{"record":{"id":"3a3eb400836c04a9","repo":"santifer/career-ops","slug":"glints-url-must-use-https-url","errorCode":null,"errorMessage":"glints: URL must use HTTPS: ${url}","messagePattern":"glints: URL must use HTTPS: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"providers/glints.mjs","lineNumber":77,"sourceCode":"        minAmount\n        CurrencyCode\n      }\n      createdAt\n    }\n    expInfo\n    hasMore\n  }\n}`;\n\n/** @param {string} url */\nfunction assertGlintsUrl(url) {\n  let parsed;\n  try {\n    parsed = new URL(url);\n  } catch {\n    throw new Error(`glints: invalid URL: ${url}`);\n  }\n  if (parsed.protocol !== 'https:') throw new Error(`glints: URL must use HTTPS: ${url}`);\n  if (!ALLOWED_GLINTS_HOSTS.has(parsed.hostname))\n    throw new Error(`glints: untrusted hostname \"${parsed.hostname}\" — must be one of: ${[...ALLOWED_GLINTS_HOSTS].join(', ')}`);\n  return url;\n}\n\n// NaN-safe Date.parse\nfunction toEpochMs(value) {\n  if (!value) return undefined;\n  const parsed = Date.parse(value);\n  return Number.isNaN(parsed) ? undefined : parsed;\n}\n\n/**\n * Derive the job detail base URL from the API hostname.\n * @param {string} apiUrl\n * @returns {string}\n */\nfunction deriveBaseUrl(apiUrl) {","sourceCodeStart":59,"sourceCodeEnd":95,"githubUrl":"https://github.com/santifer/career-ops/blob/aac998c7ed7248ea853b720ceeb1fdbeb322fc5d/providers/glints.mjs#L59-L95","documentation":"assertGlintsUrl enforces HTTPS on every URL it validates. If the URL parses but parsed.protocol is not 'https:' (typically http://), the function throws this error. This keeps all Glints GraphQL traffic encrypted and consistent with the provider's security posture.","triggerScenarios":"A glints entry's api (or other validated URL) is configured as 'http://glints.com/api/v2-alc/graphql' — a valid URL with a non-HTTPS scheme — and reaches the protocol check in assertGlintsUrl.","commonSituations":"Defaulting to http while hand-writing config; an internal proxy URL written with http; copying an insecure link from documentation or logs.","solutions":["Change the scheme to https:// in the entry's api value","If you were pointing at a plain-HTTP local proxy, remove the override and use the default https endpoint instead, or terminate TLS on the proxy","Re-run after fixing — the hostname allowlist check comes next and may surface a further issue"],"exampleFix":"// before\napi: http://glints.com/api/v2-alc/graphql\n// after\napi: https://glints.com/api/v2-alc/graphql","handlingStrategy":"validation","validationCode":"if (entry.api) {\n  const u = new URL(entry.api);\n  if (u.protocol !== 'https:') throw new Error(`glints entry ${entry.name}: api must use https:// (got ${u.protocol})`);\n}","typeGuard":"function isHttpsUrl(v) { try { return new URL(v).protocol === 'https:'; } catch { return false; } }","tryCatchPattern":"try {\n  assertGlintsUrl(url);\n} catch (e) {\n  if (String(e.message).includes('must use HTTPS')) {\n    console.error(`Upgrade ${url} to https:// — plain HTTP is rejected by the glints provider`);\n  }\n  throw e;\n}","preventionTips":["Write https:// by default for all api/careers URL config values","Search config for http:// endpoints before committing","Remember local dev proxies must also terminate TLS or use the default https endpoint"],"tags":["https","url-validation","security","glints"],"backgroundTag":"invalid-url","analyzedSha":"aac998c7ed7248ea853b720ceeb1fdbeb322fc5d","analyzedAt":"2026-09-16T06:35:29.214Z","contentChangedAt":"2026-09-16T06:35:29.214Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}