fix: RLS guard in match_incidents + try/catch around AI/embed calls
- Add new migration 20260711000013_match_incidents_auth_guard.sql that replaces match_incidents with an inline auth guard: callers without hse/admin role receive PGRST301 Forbidden, closing the SECURITY DEFINER RLS bypass. - Wrap anthropic.messages.create() in try/catch returning 503 in all four AI routes: quality-check, triage-suggest, rca-draft, similar. - Wrap JSON.parse(inc.embedding) and embedText() in similar/route.ts in a shared try/catch returning 503 Embedding service unavailable. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FFDuBhMKvoWjrWT3ZnGmmr
This commit is contained in:
@@ -19,39 +19,44 @@ export async function POST(request: NextRequest) {
|
||||
return NextResponse.json({ error: 'description and incident_type required' }, { status: 422 })
|
||||
}
|
||||
|
||||
const message = await anthropic.messages.create({
|
||||
model: 'claude-opus-4-8',
|
||||
thinking: { type: 'adaptive' },
|
||||
max_tokens: 1024,
|
||||
tools: [{
|
||||
name: 'assess_quality',
|
||||
description: 'Assess HSE incident report description quality',
|
||||
input_schema: {
|
||||
type: 'object' as const,
|
||||
properties: {
|
||||
score: { type: 'number', description: '1-10 quality score' },
|
||||
passes: { type: 'boolean', description: 'True when score is 6 or above' },
|
||||
feedback: { type: 'string', description: 'One-sentence quality summary' },
|
||||
suggestions: {
|
||||
type: 'array',
|
||||
items: { type: 'string' },
|
||||
description: 'Up to 3 concrete suggestions to improve the description',
|
||||
let message: Awaited<ReturnType<typeof anthropic.messages.create>>
|
||||
try {
|
||||
message = await anthropic.messages.create({
|
||||
model: 'claude-opus-4-8',
|
||||
thinking: { type: 'adaptive' },
|
||||
max_tokens: 1024,
|
||||
tools: [{
|
||||
name: 'assess_quality',
|
||||
description: 'Assess HSE incident report description quality',
|
||||
input_schema: {
|
||||
type: 'object' as const,
|
||||
properties: {
|
||||
score: { type: 'number', description: '1-10 quality score' },
|
||||
passes: { type: 'boolean', description: 'True when score is 6 or above' },
|
||||
feedback: { type: 'string', description: 'One-sentence quality summary' },
|
||||
suggestions: {
|
||||
type: 'array',
|
||||
items: { type: 'string' },
|
||||
description: 'Up to 3 concrete suggestions to improve the description',
|
||||
},
|
||||
},
|
||||
required: ['score', 'passes', 'feedback', 'suggestions'],
|
||||
},
|
||||
required: ['score', 'passes', 'feedback', 'suggestions'],
|
||||
},
|
||||
}],
|
||||
tool_choice: { type: 'tool', name: 'assess_quality' },
|
||||
messages: [{
|
||||
role: 'user',
|
||||
content: `You are an HSE reporting assistant for a Malaysian 3PL warehouse. Assess this incident report description.
|
||||
}],
|
||||
tool_choice: { type: 'tool', name: 'assess_quality' },
|
||||
messages: [{
|
||||
role: 'user',
|
||||
content: `You are an HSE reporting assistant for a Malaysian 3PL warehouse. Assess this incident report description.
|
||||
|
||||
Incident type: ${body.incident_type}
|
||||
Description: ${body.description}
|
||||
|
||||
Score 1–10 based on: specificity (location, time, persons involved), completeness (what happened + immediate actions), and clarity. Score 6 or above passes. If score is below 6, give up to 3 actionable suggestions.`,
|
||||
}],
|
||||
})
|
||||
}],
|
||||
})
|
||||
} catch {
|
||||
return NextResponse.json({ error: 'AI service unavailable' }, { status: 503 })
|
||||
}
|
||||
|
||||
const toolBlock = message.content.find(b => b.type === 'tool_use')
|
||||
if (!toolBlock || toolBlock.type !== 'tool_use') {
|
||||
|
||||
Reference in New Issue
Block a user