feedback: thumb up/down on logs + reviewer self-score 0-10

Two unrelated features bundled because they ship together and share
migration 0028.

Strategic-log feedback (thumb up/down):
- New strategic_log_feedback table with UNIQUE(log_id, user_id) so each
  user has one vote per log, flippable in place (up -> down -> clear).
  UI shows aggregate counts only.
- app/services/log_feedback.py: set_vote, get_counts, sign/verify
  feedback tokens (same itsdangerous pattern as auth.sign_pending,
  30-day TTL for email links).
- POST /api/log/{id}/feedback: web vote, auth required, returns counts
  + the requesting user's own vote.
- GET /feedback?token=...&vote=...: email-link target, no auth, signed
  token encodes (user, log, vote), renders feedback_thanks.html.
- partials/log.html: thumbs row below content, JS-driven swap via the
  POST endpoint. Dashboard latest-log card and /log page both render
  this partial via htmx, so the buttons appear in all three surfaces.
- digest emails: a "How was today's read?" row above the unsub footer,
  with signed-token URLs against the latest StrategicLog at send time.
  Plain-text fallback included.

Reviewer self-score (0-10):
- _SYSTEM_PROMPT asks for an integer score with anchors (10 exemplary,
  5 borderline, 0 unfit). Verdict gains score: int | None.
- Deterministic-layer hits get score=0 (hard rule, no nuance);
  error rows get None; LLM rows get the model's score clamped 0..10.
- ReviewerVerdict.score, StrategicLog.reviewer_score, and
  IndicatorSummary.reviewer_score all new SMALLINT NULL columns.
- ai_log_job + indicator_summary_job persist verdict.score onto their
  content rows when committing the row alongside content.

Tests:
- tests/test_strategic_log_feedback.py: vote, flip, clear, aggregate
  across users, invalid vote, token round-trip + tamper + garbage +
  'clear' not signable for email path.
- tests/test_output_review.py: score parsing, clamping (>10, <0),
  missing/non-numeric -> None, deterministic-layer score=0.

Full suite: 427 passed (was 412), 5 skipped, no regressions.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Giorgio Gilestro 2026-05-29 21:28:03 +02:00
parent f3ac65f8f7
commit 8946dee2e0
14 changed files with 962 additions and 14 deletions

View file

@ -176,6 +176,60 @@ async def log_page_day(
)
@router.get("/feedback", response_class=HTMLResponse)
async def log_feedback_via_token(
request: Request,
token: str,
vote: str | None = None,
session: AsyncSession = Depends(get_session),
):
"""Email-link target for thumb up/down votes on a strategic log.
The signed token encodes (user_id, log_id, intended_vote). The query
param ``vote`` is informational (lets the URL be self-describing in
the inbox); the canonical vote is what's in the token. If the two
disagree the token wins.
Renders a small thank-you confirmation. No auth required the token
is the auth-equivalent for this single side-effecting action."""
from app.services.log_feedback import (
FeedbackError, set_vote, verify_feedback_token,
)
payload = verify_feedback_token(token)
if payload is None:
return templates.TemplateResponse(
request, "feedback_thanks.html",
{"ok": False, "message": "This link has expired or is invalid.",
"log_id": None, "vote": None},
status_code=400,
)
try:
counts = await set_vote(
session,
log_id=payload["log_id"],
user_id=payload["user_id"],
vote=payload["vote"],
)
except FeedbackError as e:
return templates.TemplateResponse(
request, "feedback_thanks.html",
{"ok": False, "message": str(e), "log_id": payload["log_id"],
"vote": payload["vote"]},
status_code=400,
)
return templates.TemplateResponse(
request, "feedback_thanks.html",
{"ok": True,
"vote": payload["vote"],
"log_id": payload["log_id"],
"counts": counts,
"message": None},
)
@router.get("/settings", response_class=HTMLResponse)
async def settings_page(
request: Request,