{"record":{"id":"03e704daa72434f4","repo":"santifer/career-ops","slug":"agentic-jobs-url-must-use-https-url","errorCode":null,"errorMessage":"agentic-jobs: URL must use HTTPS: ${url}","messagePattern":"agentic-jobs: URL must use HTTPS: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"providers/agentic-jobs.mjs","lineNumber":47,"sourceCode":"// Wire in via a `job_boards:` entry with `provider: agentic-jobs`.\n\nconst SITE_ORIGIN = 'https://agentic-engineering-jobs.com';\nconst API_BASE = `${SITE_ORIGIN}/api/v1`;\nconst TRUSTED_HOST = 'agentic-engineering-jobs.com';\nconst PAGE_SIZE = 50; // fixed by the API (meta.per_page)\nconst MAX_PAGES = 40; // safety cap on request count (40*50 = 2000 postings)\nconst MAX_JOBS = 2000;\nconst PAGE_DELAY_MS = 2100; // stays under the documented 30 req/60s limit\n\n/** @param {string} url */\nfunction assertAgenticUrl(url) {\n  let parsed;\n  try {\n    parsed = new URL(url);\n  } catch {\n    throw new Error(`agentic-jobs: invalid URL: ${url}`);\n  }\n  if (parsed.protocol !== 'https:') throw new Error(`agentic-jobs: URL must use HTTPS: ${url}`);\n  if (parsed.hostname !== TRUSTED_HOST) {\n    throw new Error(`agentic-jobs: untrusted hostname \"${parsed.hostname}\" — must be ${TRUSTED_HOST}`);\n  }\n  return url;\n}\n\nconst regionNames = new Intl.DisplayNames(['en'], { type: 'region' });\n\n/**\n * Resolve a two-letter ISO country code to an English name. Returns '' for\n * anything that isn't a resolvable two-letter code. Exported for tests.\n * @param {unknown} code\n */\nexport function countryName(code) {\n  if (typeof code !== 'string' || !/^[A-Za-z]{2}$/.test(code)) return '';\n  try {\n    const name = regionNames.of(code.toUpperCase());\n    return name && name !== code.toUpperCase() ? name : '';","sourceCodeStart":29,"sourceCodeEnd":65,"githubUrl":"https://github.com/santifer/career-ops/blob/aac998c7ed7248ea853b720ceeb1fdbeb322fc5d/providers/agentic-jobs.mjs#L29-L65","documentation":"assertAgenticUrl in providers/agentic-jobs.mjs throws this when the URL parses but its protocol is not 'https:'. The agentic-jobs provider refuses to fetch over plaintext, so any http:// (or other non-HTTPS scheme) URL is rejected before the hostname check runs. Only valid HTTPS URLs proceed to the TRUSTED_HOST comparison.","triggerScenarios":"Passing an 'http://...' URL (or ftp:/file: etc.) to the provider — typically a config default or legacy feed link that was never upgraded to HTTPS.","commonSituations":"Old bookmarks/config using http://; local development servers over plain HTTP being tested against the provider; YAML config written without the scheme and another layer prepending 'http://'.","solutions":["Change the scheme to https:// and retry.","If the target host has no HTTPS, it is unsupported — use the provider's official HTTPS feed endpoint.","Enable TLS on the feed server if you control it, then update the config.","Grep your config for hardcoded http:// schemes and normalize them."],"exampleFix":"// before\nfetchAgenticJobs('http://agenticjobs.dev/api')\n// after\nfetchAgenticJobs('https://agenticjobs.dev/api')","handlingStrategy":"validation","validationCode":"const u = new URL(rawUrl);\nif (u.protocol !== 'https:') throw new Error(`agentic-jobs feed URL must use https, got ${u.protocol}`);","typeGuard":"function isHttpsUrl(s) {\n  try { return new URL(s).protocol === 'https:'; } catch { return false; }\n}","tryCatchPattern":"try {\n  await fetchAgenticJobs(url);\n} catch (e) {\n  if (String(e.message).includes('URL must use HTTPS')) {\n    const fixed = url.replace(/^http:/, 'https:');\n    console.warn(`Upgrading ${url} -> ${fixed}`);\n    return fetchAgenticJobs(fixed);\n  } else throw e;\n}","preventionTips":["Normalize feed URL schemes to https:// when loading config.","Do not configure providers against plain-HTTP endpoints.","Add an automated check that rejects http:// URLs in provider config files."],"tags":["url-validation","https","security","provider"],"backgroundTag":"invalid-url","analyzedSha":"aac998c7ed7248ea853b720ceeb1fdbeb322fc5d","analyzedAt":"2026-09-16T06:35:29.214Z","contentChangedAt":"2026-09-16T06:35:29.214Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}