Skip to content

use:enhance does not update form.message when running into a CSRF error #15737

Description

@Miniontoby

Describe the bug

Basically, when a form has use:enhance, it does not update form.message when running into a CSRF error when the ORIGIN variable is empty, during production build where ORIGIN is not specifically set.

the fact that the ORIGIN variable is empty, is not the thing that I report here.
It is the fact the form.message does not update, whilst the console's network tab DOES show in the response that there is a message key saying the CSRF error (see logs section).

Reproduction

To reproduce, you must start a new project using npx sv create with betterauth demo installed (since that gives a basic form with use:enhance) and the adapter-node.

Then build the project, using npm run build

Then run the build by going into the build folder and running node . (without adding any ORIGIN env variables)

Then open the link in your browser and go to /demos/better-auth/login (http://localhost:3000/demo/better-auth/login) and then just enter like test@test.com and test as password and then just click "Login"

in the browser console it should say 401 with the CSRF error, but on the frontend the form?.message does not update.

(it does update when the ORIGIN variable is set and then the database itself is not existing and then it does show "Unexpected error" in the form?.message)

Logs

xqEx-9sN.js:1  POST http://localhost:3000/demo/better-auth/login?/signInEmail 403 (Forbidden)

{
    "message": "Cross-site POST form submissions are forbidden"
}

System Info

System:
    OS: openbsd
    CPU: (1) x64 Intel(R) Xeon(R) CPU E5-2620 0 @ 2.00GHz
    Memory: 601.54 MB / 1.98 GB
  Binaries:
    Node: 22.15.1 - /usr/local/bin/node
    Yarn: 1.22.19 - /usr/local/bin/yarn
    npm: 10.9.2 - /usr/local/bin/npm
    pnpm: 10.33.0 - /usr/local/bin/pnpm
  npmPackages:
    @sveltejs/adapter-node: ^5.5.4 => 5.5.4
    @sveltejs/kit: ^2.57.1 => 2.57.1
    @sveltejs/vite-plugin-svelte: ^6.2.4 => 6.2.4
    svelte: ^5.55.4 => 5.55.4
    vite: ^7.3.2 => 7.3.2

Severity

annoying, but I can work around it

Additional Information

If you do need a full example: https://github.com/miniontoby/vastrobustmediastorageplatform/tree/dev

and if you do need a zip of a minimum reproducable example instead of following the steps I provided, then I am fine with making that

Activity

  1. Conduitry commented on Apr 21, 2026

    @Conduitry
    Member

    Are you talking about CORS errors or about the CSRF protection?

  2. Miniontoby commented on Apr 21, 2026

    @Miniontoby
    Author

    I am talking about the error that is in the logs section:

    Image

    Wasn't sure what to call it.
    CrossSite yeah that is CSRF, I guess, I thought CrORss Site being CORS

  3. changed the title [-]use:enhance does not update form.message when running into a CORS error[/-] [+]use:enhance does not update form.message when running into a CSRF error[/+] on Apr 21, 2026
  4. PatrickG commented on Apr 22, 2026

    @PatrickG
    Member

    What do you expect form.message to be? If there is a CSRF error your form action does not even run.

    I think we should render +error.svelte in that case.

  5. Miniontoby commented on Apr 23, 2026

    @Miniontoby
    Author

    Because THIS was the response from the request, I expected the message value to be shown in form.message

    Image

    But nope, it does NOT render the +error.svelte, it shows completely nothing to the user/frontend. Not even to the backend.
    Only when I open the console, I saw the error

  6. added
    bugSomething isn't working
    formsStuff relating to forms and form actions
    and removed
    bugSomething isn't working
    on Aug 4, 2026
  7. added theissue type on Aug 4, 2026
  8. added a commit that references this issue on Aug 19, 2026
    7570a62
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    formsStuff relating to forms and form actions

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions