santifer/career-ops · error · Error

nofluffjobs: URL must use HTTPS

Error message

nofluffjobs: URL must use HTTPS: ${url}

What it means

assertNoFluffUrl requires the HTTPS protocol. If the URL parses but parsed.protocol !== 'https:', this error is thrown. The provider refuses plain-http (or other-scheme) endpoints so that all API traffic to NoFluffJobs is encrypted.

Solutions

  1. Update the URL's scheme to https:// in the config or calling code
  2. If the value comes from user/env input, normalize it (prepend https:// when a scheme is absent, reject http explicitly)
  3. Migrate stored http:// bookmarks/links to https once, at config-load time
  4. Keep the check enabled; do not work around it with a lower-level fetch

Example fix

// before
assertNoFluffUrl('http://nofluffjobs.com/api/postings');
// after
assertNoFluffUrl('https://nofluffjobs.com/api/postings');
Defensive patterns

Strategy: validation

Validate before calling

const parsed = new URL(url);
if (parsed.protocol !== 'https:') throw new Error(`nofluffjobs requires https: ${url}`);

Type guard

function isHttpsUrl(u) {
  try { return new URL(u).protocol === 'https:'; } catch { return false; }
}

Try / catch

try {
  await nofluffjobs.fetch(entry, ctx);
} catch (e) {
  if (String(e.message).startsWith('nofluffjobs: URL must use HTTPS')) {
    entry.careers_url = entry.careers_url.replace(/^http:/, 'https:');
    return nofluffjobs.fetch(entry, ctx);
  }
  throw e;
}

Prevention

When it happens

Trigger: Passing 'http://nofluffjobs.com/...' or any non-https scheme (ftp:, file:, ws:) into the nofluffjobs provider's detect/fetch path or directly into assertNoFluffUrl.

Common situations: Old config entries written before the site enforced HTTPS; a URL copied from an insecure redirect or HTTP log line; hand-built URLs defaulting to http; documentation examples using http.

Understand the failure class

Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.

Related errors


AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16). Data as JSON: /api/errors/7c0f91a98b96bdee. Report an issue: GitHub.

Appendix: source

Thrown at providers/nofluffjobs.mjs:21

// NoFluffJobs provider — hits the public search posting API.
// It intentionally returns only the core scanner job fields; richer skill and
// salary metadata can be added later if the provider contract is expanded.

const ALLOWED_HOSTS = new Set(['nofluffjobs.com']);
const API_URL = 'https://nofluffjobs.com/api/search/posting';
const JOB_BASE = 'https://nofluffjobs.com/pl/job/';
const PAGE_SIZE = 20;
const MAX_PAGES = 5;

function assertNoFluffUrl(url) {
  let parsed;
  try {
    parsed = new URL(url);
  } catch {
    throw new Error(`nofluffjobs: invalid URL: ${url}`);
  }
  if (parsed.protocol !== 'https:') throw new Error(`nofluffjobs: URL must use HTTPS: ${url}`);
  if (!ALLOWED_HOSTS.has(parsed.hostname)) {
    throw new Error(`nofluffjobs: untrusted hostname "${parsed.hostname}" — must be nofluffjobs.com`);
  }
  return parsed;
}

function detectUrl(entry) {
  const url = entry.api || entry.careers_url || '';
  if (typeof url !== 'string' || !url.trim()) return null;
  try {
    return { url: assertNoFluffUrl(url).href };
  } catch {
    return null;
  }
}

function normalizeLocation(posting) {
  const parts = [];

View on GitHub (pinned to aac998c7ed)