{"record":{"id":"6cde9013e625e650","repo":"hashicorp/terraform","slug":"registry-response-includes-invalid-shasums-signatu-6cde90","errorCode":null,"errorMessage":"registry response includes invalid SHASUMS signature URL: must use http or https scheme","messagePattern":"registry response includes invalid SHASUMS signature URL: must use http or https scheme","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/registry_client.go","lineNumber":342,"sourceCode":"\t}\n\tshasumsURL = resp.Request.URL.ResolveReference(shasumsURL)\n\tif shasumsURL.Scheme != \"http\" && shasumsURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: must use http or https scheme\")\n\t}\n\tdocument, err := c.getFile(shasumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"failed to retrieve authentication checksums for provider: %s\", err),\n\t\t)\n\t}\n\tsignatureURL, err := url.Parse(body.SHA256SumsSignatureURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: %s\", err)\n\t}\n\tsignatureURL = resp.Request.URL.ResolveReference(signatureURL)\n\tif signatureURL.Scheme != \"http\" && signatureURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: must use http or https scheme\")\n\t}\n\tsignature, err := c.getFile(signatureURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"failed to retrieve cryptographic signature for provider: %s\", err),\n\t\t)\n\t}\n\n\tkeys := make([]SigningKey, len(body.SigningKeys.GPGPublicKeys))\n\tfor i, key := range body.SigningKeys.GPGPublicKeys {\n\t\tkeys[i] = *key\n\t}\n\n\tret.Authentication = PackageAuthenticationAll(\n\t\tNewMatchingChecksumAuthentication(document, body.Filename, checksum),\n\t\tNewArchiveChecksumAuthentication(ret.TargetPlatform, checksum),\n\t\tNewSignatureAuthentication(document, signature, keys),","sourceCodeStart":324,"sourceCodeEnd":360,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/registry_client.go#L324-L360","documentation":"Raised after resolving the SHASUMS signature URL from a provider registry response when the resulting URL scheme is neither 'http' nor 'https'. The registry client refuses to fetch signature content over any other scheme (e.g. file://, ftp://, or a scheme-less URL) to prevent untrusted registries from redirecting signature retrieval to an unintended transport. It is a hard validation on body.SHA256SumsSignatureURL after it has been resolved against the request URL.","triggerScenarios":"A registry returns a SHA256SumsSignatureURL field whose value, after ResolveReference against the request URL, yields a scheme other than http/https. This happens with typos like 'htp://', with scheme-less relative values that resolve oddly, or with a malicious/misconfigured registry returning a file:// or gopher:// URL.","commonSituations":"Operating a private/ mirrored Terraform registry whose JSON response template has a malformed signature URL; using a filesystem-backed or in-memory test fixture that returns a relative path that resolves to a non-http scheme; corporate proxy rewriting redirects to an internal non-http scheme.","solutions":["Inspect the registry response JSON for the sha256_sums_signature_url field and correct it to a fully-qualified https URL.","If using a private/mirror registry, verify its response template emits an absolute https URL for signature fields.","If the URL is relative on purpose, ensure the base request URL itself is http(s) so ResolveReference produces an http(s) result.","Confirm no man-in-the-middle proxy is rewriting the Location/Link headers to a non-http scheme."],"exampleFix":"// before (registry response JSON)\n{\"sha256_sums_signature_url\": \"file:///signatures/foo.sig\"}\n// after\n{\"sha256_sums_signature_url\": \"https://registry.example.com/v1/providers/acme/foo/1.2.0/signature\"}","handlingStrategy":"validation","validationCode":"// Validate registry-provided signature URL scheme before relying on it.\nfunc validateSigURL(raw string, base *url.URL) error {\n    u, err := url.Parse(raw)\n    if err != nil { return err }\n    resolved := base.ResolveReference(u)\n    if resolved.Scheme != \"http\" && resolved.Scheme != \"https\" {\n        return fmt.Errorf(\"signature URL must be http/https, got %q\", resolved.Scheme)\n    }\n    return nil\n}","typeGuard":"// Guard for a registry response body field.\nfunc isHTTPURL(raw string) bool {\n    u, err := url.Parse(raw)\n    if err != nil { return false }\n    return u.Scheme == \"http\" || u.Scheme == \"https\"\n}","tryCatchPattern":null,"preventionTips":["Always emit absolute https URLs from registry/mirror metadata responses.","Validate registry response payloads against the documented schema in tests.","Use only HTTPS-backed mirrors to make scheme resolution unambiguous."],"tags":["registry","url-validation","security","scheme","getproviders"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}