{"record":{"id":"f503253959062ae4","repo":"affaan-m/ECC","slug":"name-must-be-an-https-url-without-embedded-credentials","errorCode":null,"errorMessage":"{name} must be an HTTPS URL without embedded credentials","messagePattern":"(.+?) must be an HTTPS URL without embedded credentials","errorType":"validation","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"skills/taste-application/scripts/workflow_graphs.py","lineNumber":26,"sourceCode":"WORKFLOWS = Path(__file__).resolve().parents[1] / 'workflows'\nNEUTRAL_GRADE = (\n    'Colour: none. Render neutral. Grading is applied afterwards - do not '\n    'attempt any colour styling, tint, or cast. This colour rule takes precedence '\n    'over conflicting style direction; preserve structure, lighting and motion.'\n)\n\n\ndef nonempty(value, name):\n    if not isinstance(value, str) or not value.strip():\n        raise ValueError(f'{name} must be a nonempty string')\n    return value.strip()\n\n\ndef https_url(value, name):\n    value = nonempty(value, name)\n    parsed = urlsplit(value)\n    if parsed.scheme != 'https' or not parsed.hostname or parsed.username or parsed.password:\n        raise ValueError(f'{name} must be an HTTPS URL without embedded credentials')\n    return value\n\n\ndef compile_application_input(config):\n    \"\"\"Source video contains the user's content; taste affects the HOW section.\"\"\"\n    return {\n        'source_video': https_url(config.get('source_video'), 'source_video'),\n        'compiled_prompt': '\\n\\n'.join((\n            'WHAT - content and action:\\n' + nonempty(config.get('brief'), 'brief'),\n            'HOW - structure, lighting and motion:\\n' + nonempty(config.get('style_steer'), 'style_steer'),\n            'GRADE - mandatory postproduction boundary:\\n' + NEUTRAL_GRADE,\n        )),\n    }\n\n\ndef prepare_distillation_input(config):\n    \"\"\"Require externally measured grounding; never invent numerical evidence.\"\"\"\n    genre = nonempty(config.get('genre'), 'genre')","sourceCodeStart":8,"sourceCodeEnd":44,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/taste-application/scripts/workflow_graphs.py#L8-L44","documentation":"https_url() validates that a value is an HTTPS URL with a hostname and no embedded userinfo (username/password). Anything with a scheme other than https, no hostname, or credentials in the URL raises this ValueError. This guards graph input against accidental HTTP and credential leakage in URLs.","triggerScenarios":"Passing 'http://...' (not https), 'ftp://...', a bare hostname like 'example.com/video.mp4' (no scheme so scheme != 'https'), or 'https://user:pass@host/...' to compile_application_input or prepare_distillation_input.","commonSituations":"Dev/staging URLs still using http; URLs copy-pasted with embedded basic-auth credentials from a proxy or internal tool; relative or scheme-less URLs from user input.","solutions":["Change the URL scheme to https://","Remove any username:password@ userinfo from the URL and use headers/secrets instead","Verify the URL parses with a hostname: use urllib.parse.urlsplit in a pre-check"],"exampleFix":"// before\n'reference_1': 'https://user:secret@cdn.example.com/ref.mp4'\n// after\n'reference_1': 'https://cdn.example.com/ref.mp4'","handlingStrategy":"validation","validationCode":"from urllib.parse import urlsplit\n\ndef ensure_https_url(value, name):\n    p = urlsplit(value)\n    if p.scheme != 'https' or not p.hostname or p.username or p.password:\n        raise ValueError(f'{name} must be an HTTPS URL without embedded credentials')","typeGuard":"def is_safe_https_url(v) -> bool:\n    p = urlsplit(v) if isinstance(v, str) else None\n    return bool(p and p.scheme == 'https' and p.hostname and not p.username and not p.password)","tryCatchPattern":"try:\n    graph_input = prepare_distillation_input(config)\nexcept ValueError as e:\n    if 'HTTPS URL' in str(e):\n        print(f'Bad reference URL: {e}')\n    else:\n        raise","preventionTips":["Always serve reference media over HTTPS; update http:// internal links","Strip credentials from URLs before they enter config; pass secrets via headers instead","Sanitize copy-pasted URLs (strip user:pass@ inserted by proxies)"],"tags":["validation","url","https"],"backgroundTag":"invalid-url-format","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}