affaan-m/ECC · error · ValueError
must be an HTTPS URL without embedded credentials
Error message
{name} must be an HTTPS URL without embedded credentials What it means
https_url() validates that a value is an HTTPS URL with a hostname and no embedded userinfo (username/password). Anything with a scheme other than https, no hostname, or credentials in the URL raises this ValueError. This guards graph input against accidental HTTP and credential leakage in URLs.
Solutions
- Change the URL scheme to https://
- Remove any username:password@ userinfo from the URL and use headers/secrets instead
- Verify the URL parses with a hostname: use urllib.parse.urlsplit in a pre-check
Example fix
// before 'reference_1': 'https://user:secret@cdn.example.com/ref.mp4' // after 'reference_1': 'https://cdn.example.com/ref.mp4'
Defensive patterns
Strategy: validation
Validate before calling
from urllib.parse import urlsplit
def ensure_https_url(value, name):
p = urlsplit(value)
if p.scheme != 'https' or not p.hostname or p.username or p.password:
raise ValueError(f'{name} must be an HTTPS URL without embedded credentials') Type guard
def is_safe_https_url(v) -> bool:
p = urlsplit(v) if isinstance(v, str) else None
return bool(p and p.scheme == 'https' and p.hostname and not p.username and not p.password) Try / catch
try:
graph_input = prepare_distillation_input(config)
except ValueError as e:
if 'HTTPS URL' in str(e):
print(f'Bad reference URL: {e}')
else:
raise Prevention
- Always serve reference media over HTTPS; update http:// internal links
- Strip credentials from URLs before they enter config; pass secrets via headers instead
- Sanitize copy-pasted URLs (strip user:pass@ inserted by proxies)
When it happens
Trigger: Passing 'http://...' (not https), 'ftp://...', a bare hostname like 'example.com/video.mp4' (no scheme so scheme != 'https'), or 'https://user:pass@host/...' to compile_application_input or prepare_distillation_input.
Common situations: Dev/staging URLs still using http; URLs copy-pasted with embedded basic-auth credentials from a proxy or internal tool; relative or scheme-less URLs from user input.
Understand the failure class
Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.
Related errors
- download requires HTTPS on an approved fal.media host
- invalid Discord webhook URL
- Invalid managed hook handler at
- -32602
- a claim token is required
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/f503253959062ae4.
Report an issue: GitHub.
Appendix: source
Thrown at skills/taste-application/scripts/workflow_graphs.py:26
WORKFLOWS = Path(__file__).resolve().parents[1] / 'workflows'
NEUTRAL_GRADE = (
'Colour: none. Render neutral. Grading is applied afterwards - do not '
'attempt any colour styling, tint, or cast. This colour rule takes precedence '
'over conflicting style direction; preserve structure, lighting and motion.'
)
def nonempty(value, name):
if not isinstance(value, str) or not value.strip():
raise ValueError(f'{name} must be a nonempty string')
return value.strip()
def https_url(value, name):
value = nonempty(value, name)
parsed = urlsplit(value)
if parsed.scheme != 'https' or not parsed.hostname or parsed.username or parsed.password:
raise ValueError(f'{name} must be an HTTPS URL without embedded credentials')
return value
def compile_application_input(config):
"""Source video contains the user's content; taste affects the HOW section."""
return {
'source_video': https_url(config.get('source_video'), 'source_video'),
'compiled_prompt': '\n\n'.join((
'WHAT - content and action:\n' + nonempty(config.get('brief'), 'brief'),
'HOW - structure, lighting and motion:\n' + nonempty(config.get('style_steer'), 'style_steer'),
'GRADE - mandatory postproduction boundary:\n' + NEUTRAL_GRADE,
)),
}
def prepare_distillation_input(config):
"""Require externally measured grounding; never invent numerical evidence."""
genre = nonempty(config.get('genre'), 'genre')View on GitHub (pinned to 8321021c54)