namespace FrameworkBLL.GOP.Worker.AI { /// /// Configuration for GOP's link to the external Enterprise AI engine (AI-Enterprise-v1.0), /// bound from appsettings "GOP:AIExtract". /// /// EngineBaseUrl: confirmed live and reachable from GB5DEMO at http://217.217.249.121:8006 /// (not GB5DEMO itself — that host runs nothing on this port). The actual JWT_SECRET_KEY the /// engine verifies against is env-var-only on that deployment and not present in this repo or /// anywhere in GB5's own config — it must be provisioned into Vault at SigningKeyVaultPath /// out-of-band (ask whoever operates that deployment) before any call here can succeed with a /// real 200; until then, calls will fail with a clean 401 from the engine, not a GB5-side crash. /// public class AIExtractOptions { public const string SectionName = "GOP:AIExtract"; public string EngineBaseUrl { get; set; } = "http://217.217.249.121:8006"; /// Vault path for the shared secret AI-Enterprise-v1.0 verifies tokens against. /// Deliberately a distinct path from GB5's own internal JWT signing keys — this secret is /// owned by a separate, externally-operated system, not something GB5 issues or verifies. public string SigningKeyVaultPath { get; set; } = "gop/ai-enterprise-jwt-secret"; public string Issuer { get; set; } = "GB5-GOP"; public string Audience { get; set; } = "AI-Enterprise-v1.0"; /// Short-lived — minted fresh per ApiCall-style step invocation, never cached /// or reused across executions. public int AccessTokenMinutes { get; set; } = 5; } }