feat: sase.tr v2 full application implementation
Complete rewrite of sase.tr VIN lookup platform with modern stack: Backend (NestJS 10 + Drizzle ORM + PostgreSQL + Redis + BullMQ): - 34 DB models (core + PL24 + EMEX schemas) - Auth via Better Auth (email/password + social) - Brands, Plans, Subscriptions, Payments (iyzico + EFT) - VIN decode orchestration (Corgi + PL24 + EMEX + NHTSA) - Interactive schema viewer backend (MinIO storage) - EMEX scraping integration (Puppeteer + BullMQ workers) - Translation module (EN→TR automotive dictionary) - Admin dashboard API (stats, user mgmt, payment approval) - Rate limiting, Helmet security, file upload validation Frontend (Next.js 15 + Tailwind v4 + shadcn/ui + TanStack Query + Zustand): - 20 routes: auth, dashboard, VIN search, schema viewer, admin - Interactive schema viewer with zoom/pan/hotspot highlighting - Subscription management with brand selector - Payment flow (iyzico 3D Secure + EFT with receipt upload) - i18n support (TR/EN) - Error boundaries, loading skeletons, 404 page Infrastructure: - 85 tests (52 backend + 33 frontend, Vitest) - CI/CD (GitHub Actions: lint, typecheck, test, build, deploy) - Zero-downtime deploy script (PM2) - Env validation script Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
56
apps/api/src/main.ts
Normal file
56
apps/api/src/main.ts
Normal file
@@ -0,0 +1,56 @@
|
||||
import { NestFactory } from "@nestjs/core";
|
||||
import { ConfigService } from "@nestjs/config";
|
||||
import helmet from "helmet";
|
||||
import type { Request, Response, NextFunction } from "express";
|
||||
import { AppModule } from "./app.module";
|
||||
import { fileUploadValidation } from "./common/middleware/file-upload-validation.middleware";
|
||||
|
||||
async function bootstrap() {
|
||||
const app = await NestFactory.create(AppModule);
|
||||
|
||||
const configService = app.get(ConfigService);
|
||||
const port = configService.get<number>("port", 4000);
|
||||
const corsOrigins = configService.get<string[]>("cors.origin", ["http://localhost:3000"]);
|
||||
|
||||
app.setGlobalPrefix("api");
|
||||
|
||||
// Security headers
|
||||
app.use(helmet());
|
||||
|
||||
app.enableCors({
|
||||
origin: corsOrigins,
|
||||
credentials: true,
|
||||
methods: ["GET", "POST", "PUT", "PATCH", "DELETE", "OPTIONS"],
|
||||
allowedHeaders: ["Content-Type", "Authorization", "Cookie"],
|
||||
exposedHeaders: ["set-cookie"],
|
||||
maxAge: 86400,
|
||||
});
|
||||
|
||||
// File upload validation middleware (PNG/JPG/PDF only, max 5MB)
|
||||
app.use(fileUploadValidation);
|
||||
|
||||
// Cache-Control headers middleware
|
||||
app.use((req: Request, res: Response, next: NextFunction) => {
|
||||
if (req.method !== "GET") {
|
||||
return next();
|
||||
}
|
||||
|
||||
const path = req.originalUrl;
|
||||
|
||||
if (path.startsWith("/api/brands")) {
|
||||
res.setHeader("Cache-Control", "public, max-age=1800");
|
||||
} else if (path.startsWith("/api/plans")) {
|
||||
res.setHeader("Cache-Control", "public, max-age=1800");
|
||||
} else if (path.startsWith("/api/health")) {
|
||||
res.setHeader("Cache-Control", "no-cache");
|
||||
} else {
|
||||
res.setHeader("Cache-Control", "no-store");
|
||||
}
|
||||
|
||||
next();
|
||||
});
|
||||
|
||||
await app.listen(port);
|
||||
console.log(`API running on http://localhost:${port}`);
|
||||
}
|
||||
bootstrap();
|
||||
Reference in New Issue
Block a user