santifer/career-ops · error
getonbrd: URL must use HTTPS
Error message
getonbrd: URL must use HTTPS: ${url} What it means
assertGetonbrdUrl requires every URL it accepts to use the https: protocol. After a successful URL parse, if parsed.protocol is anything else (http:, ftp:, file:, etc.), the function throws this error. This enforces transport security for all Get on Board requests made by the provider.
Solutions
- Change the URL scheme to https:// in the portals.yml entry
- Check for scheme variables or env interpolation in config generation that may emit http
- Note that the hostname check runs after this one, so fix the scheme first, then re-run to surface any hostname issue
Example fix
// before careers_url: http://www.getonbrd.com/api/v0/categories/programming/jobs // after careers_url: https://www.getonbrd.com/api/v0/categories/programming/jobs
Defensive patterns
Strategy: validation
Validate before calling
const u = new URL(entry.careers_url);
if (u.protocol !== 'https:') throw new Error(`${entry.name}: careers_url must use https:// (got ${u.protocol})`); Type guard
function isHttpsUrl(v) { try { return new URL(v).protocol === 'https:'; } catch { return false; } } Try / catch
try {
assertGetonbrdUrl(url);
} catch (e) {
if (String(e.message).includes('must use HTTPS')) {
url = url.replace(/^http:/, 'https:'); // auto-upgrade then retry
} else throw e;
} Prevention
- Default to https:// when writing any careers_url or api value
- Never rely on the provider to upgrade http to https
- Grep config for 'http://' (without s) before committing changes
When it happens
Trigger: A portals.yml entry passes a URL that parses fine but uses a non-HTTPS scheme — typically 'http://www.getonbrd.com/...' — and the provider runs it through assertGetonbrdUrl.
Common situations: Copying an old http:// link from bookmarks or logs; writing http by habit when hand-editing portals.yml; a redirect-generation script producing http URLs.
Understand the failure class
Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.
Related errors
- a16z-speedrun-talent: URL must use HTTPS
- agentic-jobs: URL must use HTTPS
- collage: URL must use HTTPS
- glints: URL must use HTTPS
- itviec: URL must use HTTPS
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/df2f2edd19c67ad8.
Report an issue: GitHub.
Appendix: source
Thrown at providers/getonbrd.mjs:83
throw new Error('getonbrd: `categories` is empty — omit it to use the "programming" default');
}
if (out.length > MAX_CATEGORIES) {
throw new Error(
`getonbrd: ${out.length} categories configured — cap is ${MAX_CATEGORIES} (each one costs up to max_pages requests)`,
);
}
return out;
}
/** @param {string} url */
function assertGetonbrdUrl(url) {
let parsed;
try {
parsed = new URL(url);
} catch {
throw new Error(`getonbrd: invalid URL: ${url}`);
}
if (parsed.protocol !== 'https:') throw new Error(`getonbrd: URL must use HTTPS: ${url}`);
if (parsed.hostname !== TRUSTED_HOST) {
throw new Error(`getonbrd: untrusted hostname "${parsed.hostname}" — must be ${TRUSTED_HOST}`);
}
return url;
}
/** Resolve the page cap: a positive integer `max_pages` on the entry, capped. */
function resolveMaxPages(entry) {
const v = entry?.max_pages;
if (Number.isInteger(v) && v > 0) return Math.min(v, MAX_PAGES_CAP);
return DEFAULT_MAX_PAGES;
}
/**
* Normalize a single Get on Board job (JSON:API resource). Exported for tests.
*
* Field mapping → the normalized Job shape:
* - title: `attributes.title`, trimmed (items without one are dropped).View on GitHub (pinned to aac998c7ed)