csrf
CSRF protection filter that validates request origins against a trusted allowlist.
On this page
CSRF protection filter that validates request origins against a trusted allowlist.
Configuration Notes
Safe methods (GET, HEAD, OPTIONS by default) bypass the check. State-changing methods require an Origin or Referer header matching the trusted origins; rejected requests receive 403 Forbidden.
A bare wildcard ("*") cannot be mixed with other origins.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
enable_sec_fetch_site | bool | no | Whether to also validate the Sec-Fetch-Site header. |
enforce_percentage | integer | no | Percentage of requests to enforce (0..=100). |
safe_methods | string[] | no | HTTP methods that bypass CSRF checks. |
trusted_origins | string[] | yes | Allowed origin values (scheme + host + optional port). |
Example
filter: csrf
trusted_origins:
- "https://app.example.com"
- "https://*.example.com"
enforce_percentage: 100
enable_sec_fetch_site: true