santifer/career-ops · error · Error

remotli: URL must use HTTPS

Error message

remotli: URL must use HTTPS: ${url}

What it means

remotli provider validates every URL before use via assertRemotliUrl. After confirming the string parses as a URL, it rejects any URL whose protocol is not https:. This is a security guard ensuring no plaintext HTTP traffic is sent to the job board and no non-HTTPS scheme (file:, data:, etc.) is smuggled in.

Solutions

  1. Change the URL to use https:// (e.g. https://remotli.ch/...) in the provider entry or config.
  2. Verify the scheme before calling the provider: normalize/upgrade http:// to https:// when building the URL.
  3. Check env vars or config templates that supply the base URL and fix any that default to http.

Example fix

// before
url = 'http://remotli.ch/api/jobs';
// after
url = 'https://remotli.ch/api/jobs';
Defensive patterns

Strategy: validation

Validate before calling

function isHttpsUrl(url) { try { return new URL(url).protocol === 'https:'; } catch { return false; } }
if (!isHttpsUrl(entry.url)) throw new Error(`skip: non-HTTPS URL ${entry.url}`);

Type guard

const isHttpsUrl = (u) => { try { return new URL(u).protocol === 'https:'; } catch { return false; } };

Try / catch

try { await provider.fetch(entry, ctx); } catch (e) { if (String(e.message).includes('must use HTTPS')) { console.warn(`Fix config: ${entry.url}`); return null; } throw e; }

Prevention

When it happens

Trigger: Passing a URL to the remotli provider whose parsed protocol !== 'https:' — e.g. an entry configured with http://remotli.ch/..., an ftp: or file: URL, or a URL built with a scheme-less string that still parsed (unlikely here) — triggers this throw.

Common situations: A portals.yml entry hand-edited to http://, a config value copied from an old docs page or an internal staging mirror served over HTTP, or code assembling the URL from an env var that lacks the scheme.

Understand the failure class

Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.

Related errors


AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16). Data as JSON: /api/errors/2ad962a92430a95f. Report an issue: GitHub.

Appendix: source

Thrown at providers/remotli.mjs:241

  const postedAt = toEpochMs(job.publishedAt || job.createdAt);
  if (postedAt !== undefined) out.postedAt = postedAt;

  const salary = resolveSalary(job);
  if (salary) out.salary = salary;

  return out;
}

/** Guard the API URL: HTTPS + remotli.ch only. */
function assertRemotliUrl(url) {
  let parsed;
  try {
    parsed = new URL(url);
  } catch {
    throw new Error(`remotli: invalid URL: ${url}`);
  }
  if (parsed.protocol !== 'https:') throw new Error(`remotli: URL must use HTTPS: ${url}`);
  if (!HOST_RE.test(parsed.hostname))
    throw new Error(`remotli: untrusted hostname "${parsed.hostname}" — must be remotli.ch`);
  return url;
}

/** @type {Provider} */
export default {
  id: 'remotli',

  detect(entry) {
    const raw = typeof entry.careers_url === 'string' ? entry.careers_url : '';
    if (!raw) return null;
    let parsed;
    try {
      parsed = new URL(raw);
    } catch {
      return null;
    }

View on GitHub (pinned to aac998c7ed)