{"record":{"id":"1b346f58bb959cb0","repo":"santifer/career-ops","slug":"collage-url-must-use-https-url","errorCode":null,"errorMessage":"collage: URL must use HTTPS: ${url}","messagePattern":"collage: URL must use HTTPS: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"providers/collage.mjs","lineNumber":17,"sourceCode":"// @ts-check\n/** @typedef {import('./_types.js').Provider} Provider */\n\n// Collage HR public job-site API.  A job-site address is an explicit tenant\n// identifier, not a company-name slug we should guess.  Entries may provide\n// the exact API URL or a public Collage careers URL from which the final path\n// segment is read.\n\nconst API_ORIGIN = 'https://api.collage.co';\nconst COLLAGE_API_HOST = 'api.collage.co';\nconst COLLAGE_SITE_HOST_RE = /^secure\\.collage\\.co$/;\n\n/** @param {string} url */\nfunction assertCollageApiUrl(url) {\n  let parsed;\n  try { parsed = new URL(url); } catch { throw new Error(`collage: invalid URL: ${url}`); }\n  if (parsed.protocol !== 'https:') throw new Error(`collage: URL must use HTTPS: ${url}`);\n  if (parsed.hostname !== COLLAGE_API_HOST) {\n    throw new Error(`collage: untrusted hostname \"${parsed.hostname}\" — must be ${COLLAGE_API_HOST}`);\n  }\n  if (!/^\\/v1\\/positions\\/[^/?#]+$/.test(parsed.pathname)) {\n    throw new Error(`collage: API URL must be /v1/positions/<job-site-address>: ${url}`);\n  }\n  return url;\n}\n\n/** @param {import('./_types.js').PortalEntry} entry */\nfunction resolveApiUrl(entry) {\n  const explicit = typeof entry.api === 'string' ? entry.api.trim() : '';\n  if (explicit) return assertCollageApiUrl(explicit);\n\n  const raw = typeof entry.careers_url === 'string' ? entry.careers_url.trim() : '';\n  if (!raw) return null;\n  let parsed;\n  try { parsed = new URL(raw); } catch { return null; }","sourceCodeStart":1,"sourceCodeEnd":35,"githubUrl":"https://github.com/santifer/career-ops/blob/aac998c7ed7248ea853b720ceeb1fdbeb322fc5d/providers/collage.mjs#L1-L35","documentation":"assertCollageApiUrl requires every explicitly configured Collage API URL to use the https: protocol; the provider refuses to issue plaintext HTTP requests to the API host. This error fires when the parsed URL is valid but its protocol is http: (or anything other than https:).","triggerScenarios":"A portals.yml entry has `api: http://api.collage.co/v1/positions/<site>` — http scheme instead of https. Any other scheme (ftp:, ws:) would hit the same check.","commonSituations":"Typing http:// out of habit; migrating an entry from a local dev mock URL; a config generator that templates scheme://host with the wrong scheme.","solutions":["Change the scheme to https:// in the `api:` field of the portals.yml entry","Re-run the scan to confirm the entry is picked up","Never downgrade to http — Collage's API host serves HTTPS only"],"exampleFix":"# before (portals.yml)\napi: http://api.collage.co/v1/positions/acme\n# after\napi: https://api.collage.co/v1/positions/acme","handlingStrategy":"validation","validationCode":"// Ensure HTTPS before handing the URL to the provider\nfunction isHttpsUrl(v) {\n  try { return new URL(v).protocol === 'https:'; } catch { return false; }\n}\nif (!isHttpsUrl(entry.api)) throw new Error(`${entry.name}: api must use https://`);\n","typeGuard":"function isHttpsCollageApi(v) {\n  try { const u = new URL(v); return u.protocol === 'https:' && u.hostname === 'api.collage.co'; }\n  catch { return false; }\n}","tryCatchPattern":"try {\n  const jobs = await collageProvider.fetch(entry, ctx);\n} catch (err) {\n  if (String(err.message).includes('URL must use HTTPS')) {\n    console.error(`Upgrade ${entry.api} to https:// in portals.yml`);\n  } else { throw err; }\n}","preventionTips":["Never author config with http:// — default every careers/API URL to https://","Add a pre-flight check that rejects non-HTTPS URLs when loading portals.yml","Remember the scheme check runs before the hostname check, so fix http->https first"],"tags":["url-validation","https","security"],"backgroundTag":"invalid-url-format","analyzedSha":"aac998c7ed7248ea853b720ceeb1fdbeb322fc5d","analyzedAt":"2026-09-16T06:35:29.214Z","contentChangedAt":"2026-09-16T06:35:29.214Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}