santifer/career-ops · error

glints: URL must use HTTPS

Error message

glints: URL must use HTTPS: ${url}

What it means

assertGlintsUrl enforces HTTPS on every URL it validates. If the URL parses but parsed.protocol is not 'https:' (typically http://), the function throws this error. This keeps all Glints GraphQL traffic encrypted and consistent with the provider's security posture.

Solutions

  1. Change the scheme to https:// in the entry's api value
  2. If you were pointing at a plain-HTTP local proxy, remove the override and use the default https endpoint instead, or terminate TLS on the proxy
  3. Re-run after fixing — the hostname allowlist check comes next and may surface a further issue

Example fix

// before
api: http://glints.com/api/v2-alc/graphql
// after
api: https://glints.com/api/v2-alc/graphql
Defensive patterns

Strategy: validation

Validate before calling

if (entry.api) {
  const u = new URL(entry.api);
  if (u.protocol !== 'https:') throw new Error(`glints entry ${entry.name}: api must use https:// (got ${u.protocol})`);
}

Type guard

function isHttpsUrl(v) { try { return new URL(v).protocol === 'https:'; } catch { return false; } }

Try / catch

try {
  assertGlintsUrl(url);
} catch (e) {
  if (String(e.message).includes('must use HTTPS')) {
    console.error(`Upgrade ${url} to https:// — plain HTTP is rejected by the glints provider`);
  }
  throw e;
}

Prevention

When it happens

Trigger: A glints entry's api (or other validated URL) is configured as 'http://glints.com/api/v2-alc/graphql' — a valid URL with a non-HTTPS scheme — and reaches the protocol check in assertGlintsUrl.

Common situations: Defaulting to http while hand-writing config; an internal proxy URL written with http; copying an insecure link from documentation or logs.

Understand the failure class

Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.

Related errors


AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16). Data as JSON: /api/errors/3a3eb400836c04a9. Report an issue: GitHub.

Appendix: source

Thrown at providers/glints.mjs:77

        minAmount
        CurrencyCode
      }
      createdAt
    }
    expInfo
    hasMore
  }
}`;

/** @param {string} url */
function assertGlintsUrl(url) {
  let parsed;
  try {
    parsed = new URL(url);
  } catch {
    throw new Error(`glints: invalid URL: ${url}`);
  }
  if (parsed.protocol !== 'https:') throw new Error(`glints: URL must use HTTPS: ${url}`);
  if (!ALLOWED_GLINTS_HOSTS.has(parsed.hostname))
    throw new Error(`glints: untrusted hostname "${parsed.hostname}" — must be one of: ${[...ALLOWED_GLINTS_HOSTS].join(', ')}`);
  return url;
}

// NaN-safe Date.parse
function toEpochMs(value) {
  if (!value) return undefined;
  const parsed = Date.parse(value);
  return Number.isNaN(parsed) ? undefined : parsed;
}

/**
 * Derive the job detail base URL from the API hostname.
 * @param {string} apiUrl
 * @returns {string}
 */
function deriveBaseUrl(apiUrl) {

View on GitHub (pinned to aac998c7ed)