Files
supabase/apps/studio/lib/api/apiWrappers.test.ts
T
Matt Rossman e8ab92408f feat(assistant): enable Braintrust tracing for non-sensitive chats (#42963)
Enables Braintrust tracing for AI Assistant chats to support debugging
and future online evals.

**Code Changes**

- Wraps `generateAssistantResponse` in a Braintrust `traced()` span,
logging the user's latest message as input along with metadata
(`chatId`, `chatName`, `projectRef`, `userId`, `orgId`, `planId`, etc.)
- Threads JWT claims from `apiWrapper` → handler to log `userId` in
Braintrust without an extra API call (+ expanded `apiWrapper` tests)
- Threads `orgId` and `planId` from `getOrgAIDetails` to log in
Braintrust

**Infrastructure Changes**

- Created a "Vercel" service account in Braintrust
- Added `BRAINTRUST_API_KEY` and `BRAINTRUST_PROJECT_ID` env vars to the
studio-staging project in Vercel using a service token for the above
service account
- Added an "Overview" view to the Logs tab in the Braintrust Assistant
project to surface the new metadata

**Precautions**

- HIPAA sensitive projects are excluded from logging (see
https://github.com/supabase/supabase/pull/42787 for the detection logic)
- Production is temporarily excluded from logging until we're confident
in the setup

**Testing steps**

- Chat with the AI Assistant in the [studio-staging preview
build](https://github.com/supabase/supabase/pull/42963#issuecomment-3917178023)
below
- Visit the [Logs tab in the Braintrust Assistant
project](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs)
and inspect the trace

<img width="4680" height="962" alt="CleanShot 2026-02-18 at 17 43 55@2x"
src="https://github.com/user-attachments/assets/c3a11b21-4e7f-4e90-bdab-a25ab8ee0d1f"
/>

<img width="2632" height="1288" alt="CleanShot 2026-02-18 at 17 45
04@2x"
src="https://github.com/user-attachments/assets/6c7b6ebc-5090-4ede-8f71-859ff7e386aa"
/>

**References**
- https://www.braintrust.dev/docs/integrations/sdk-integrations/vercel
- https://www.braintrust.dev/docs/instrument/custom-tracing

Closes AI-438
2026-02-19 11:43:47 -05:00

62 lines
2.0 KiB
TypeScript

import type { JwtPayload } from '@supabase/supabase-js'
import type { NextApiRequest, NextApiResponse } from 'next'
import { describe, it, expect, vi, beforeEach } from 'vitest'
import { ResponseError } from 'types'
import apiWrapper from './apiWrapper'
import { apiAuthenticate } from './apiAuthenticate'
vi.mock('lib/constants', () => ({
IS_PLATFORM: true,
API_URL: 'https://api.example.com',
}))
vi.mock('./apiAuthenticate', () => ({
apiAuthenticate: vi.fn(),
}))
describe('apiWrapper', () => {
const mockReq = {} as NextApiRequest
const mockRes = {
status: vi.fn().mockReturnThis(),
json: vi.fn().mockReturnThis(),
} as unknown as NextApiResponse
const mockHandler = vi.fn()
beforeEach(() => {
vi.clearAllMocks()
})
it('should call handler directly when withAuth is false', async () => {
await apiWrapper(mockReq, mockRes, mockHandler, { withAuth: false })
expect(mockHandler).toHaveBeenCalledWith(mockReq, mockRes, undefined)
expect(apiAuthenticate).not.toHaveBeenCalled()
})
it('should pass JWT claims to handler when withAuth is true', async () => {
const mockClaims: JwtPayload = {
iss: 'supabase',
sub: 'user-123',
aud: 'authenticated',
exp: 9999999999,
iat: 1000000000,
role: 'authenticated',
aal: 'aal1',
session_id: 'session-123',
}
vi.mocked(apiAuthenticate).mockResolvedValue(mockClaims)
await apiWrapper(mockReq, mockRes, mockHandler, { withAuth: true })
expect(apiAuthenticate).toHaveBeenCalledWith(mockReq, mockRes)
expect(mockHandler).toHaveBeenCalledWith(mockReq, mockRes, mockClaims)
})
it('should return 401 when authentication fails', async () => {
const mockError = { error: new ResponseError('Invalid token') }
vi.mocked(apiAuthenticate).mockResolvedValue(mockError)
await apiWrapper(mockReq, mockRes, mockHandler, { withAuth: true })
expect(mockRes.status).toHaveBeenCalledWith(401)
expect(mockHandler).not.toHaveBeenCalled()
})
})