All errors were API mismatches — handler code calling wrong method names, wrong argument types, or missing imports/derives. No logic changes. Build now passes with SQLX_OFFLINE=true. Key fixes: - embed_text -> embed_one, Vector -> Vec<f32> conversion - extract_token: extract auth header from HttpRequest first - AuthError variants aligned to actual enum definition - recursive async fns boxed (dfs_paths in inference + path_finder) - missing derives (Default, Serialize), imports (sqlx::Row, Timelike) - borrow-after-move: compute .len() before struct field move - streaming_body -> streaming with Result<Bytes> for SSE - CI: add SQLX_OFFLINE=true for offline builds without DB 25 files changed, 99 insertions(+), 81 deletions(-) Co-authored-by: rock <[email protected]>
AuthentikServiceAccount: ├─ OAuth2 client_credentials flow ├─ Token caching with TTL (refresh 60s before expiry) ├─ Auto-renewal on cache miss/expiry ├─ Thread-safe: Arc<RwLock<Option<CachedToken>>> └─ Tests: 5 unit tests (all passing) Configuration: ├─ client_id: "poimen-memory-service" (from Authentik) ├─ client_secret: encrypted via SOPS ├─ token_endpoint: https://authentik.riotpiao.com/application/o/token/ └─ cache_ttl_secs: 3600 (default) Usage: let sa = AuthentikServiceAccount::new(config); let token = sa.get_token().await?; // Returns cached or fresh Compilation: ✅