{"record":{"id":"8d14cfaf8e7ffa37","repo":"Hmbown/CodeWhale","slug":"outbound-origin-must-use-https","errorCode":null,"errorMessage":"outbound origin must use https","messagePattern":"outbound origin must use https","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/cloud_dispatch.rs","lineNumber":1330,"sourceCode":"                        || v4.is_broadcast()\n                        || v4.is_multicast()\n                        || v4.is_documentation()\n                        || (octets[0] == 100 && (octets[1] & 0b1100_0000) == 0b0100_0000)\n                } else {\n                    v6.is_loopback()\n                        || v6.is_unspecified()\n                        || v6.is_multicast()\n                        || (v6.segments()[0] & 0xfe00) == 0xfc00\n                        || (v6.segments()[0] & 0xffc0) == 0xfe80\n                }\n            }\n        };\n        if blocked {\n            bail!(\"outbound origin must not target a loopback, private, or reserved address\");\n        }\n    }\n    if url.scheme() != \"https\" {\n        bail!(\"outbound origin must use https\");\n    }\n    Ok(url)\n}\n\n/// Meter one closed interval on a dispatched cloud job.\n///\n/// The job's sandbox id must match the provider observation. Wall-clock after\n/// create is not enough: the observation has to be provider-accepted active\n/// time bound to the immutable admission.\npub fn meter_cloud_job(\n    job: &CloudJob,\n    admission: &ComputerAdmission,\n    observation: ProviderObservation,\n) -> Result<ComputerMeterReceipt, ComputerMeterError> {\n    match job.sandbox_id.as_deref() {\n        Some(sandbox_id) if sandbox_id == observation.provider_sandbox_id => {\n            issue_computer_meter_receipt(admission, observation)\n        }","sourceCodeStart":1312,"sourceCodeEnd":1348,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/cloud_dispatch.rs#L1312-L1348","documentation":"The final check in validate_outbound_origin requires https for every origin that got this far. http is only tolerated for loopback hosts in debug builds; all public hosts must use TLS because these URLs carry credentials.","triggerScenarios":"Passing an http:// public URL (e.g. http://api.example.com) as the remote endpoint or toolbox URL after it passed the scheme/host checks.","commonSituations":"Self-hosted services fronted only by plain http; miswritten config dropping the 's'; legacy internal endpoints exposed via http proxy.","solutions":["Change the origin scheme to https:// and ensure the service terminates TLS.","Put the service behind a TLS-terminating proxy (nginx/Caddy/cloud LB) and use that URL.","Verify the exact env var/config value — an http:// default may need overriding."],"exampleFix":"// before\nexport DAYTONA_API_URL=http://api.example.com\n// after\nexport DAYTONA_API_URL=https://api.example.com","handlingStrategy":"validation","validationCode":"if raw.trim().starts_with(\"http://\") { return Err(\"use https:// for remote origins\"); }","typeGuard":null,"tryCatchPattern":"match validate_outbound_origin(raw) {\n    Err(e) if e.to_string().contains(\"must use https\") => eprintln!(\"enable TLS or put a TLS proxy in front: {raw}\"),\n    other => other?,\n}","preventionTips":["Standardize on https endpoints in all environment config.","Terminate TLS at your ingress/proxy.","Add a CI/config lint rejecting http:// origins outside loopback debug setups."],"tags":["validation","tls","https","config"],"backgroundTag":"invalid-url","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}