koala73/worldmonitor · error · Error

Webhook URL must not point to a private/local address

Error message

Webhook URL must not point to a private/local address

What it means

createApiKey() requires both getConvexClient() and getConvexApi() (src/services/convex-client.ts); if either resolves null it throws 'Convex unavailable' before any mutation. getConvexClient() returns null when VITE_CONVEX_URL is unset at build time, or when the ConvexClient constructor throws, notably Firefox 149/Linux rejecting with 't is not a constructor' (WORLDMONITOR-N0/MX) where the code deliberately degrades to a null client instead of crashing.

Solutions

  1. Set VITE_CONVEX_URL to the Convex deployment URL in the environment (.env.local) and rebuild
  2. Look for the console warning '[convex-client] ConvexClient constructor rejected:' to identify browser-side constructor failures
  3. Reproduce in Chrome to rule out the Firefox 149/Linux constructor bug
  4. Hide API-key creation UI and show an env-missing banner when getConvexClient() resolves null

Example fix

// before
await createApiKey(name); // throws 'Convex unavailable' with no VITE_CONVEX_URL

// after
const client = await getConvexClient();
if (!client) {
  showEnvBanner('Convex is not configured (VITE_CONVEX_URL missing or client init failed).');
  return;
}
await createApiKey(name);
Defensive patterns

Strategy: validation

Validate before calling

const client = await getConvexClient();
if (!client) {
  showEnvBanner('Convex is not configured (VITE_CONVEX_URL missing or client init failed).');
  return;
}
await createApiKey(name);

Try / catch

try {
  await createApiKey(name);
} catch (e) {
  if (e instanceof Error && e.message === 'Convex unavailable') showEnvBanner('Backend not configured.');
  else throw e;
}

Prevention

When it happens

Trigger: Running the app without VITE_CONVEX_URL in the environment; the Convex/browser constructor failing in specific browsers (console shows '[convex-client] ConvexClient constructor rejected:'); client init failing mid-boot.

Common situations: Fresh clone missing .env.local; preview/staging build missing the env var; Firefox 149/Linux bundle interop bug; tests running without clientFactoryForTests configured.

Related errors


AI-assisted analysis of koala73/worldmonitor@7d06c8633d (2026-08-21). Data as JSON: /api/errors/18655adb282cb999. Report an issue: GitHub.

Appendix: source

Thrown at api/_notification-webhook-ssrf.ts:252

export async function assertNotificationWebhookRegistrationUrlSafe(
  rawUrl: string,
  resolveHostname: ResolveHostname = defaultResolveHostname,
): Promise<void> {
  const staticError = blockedNotificationWebhookUrlReason(rawUrl);
  if (staticError) throw new Error(staticError);

  const hostname = new URL(rawUrl).hostname.toLowerCase();
  if (isIpLiteral(hostname)) return;
  let resolvedAddresses: string[];
  try {
    resolvedAddresses = await resolveHostname(hostname);
  } catch (error) {
    const message = error instanceof Error ? error.message : String(error);
    throw new Error(`Webhook URL DNS resolution failed: ${message}`);
  }
  if (!resolvedAddresses.length) throw new Error('Webhook URL DNS resolution returned no addresses');
  if (resolvedAddresses.some(isBlockedNotificationResolvedAddress)) {
    throw new Error('Webhook URL must not point to a private/local address');
  }
}

View on GitHub (pinned to 7d06c8633d)