This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| // ============================================================================= | |
| // api-service — PermissionGuard (fail-closed RBAC — Invariant #2, THE headline fix) | |
| // ============================================================================= | |
| // Acceleate Consulting - Walid Boudabbous <walid@acceleate.com> | |
| // | |
| // Guard chain position 5 (last): Throttler → GatewayAuth → ApiKey → | |
| // [PrincipalContextInterceptor] → PermissionGuard. Registered AFTER the auth | |
| // guards so `request.principal` is set... EXCEPT: NestJS runs ALL guards before | |
| // ANY interceptor, so PrincipalContextInterceptor has NOT run when this guard | |
| // executes. This guard therefore re-derives the acting principal from whichever |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| /** | |
| * Chunking + provenance (W1). | |
| * | |
| * Two things the earlier PoC got wrong and this fixes: | |
| * | |
| * 1. THE BENCHMARK DID NOT CHUNK. `run-bench.ts` inlined its own ingest and stored every | |
| * document as a single point (`chunk_id: "{id}#0"`), bypassing `src/transformers/` | |
| * entirely. So it measured a different, simpler pipeline than the PoC's — an inconsistency, | |
| * not a design choice. | |
| * |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| // ============================================================================= | |
| // ddx-api — Dudoxx Mastra provider factory (LiteLLM-routed, per-request model) | |
| // ============================================================================= | |
| // Dudoxx UG / Acceleate Consulting - Walid Boudabbous <walid@acceleate.com> | |
| // | |
| // The ONE place a Mastra LanguageModel is constructed for ddx-api. All LLM + | |
| // embedding traffic routes through the Dudoxx LiteLLM proxy (LITELLM_BASE_URL, | |
| // default https://llm-gateway.example.com) — a model id is NEVER hardcoded in an | |
| // agent file. The chat default is `dudoxx-gemma` (invariant note: the CHAT | |
| // model is NOT the embedder — the embedder is dudoxx-embed@2560, resolved |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| // ============================================================================= | |
| // ddx-api — GatewayAuthGuard (HMAC verification, BFF-only entry) | |
| // ============================================================================= | |
| // Dudoxx UG / Acceleate Consulting - Walid Boudabbous <walid@acceleate.com> | |
| // | |
| // Guard chain position 2 (after ThrottlerGuard). Verifies the HMAC-signed | |
| // X-Gateway-* header set every trusted consumer (web BFF, seeder) presents, | |
| // keyed by a PER-CONSUMER secret (GATEWAY_API_KEY_{WEB,SEEDER}) plus the shared | |
| // GATEWAY_SIGNING_SECRET. Rejects unsigned / tampered / replayed sets 401 | |
| // BEFORE any downstream guard runs (invariant #7). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| import type { FhirResource } from '../types.js'; | |
| import type { Adapter } from './types.js'; | |
| interface R4Coding { | |
| system?: string; | |
| code?: string; | |
| display?: string; | |
| version?: string; | |
| userSelected?: boolean; | |
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| import type { FhirResource, SeedResult } from '../types.js'; | |
| import type { FhirHttpClient } from '../client/http.js'; | |
| import { findSeedIdentifier, identifierSearchToken } from './identifier.js'; | |
| export async function upsert(http: FhirHttpClient, resource: FhirResource): Promise<SeedResult> { | |
| const seedId = findSeedIdentifier(resource); | |
| if (!seedId) { | |
| return { | |
| resourceType: resource.resourceType, | |
| identifier: '(missing)', |