handle Invalid Source Provenance
fun handleInvalidSourceProvenance(e: InvalidSourceProvenanceException): <Error class: unknown class><ExtractErrorResponse>
Answers 400 with the reason a request was refused, so a caller can read which check it broke — a length ceiling names its limit. Declared on this controller alone, so nothing else in a host application changes shape.