From 494dd25cf8f9fba0ff10acaf4bef8f638ab0aa5c Mon Sep 17 00:00:00 2001 From: vimzh Date: Sun, 24 May 2026 12:43:12 +0530 Subject: [PATCH] fix(onboarding): hoist EXA_API_KEY check and return generic 503 Copilot review flagged two things: 1. console.error inside the handler fires on every request when the key is missing, which spams logs and can mask other errors. Moved the read to module scope so the warning fires once at module load. 2. 'Content extraction service is not configured' tells the client a bit too much about deployment state. Reply with a generic 'Content extraction is unavailable' instead, while keeping the detailed reason in the server log. Also bumped the status from 500 to 503 since 'service unavailable due to missing config' is what we are actually telling the client now. --- .../web/app/api/onboarding/extract-content/route.ts | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/apps/web/app/api/onboarding/extract-content/route.ts b/apps/web/app/api/onboarding/extract-content/route.ts index 6378057d..9322f324 100644 --- a/apps/web/app/api/onboarding/extract-content/route.ts +++ b/apps/web/app/api/onboarding/extract-content/route.ts @@ -9,14 +9,19 @@ interface ExaApiResponse { results: ExaContentResult[] } +const exaApiKey = process.env.EXA_API_KEY +if (!exaApiKey) { + console.error( + "EXA_API_KEY is not configured; /api/onboarding/extract-content will return 503", + ) +} + export async function POST(request: Request) { try { - const exaApiKey = process.env.EXA_API_KEY if (!exaApiKey) { - console.error("EXA_API_KEY is not configured") return Response.json( - { error: "Content extraction service is not configured" }, - { status: 500 }, + { error: "Content extraction is unavailable" }, + { status: 503 }, ) }