This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 22 · May 26 – Jun 1, 2025

net/http: add CrossOriginForgeryHandler

Worth knowingstdlib

What changed
The net/http package now includes CrossOriginProtection, a helper that rejects non‑safe browser requests from a different origin based on the Sec-Fetch-Site or Origin headers.
Production impact
The source does not say.
Try it
Create a CrossOriginProtection instance and wrap an existing handler to see how it blocks unsafe cross‑origin requests.
Source
github.com/golang/go/issues/73626

Understand it, then run it

The net/http package now has a helper called CrossOriginProtection. It is meant to stop a browser from sending a request that changes state (like a POST) when that request comes from a different website. The helper looks at two HTTP headers that browsers add: Sec-Fetch-Site and Origin. If the request is not a safe method (GET, HEAD, or OPTIONS) and the headers say the request came from another origin, the helper will reject it. If the headers are missing, the request is allowed – the helper assumes it is either a same‑origin request or not coming from a browser.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed