{"record":{"id":"fe755b697b100e15","repo":"hashicorp/terraform","slug":"response-has-invalid-content-type-s","errorCode":null,"errorMessage":"response has invalid Content-Type: %s","messagePattern":"response has invalid Content-Type: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/http_mirror_source.go","lineNumber":377,"sourceCode":"\tdefer func() {\n\t\t// If we're not returning the body then we'll close it\n\t\t// before we return.\n\t\tif body == nil {\n\t\t\tresp.Body.Close()\n\t\t}\n\t}()\n\t// After this point, our final URL return value should always be the\n\t// one from resp.Request, because that takes into account any redirects\n\t// we followed along the way.\n\tfinalURL = resp.Request.URL\n\n\tif resp.StatusCode == http.StatusOK {\n\t\t// If and only if we get an OK response, we'll check that the response\n\t\t// type is JSON and return the body reader.\n\t\tct := resp.Header.Get(\"Content-Type\")\n\t\tmt, params, err := mime.ParseMediaType(ct)\n\t\tif err != nil {\n\t\t\treturn 0, nil, finalURL, fmt.Errorf(\"response has invalid Content-Type: %s\", err)\n\t\t}\n\t\tif mt != \"application/json\" {\n\t\t\treturn 0, nil, finalURL, fmt.Errorf(\"response has invalid Content-Type: must be application/json\")\n\t\t}\n\t\tfor name := range params {\n\t\t\t// The application/json content-type has no defined parameters,\n\t\t\t// but some servers are configured to include a redundant \"charset\"\n\t\t\t// parameter anyway, presumably out of a sense of completeness.\n\t\t\t// We'll ignore them but warn that we're ignoring them in case the\n\t\t\t// subsequent parsing fails due to the server trying to use an\n\t\t\t// unsupported character encoding. (RFC 7159 defines its own\n\t\t\t// JSON-specific character encoding rules.)\n\t\t\tlog.Printf(\"[WARN] Network mirror returned %q as part of its JSON content type, which is not defined. Ignoring.\", name)\n\t\t}\n\t\tbody = resp.Body\n\t}\n\n\treturn resp.StatusCode, body, finalURL, nil","sourceCodeStart":359,"sourceCodeEnd":395,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/http_mirror_source.go#L359-L395","documentation":"For a 200 response, the client parses the `Content-Type` header with `mime.ParseMediaType`. If the header value is malformed (e.g. unparseable parameters, stray characters), the parse error is surfaced. This is distinct from a wrong-but-well-formed media type.","triggerScenarios":"`mime.ParseMediaType(ct)` returns an error for the response's `Content-Type` header; error at http_mirror_source.go:377.","commonSituations":"Mirror/proxy sends a malformed `Content-Type` (missing closing quote, illegal chars); custom header injection by an intermediary; rare misconfigured CDN.","solutions":["Capture the raw `Content-Type` header with `curl -i` and inspect it.","Fix the mirror server / reverse proxy to emit a clean `Content-Type: application/json`.","Remove any middleware that rewrites headers incorrectly."],"exampleFix":"// before\nContent-Type: application/json; charset=\n// after\nContent-Type: application/json","handlingStrategy":"validation","validationCode":"// Validate Content-Type well-formedness before sending the response\nct := resp.Header.Get(\"Content-Type\")\nif _, _, err := mime.ParseMediaType(ct); err != nil {\n    return fmt.Errorf(\"mirror sent malformed Content-Type %q: %w\", ct, err)\n}","typeGuard":"// isValidContentType narrows to parseable header values\nfunc isValidContentType(ct string) bool {\n    _, _, err := mime.ParseMediaType(ct)\n    return err == nil\n}","tryCatchPattern":null,"preventionTips":["Configure the mirror to emit a clean `Content-Type: application/json`.","Avoid header-rewriting middleware.","Audit reverse-proxy config for stray header edits.","Smoke-test headers with `curl -i`."],"tags":["network","mirror","http-headers","content-type"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}