feat: production readiness — 3-extension deploy with security hardening and observability
- Strip extensions to enable-banking, ai-categorization, ai-chat only - Remove push-notifications cron from vercel.json - Add security headers (HSTS, CSP, X-Frame-Options, Permissions-Policy) - Add /api/health endpoint for uptime monitoring - Add env var validation in ensureInitialized() - Fix SIE4 #IB opening balance records from year-end closing entry - Replace in-memory ai-chat rate limiter with Supabase-backed distributed rate limiting - Add Sentry error tracking scaffolding (@sentry/nextjs, instrumentation hook) - Add AI token usage tracking (migration 047, usage-tracker, wired into both AI extensions) - Include pending enable-banking and dashboard improvements Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
1a1c6ba40f
commit
13725ffc16
@@ -0,0 +1,29 @@
|
||||
-- AI usage tracking for token consumption monitoring
|
||||
CREATE TABLE IF NOT EXISTS ai_usage_tracking (
|
||||
id UUID PRIMARY KEY DEFAULT uuid_generate_v4(),
|
||||
user_id UUID REFERENCES auth.users ON DELETE CASCADE NOT NULL,
|
||||
extension_id TEXT NOT NULL,
|
||||
model TEXT NOT NULL,
|
||||
input_tokens INTEGER NOT NULL DEFAULT 0,
|
||||
output_tokens INTEGER NOT NULL DEFAULT 0,
|
||||
usage_date DATE NOT NULL DEFAULT current_date,
|
||||
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
||||
);
|
||||
|
||||
-- RLS
|
||||
ALTER TABLE ai_usage_tracking ENABLE ROW LEVEL SECURITY;
|
||||
|
||||
CREATE POLICY "Users can view own usage"
|
||||
ON ai_usage_tracking FOR SELECT
|
||||
USING (auth.uid() = user_id);
|
||||
|
||||
CREATE POLICY "Users can insert own usage"
|
||||
ON ai_usage_tracking FOR INSERT
|
||||
WITH CHECK (auth.uid() = user_id);
|
||||
|
||||
-- Indexes for efficient querying
|
||||
CREATE INDEX idx_ai_usage_tracking_user_date
|
||||
ON ai_usage_tracking (user_id, usage_date);
|
||||
|
||||
CREATE INDEX idx_ai_usage_tracking_user_ext_date
|
||||
ON ai_usage_tracking (user_id, extension_id, usage_date);
|
||||
Reference in New Issue
Block a user