santifer/career-ops · error · Error

solidjobs: URL must use HTTPS

Error message

solidjobs: URL must use HTTPS: ${url}

What it means

assertUrl enforces HTTPS for every SolidJobs API URL: a parseable URL whose protocol is not https: (usually http:) is rejected. The public API at solid.jobs is only consumed over TLS, both for security and because redirect:'error' + HTTPS is part of the provider's SSRF posture.

Solutions

  1. Change the scheme to https:// in careers_url
  2. Grep portals.yml for http://solid.jobs and fix all occurrences
  3. Rely on detect()/fetch building URLs from the documented https form rather than pasting raw http URLs
  4. If redirect downgrades occur, keep redirect:'error' and do not follow to http targets

Example fix

// before
careers_url: 'http://solid.jobs/public-api/offers/it'
// after
careers_url: 'https://solid.jobs/public-api/offers/it'
Defensive patterns

Strategy: validation

Validate before calling

function isHttpsSolidjobsUrl(url) {
  try {
    const u = new URL(url);
    return u.protocol === 'https:' && u.hostname === 'solid.jobs';
  } catch { return false; }
}
if (!isHttpsSolidjobsUrl(entry.careers_url)) throw new Error('solidjobs requires https://solid.jobs URLs');

Try / catch

try {
  await solidjobsProvider.fetch(entry, ctx);
} catch (e) {
  if (String(e.message).includes('must use HTTPS')) {
    console.error(`Entry ${entry.name}: upgrade ${entry.careers_url} to https://`);
  } else throw e;
}

Prevention

When it happens

Trigger: Configuring careers_url as http://solid.jobs/public-api/offers/it; calling assertUrl directly in tests with an http:// URL; a proxy or local rewrite that downgrades the scheme.

Common situations: Typing http:// out of habit in portals.yml; an old config from before an HTTPS migration; string interpolation that lost the 's'; mirrored/internal endpoints using plain HTTP.

Understand the failure class

Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.

Related errors


AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16). Data as JSON: /api/errors/3a8397537089cf30. Report an issue: GitHub.

Appendix: source

Thrown at providers/solidjobs.mjs:27

const ALLOWED_HOSTS = new Set(['solid.jobs']);

/**
 * Validates that the provided URL is a trusted SolidJobs API endpoint.
 * Enforces HTTPS protocol, strict hostname matching, and required path prefix.
 * 
 * @param {string} url - The URL string to validate.
 * @returns {string} The validated URL string.
 * @throws {Error} If the URL is malformed, uses non-HTTPS, has an untrusted host, or wrong path.
 */
function assertUrl(url) {
  let parsed;
  try {
    parsed = new URL(url);
  } catch {
    throw new Error(`solidjobs: invalid URL: ${url}`);
  }
  if (parsed.protocol !== 'https:') throw new Error(`solidjobs: URL must use HTTPS: ${url}`);
  if (!ALLOWED_HOSTS.has(parsed.hostname))
    throw new Error(`solidjobs: untrusted hostname "${parsed.hostname}" — must be solid.jobs`);
  if (!parsed.pathname.startsWith('/public-api/offers/'))
    throw new Error(`solidjobs: URL path must start with /public-api/offers/: ${url}`);
  return url;
}

/** @type {Provider} */
export default {
  id: 'solidjobs',

  /**
   * Attempts to detect if the provider can handle the given entry by checking the careers_url.
   * * @param {{ careers_url?: string, name?: string }} entry - The configuration entry.
   * @returns {{url: string} | null} An object with the matched URL, or null if not matched.
   */
  detect(entry) {
    const url = entry.careers_url || '';

View on GitHub (pinned to aac998c7ed)