gofiber/fiber · error
protocol not supported; only http or https are allowed
Error message
protocol not supported; only http or https are allowed
What it means
Exported sentinel (client/core.go:302) signaling that a URL's scheme is neither http nor https. The client only speaks those two schemes (the same protocolCheck regex used in parserRequestURL), so any other scheme (ftp://, ws://, file://) is rejected. The error is exported for callers that want to perform the same validation before constructing a request.
Solutions
- Reject or rewrite URLs whose scheme is not http/https before calling the client.
- Use url.Parse and check u.Scheme ∈ {http, https}; compare against ErrNotSupportSchema if you mirror the library's check.
- For WebSocket use the dedicated websocket middleware, not the HTTP client.
- Document that only http and https are supported in your configuration surface.
Example fix
// before u := "ftp://files.example.com/data" req := client.Get().SetURL(u) // unsupported scheme // after u := "https://files.example.com/data" req := client.Get().SetURL(u)
Defensive patterns
Strategy: validation
Validate before calling
func validateScheme(rawURL string) error {
u, err := url.Parse(rawURL)
if err != nil { return err }
if u.Scheme != "http" && u.Scheme != "https" {
return fiber.ErrNotSupportSchema
}
return nil
} Try / catch
if err := validateScheme(u); err != nil {
if errors.Is(err, fiber.ErrNotSupportSchema) { /* reject input */ }
} Prevention
- Whelist http/https at the configuration boundary.
- Use net/url.Parse and validate scheme before constructing a Request.
- For non-HTTP protocols use a dedicated client, not fiber.Client.
When it happens
Trigger: Passing a URL with a non-http(s) scheme to Request.SetURL; or validating a URL independently and comparing against this sentinel. (Note: the built-in hooks.go path currently surfaces ErrURLFormat for missing-scheme and fasthttp.ErrorInvalidURI for an unknown scheme during redirect; ErrNotSupportSchema is the public, stable sentinel for the same intent.)
Common situations: User-supplied URLs that include ws:// or ftp://; configuration loaders that accept arbitrary schemes; redirect chains that hop to a non-http scheme.
Related errors
- the URL is incorrect
- client: HTTPS to HTTP redirect blocked
- only file paths and io.Writer are supported
- the body type should be []byte
- the file should have a name
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/a665e854b325880a.
Report an issue: GitHub.
Appendix: source
Thrown at client/core.go:302
// releaseErrChan returns the error channel to the pool.
// It's caller's responsibility to ensure that:
// - the channel is not closed
// - the channel is drained before returning it
// - the channel is not reused after returning it
func releaseErrChan(ch chan error) {
errChanPool.Put(ch)
}
// newCore returns a new core object.
func newCore() *core {
return &core{}
}
var (
ErrTimeoutOrCancel = errors.New("timeout or cancel")
ErrURLFormat = errors.New("the URL is incorrect")
ErrNotSupportSchema = errors.New("protocol not supported; only http or https are allowed")
ErrFileNoName = errors.New("the file should have a name")
ErrBodyType = errors.New("the body type should be []byte")
ErrNotSupportSaveMethod = errors.New("only file paths and io.Writer are supported")
ErrBodyTypeNotSupported = errors.New("the body type is not supported")
)
View on GitHub (pinned to a105acad6c)