Romaji to Kana Converter: Angular & Express — Chapter 5, Exercise 2 ===================================================================== TASK Build the real /api/convert route with the validation this chapter describes. Send it a request with no romaji field and confirm you get a clean 400 JSON error rather than a 500 stack trace, then send it a valid request and confirm the real, correct kana comes back exactly as verified above. SOLUTION // server.js — the real, validated route require('dotenv').config(); const express = require('express'); const cors = require('cors'); const { convert } = require('./conversion-engine'); const app = express(); app.use(cors()); app.use(express.json()); app.post('/api/convert', (req, res) => { const { romaji } = req.body; if (typeof romaji !== 'string' || romaji.trim() === '') { return res.status(400).json({ error: 'romaji field is required and must be a non-empty string', }); } const result = convert(romaji); res.json(result); }); const PORT = process.env.PORT || 4000; app.listen(PORT, () => console.log(`Server running on port ${PORT}`)); Testing both cases, with the server actually running: $ curl -i -X POST http://localhost:4000/api/convert \ -H "Content-Type: application/json" -d '{}' HTTP/1.1 400 Bad Request Content-Type: application/json; charset=utf-8 {"error":"romaji field is required and must be a non-empty string"} $ curl -X POST http://localhost:4000/api/convert \ -H "Content-Type: application/json" -d '{"romaji":"gakkou e ikimasu"}' {"hiragana":"がっこう へ いきます","katakana":"ガッコウ ヘ イキマス"} WHY THIS WORKS AS AN ANSWER ---------------------------- The missing-field request returns a genuine 400 status with a structured JSON body naming the actual problem -- no HTML, no stack trace, no leaked file paths -- because the typeof/empty-string check runs and returns before convert() is ever called with a bad value. The valid request returns the exact same result the chapter's own verification script already confirmed byte-for-byte against Chapter 3's original output, this time delivered over a real HTTP round trip rather than a direct function call.