read.markets/app/templates_env.py
Giorgio Gilestro 47dce1a1a4 compliance: flag-gate AI portfolio + cloud sync + Stripe; de-risk prompts; harden reviewer
Implements docs/read-markets-compliance-changes.md as flag-gated changes
(no deletions) so paused features stay in the tree for future re-enable.
All four flags default False so a fresh deploy is compliance-safe.

- New env flags: PORTFOLIO_AI_ENABLED, PORTFOLIO_SYNC_ENABLED,
  TICKER_UNIVERSE_AGGREGATE_ENABLED, SUBSCRIPTIONS_ENABLED.
- Gates: /api/analyze, /api/portfolio/sync*, /api/stripe/*, /pricing,
  ticker_universe writes, portfolio_analysis.analyse(). is_paid_active()
  returns True for any auth'd user when subscriptions are paused.
- Prompts (PROMPT_VERSION 10): universal _COMPLIANCE_RIDER prepended to
  every system prompt; watch list removed; price-target / close-above-below
  / trigger / forward-state-as-description rules added; SPECULATIVE
  pivoted to regime-only scenarios; daily + weekly digests tightened.
- Reviewer: deterministic regex/lexicon pre-check fail-closed under the
  Haiku call; portfolio rider gated by PORTFOLIO_AI_ENABLED; base prompt
  sharpened for forward-state and MAR forward-opinion patterns;
  ReviewerVerdict audit table; generate_with_review retry helper.
- Migration 0026: purge portfolio_sync + ticker_universe; create
  reviewer_verdicts.
- Copy: MAR cite fixed to Art 3(1)(35) + Art 20 + Del Reg 2016/958;
  portfolio reframed as browser-only viewer in disclaimer / privacy /
  terms / about / pricing / landing (en + it). TODO(legal) marker for
  lawyer sign-off on disclaimer.
- Tests: 13 lexicon + 6 reviewer compliance regressions; conftest enables
  all flags so existing 402 tests still cover their code paths.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-29 19:57:12 +02:00

94 lines
3.4 KiB
Python

"""Shared Jinja2 environment with custom filters for the dashboard.
Imported by both routers/pages.py and routers/api.py so the filters are
registered exactly once."""
from __future__ import annotations
import time
from pathlib import Path
from fastapi.templating import Jinja2Templates
from markupsafe import Markup, escape
from app import branding
from app.config import get_settings
from app.services.glossary import wrap_glossary
# Cache-busting token for static assets. Computed once at import time
# (i.e. process startup), so every container restart yields a fresh
# value and browsers refetch CSS/JS instead of serving stale cache.
# Templates append `?v={{ ASSET_VERSION }}` to every static URL.
ASSET_VERSION = str(int(time.time()))
TEMPLATE_DIR = Path(__file__).resolve().parent / "templates"
def _fmt_price(v: float | None) -> str:
"""Format a price in a way that's readable in dense terminal tables.
Avoids scientific notation for large round numbers (FTSE 25,962, not 2.596e+04)
and keeps enough precision for FX rates like 0.8725 EUR/GBP."""
if v is None:
return ""
av = abs(v)
if av >= 1000:
return f"{v:,.2f}"
if av >= 10:
return f"{v:.2f}"
if av >= 1:
return f"{v:.4f}"
return f"{v:.4f}"
def _fmt_signed(v: float | None, decimals: int = 2) -> str:
if v is None:
return ""
return f"{v:+,.{decimals}f}"
def _fmt_money(v: float | None) -> str:
if v is None:
return ""
return f"{v:,.2f}"
def _glossary_filter(value, tone: str | None = None):
"""Wrap glossary terms in NOVICE-mode AI content. Returns Markup so
Jinja won't re-escape the inserted <span> tags. Plain-text inputs are
HTML-escaped first; already-Markup inputs (e.g. log.content_html) are
treated as HTML and passed through wrap_glossary unchanged."""
if value is None:
return Markup("")
if isinstance(value, Markup):
html = str(value)
else:
html = str(escape(value))
if (tone or "").upper() != "NOVICE":
return Markup(html)
return Markup(wrap_glossary(html, tone=tone))
templates = Jinja2Templates(directory=str(TEMPLATE_DIR))
templates.env.filters["price"] = _fmt_price
templates.env.filters["signed"] = _fmt_signed
templates.env.filters["money"] = _fmt_money
templates.env.filters["glossary"] = _glossary_filter
# Brand globals — every template that prints a product name should pull
# from these so a future rename is a one-liner in `app/branding.py`.
templates.env.globals["BRAND_NAME"] = branding.BRAND_NAME
templates.env.globals["BRAND_SHORT"] = branding.BRAND_SHORT
templates.env.globals["SITE_URL"] = branding.SITE_URL
templates.env.globals["APP_URL"] = branding.APP_URL
templates.env.globals["TAGLINE"] = branding.TAGLINE
templates.env.globals["LEGAL_OPERATOR"] = branding.LEGAL_OPERATOR
templates.env.globals["OPERATOR_EMAIL"] = branding.OPERATOR_EMAIL
templates.env.globals["OPERATOR_JURISDICTION"] = branding.OPERATOR_JURISDICTION
templates.env.globals["BETA_MODE"] = get_settings().BETA_MODE
# Compliance feature flags — read once at startup (templates restart with the
# app). See app.config.Settings for semantics.
_s = get_settings()
templates.env.globals["PORTFOLIO_AI_ENABLED"] = _s.PORTFOLIO_AI_ENABLED
templates.env.globals["PORTFOLIO_SYNC_ENABLED"] = _s.PORTFOLIO_SYNC_ENABLED
templates.env.globals["SUBSCRIPTIONS_ENABLED"] = _s.SUBSCRIPTIONS_ENABLED
templates.env.globals["ASSET_VERSION"] = ASSET_VERSION