gofiber/fiber · warning

csrf: token not found

Error message

csrf: token not found

What it means

Returned by middleware/csrf when no valid CSRF token can be found for an unsafe (state-changing) request. It fires in three spots: the configured Extractor returns extractors.ErrNotFound, the extracted token is the empty string, or the token is not present in storage (raw == nil) after extraction. The middleware also expires the cookie in the storage-miss case so the client rotates.

Solutions

  1. Ensure the client fetches the token (cookie or TokenFromContext on a prior GET) and resubmits it via the configured channel.
  2. Verify the Extractor config points at the header/form field your client actually sends.
  3. If SingleUseToken is enabled, fetch a fresh token after each mutation.
  4. Check that CookieName, SameSite, Secure, and Domain let the cookie reach the browser so a token exists to submit.

Example fix

// before: client sends mutation with no token
// after: fetch token on GET, echo it back
token := csrf.TokenFromContext(c.Context())
// send token in the header configured by csrf.Extractor
req.Header.Set("X-CSRF-Token", token)
Defensive patterns

Strategy: try-catch

Try / catch

if err := csrfHandler(c); err != nil {
    if errors.Is(err, csrf.ErrTokenNotFound) {
        return c.Status(fiber.StatusForbidden).SendString("csrf token required")
    }
    return err
}

Prevention

When it happens

Trigger: A POST/PUT/DELETE/PATCH request with no token in the configured source (header/query/param/form), a blank token value, or a token that was never stored or has expired from storage.

Common situations: Frontend forgot to send the CSRF token header; the cookie holding the token expired or was blocked by SameSite/Secure settings; the token was consumed by SingleUseToken=true on a prior request; misconfigured Extractor reading from the wrong field.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/7785a79e7c20f8de. Report an issue: GitHub.

Appendix: source

Thrown at middleware/csrf/csrf.go:24

	"net/url"
	"slices"
	"strings"
	"sync"
	"time"

	"github.com/gofiber/utils/v2"
	utilsstrings "github.com/gofiber/utils/v2/strings"

	"github.com/gofiber/fiber/v3"
	"github.com/gofiber/fiber/v3/extractors"
	"github.com/gofiber/fiber/v3/internal/headerlookup"
	"github.com/gofiber/fiber/v3/internal/redact"
	"github.com/gofiber/fiber/v3/internal/schemehost"
	"github.com/gofiber/fiber/v3/middleware/logger"
)

var (
	ErrTokenNotFound    = errors.New("csrf: token not found")
	ErrTokenInvalid     = errors.New("csrf: token invalid")
	ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
	ErrRefererNotFound  = errors.New("csrf: referer header missing")
	ErrRefererInvalid   = errors.New("csrf: referer header invalid")
	ErrRefererNoMatch   = errors.New("csrf: referer does not match host or trusted origins")
	ErrOriginInvalid    = errors.New("csrf: origin header invalid")
	ErrOriginNoMatch    = errors.New("csrf: origin does not match host or trusted origins")
	errOriginNotFound   = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
	dummyValue          = []byte{'+'}                                  // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.

)

var registerLogContextTagsOnce sync.Once

// Handler for CSRF middleware
type Handler struct {
	sessionManager *sessionManager
	storageManager *storageManager

View on GitHub (pinned to a105acad6c)