Repository navigation
What's Changed
Gene query API and API keys (for scripts)
- Personal ACGC API keys for scripts, sent as
Authorization: Bearer acgc_…. Only a hash of each key is stored. Each key has its own rate limit (60/min by default) and is re-checked against the email-domain allowlist on every request. A key can't create, list or revoke keys. (#108) - In-app API keys page at
/api-keysto create (shown once), list and revoke keys. Admins see everyone's keys. (#113) - Gene query endpoints that return only the classification and rationale, plus a
view_urllink to the full report:POST /v1/genes/query(up to 50 genes),GET /v1/genes/{symbol}, and background jobs at/v1/genes/query/jobs. (#107) - Gene query fixes: 404 only when HGNC or Ensembl confirms a gene doesn't exist, and 503 when the lookup itself fails.
/v1/annotate/geneno longer returns a link to a run that wasn't saved. (#114) - New API user guide in
docs/api.md, linked from the README. (#115)
Login
- Run links (
/?run=<id>) now survive login: users with an expired session sign in and return to the run. The redirect target is restricted to paths on this site. (#106)
OpenEvidence
- The OpenEvidence card no longer times out on slow first lookups. A cache miss answers "pending" right away while the lookup runs in the background, and the card checks back until it's ready. Paid calls are deduplicated. (#102)
- The default OpenEvidence model is now
osler. (#105) - Fixed widget metadata leaking into OpenEvidence card text. (#104)
Literature
- PubMed preprints are labeled end to end. They rank below peer-reviewed research, prompts treat them as weaker evidence, and evidence cards show a "Preprint – not peer-reviewed" badge. No papers are dropped. (#112)
Benchmarks and CI
- osler vs darwin OpenEvidence benchmark (#103), a fix for its tests (#109), and accurate time-to-first-token measurement (#111).
Deploy notes
- No migration: the
api_keystable is created at startup. - New settings all have defaults; see
.env.example(API_KEY_*,OPENEVIDENCE_SIDECAR_*). - Keycloak login stays off until
KEYCLOAK_CLIENT_IDandKEYCLOAK_CLIENT_SECRETare set; Google login is unchanged.