# "Contradictory scheme headers" error after testing upgrading from Django 1.11 to 4.0.10

**URL:** <https://forum.djangoproject.com/t/contradictory-scheme-headers-error-after-testing-upgrading-from-django-1-11-to-4-0-10/41136>\
**Category:** Deployment\
**Created:** [May 28, 2025, 8:46am UTC](https://forum.djangoproject.com/t/contradictory-scheme-headers-error-after-testing-upgrading-from-django-1-11-to-4-0-10/41136 "2025-05-28T08:46:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![G47](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/g47/32/19613_2.png) [@G47](https://forum.djangoproject.com/u/G47)\
**Post date:** [May 28, 2025, 8:46am UTC](https://forum.djangoproject.com/t/contradictory-scheme-headers-error-after-testing-upgrading-from-django-1-11-to-4-0-10/41136/1 "2025-05-28T08:46:40Z")

</div>

Hi everyone,

I’m still quite new to Django and server configurations, so I hope this question makes sense.

I’m currently testing a Django 4.0.10 deployment behind Nginx and Gunicorn. I noticed that when accessing the server via `http://ip/testapi`, Django returns this error:

> **Bad Request: Contradictory scheme headers**

Interestingly, I have an older dev server running Django 1.11 with exactly the same Nginx configuration and the same value for `SECURE_PROXY_SSL_HEADER`:

```python
SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')

```

The Nginx config includes:

```nginx
proxy_set_header X-Forwarded-Proto "https";

```

Both servers are accessed via plain HTTP (not HTTPS), yet only the newer Django version returns this error.

My questions are:

1. Is this error caused by new behavior introduced in Django itself?
2. In which version was this “Contradictory scheme headers” check added?

I’d really appreciate any explanation, even in simple terms, or pointers to documentation. Thank you so much in advance for your help!

---

<div class="post-metadata">

**Author:** ![carltongibson](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/carltongibson/32/267_2.png) [@carltongibson](https://forum.djangoproject.com/u/carltongibson)\
**Post date:** [May 28, 2025, 9:28am UTC](https://forum.djangoproject.com/t/contradictory-scheme-headers-error-after-testing-upgrading-from-django-1-11-to-4-0-10/41136/2 "2025-05-28T09:28:55Z")

</div>

> [@G47](#):
>
> Bad Request: Contradictory scheme headers

This is [a gunicorn error](https://github.com/benoitc/gunicorn/blob/a86ea1e4e6c271d1cd1823c7e14490123f9238fe/gunicorn/http/errors.py#L143), not a Django one.

This issue discusses the problem:

> <https://github.com/benoitc/gunicorn/issues/1857>
>
> see #1766 for some people having the same issue
> 
> I have the following in my ng…inx config:
> \`\`\`
> proxy\_set\_header X-Forwarded-Proto $scheme;
> proxy\_set\_header X-Forwarded-Protocol $scheme;
> \`\`\`
> 
> This causes an error because the default setting for \`secure\_scheme\_headers\` is \`{'X-FORWARDED-PROTOCOL': 'ssl', 'X-FORWARDED-PROTO': 'https', 'X-FORWARDED-SSL': 'on'}\`. When it compares the \`ssl\` to the \`https\` the error is thrown in https://github.com/benoitc/gunicorn/blob/19.9.0/gunicorn/http/message.py#L118
