Radar · Go · Archive · Week 22 · May 26 – Jun 1, 2025
net/http: add CrossOriginForgeryHandler
Worth knowingstdlib
- What changed
- The
net/httppackage now includesCrossOriginProtection, a helper that rejects non‑safe browser requests from a different origin based on theSec-Fetch-SiteorOriginheaders. - Production impact
- The source does not say.
- Try it
- Create a
CrossOriginProtectioninstance and wrap an existing handler to see how it blocks unsafe cross‑origin requests. - Source
- github.com/golang/go/issues/73626
Understand it, then run it
The net/http package now has a helper called CrossOriginProtection. It is meant to stop a browser from sending a request that changes state (like a POST) when that request comes from a different website. The helper looks at two HTTP headers that browsers add: Sec-Fetch-Site and Origin. If the request is not a safe method (GET, HEAD, or OPTIONS) and the headers say the request came from another origin, the helper will reject it. If the headers are missing, the request is allowed – the helper assumes it is either a same‑origin request or not coming from a browser.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed