BigPizzaV3/CodexPlusPlus · error · Error
API 地址须使用 HTTPS,且不含账号、密码、查询参数或片段
Error message
API 地址须使用 HTTPS,且不含账号、密码、查询参数或片段
What it means
After parsing, apiEndpoint() enforces URL hygiene: protocol must be https:, with no embedded username/password, query string, or fragment. This prevents credentials leaking in the URL and avoids ambiguity in the endpoint. Violations throw this error.
Solutions
- Use https:// and remove any username, password, ?query, and #fragment from the base URL.
- Pass the API key in the dedicated key field, never in the URL.
- For local testing with plain http, use an HTTPS tunnel/proxy (the check intentionally rejects http).
Example fix
// before baseUrl = 'http://api.example.com/v1?key=abc'; // after baseUrl = 'https://api.example.com/v1'; // key entered in the API Key field
Defensive patterns
Strategy: validation
Validate before calling
function cleanUrl(raw){ const u = new URL(String(raw).trim()); return u.protocol === 'https:' && !u.username && !u.password && !u.search && !u.hash; } Type guard
const isCleanHttpsUrl = (s) => { try { const u = new URL(s); return u.protocol === 'https:' && !u.username && !u.password && !u.search && !u.hash; } catch { return false; } }; Try / catch
try { endpoint = apiEndpoint(raw); } catch (e) { if (e.message.includes('HTTPS')) instructUserToUseKeyField(); } Prevention
- Never embed credentials or API keys in the URL; use the dedicated key field.
- Strip query strings and fragments before saving provider base URLs.
- Prefer providers' HTTPS endpoints; tunnel local http services through HTTPS for testing.
When it happens
Trigger: baseUrl uses http:// (not https), contains user:pass@, or carries ?query or #fragment — e.g. pasting a URL that already includes ?api-key=... or a #section anchor.
Common situations: User pasted a URL with an API key query parameter (a security anti-pattern the check blocks); used a local http:// dev endpoint; included an anchor copied from docs.
Understand the failure class
Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.
Related errors
- API 地址须使用 HTTPS,且不含账号、密码、查询参数或片段
- Base URL 必须使用 HTTPS
- 链接缺少解密密钥。请使用完整的分享链接。
- Base URL 不能为空
- 上游 Base URL 不能为空
AI-assisted analysis of BigPizzaV3/CodexPlusPlus@b1ed92e5e4 (2026-09-19).
Data as JSON: /api/errors/450f2579e0abc9a4.
Report an issue: GitHub.
Appendix: source
Thrown at tools/conversation-canvas/public/canvas.user.js:623
for(;;){
signal?.throwIfAborted();
const conversation=manager.getConversation(session.sideId);
if(!conversation)throw Error('后台整理会话已失效,已完成批次仍保留;点击继续可重新处理本批');
const turn=nativeTurns(conversation).find(t=>t.turnId===session.turnId);
if(turn&&turn.status!=='inProgress'){
if(turn.status!=='completed'||turn.error){session.requestId=null;session.turnId=null;session.phase='ready';await save();throw Error('本批整理中断,已完成批次已保存,可点击继续');}
if(session.phase!=='completed')session.batches=(session.batches||0)+1;
session.phase='completed';await save();
return turn.items.filter(i=>i.type==='agentMessage'&&(i.phase==null||i.phase==='final_answer')).map(i=>i.text??'').join('\n');
}
await new Promise(resolve=>setTimeout(resolve,1000));
}
}
// OpenAI-compatible Chat Completions. Never persist credentials in tree checkpoints.
function apiEndpoint(raw){
let url;try{url=new URL(String(raw).trim());}catch{throw Error('请输入完整的 HTTPS API 地址');}
if(url.protocol!=='https:'||url.username||url.password||url.search||url.hash)throw Error('API 地址须使用 HTTPS,且不含账号、密码、查询参数或片段');
const path=url.pathname.replace(/\/+$/,'');
url.pathname=path.endsWith('/chat/completions')?path:(path||'/v1')+'/chat/completions';
return url.href;
}
function apiConfig(input){
const channel=input?.channel==='external'?'external':'native';
const value={channel,baseUrl:String(input?.baseUrl||'').trim(),model:String(input?.model||'').trim(),key:String(input?.key||'').trim(),remember:input?.remember===true,speed:input?.speed==='provider'?'provider':'fast',revision:input?.revision||crypto.randomUUID()};
if(channel==='external'){
value.endpoint=apiEndpoint(value.baseUrl);
if(!value.model||value.model.length>200)throw Error('请填写 API 的模型名称');
if(!value.key||/[\r\n]/.test(value.key))throw Error('请在设置中填写有效 API Key');
}
return value;
}
function storedApiConfig(config){
const {channel,baseUrl,model,remember,speed,revision}=config;View on GitHub (pinned to b1ed92e5e4)