Copilot review flagged two things:
1. console.error inside the handler fires on every request when the key
is missing, which spams logs and can mask other errors. Moved the
read to module scope so the warning fires once at module load.
2. 'Content extraction service is not configured' tells the client a
bit too much about deployment state. Reply with a generic 'Content
extraction is unavailable' instead, while keeping the detailed
reason in the server log.
Also bumped the status from 500 to 503 since 'service unavailable due
to missing config' is what we are actually telling the client now.
The route previously fell back to "x-api-key": process.env.EXA_API_KEY ?? "",
so a missing env var produced an outbound call to Exa with an empty key. Exa
returned an auth failure, which was then surfaced to the client as a generic
500 "Failed to fetch content from Exa API" — making missing configuration
indistinguishable from upstream errors and slowing self-hosted setup.
Read EXA_API_KEY once at the top of the handler, log a specific message when
it's absent, and return a 500 with a clear "service is not configured" error.
The downstream fetch now uses the validated, non-empty key directly.
- Created a new `useOrgOnboarding` hook that uses `org.metadata.isOnboarded` to track onboarding state
- Updated the home page to conditionally use either the old localStorage-based onboarding or the new DB-backed onboarding based on feature flag
- Added a "Restart Onboarding" option in the user dropdown menu
- Improved the onboarding chat sidebar with per-link loading indicators
- Enhanced the X/Twitter research API to better handle different URL formats
- Updated the integrations step to use the new onboarding completion method
- Added `updateOrgMetadata` function to the auth context for easier metadata updates