fix(client): update AWS credential handling to prefer BEDROCK_AWS_* environment variables (#937)

This commit is contained in:
Mattsson
2026-07-08 18:09:34 +02:00
committed by GitHub
parent b10cf2ec23
commit ae489cfdcb
3 changed files with 43 additions and 16 deletions
@@ -246,7 +246,18 @@ export async function extractInvoiceFields(
return { data: emptyResult(), rawText: null }
}
if (!process.env.AWS_ACCESS_KEY_ID || !process.env.AWS_SECRET_ACCESS_KEY) {
// Prefer BEDROCK_AWS_* over the plain AWS_* names: on Vercel/Lambda the
// platform injects its own reserved AWS_* execution-role vars that shadow
// whatever is configured, so a hosted deploy must use the BEDROCK_AWS_* names
// (see lib/agent/composer/client.ts for the full explanation).
const awsRegion =
process.env.BEDROCK_AWS_REGION || process.env.AWS_REGION || 'eu-north-1'
const awsAccessKey =
process.env.BEDROCK_AWS_ACCESS_KEY_ID || process.env.AWS_ACCESS_KEY_ID
const awsSecretKey =
process.env.BEDROCK_AWS_SECRET_ACCESS_KEY || process.env.AWS_SECRET_ACCESS_KEY
if (!awsAccessKey || !awsSecretKey) {
log.warn('AWS Bedrock credentials missing: returning empty extraction', {
file_name_hash: createHash('sha256').update(input.fileName).digest('hex').slice(0, 12),
})
@@ -254,9 +265,9 @@ export async function extractInvoiceFields(
}
const client = new AnthropicBedrock({
awsRegion: process.env.AWS_REGION || 'eu-north-1',
awsAccessKey: process.env.AWS_ACCESS_KEY_ID,
awsSecretKey: process.env.AWS_SECRET_ACCESS_KEY,
awsRegion,
awsAccessKey,
awsSecretKey,
})
let rawText: string | null = null