fetchmetadata

package
v0.0.26 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: MIT Imports: 2 Imported by: 0

README

fetchmetadata middleware

Enforces browser Fetch Metadata headers as defense in depth against CSRF, XSSI and cross-site leaks.

app.Use(fetchmetadata.New(fetchmetadata.Config{
    AllowTopLevelNavigations: true,
    AllowedDestinations: []string{"image"},
    ExemptPaths: []string{"/webhooks/"},
}))

This does not replace CSRF tokens for cookie-authenticated unsafe requests. Exempt only endpoints protected by an appropriate non-cookie mechanism.

Documentation

Overview

Package fetchmetadata implements W3C Fetch Metadata Request Headers security policies. It provides automated defense against Cross-Site Request Forgery (CSRF), Cross-Site Script Inclusion (XSSI), and XS-Leaks at the transport layer.

Index

Constants

This section is empty.

Variables

View Source
var DefaultConfig = Config{
	AllowTopLevelNavigations: true,
	OnDenied: func(c fh.Ctx) error {
		return c.Status(fh.StatusForbidden).ProblemDetails(
			fh.StatusForbidden,
			"CROSS_SITE_REQUEST_BLOCKED",
			"Request blocked by Fetch Metadata Resource Isolation Policy",
			"https://www.w3.org/TR/fetch-metadata/",
		)
	},
}

DefaultConfig provides a secure default resource isolation policy.

Functions

func New

func New(config ...Config) fh.HandlerFunc

New creates a Fetch Metadata resource isolation middleware.

Types

type Config

type Config struct {
	// Filter defines a predicate to skip this middleware.
	Filter func(c fh.Ctx) bool

	// AllowTopLevelNavigations allows cross-site GET/HEAD navigations (e.g. clicking a link to your site).
	// Defaults to true.
	AllowTopLevelNavigations bool

	// AllowedDestinations allows cross-site requests with specific Sec-Fetch-Dest values (e.g. "image").
	AllowedDestinations []string

	// ExemptPaths contains exact paths or prefixes to exempt from Fetch Metadata enforcement (e.g. public webhooks).
	ExemptPaths []string

	// OnDenied is called when a request violates the fetch metadata policy.
	// Defaults to returning 403 Forbidden with RFC 9457 Problem Details.
	OnDenied fh.HandlerFunc
}

Config defines the configuration for Fetch Metadata isolation policy.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL