import { NextRequest, NextResponse } from "next/server"; import { z } from "zod"; import { db, recipes, recipeIngredients, recipeSteps } from "@epicure/db"; import { requireSessionOrApiKey } from "@/lib/api-auth"; import { applyRateLimit } from "@/lib/rate-limit"; import { withAiQuota, resolveAiConfigOrError } from "@/lib/ai/ai-error"; import { importFromPhoto } from "@/lib/ai/features/import-photo"; import { getModelConfigForUseCase } from "@/lib/ai/resolve-user-key"; import { checkTierLimitInTransaction, TierLimitError } from "@/lib/tiers"; const Schema = z.object({ imageBase64: z.string().max(14_000_000), mimeType: z.enum(["image/jpeg", "image/png", "image/webp"]), }); export async function POST(req: NextRequest) { const { session, response } = await requireSessionOrApiKey(req); if (response) return response; const body = await req.json() as unknown; const parsed = Schema.safeParse(body); if (!parsed.success) { return NextResponse.json({ error: "Validation error", issues: parsed.error.issues }, { status: 400 }); } const limited = await applyRateLimit(`rl:ai:${session!.user.id}`, 5, 60); if (limited) return limited; const userId = session!.user.id; const locale = (session!.user as { locale?: string }).locale ?? "en"; const visionConfigResult = await resolveAiConfigOrError(() => getModelConfigForUseCase(userId, "vision")); if (!visionConfigResult.ok) return visionConfigResult.response; const visionConfig = visionConfigResult.data; // Fall back to vision-capable defaults if no explicit model configured if (!visionConfig.model) { if (visionConfig.provider === "openai") visionConfig.model = "gpt-4o"; else if (visionConfig.provider === "anthropic") visionConfig.model = "claude-sonnet-4-6"; } const textConfigResult = await resolveAiConfigOrError(() => getModelConfigForUseCase(userId, "text")); if (!textConfigResult.ok) return textConfigResult.response; const textConfig = textConfigResult.data; const result = await withAiQuota(userId, session!.user.tier as "free" | "pro" | "family", () => importFromPhoto(parsed.data.imageBase64, parsed.data.mimeType, visionConfig, textConfig, locale), { skipQuota: visionConfig.isByok && textConfig.isByok } ); if (!result.ok) return result.response; const recipe = result.data; if (!recipe.found) { return NextResponse.json({ error: "No recipe recognized in photo" }, { status: 422 }); } const newRecipeId = crypto.randomUUID(); const now = new Date(); try { await db.transaction(async (tx) => { await checkTierLimitInTransaction(tx, userId, session!.user.tier as "free" | "pro" | "family", "recipe"); await tx.insert(recipes).values({ id: newRecipeId, authorId: userId, title: recipe.title, description: recipe.description, baseServings: recipe.baseServings ?? 4, recipeType: recipe.recipeType, visibility: "private", difficulty: recipe.difficulty, prepMins: recipe.prepMins, cookMins: recipe.cookMins, dietaryTags: recipe.dietaryTags ?? {}, aiGenerated: true, // The extraction prompt always writes the recipe in the caller's own // locale (see importFromPhoto's langInstruction) regardless of what // language the photo/label was in — so this *is* the recipe's // language, not a guess, and lets the Translate button correctly // stay hidden until the user's app language changes. language: locale, createdAt: now, updatedAt: now, }); if (recipe.ingredients.length > 0) { await tx.insert(recipeIngredients).values( recipe.ingredients.map((ing, i) => ({ id: crypto.randomUUID(), recipeId: newRecipeId, rawName: ing.rawName, quantity: ing.quantity !== undefined ? String(ing.quantity) : undefined, unit: ing.unit, note: ing.note, order: i, })) ); } if (recipe.steps.length > 0) { await tx.insert(recipeSteps).values( recipe.steps.map((step, i) => ({ id: crypto.randomUUID(), recipeId: newRecipeId, instruction: step.instruction, timerSeconds: step.timerSeconds, order: i, })) ); } }); } catch (err) { if (err instanceof TierLimitError) { return NextResponse.json({ error: "Recipe limit reached for your tier" }, { status: 403 }); } throw err; } return NextResponse.json({ id: newRecipeId }); }