santifer/career-ops · error
glints: URL must use HTTPS
Error message
glints: URL must use HTTPS: ${url} What it means
assertGlintsUrl enforces HTTPS on every URL it validates. If the URL parses but parsed.protocol is not 'https:' (typically http://), the function throws this error. This keeps all Glints GraphQL traffic encrypted and consistent with the provider's security posture.
Solutions
- Change the scheme to https:// in the entry's api value
- If you were pointing at a plain-HTTP local proxy, remove the override and use the default https endpoint instead, or terminate TLS on the proxy
- Re-run after fixing — the hostname allowlist check comes next and may surface a further issue
Example fix
// before api: http://glints.com/api/v2-alc/graphql // after api: https://glints.com/api/v2-alc/graphql
Defensive patterns
Strategy: validation
Validate before calling
if (entry.api) {
const u = new URL(entry.api);
if (u.protocol !== 'https:') throw new Error(`glints entry ${entry.name}: api must use https:// (got ${u.protocol})`);
} Type guard
function isHttpsUrl(v) { try { return new URL(v).protocol === 'https:'; } catch { return false; } } Try / catch
try {
assertGlintsUrl(url);
} catch (e) {
if (String(e.message).includes('must use HTTPS')) {
console.error(`Upgrade ${url} to https:// — plain HTTP is rejected by the glints provider`);
}
throw e;
} Prevention
- Write https:// by default for all api/careers URL config values
- Search config for http:// endpoints before committing
- Remember local dev proxies must also terminate TLS or use the default https endpoint
When it happens
Trigger: A glints entry's api (or other validated URL) is configured as 'http://glints.com/api/v2-alc/graphql' — a valid URL with a non-HTTPS scheme — and reaches the protocol check in assertGlintsUrl.
Common situations: Defaulting to http while hand-writing config; an internal proxy URL written with http; copying an insecure link from documentation or logs.
Understand the failure class
Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.
Related errors
- a16z-speedrun-talent: URL must use HTTPS
- agentic-jobs: URL must use HTTPS
- collage: URL must use HTTPS
- getonbrd: URL must use HTTPS
- itviec: URL must use HTTPS
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/3a3eb400836c04a9.
Report an issue: GitHub.
Appendix: source
Thrown at providers/glints.mjs:77
minAmount
CurrencyCode
}
createdAt
}
expInfo
hasMore
}
}`;
/** @param {string} url */
function assertGlintsUrl(url) {
let parsed;
try {
parsed = new URL(url);
} catch {
throw new Error(`glints: invalid URL: ${url}`);
}
if (parsed.protocol !== 'https:') throw new Error(`glints: URL must use HTTPS: ${url}`);
if (!ALLOWED_GLINTS_HOSTS.has(parsed.hostname))
throw new Error(`glints: untrusted hostname "${parsed.hostname}" — must be one of: ${[...ALLOWED_GLINTS_HOSTS].join(', ')}`);
return url;
}
// NaN-safe Date.parse
function toEpochMs(value) {
if (!value) return undefined;
const parsed = Date.parse(value);
return Number.isNaN(parsed) ? undefined : parsed;
}
/**
* Derive the job detail base URL from the API hostname.
* @param {string} apiUrl
* @returns {string}
*/
function deriveBaseUrl(apiUrl) {View on GitHub (pinned to aac998c7ed)