santifer/career-ops · error · Error

a16z-speedrun-talent: URL must use HTTPS

Error message

a16z-speedrun-talent: URL must use HTTPS: ${url}

What it means

assertFeedUrl in providers/a16z-speedrun-talent.mjs throws this when the URL parses but its protocol is not 'https:'. The provider only talks to HTTPS feeds, refusing plaintext HTTP to protect the integrity and confidentiality of fetched job data. Hostname checking happens after this, so this throw fires for any validly-parsed non-HTTPS URL regardless of host.

Solutions

  1. Change the URL scheme to https:// and retry.
  2. If the host only serves HTTP, it is unsupported — use the official HTTPS feed endpoint.
  3. If you control the feed, enable HTTPS on the server and update the config.
  4. Search your config for hardcoded http:// scheme strings and normalize them to https://.

Example fix

// before
fetchSpeedrunFeed('http://example.com/api/jobs')
// after
fetchSpeedrunFeed('https://example.com/api/jobs')
Defensive patterns

Strategy: validation

Validate before calling

const u = new URL(rawUrl);
if (u.protocol !== 'https:') throw new Error(`feed URL must use https, got ${u.protocol}`);

Type guard

function isHttpsUrl(s) {
  try { return new URL(s).protocol === 'https:'; } catch { return false; }
}

Try / catch

try {
  await fetchSpeedrunFeed(url);
} catch (e) {
  if (String(e.message).includes('URL must use HTTPS')) {
    const fixed = url.replace(/^http:/, 'https:');
    console.warn(`Upgrading ${url} -> ${fixed}`);
    return fetchSpeedrunFeed(fixed);
  } else throw e;
}

Prevention

When it happens

Trigger: Calling the provider with an http:// URL (or ftp:, file:, etc.) — e.g. a portals.yml careers_url written as 'http://...' or a URL built from an untyped scheme variable.

Common situations: Older feed links that predate HTTPS migration; hand-written config defaults using http://; internal test servers served over plain HTTP being pointed at the provider.

Understand the failure class

Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.

Related errors


AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16). Data as JSON: /api/errors/16670af8b234ef7d. Report an issue: GitHub.

Appendix: source

Thrown at providers/a16z-speedrun-talent.mjs:47

const DEFAULT_MAX_PAGES = 6; // × PER_PAGE = the 300-job default scan
// Runaway bound, not a coverage target: iteration already stops at the
// feed's reported total_pages (or, when the feed omits it, a short page), so
// on an honest feed the cap costs nothing and full-board sweeps keep working
// as the board grows.
// It only bites a misbehaving feed or an absurd max_pages entry — so it
// sits well above plausible board size (~353 pages / ~17.6k jobs as of
// 2026-08), same policy as workday.mjs's cap.
const MAX_PAGES_CAP = 1000;

/** @param {string} url */
function assertFeedUrl(url) {
  let parsed;
  try {
    parsed = new URL(url);
  } catch {
    throw new Error(`a16z-speedrun-talent: invalid URL: ${url}`);
  }
  if (parsed.protocol !== 'https:') throw new Error(`a16z-speedrun-talent: URL must use HTTPS: ${url}`);
  if (parsed.hostname !== TRUSTED_HOST) {
    throw new Error(`a16z-speedrun-talent: untrusted hostname "${parsed.hostname}" — must be ${TRUSTED_HOST}`);
  }
  return url;
}

/** Resolve the page cap: a positive integer `max_pages` on the entry, capped. */
function resolveMaxPages(entry) {
  const v = entry?.max_pages;
  if (Number.isInteger(v) && v > 0) return Math.min(v, MAX_PAGES_CAP);
  return DEFAULT_MAX_PAGES;
}

/** Optional server-side query: `q:` on the entry, else joined `keywords:`. */
function resolveQuery(entry) {
  if (typeof entry?.q === 'string' && entry.q.trim()) return entry.q.trim();
  if (Array.isArray(entry?.keywords) && entry.keywords.length > 0) {
    const joined = entry.keywords.filter((k) => typeof k === 'string' && k.trim()).join(' ').trim();

View on GitHub (pinned to aac998c7ed)