santifer/career-ops · error · Error
oraclecloud: URL must use HTTPS
Error message
oraclecloud: URL must use HTTPS: ${url} What it means
assertOracleUrl requires HTTPS. If the URL parses but its protocol is not 'https:', this error is thrown. Oracle Fusion endpoints are only ever contacted over TLS, so http:// (or any other scheme) is rejected.
Solutions
- Change the scheme to https:// in the config/source value
- Normalize incoming values at load time (reject or upgrade http URLs once, up front)
- Update any stored legacy links to their https equivalents
- Keep the check; never bypass it by calling fetch directly
Example fix
// before
assertOracleUrl('http://acme.fa.ocs.oraclecloud.com/hcmRestApi/careers');
// after
assertOracleUrl('https://acme.fa.ocs.oraclecloud.com/hcmRestApi/careers'); Defensive patterns
Strategy: validation
Validate before calling
const parsed = new URL(url);
if (parsed.protocol !== 'https:') throw new Error(`oraclecloud requires https: ${url}`); Type guard
function isHttpsUrl(u) {
try { return new URL(u).protocol === 'https:'; } catch { return false; }
} Try / catch
try {
useOracle(url);
} catch (e) {
if (String(e.message).startsWith('oraclecloud: URL must use HTTPS')) {
return useOracle(url.replace(/^http:/, 'https:'));
}
throw e;
} Prevention
- Normalize http:// to https:// once at config load for known TLS-only hosts
- Ban http:// in provider configs via CI lint
- Take URLs from current documentation, not legacy bookmarks
- Verify the scheme whenever hand-assembling an Oracle tenant URL
When it happens
Trigger: Providing 'http://<tenant>.fa.ocs.oraclecloud.com/...' or another non-https scheme to the oraclecloud provider or assertOracleUrl.
Common situations: Legacy config entries written with http://; URLs copied from HTTP redirect logs or older documentation; hand-assembled URLs defaulting to http; internal proxy links using http.
Understand the failure class
Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.
Related errors
- a16z-speedrun-talent: URL must use HTTPS
- agentic-jobs: URL must use HTTPS
- collage: URL must use HTTPS
- getonbrd: URL must use HTTPS
- glints: URL must use HTTPS
AI-assisted analysis of santifer/career-ops@e7abd431fc (2026-09-16).
Data as JSON: /api/errors/cec5174de6ec26ae.
Report an issue: GitHub.
Appendix: source
Thrown at providers/oraclecloud.mjs:68
const ORACLE_HOST_RE = /^[a-z0-9-]+\.fa\.(?:[a-z0-9-]+\.)?(?:ocs\.)?oraclecloud(?:[1-9][0-9]?)?\.com$/i;
const PAGE_SIZE = 200;
const MAX_PAGES = 25; // safety cap (~5000 jobs); hard ceiling like workday
const RETRY_POLICY = { retries: 3 };
const INTER_PAGE_DELAY_MS = 250; // WAF-aware spacing between same-host pages
// facetsList is a fixed constant on the finder; %3B is the encoded ';' separator.
const FACETS_LIST = 'LOCATIONS%3BWORK_LOCATIONS%3BWORKPLACE_TYPES%3BTITLES%3BCATEGORIES%3BORGANIZATIONS%3BPOSTING_DATES%3BFLEX_FIELDS';
/** @param {string} url */
function assertOracleUrl(url) {
let parsed;
try {
parsed = new URL(url);
} catch {
throw new Error(`oraclecloud: invalid URL: ${url}`);
}
if (parsed.protocol !== 'https:') throw new Error(`oraclecloud: URL must use HTTPS: ${url}`);
if (!ORACLE_HOST_RE.test(parsed.hostname)) {
throw new Error(`oraclecloud: untrusted hostname "${parsed.hostname}" — must match *.fa[.<region>][.ocs].oraclecloud[1-99].com`);
}
return url;
}
// NaN-safe Date.parse — `|| undefined` would also coerce a valid epoch 0.
// (copied from greenhouse.mjs)
function toEpochMs(value) {
if (!value) return undefined;
const parsed = Date.parse(value);
return Number.isNaN(parsed) ? undefined : parsed;
}
function sleep(ms, ctx) {
if (typeof ctx?.sleep === 'function') return ctx.sleep(ms);
return new Promise((resolve) => setTimeout(resolve, ms));
}View on GitHub (pinned to e7abd431fc)