* feat(ai): job-shaped AI service with OpenAI-compatible backend, extraction-first; stop extracting every inbox document twice Sovereign plan WS1 PR1 (#1406 Tier 2, extraction-first, aligned with the AI surface audit). lib/ai grows a job-shaped service (generateText / generateStructured / extractFromDocument; no streaming members yet, see plan rule R3): - services/anthropic-family delegates to the existing createAiClient() and sends the exact request literals the inbox extractor sent before (request-shape tests deep-equal them), so hosted Bedrock stays byte-identical. - services/openai-compatible talks to any chat-completions endpoint (BYO Swedish provider) via Vercel AI SDK 6.x, exact-pinned and guarded: images as parts, PDFs rasterized with poppler (AI_PDF_MODE) or sent natively, AI_VISION / AI_STRICT_JSON declared, honest skips (ai_no_vision, pdf_rasterizer_missing) instead of fake failures. - config.ts: AI_PROVIDER/AI_BASE_URL/AI_API_KEY/AI_MODEL and per-tier AI_*_MODEL with the legacy BEDROCK_* names kept as the same overrides; getAiStatus() is the single source of truth for "is AI wired up". - provider.ts: openai-compatible in the auto-detect chain (after Bedrock and the direct API); createAiClient() refuses it loudly. Document extraction moves onto the service and gets the audit's fixes: - Inbox documents were extracted TWICE (pipeline A ran inside uploadDocument() before the inbox row existed, so its dedupe branch never fired; 3 707 + 1 666 calls / 30 d). The inbox now declares extractionOwner on the upload, the extension yields, and the inbox mirrors its single outcome onto document_attachments from every writer (sync, deferred, attach, retry, MCP). - Every "no extraction will ever happen" outcome is stamped (skipped:no_ai_entitlement / ai_unconfigured / system_generated / ...); the status route maps the quiet ones to 'disabled' on the first poll instead of a 30 s client timeout. Prod showed 309 of the 327 never-extracted uploads were the paywall working silently. - Self-generated documents (our own invoice PDFs, payout files) are no longer OCR'd. - Agent invoke answers 503 ai_unconfigured when the deployment has no assistant backend, distinct from the paywall. Guard: new direct-ai-client antipattern check (shrink-only allowlist of the pre-abstraction SDK callers) plus exact pins for @anthropic-ai/sdk, ai and @ai-sdk/openai-compatible. Verified: 15 958 unit tests green, guards, lint ratchet, typecheck, and a live smoke against hosted Bedrock through the new service (ping, streamed tool turn, thinking+cache, PDF extraction). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(ai): make AI_API_KEY optional for OpenAI-compatible endpoints (keyless local model servers) A local model server (llama.cpp's server, Ollama /v1, LM Studio, vLLM) usually has no auth. Before, the OpenAI-compatible backend required both AI_BASE_URL and AI_API_KEY to count as configured, so running Accounted on a local model meant setting a meaningless placeholder key. - resolveAiProvider / hasAiCredentials: a base URL alone is now enough. - services/openai-compatible: only send Authorization: Bearer when AI_API_KEY is set, so a keyless server is never handed an empty bearer; a hosted provider that needs a key still sets it. - Docs (SELF-HOSTING Option 3: local-model example, key marked optional), DECISIONS. Verified: with no AI_API_KEY, just AI_BASE_URL + AI_MODEL, getAiStatus() reports configured=true / provider=openai-compatible (live). lib/ai suite 71 green; tsc, guards, lint clean. Bedrock/Anthropic logic unchanged. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
65 lines
2.5 KiB
TypeScript
65 lines
2.5 KiB
TypeScript
import { createServiceClientNoCookies } from '@/lib/auth/api-keys'
|
|
import { createLogger } from '@/lib/logger'
|
|
import type { InvoiceExtractionResult } from '@/types'
|
|
|
|
const log = createLogger('invoice-inbox-mirror')
|
|
|
|
export interface ExtractionOutcome {
|
|
/** The parsed result (may be the empty skeleton). Ignored unless `rawText` is set and nothing was skipped. */
|
|
data: InvoiceExtractionResult | null
|
|
/** Raw model output; null when the call failed or was skipped. */
|
|
rawText: string | null
|
|
/** Provider-form model id that answered, when a call was made. */
|
|
model?: string | null
|
|
/** Why no model call was made: inbox skip reasons and lib/ai skip reasons alike. */
|
|
skipped?: string | null
|
|
}
|
|
|
|
/**
|
|
* Mirror an inbox extraction outcome onto document_attachments
|
|
* (extracted_data / extracted_at / extraction_model).
|
|
*
|
|
* The invoice inbox owns extraction for the documents it ingests, and the
|
|
* document-extraction extension yields to it (see extractionOwner on the
|
|
* document.uploaded event). Everything that read the document row before
|
|
* (the extraction-status poll behind the upload UI, the agent intents'
|
|
* "what do we already know" reads) keeps working because the inbox writes
|
|
* the same columns the extension would have, with the one model call it
|
|
* actually made.
|
|
*
|
|
* Service-role client, same as the extension: this runs from routes, the
|
|
* deferred worker and the MCP server alike, and the write is a system
|
|
* side-effect rather than a user action. Never throws: a failed mirror
|
|
* leaves the document row unstamped, which the UI already tolerates.
|
|
*/
|
|
export async function mirrorExtractionToDocument(
|
|
documentId: string,
|
|
outcome: ExtractionOutcome
|
|
): Promise<void> {
|
|
try {
|
|
const succeeded = !outcome.skipped && outcome.rawText != null && outcome.data != null
|
|
const extractionModel = outcome.skipped
|
|
? `skipped:${outcome.skipped}`
|
|
: succeeded
|
|
? outcome.model || 'invoice-inbox'
|
|
: 'failed:no_raw_text'
|
|
const supabase = createServiceClientNoCookies()
|
|
const { error } = await supabase
|
|
.from('document_attachments')
|
|
.update({
|
|
extracted_data: succeeded ? (outcome.data as unknown as Record<string, unknown>) : null,
|
|
extracted_at: new Date().toISOString(),
|
|
extraction_model: extractionModel,
|
|
})
|
|
.eq('id', documentId)
|
|
if (error) {
|
|
log.warn('mirror failed', { doc: documentId, extractionModel, err: error.message })
|
|
}
|
|
} catch (err) {
|
|
log.warn('mirror threw', {
|
|
doc: documentId,
|
|
err: err instanceof Error ? err.message : String(err),
|
|
})
|
|
}
|
|
}
|