gitbutlerapp/gitbutler · error

must use HTTPS

Error message

{url_type} must use HTTPS: {url}

What it means

validate_gitbutler_url enforces that all API/download URLs use HTTPS before further host checks. This error is thrown when a URL passed to validate_api_url or validate_download_url does not start with https://, protecting against plaintext downloads that could be tampered with.

Solutions

  1. Change the URL scheme to https://
  2. Fix the code/config that builds the URL to always use https
  3. If testing locally, use a local HTTPS endpoint or bypass the validator in a test-only path
  4. Update any custom mirror configuration to an HTTPS mirror

Example fix

// before
let url = format!("http://releases.gitbutler.com/{version}");
// after
let url = format!("https://releases.gitbutler.com/{version}");
Defensive patterns

Strategy: validation

Validate before calling

fn is_https(url: &str) -> bool { url.starts_with("https://") }

Try / catch

match result {
    Err(e) if e.to_string().contains("must use HTTPS") => {
        // upgrade the URL scheme to https and retry
    }
    other => other?,
}

Prevention

When it happens

Trigger: A constructed or configured URL uses http:// (or another scheme), typically from custom config, a hardcoded http endpoint, or building the URL with the wrong scheme.

Common situations: User-supplied mirror/config with http://, internal testing endpoint left in config, code concatenating "http://" by mistake, redirect source handing back an insecure URL.

Understand the failure class

Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.

Related errors


AI-assisted analysis of gitbutlerapp/gitbutler@58e5313667 (2026-09-18). Data as JSON: /api/errors/6fa096a2b179b9a9. Report an issue: GitHub.

Appendix: source

Thrown at crates/but-installer/src/release.rs:104

            release.version,
            requested
        );
    }

    Ok(release)
}

/// Common URL validation logic for GitButler domains.
///
/// Validates HTTPS protocol, parses URL, and checks the host against a predicate.
fn validate_gitbutler_url(
    url: &str,
    url_type: &str,
    is_host_valid: impl Fn(&str) -> bool,
) -> Result<()> {
    // Only allow HTTPS URLs
    if !url.starts_with("https://") {
        bail!("{url_type} must use HTTPS: {url}");
    }

    // Extract host from URL
    let url_parsed =
        url::Url::parse(url).with_context(|| format!("Invalid {} URL", url_type.to_lowercase()))?;
    let host = url_parsed
        .host_str()
        .ok_or_else(|| anyhow!("No host in {} URL", url_type.to_lowercase()))?;

    // Validate host using the provided predicate
    if !is_host_valid(host) {
        bail!("{url_type} is not from a trusted GitButler domain: {url}");
    }

    Ok(())
}

/// Validates that an API URL is from the trusted API domain.

View on GitHub (pinned to 58e5313667)