import { NextResponse } from 'next/server'; import { configManager } from '@/lib/admin/config-manager'; import { logger } from '@/lib/logger'; import { DEFAULT_AI_ENTITLEMENT, type AiPolicy } from '@/lib/ai/types'; /** * GET /api/ai/policy - AI Assistant policy (NOT admin-protected - users read this) * * P0 stub (docs/AI-ASSISTANT-CONCEPT.md §12): proves the client<->server * policy-fetch plumbing end-to-end with no provider ever called. `enabled` * mirrors the admin FeatureGates toggle; entitlement is hardcoded unlicensed * until P2 wires a real seats/billing backend (§9) - there is no provider * class to grant yet regardless of what an entitlement record might say. */ export async function GET() { try { await configManager.ensureLoaded(); const policy = configManager.getPolicy(); const aiPolicy: AiPolicy = { enabled: policy.features.aiAssistantEnabled, entitlement: { ...DEFAULT_AI_ENTITLEMENT }, publicConsentVersion: null, }; return NextResponse.json(aiPolicy, { headers: { 'Cache-Control': 'no-store' }, }); } catch (error) { logger.error('AI policy read error', { error: error instanceof Error ? error.message : 'Unknown error' }); return NextResponse.json({ error: 'Internal server error' }, { status: 500 }); } }