BigPizzaV3/CodexPlusPlus · error · Error

API 地址须使用 HTTPS,且不含账号、密码、查询参数或片段

Error message

API 地址须使用 HTTPS,且不含账号、密码、查询参数或片段

What it means

After parsing, apiEndpoint() enforces URL hygiene: protocol must be https:, with no embedded username/password, query string, or fragment. This prevents credentials leaking in the URL and avoids ambiguity in the endpoint. Violations throw this error.

Solutions

  1. Use https:// and remove any username, password, ?query, and #fragment from the base URL.
  2. Pass the API key in the dedicated key field, never in the URL.
  3. For local testing with plain http, use an HTTPS tunnel/proxy (the check intentionally rejects http).

Example fix

// before
baseUrl = 'http://api.example.com/v1?key=abc';
// after
baseUrl = 'https://api.example.com/v1'; // key entered in the API Key field
Defensive patterns

Strategy: validation

Validate before calling

function cleanUrl(raw){ const u = new URL(String(raw).trim()); return u.protocol === 'https:' && !u.username && !u.password && !u.search && !u.hash; }

Type guard

const isCleanHttpsUrl = (s) => { try { const u = new URL(s); return u.protocol === 'https:' && !u.username && !u.password && !u.search && !u.hash; } catch { return false; } };

Try / catch

try { endpoint = apiEndpoint(raw); } catch (e) { if (e.message.includes('HTTPS')) instructUserToUseKeyField(); }

Prevention

When it happens

Trigger: baseUrl uses http:// (not https), contains user:pass@, or carries ?query or #fragment — e.g. pasting a URL that already includes ?api-key=... or a #section anchor.

Common situations: User pasted a URL with an API key query parameter (a security anti-pattern the check blocks); used a local http:// dev endpoint; included an anchor copied from docs.

Understand the failure class

Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.

Related errors


AI-assisted analysis of BigPizzaV3/CodexPlusPlus@b1ed92e5e4 (2026-09-19). Data as JSON: /api/errors/450f2579e0abc9a4. Report an issue: GitHub.

Appendix: source

Thrown at tools/conversation-canvas/public/canvas.user.js:623

  for(;;){
    signal?.throwIfAborted();
    const conversation=manager.getConversation(session.sideId);
    if(!conversation)throw Error('后台整理会话已失效,已完成批次仍保留;点击继续可重新处理本批');
    const turn=nativeTurns(conversation).find(t=>t.turnId===session.turnId);
    if(turn&&turn.status!=='inProgress'){
      if(turn.status!=='completed'||turn.error){session.requestId=null;session.turnId=null;session.phase='ready';await save();throw Error('本批整理中断,已完成批次已保存,可点击继续');}
      if(session.phase!=='completed')session.batches=(session.batches||0)+1;
      session.phase='completed';await save();
      return turn.items.filter(i=>i.type==='agentMessage'&&(i.phase==null||i.phase==='final_answer')).map(i=>i.text??'').join('\n');
    }
    await new Promise(resolve=>setTimeout(resolve,1000));
  }
}

  // OpenAI-compatible Chat Completions. Never persist credentials in tree checkpoints.
function apiEndpoint(raw){
  let url;try{url=new URL(String(raw).trim());}catch{throw Error('请输入完整的 HTTPS API 地址');}
  if(url.protocol!=='https:'||url.username||url.password||url.search||url.hash)throw Error('API 地址须使用 HTTPS,且不含账号、密码、查询参数或片段');
  const path=url.pathname.replace(/\/+$/,'');
  url.pathname=path.endsWith('/chat/completions')?path:(path||'/v1')+'/chat/completions';
  return url.href;
}

function apiConfig(input){
  const channel=input?.channel==='external'?'external':'native';
  const value={channel,baseUrl:String(input?.baseUrl||'').trim(),model:String(input?.model||'').trim(),key:String(input?.key||'').trim(),remember:input?.remember===true,speed:input?.speed==='provider'?'provider':'fast',revision:input?.revision||crypto.randomUUID()};
  if(channel==='external'){
    value.endpoint=apiEndpoint(value.baseUrl);
    if(!value.model||value.model.length>200)throw Error('请填写 API 的模型名称');
    if(!value.key||/[\r\n]/.test(value.key))throw Error('请在设置中填写有效 API Key');
  }
  return value;
}

function storedApiConfig(config){
  const {channel,baseUrl,model,remember,speed,revision}=config;

View on GitHub (pinned to b1ed92e5e4)