Adopt agents-settings kit, ship Product/SKU scan models, harden auth, verify OCR accuracy

Backend (app-pfm-ocr-v2/backend):
- Product/SKU scan feature complete: trained DINOv2 index (118 reference
  photos, 16 SKU classes) and YOLO classifier (83.3% top-1 val accuracy),
  fixed scripts/install-pipeline.sh (was missing ultralytics/torch), fully
  browser-verified end-to-end on /scan-pfm. Mobile m-scan-pfm page cancelled
  (Flutter app handles mobile; web UI is desktop-only for pipeline testing).
- Fixed a real data-loss bug: Save Ground Truth (scan-pfm and the DO-flow's
  manual-label) was silently writing into the pfm-web-app container's
  ephemeral filesystem instead of the host, because /sources wasn't
  bind-mounted in docker-compose.yml. Added the mount, recovered an
  orphaned entry.
- accounts.password is now bcrypt-hashed (bcryptjs, idempotent migration
  in db/init.ts) instead of plaintext; login route compares hashes.
- /api/v1/documents/* (list, PUT, upload) now enforces real 401 auth,
  matching what the Flutter client already sends. The "classic" routes
  deliberately stay open — they're dev-only web UI with no login flow and
  won't exist in production.
- OCR accuracy investigated end-to-end: real baseline is 95.10% overall
  (target met; accuracy_report.md was stale at 75.04%, now flagged). Fixed
  one genuine parser.ts bug (SO/DO field duplication in the global fallback
  regex); remaining gaps are OCR/layout-model limitations, not parser bugs.
- Adopted a standalone copy of the fhanyuh/agents-settings e/n workflow
  scoped to backend/ (AGENTS.md Part A/B split, SKILLS.md, plans/, docs/),
  independent of the root copy which now covers Flutter only.
- next-implementation.md deleted; content folded into
  backend/plans/next-enhancements.md for traceability.

Root:
- Adopted fhanyuh/agents-settings kit (AGENTS.md, SKILLS.md, plans/,
  docs/feature-list.md), scoped to the Flutter app only.
- Pending documents queue now persists to Hive (lib/core/storage) instead
  of memory-only, surviving an app kill mid-upload.

Removed backend_backup/ (stale Express/Prisma prototype, superseded by
pfm-web-app) and the completed plans/next-enhancement-plan.md checklist.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Rafhan Mazaya FathurrahmanandClaude Sonnet 5 committed 2026-07-08 11:56:32 +07:00
1 parent 3df9f6ec5d
commit e60ab63154
129 files changed
+8520 -6684

No files matched your search

+27 -3
View File
@@ -221,13 +221,35 @@ async function fetchWithTimeout(url: string, init: RequestInit, timeoutMs: numbe
}
}
async function fetchParse(baseUrl: string, filename: string): Promise<any> {
// Store name/address are assigned per-account now, not OCR-detected (see
// v1/documents/upload/route.ts + /api/parse). To score store/alamat fields
// the same way production behaves, simulate "the account assigned to this
// image's ground-truth store uploaded it" by resolving gt.store -> kode_toko
// and passing that through, same as a real account's JWT would.
async function fetchStoreNameToKodeMap(): Promise<Map<string, string>> {
const { Pool } = await import("pg");
const pool = new Pool({
host: process.env.PGHOST || "localhost",
port: parseInt(process.env.PGPORT || "5432", 10),
user: process.env.PGUSER || "postgres",
password: process.env.PGPASSWORD || "postgres",
database: process.env.PGDATABASE || "dopfm",
});
try {
const res = await pool.query("SELECT nama_toko, kode_toko FROM store_master");
return new Map(res.rows.map((r: any) => [r.nama_toko, r.kode_toko]));
} finally {
await pool.end();
}
}
async function fetchParse(baseUrl: string, filename: string, kodeToko?: string): Promise<any> {
const res = await fetchWithTimeout(
`${baseUrl}/api/parse`,
{
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ filename }),
body: JSON.stringify({ filename, kodeToko }),
},
FETCH_TIMEOUT_MS
);
@@ -540,6 +562,7 @@ async function main() {
const gtMap = loadGroundTruth();
const testImages = listTestImages();
const storeNameToKode = await fetchStoreNameToKodeMap();
if (testImages.length === 0) {
console.error(`No test images found in ${TEST_IMAGES_DIR}`);
@@ -566,7 +589,8 @@ async function main() {
if (!gt) continue;
process.stdout.write(`Parsing ${filename}... `);
try {
const parsed = await fetchParse(args.baseUrl, filename);
const kodeToko = storeNameToKode.get(gt.store);
const parsed = await fetchParse(args.baseUrl, filename, kodeToko);
const { checks, detail } = compareImage(gt, parsed);
allChecks.push(...checks);
detailsByFile[filename] = detail;