{"record":{"id":"16670af8b234ef7d","repo":"santifer/career-ops","slug":"a16z-speedrun-talent-url-must-use-https-url","errorCode":null,"errorMessage":"a16z-speedrun-talent: URL must use HTTPS: ${url}","messagePattern":"a16z-speedrun-talent: URL must use HTTPS: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"providers/a16z-speedrun-talent.mjs","lineNumber":47,"sourceCode":"const DEFAULT_MAX_PAGES = 6; // × PER_PAGE = the 300-job default scan\n// Runaway bound, not a coverage target: iteration already stops at the\n// feed's reported total_pages (or, when the feed omits it, a short page), so\n// on an honest feed the cap costs nothing and full-board sweeps keep working\n// as the board grows.\n// It only bites a misbehaving feed or an absurd max_pages entry — so it\n// sits well above plausible board size (~353 pages / ~17.6k jobs as of\n// 2026-08), same policy as workday.mjs's cap.\nconst MAX_PAGES_CAP = 1000;\n\n/** @param {string} url */\nfunction assertFeedUrl(url) {\n  let parsed;\n  try {\n    parsed = new URL(url);\n  } catch {\n    throw new Error(`a16z-speedrun-talent: invalid URL: ${url}`);\n  }\n  if (parsed.protocol !== 'https:') throw new Error(`a16z-speedrun-talent: URL must use HTTPS: ${url}`);\n  if (parsed.hostname !== TRUSTED_HOST) {\n    throw new Error(`a16z-speedrun-talent: untrusted hostname \"${parsed.hostname}\" — must be ${TRUSTED_HOST}`);\n  }\n  return url;\n}\n\n/** Resolve the page cap: a positive integer `max_pages` on the entry, capped. */\nfunction resolveMaxPages(entry) {\n  const v = entry?.max_pages;\n  if (Number.isInteger(v) && v > 0) return Math.min(v, MAX_PAGES_CAP);\n  return DEFAULT_MAX_PAGES;\n}\n\n/** Optional server-side query: `q:` on the entry, else joined `keywords:`. */\nfunction resolveQuery(entry) {\n  if (typeof entry?.q === 'string' && entry.q.trim()) return entry.q.trim();\n  if (Array.isArray(entry?.keywords) && entry.keywords.length > 0) {\n    const joined = entry.keywords.filter((k) => typeof k === 'string' && k.trim()).join(' ').trim();","sourceCodeStart":29,"sourceCodeEnd":65,"githubUrl":"https://github.com/santifer/career-ops/blob/aac998c7ed7248ea853b720ceeb1fdbeb322fc5d/providers/a16z-speedrun-talent.mjs#L29-L65","documentation":"assertFeedUrl in providers/a16z-speedrun-talent.mjs throws this when the URL parses but its protocol is not 'https:'. The provider only talks to HTTPS feeds, refusing plaintext HTTP to protect the integrity and confidentiality of fetched job data. Hostname checking happens after this, so this throw fires for any validly-parsed non-HTTPS URL regardless of host.","triggerScenarios":"Calling the provider with an http:// URL (or ftp:, file:, etc.) — e.g. a portals.yml careers_url written as 'http://...' or a URL built from an untyped scheme variable.","commonSituations":"Older feed links that predate HTTPS migration; hand-written config defaults using http://; internal test servers served over plain HTTP being pointed at the provider.","solutions":["Change the URL scheme to https:// and retry.","If the host only serves HTTP, it is unsupported — use the official HTTPS feed endpoint.","If you control the feed, enable HTTPS on the server and update the config.","Search your config for hardcoded http:// scheme strings and normalize them to https://."],"exampleFix":"// before\nfetchSpeedrunFeed('http://example.com/api/jobs')\n// after\nfetchSpeedrunFeed('https://example.com/api/jobs')","handlingStrategy":"validation","validationCode":"const u = new URL(rawUrl);\nif (u.protocol !== 'https:') throw new Error(`feed URL must use https, got ${u.protocol}`);","typeGuard":"function isHttpsUrl(s) {\n  try { return new URL(s).protocol === 'https:'; } catch { return false; }\n}","tryCatchPattern":"try {\n  await fetchSpeedrunFeed(url);\n} catch (e) {\n  if (String(e.message).includes('URL must use HTTPS')) {\n    const fixed = url.replace(/^http:/, 'https:');\n    console.warn(`Upgrading ${url} -> ${fixed}`);\n    return fetchSpeedrunFeed(fixed);\n  } else throw e;\n}","preventionTips":["Normalize all configured feed URLs to https:// at config load time.","Never point providers at plain-HTTP test servers in shared config.","Add a lint/check that no http:// URLs appear in portals/config files."],"tags":["url-validation","https","security","provider"],"backgroundTag":"invalid-url","analyzedSha":"aac998c7ed7248ea853b720ceeb1fdbeb322fc5d","analyzedAt":"2026-09-16T06:35:29.214Z","contentChangedAt":"2026-09-16T06:35:29.214Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}