santifer/career-ops · error · Error
remotli: URL must use HTTPS
Error message
remotli: URL must use HTTPS: ${url} What it means
remotli provider validates every URL before use via assertRemotliUrl. After confirming the string parses as a URL, it rejects any URL whose protocol is not https:. This is a security guard ensuring no plaintext HTTP traffic is sent to the job board and no non-HTTPS scheme (file:, data:, etc.) is smuggled in.
Solutions
- Change the URL to use https:// (e.g. https://remotli.ch/...) in the provider entry or config.
- Verify the scheme before calling the provider: normalize/upgrade http:// to https:// when building the URL.
- Check env vars or config templates that supply the base URL and fix any that default to http.
Example fix
// before url = 'http://remotli.ch/api/jobs'; // after url = 'https://remotli.ch/api/jobs';
Defensive patterns
Strategy: validation
Validate before calling
function isHttpsUrl(url) { try { return new URL(url).protocol === 'https:'; } catch { return false; } }
if (!isHttpsUrl(entry.url)) throw new Error(`skip: non-HTTPS URL ${entry.url}`); Type guard
const isHttpsUrl = (u) => { try { return new URL(u).protocol === 'https:'; } catch { return false; } }; Try / catch
try { await provider.fetch(entry, ctx); } catch (e) { if (String(e.message).includes('must use HTTPS')) { console.warn(`Fix config: ${entry.url}`); return null; } throw e; } Prevention
- Always write https:// in portal/provider config entries.
- Add a lint/check step that scans config for http:// URLs.
- Never build URLs by concatenating schemes from user input.
When it happens
Trigger: Passing a URL to the remotli provider whose parsed protocol !== 'https:' — e.g. an entry configured with http://remotli.ch/..., an ftp: or file: URL, or a URL built with a scheme-less string that still parsed (unlikely here) — triggers this throw.
Common situations: A portals.yml entry hand-edited to http://, a config value copied from an old docs page or an internal staging mirror served over HTTP, or code assembling the URL from an env var that lacks the scheme.
Understand the failure class
Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.
Related errors
- itviec: URL must use HTTPS
- torre: URL must use HTTPS
- weworkremotely: URL must use HTTPS
- a16z-speedrun-talent: URL must use HTTPS
- agentic-jobs: URL must use HTTPS
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/2ad962a92430a95f.
Report an issue: GitHub.
Appendix: source
Thrown at providers/remotli.mjs:241
const postedAt = toEpochMs(job.publishedAt || job.createdAt);
if (postedAt !== undefined) out.postedAt = postedAt;
const salary = resolveSalary(job);
if (salary) out.salary = salary;
return out;
}
/** Guard the API URL: HTTPS + remotli.ch only. */
function assertRemotliUrl(url) {
let parsed;
try {
parsed = new URL(url);
} catch {
throw new Error(`remotli: invalid URL: ${url}`);
}
if (parsed.protocol !== 'https:') throw new Error(`remotli: URL must use HTTPS: ${url}`);
if (!HOST_RE.test(parsed.hostname))
throw new Error(`remotli: untrusted hostname "${parsed.hostname}" — must be remotli.ch`);
return url;
}
/** @type {Provider} */
export default {
id: 'remotli',
detect(entry) {
const raw = typeof entry.careers_url === 'string' ? entry.careers_url : '';
if (!raw) return null;
let parsed;
try {
parsed = new URL(raw);
} catch {
return null;
}View on GitHub (pinned to aac998c7ed)