santifer/career-ops · error · Error
smartrecruiters: URL must use HTTPS
Error message
smartrecruiters: URL must use HTTPS: ${url} What it means
assertSmartRecruitersUrl enforces HTTPS: any URL with a protocol other than https: (typically http:) is rejected. The SmartRecruiters provider only talks to the TLS-protected api.smartrecruiters.com endpoint, so plaintext URLs are refused both for security and because the plain-HTTP endpoint would not resolve correctly anyway.
Solutions
- Change the scheme to https:// in the configured URL
- Check portals.yml for http:// occurrences of smartrecruiters hosts and correct them
- Use the provider's buildPostingsUrl helper, which always emits https://
- Note resolveSlug() silently skips non-HTTPS entries — if your careers_url is http://, slug derivation fails; fix the scheme rather than expecting a fallback
Example fix
// before careers_url: 'http://careers.smartrecruiters.com/acme' // after careers_url: 'https://careers.smartrecruiters.com/acme'
Defensive patterns
Strategy: validation
Validate before calling
function isHttpsUrl(url) {
try { return new URL(url).protocol === 'https:'; } catch { return false; }
}
if (!isHttpsUrl(entry.api ?? entry.careers_url)) throw new Error('smartrecruiters URLs must use https://'); Try / catch
try {
await srProvider.fetch(entry, ctx);
} catch (e) {
if (String(e.message).includes('must use HTTPS')) {
console.error(`Entry ${entry.name}: switch ${entry.api ?? entry.careers_url} to https://`);
} else throw e;
} Prevention
- Grep portals.yml for 'http://' periodically and fix to https://
- Adopt https as the only accepted scheme in config validation
- Remember resolveSlug silently skips non-HTTPS inputs — a http careers_url also causes slug-derivation errors downstream
- Keep redirect:'error' so TLS downgrade via redirect cannot happen silently
When it happens
Trigger: Configuring an api or careers_url with http:// instead of https:// and having that raw URL reach assertSmartRecruitersUrl; calling the validator directly in tests or tooling with an http:// URL.
Common situations: Hand-editing portals.yml and typing http:// out of habit; copying an internal staging URL that uses plain HTTP; an old config written before an HTTPS migration; proxy tooling rewriting the scheme.
Understand the failure class
Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.
Related errors
- solidjobs: URL must use HTTPS
- a16z-speedrun-talent: URL must use HTTPS
- agentic-jobs: URL must use HTTPS
- collage: URL must use HTTPS
- getonbrd: URL must use HTTPS
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/0c3f3e800f2dd185.
Report an issue: GitHub.
Appendix: source
Thrown at providers/smartrecruiters.mjs:72
const sections = detail?.jobAd?.sections;
if (!sections || typeof sections !== 'object') return '';
const parts = [];
for (const key of ['companyDescription', 'jobDescription', 'qualifications', 'additionalInformation']) {
const text = sections[key]?.text;
if (typeof text === 'string' && text.trim()) parts.push(text);
}
if (parts.length === 0) return '';
return htmlToText(parts.join('\n'));
}
function assertSmartRecruitersUrl(url) {
let parsed;
try {
parsed = new URL(url);
} catch {
throw new Error(`smartrecruiters: invalid URL: ${url}`);
}
if (parsed.protocol !== 'https:') throw new Error(`smartrecruiters: URL must use HTTPS: ${url}`);
if (!ALLOWED_SMARTRECRUITERS_HOSTS.has(parsed.hostname)) {
throw new Error(`smartrecruiters: untrusted hostname "${parsed.hostname}" — must be one of: ${[...ALLOWED_SMARTRECRUITERS_HOSTS].join(', ')}`);
}
return url;
}
function resolveSlug(entry) {
// entry.api takes precedence over careers_url (mirrors greenhouse/ashby) so a
// branded page (e.g. https://jobs.continental.com) can stay as careers_url
// while the SmartRecruiters slug is pinned via
// api: https://careers.smartrecruiters.com/<slug> in portals.yml.
for (const raw of [entry.api, entry.careers_url]) {
if (typeof raw !== 'string' || !raw) continue;
let parsed;
try {
parsed = new URL(raw);
} catch {
continue;View on GitHub (pinned to aac998c7ed)