namespace GB5Shared.ExternalAI
{
///
/// Per-module configuration for a link to the external Enterprise AI engine
/// (AI-Enterprise-v1.0, a separate Python/FastAPI service — see
/// FrameworkBLL.GOP.Worker.AI.AIExtractOptions for the original, GOP-specific version this
/// generalizes). Each consuming module (EAIAdmin, KMS, ...) binds its own instance from its
/// own config section (e.g. "EAIAdmin:AIExtract", "KMS:AIExtract") and passes it into
/// per call — deliberately not resolved via generic
/// IOptions<AIEngineOptions> DI, since multiple modules binding the same options TYPE to
/// different sections inside one process (PlatformHost) would collide on the last registration
/// won. See EAIAdmin/KmsAISyncClient for how each module resolves its own instance from
/// IConfiguration directly.
///
public class AIEngineOptions
{
public string EngineBaseUrl { get; set; } = "http://217.217.249.121:8006";
/// Vault path for the shared secret AI-Enterprise-v1.0 verifies tokens against.
/// Owned by a separate, externally-operated system, not something GB5 issues or verifies —
/// each module gets its own path so it can rotate independently even if the underlying
/// secret value happens to be the same one the engine's operator provisioned.
public string SigningKeyVaultPath { get; set; } = string.Empty;
public string Issuer { get; set; } = string.Empty;
public string Audience { get; set; } = "AI-Enterprise-v1.0";
/// Short-lived — minted fresh per call, never cached or reused.
public int AccessTokenMinutes { get; set; } = 5;
public int TimeoutSeconds { get; set; } = 120;
}
}