koala73/worldmonitor · error · Error
Webhook URL must not point to a private/local address
Error message
Webhook URL must not point to a private/local address
What it means
createApiKey() requires both getConvexClient() and getConvexApi() (src/services/convex-client.ts); if either resolves null it throws 'Convex unavailable' before any mutation. getConvexClient() returns null when VITE_CONVEX_URL is unset at build time, or when the ConvexClient constructor throws, notably Firefox 149/Linux rejecting with 't is not a constructor' (WORLDMONITOR-N0/MX) where the code deliberately degrades to a null client instead of crashing.
Solutions
- Set VITE_CONVEX_URL to the Convex deployment URL in the environment (.env.local) and rebuild
- Look for the console warning '[convex-client] ConvexClient constructor rejected:' to identify browser-side constructor failures
- Reproduce in Chrome to rule out the Firefox 149/Linux constructor bug
- Hide API-key creation UI and show an env-missing banner when getConvexClient() resolves null
Example fix
// before
await createApiKey(name); // throws 'Convex unavailable' with no VITE_CONVEX_URL
// after
const client = await getConvexClient();
if (!client) {
showEnvBanner('Convex is not configured (VITE_CONVEX_URL missing or client init failed).');
return;
}
await createApiKey(name); Defensive patterns
Strategy: validation
Validate before calling
const client = await getConvexClient();
if (!client) {
showEnvBanner('Convex is not configured (VITE_CONVEX_URL missing or client init failed).');
return;
}
await createApiKey(name); Try / catch
try {
await createApiKey(name);
} catch (e) {
if (e instanceof Error && e.message === 'Convex unavailable') showEnvBanner('Backend not configured.');
else throw e;
} Prevention
- Fail fast at boot: if getConvexClient() is null, hide Convex-backed features
- Keep VITE_CONVEX_URL in .env.local for every environment that renders the settings UI
- Watch for the '[convex-client] ConvexClient constructor rejected:' warning to catch browser-specific init failures
When it happens
Trigger: Running the app without VITE_CONVEX_URL in the environment; the Convex/browser constructor failing in specific browsers (console shows '[convex-client] ConvexClient constructor rejected:'); client init failing mid-boot.
Common situations: Fresh clone missing .env.local; preview/staging build missing the env var; Firefox 149/Linux bundle interop bug; tests running without clientFactoryForTests configured.
Related errors
AI-assisted analysis of koala73/worldmonitor@7d06c8633d (2026-08-21).
Data as JSON: /api/errors/18655adb282cb999.
Report an issue: GitHub.
Appendix: source
Thrown at api/_notification-webhook-ssrf.ts:252
export async function assertNotificationWebhookRegistrationUrlSafe(
rawUrl: string,
resolveHostname: ResolveHostname = defaultResolveHostname,
): Promise<void> {
const staticError = blockedNotificationWebhookUrlReason(rawUrl);
if (staticError) throw new Error(staticError);
const hostname = new URL(rawUrl).hostname.toLowerCase();
if (isIpLiteral(hostname)) return;
let resolvedAddresses: string[];
try {
resolvedAddresses = await resolveHostname(hostname);
} catch (error) {
const message = error instanceof Error ? error.message : String(error);
throw new Error(`Webhook URL DNS resolution failed: ${message}`);
}
if (!resolvedAddresses.length) throw new Error('Webhook URL DNS resolution returned no addresses');
if (resolvedAddresses.some(isBlockedNotificationResolvedAddress)) {
throw new Error('Webhook URL must not point to a private/local address');
}
}
View on GitHub (pinned to 7d06c8633d)