{"record":{"id":"a665e854b325880a","repo":"gofiber/fiber","slug":"protocol-not-supported-only-http-or-https-are-all","errorCode":null,"errorMessage":"protocol not supported; only http or https are allowed","messagePattern":"protocol not supported; only http or https are allowed","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"client/core.go","lineNumber":302,"sourceCode":"\n// releaseErrChan returns the error channel to the pool.\n// It's caller's responsibility to ensure that:\n// - the channel is not closed\n// - the channel is drained before returning it\n// - the channel is not reused after returning it\nfunc releaseErrChan(ch chan error) {\n\terrChanPool.Put(ch)\n}\n\n// newCore returns a new core object.\nfunc newCore() *core {\n\treturn &core{}\n}\n\nvar (\n\tErrTimeoutOrCancel      = errors.New(\"timeout or cancel\")\n\tErrURLFormat            = errors.New(\"the URL is incorrect\")\n\tErrNotSupportSchema     = errors.New(\"protocol not supported; only http or https are allowed\")\n\tErrFileNoName           = errors.New(\"the file should have a name\")\n\tErrBodyType             = errors.New(\"the body type should be []byte\")\n\tErrNotSupportSaveMethod = errors.New(\"only file paths and io.Writer are supported\")\n\tErrBodyTypeNotSupported = errors.New(\"the body type is not supported\")\n)\n","sourceCodeStart":284,"sourceCodeEnd":308,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/client/core.go#L284-L308","documentation":"Exported sentinel (client/core.go:302) signaling that a URL's scheme is neither http nor https. The client only speaks those two schemes (the same protocolCheck regex used in parserRequestURL), so any other scheme (ftp://, ws://, file://) is rejected. The error is exported for callers that want to perform the same validation before constructing a request.","triggerScenarios":"Passing a URL with a non-http(s) scheme to Request.SetURL; or validating a URL independently and comparing against this sentinel. (Note: the built-in hooks.go path currently surfaces ErrURLFormat for missing-scheme and fasthttp.ErrorInvalidURI for an unknown scheme during redirect; ErrNotSupportSchema is the public, stable sentinel for the same intent.)","commonSituations":"User-supplied URLs that include ws:// or ftp://; configuration loaders that accept arbitrary schemes; redirect chains that hop to a non-http scheme.","solutions":["Reject or rewrite URLs whose scheme is not http/https before calling the client.","Use url.Parse and check u.Scheme ∈ {http, https}; compare against ErrNotSupportSchema if you mirror the library's check.","For WebSocket use the dedicated websocket middleware, not the HTTP client.","Document that only http and https are supported in your configuration surface."],"exampleFix":"// before\nu := \"ftp://files.example.com/data\"\nreq := client.Get().SetURL(u) // unsupported scheme\n\n// after\nu := \"https://files.example.com/data\"\nreq := client.Get().SetURL(u)","handlingStrategy":"validation","validationCode":"func validateScheme(rawURL string) error {\n    u, err := url.Parse(rawURL)\n    if err != nil { return err }\n    if u.Scheme != \"http\" && u.Scheme != \"https\" {\n        return fiber.ErrNotSupportSchema\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"if err := validateScheme(u); err != nil {\n    if errors.Is(err, fiber.ErrNotSupportSchema) { /* reject input */ }\n}","preventionTips":["Whelist http/https at the configuration boundary.","Use net/url.Parse and validate scheme before constructing a Request.","For non-HTTP protocols use a dedicated client, not fiber.Client."],"tags":["client","url","scheme","http"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}