santifer/career-ops · error
flowxtra: URL must use HTTPS
Error message
flowxtra: URL must use HTTPS: ${url} What it means
assertFlowxtraEndpointUrl in providers/flowxtra.mjs validates that the Flowxtra jobs endpoint URL is well-formed, uses HTTPS, and points at the trusted endpoint host before any request is made. This specific throw fires when the URL parses but its protocol is not 'https:'. The provider deliberately refuses plain HTTP to prevent credentials or job data from being sent unencrypted and to block protocol-based SSRF tricks.
Solutions
- Change the endpoint URL to start with https:// (e.g. https://flowxtra.example.com/...).
- If the endpoint genuinely only serves HTTP, put an HTTPS-terminating proxy in front and point the entry at the proxy host.
- Check the config source of the URL for template/variable mistakes that drop or corrupt the scheme.
- If a local test endpoint is the cause, use an https-capable local setup (self-signed cert) rather than downgrading the assertion.
Example fix
// before endpoint: "http://flowxtra.example.com/api/jobs" // after endpoint: "https://flowxtra.example.com/api/jobs"
Defensive patterns
Strategy: validation
Validate before calling
function isHttpsUrl(u) {
try { return new URL(u).protocol === 'https:'; } catch { return false; }
}
if (!isHttpsUrl(endpoint)) throw new Error(`config: endpoint must be https: ${endpoint}`); Type guard
const isHttpsUrl = (u) => { try { return new URL(u).protocol === 'https:'; } catch { return false; } }; Try / catch
try {
await provider.fetch(entry);
} catch (e) {
if (String(e.message).startsWith('flowxtra: URL must use HTTPS')) {
console.error(`Fix portals.yml entry "${entry.name}": use https://`);
return;
}
throw e;
} Prevention
- Always store endpoint URLs with the full https:// scheme in portals.yml.
- Validate all careers_url values at config-load time with a URL parse + scheme check.
- Add a lint step that scans portals.yml for http:// endpoints.
When it happens
Trigger: Passing a URL whose parsed.protocol is anything other than 'https:' — e.g. an entry configured with an http:// endpoint, a URL built with an empty/injected protocol, or a string like 'ftp://host/path' that still parses via new URL().
Common situations: A portals.yml careers entry pasted from an internal intranet using http://; a config typo dropping the 's'; test fixtures substituting http://localhost endpoints that the assertion rejects in production code paths.
Understand the failure class
Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.
Related errors
- collage: untrusted hostname
- comeet: URL path must be the careers-api endpoint
- flowxtra: untrusted hostname
- himalayas: untrusted hostname
- itviec: untrusted hostname
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/3dd2853273bfb456.
Report an issue: GitHub.
Appendix: source
Thrown at providers/flowxtra.mjs:33
//
// Wire in via a `job_boards:` entry with `provider: flowxtra`.
const JOBS_ENDPOINT = 'https://app.flowxtra.com/api/central/jobs';
const TRUSTED_ENDPOINT_HOST = 'app.flowxtra.com';
const TRUSTED_APPLY_HOST = 'flowxtra.com';
const PER_PAGE = 100;
const DEFAULT_MAX_PAGES = 3;
const MAX_PAGES_CAP = 50;
/** @param {string} url */
function assertFlowxtraEndpointUrl(url) {
let parsed;
try {
parsed = new URL(url);
} catch {
throw new Error(`flowxtra: invalid URL: ${url}`);
}
if (parsed.protocol !== 'https:') throw new Error(`flowxtra: URL must use HTTPS: ${url}`);
if (parsed.hostname !== TRUSTED_ENDPOINT_HOST) {
throw new Error(`flowxtra: untrusted hostname "${parsed.hostname}" — must be ${TRUSTED_ENDPOINT_HOST}`);
}
return url;
}
/** Resolve the page cap: a positive integer `max_pages` on the entry, capped. */
function resolveMaxPages(entry) {
const v = entry?.max_pages;
if (Number.isInteger(v) && v > 0) return Math.min(v, MAX_PAGES_CAP);
return DEFAULT_MAX_PAGES;
}
// NaN-safe Date.parse — `|| undefined` would also coerce a valid epoch 0.
function toEpochMs(value) {
if (!value) return undefined;
const parsed = Date.parse(value);
return Number.isNaN(parsed) ? undefined : parsed;View on GitHub (pinned to aac998c7ed)