Stdlib entry point
(*TheAuth).Handler() returns an http.Handler with every route Mount
registers, for net/http without chi:
CSRF and Origin checks
SameSite=Lax does not stop requests from sibling subdomains, which are
same-site. theauth-go therefore rejects (403) any POST, PUT, PATCH or DELETE
that carries cookies when its Origin (or, if absent, Referer) is not
trusted. Trusted means the BaseURL origin or an entry in
Config.TrustedOrigins. If neither header is present, a Sec-Fetch-Site of
same-site or cross-site is rejected.
Exempt: GET/HEAD/OPTIONS, requests with Authorization: Bearer, and requests
with no cookies. Set Config.DisableCSRFProtection to opt out.
Secure cookies
Cookies get Secure when Config.SecureCookie is true, BaseURL is https,
the connection is TLS, or the peer is in TrustedProxies and sent
X-Forwarded-Proto: https. A plain-http BaseURL (local dev) stays non-Secure.
Behind a reverse proxy
X-Forwarded-For and X-Forwarded-Proto are honored only from peers inside
Config.TrustedProxies. The default is empty, so behind Caddy, nginx or a load
balancer every client appears as the proxy IP and the per-IP rate limit
collapses into one shared bucket. List the proxy network:
A startup warning is logged when the list is empty; set
SuppressTrustedProxiesWarning if the server is exposed directly.Last modified on October 7, 2026