I Am 12. My Phone Costs $150. Groq Tried to Kill My AI. Here Is How I Survived It.
I am 12 years old. My development machine is a POCO C55 that cost $150. I live in Tamil Nadu, India. Yesterday, my AI mentor, KODA, stopped working. Not because I wrote bad code. But because Groq retired the model I
I am 12 years old.
My development machine is a POCO C55 that cost $150.
I live in Tamil Nadu, India.
Yesterday, my AI mentor, KODA, stopped working. Not because I wrote bad code. But because Groq retired the model I was using.
llama-3.3-70b-versatile no longer exists. Every request returned a silent 404. My frontend showed a generic "Connection Error." My users saw nothing.
Most developers would panic. Some would wait for support tickets.
On a phone, with no terminal, no local dev server, and no wrangler tail, I had 20 minutes to fix it before my morning post went live.
Here is exactly how I stabilized KODA v23 β v24, fixed 8 critical XSS vulnerabilities, added Live Web Search, and built a fallback chain that ensures this never breaks me again.
β‘ PHASE 1: THE FRONTEND AUTOPSY
When I handed over the initial v23 report, I claimed: "Frontend is DONE AND TESTED."
That was a lie. Or rather, an optimism bias.
Upon deep inspection, I found:
-
XSS Holes: Sidebar chat titles and Vault file names were interpolating user input directly via
innerHTML. Anyone could inject scripts. -
Markdown Mangling: My regex parser was turning
#include <stdio.h>inside code blocks into<h3>headers. It was destroying C++ tutorials. -
Orphan Rows: If
createNewChat()failed, the app still tried to insert messages against anullconversation ID, cluttering the database. - Ghost Errors: API failures vanished on re-render because they werenβt pushed to state.
The Fixes
- Security First: Switched all dynamic rendering to
textContent+escapeHtml(). Zero injection points remain. - Smart Markdown: Stashed code blocks behind placeholders before running inline formatting (bold/italic/headings), then restored them. Now
**bold**works outside code, but#hashstays safe inside it. - State Integrity:
createNewChat()now returns a boolean. If false, the caller aborts. No more orphan rows. - Visible Failures: All errors are now pushed to
state.messagesso they persist across renders. Users see exactly what went wrong.
π οΈ PHASE 2: SURVIVING THE MODEL DEPRECATION
The root cause of the outage was simple: Cloud providers retire models.
Groq killed llama-3.3-70b-versatile. I needed a new brain, fast.
The Solution: The Fallback Chain
I didn't just swap one model for another. I built a resilience layer.
const MODELS = [
'openai/gpt-oss-120b', // Primary: Current Flagship
'openai/gpt-oss-20b', // Secondary: Fast/Lightweight
'qwen/qwen3-32b' // Tertiary: Open Source Alternative
];
// Logic: Try Primary. If 404/5xx, auto-retry Next. User sees nothing.
Now, if Groq kills gpt-oss-120b tomorrow, KODA automatically switches to gpt-oss-20b within milliseconds. The user never knows.
Debugging Without a Terminal
How do you debug a Cloudflare Worker on a phone?
You don't use CLI tools. You use the Dashboard.
- Opened Cloudflare Dashboard β Worker β Logs Tab.
- Saw the raw error:
{"error":{"message":"The model llama-3.3-70b-versatile does not exist..."}} - Updated the model string in the editor.
- Hit Deploy.
- Verified with a GET health check endpoint I added specifically for this scenario.
Lesson: Never trust your own status report. Test before you claim. And always build a health check endpoint (GET /) that confirms secrets are loaded.
π PHASE 3: LIVE WEB SEARCH (STOPPING THE HALLUCINATIONS)
Before this update, I asked KODA: "What is the latest React version?"
It confidently replied: "React 19.3 was released September 9, 2026."
It cited sources like γ1β L1-L4γ.
Fake. Hallucinated. Dangerous.
Without live data, LLMs guess. With live data, they know.
Implementation
- Backend: Integrated Tavily API (1,000 free searches/month). Stored key as
TAVILY_API_KEYsecret. - Logic: When
webSearch: trueis sent from frontend:- Worker calls Tavily.
- Gets 5 ranked results + AI summary.
- Injects them into Groq prompt as
[WEB_RESULTS]. - Instructs model to cite
[1],[2].
- Frontend: Toggle button turns orange when active. Sources render as clickable links below the reply.
Now, when I ask about React, KODA pulls the actual npm registry data and cites the official blog post. No more guessing.
π THE BY-THE-NUMBERS RECOVERY
| Metric | Value |
|---|---|
| Days from Broken to Stable | 3 |
| Critical Bugs Fixed | 8 (incl. 2 XSS) |
| New Features Added | 20+ (Voice, Edit, Regenerate, Theme) |
| Languages Supported | 9 (EN, HI, TA, ZH, ES, JA, RU, PT, AR) |
| Lines of Worker Code | ~280 |
| Hardware Used | 1 Phone |
| Model Deprecations Survived | 2 |
π FINAL THOUGHTS
People ask why I bother building on a POCO C55. Why not use a MacBook?
Because constraints force creativity.
- No terminal? Use the Dashboard logs.
- No local server? Use Hoppscotch in the browser.
- Model died? Build a fallback chain.
- Hallucinating? Add web search.
Age doesn't matter. Device doesn't matter. Location doesn't matter.
Resilience matters.
KODA v24 is live. The fallback chain is armed. The web search is on. The XSS holes are sealed.
Try it here: koda-aicodementor.netlify.app
Break it if you can. Iβll be watching the logs. π―
BuildInPublic #AI #Cloudflare #Groq #Cybersecurity #WebDev #HYNAWEB #SoloFounder #Resilience #12YearsOld
Originally published by Dev.to WebDev. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.