santifer/career-ops · error · Error
solidjobs: URL must use HTTPS
Error message
solidjobs: URL must use HTTPS: ${url} What it means
assertUrl enforces HTTPS for every SolidJobs API URL: a parseable URL whose protocol is not https: (usually http:) is rejected. The public API at solid.jobs is only consumed over TLS, both for security and because redirect:'error' + HTTPS is part of the provider's SSRF posture.
Solutions
- Change the scheme to https:// in careers_url
- Grep portals.yml for http://solid.jobs and fix all occurrences
- Rely on detect()/fetch building URLs from the documented https form rather than pasting raw http URLs
- If redirect downgrades occur, keep redirect:'error' and do not follow to http targets
Example fix
// before careers_url: 'http://solid.jobs/public-api/offers/it' // after careers_url: 'https://solid.jobs/public-api/offers/it'
Defensive patterns
Strategy: validation
Validate before calling
function isHttpsSolidjobsUrl(url) {
try {
const u = new URL(url);
return u.protocol === 'https:' && u.hostname === 'solid.jobs';
} catch { return false; }
}
if (!isHttpsSolidjobsUrl(entry.careers_url)) throw new Error('solidjobs requires https://solid.jobs URLs'); Try / catch
try {
await solidjobsProvider.fetch(entry, ctx);
} catch (e) {
if (String(e.message).includes('must use HTTPS')) {
console.error(`Entry ${entry.name}: upgrade ${entry.careers_url} to https://`);
} else throw e;
} Prevention
- Standardize on https:// in all portal config; ban http:// in validation
- Remember the provider uses redirect:'error' so an http URL cannot silently succeed after a redirect
- Grep config for http://solid.jobs on every config change
- Prefer letting detect() accept entries rather than hand-pasting raw URLs
When it happens
Trigger: Configuring careers_url as http://solid.jobs/public-api/offers/it; calling assertUrl directly in tests with an http:// URL; a proxy or local rewrite that downgrades the scheme.
Common situations: Typing http:// out of habit in portals.yml; an old config from before an HTTPS migration; string interpolation that lost the 's'; mirrored/internal endpoints using plain HTTP.
Understand the failure class
Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.
Related errors
- smartrecruiters: URL must use HTTPS
- a16z-speedrun-talent: URL must use HTTPS
- agentic-jobs: URL must use HTTPS
- collage: URL must use HTTPS
- getonbrd: URL must use HTTPS
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/3a8397537089cf30.
Report an issue: GitHub.
Appendix: source
Thrown at providers/solidjobs.mjs:27
const ALLOWED_HOSTS = new Set(['solid.jobs']);
/**
* Validates that the provided URL is a trusted SolidJobs API endpoint.
* Enforces HTTPS protocol, strict hostname matching, and required path prefix.
*
* @param {string} url - The URL string to validate.
* @returns {string} The validated URL string.
* @throws {Error} If the URL is malformed, uses non-HTTPS, has an untrusted host, or wrong path.
*/
function assertUrl(url) {
let parsed;
try {
parsed = new URL(url);
} catch {
throw new Error(`solidjobs: invalid URL: ${url}`);
}
if (parsed.protocol !== 'https:') throw new Error(`solidjobs: URL must use HTTPS: ${url}`);
if (!ALLOWED_HOSTS.has(parsed.hostname))
throw new Error(`solidjobs: untrusted hostname "${parsed.hostname}" — must be solid.jobs`);
if (!parsed.pathname.startsWith('/public-api/offers/'))
throw new Error(`solidjobs: URL path must start with /public-api/offers/: ${url}`);
return url;
}
/** @type {Provider} */
export default {
id: 'solidjobs',
/**
* Attempts to detect if the provider can handle the given entry by checking the careers_url.
* * @param {{ careers_url?: string, name?: string }} entry - The configuration entry.
* @returns {{url: string} | null} An object with the matched URL, or null if not matched.
*/
detect(entry) {
const url = entry.careers_url || '';View on GitHub (pinned to aac998c7ed)