{"_id":"@acetrumtech/rag-chatbot-pro","_rev":"2-72bbe1ef73c67cb25c62d8824da92c19","name":"@acetrumtech/rag-chatbot-pro","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@acetrumtech/rag-chatbot-pro","version":"0.1.0","keywords":["chatbot","rag","ai","widget","nextjs","lead-capture","pro"],"author":{"name":"Acetrum","email":"info.acetrum@gmail.com"},"license":"UNLICENSED","_id":"@acetrumtech/rag-chatbot-pro@0.1.0","maintainers":[{"name":"acetrumtech","email":"info.acetrum@gmail.com"}],"homepage":"https://acetrum.com","bugs":{"url":"https://acetrum.com/contact"},"dist":{"shasum":"6259aa664041aa2f25db27d402cacc5f2d98b62e","tarball":"https://registry.npmjs.org/@acetrumtech/rag-chatbot-pro/-/rag-chatbot-pro-0.1.0.tgz","fileCount":9,"integrity":"sha512-1pLlorioE2MlTgLsOVEQJJ+Nnnbhf22fRcaJlV7z9k3YDNNE1mgFEKx+4DVO3zOxDofSLpiSmTddBPrTjKqI2A==","signatures":[{"sig":"MEUCIFoPEEtDIGgj1Ze73i1mCcFkNSJmThT4BV2KaBO+CachAiEA/abdochx1zuBOBNNb44WiFxZcsJtQi/P81aI+PPcktk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":116725},"main":"./index.js","type":"module","engines":{"node":">=18"},"exports":{".":"./index.js","./next":"./next.js","./vite":"./vite.js","./express":"./express.js"},"gitHead":"f795da3863f509cb7d872b916356bc44af27e7a2","_npmUser":{"name":"acetrumtech","email":"info.acetrum@gmail.com"},"repository":{"url":"git+https://github.com/avneesh30/rag-chatbot-pro.git","type":"git"},"_npmVersion":"11.6.2","description":"Pro RAG chatbot plugin — DOCX/TXT/MD/CSV + website crawl, client dashboard, citations, semantic cache. Requires a paid license key (acetrum.com) to function; degrades to a free-tier subset without one.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"unpdf":"^0.12.2","mammoth":"^1.12.0","nodemailer":"^9.0.4","better-sqlite3":"^13.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/rag-chatbot-pro_0.1.0_1786787775806_0.3325004357914647","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@acetrumtech/rag-chatbot-pro","version":"0.1.1","description":"Pro RAG chatbot plugin — DOCX/TXT/MD/CSV + website crawl, client dashboard, citations, semantic cache. Requires a paid license key (acetrum.com) to function; degrades to a free-tier subset without one.","type":"module","main":"./index.js","exports":{".":"./index.js","./vite":"./vite.js","./next":"./next.js","./express":"./express.js"},"engines":{"node":">=18"},"license":"UNLICENSED","publishConfig":{"access":"public"},"author":{"name":"Acetrum","email":"info.acetrum@gmail.com"},"homepage":"https://acetrum.com","repository":{"type":"git","url":"git+https://github.com/avneesh30/rag-chatbot-pro.git"},"bugs":{"url":"https://acetrum.com/contact"},"keywords":["chatbot","rag","ai","widget","nextjs","lead-capture","pro"],"dependencies":{"nodemailer":"^9.0.4","unpdf":"^1.8.0","better-sqlite3":"^13.0.3","mammoth":"^1.12.0"},"gitHead":"5a02a385e181cc819f66379573f6714c2ae611b4","_id":"@acetrumtech/rag-chatbot-pro@0.1.1","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-19ZozUW2fV9ws65FTE3Wq8EkQRIwI8so5jKGSi27I/L7BwZq/xeX+VjOwA6l2C6z4eEI6YzqRoHhho4pgN/t7Q==","shasum":"1cb45e703a79522d783e3d3f79fdcc4201c8de47","tarball":"https://registry.npmjs.org/@acetrumtech/rag-chatbot-pro/-/rag-chatbot-pro-0.1.1.tgz","fileCount":9,"unpackedSize":116724,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCsu5EIzRPIPigBZ27ebiCbyYOTJWc00qeCsMkegdZpwAIhANTIG2jJ7MaBld6eLm2DGX5XcuyyBQZir0Oepj/s9e55"}]},"_npmUser":{"name":"acetrumtech","email":"info.acetrum@gmail.com"},"directories":{},"maintainers":[{"name":"acetrumtech","email":"info.acetrum@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/rag-chatbot-pro_0.1.1_1786791835946_0.3914825996937641"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-15T09:56:15.547Z","modified":"2026-08-15T11:03:56.302Z","0.1.0":"2026-08-15T09:56:15.948Z","0.1.1":"2026-08-15T11:03:56.089Z"},"bugs":{"url":"https://acetrum.com/contact"},"author":{"name":"Acetrum","email":"info.acetrum@gmail.com"},"license":"UNLICENSED","homepage":"https://acetrum.com","keywords":["chatbot","rag","ai","widget","nextjs","lead-capture","pro"],"repository":{"type":"git","url":"git+https://github.com/avneesh30/rag-chatbot-pro.git"},"description":"Pro RAG chatbot plugin — DOCX/TXT/MD/CSV + website crawl, client dashboard, citations, semantic cache. Requires a paid license key (acetrum.com) to function; degrades to a free-tier subset without one.","maintainers":[{"name":"acetrumtech","email":"info.acetrum@gmail.com"}],"readme":"# @acetrumtech/rag-chatbot-pro\n\nPro version of [rag-chatbot-plugin](../rag-chatbot-plugin) — imports/extends the free\npackage, gated by a license check against our own [license-server](../license-server).\n\n**Published to public npm** as `@acetrumtech/rag-chatbot-pro` — publicly\ninstallable, but proprietary (see `LICENSE.md`) and non-functional without a\nvalid, paid license key. `npm run publish:pro` builds + obfuscates + publishes\nin one step.\n\n## What's here (Step 3 — skeleton)\n\n- `src/license.js` — the license-check module: 24h local cache, live `POST /verify`\n  against the license server, HMAC signature + freshness verification, 7-day grace\n  period if the server is unreachable. **Never throws** — an invalid/unreachable\n  license degrades to free mode, never crashes the client's site.\n- `src/hmac.js` — same signing scheme as `license-server/app/src/hmac.js`, so a\n  server response can be independently re-verified here.\n- `src/config.js` — `loadProConfig()`: wraps the free package's `loadConfig()`, adds\n  a `pro` config section, runs the license check, and sets `cfg.pro.isPro`.\n- `src/index.js` — re-exports the entire free package's API + the pro pieces above.\n\nNo pro-only features/routes exist yet — those land in later roadmap phases\n(Client Dashboard is next, Phase 1). This step is purely the license-gating\nfoundation everything else will check against.\n\n## Config\n\nIn `chatbot.config.js` (or via env vars):\n\n```js\nexport default {\n  // ...all the usual free config...\n  pro: {\n    licenseKey: 'XYZC-XXXXXXXXXXXX',       // the only thing a client actually types in\n    // domain: NOT set here — auto-detected from the first request's Host\n    // header (as `https://<host>/`), see note below. Only set this explicitly\n    // for an unusual case (e.g. running behind a domain the Host header won't\n    // reflect correctly, like some proxy setups).\n    // licenseServerUrl is NOT set here either — see note below.\n    // Step 9 — semantic cache. Off by default. Answers repeated/near-duplicate\n    // visitor questions from a cache instead of a fresh RAG search + LLM call —\n    // see src/semantic-cache.js for the full design notes (threshold tradeoffs,\n    // the \"matches on latest question text only\" scoping decision, and the\n    // enquiry-bypass heuristic that keeps it from swallowing real leads).\n    semanticCache: {\n      enabled: true,\n      threshold: 0.93,   // cosine similarity cutoff — raise for stricter matching, lower for more hits\n      maxEntries: 500,   // oldest entries pruned once exceeded\n      ttlHours: 168       // 7 days; entries older than this are treated as a miss\n    }\n  }\n};\n```\n\n**A client only ever needs to set `licenseKey`.** Everything else about\nlicensing is either infrastructure we own or something the plugin figures out\nitself:\n\n- **`licenseServerUrl` is a build-time constant, not client config.** It's\n  *our* infrastructure, the same for every client. `build.js` inlines it\n  (alongside `LICENSE_HMAC_SECRET`) as a build-time constant via esbuild's\n  `define` — a distributed/obfuscated install never needs `LICENSE_SERVER_URL`\n  set anywhere, and a client's `.env` never sees our VPS address. (Still\n  overridable per-install via `pro.licenseServerUrl` in chatbot.config.js if\n  we ever need to point one specific install at a different server.)\n- **`domain` is auto-detected, not typed in.** `loadProConfig()` leaves it\n  unresolved at startup if not explicitly set; `handler.ts` derives it from\n  the first real request's `Host` header (as `https://<host>/`) and runs the\n  actual `/verify` check then, on whichever request arrives first — same\n  fire-once, memoized-in-flight pattern already used for the RAG index build.\n  This is why the license check log line (`license OK (valid) — domain: ...`)\n  shows up after the first request hits the server, not at cold start. Still\n  overridable via `pro.domain`/`LICENSE_DOMAIN` for the rare case where\n  auto-detection isn't right (e.g. behind a proxy that rewrites Host).\n  **Caveat**: the license server does a literal string match on domain, not a\n  normalized one — a license created via the admin dashboard with a different\n  string format (bare `clientsite.com` instead of `https://clientsite.com/`)\n  won't match auto-detection's reconstructed format. Create licenses with the\n  `https://domain/` format to match what auto-detection actually sends.\n\n`LICENSE_SERVER_URL`/`LICENSE_HMAC_SECRET` env var equivalents exist only for\nsource/`lib/` dev (see `Local dev` below) — there are no env var equivalents\nfor `licenseKey`/`domain` at all; both are code-level (a config prop / request\nHost header), never env. Semantic cache env equivalents: `SEMANTIC_CACHE_ENABLED` (`true`/`false`),\n`SEMANTIC_CACHE_THRESHOLD`, `SEMANTIC_CACHE_MAX_ENTRIES`, `SEMANTIC_CACHE_TTL_HOURS`.\n\nThe Client Dashboard's `/admin` page shows a \"Cache hits (saved AI calls)\" stat\nonce enabled. Cache is automatically cleared on `POST /reindex` (new/changed docs\ncould make old cached answers stale).\n\n**Dashboard URL note:** `/admin` is relative to your configured `server.basePath`\n(default `/api/chatbot`), so the actual URL is `<your-api-url>/admin` — e.g.\n`https://yoursite.com/api/chatbot/admin`, not bare `/admin`. All of the\ndashboard's own internal nav/links account for this automatically now (fixed\n2026-08-06 — they used to be hardcoded to bare `/admin/...`, which 404'd on\nevery real (non-root-basePath) deployment the moment you clicked anything\ninside the dashboard, even though the dashboard's own landing page loaded fine\nat its correct URL).\n\n## Usage\n\n```js\nimport { loadProConfig, createProCoreHandler } from '@acetrumtech/rag-chatbot-pro';\n\nconst cfg = await loadProConfig();\nconsole.log(cfg.pro.isPro ? `Pro (${cfg.pro.plan})` : 'Free mode');\n\nconst handle = createProCoreHandler(cfg);\n```\n\n## TypeScript\n\nSource is TypeScript (`src/**/*.ts`), compiled by `tsc` to `lib/` (type-checked,\nwith `.d.ts` output — this is what `main`/`exports` in package.json point at, and\nwhat `devtest/`/`test/` run against). `npm run build` runs `tsc` then a small\npostbuild step (strips a synthetic `export {}` from the compiled widget so it\nstays valid as a classic `<script>` tag — see `src/widget/widget.ts`'s comment).\n\nThe distributable tarball (what actually ships to paying clients) is a\n*separate*, further step: `npm run bundle` (`build.js`, esbuild) minifies +\nobfuscates `lib/` into `dist/`, inlining `LICENSE_HMAC_SECRET` and\n`LICENSE_SERVER_URL` at build time. `npm run pack:pro` runs both\n(`build` → `bundle` → `npm pack`).\n\n```bash\nnpm run build      # tsc -> lib/ (compile + type-check)\nnpm run watch       # tsc --watch, for local dev — restart devtest/run.js to pick up changes\nnpm run bundle      # lib/ -> dist/ (obfuscated tarball build, needs LICENSE_HMAC_SECRET + LICENSE_SERVER_URL)\n```\n\n## Local dev / testing against the real license-server\n\n```bash\ncp .env.example .env   # fill in LICENSE_HMAC_SECRET (must match license-server's .env) + LICENSE_SERVER_URL\nnpm install\nnpm test              # builds (tsc) then exercises all license branches against localhost:4000\nnpm run test:cache    # builds then runs the semantic-cache unit tests (no live API needed)\n```\n\nRequires `license-server` running locally (`docker compose up -d` in that repo) with\nat least one test license created via its `/admin` dashboard.\n","readmeFilename":"README.md"}