations: A client/scraper that omits Referer entirely; a proxy stripping Referer; a malformed Referer injected by a buggy intermediate; Referrer-Policy set to no-referrer combined with an absent Origin.
Related errors
- csrf: referer header missing
- csrf: origin header invalid
- csrf: referer does not match host or trusted origins
- csrf: sec-fetch-site header invalid
- CSRF: Chained extractor reads from the same cookie
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/595658bd924d6083.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/csrf/csrf.go:28
"time"
"github.com/gofiber/utils/v2"
utilsstrings "github.com/gofiber/utils/v2/strings"
"github.com/gofiber/fiber/v3"
"github.com/gofiber/fiber/v3/extractors"
"github.com/gofiber/fiber/v3/internal/headerlookup"
"github.com/gofiber/fiber/v3/internal/redact"
"github.com/gofiber/fiber/v3/internal/schemehost"
"github.com/gofiber/fiber/v3/middleware/logger"
)
var (
ErrTokenNotFound = errors.New("csrf: token not found")
ErrTokenInvalid = errors.New("csrf: token invalid")
ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
ErrRefererNotFound = errors.New("csrf: referer header missing")
ErrRefererInvalid = errors.New("csrf: referer header invalid")
ErrRefererNoMatch = errors.New("csrf: referer does not match host or trusted origins")
ErrOriginInvalid = errors.New("csrf: origin header invalid")
ErrOriginNoMatch = errors.New("csrf: origin does not match host or trusted origins")
errOriginNotFound = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
dummyValue = []byte{'+'} // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.
)
var registerLogContextTagsOnce sync.Once
// Handler for CSRF middleware
type Handler struct {
sessionManager *sessionManager
storageManager *storageManager
config Config
}
// The contextKey type is unexported to prevent collisions with context keys defined inView on GitHub (pinned to a105acad6c)