{"record":{"id":"0c3f3e800f2dd185","repo":"santifer/career-ops","slug":"smartrecruiters-url-must-use-https-url","errorCode":null,"errorMessage":"smartrecruiters: URL must use HTTPS: ${url}","messagePattern":"smartrecruiters: URL must use HTTPS: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"providers/smartrecruiters.mjs","lineNumber":72,"sourceCode":"  const sections = detail?.jobAd?.sections;\n  if (!sections || typeof sections !== 'object') return '';\n  const parts = [];\n  for (const key of ['companyDescription', 'jobDescription', 'qualifications', 'additionalInformation']) {\n    const text = sections[key]?.text;\n    if (typeof text === 'string' && text.trim()) parts.push(text);\n  }\n  if (parts.length === 0) return '';\n  return htmlToText(parts.join('\\n'));\n}\n\nfunction assertSmartRecruitersUrl(url) {\n  let parsed;\n  try {\n    parsed = new URL(url);\n  } catch {\n    throw new Error(`smartrecruiters: invalid URL: ${url}`);\n  }\n  if (parsed.protocol !== 'https:') throw new Error(`smartrecruiters: URL must use HTTPS: ${url}`);\n  if (!ALLOWED_SMARTRECRUITERS_HOSTS.has(parsed.hostname)) {\n    throw new Error(`smartrecruiters: untrusted hostname \"${parsed.hostname}\" — must be one of: ${[...ALLOWED_SMARTRECRUITERS_HOSTS].join(', ')}`);\n  }\n  return url;\n}\n\nfunction resolveSlug(entry) {\n  // entry.api takes precedence over careers_url (mirrors greenhouse/ashby) so a\n  // branded page (e.g. https://jobs.continental.com) can stay as careers_url\n  // while the SmartRecruiters slug is pinned via\n  // api: https://careers.smartrecruiters.com/<slug> in portals.yml.\n  for (const raw of [entry.api, entry.careers_url]) {\n    if (typeof raw !== 'string' || !raw) continue;\n    let parsed;\n    try {\n      parsed = new URL(raw);\n    } catch {\n      continue;","sourceCodeStart":54,"sourceCodeEnd":90,"githubUrl":"https://github.com/santifer/career-ops/blob/aac998c7ed7248ea853b720ceeb1fdbeb322fc5d/providers/smartrecruiters.mjs#L54-L90","documentation":"assertSmartRecruitersUrl enforces HTTPS: any URL with a protocol other than https: (typically http:) is rejected. The SmartRecruiters provider only talks to the TLS-protected api.smartrecruiters.com endpoint, so plaintext URLs are refused both for security and because the plain-HTTP endpoint would not resolve correctly anyway.","triggerScenarios":"Configuring an api or careers_url with http:// instead of https:// and having that raw URL reach assertSmartRecruitersUrl; calling the validator directly in tests or tooling with an http:// URL.","commonSituations":"Hand-editing portals.yml and typing http:// out of habit; copying an internal staging URL that uses plain HTTP; an old config written before an HTTPS migration; proxy tooling rewriting the scheme.","solutions":["Change the scheme to https:// in the configured URL","Check portals.yml for http:// occurrences of smartrecruiters hosts and correct them","Use the provider's buildPostingsUrl helper, which always emits https://","Note resolveSlug() silently skips non-HTTPS entries — if your careers_url is http://, slug derivation fails; fix the scheme rather than expecting a fallback"],"exampleFix":"// before\ncareers_url: 'http://careers.smartrecruiters.com/acme'\n// after\ncareers_url: 'https://careers.smartrecruiters.com/acme'","handlingStrategy":"validation","validationCode":"function isHttpsUrl(url) {\n  try { return new URL(url).protocol === 'https:'; } catch { return false; }\n}\nif (!isHttpsUrl(entry.api ?? entry.careers_url)) throw new Error('smartrecruiters URLs must use https://');","typeGuard":null,"tryCatchPattern":"try {\n  await srProvider.fetch(entry, ctx);\n} catch (e) {\n  if (String(e.message).includes('must use HTTPS')) {\n    console.error(`Entry ${entry.name}: switch ${entry.api ?? entry.careers_url} to https://`);\n  } else throw e;\n}","preventionTips":["Grep portals.yml for 'http://' periodically and fix to https://","Adopt https as the only accepted scheme in config validation","Remember resolveSlug silently skips non-HTTPS inputs — a http careers_url also causes slug-derivation errors downstream","Keep redirect:'error' so TLS downgrade via redirect cannot happen silently"],"tags":["url-validation","https","security","config-error"],"backgroundTag":"invalid-url","analyzedSha":"aac998c7ed7248ea853b720ceeb1fdbeb322fc5d","analyzedAt":"2026-09-16T06:35:29.214Z","contentChangedAt":"2026-09-16T06:35:29.214Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}