Omnikite Logo
Omnikite
Toggle theme
Security & Network100% In-Memory SandboxPopular Utility

Sec-Fetch Metadata Request Isolation Policy Builder

Build Next.js & Express middleware using Sec-Fetch-Site, Mode, and Dest headers to eliminate CSRF and XS-Leaks.

More in Security & Network
Advertisement
Zero-Knowledge Privacy

Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. No data is ever transmitted across the network.

Sub-Millisecond Native

Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.

RFC Standards Compliant

Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.

How to Use Sec-Fetch Metadata Request Isolation Policy Builder

1
Configure Isolation Rules

Toggle same-site only, top-level navigations, and image exemptions.

2
Inspect Middleware Code

Review the TypeScript request isolation function.

3
Copy Middleware

Integrate into your Next.js middleware.ts or Express server.

Frequently Asked Questions

What is Sec-Fetch-Site?

Sec-Fetch-Site indicates the relationship between the initiator's origin and the target origin (same-origin, same-site, cross-site, none).

Does this replace CSRF tokens?

Resource isolation via Sec-Fetch metadata provides powerful defense-in-depth that can prevent unauthorized cross-origin requests at the gateway.

Advertisement