hashicorp/terraform · error

registry response includes invalid download URL: must use…

Error message

registry response includes invalid download URL: must use http or https scheme

What it means

Thrown when the resolved download URL's scheme is neither http nor https. The download URL is resolved against the request URL first, so a relative path against an https base normally yields https; this fires when the absolute scheme is file/data/javascript/etc.

Solutions

  1. Ensure the registry serves download_url over http(s) only
  2. If self-hosting, publish artifacts behind an https endpoint
  3. Report a non-http(s) download_url as a registry defect
Defensive patterns

Strategy: validation

Validate before calling

u, err := url.Parse(body.DownloadURL)
if err != nil {
    return err
}
if u.Scheme != "http" && u.Scheme != "https" {
    return fmt.Errorf("download_url must be http(s), got %q", u.Scheme)
}

Type guard

func IsHTTPURL(s string) bool {
    u, err := url.Parse(s)
    return err == nil && (u.Scheme == "http" || u.Scheme == "https")
}

Try / catch

if downloadURL.Scheme != "http" && downloadURL.Scheme != "https" {
    return fmt.Errorf("refusing non-http(s) download URL %q", downloadURL)
}

Prevention

When it happens

Trigger: downloadURL.Scheme is not 'http' and not 'https' after resp.Request.URL.ResolveReference(downloadURL).

Common situations: Registry returns a file:// URL; download_url is empty and resolves to the base with no path producing an unexpected scheme; a mirror serving data: URIs; SSRF-hardening failure on the registry side.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/f7701ff7e9f01961. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/registry_client.go:289

			if err != nil {
				return PackageMeta{}, err
			}
			protoErr.Suggestion = closest
			return PackageMeta{}, protoErr
		}
	}

	if body.OS != target.OS || body.Arch != target.Arch {
		return PackageMeta{}, fmt.Errorf("registry response to request for %s archive has incorrect target %s", target, Platform{body.OS, body.Arch})
	}

	downloadURL, err := url.Parse(body.DownloadURL)
	if err != nil {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid download URL: %s", err)
	}
	downloadURL = resp.Request.URL.ResolveReference(downloadURL)
	if downloadURL.Scheme != "http" && downloadURL.Scheme != "https" {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid download URL: must use http or https scheme")
	}

	ret := PackageMeta{
		Provider:         provider,
		Version:          version,
		ProtocolVersions: protoVersions,
		TargetPlatform: Platform{
			OS:   body.OS,
			Arch: body.Arch,
		},
		Filename: body.Filename,
		Location: PackageHTTPURL(downloadURL.String()),
		// "Authentication" is populated below
	}

	if len(body.SHA256Sum) != sha256.Size*2 { // *2 because it's hex-encoded
		return PackageMeta{}, c.errQueryFailed(
			provider,

View on GitHub (pinned to d32a084675)