gofiber/fiber · warning

client: HTTPS to HTTP redirect blocked

Error message

client: HTTPS to HTTP redirect blocked

What it means

Returned by resolveRedirect (client/transport.go:532) when the redirect starts on an HTTPS origin (wasHTTPS) and the Location header points to a plaintext http:// URL. The client refuses the hop on every transport — silently following it would expose the (already-encrypted) request — cookies, headers, body — to a downgrade attack. The middleware/proxy package ships its own equivalent sentinel for the same rule.

Solutions

  1. Fix the upstream so Location preserves the https:// scheme (configure your proxy/CDN to emit https redirects).
  2. If the downgrade is intentional and safe (e.g. internal network), set Client.MaxRedirects to 0 and follow the hop yourself with a fresh HTTPS-or-HTTP-aware call.
  3. On the proxy side, the same logic applies — DoRedirects rejects the downgrade; fix the origin or handle the redirect manually.
  4. Add an integration test asserting no Location header in your responses downgrades the scheme.

Example fix

// before
client.SetMaxRedirects(5)
resp, err := req.Send() // upstream 302 Location: http://... -> ErrRedirectDowngrade

// after (opt out and follow yourself, only if safe)
client.SetMaxRedirects(0)
resp, err := req.Send() // get the 302, then decide
Defensive patterns

Strategy: try-catch

Validate before calling

// Pre-validate that the redirect target preserves the scheme
func wouldDowngrade(base, location string) bool {
    wasHTTPS := strings.EqualFold(urlScheme(base), "https")
    u, err := url.Parse(location)
    if err != nil || u.Scheme == "" { return false }
    return wasHTTPS && strings.EqualFold(u.Scheme, "http")
}

Try / catch

resp, err := req.Send()
if errors.Is(err, fiber.ErrRedirectDowngrade) {
    // surface to ops — the upstream is misconfigured; do NOT silently follow
    // or set MaxRedirects(0) and handle the hop yourself only if it is safe
}

Prevention

When it happens

Trigger: An HTTPS server returns 301/302/307/308 with a Location like http://example.com/next; a misconfigured reverse proxy that rewrites Location to http://; an upstream that drops the scheme; HSTS-incompatible redirect chains. Reproducible via the 'https downgrade' test case (client/transport_test.go:615).

Common situations: Load balancer terminating TLS but advertising http:// in Location; dev/staging servers without TLS redirecting to plain HTTP; misconfigured CDN; upstream returning absolute http:// URLs in redirects.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/6265bb2ae6fd2cf4. Report an issue: GitHub.

Appendix: source

Thrown at client/errors.go:18

package client

import (
	"errors"
)

var (
	errResponseChanTypeAssertion = errors.New("failed to type-assert to *Response")
	errChanErrorTypeAssertion    = errors.New("failed to type-assert to chan error")
	errRequestTypeAssertion      = errors.New("failed to type-assert to *Request")
	errFileTypeAssertion         = errors.New("failed to type-assert to *File")
	errCookieJarTypeAssertion    = errors.New("failed to type-assert to *CookieJar")
	errSyncPoolBuffer            = errors.New("failed to retrieve buffer from a sync.Pool")

	// ErrRedirectDowngrade is returned when a redirect leads from an HTTPS origin
	// to plaintext HTTP, on every transport. Set MaxRedirects to 0 to take such a
	// hop yourself instead.
	ErrRedirectDowngrade = errors.New("client: HTTPS to HTTP redirect blocked")
)

View on GitHub (pinned to a105acad6c)