santifer/career-ops · error · Error

himalayas: URL must use HTTPS

Error message

himalayas: URL must use HTTPS: ${url}

What it means

URL scheme guard in the Himalayas board provider (assertHimalayasUrl): the parsed URL's protocol is not https:. The URL is syntactically valid but not HTTPS, and the provider only fetches the trusted himalayas.app feed over TLS. The input at fault is the URL handed to the provider (typically careers_url in portals.yml).

Solutions

  1. Change the URL scheme to https:// in the config or code that builds it.
  2. Hardcode https: in any URL-building helper rather than inheriting the input scheme.
  3. Lint config at load time to reject non-https URLs for this provider.
  4. Use the provider's FEED_URL constant instead of a hand-written URL.

Example fix

// before
const feed = 'http://himalayas.app/jobs/api?limit=50';
// after
const feed = 'https://himalayas.app/jobs/api?limit=50';
Defensive patterns

Strategy: validation

Validate before calling

function isHttpsHimalayasUrl(url) {
  try { return new URL(url).protocol === 'https:' && new URL(url).hostname === 'himalayas.app'; } catch { return false; }
}

Type guard

const isHttpsUrl = (s) => { try { return new URL(s).protocol === 'https:'; } catch { return false; } };

Try / catch

try {
  await provider.fetch(entry, ctx);
} catch (err) {
  if (/himalayas: URL must use HTTPS/.test(err.message)) {
    console.error(`Switch himalayas feed to https: ${err.message}`);
    return;
  }
  throw err;
}

Prevention

When it happens

Trigger: A configured feed URL using http:// instead of https://, or a URL built by concatenating an http base with the API path.

Common situations: Old bookmarks/docs with http links, local dev proxies configured with http://, or string-built URLs where the scheme came from an untrusted default.

Understand the failure class

Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.

Related errors


AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16). Data as JSON: /api/errors/7405196bbeb7efe4. Report an issue: GitHub.

Appendix: source

Thrown at providers/himalayas.mjs:22

// Himalayas provider - board-wide remote jobs API
// (https://himalayas.app/jobs/api?limit=50). Returns { jobs: [...] }. The
// full feed is fetched so scan.mjs's title_filter / location_filter can do
// the local gating consistently with other zero-token board providers.
//
// Wire in via a `job_boards:` entry with `provider: himalayas`.

const FEED_URL = 'https://himalayas.app/jobs/api?limit=50';
const TRUSTED_HOST = 'himalayas.app';

/** @param {string} url */
function assertHimalayasUrl(url) {
  let parsed;
  try {
    parsed = new URL(url);
  } catch {
    throw new Error(`himalayas: invalid URL: ${url}`);
  }
  if (parsed.protocol !== 'https:') throw new Error(`himalayas: URL must use HTTPS: ${url}`);
  if (parsed.hostname !== TRUSTED_HOST) {
    throw new Error(`himalayas: untrusted hostname "${parsed.hostname}" - must be ${TRUSTED_HOST}`);
  }
  return url;
}

function cleanText(value) {
  return typeof value === 'string' ? value.trim() : '';
}

function cleanHimalayasUrl(value) {
  const raw = cleanText(value);
  if (!raw) return '';
  try {
    const parsed = new URL(raw);
    const host = parsed.hostname.toLowerCase();
    const trusted = host === TRUSTED_HOST || host.endsWith(`.${TRUSTED_HOST}`);
    return parsed.protocol === 'https:' && trusted ? parsed.href : '';

View on GitHub (pinned to aac998c7ed)