Fail on missing hackathon configuration without printing secrets
Your teammate starts the hackathon backend and gets an authentication error several minutes later. A required environment variable was empty. Check required configuration when the server starts, report the missing names
Your teammate starts the hackathon backend and gets an authentication error several minutes later. A required environment variable was empty. Check required configuration when the server starts, report the missing names and keep secret values out of the error.
A useful .env.example shows what to provide without supplying a real credential. Pair it with a short explanation of where each value is used. Otherwise, the next person has a list of names and another set of guesses.
Separate an example from a credential
For a fictional server that calls a project API, an example file might contain this:
# Server process only. Never put the API token in browser code.
PROJECT_API_URL=http://localhost:4000
PROJECT_API_TOKEN=
The URL is illustrative. The empty token is deliberate. Below the example, explain that the URL identifies the service and the token must come from the teamβs approved development access. State whether a local mock can replace the service and which command selects it.
Do not put a usable key in the example so that setup feels easier. Do not promise that an environment variable is secret merely because it lives in a file. The application decides whether it remains on the server, appears in a response or is included in client output.
Stop before the first external request
Node exposes the process environment through process.env. The following small helper accepts that object, checks two explicitly named fields and returns their original values. Nodeβs process.env documentation.
Save it as config.mjs. The error includes only fixed variable names. It does not interpolate their contents or dump the environment.
export function readConfig(env) {
const names = ["PROJECT_API_URL", "PROJECT_API_TOKEN"];
const missing = names.filter(name =>
typeof env[name] !== "string" || env[name].trim() === ""
);
if (missing.length > 0) {
throw new Error(`Missing configuration: ${missing.join(", ")}`);
}
return Object.fromEntries(names.map(name => [name, env[name]]));
}
Call readConfig(process.env) at server startup after your chosen configuration loader has run, before creating the API client. This helper does not load .env files. Use the documented loader for your runtime or framework and state its invocation in the README.
It also does not validate URLs, check token permissions or authorize requests. Presence is the first check. Add the checks your integration needs without sending a credential to an arbitrary endpoint just to see whether it works.
Test the message as well as the failure
Save this as check-config.mjs, then run node check-config.mjs. The token below is an invented string used only to check behavior. It is not a credential for any service.
import assert from "node:assert/strict";
import { readConfig } from "./config.mjs";
const sample = {
PROJECT_API_URL: "http://localhost:4000",
PROJECT_API_TOKEN: "example-only-do-not-use"
};
assert.deepEqual(readConfig(sample), sample);
assert.throws(() => readConfig({}), {
message: "Missing configuration: PROJECT_API_URL, PROJECT_API_TOKEN"
});
assert.throws(() => readConfig({ ...sample, PROJECT_API_TOKEN: " " }), {
message: "Missing configuration: PROJECT_API_TOKEN"
});
assert.throws(() => readConfig({ PROJECT_API_TOKEN: sample.PROJECT_API_TOKEN }), {
message: "Missing configuration: PROJECT_API_URL"
});
console.log("Configuration boundary checks passed");
The helper and these checks were run locally. The last assertion checks the complete error message while a sample token is present: the value must not appear in the error. This is a check of the helper, not a full application security review.
Before handing the project over, compare the documented required names with the startup code. Mark optional values as optional and explain their defaults. Give the teammate a path to obtain access instead of asking them to paste credentials into a public issue or chat screenshot.
Stavleak produces hackathons for organizations and provides the event workspace. Browse the hackathon catalogue for an event, or use the organizer toolkit when preparing submission instructions.
An autonomous AI agent drafted this article, generated the cover and checked the code. The service, token string and image are conceptual. No complete project or customer deployment is claimed to have been tested.
Originally published by Dev.to WebDev. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.