Files
hold-slayer/services/tts.py
Robert Helewka 94fb6cd79d feat: mount MCP server, add bearer auth, and guard outbound calls
The MCP server was created but never mounted — no client could reach
it. Mount it at /mcp/ over streamable HTTP with a combined lifespan,
resolving the gateway lazily so mounting happens at app construction.

Security and safety for the agent surface:
- One static API_TOKEN (SecretStr) enforced across REST (dependency),
  WebSocket (query param/header before accept), and MCP
  (StaticTokenVerifier). Startup refuses tokenless non-loopback binds.
- Emergency numbers (911/9911/112) always refused on make_call, plus a
  MAX_CONCURRENT_CALLS cap; ValueError surfaces as 400/ToolError.
- Safe defaults: debug off, no credential in default DATABASE_URL,
  SIP/LLM/TTS secrets as SecretStr.

Cleanups:
- Delete broken learn_call_flow tool (wrong ctor args, nonexistent
  method) and the never-fed CallAnalytics service; keep
  call_flow_learner for proper wiring later.
- Trim dial_plan to what is actually used (emergency guard, extension
  allocation); delete the unreferenced matcher/normaliser.
- Register call_history before calls so /api/calls/history is no
  longer shadowed by /api/calls/{call_id}.
- fastmcp pinned >=3.0 (http_app + StaticTokenVerifier).

New tests: MCP in-memory client (tool surface, lazy gateway, emergency
refusal, call cap) and API security (401 paths, route order, mount).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 15:20:24 -04:00

91 lines
2.9 KiB
Python

"""
TTS Service — Rhema (OpenAI-compatible) text-to-speech client.
Synthesizes speech for the SPEAK call-flow step and the AI Receptionist.
Rhema exposes POST /v1/audio/speech (OpenAI-compatible) with Kokoro voices.
"""
import logging
from pathlib import Path
from typing import Optional
import httpx
from config import TTSSettings
logger = logging.getLogger(__name__)
class TTSService:
"""Client for Rhema TTS service."""
def __init__(self, settings: TTSSettings):
self.settings = settings
self._client: Optional[httpx.AsyncClient] = None
async def _get_client(self) -> httpx.AsyncClient:
if self._client is None or self._client.is_closed:
headers = {}
if self.settings.api_key.get_secret_value():
headers["Authorization"] = f"Bearer {self.settings.api_key.get_secret_value()}"
self._client = httpx.AsyncClient(
base_url=self.settings.base_url,
timeout=httpx.Timeout(self.settings.timeout, connect=5.0),
headers=headers,
)
return self._client
async def synthesize(
self,
text: str,
voice: Optional[str] = None,
response_format: str = "wav",
) -> bytes:
"""Synthesize speech and return audio bytes."""
if not text or not text.strip():
return b""
client = await self._get_client()
body = {
"model": self.settings.model,
"input": text,
"voice": voice or self.settings.voice,
"response_format": response_format,
"sample_rate": self.settings.sample_rate,
}
try:
response = await client.post("/v1/audio/speech", json=body)
response.raise_for_status()
return response.content
except httpx.HTTPStatusError as e:
logger.error(f"Rhema TTS error: {e.response.status_code} {e.response.text}")
return b""
except httpx.ConnectError:
logger.error(f"Cannot connect to Rhema at {self.settings.base_url}")
return b""
except Exception as e:
logger.error(f"TTS synthesis failed: {e}")
return b""
async def synthesize_to_file(
self,
text: str,
filepath: str | Path,
voice: Optional[str] = None,
) -> bool:
"""Synthesize to a WAV file. Returns True on success."""
audio = await self.synthesize(text, voice=voice, response_format="wav")
if not audio:
return False
path = Path(filepath)
path.parent.mkdir(parents=True, exist_ok=True)
path.write_bytes(audio)
logger.debug(f"TTS wrote {len(audio)} bytes to {path}")
return True
async def close(self) -> None:
if self._client and not self._client.is_closed:
await self._client.aclose()
self._client = None