Nxtgauge AI Assistant
Find a file
Ashwin Kumar Sivakumar 23a707e175
All checks were successful
build-and-release / build (push) Successful in 4m14s
Fix security audit findings: IDOR, rate limiting, action audit trail
- Chat and ticket-creation endpoints now scope lookups/attribution to
  the authenticated JWT identity instead of trusting a client-supplied
  user_id in the request body (IDOR)
- Add per-user in-memory rate limiter on AI-generation endpoints to
  guard against unbounded LLM-cost abuse
- Bind confirm_action to the authenticated user for audit logging
- Bump vulnerable transitive dependencies via cargo update

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 17:32:01 +05:30
.forgejo fix(ci): sort registry prune by real image build time, protect current SHA 2026-07-17 05:37:58 +05:30
.gitea/workflows fix(ci): use runner docker host 2026-07-05 22:25:37 +05:30
.github/workflows ci: remove GitHub Actions workflow - using Forgejo CI exclusively 2026-07-06 04:19:48 +05:30
migrations feat(ai-assistant): bootstrap rust axum backend with providers, routes, and db scaffolding 2026-04-11 15:04:14 +02:00
prompts/v1 feat: add Ask Ash AI assistant implementation 2026-06-14 20:28:17 +02:00
seeds feat(ai-assistant): bootstrap rust axum backend with providers, routes, and db scaffolding 2026-04-11 15:04:14 +02:00
src Fix security audit findings: IDOR, rate limiting, action audit trail 2026-07-23 17:32:01 +05:30
.env.example fix(ci): push image to Forgejo registry and update GitOps repo over HTTPS 2026-07-16 20:33:14 +05:30
.gitignore feat(ai-assistant): bootstrap rust axum backend with providers, routes, and db scaffolding 2026-04-11 15:04:14 +02:00
Cargo.lock Fix security audit findings: IDOR, rate limiting, action audit trail 2026-07-23 17:32:01 +05:30
Cargo.toml Fix panic on every authenticated request: jsonwebtoken missing crypto backend 2026-07-02 22:27:03 +05:30
Dockerfile ci: deploy ai assistant via github actions and ghcr 2026-06-14 22:52:50 +05:30
README.md chore: trigger build 2026-07-06 04:42:22 +05:30

nxtgauge-ai-assistant

Backend-only Rust service for Nxtgauge AI workflows.

Scope (MVP)

  • Job description generation
  • Form filling assistance
  • Help article retrieval
  • Support ticket creation via chatbot

Stack

  • Rust + Axum
  • Ollama (default local runtime)
  • Postgres scaffolding via sqlx
  • Provider abstractions for future runtime swaps

Run

cp .env.example .env
cargo run

Endpoints

  • GET /health
  • POST /api/v1/chat/message
  • POST /api/v1/jobs/generate-description
  • POST /api/v1/forms/extract
  • POST /api/v1/tickets/create
  • POST /api/v1/help/search

Environment

  • APP_HOST
  • APP_PORT
  • DATABASE_URL
  • OLLAMA_BASE_URL
  • OLLAMA_CHAT_MODEL (default smollm2:360m)
  • OLLAMA_EMBED_MODEL (default nomic-embed-text)
  • HELP_CENTER_SEED_PATH
  • TICKETS_SOURCE

Architecture

  • chat/: workflow-oriented orchestration
  • jobs/, forms/, tickets/: domain modules
  • providers/llm: AiProvider + Ollama implementation
  • providers/tickets: TicketProvider + mock adapter
  • providers/help_center: HelpCenterProvider + local seed implementation
  • retrieval/embeddings: embedding abstraction + Ollama adapter
  • db/: DB connection, entities, repository helpers
  • routes/, handlers/: API layer

Notes

  • Service starts even if Ollama model is unavailable; provider returns graceful fallback responses.
  • STT (faster-whisper) is intentionally deferred to phase 2.

CI (Woodpecker)

Required secrets:

  • REGISTRY_USERNAME
  • REGISTRY_PASSWORD

Trigger build 1783293142