{"record":{"id":"ca754169e78f43d9","repo":"aio-libs/aiohttp","slug":"invalid-redirect-url-origin","errorCode":null,"errorMessage":"Invalid redirect URL origin","messagePattern":"Invalid redirect URL origin","errorType":"exception","errorClass":"InvalidUrlRedirectClientError","httpStatus":null,"severity":"error","filePath":"aiohttp/client.py","lineNumber":844,"sourceCode":"                                \"Server attempted redirecting to a location that does not look like a URL\",\n                            ) from e\n\n                        scheme = parsed_redirect_url.scheme\n                        if scheme not in HTTP_AND_EMPTY_SCHEMA_SET:\n                            if req._body is not None:\n                                await req._body.close()\n                            resp.close()\n                            raise NonHttpUrlRedirectClientError(r_url)\n                        elif not scheme:\n                            parsed_redirect_url = url.join(parsed_redirect_url)\n\n                        try:\n                            redirect_origin = parsed_redirect_url.origin()\n                        except ValueError as origin_val_err:\n                            if req._body is not None:\n                                await req._body.close()\n                            resp.close()\n                            raise InvalidUrlRedirectClientError(\n                                parsed_redirect_url,\n                                \"Invalid redirect URL origin\",\n                            ) from origin_val_err\n\n                        if url.origin() != redirect_origin:\n                            cookies = None\n                            headers.popall(hdrs.AUTHORIZATION, None)\n                            headers.popall(hdrs.COOKIE, None)\n                            headers.popall(hdrs.PROXY_AUTHORIZATION, None)\n\n                        url = parsed_redirect_url\n                        params = {}\n                        resp.release()\n                        continue\n\n                    break\n\n            if req._body is not None:","sourceCodeStart":826,"sourceCodeEnd":862,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/client.py#L826-L862","documentation":"Raised as InvalidUrlRedirectClientError when parsed_redirect_url.origin() throws ValueError, i.e. the redirect URL is parseable as a string but lacks a valid scheme/host/origin (e.g. missing host, bad port, opaque scheme). aiohttp cannot reason about cookies/auth scoping without an origin.","triggerScenarios":"Server returns a 3xx LOCATION with a scheme but no host (e.g. 'https://:443/path'), an invalid port, or an origin-defeating construction. parsed_redirect_url.origin() raises ValueError.","commonSituations":"Misconfigured reverse proxy generating LOCATION from a template. Server returning a redirect to a URL with an empty or invalid host. Path-only redirect combined with a base_url that yields no origin.","solutions":["Disable auto-follow and validate the redirect target yourself before re-requesting.","Fix the server's LOCATION generation (ensure it always emits a full host).","If you control the server, return an absolute URL with a valid scheme and host."],"exampleFix":"// before\nawait session.get(url)  # 3xx to 'https:///path' -> raises\n// after\nresp = await session.get(url, allow_redirects=False)\nloc = resp.headers.get('Location')\nif loc and URL(loc).origin():\n    resp = await session.get(URL(loc))","handlingStrategy":"validation","validationCode":"from aiohttp import URL\n\ndef has_valid_origin(raw) -> bool:\n    try:\n        URL(raw).origin()\n        return True\n    except ValueError:\n        return False","typeGuard":"from aiohttp import URL\n\ndef is_safe_redirect(raw) -> bool:\n    try:\n        u = URL(raw)\n        return bool(u.scheme in ('http', 'https') and u.host and u.origin())\n    except ValueError:\n        return False","tryCatchPattern":"from aiohttp.client_exceptions import InvalidUrlRedirectClientError\n\ntry:\n    resp = await session.get(url)\nexcept InvalidUrlRedirectClientError as e:\n    if 'origin' in str(e):\n        resp = await session.get(url, allow_redirects=False)\n    else:\n        raise","preventionTips":["Ensure servers emit absolute redirect URLs with scheme+host.","Validate LOCATION before re-requesting when handling redirects manually.","Treat origin-less redirects as protocol errors and stop following."],"tags":["redirect","url-validation","origin"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}