gofiber/fiber · warning
client: HTTPS to HTTP redirect blocked
Error message
client: HTTPS to HTTP redirect blocked
What it means
Returned by resolveRedirect (client/transport.go:532) when the redirect starts on an HTTPS origin (wasHTTPS) and the Location header points to a plaintext http:// URL. The client refuses the hop on every transport — silently following it would expose the (already-encrypted) request — cookies, headers, body — to a downgrade attack. The middleware/proxy package ships its own equivalent sentinel for the same rule.
Solutions
- Fix the upstream so Location preserves the https:// scheme (configure your proxy/CDN to emit https redirects).
- If the downgrade is intentional and safe (e.g. internal network), set Client.MaxRedirects to 0 and follow the hop yourself with a fresh HTTPS-or-HTTP-aware call.
- On the proxy side, the same logic applies — DoRedirects rejects the downgrade; fix the origin or handle the redirect manually.
- Add an integration test asserting no Location header in your responses downgrades the scheme.
Example fix
// before client.SetMaxRedirects(5) resp, err := req.Send() // upstream 302 Location: http://... -> ErrRedirectDowngrade // after (opt out and follow yourself, only if safe) client.SetMaxRedirects(0) resp, err := req.Send() // get the 302, then decide
Defensive patterns
Strategy: try-catch
Validate before calling
// Pre-validate that the redirect target preserves the scheme
func wouldDowngrade(base, location string) bool {
wasHTTPS := strings.EqualFold(urlScheme(base), "https")
u, err := url.Parse(location)
if err != nil || u.Scheme == "" { return false }
return wasHTTPS && strings.EqualFold(u.Scheme, "http")
} Try / catch
resp, err := req.Send()
if errors.Is(err, fiber.ErrRedirectDowngrade) {
// surface to ops — the upstream is misconfigured; do NOT silently follow
// or set MaxRedirects(0) and handle the hop yourself only if it is safe
} Prevention
- Ensure upstreams/CDNs preserve https in Location headers.
- Treat ErrRedirectDowngrade as a security signal, not a transient error.
- Add a redirect audit test that asserts no Location downgrades scheme.
When it happens
Trigger: An HTTPS server returns 301/302/307/308 with a Location like http://example.com/next; a misconfigured reverse proxy that rewrites Location to http://; an upstream that drops the scheme; HSTS-incompatible redirect chains. Reproducible via the 'https downgrade' test case (client/transport_test.go:615).
Common situations: Load balancer terminating TLS but advertising http:// in Location; dev/staging servers without TLS redirecting to plain HTTP; misconfigured CDN; upstream returning absolute http:// URLs in redirects.
Related errors
- ErrRedirectDowngrade
- %w: %w
- failed to append certificate
- only file paths and io.Writer are supported
- protocol not supported; only http or https are allowed
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/6265bb2ae6fd2cf4.
Report an issue: GitHub.
Appendix: source
Thrown at client/errors.go:18
package client
import (
"errors"
)
var (
errResponseChanTypeAssertion = errors.New("failed to type-assert to *Response")
errChanErrorTypeAssertion = errors.New("failed to type-assert to chan error")
errRequestTypeAssertion = errors.New("failed to type-assert to *Request")
errFileTypeAssertion = errors.New("failed to type-assert to *File")
errCookieJarTypeAssertion = errors.New("failed to type-assert to *CookieJar")
errSyncPoolBuffer = errors.New("failed to retrieve buffer from a sync.Pool")
// ErrRedirectDowngrade is returned when a redirect leads from an HTTPS origin
// to plaintext HTTP, on every transport. Set MaxRedirects to 0 to take such a
// hop yourself instead.
ErrRedirectDowngrade = errors.New("client: HTTPS to HTTP redirect blocked")
)
View on GitHub (pinned to a105acad6c)