gofiber/fiber · warning

csrf: referer header missing

Error message

csrf: referer header missing

What it means

Returned by middleware/csrf.refererMatchesHost when the Referer header is present but empty. It is the HTTPS fallback path: when an unsafe request has no Origin, CSRF validates Referer instead, and an empty-but-present Referer is treated as missing rather than invalid. This fires only for HTTPS requests without an Origin header.

Solutions

  1. Ensure the client sends a non-empty, valid Referer on cross-origin state changes when Origin is absent.
  2. Relax an over-aggressive Referrer-Policy (e.g. no-referrer) for same-site navigations that perform mutations.
  3. Add the legitimate origin to TrustedOrigins so the origin check succeeds and the referer fallback is not reached.

Example fix

// before: client sends empty Referer, no Origin
Referer:
// after: send a real Referer matching the host
Referer: https://app.example.com/dashboard
Defensive patterns

Strategy: validation

Try / catch

if errors.Is(err, csrf.ErrRefererNotFound) {
    // empty Referer on HTTPS with no Origin: reject and ask client to send a real Referer
    return c.Status(fiber.StatusForbidden).SendString("referer required")
}

Prevention

When it happens

Trigger: An HTTPS POST/PUT/etc. that carries no Origin header and whose Referer header is the empty string. Browsers normally send a non-empty Referer, so this typically indicates a privacy-stripped or crafted request.

Common situations: A browser with strict Referrer-Policy that strips the value but keeps the header; a non-browser client sending an empty Referer; a proxy that blanks Referer for privacy.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/752303f73a6ed116. Report an issue: GitHub.

Appendix: source

Thrown at middleware/csrf/csrf.go:27

	"sync"
	"time"

	"github.com/gofiber/utils/v2"
	utilsstrings "github.com/gofiber/utils/v2/strings"

	"github.com/gofiber/fiber/v3"
	"github.com/gofiber/fiber/v3/extractors"
	"github.com/gofiber/fiber/v3/internal/headerlookup"
	"github.com/gofiber/fiber/v3/internal/redact"
	"github.com/gofiber/fiber/v3/internal/schemehost"
	"github.com/gofiber/fiber/v3/middleware/logger"
)

var (
	ErrTokenNotFound    = errors.New("csrf: token not found")
	ErrTokenInvalid     = errors.New("csrf: token invalid")
	ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
	ErrRefererNotFound  = errors.New("csrf: referer header missing")
	ErrRefererInvalid   = errors.New("csrf: referer header invalid")
	ErrRefererNoMatch   = errors.New("csrf: referer does not match host or trusted origins")
	ErrOriginInvalid    = errors.New("csrf: origin header invalid")
	ErrOriginNoMatch    = errors.New("csrf: origin does not match host or trusted origins")
	errOriginNotFound   = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
	dummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.

)

var registerLogContextTagsOnce sync.Once

// Handler for CSRF middleware
type Handler struct {
	sessionManager *sessionManager
	storageManager *storageManager
	config         Config
}

View on GitHub (pinned to a105acad6c)