gitbutlerapp/gitbutler · error
must use HTTPS
Error message
{url_type} must use HTTPS: {url} What it means
validate_gitbutler_url enforces that all API/download URLs use HTTPS before further host checks. This error is thrown when a URL passed to validate_api_url or validate_download_url does not start with https://, protecting against plaintext downloads that could be tampered with.
Solutions
- Change the URL scheme to https://
- Fix the code/config that builds the URL to always use https
- If testing locally, use a local HTTPS endpoint or bypass the validator in a test-only path
- Update any custom mirror configuration to an HTTPS mirror
Example fix
// before
let url = format!("http://releases.gitbutler.com/{version}");
// after
let url = format!("https://releases.gitbutler.com/{version}"); Defensive patterns
Strategy: validation
Validate before calling
fn is_https(url: &str) -> bool { url.starts_with("https://") } Try / catch
match result {
Err(e) if e.to_string().contains("must use HTTPS") => {
// upgrade the URL scheme to https and retry
}
other => other?,
} Prevention
- Always build URLs with https:// constants, not user-supplied schemes
- Normalize/validate any user-configured mirror URLs at startup
- Never downgrade to http for 'testing' in production paths
When it happens
Trigger: A constructed or configured URL uses http:// (or another scheme), typically from custom config, a hardcoded http endpoint, or building the URL with the wrong scheme.
Common situations: User-supplied mirror/config with http://, internal testing endpoint left in config, code concatenating "http://" by mistake, redirect source handing back an insecure URL.
Understand the failure class
Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.
Related errors
- is not from a trusted GitButler domain
- Clone remote URL contains unsupported control characters
- must be an HTTP or HTTPS URL
- Invalid path scheme
- Refusing to remove label with degenerate name
AI-assisted analysis of gitbutlerapp/gitbutler@58e5313667 (2026-09-18).
Data as JSON: /api/errors/6fa096a2b179b9a9.
Report an issue: GitHub.
Appendix: source
Thrown at crates/but-installer/src/release.rs:104
release.version,
requested
);
}
Ok(release)
}
/// Common URL validation logic for GitButler domains.
///
/// Validates HTTPS protocol, parses URL, and checks the host against a predicate.
fn validate_gitbutler_url(
url: &str,
url_type: &str,
is_host_valid: impl Fn(&str) -> bool,
) -> Result<()> {
// Only allow HTTPS URLs
if !url.starts_with("https://") {
bail!("{url_type} must use HTTPS: {url}");
}
// Extract host from URL
let url_parsed =
url::Url::parse(url).with_context(|| format!("Invalid {} URL", url_type.to_lowercase()))?;
let host = url_parsed
.host_str()
.ok_or_else(|| anyhow!("No host in {} URL", url_type.to_lowercase()))?;
// Validate host using the provided predicate
if !is_host_valid(host) {
bail!("{url_type} is not from a trusted GitButler domain: {url}");
}
Ok(())
}
/// Validates that an API URL is from the trusted API domain.View on GitHub (pinned to 58e5313667)