csrf

CSRF protection filter that validates request origins against a trusted allowlist.
On this page

CSRF protection filter that validates request origins against a trusted allowlist.

Configuration Notes

Safe methods (GET, HEAD, OPTIONS by default) bypass the check. State-changing methods require an Origin or Referer header matching the trusted origins; rejected requests receive 403 Forbidden.

A bare wildcard ("*") cannot be mixed with other origins.

Configuration

FieldTypeRequiredDescription
enable_sec_fetch_siteboolnoWhether to also validate the Sec-Fetch-Site header.
enforce_percentageintegernoPercentage of requests to enforce (0..=100).
safe_methodsstring[]noHTTP methods that bypass CSRF checks.
trusted_originsstring[]yesAllowed origin values (scheme + host + optional port).

Example

filter: csrf
trusted_origins:
  - "https://app.example.com"
  - "https://*.example.com"
enforce_percentage: 100
enable_sec_fetch_site: true