1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
|
# Blocked Work
This file is append-only for permission, credential, third-party console, or
privilege blockers. Do not record ordinary implementation work here.
## Open Items
- [ ] `BLK-002` Stripe test restricted key is invalid and Dashboard key management is unavailable
- Affected capability: Real Stripe sandbox validation of manual balance top-up, saved payment method, automatic top-up, Customer Portal, refund, Webhook processing, and reconciliation.
- Blocker type: Credentials / Third-party console
- Observed failure: On 2026-08-06, an authenticated `GET https://api.stripe.com/v1/account` using the test restricted key from `AIGW_STRIPE_API_KEY` returned Stripe `invalid_request_error` with `Invalid API Key provided`. The authenticated Chrome session reached the Stripe test account, but both `/test/apikeys` and `/test/dashboard` rendered Stripe's error page stating that its engineers were investigating the problem, so a replacement key could not be created safely in this run.
- Root cause: The locally configured `rk_test_...` credential is no longer accepted by Stripe. Replacement requires the Stripe Dashboard, which was returning a Stripe-side availability error during verification.
- Human remediation steps: After the Stripe Dashboard recovers, open Test mode -> Developers -> API keys -> Restricted keys; revoke the invalid key and create a dedicated AIGW test restricted key. Grant Checkout Sessions Write, Customer Portal Sessions Write, Customers Write, Setup Intents Read, Payment Intents Write, Refunds Write, and read access for Charges, Disputes, Invoices, Checkout Sessions, and Payment Intents. Keep Stripe Tax disabled until an active registration and canonical product tax code are confirmed. Create or select the test Webhook endpoint for `/billing/stripe/webhook`, subscribe to the event list in `README.md`, copy its test signing secret, then inject the new values through `AIGW_STRIPE_API_KEY` and `AIGW_STRIPE_WEBHOOK_SECRET`; set `AIGW_STRIPE_ENABLED=true`. Do not put either value in JSON, source code, or a committed environment file.
- Verification after remediation: Run `AIGW_STRIPE_API_KEY="$AIGW_STRIPE_API_KEY" go run ./cmd/stripe-preflight` and require `ready=true`; then run the repository Stripe sandbox workflow and confirm a hosted Checkout payment credits the wallet exactly once, the Customer Portal returns a URL, Setup Checkout stores only a PaymentMethod reference, an off-session automatic top-up credits exactly once, a refund creates an equal negative ledger entry, reconciliation reports zero mismatches, `/readyz` reports all Stripe checks `ok`, and no secret appears in logs or API responses.
- Current status: BLOCKED for live Stripe validation; bypassed for continued implementation and deterministic PostgreSQL/Webhook integration tests.
- [ ] `BLK-001` Real upstream account group has no Embeddings model
- Affected capability: Real-provider validation of `POST /v1/embeddings` and its prepaid balance deduction.
- Blocker type: Third-party console / Provider entitlement
- Observed failure: The configured upstream returned HTTP 400 on `POST https://sub.yeluo.cloud/v1/embeddings`; AIGW normalized it to HTTP 502 `provider_error` with `Model "text-embedding-3-small" is not supported by any configured account in this group` for request `req_f859c9c300eba4e99946ae0441a3ef5c` on 2026-08-06. The root `/embeddings` path returned the provider's `text/html` SPA rather than an API response.
- Root cause: The existing provider credential/account group exposes the Responses model `openai/gpt-5.5` but does not have an Embeddings-capable upstream account/model route.
- Human remediation steps: In the upstream provider console for `sub.yeluo.cloud`, add an account/channel that supports OpenAI Embeddings; confirm its public model identifier (for example `text-embedding-3-small`); assign that channel to the same account group used by the encrypted AIGW provider credential; verify `POST /v1/embeddings` returns JSON with `data[0].embedding` and `usage.prompt_tokens`/`usage.total_tokens`. If the provider uses a different model name, update the AIGW model route's upstream model through Admin UI -> Models.
- Verification after remediation: Enable the `Yeluo Embeddings` provider and `openai/text-embedding-3-small` model, create a one-time API key with a daily cap, call AIGW `POST /v1/embeddings`, then confirm HTTP 200, non-empty embedding, `usage_events.protocol='openai_embeddings'`, `metering_status='reported'`, a negative request-linked usage ledger entry, and wallet balance reduced by exactly `charged_micros`.
- Current status: BLOCKED for this provider; bypassed for continued implementation and local PostgreSQL/wallet end-to-end verification.
## Entry Template
- [ ] `BLK-000` Title
- Affected capability:
- Blocker type: Permission / Missing credential / Third-party console / Privilege / Other
- Observed failure:
- Root cause:
- Human remediation steps:
- Verification after remediation:
- Current status: BLOCKED / Bypassed / Resolved
|