{"record":{"id":"cec5174de6ec26ae","repo":"santifer/career-ops","slug":"oraclecloud-url-must-use-https-url","errorCode":null,"errorMessage":"oraclecloud: URL must use HTTPS: ${url}","messagePattern":"oraclecloud: URL must use HTTPS: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"providers/oraclecloud.mjs","lineNumber":68,"sourceCode":"const ORACLE_HOST_RE = /^[a-z0-9-]+\\.fa\\.(?:[a-z0-9-]+\\.)?(?:ocs\\.)?oraclecloud(?:[1-9][0-9]?)?\\.com$/i;\n\nconst PAGE_SIZE = 200;\nconst MAX_PAGES = 25;             // safety cap (~5000 jobs); hard ceiling like workday\nconst RETRY_POLICY = { retries: 3 };\nconst INTER_PAGE_DELAY_MS = 250;  // WAF-aware spacing between same-host pages\n\n// facetsList is a fixed constant on the finder; %3B is the encoded ';' separator.\nconst FACETS_LIST = 'LOCATIONS%3BWORK_LOCATIONS%3BWORKPLACE_TYPES%3BTITLES%3BCATEGORIES%3BORGANIZATIONS%3BPOSTING_DATES%3BFLEX_FIELDS';\n\n/** @param {string} url */\nfunction assertOracleUrl(url) {\n  let parsed;\n  try {\n    parsed = new URL(url);\n  } catch {\n    throw new Error(`oraclecloud: invalid URL: ${url}`);\n  }\n  if (parsed.protocol !== 'https:') throw new Error(`oraclecloud: URL must use HTTPS: ${url}`);\n  if (!ORACLE_HOST_RE.test(parsed.hostname)) {\n    throw new Error(`oraclecloud: untrusted hostname \"${parsed.hostname}\" — must match *.fa[.<region>][.ocs].oraclecloud[1-99].com`);\n  }\n  return url;\n}\n\n// NaN-safe Date.parse — `|| undefined` would also coerce a valid epoch 0.\n// (copied from greenhouse.mjs)\nfunction toEpochMs(value) {\n  if (!value) return undefined;\n  const parsed = Date.parse(value);\n  return Number.isNaN(parsed) ? undefined : parsed;\n}\n\nfunction sleep(ms, ctx) {\n  if (typeof ctx?.sleep === 'function') return ctx.sleep(ms);\n  return new Promise((resolve) => setTimeout(resolve, ms));\n}","sourceCodeStart":50,"sourceCodeEnd":86,"githubUrl":"https://github.com/santifer/career-ops/blob/e7abd431fce9348a95261acac9e0c14779c35df8/providers/oraclecloud.mjs#L50-L86","documentation":"assertOracleUrl requires HTTPS. If the URL parses but its protocol is not 'https:', this error is thrown. Oracle Fusion endpoints are only ever contacted over TLS, so http:// (or any other scheme) is rejected.","triggerScenarios":"Providing 'http://<tenant>.fa.ocs.oraclecloud.com/...' or another non-https scheme to the oraclecloud provider or assertOracleUrl.","commonSituations":"Legacy config entries written with http://; URLs copied from HTTP redirect logs or older documentation; hand-assembled URLs defaulting to http; internal proxy links using http.","solutions":["Change the scheme to https:// in the config/source value","Normalize incoming values at load time (reject or upgrade http URLs once, up front)","Update any stored legacy links to their https equivalents","Keep the check; never bypass it by calling fetch directly"],"exampleFix":"// before\nassertOracleUrl('http://acme.fa.ocs.oraclecloud.com/hcmRestApi/careers');\n// after\nassertOracleUrl('https://acme.fa.ocs.oraclecloud.com/hcmRestApi/careers');","handlingStrategy":"validation","validationCode":"const parsed = new URL(url);\nif (parsed.protocol !== 'https:') throw new Error(`oraclecloud requires https: ${url}`);","typeGuard":"function isHttpsUrl(u) {\n  try { return new URL(u).protocol === 'https:'; } catch { return false; }\n}","tryCatchPattern":"try {\n  useOracle(url);\n} catch (e) {\n  if (String(e.message).startsWith('oraclecloud: URL must use HTTPS')) {\n    return useOracle(url.replace(/^http:/, 'https:'));\n  }\n  throw e;\n}","preventionTips":["Normalize http:// to https:// once at config load for known TLS-only hosts","Ban http:// in provider configs via CI lint","Take URLs from current documentation, not legacy bookmarks","Verify the scheme whenever hand-assembling an Oracle tenant URL"],"tags":["url-validation","https","security"],"backgroundTag":"invalid-url","analyzedSha":"e7abd431fce9348a95261acac9e0c14779c35df8","analyzedAt":"2026-09-16T06:35:29.214Z","contentChangedAt":"2026-09-16T06:35:29.214Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}