Backend: AI generation endpoints (Gemini nano-banana + Veo)

Server-side proxy so the Google API key (from Infisical) never reaches the
client. Behind an AiClient trait with a fake for headless tests.

- ai.rs: GeminiClient — refine prompt (gemini-2.5-flash), generate image
  (gemini-2.5-flash-image / "nano-banana"), and async video (veo-2.0:
  predictLongRunning → poll → proxy the redirecting download). DisabledAiClient
  when no key is configured.
- POST /v1/ai/refine, /v1/ai/image (rate-limited 60/h, 20/h)
- POST /v1/ai/video (submit, 5/h) + /v1/ai/video/status (poll → base64 mp4)
- config: GEMINI_API_KEY via SecretSource
- 5 endpoint/parse tests; full workspace gate green (114 tests)

Live-verified: refine + nano-banana return through the proxy; Veo submits,
polls to done in ~60s, and streams back a valid mp4.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-05 12:56:19 -05:00
co-authored by Claude Opus 4.8
parent eddca62f23
commit 4be1cf5fa3
10 changed files with 597 additions and 1 deletions
@@ -54,6 +54,8 @@ pub struct Config {
pub ip_hash_secret: String,
/// Shared secret RevenueCat sends in the webhook `Authorization` header.
pub billing_webhook_secret: String,
/// Google Gemini API key (for the AI card generator). Empty = AI disabled.
pub gemini_api_key: String,
pub bind_addr: String,
pub r2: R2Config,
pub wallet: WalletConfig,
@@ -102,6 +104,7 @@ impl Config {
profile_base_url: optional(src, "PROFILE_BASE_URL", "https://cardclaws.com").await,
ip_hash_secret: require(src, "IP_HASH_SECRET").await?,
billing_webhook_secret: optional(src, "BILLING_WEBHOOK_SECRET", "").await,
gemini_api_key: optional(src, "GEMINI_API_KEY", "").await,
bind_addr: optional(src, "BIND_ADDR", "0.0.0.0:8080").await,
r2: R2Config {
endpoint: optional(