namespace FrameworkBLL.GOP.Worker.AI
{
///
/// Configuration for GOP's link to the external Enterprise AI engine (AI-Enterprise-v1.0),
/// bound from appsettings "GOP:AIExtract".
///
/// EngineBaseUrl: confirmed live and reachable from GB5DEMO at http://217.217.249.121:8006
/// (not GB5DEMO itself — that host runs nothing on this port). The actual JWT_SECRET_KEY the
/// engine verifies against is env-var-only on that deployment and not present in this repo or
/// anywhere in GB5's own config — it must be provisioned into Vault at SigningKeyVaultPath
/// out-of-band (ask whoever operates that deployment) before any call here can succeed with a
/// real 200; until then, calls will fail with a clean 401 from the engine, not a GB5-side crash.
///
public class AIExtractOptions
{
public const string SectionName = "GOP:AIExtract";
public string EngineBaseUrl { get; set; } = "http://217.217.249.121:8006";
/// Vault path for the shared secret AI-Enterprise-v1.0 verifies tokens against.
/// Deliberately a distinct path from GB5's own internal JWT signing keys — this secret is
/// owned by a separate, externally-operated system, not something GB5 issues or verifies.
public string SigningKeyVaultPath { get; set; } = "gop/ai-enterprise-jwt-secret";
public string Issuer { get; set; } = "GB5-GOP";
public string Audience { get; set; } = "AI-Enterprise-v1.0";
/// Short-lived — minted fresh per ApiCall-style step invocation, never cached
/// or reused across executions.
public int AccessTokenMinutes { get; set; } = 5;
}
}