
Exact origin and derived-host policy, fetch metadata, optional token evidence, immutable decisions, and incomplete-evidence review stay separate from proxy trust, token verification, authentication, authorization, and mutation execution. This is the real published Genesis interface—not a stock image.
Genesis Code Store · GCD-FLOOT-310
Mutation Request Origin & CSRF Context Guard
Classify state-changing requests from exact allowed origins, Origin and Host agreement, Sec-Fetch-Site context, and an optional host-verified CSRF-token result before any mutation runs.
An original zero-dependency request-provenance decision guard for Floot, React, and server applications. It validates exact HTTP(S) origin policy, derives allowed hosts, normalizes seven supported methods, checks Origin and Host agreement, rejects cross-site fetch context, enforces an optional positive CSRF-token verification result, and returns one deeply frozen allow, reject, review, or not-applicable decision with stable reasons.
Classify state-changing requests from exact allowed origins, Origin and Host agreement, Sec-Fetch-Site context, and an optional host-verified CSRF-token result before any mutation runs.
Free ZIP download Verified ZIP · 15 files · JavaScript + TypeScript declarations + 143 tests + README + START-HERE
Free products remain subject to the written license included with the package. Free does not mean public-domain or unrestricted resale. Domain limits count websites, not individual page URLs.
Read license termsWhat it helps you do
- Exact allowlisted-origin and derived-host decisions without wildcard or suffix matching
- Cross-site rejection, origin/host contradiction handling, optional token enforcement, and incomplete-evidence review
- Deeply frozen stable output with explicit proof that no token, authentication, authorization, network, mutation, or persistence effect occurred
What this specific product actually does
Every Genesis listing has its own capabilities, workflow, automation status, limits, and proof standard—without generic promises copied from another product.
Inside Mutation Request Origin & CSRF Context Guard
- 01Normalizes GET, HEAD, OPTIONS, POST, PUT, PATCH, and DELETE while keeping safe methods outside the mutation boundary.
- 02Validates one to 100 exact HTTP(S) origin-only policy entries and derives their corresponding allowed hosts.
- 03Rejects malformed origins and hosts, cross-site fetch context, unapproved origins or hosts, and contradictory Origin/Host evidence.
- 04Requires a positive caller-supplied CSRF-token verification result when the host enables the token policy.
- 05Allows missing Origin only with same-origin fetch metadata and a positive token result; otherwise returns review rather than implicit trust.
- 06Returns deeply frozen decisions, stable issues, normalized evidence, and explicit non-effect flags with zero dependencies.
Deterministic request provenance without hidden security or mutation effects.
The guard classifies supplied request context only; the host owns proxy trust, token verification, authentication, authorization, mutation, monitoring, incident response, and rollback.
This product does not modify a customer website.
Who this is built for
- 01Floot and React endpoint middleware that needs a deterministic request-provenance gate before state changes
- 02Security reviews separating browser request evidence from real CSRF-token verification, authentication, and resource authorization
- 03Teams that need exact-origin policy and auditable deny-by-default handling without coupling to one server framework
How you receive it
GCD-FLOOT-310
Verified ZIP · 15 files · JavaScript + TypeScript declarations + 143 tests + README + START-HERE
All Platforms, Floot, React / Next.js
Free
This listing is a downloadable Genesis code package. The ZIP includes reusable code and START-HERE directions.
Three steps for this product
- 01
Configure trusted request evidence
Define exact deployment origins, review trusted-proxy behavior, and obtain Origin, Host, and Sec-Fetch-Site from the server request.
- 02
Verify the token outside the guard
Use a reviewed constant-time host verifier where needed, pass only its boolean result, and stop on reject or review output.
- 03
Authorize, mutate, and monitor separately
Authenticate the user, authorize the exact resource and action, perform the mutation only after every gate passes, and test logs, incidents, and rollback.
Before & After Repair Report
Mutation Request Origin & CSRF Context Guard · GCD-FLOOT-310
Report format preview. Scores and status values populate only from measurements produced by an actual run. Genesis does not invent improvements.
What Genesis Code Doctor fixed
- Only verified changes appear here.
- Each repair can show affected files, routes, checks, or rules.
- Regression checks are recorded separately from the repair itself.
Still needs attention
- Unresolved, blocked, unavailable, or not-tested items remain visible.
- Evidence links can explain why an item passed, failed, or needs review.
- Follow-up verification can be run after implementation.
Know the fit, evidence, and handoff before a repair is used.
These controls turn a code product into a traceable repair workflow. They do not claim compatibility or success that has not been verified.
Declared support is available
Declared platforms: All Platforms, Floot, React / Next.js
Exact compatibility still depends on the customer's framework version, dependencies, hosting, custom code, and current site state.
Lifecycle protection is part of the product standard.
- Compatibility is reviewed before release.
- Regression and rollback requirements stay explicit.
- Follow-up verification can be run after implementation.
Genesis keeps the recommendation tied to evidence.
- Confirm the observed problem.
- Check product fit and safety boundary.
- Apply only the authorized repair scope.
- Re-run equivalent checks before calling it fixed.
Generate a clean technical handoff in one click.
The handoff includes product identity, declared compatibility, delivery method, capabilities, safety boundary, and the verification sequence.
What this item does not claim
This guard evaluates caller-supplied request evidence only. It does not terminate TLS, establish proxy trust, read cookies, generate or verify CSRF tokens, authenticate a user, authorize a resource, inspect request bodies, make network requests, log events, mutate application state, or persist data. The host owns trusted proxy configuration, token security, authentication, authorization, secure errors, monitoring, incident response, and rollback.
Simple delivery when verified code is released
Free code uses Free Download. Paid code uses Add to Cart. Every released package includes a verified ZIP, README, license notice, and START-HERE directions.
Copyright © Connect Point ISP LLC. Genesis Code Doctor™. All rights reserved. Purchase or download does not transfer ownership. Except where a product expressly provides a different written license, Genesis packages may not be resold, redistributed, sublicensed, repackaged for sale, or published as a competing download.