santifer/career-ops · error · Error

oraclecloud: URL must use HTTPS

Error message

oraclecloud: URL must use HTTPS: ${url}

What it means

assertOracleUrl requires HTTPS. If the URL parses but its protocol is not 'https:', this error is thrown. Oracle Fusion endpoints are only ever contacted over TLS, so http:// (or any other scheme) is rejected.

Solutions

  1. Change the scheme to https:// in the config/source value
  2. Normalize incoming values at load time (reject or upgrade http URLs once, up front)
  3. Update any stored legacy links to their https equivalents
  4. Keep the check; never bypass it by calling fetch directly

Example fix

// before
assertOracleUrl('http://acme.fa.ocs.oraclecloud.com/hcmRestApi/careers');
// after
assertOracleUrl('https://acme.fa.ocs.oraclecloud.com/hcmRestApi/careers');
Defensive patterns

Strategy: validation

Validate before calling

const parsed = new URL(url);
if (parsed.protocol !== 'https:') throw new Error(`oraclecloud requires https: ${url}`);

Type guard

function isHttpsUrl(u) {
  try { return new URL(u).protocol === 'https:'; } catch { return false; }
}

Try / catch

try {
  useOracle(url);
} catch (e) {
  if (String(e.message).startsWith('oraclecloud: URL must use HTTPS')) {
    return useOracle(url.replace(/^http:/, 'https:'));
  }
  throw e;
}

Prevention

When it happens

Trigger: Providing 'http://<tenant>.fa.ocs.oraclecloud.com/...' or another non-https scheme to the oraclecloud provider or assertOracleUrl.

Common situations: Legacy config entries written with http://; URLs copied from HTTP redirect logs or older documentation; hand-assembled URLs defaulting to http; internal proxy links using http.

Understand the failure class

Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.

Related errors


AI-assisted analysis of santifer/career-ops@e7abd431fc (2026-09-16). Data as JSON: /api/errors/cec5174de6ec26ae. Report an issue: GitHub.

Appendix: source

Thrown at providers/oraclecloud.mjs:68

const ORACLE_HOST_RE = /^[a-z0-9-]+\.fa\.(?:[a-z0-9-]+\.)?(?:ocs\.)?oraclecloud(?:[1-9][0-9]?)?\.com$/i;

const PAGE_SIZE = 200;
const MAX_PAGES = 25;             // safety cap (~5000 jobs); hard ceiling like workday
const RETRY_POLICY = { retries: 3 };
const INTER_PAGE_DELAY_MS = 250;  // WAF-aware spacing between same-host pages

// facetsList is a fixed constant on the finder; %3B is the encoded ';' separator.
const FACETS_LIST = 'LOCATIONS%3BWORK_LOCATIONS%3BWORKPLACE_TYPES%3BTITLES%3BCATEGORIES%3BORGANIZATIONS%3BPOSTING_DATES%3BFLEX_FIELDS';

/** @param {string} url */
function assertOracleUrl(url) {
  let parsed;
  try {
    parsed = new URL(url);
  } catch {
    throw new Error(`oraclecloud: invalid URL: ${url}`);
  }
  if (parsed.protocol !== 'https:') throw new Error(`oraclecloud: URL must use HTTPS: ${url}`);
  if (!ORACLE_HOST_RE.test(parsed.hostname)) {
    throw new Error(`oraclecloud: untrusted hostname "${parsed.hostname}" — must match *.fa[.<region>][.ocs].oraclecloud[1-99].com`);
  }
  return url;
}

// NaN-safe Date.parse — `|| undefined` would also coerce a valid epoch 0.
// (copied from greenhouse.mjs)
function toEpochMs(value) {
  if (!value) return undefined;
  const parsed = Date.parse(value);
  return Number.isNaN(parsed) ? undefined : parsed;
}

function sleep(ms, ctx) {
  if (typeof ctx?.sleep === 'function') return ctx.sleep(ms);
  return new Promise((resolve) => setTimeout(resolve, ms));
}

View on GitHub (pinned to e7abd431fc)