aio-libs/aiohttp · error · InvalidUrlRedirectClientError

Invalid redirect URL origin

Error message

Invalid redirect URL origin

What it means

Raised as InvalidUrlRedirectClientError when parsed_redirect_url.origin() throws ValueError, i.e. the redirect URL is parseable as a string but lacks a valid scheme/host/origin (e.g. missing host, bad port, opaque scheme). aiohttp cannot reason about cookies/auth scoping without an origin.

Solutions

  1. Disable auto-follow and validate the redirect target yourself before re-requesting.
  2. Fix the server's LOCATION generation (ensure it always emits a full host).
  3. If you control the server, return an absolute URL with a valid scheme and host.

Example fix

// before
await session.get(url)  # 3xx to 'https:///path' -> raises
// after
resp = await session.get(url, allow_redirects=False)
loc = resp.headers.get('Location')
if loc and URL(loc).origin():
    resp = await session.get(URL(loc))
Defensive patterns

Strategy: validation

Validate before calling

from aiohttp import URL

def has_valid_origin(raw) -> bool:
    try:
        URL(raw).origin()
        return True
    except ValueError:
        return False

Type guard

from aiohttp import URL

def is_safe_redirect(raw) -> bool:
    try:
        u = URL(raw)
        return bool(u.scheme in ('http', 'https') and u.host and u.origin())
    except ValueError:
        return False

Try / catch

from aiohttp.client_exceptions import InvalidUrlRedirectClientError

try:
    resp = await session.get(url)
except InvalidUrlRedirectClientError as e:
    if 'origin' in str(e):
        resp = await session.get(url, allow_redirects=False)
    else:
        raise

Prevention

When it happens

Trigger: Server returns a 3xx LOCATION with a scheme but no host (e.g. 'https://:443/path'), an invalid port, or an origin-defeating construction. parsed_redirect_url.origin() raises ValueError.

Common situations: Misconfigured reverse proxy generating LOCATION from a template. Server returning a redirect to a URL with an empty or invalid host. Path-only redirect combined with a base_url that yields no origin.

Related errors


AI-assisted analysis of aio-libs/aiohttp@d041d4d0fd (2026-08-11). Data as JSON: /api/errors/ca754169e78f43d9. Report an issue: GitHub.

Appendix: source

Thrown at aiohttp/client.py:844

                                "Server attempted redirecting to a location that does not look like a URL",
                            ) from e

                        scheme = parsed_redirect_url.scheme
                        if scheme not in HTTP_AND_EMPTY_SCHEMA_SET:
                            if req._body is not None:
                                await req._body.close()
                            resp.close()
                            raise NonHttpUrlRedirectClientError(r_url)
                        elif not scheme:
                            parsed_redirect_url = url.join(parsed_redirect_url)

                        try:
                            redirect_origin = parsed_redirect_url.origin()
                        except ValueError as origin_val_err:
                            if req._body is not None:
                                await req._body.close()
                            resp.close()
                            raise InvalidUrlRedirectClientError(
                                parsed_redirect_url,
                                "Invalid redirect URL origin",
                            ) from origin_val_err

                        if url.origin() != redirect_origin:
                            cookies = None
                            headers.popall(hdrs.AUTHORIZATION, None)
                            headers.popall(hdrs.COOKIE, None)
                            headers.popall(hdrs.PROXY_AUTHORIZATION, None)

                        url = parsed_redirect_url
                        params = {}
                        resp.release()
                        continue

                    break

            if req._body is not None:

View on GitHub (pinned to d041d4d0fd)