DerList v0.11.5 — Product Importer & AI Research Fixes
Pre-release
Pre-release
Product Importer & AI Research Fixes
This release redesigns the product identification pipeline to use AI as the primary product identification source. The system now verifies product identity strictly, tracks data sources per-field, and provides clear fallback when AI is unavailable.
AI-First Product Identification
- AI is now the PRIMARY product identification source (previously a fallback)
- Configured AI provider researches the exact product from the user's URL
- Strict structured JSON response schema enforced on all AI output
- AI receives all available evidence: URL, ASIN, retailer, search results, structured metadata
- AI prompt explicitly prohibits inventing prices, images, UPCs, SKUs, or URLs
- AI must return
nullfor any field it cannot verify - AI confidence scored per-field (name, brand, model, category, price, image, etc.)
Product Identity Verification
- New identity validator with 10 verification checks
- ASIN exact match enforcement: input ASIN must match identified product ASIN
- Critical conflict detection rejects misidentified products
- Title-not-URL check prevents URLs from being used as product names
- Title-not-retailer check rejects generic retailer names as product titles
- Title consistency cross-check between AI and search evidence
- Brand consistency verification across sources
- Price reasonableness validation
- Multiple evidence agreement scoring
Search as Supporting Evidence
- Search providers (SerpAPI, Brave) now gather supporting evidence for AI
- Search results no longer independently identify products
- Search-only results capped at 60% confidence (always needs review)
- Multi-query ASIN search strategy preserved for evidence gathering
Import Status & Field Source Tracking
- Full import lifecycle states: idle, analyzing, identifying, verifying, needs_review, ready, added, failed, no_ai_configured, conflict
- Per-field source tracking (ai, url, search, keepa, structured-data, manual)
- Per-field confidence scores
- Import metadata: provider used, model, tokens, duration, timestamp
No-AI-Configured Handling
- Explicit
no_ai_configuredstatus when user has no AI provider - Clear UI message: "AI identification isn't configured"
- Product Editor opens for manual entry with verified context (URL, ASIN, retailer) preserved
- System never fabricates product information when AI is unavailable
Image Validation & SSRF Protection
- SSRF protection blocks localhost, private IPs, IPv6 loopback, link-local, cloud metadata endpoints, unsafe ports
- Rejects encrypted Google thumbnails, favicons, placeholders, CAPTCHA images
- HTTP-verifies images before acceptance
- Keepa image provider extracts real Amazon CDN image IDs from imagesCSV
Live Wishlist Events
- New SSE event types:
wishlist.identification.started,wishlist.identification.progress,wishlist.identification.completed,wishlist.identification.failed,wishlist.identification.conflict - Activity timeline with step-by-step progress updates
emitIdentificationEvent()helper for pipeline integration
Product Editor Enhancements
- Import status banner (no_ai_configured, ready, needs_review, conflict, failed states)
- Field source badges showing where each value came from (AI, URL, Search, Keepa, Manual)
- AI activity timeline panel showing step-by-step identification progress
- ASIN, UPC, MPN fields added to editor
- Identify button now works with URL input
Tests
- 54 new tests covering the AI identification pipeline
- Amazon URL parsing and ASIN extraction
- Exact ASIN matching and wrong ASIN rejection
- AI response parsing with code-fence stripping
- Invalid JSON handling
- URL-as-title regression tests
- SSRF protection (localhost, private IPs, metadata endpoints, unsafe ports)
- Critical regression test: B0GSS4SGZR must NOT be identified as Beats Solo 4
Bug Fixes
- Product URLs no longer used as product titles
- Mismatched ASINs no longer silently accepted
- Search results no longer override AI when identifiers conflict
- Price never fabricated (returns null when unverifiable)
- Image URLs never constructed from ASINs
- Retailer names no longer accepted as product brands
Full Changelog: v0.11.0...v0.11.5