Backend (app-pfm-ocr-v2/backend): - Product/SKU scan feature complete: trained DINOv2 index (118 reference photos, 16 SKU classes) and YOLO classifier (83.3% top-1 val accuracy), fixed scripts/install-pipeline.sh (was missing ultralytics/torch), fully browser-verified end-to-end on /scan-pfm. Mobile m-scan-pfm page cancelled (Flutter app handles mobile; web UI is desktop-only for pipeline testing). - Fixed a real data-loss bug: Save Ground Truth (scan-pfm and the DO-flow's manual-label) was silently writing into the pfm-web-app container's ephemeral filesystem instead of the host, because /sources wasn't bind-mounted in docker-compose.yml. Added the mount, recovered an orphaned entry. - accounts.password is now bcrypt-hashed (bcryptjs, idempotent migration in db/init.ts) instead of plaintext; login route compares hashes. - /api/v1/documents/* (list, PUT, upload) now enforces real 401 auth, matching what the Flutter client already sends. The "classic" routes deliberately stay open — they're dev-only web UI with no login flow and won't exist in production. - OCR accuracy investigated end-to-end: real baseline is 95.10% overall (target met; accuracy_report.md was stale at 75.04%, now flagged). Fixed one genuine parser.ts bug (SO/DO field duplication in the global fallback regex); remaining gaps are OCR/layout-model limitations, not parser bugs. - Adopted a standalone copy of the fhanyuh/agents-settings e/n workflow scoped to backend/ (AGENTS.md Part A/B split, SKILLS.md, plans/, docs/), independent of the root copy which now covers Flutter only. - next-implementation.md deleted; content folded into backend/plans/next-enhancements.md for traceability. Root: - Adopted fhanyuh/agents-settings kit (AGENTS.md, SKILLS.md, plans/, docs/feature-list.md), scoped to the Flutter app only. - Pending documents queue now persists to Hive (lib/core/storage) instead of memory-only, surviving an app kill mid-upload. Removed backend_backup/ (stale Express/Prisma prototype, superseded by pfm-web-app) and the completed plans/next-enhancement-plan.md checklist. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
76 lines
2.5 KiB
Dart
76 lines
2.5 KiB
Dart
import 'package:dio/dio.dart';
|
|
import 'package:flutter_riverpod/flutter_riverpod.dart';
|
|
import 'package:shared_preferences/shared_preferences.dart';
|
|
import '../../config/app_config.dart';
|
|
import 'api_exception.dart';
|
|
|
|
class ApiClient {
|
|
late final Dio _dio;
|
|
|
|
ApiClient() {
|
|
_dio = Dio(
|
|
BaseOptions(
|
|
baseUrl: AppConfig.apiBaseUrl,
|
|
connectTimeout: const Duration(seconds: 10),
|
|
// Upload triggers a synchronous OCR pass server-side that can take up to
|
|
// 210s worst case (see v1/documents/upload/route.ts's AbortSignal.timeout).
|
|
// Keep a safety margin above that so a legitimately slow-but-successful
|
|
// parse isn't killed client-side as a false "connection timeout".
|
|
receiveTimeout: const Duration(seconds: 240),
|
|
headers: {
|
|
'Content-Type': 'application/json',
|
|
'Accept': 'application/json',
|
|
},
|
|
),
|
|
);
|
|
|
|
_setupInterceptors();
|
|
}
|
|
|
|
void _setupInterceptors() {
|
|
// Request interceptor to append JWT token
|
|
_dio.interceptors.add(InterceptorsWrapper(
|
|
onRequest: (options, handler) async {
|
|
final prefs = await SharedPreferences.getInstance();
|
|
final token = prefs.getString('auth_token');
|
|
if (token != null) {
|
|
options.headers['Authorization'] = 'Bearer $token';
|
|
}
|
|
return handler.next(options);
|
|
},
|
|
));
|
|
|
|
// Logging interceptor for debugging
|
|
_dio.interceptors.add(LogInterceptor(
|
|
requestBody: true,
|
|
responseBody: true,
|
|
));
|
|
|
|
// Standardized Error Interceptor: wraps every failure into an ApiException
|
|
// (attached as DioException.error) so call sites read one consistent shape
|
|
// instead of reverse-engineering DioException.toString().
|
|
_dio.interceptors.add(InterceptorsWrapper(
|
|
onError: (DioException e, handler) {
|
|
final apiException = ApiException.fromDioException(e);
|
|
final customError = DioException(
|
|
requestOptions: e.requestOptions,
|
|
response: e.response,
|
|
type: e.type,
|
|
error: apiException,
|
|
);
|
|
return handler.next(customError);
|
|
},
|
|
));
|
|
|
|
// Dummy Response Interceptor for Development
|
|
// TODO: Remove this interceptor before production release
|
|
// _dio.interceptors.add(DummyResponseInterceptor());
|
|
}
|
|
|
|
Dio get client => _dio;
|
|
}
|
|
|
|
// Single shared instance so every screen/notifier reuses the same Dio HTTP client
|
|
// (connection keep-alive) instead of paying a fresh TCP/TLS handshake per call site.
|
|
final apiClientProvider = Provider<ApiClient>((ref) => ApiClient());
|