affaan-m/ECC · error · ValueError
source reference must be HTTPS without embedded credentials
Error message
source reference must be HTTPS without embedded credentials
What it means
In hosted (non-local_only) mode, compiled_input['source_video'] must be an HTTPS URL with a hostname and no embedded userinfo (username/password). This guard ensures the provider source reference is a secure, unambiguous remote URL and that credentials are never smuggled into the bundle.
Solutions
- Use a full https:// URL with an explicit hostname: https://cdn.example.com/source.mp4
- Remove any user:password@ userinfo from the URL and pass credentials out-of-band
- Ensure the scheme is exactly https, not http or file
- Verify with urllib.parse.urlsplit before calling: scheme=='https', hostname truthy, username and password None
Example fix
// before
{"source_video": "http://user:token@host/video.mp4"}
// after
{"source_video": "https://host/video.mp4"} Defensive patterns
Strategy: validation
Validate before calling
from urllib.parse import urlsplit
def source_url_is_safe(u):
url = urlsplit(str(u))
return url.scheme == "https" and bool(url.hostname) and not url.username and not url.password Type guard
def is_https_source(ci):
return isinstance(ci, dict) and source_url_is_safe(ci.get("source_video", "")) Try / catch
try:
bundle = build_application_bundle(cfg, ci, local_only=False)
except ValueError as e:
if "HTTPS without embedded credentials" in str(e):
ci["source_video"] = normalize_to_https(ci["source_video"]) # strip userinfo, upgrade scheme
bundle = build_application_bundle(cfg, ci, local_only=False)
else:
raise Prevention
- Store only https:// CDN URLs as source references
- Never embed tokens in URL userinfo; use headers or env vars
- Validate source_video with urlsplit at config-load time
- Reject http:// inputs at ingestion, not at bundle time
When it happens
Trigger: build_application_bundle(..., local_only=False) where compiled_input['source_video'] is http://, a bare path, an https URL containing user:pass@, or otherwise lacks a hostname.
Common situations: Pasting a local file path (file:// or /mnt/...) into source_video; using an old http:// staging URL; embedding an API token in the URL's userinfo to 'make it work'; URL-encoding artifacts leaving an empty hostname.
Understand the failure class
Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.
Related errors
- download requires HTTPS on an approved fal.media host
- download requires HTTPS on an approved fal.media host
- remote instinct imports require https URLs
- artifact must be a resident regular file
- artifact path escapes output directory
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/0468c48f33e9b1bd.
Report an issue: GitHub.
Appendix: source
Thrown at skills/taste-application/scripts/tasteforge/integration.py:352
raise ValueError("approval evidence must bind exact source, candidate and placement")
occupied.append(target)
def build_application_bundle(config: dict, compiled_input: dict | None, *, local_only: bool = False) -> dict:
"""Validate resident evidence and return a new deterministic, offline bundle."""
if type(local_only) is not bool:
raise ValueError("local_only must be an exact boolean")
_object(config, _REQUIRED, _OPTIONAL)
if len(_canonical(config)) > _MAX_JSON:
raise ValueError("application config exceeds local size limit")
if local_only:
if compiled_input is not None:
raise ValueError("local-only preservation cannot accept provider input")
else:
_object(compiled_input, {"source_video", "compiled_prompt"})
url = urlsplit(_text(compiled_input["source_video"]))
if url.scheme != "https" or not url.hostname or url.username or url.password:
raise ValueError("source reference must be HTTPS without embedded credentials")
_text(compiled_input["compiled_prompt"])
cfg = copy.deepcopy(config)
for key in ("audio", "candidates", "inserts", "historical_receipts"):
cfg.setdefault(key, [])
if not isinstance(cfg[key], list):
raise ValueError("bundle collections must be lists")
if local_only and (cfg["candidates"] or cfg["inserts"]):
raise ValueError("local-only preservation cannot contain candidates or inserts")
tracks = _snapshot(cfg["baseline"])
_binding(cfg["source"], tracks, cfg["baseline"])
audio_keys = [_binding(item, tracks, cfg["baseline"], audio=True) for item in cfg["audio"]]
expected_audio = {(t, i) for t, clips in tracks.items() if t.startswith("audio")
for i in range(len(clips))}
if len(set(audio_keys)) != len(audio_keys) or set(audio_keys) != expected_audio:
raise ValueError("every original audio clip must be preserved exactly once")
stack = _preserved_stack(cfg["protected_intervals"], tracks, cfg["baseline"]["timeline_range"])
input_hash = None if local_only else _digest(compiled_input)
edit_hash = _digest({key: cfg[key] for key in _REQUIRED})View on GitHub (pinned to 8321021c54)