feat: sase.tr v2 full application implementation

Complete rewrite of sase.tr VIN lookup platform with modern stack:

Backend (NestJS 10 + Drizzle ORM + PostgreSQL + Redis + BullMQ):
- 34 DB models (core + PL24 + EMEX schemas)
- Auth via Better Auth (email/password + social)
- Brands, Plans, Subscriptions, Payments (iyzico + EFT)
- VIN decode orchestration (Corgi + PL24 + EMEX + NHTSA)
- Interactive schema viewer backend (MinIO storage)
- EMEX scraping integration (Puppeteer + BullMQ workers)
- Translation module (EN→TR automotive dictionary)
- Admin dashboard API (stats, user mgmt, payment approval)
- Rate limiting, Helmet security, file upload validation

Frontend (Next.js 15 + Tailwind v4 + shadcn/ui + TanStack Query + Zustand):
- 20 routes: auth, dashboard, VIN search, schema viewer, admin
- Interactive schema viewer with zoom/pan/hotspot highlighting
- Subscription management with brand selector
- Payment flow (iyzico 3D Secure + EFT with receipt upload)
- i18n support (TR/EN)
- Error boundaries, loading skeletons, 404 page

Infrastructure:
- 85 tests (52 backend + 33 frontend, Vitest)
- CI/CD (GitHub Actions: lint, typecheck, test, build, deploy)
- Zero-downtime deploy script (PM2)
- Env validation script

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Sase Dev
2026-02-12 02:03:56 +00:00
parent 7fc47ce9cc
commit 56a3c8bfaa
215 changed files with 25043 additions and 0 deletions

56
apps/api/src/main.ts Normal file
View File

@@ -0,0 +1,56 @@
import { NestFactory } from "@nestjs/core";
import { ConfigService } from "@nestjs/config";
import helmet from "helmet";
import type { Request, Response, NextFunction } from "express";
import { AppModule } from "./app.module";
import { fileUploadValidation } from "./common/middleware/file-upload-validation.middleware";
async function bootstrap() {
const app = await NestFactory.create(AppModule);
const configService = app.get(ConfigService);
const port = configService.get<number>("port", 4000);
const corsOrigins = configService.get<string[]>("cors.origin", ["http://localhost:3000"]);
app.setGlobalPrefix("api");
// Security headers
app.use(helmet());
app.enableCors({
origin: corsOrigins,
credentials: true,
methods: ["GET", "POST", "PUT", "PATCH", "DELETE", "OPTIONS"],
allowedHeaders: ["Content-Type", "Authorization", "Cookie"],
exposedHeaders: ["set-cookie"],
maxAge: 86400,
});
// File upload validation middleware (PNG/JPG/PDF only, max 5MB)
app.use(fileUploadValidation);
// Cache-Control headers middleware
app.use((req: Request, res: Response, next: NextFunction) => {
if (req.method !== "GET") {
return next();
}
const path = req.originalUrl;
if (path.startsWith("/api/brands")) {
res.setHeader("Cache-Control", "public, max-age=1800");
} else if (path.startsWith("/api/plans")) {
res.setHeader("Cache-Control", "public, max-age=1800");
} else if (path.startsWith("/api/health")) {
res.setHeader("Cache-Control", "no-cache");
} else {
res.setHeader("Cache-Control", "no-store");
}
next();
});
await app.listen(port);
console.log(`API running on http://localhost:${port}`);
}
bootstrap();