santifer/career-ops · error · Error
nofluffjobs: URL must use HTTPS
Error message
nofluffjobs: URL must use HTTPS: ${url} What it means
assertNoFluffUrl requires the HTTPS protocol. If the URL parses but parsed.protocol !== 'https:', this error is thrown. The provider refuses plain-http (or other-scheme) endpoints so that all API traffic to NoFluffJobs is encrypted.
Solutions
- Update the URL's scheme to https:// in the config or calling code
- If the value comes from user/env input, normalize it (prepend https:// when a scheme is absent, reject http explicitly)
- Migrate stored http:// bookmarks/links to https once, at config-load time
- Keep the check enabled; do not work around it with a lower-level fetch
Example fix
// before
assertNoFluffUrl('http://nofluffjobs.com/api/postings');
// after
assertNoFluffUrl('https://nofluffjobs.com/api/postings'); Defensive patterns
Strategy: validation
Validate before calling
const parsed = new URL(url);
if (parsed.protocol !== 'https:') throw new Error(`nofluffjobs requires https: ${url}`); Type guard
function isHttpsUrl(u) {
try { return new URL(u).protocol === 'https:'; } catch { return false; }
} Try / catch
try {
await nofluffjobs.fetch(entry, ctx);
} catch (e) {
if (String(e.message).startsWith('nofluffjobs: URL must use HTTPS')) {
entry.careers_url = entry.careers_url.replace(/^http:/, 'https:');
return nofluffjobs.fetch(entry, ctx);
}
throw e;
} Prevention
- Add a config-load step that rewrites or rejects http:// NoFluffJobs links
- Keep a lint rule in CI banning http:// in provider config files
- Document the https requirement next to the config schema
- Test new entries with a quick parse+protocol check before a full scan
When it happens
Trigger: Passing 'http://nofluffjobs.com/...' or any non-https scheme (ftp:, file:, ws:) into the nofluffjobs provider's detect/fetch path or directly into assertNoFluffUrl.
Common situations: Old config entries written before the site enforced HTTPS; a URL copied from an insecure redirect or HTTP log line; hand-built URLs defaulting to http; documentation examples using http.
Understand the failure class
Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.
Related errors
- a16z-speedrun-talent: URL must use HTTPS
- agentic-jobs: URL must use HTTPS
- collage: URL must use HTTPS
- getonbrd: URL must use HTTPS
- glints: URL must use HTTPS
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/7c0f91a98b96bdee.
Report an issue: GitHub.
Appendix: source
Thrown at providers/nofluffjobs.mjs:21
// NoFluffJobs provider — hits the public search posting API.
// It intentionally returns only the core scanner job fields; richer skill and
// salary metadata can be added later if the provider contract is expanded.
const ALLOWED_HOSTS = new Set(['nofluffjobs.com']);
const API_URL = 'https://nofluffjobs.com/api/search/posting';
const JOB_BASE = 'https://nofluffjobs.com/pl/job/';
const PAGE_SIZE = 20;
const MAX_PAGES = 5;
function assertNoFluffUrl(url) {
let parsed;
try {
parsed = new URL(url);
} catch {
throw new Error(`nofluffjobs: invalid URL: ${url}`);
}
if (parsed.protocol !== 'https:') throw new Error(`nofluffjobs: URL must use HTTPS: ${url}`);
if (!ALLOWED_HOSTS.has(parsed.hostname)) {
throw new Error(`nofluffjobs: untrusted hostname "${parsed.hostname}" — must be nofluffjobs.com`);
}
return parsed;
}
function detectUrl(entry) {
const url = entry.api || entry.careers_url || '';
if (typeof url !== 'string' || !url.trim()) return null;
try {
return { url: assertNoFluffUrl(url).href };
} catch {
return null;
}
}
function normalizeLocation(posting) {
const parts = [];View on GitHub (pinned to aac998c7ed)