125 Commits

Author SHA1 Message Date
71568e2274 feat(rpartstore): Renault/Dacia için RPartStore VIN-decode fallback kaynağı
Some checks are pending
QA Gate (P0/P1) / Test affected app (pull_request) Waiting to run
rpartstore.renault.com (Renault Group bayi portalı) yeni decode kaynağı olarak
eklendi. Portal REST değil STOMP 1.2 over WebSocket konuşuyor; login Okta OIE
(IDX JSON API + PKCE), tarayıcı gerekmiyor. Sıralama Renault/Dacia için:
pcat + PL24 + emex yarışı → rpartstore → (bayrağı açıksa) Vinpin son çare.

- integrations/rpartstore: STOMP codec, Okta login, oturum (trace-id ile
  çok-mesajlı cevap eşleme), istemci (Redis'te 1 saatlik token), Renault/Dacia
  yönlendirme, RPartStore → PL24 catalog_vehicles model eşleyici (roman rakam,
  karoseri niteleyici, yanlış-pazar cezası).
- rpartstore_decodes tablosu (migration 0037) + rpartstore-decode BullMQ
  kuyruğu; worker concurrency 1 + 1 iş / 6 s limiter (portal 2 arama / 10 s).
- Günlük sert kota RPARTSTORE_DAILY_CAP (varsayılan 10, İstanbul günü):
  işlemci göndermeden önce Redis INCR ile rezervasyon yapar, aşan VIN'ler
  `capped` olur ve 24 saat sonra tekrar denenir; API kota doluysa kuyruğa
  hiç almaz. Kısa vadeli rate-limit cevabında retryAfter kadar bekleyip bir
  kez tekrar dener.
- VehiclesService.tryRpartstoreFallback: Vinpin fallback ile aynı sözleşme
  (decoding/catalogVehicle cevapları, tek başarısızlık log satırı).
- Env: RPARTSTORE_ENABLED/USER/PASS/DAILY_CAP/BROKER_URL/APP_VERSION
  (compose api+worker). Vinpin koda dokunulmadan pasif kalır (VINPIN_ENABLED).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-25 13:58:09 +03:00
41147f3f05 fix(pl24): kendi bütçe frenimiz "hesap banlandı" alarmı üretmesin
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Prod 2026-09-21 19:10 (İstanbul) itibarıyla Telegram "🔴 PL24 giriş
yapılamıyor — hesap banlanmış olabilir" dedi. Hesap sağlamdı:
kullanıcı tarayıcıdan giriş yapabildi, aynı gün 143 başarılı auth
çağrısı ve **0 × 401** vardı. Gerçek sebep alarmın kendi metninde:
"PL24 daily HTTP budget exhausted (user lane: 1205/1200)" — yani
upstream değil, BİZİM günlük tavanımız.

Zincir: `attemptLogin` içindeki `budget.consume()` fırlatıyor → dış
`catch` bunu `{ error }` olarak düzleştiriyor → `loginWithLock`
`!result.sessionToken` dalına giriyor → `breakerFail()` + kesinti
sayacı → bir saat sonra ban alarmı. Yani kendi frenimiz hem devre
kesiciyi tetikliyor hem de operatörü yanlış yere çağırıyor.

- `PL24BudgetExceededError` artık `attemptLogin` ve
  `authorizeServiceForAccount` içinde olduğu gibi yukarı çıkıyor;
  giriş/yetkilendirme hatasına çevrilmiyor. Devre kesici tetiklenmiyor,
  kesinti sayacı başlamıyor, Telegram susuyor. Çağıran taraf PL24'ü
  atlayıp pcat/emex'e düşüyor — bugün de öyle oluyordu, ama artık
  sessizce ve doğru gerekçeyle.
- Şerit bazlı sayaç eklendi: `pl24:http:<gün>:{user,worker}`. Paylaşılan
  toplam tavanın NE ZAMAN dolduğunu söylüyordu ama KİMİN harcadığını
  söylemiyordu; tavanı veriyle boyutlandırmak için bu şart. Bugün
  toplam 1200'e vurdu ve 16:10 UTC'den sonra her kullanıcı decode'u
  reddedildi, ama ne kadarının ısıtma prefetch'i ne kadarının ekran
  başında bekleyen biri olduğu `proxy_logs`'tan çıkarılamıyordu.

5 yeni test. api 650 test geçiyor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-21 20:52:52 +03:00
e03d721c37 Merge pull request 'feat(pl24): Faz 3 — backfill anahtarı + Mitsubishi parça-listesi düzeltmesi' (#270) from dev into main 2026-09-21 20:47:52 +03:00
142ec3a150 feat(pl24): Faz 3 — backfill anahtarı + Mitsubishi parça-listesi düzeltmesi
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Faz 3 backfill'i açmadan önce hacmi ölçtüm ve raporun işaret ettiğinden
çok daha büyük bir israf çıktı.

**Mitsubishi'nin parça listesi grup sanılıyordu.**
`/p5mitsubishi/extern/details/vinDetails` yanıtı `partno`/`qty` taşıyan
bir PARÇA listesi (canlı doğrulama: 16 kayıt), ama her kaydın kendi
linki `partInfoTable` ve ne wid ne yol sınıflandırıcıda karşılık
buluyordu. Sonuç (prod ölçümü): 2.193 parça listesi grup düğümüne
döndü, içlerindeki 19.576 tekil parça ("SCREW,LOCK CYLINDER",
"BOLT,STEERING COLUMN WASHER") kategori olarak kaydedildi. Bu 19.576
sahte düğümün TOPLAM 2 tanesinde parça var ve hepsi her prefetch
turunda yeniden çekiliyor. İkisi de %100 Mitsubishi.

- `detailsTable` artık yaprak, `isPl24PartDetailNode()` ile
  `partInfoTable` hiç kuyruklanmıyor.
- `isLeafLinkPath` artık `linkWid`'i de geçiriyor. Okuma yolu bu
  güvenilir sinyali hep kullanıyordu ama kuyruklama yolu düşürüyordu —
  sınıflandırıcı `detailsTable`'ı öğrense bile burada yine grup
  sayılacaktı.
- Migration 0036: 19.576 sahte kategori siliniyor. Okuma yolu bir
  düğümün ÖNCE çocuklarına baktığı için bu silme düzeltmenin parçası,
  ayrı temizlik değil. Kuru çalıştırma: 19.576 kategori, 9 araç, 2
  parça, Mitsubishi dışı 0.

**Backfill anahtarı.** `PL24_BACKFILL_ENABLED` eklendi, varsayılan
KAPALI. Eski `PL24_TR_DISABLED` adı "tr hesabı öldü" diyordu ama işi
"toplu yükü tek sağ kalan hesaptan uzak tut"tu. Eski değişken hâlâ
kapatabiliyor — yarım deploy musluğu sessizce açamasın. Kullanıcı
tetikli fast-lane bu anahtardan etkilenmiyor.

9 yeni test. api 647 test geçiyor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 10:51:42 +03:00
e8ffa6a5db Merge pull request 'fix(pl24): model listesi giriş noktasını catmeta'dan çöz (Volvo browse)' (#269) from dev into main 2026-09-20 10:18:50 +03:00
bd9f4bd3f8 style(pl24): normalizeLabel'daki yanıltıcı karakter sınıfını düzelt
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
`[̀-ͯ]` bir aralık sınıfı; biome bunu "bir taban karakter +
birleştirici karakter çiftini de eşleyebilir" diye işaretliyordu.
NFD zaten her aksanı kendi işaretine ayırdığı için doğrudan `\p{M}`
(tüm birleştirici işaretler) hem doğru hem daha geniş.

Gerçek Volvo/PSA/Subaru yakalamalarıyla çıktı birebir aynı kaldı.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 09:32:24 +03:00
d75c468341 fix(pl24): model listesi giriş noktasını catmeta'dan çöz
Prod'da browse onarması Peugeot'yu taşıdı (64 bayat satır → 39 güncel
model) ama Volvo'da "upstream returned no models" ile korumalı dala
düştü. Sebep: `BACKEND_MODEL_PATH`'te p5volvo yok ve yedek keşif yedi
bilinen yolu deniyor — Volvo'nunki `/extern/vehicles/models`, yani
ÇOĞUL "vehicles", listede yok. Volvo/Polestar browse bu yüzden sıfır
model tohumluyor ve emekli P4 listesini sunmaya devam ediyordu.

Otoritatif kaynak her P5 backend'inin kendi `/extern/catmeta`
yanıtındaki `data.catalogEntryPoint.path`. Canlı doğrulandı:
  p5volvo → /p5volvo/extern/vehicles/models  (60 model: XC90, V40…)
  p5psa   → /p5psa/extern/vehicle/catalogs

İki değişiklik:
- p5psa ve p5volvo `BACKEND_MODEL_PATH`'e sabitlendi (sıfır ek istek).
  p5psa zaten çalışıyordu ama her çağrıda beş boşa probe isteğiyle
  yeniden keşfediliyordu.
- `resolveModelPathFromCatmeta()`: haritada olmayan backend artık yedi
  kör probe yerine tek otoritatif catmeta çağrısı yapıyor. Sonuç
  backend başına 30 gün cache'leniyor (olumsuz sonuç dahil), yani
  backend ömrü boyunca tek istek; PL24 bir ucu taşırsa kendiliğinden
  düzeliyor. Hata durumunda null → eski yedeğe düşer.

8 yeni test. api 638 test geçiyor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 09:30:53 +03:00
a4e22e1bb8 Merge pull request 'fix(pl24): bütçe kilitlenmesi, sabitlenmiş browse satırları, Volvo alanları + WMI kapsamı' (#268) from dev into main 2026-09-20 09:15:26 +03:00
c2f4d8f421 feat(pl24): WMI haritasını canlı servis taramasıyla genişlet, Renault'yu aç
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Prod'daki 4.799 aracın 1.406'sının WMI'si haritada yoktu. Hangilerinin
PL24'te gerçekten karşılığı olduğu tahmin edilmedi — canlı
`/pl24-wmi/ext/api/2.0/decode` servisine gerçek prod VIN'leriyle tek tek
soruldu (2026-09-20).

**Renault yeniden açıldı (450 araç).** İki gerekçe de artık geçersiz,
ikisi de prod'a karşı doğrulandı:
- Askı kalkmış: `/p5renault` directAccess, gerçek müşteri aracı
  VF14SRCL458170337 için `VEHICLE_IDENTIFIED` + "SYMBOL II/LOGAN II"
  döndü; WMI servisi de `{service: renault_parts, error: false}` diyor.
- Devre kesici artık kesin olumsuz yanıtları saymıyor, yalnız geçici
  taşıma hatalarını (`vehicles.service` `isTransient`).

**Yeni eşlemeler (toplam 730 araç):** NLH/TMA/NLJ/KMF → hyundai_parts,
KNE/KNC → kia_parts, MMC/XMC → mmc_parts, JSA → suzuki_parts,
NMB → **mercestrucks**_parts (servis binek Mercedes'e değil kamyon
kataloğuna çözüyor; bu 30 araç "Mercedes-Benz" etiketliydi ama binek
kataloğunda yok).

**Kasıtlı olarak EKLENMEYENLER** — servis HTTP 410 "no brands found"
dedi, tıpkı NM4 ve VR7 gibi: JHM/SHH/SHS/MAK/NLA (Honda), KL1
(Chevrolet). Eklemek yalnız boşuna istek üretir ve pcat/emex/vinpin
fallback'ini geciktirir. JMZ (Mazda) 410 değil ama fordp/fordt
döndürüyor (Ford-Mazda platform ortaklığı); marka tutarsız olduğu için
eklenmedi.

6 yeni test; "olmayanlar" da kilitlendi. Ayrıca her eşlemenin katalog
tanımı olduğunu doğrulayan bütünlük testi. api 623 test geçiyor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 08:53:07 +03:00
72f8c2a3e4 fix(pl24): Volvo alanlarında iç kodu değil okunur değeri kullan
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Volvo vinfoBasic aynı özniteliği iki kez veriyor: "Şanzıman kodu" = "B"
ile "Şanzıman" = "6-PSHIFT 2WD / MPS6", "Satis tipi" = "42" ile "Türü"
= "S80". VAG için doğru olan kod-önce sırası (VAG'ın "Şanzıman kodu"
zaten anlamlı: "MQ200") bu yüzden Volvo'da şanzımanı tek harf, seriyi
çıplak sayı yapıyordu.

`lookupDescriptive()` eklendi: listedeki ilk *açıklayıcı* değeri döner
(2 karakterden uzun ve salt rakam değil), hiçbiri açıklayıcı değilse
ilk mevcut değere düşer — yani yalnız kod üreten backend'ler aynen
eskisi gibi davranır. Şanzıman ve seri bu yardımcıya geçti.

Ayrıca eksik İngilizce etiketler eklendi: `transmission` (İngilizce
yanıtta şanzıman yine tek harfe düşüyordu) ve `body_style`.

Ölçüm (gerçek keşif yakalamaları, YV1AS84ABD1168166 S80):
- şanzıman "B" → "6-PSHIFT 2WD / MPS6"
- seri "42" → "S80"
- kaporta İngilizce yanıtta null → "Sedan"
- PSA İngilizce yanıtta şanzıman null → "BVM5"
PSA Türkçe, Subaru ve diğer markalarda çıktı değişmedi.

6 yeni test + iki dilde gerçek Volvo fixture'ı. api 617 test geçiyor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 08:45:16 +03:00
0928559ea4 fix(catalog): browse onarmasında yalnız bayat satırları sil
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Bir servis karışık olabilir: bazı satırları yeni mimariyle yeniden
listelenmiş, bazıları hâlâ eski. Silme servis adına göre yapıldığında
zaten taşınmış satırlar da gidiyordu — üstteki insert onları
`onConflictDoNothing` ile atladığı için geri gelmiyorlar, yani temelli
kayıp. Silme artık yalnız gerçekten bayat olan satırlara uygulanıyor.

Hangi satırların silindiğini doğrulayan test eklendi (drizzle
`inArray` parametrelerini okuyarak).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 08:40:26 +03:00
eb18c9a122 fix(catalog): sabitlenmiş browse satırlarını görüntülendikçe yenile
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
`catalog_vehicles` kalıcı bir cache: `getModels` markanın tek bir satırı
varsa erken dönüyor, dolayısıyla `fetchVehicleList` o marka için bir
daha hiç çağrılmıyor. PSA ve Volvo hâlâ P4 iken listelenmiş 188 satır
(prod 2026-09-20: 127 LEGACY_PSA + 61 LEGACY_VOLVO) bu yüzden kalıcı
olarak çakılı kalmıştı:

- Peugeot/Citroën browse donmuş 2024-02-13 anlık görüntüsünü sunuyor,
- Volvo/Polestar browse HTTP 503 dönen bir uca gidiyor.

Kod düzeltmesi bu satırlara hiçbir zaman ulaşmıyordu.

`isStaleBrowseArchitecture()` + `CatalogService.healStaleBrowseRows()`:
satırın kayıtlı mimarisi servis tablosundakiyle uyuşmuyorsa marka bir
kez yeniden listeleniyor, yeni satırlar yazılıp eskiler aynı
transaction'da siliniyor. VIN tarafındaki onarma ile aynı temkinli
kurallar: marka başına günde bir deneme (Redis kilidi), başarısız veya
boş listede eski satırlar korunuyor, silme ancak yenisi elde edilince
ve servis bazında yapılıyor.

8 yeni test; api paketi 610 test geçiyor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 08:35:09 +03:00
ae8a8046bf refactor(prefetch): kapı sırasını en ucuzdan pahalıya diz
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Pencere kontrolü saf saat aritmetiği, hiç I/O yapmıyor ve pencere
dışındaki iş zaten hiçbir faydalı iş yapamıyor — dolayısıyla dakikalık
Redis sayacından da önce gelmeli. Yeni sıra: pencere → cooldown →
dakikalık tavan → günlük bütçe. Böylece pencere dışında uyanan iş
hiçbir sayacı kirletmiyor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 08:31:55 +03:00
7644d91407 fix(prefetch): PL24 bütçe/iş-saati kilitlenmesini kır
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Prod'da PL24 prefetch tamamen durmuştu: günlük bütçe 600/600 dolu
görünürken gün boyunca SIFIR katalog isteği ve SIFIR yeni kategori
üretiliyordu (ölçüm 2026-09-20).

İki hata birlikte kapalı bir döngü kuruyordu:

1. Günlük bütçe `process()` içinde düşülüyor, iş-saati (ve cooldown)
   kapısı ise her handler'ın başında duruyordu. Pencere dışında uyanan
   bir iş önce bütçeden bir birim yiyor, sonra `time-window` fırlatıp
   hiçbir iş yapmadan erteleniyordu.

2. Bütçesi biten kaynak "bir sonraki UTC gece yarısı"na erteleniyordu.
   PREFETCH_PL24_START=9 ile bu an 03:00 Europe/Istanbul'a denk gelir —
   pencere açılmadan altı saat önce. Uyanan iş yine pencereye takılıyor,
   yine erteleniyor; taze günlük bütçe daha pencere açılmadan bu boş
   uyanmalarla tükeniyordu.

Düzeltme:
- cooldown + iş-saati kapıları `process()` içinde, bütçe düşülmeden
  ÖNCE çalışıyor; handler'lardaki kopyaları kaldırıldı.
- `alignToWindow()` eklendi: bütçe ertelemesi pencerenin içine
  hizalanıyor. Pencere tanımlı değilse (varsayılan 0–24) no-op.
- `currentIstanbulHour` artık `istanbulHourAt`'e deleg ediyor ve h24
  döngüsünün gece yarısı için ürettiği "24" değeri `% 24` ile
  normalleniyor (aksi halde saat hiçbir pencereye düşmez).

8 yeni regresyon testi; api paketi 602 test geçiyor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 08:29:55 +03:00
40c4d33068 Merge pull request 'fix(pl24): VR7 WMI'sini haritadan çıkar — PL24'te böyle bir marka yok' (#267) from dev into main 2026-09-20 08:16:37 +03:00
semih
fe91b504de fix(pl24): VR7 WMI'sini haritadan çıkar — PL24'te böyle bir marka yok
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Faz 2 / açık soru kapatıldı (analiz: /home/s/ss/plv2.md, bulgu types_wmi-04).

Rapor "VR7 muhtemelen Citroën, peugeot_parts yanlış" diyordu ve doğrulama
istiyordu. Canlı portal WMI servisi (2026-09-19, /pl24-wmi/ext/api/2.0/decode,
pl24-wmidata kapsamlı token) kesin yanıtı verdi:

  HTTP 410 — "error resolving VIN: no brands found for WMI = VR7"

Yani VR7 ne Peugeot ne Citroën: PL24'ün WMI veritabanında HİÇ YOK, tıpkı Tofaş
NM4 gibi. Raporun önerisi (VR7 → citroen_parts) uygulansaydı hata aynen devam
edecekti.

Prod'daki 17 VR7 aracının tamamı model çözülmeden ("Peugeot Peugeot") ve 0
kategoriyle kaydedilmişti. Haritada tutmak yalnız her sorguda boşuna bir PL24
isteği üretiyor ve gerçek kaynağa (pcat/emex/vinpin) geçişi geciktiriyor —
canlı gözlem: P4→P5 onarma denemesi de bu VIN'lerde "kayıt bulunamadı" ile
düşüyor.

Test: pl24.types.spec'e kapsam-dışı WMI kilidi (VR7 ve NM4 haritada olmamalı) +
canlı doğrulanmış yönlendirmeler (JF1→subaru, ZAR→alfa, VXK→psa_opel).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 00:35:03 +03:00
3b63ae02c6 Merge pull request 'feat(pl24): bayat P4 mimarisindeki araçları görüntülendikçe P5'e taşı' (#265) from dev into main 2026-09-20 00:26:01 +03:00
58ba612707 Merge pull request 'feat(internal-admin): expired/cancelled kullanıcı için yeni abonelik başlatma ucu' (#266) from feat/admin-start-subscription into main 2026-09-19 01:37:19 +03:00
Semih
854ccbbe12 feat(internal-admin): expired/cancelled kullanıcı için yeni abonelik başlatma ucu
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
POST /internal/admin/users/:id/subscriptions — panelin "Yeni abonelik başlat"
butonu için. manuallyActivate expired/cancelled'ı "yeni subscription
başlatın" diye reddediyordu ama bunu yapacak uç yoktu; manuel tanımlar
DB'den elle yapılıyordu.

- BillingService.startSubscription: active/trial varsa 409, plan aktif değilse
  409, Full plan → tüm aktif markalar, marka-limitli plan → brandIds tam sayı +
  aktif marka doğrulaması. days verilirse bitiş = şimdi + days (1..3650), yoksa
  billingPeriod default'u (aylık/yıllık). Gelir eventi (PostHog/Meta) ve
  referral kredisi tüketimi YOK — para hareketi olmayan founder tanımı.
- UserBillingController (internal/admin/users) + module kaydı.
- billing.service.spec.ts: 7 test.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ww3tfpuxBcettz81dDvyYt
2026-09-19 00:45:11 +03:00
semih
ddc223f745 feat(pl24): bayat P4 mimarisindeki araçları görüntülendikçe P5'e taşı
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Faz 2 / veri göçü (analiz: /home/s/ss/plv2.md, bulgu psa-07 / consumers_jobs-05).

SORUN: PSA ve Volvo upstream'de P5'e taşındı, ama daha önce decode edilmiş
araçlar hâlâ eski yollara işaret ediyor: 324 PSA aracı (302'si bir kullanıcıya
bağlı, 33.535 kategori) donmuş 2024-02-13 anlık görüntüsünden, 36 Volvo aracı
(34'ü kullanıcılı, 10.195 kategori) ölü P4 ucundan besleniyor. `decodeVin`'in
db_hit kısa devresi yüzünden kod düzeltmesi bu satırlara ASLA ulaşmıyor; ayrıca
`categories` tablosundaki (vehicle_id, name, source) tekil indeksi yüzünden yeni
ağaç eskisinin üzerine yazılamıyor.

YAKLAŞIM: toplu yeniden decode fırtınası yerine **görüntülendikçe kendi kendini
onarma**. Tek hayatta kalan hesaba 360 aracı arka arkaya sormak yerine, her araç
ilk açılışında bir kez taşınır.

- `isStalePl24Architecture()` (pl24-tree.ts): saklı catalogPath `/psa`|`/volvo`
  ama servis bugün P5 ise bayat. Hâlâ P4 olan markalar (Ford/Opel/Hyundai/Kia/
  Nissan) ve zaten P5 olan kayıtlar dokunulmaz.
- `CategoriesService.healStalePl24Architecture()`: cache'i atlayarak yeniden
  decode eder, eski ağacı SİLİP yenisini tek transaction'da yazar, raw_data'yı
  yeni catalogInfo ile günceller, `fully_fetched`'i düşürür ve
  `cat:tree` / `prefetch:complete` / `prefetch:noresult` anahtarlarını temizler.

Bilinçli olarak temkinli:
- Yeniden decode başarısız olur veya kategori dönmezse ESKİ ağaç korunur
  (bayat veri, veri yokluğundan iyidir).
- Deneme `pl24:heal:<vehicleId>` ile günde bir kez (setNx) — çözülemeyen bir VIN
  her sayfa görüntülemesinde PL24'e gidemez.
- Eski satırlar ancak yeni ağaç elde edildikten SONRA siliniyor (tekil indeks).
- PL24 bütçesi/hız sınırı zaten üstte: her onarma ~2 upstream isteği.

Test: `isStalePl24Architecture` 4 test (bayat tespiti, zaten-P5, hâlâ-P4 markalar,
eksik bilgi) + onarma akışı 4 test (ağaç değişir, P5 kayda dokunulmaz, boş decode
eski ağacı korur, günlük kilit). 221 test geçti; tsc + biome temiz.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 16:53:15 +03:00
d9bc61b99e Merge pull request 'fix(pl24): Opel/Hyundai/Kia decode'unda 0 kategori — tablo satırları okunmuyordu' (#264) from dev into main 2026-09-17 14:51:35 +03:00
semih
8d284f6442 fix(pl24): Opel/Hyundai/Kia decode'unda 0 kategori — tablo satırları okunmuyordu
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Faz 1 / adım 6 (analiz: /home/s/ss/plv2.md, bulgu p4legacy-03).

SORUN: Bu markalar ana gruplarını <a href> ile DEĞİL, satır attribute'uyla
veriyor:
  Opel     <tr class="tc-data-row" jsonurl="json-vin-main-group.action?catId=25
             &mainGroupId=394…" caption="BODY SHELL AND PANELS" ident="394">
  Hyundai  <tr class="tc-data-row" url="vin-group.action?…&mainGroup=BO…">
             <td>BO</td><td>BODY</td>
decodeVin yolu yalnız anchor tarayan parseP4NavigationCategories'i kullanıyordu
→ sayfa listeyi taşıdığı hâlde 0 kategori. Prod ölçümü (raw_data.categories):
Opel 177/181 (%97,8), Hyundai 12/12, Kia 6/6, Nissan 1/1 araç decode anında BOŞ.
(Kategori tablosu sonradan lazy-seed ile doluyor, ama decode kategorisiz
döndüğü için kullanıcı ilk açılışta boş görüyor ve prefetch self-seed'e zorlanıyor.)

Üç ayrı kusur vardı:
1. `parseFordGroupsFromHtml` bu satırları zaten anlıyor ama decode'dan hiç
   çağrılmıyordu → kategori zincirine fallback olarak eklendi
   (JSON ucu → tc-data-row tablosu → anchor taraması).
2. Volvo için konmuş `vin-group.action && !group1=` guard'ı Hyundai/Kia'nın
   AYNI ucu `mainGroup=` anahtarıyla kullanan gerçek ana gruplarını da eliyordu
   → artık `group1=` veya `mainGroup=` taşıyan satırlar korunuyor.
3. Satır attribute'ları HTML-escaped (`&amp;`), bu yüzden `[?&]mainGroup=`
   kontrolü hiç tutmuyordu → URL artık ayrıştırma anında entity-decode ediliyor
   (saklanan linkPath de böylece temiz).

Test: yeni `pl24-p4-groups.spec.ts` + 2026-09-16 canlı yakalamalarından kırpılmış
fixture'lar (`__fixtures__/p4_{opel,hyundai,ford,nissan}.html`). Opel 31 ana grup
("BODY SHELL AND PANELS"…), Hyundai 6 ("BODY"…), anchor-only parser'ın bu
sayfalarda hâlâ 0 döndüğü (fallback'in gerekçesi), Ford sharedCatCode scope
satırlarının bozulmadığı ve Nissan model-seçim satırlarının elendiği kilitlendi.
213 test geçti; tsc + biome temiz.

NOT: db_hit kısa devresi yüzünden mevcut araçlar kendiliğinden düzelmez; kazanç
yeni decode'larda. Toplu yeniden decode Faz 2'de.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 14:47:53 +03:00
4cae337241 Merge pull request 'feat(pl24): PSA+Volvo → P5, reaktif drill freni, 1 saatlik kesinti için Telegram uyarısı' (#263) from dev into main 2026-09-17 14:26:26 +03:00
semih
dde6f6a15c feat(pl24): PSA + Volvo'yu P5'e taşı, eksik katalogları ekle, ağaç sınıflandırmasını birleştir
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Faz 1 / adım 3-4 (analiz: /home/s/ss/plv2.md §3.3/§3.5, bulgular types_wmi-01/02/03/04/05,
p5core-02/03/04/05, psa-04/05/06, consumers_jobs-01/02).

CANLI GERÇEK (2026-09-16 keşfi): PL24 manufacturers API'si peugeot/citroen/
citroenDs/psa_opel/psa_vauxhall'ı `/p5psa`, volvo/polestar'ı `/p5volvo`,
subaru'yu `/p5subaru` olarak veriyor. Eski Volvo P4 ucu **503** döndürüyor
(ölü); eski PSA P4 ucu 200 döndürüyor ama verisi **2024-02-13'te donmuş**
(P5 upds 2026-09-07). Kodumuz her ikisini de P4'e yönlendiriyordu.

SERVİS TABLOSU:
- peugeot/citroen/citroenDs + YENİ psa_opel_parts, psa_vauxhall_parts → /p5psa
- volvo/polestar → /p5volvo · YENİ subaru_parts → /p5subaru
- YENİ abarth/alfa/jeep/lancia → /p5fiat
- WMI düzeltmeleri: ZAR→alfa, ZLA→lancia (fiatp'den), VXK→psa_opel (PSA-platform
  Corsa F/Mokka B), YENİ JF1/JF2→subaru, 1C4/1J4→jeep. SERVICE_TO_BRAND genişledi.
- P4 kodu ve eski yollar DOKUNULMADI: mevcut 322 PSA + 36 Volvo aracı eski
  ağaçlarıyla çalışmaya devam eder (veri göçü ayrı iş).

PARSER (canlı yanıt şekillerine göre):
- `normalizeLabel()`: JS toLowerCase Türkçe "İ"yi "i̇" (i + birleşen nokta)
  yapıyordu → PSA'nın "AKTARMA SİSTEMLERİ"/"GÖVDE TİPİ" etiketleri HİÇBİR ZAMAN
  eşleşmiyordu, şanzıman/gövde sessizce null kalıyordu. Artık tr-locale +
  diakritik temizliği + ı→i.
- `parsePsaModelYear()`: "AM 2005" → 2005; "MAJÖR ENDEKS" bir yıl DEĞİL (bu
  yüzden Citroën'ler 2001 görünüyordu). `damToModelYear()`: PSA DAM alanı
  (1976-01-01'den gün) → üretim yılı, model yılı Temmuz'da döner.
  PSA VIN'lerinde 10. karakter model yılı olmadığı için VIN fallback'i en sona.
- Alan listeleri: motor/engine (PSA "MOTOR", Volvo "Motor"), aktarma_sistemleri,
  mission, govde_tipi, kaporta_stili, türü→series.
- Alt grup kodu: PSA'da `record.id` = illusPath ve birden çok illüstrasyon
  paylaşıyor (canlı: 36 kayıt / 11 id) → benzersiz kod `values.illustration`.
- Parça filtresi: Volvo BOM'unun başlık satırı (id "null_null", link yok,
  unavailable) hayalet parça olarak geçiyordu → elendi.
- Adet: qty (VAG/Subaru) · coef (PSA) · unit (Volvo). Uygulanabilirlik:
  modelDescription · restriction.

AĞAÇ SINIFLANDIRMASI (yeni `pl24-tree.ts`, tek kaynak):
Dört ayrı sezgisel vardı ve birbiriyle çelişiyordu:
- `linkWid.includes("group")` → p5psa `illusTable`, p5volvo/p5subaru
  `illustrationsTable` yakalanmıyordu → o seviye yaprak sanılıp parça olarak
  çekiliyor, partno'suz kayıtlar 0 parçaya dönüşüyor, panel sessizce boş
  kalıyordu (2026-06 isPsaParent olayının aynısı).
- case-sensitive `includes("/bomdetails")` → p5psa/p5volvo'nun camelCase
  `/details/vin/bomDetails` yaprakları grup sanılıyor, parçaları hiç prefetch
  edilmiyordu (bugün Mitsubishi %99,9 / Fiat %80 / Renault %70 bomDetails
  yaprağı 0 parça — aynı kök neden).
Artık `isPl24LeafNode`/`isPl24GroupNode` tek kaynak; categories.service (2 yer),
catalog.service (2 yer) ve prefetch-worker aynı fonksiyonu kullanıyor.

Test: yeni `pl24-tree.spec.ts` (7 test, canlı VW/PSA/Volvo/Subaru wid+path
çiftleriyle regresyon kilidi). Etkilenen paketler: 208 test geçti. tsc + biome temiz.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 14:00:30 +03:00
semih
3cfa3d588a feat(pl24): PL24 girişi 1 saat başarısızsa Telegram uyarısı
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
İki hesap banı da günler sonra, DB satır sayılarından fark edildi (tr 07-24 →
08-18'de, de 09-04 → 09-16'da). Üçüncüsünde bir saat içinde haber olsun.

- Yeni global `TelegramService` (aynı bot: TELEGRAM_BOT_TOKEN/TELEGRAM_CHAT_ID;
  yapılandırılmamışsa sessizce devre dışı, istek yolunu asla etkilemez).
- `PL24AuthService` kesinti saatini Redis'te tutuyor (`pl24:auth:fail-since:<hesap>`),
  böylece api+worker ve yeniden başlatmalar aynı başlangıcı görür — crash-loop
  saati sıfırlayamaz. Başarılı login saati siler.
- Kesinti 60 dakikayı geçince tek sefer uyarı (`pl24:auth:alerted:<hesap>` NX,
  6 saat) — hesap kodu, süre, son hata ve "banlanmış olabilir" notu ile.
  Düzelince sessiz "🟢 düzeldi" mesajı.
- Devre kesici açıkken de saat işler: kesici login denemesini bastırdığı için
  aksi halde hesap en ölü olduğu anda saat duruyordu.
- compose'a eksik env referansları: TELEGRAM_*, PL24_HTTP_DAILY_MAX,
  PL24_HTTP_USER_RESERVE, PREFETCH_PL24_FAST_DEPTH, PREFETCH_PL24_DELAY_MS
  (Coolify env'i ancak compose'da referanslıysa container'a ulaşıyor).

Test: 3 yeni test (1 saat dolmadan susar, dolunca tek sefer uyarır, düzelince
kurtarma mesajı + saat sıfırlanır). Redis stub'ı gerçek SET NX semantiğine
çekildi (alarm tekrarının bastırılması buna dayanıyor). 80 PL24 testi geçti.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 13:53:15 +03:00
semih
02ec3856d5 perf(pl24): reaktif drill derinliğini sınırla, backfill'i jitter'lı aralıkla yavaşlat
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Faz 1 / adım 2b (analiz: /home/s/ss/plv2.md, bulgu consumers_jobs-03).

SORUN: Ban'ı süren hacim backfill değil, her yeni decode'da çalışan fast-lane
TAM AĞAÇ drill'iydi. 2026-08-18→09-04 arasında (PL24_TR_DISABLED main lane'i
park etmişken) yeni kategorilerin %100'ü aynı gün decode edilen araçlardan
geldi: günde 3-17 decode → 1.4k-6.8k kategori (bir Passat 1.251, bir L200
2.323). Araç başına drill derinliği sınırsızdı ve PL24 istekleri arasında hiç
bekleme yoktu.

DEĞİŞİKLİK:
- `PREFETCH_PL24_FAST_DEPTH` (varsayılan 1): PL24 reaktif/fast lane yalnız üst
  gruplar + doğrudan çocuklarını gezer. Daha derini ya kullanıcı o düğümü
  açtığında (lazy) ya da bütçeli backfill lane'inde çekilir. Diğer kaynaklar ve
  PL24 main lane MAX_DEPTH kullanmaya devam eder. Fast lane'in derinlik tavanına
  ulaşması normal durum olduğu için log seviyesi warn değil log.
- `PREFETCH_PL24_DELAY_MS` (varsayılan 8000) + ±%50 jitter: PL24 BACKFILL
  işlerine per-job bekleme. Kullanıcının fast lane'i asla yavaşlatılmaz.
  Metronom gibi düzenli akış otomasyon imzasıdır; jitter onu kırar.
- Telemetri düzeltmesi: `proxy_logs`'a ham hesap etiketi ("tr") yerine gerçekte
  kullanılan hesap yazılıyor (PL24_TR_DISABLED altında "de"). Yeni
  `PL24AuthService.activeAccount()`.

Test: `__testables` ile maxDepthFor/jitter dışa açıldı + derinlik tavanı testi.
Etkilenen paketler: 198 test geçti. tsc + biome temiz.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 13:44:59 +03:00
2add2b253a Merge pull request 'feat(pl24): günlük HTTP bütçesi, kullanıcı rezervi ve proxy_logs telemetrisi' (#262) from dev into main 2026-09-17 13:37:50 +03:00
semih
56a8ea09be feat(pl24): günlük HTTP bütçesi, kullanıcı rezervi ve proxy_logs telemetrisi
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Faz 1 / adım 2 (analiz: /home/s/ss/plv2.md, bulgular consumers_jobs-03/06/07,
deploy_ops-13).

SORUN: İki PL24 hesap banı da günde 5-7 bin kategori yazan (≈10 bin+ istek)
otomatik drill dalgalarının ardından geldi; gerçek kullanıcı decode'u ≤14/gün.
Mevcut korumaların hepsi iş-seviyesinde (iş/dk, iş/gün) — HTTP isteği sayan
hiçbir tavan yoktu. Üstelik PL24 çağrıları `proxy_logs`'a hiç yazılmıyordu
(yalnız pcat/emex), bu yüzden hacim ancak ban'dan SONRA, DB satır sayılarından
geriye dönük çıkarılabildi. Kill switch de yalnız decodeVin'i kapatıyordu; drill,
backfill ve katalog gezinmesi "kapalı" kaynağa istek atmaya devam ediyordu.

DEĞİŞİKLİK:
- Yeni `PL24BudgetService`: tüm PL24 upstream trafiği için tek geçit.
  - Günlük sayaç `pl24:http:<gün>` (Redis, 8 gün TTL); tavan `PL24_HTTP_DAILY_MAX`
    (varsayılan 1200).
  - Kullanıcı rezervi `PL24_HTTP_USER_RESERVE` (varsayılan %40): backfill tavanın
    %60'ında durur, kullanıcı decode'u sonuna kadar akar — kaçak bir backfill
    müşteriyi asla aç bırakamaz. Lane ayrımı mevcut `isBackfillContext()` ile.
  - Reddedilen çağrı ağa hiç çıkmaz ve telemetriye yazılmaz.
  - Redis düşerse fail-open (auth/katalog telemetri yüzünden bloklanmaz).
- Telemetri: `ProxyServiceLeg` += `pl24_http`, `pl24_auth`. Login, authorize ve
  tüm katalog fetch'leri `proxy_logs`'a yazıyor (provider dataimpulse/none,
  sessionKey=hesap, status, süre, 403/429 → banned, taşıma hatası sınıflandırma).
  Artık "hangi gün kaç istek attık, ilk 401/403 ne zaman başladı" sorusu
  ban'dan ÖNCE yanıtlanabilir.
- Kill switch yayıldı: `kill-source-pl24` artık `budgetedFetch` içinde, yani
  decode + drill + backfill + browse + görsel indirme dahil TÜM katalog trafiğini
  kapatıyor (eskiden yalnız decodeVin).
- `fetchWithRetry` 401 çaresi netleşti: yalnız servis token'ı tazelenir; oturumun
  kendisi gerekirse auth katmanında düşürülür.

Test: yeni `pl24-budget.service.spec.ts` (9 test: tavan, kullanıcı rezervi,
reddedilen çağrının ağa çıkmaması, Redis fail-open, telemetri biçimi/leg ayrımı,
ban sinyali, taşıma hatası sınıflandırma). Etkilenen paketler: 197 test geçti.
tsc + biome temiz.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 13:13:05 +03:00
62ad9ac318 Merge pull request 'refactor(pl24): oturum modeli — tek login, çerez tabanlı authorize yenileme' (#261) from dev into main 2026-09-17 13:01:27 +03:00
semih
e50a907931 refactor(pl24): oturum modeli — tek login, çerez tabanlı authorize yenileme
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Faz 1 / adım 1 (analiz: /home/s/ss/plv2.md §4.1, bulgular auth-02/03/05/06/09/11/15,
p4legacy-07, consumers-04).

SORUN: PL24'ün base JWT'si 600 saniye yaşıyor ve kod bunu "oturum" sayıyordu
(isTokenValid → login). Talep varsa her ~9 dakikada bir squeezeOut:true ile
YENİDEN LOGIN atılıyordu (günde ~144 login/hesap). PL24 hesap başına tek oturum
veriyor; bu desen hem kendi oturumumuzu sürekli düşürüyor hem de iki hesap
banından önceki otomasyon imzasını oluşturuyordu. Portalın kendisi bir kez login
olup PL24TOKEN çerezini saklıyor ve yalnız authorize'ı yeniliyor.

DEĞİŞİKLİK:
- Oturum = PL24TOKEN çerezi (süresiz). `ensureSession()` sahibi; bellekte tutulur,
  Redis'te `pl24:auth:session:<hesap>` ile 24 saat paylaşılır (api/worker aynı
  oturumu devralır). Süre kontrolü YOK — oturum yalnız sunucu reddederse düşer.
- Servis token'ı = authorize ile mint edilen 600 s'lik JWT; yalnız `Cookie:
  PL24TOKEN` ile istenir (Bearer gerekmiyor — canlı doğrulandı).
- `session_status:"gone"` ve authorize 401/403 artık okunuyor: oturum düşürülür,
  tek sefer yeniden login + retry.
- Single-flight: süreç içi in-flight promise + Redis kilidi
  (`pl24:auth:login-lock:<hesap>`), kilidi alamayan paylaşılan oturumu bekler.
  Eski prewarm iki paralel login atıyordu ve biri her boot'ta HTTP 500 alıyordu.
- Login sözleşmesi: portal ucu `/auth/ext/api/1.1/login`
  ({account,user,password,squeezeOut} → {loginStatus,sessionToken} + Set-Cookie);
  RFC7807 problem gövdesi tiplendi. Önce squeezeOut:false denenir, yalnız
  "session-limit-exceeded"/USER_ALREADY_LOGGED_IN'de squeezeOut:true ile tekrar.
  `PL24_LOGIN_API=legacy` eski uca döner (bir sürüm geri çekilme bayrağı).
- Hata sınıflandırma: account-not-active / user-not-active / authentication /
  2FA-required → ilk hatada 6 saatlik devre kesici (eskiden ölü hesap 5 dakikada
  bir sonsuza dek deneniyordu: prod'da 376 ardışık 401). Ağ/timeout → 5 dakika.
- Saatlik login tavanı (hesap başına 6) — sağlıklı günde 0-1 login beklenir.
- P4 (.action) sayfaları için authorize kaldırıldı: yalnız çerez gönderiliyor
  (canlı doğrulandı). Ford/PSA'daki 18 "ısıtma" authorize çağrısı ensureSession'a
  indirildi; demo-sayfa/401 çaresi artık servis token temizleme değil oturum
  yenileme.
- Gerçek Chrome User-Agent sabiti (eski değer hiçbir tarayıcıda yok).
- authorize'a `pl24-wmidata` eklendi (portal WMI decode'u için ön hazırlık).
- Ölü kod silindi: getAccessToken*/getSessionCookie* base-JWT yolu, hasService,
  getAvailableServices, AUTH_TOKEN_TTL.

Test: pl24-auth.service.spec.ts yeniden yazıldı (19 test: tek login, single-flight,
Redis devralma, cookie-only authorize, gone/401 yeniden login, 412 squeezeOut,
P4 cookie-only header, kalıcı hata kesicisi, saatlik tavan). Tüm PL24 + tüketici
paketleri: 188 test geçti. tsc + biome temiz.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 00:59:36 +03:00
ca18749ec5 Merge pull request 'chore(prefetch): PL24 günlük backfill tavanını env ile ayarlanabilir yap' (#260) from dev into main 2026-09-17 00:44:47 +03:00
semih
330015fbb6 chore(prefetch): PL24 günlük backfill tavanını env'den ayarlanabilir yap
SOURCE_DAILY_MAX.pl24 zaten PREFETCH_DAILY_PL24'ü okuyor
(prefetch-worker.service.ts:156) ama compose'da hiç ${...} referansı
olmadığı için Coolify env'i container'a ulaşmıyordu; tavan 15.000'de
kilitliydi.

PL24 hesap banları (tr 07-24, de 09-04) günde 5-7 bin kategori üreten
otomatik drill dalgalarının ardından geldi. Yeni hesaba geçerken
(de-025446) backfill'in güvenli bir günlük tavanla çalışması gerekiyor.

Coolify env: PREFETCH_DAILY_PL24=600 (main lane payı %80 = 480 iş/gün),
PREFETCH_PL24_START=9 / PREFETCH_PL24_END=18 (Europe/Istanbul insan
saatleri), PREFETCH_RATE_PL24=6 (main 4/dk, fast 2/dk).

Analiz: /home/s/ss/plv2.md

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 20:55:56 +03:00
24f7e7aa5b Merge pull request 'fix(pl24): tr hesabı kapalıyken de köprüsü (PL24_TR_DISABLED) + login devre kesici' (#259) from dev into main 2026-08-18 18:02:43 +03:00
5d9da95830 fix(pl24): tr hesabı kapalıyken de köprüsü (PL24_TR_DISABLED) + login devre kesici
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
- tr-903645 PL24 tarafında pasif (07-24, "The account is not active"): flag
  açıkken tüm tr auth/proxy/egress şeffaf biçimde de-708171'e maplenir
  (PSA dahil — legacy authorizeService yolu tr'ye hardcode'du)
- PSA fetch'lerine dispatcher eklendi: de oturumu DE proxy'den çıkar
- resolveAccount flag altında herkese de döner (fetch/cache/etiket tutarlı)
- login devre kesici: 3 ardışık hata → 5 dk soğuma (haftalardır süren
  ~6 boş login/dk fırtınasını bitirir)
- prefetch: flag açıkken pl24 backfill üretimi durur + kuyruktaki pl24
  main-lane işleri 15 dk defer'la park edilir (fast/user lane akmaya devam
  eder) — hayatta kalan tek hesabı arka plan yükü yakmasın
- compose: PL24_TR_DISABLED env injection (api+worker)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-18 14:47:53 +03:00
1e3f37f71e Merge pull request 'fix(billing): dunning kurtarma zinciri (migration 0035 + webhook + banner)' (#258) from dev into main 2026-08-18 13:07:15 +03:00
181bdbe971 fix(billing): dunning kurtarma zinciri (migration 0035 + webhook + banner)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Stripe gerçeği: 3 abonelik past_due (3×₺999 = brüt MRR'ın ~%27'si), 1 abonelik
dün dunning'den iptal (tugem, ₺999 kayıp); kurtarma tarihsel %0. Kök nedenler:
(1) dunning e-postasının CTA'sı ödeme imkânı olmayan /dashboard/subscription'a
gidiyordu, (2) kart güncelleme yüzeyi hiç yok + yeniden checkout 'Zaten aktif
aboneliğiniz var' ile bloklu, (3) app past_due'yu hiç bilmiyordu (DB state yok,
banner yok), (4) subscription.deleted no-op'tu (churn görünmez + status active
kaldığı için re-subscribe kalıcı bloklu).

- migration 0035: user_subscriptions.dunning_since + dunning_invoice_url
- handleInvoiceFailed: dunning state persist + e-posta CTA'sı Stripe hosted
  invoice sayfasına (öde/yeni kart/3DS) + milestone e-posta (1./3./final —
  deneme başına aynı mail spam'i bitti) + attempt_count PostHog'a
- handleInvoicePaid: her iki dalda dunning temizliği
- handleSubscriptionDeleted: status→cancelled (re-subscribe deblke),
  subscription_churned PostHog event'i (reason: payment_failure/cancelled)
- web: DunningBanner (kapatılamaz, kırmızı; CTA hosted invoice) dashboard'da
- spec: yeni davranışa güncellendi + milestone/final testleri (14/14)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-11 11:10:44 +03:00
c12b2992f9 Merge pull request 'fix(analytics): CSP Google Ads tag + conversion domainleri (ASIL conversion bugu)' (#256) from dev into main 2026-08-04 16:54:36 +03:00
57d16b9aea fix(analytics): CSP'ye kalan enhanced-conversion endpoint'lerini ekle
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Dev testinde ana conversion ping'i (googleadservices/pagead/conversion) geçti
ama ad.doubleclick.net (ccm/collect enhanced) + google.com.tr (TR yerelleştirilmiş
1p-conversion) hâlâ bloklanıyordu. img-src/connect-src'e eklendi.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-04 16:53:48 +03:00
eb277cd55a fix(analytics): CSP'ye Google Ads tag + conversion domain'lerini ekle
CSP script-src googletagmanager.com İÇERMİYORDU → gtag.js hiç yüklenmiyordu →
gtag config/conversion event'i çalışmıyor, _gcl_aw linker cookie set olmuyor,
conversion ping'i Google'a hiç gitmiyor → haftalardır panelde 0 dönüşüm (doğru
AW id + label + kanonik gtag'e rağmen). ASIL bloker buydu — gtag shim (6c936d5)
+ OAuth (685c6af) fix'leri gerekliydi ama tek başına yetmezdi.
- script-src += www.googletagmanager.com
- img-src/connect-src += google.com, googleadservices.com, googleads.g.doubleclick.net
Meta Pixel worker-src ve Sentry ingest ile aynı sınıf CSP-blocking bug.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-04 16:47:22 +03:00
8346a1db8e Merge pull request 'perf(prefetch): pcat gunluk butce 30k->45k' (#255) from dev into main 2026-08-01 14:32:44 +03:00
2df73e6a48 perf(prefetch): pcat günlük bütçe 30k→45k (main lane 36k, fast lane 9k rezerv)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Gate fix (PR#254) prod'da doğrulandı: pressure=56 (eskiden backlog=11495),
bütçesi dolan kaynak eligible'dan düşüyor — runaway guard'ları canlı. Bütçenin
kalan tek riski bant genişliği maliyeti.

45k gerekçesi: guard'ı doğuran 2026-07-09 olayı ~74k çağrı/~10 GB idi; 45k onun
%61'i (~6 GB/gün). DAILY_FAST_RESERVE ile backfill main lane 36k alır = eski
efektif 30k'ya göre +%20, kullanıcıya 9k rezerv kalır. Burst hızı DEĞİŞMİYOR
(pcat 90/dk) → per-IP ban baskısı aynı, sadece tempo günün daha uzun bölümünde
sürüyor. Rollback: bir saatte >2 pcat HTTP 402 → 30_000'e dön.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-01 14:32:42 +03:00
c21472d930 Merge pull request 'fix(prefetch): Phase-2 kilidini ac (pressure/total gate) + tamamlanma muhasebesi' (#254) from dev into main 2026-08-01 14:22:23 +03:00
3597b03c4f fix(prefetch): Phase-2 kilidini aç (pressure vs total gate) + tamamlanma muhasebesi
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Sorun (2026-08-01): wait=0/active=0 iken scan backlog=11495 hesaplıyordu — hepsi
günlük-bütçe ile ertesi gün 00:00'a park edilmiş pcat job'ı. backlog>maxBacklog
olduğu için Phase-2 günün çoğunda askıdaydı; 2143 kısmi araç ilerlemiyordu.

Adversarial analiz kritik uyarı verdi: delayed'ı gate'ten çıkarmak TEK BAŞINA
470k runaway'i tekrarlar (üretim ~288k job/gün vs bütçe 65k/gün; bütçe-defer'leri
skipAttempt ile attempts tüketmediğinden asla düşmez). Bu yüzden üretim kaynağında
kesiliyor + ikinci tavan ekleniyor:

- Gate ikiye ayrıldı: pressure (waiting+active+10dk içinde vadesi gelen delayed,
  HER İKİ kuyruk) vs maxBacklog; total (tüm bekleyen) vs HARD_MAX_TOTAL_JOBS=50k.
  zcount BullMQ delayed ZSET score'u (dueMs*4096+seq) ile; hata halinde fail-CLOSED.
- ÜRETİMİ KES: scan, günlük main-lane bütçesi dolmuş kaynağı eligible'dan düşürür.
- Admission control JOB cinsinden (EST_JOBS_PER_VEHICLE=400), araç cinsinden değil.
- Günlük bütçe lane-aware (fast lane'e %20 rezerv) + READ-then-INCR (sayaç artık
  defer'lerle şişmiyor; 48531 vs 30000 gözlemi) + 45dk jitter (thundering herd).
- KÖK NEDEN: addJob artık boolean, queueCategoryJob sayı döndürüyor; progress.total
  yalnız GERÇEKTEN kuyruğa giren job'ı sayıyor. Şişmiş total zinciri asla
  "finished"a ulaştırmıyordu → araç fullyFetched işaretlenmiyor → scan sonsuza dek
  yeniden seçiyordu (~25/gün platosu). processInit queued===0 ise finalizeVehicle.
- prefetch:scheduled:<id> ÇAKIŞMASI: backfill artık :backfill: namespace'i yazıyor;
  eski 6h TTL kullanıcının fresh-decode fast-lane init'ini sessizce atlatıyordu.
  TTL 6h→36h (bütçe-park edilmiş zincir ~24h yaşıyor).
- Phase-2 artık kalıcı vehicles.fullyFetched'i hedefliyor (efemeral marker değil).
- CATEGORY_CAP DB'den ölçülüyor (her processInit'te sıfırlanan sayaçtan değil).

537 test geçti. Bütçe artışı (PREFETCH_DAILY_PCAT) BU PR'da DEĞİL — ayrı adım.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-01 14:21:44 +03:00
2cda50f9af Merge pull request 'fix(analytics): gtag shim kanonik arguments push' (#253) from dev into main 2026-08-01 10:09:43 +03:00
6c936d546b fix(analytics): gtag shim kanonik arguments push — tüm conversion takibi kırıktı
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
initGoogleAds gtag shim'i array push ediyordu ((...args) => dataLayer.push(args));
gtag.js komut olarak sadece `arguments` nesnesini işler, array'i inert dataLayer
verisi sayar → config/event HİÇ çalışmıyordu → _gcl_aw linker cookie'si set
olmuyor, conversion ping'i Google'a gitmiyor, panelde 14 günde 0 dönüşüm (email
kayıtları dahil — sadece OAuth değil). Google'ın kanonik snippet formuna
(function gtag(){dataLayer.push(arguments)}) döndürüldü. OAuth post-auth fix'iyle
(685c6af) birlikte email+OAuth tüm kayıtlar artık ateşler + doğru atfeder.
Doğrulama: headless test gtag'i teyit edemez (Google bot-baskılaması); kesin
kanıt gerçek tarayıcıda kaydın panele düşmesi.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-01 10:09:28 +03:00
bf0cc4e96c Merge pull request 'fix(analytics): OAuth Google Ads sign-up conversion' (#252) from dev into main 2026-08-01 09:16:41 +03:00
685c6af3ed fix(analytics): OAuth kayıtlarında Google Ads sign-up conversion'ı ateşle
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Conversion sadece register.tsx email path'inde ateşleniyordu; Google OAuth
signup'lar (register + login Google butonu) hiç ateşlemiyordu → ölçüm: paid-
kaynaklı kayıtların ~%79'u OAuth, Google Ads'e görünmüyordu, Max Conversions
sinyalsiz optimize ediyordu. Evrensel post-auth bileşeni (google-ads-signup-
conversion.tsx, __root'a mount) yeni kullanıcıda (createdAt < 30dk) conversion'ı
bir kez ateşler; transaction_id signup_<userId> Google tarafında dedup eder,
register.tsx guard'ı email path'in çift-ateşini önler. _gcl_aw cookie OAuth
roundtrip'inde korunduğu için atıf doğru. Playwright 6/6.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-01 09:16:20 +03:00
95818b2501 Merge pull request 'feat(growth): B2B segment kapısı + funnel-bucket A/B (Kova B)' (#251) from dev into main 2026-07-29 11:03:48 +03:00
55b4cd38e9 feat(growth): B2B segment kapısı + funnel-bucket A/B deneyi (Kova B)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Fix (herkes, flag'siz): evrensel post-auth segment kapısı (segment-gate.tsx).
Kayıtların ~%41'i segmentsizdi çünkü login.tsx Google OAuth segment adımını
atlıyordu. Yeni kullanıcıya zorunlu (açığı kapatır), mevcut segmentsize
7g-cooldown'lu yumuşak prompt (~538 backfill). Segment localStorage +
PostHog person prop (b2b_segment); backend persist faz 2.

Kova B (funnel-bucket flag, b2b_qualified): trial-value-upsell'e segmente-özel
Meta-kanıtlı kopya (iade / yanlış-parça / sınırsız-şase). Flag SADECE banner
görünürken okunur → deney maruziyeti = gerçekten gören aktif trial'lar.
vehicle_owner / bilinmeyen segment → nötr control kopya (ürün kararı).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-27 17:26:19 +03:00
c0045fa372 Merge pull request 'feat(prefetch): kalici vehicles.fully_fetched kolonu (migration 0034)' (#250) from dev into main 2026-07-25 10:44:19 +03:00
6610bdf720 feat(prefetch): kalıcı vehicles.fully_fetched kolonu (güvenilir tamlık ölçümü)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Redis prefetch:complete:* 21g TTL'li → "% tam çekilmiş"i güvenilir ölçemiyorduk.
Migration 0034: vehicles'a fully_fetched (bool, default false) + fully_fetched_at
(ts) + index. incrementCompleted chain parça ile bitince kalıcı flag'i set eder
(Redis marker'a EK — operasyonel skip mantığı değişmedi). fully_fetched_at her
re-drill tamamlanışında güncellenir (son-doğrulanma). Idempotent SQL.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-25 10:40:40 +03:00
8c1ee15fac Merge pull request 'perf(prefetch): backfill günlük bütçe (storm guard)' (#249) from dev into main 2026-07-16 13:32:47 +03:00
ed8a6ce6e9 perf(prefetch): backfill'e per-source günlük bütçe (storm guard)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Per-dakika rate cap'i (pcat 90/dk) burst'ü sınırlıyor ama günlük TOPLAM'ı değil —
bir kaynak saatlerce tavanda çalışıp proxy bütçesini boşaltabiliyor (2026-07-09:
backlog drain pcat'i ~74k çağrı / ~10 GB'a çıkardı). SOURCE_DAILY_MAX eklendi:
UTC-gün fixed-window Redis sayacı; kaynak günlük bütçeyi aşınca backfill job'ları
pencere dönene kadar ertelenir. Kullanıcı decode'ları etkilenmez (worker'dan
geçmiyor). Dakikalık gate'ten SONRA sayılır → rate-limitli retry'lar şişirmez.

Default (env-tunable): pcat 30k, emex 20k, pl24 15k/gün. Backlog drain'i
hızlandırmak için yükselt, bütçeyi daha çok korumak için düşür.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 13:32:34 +03:00
8a4dd6e10e Merge pull request 'chore(proxy): DataImpulse birincil, Floxy default kaldır' (#248) from dev into main 2026-07-16 13:04:30 +03:00
bf834b8f41 chore(proxy): DataImpulse'i birincil yap, Floxy default'unu kaldır
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Floxy kalıcı olarak devre dışı (bakiye/tünel ölü — pcat+emex loglarında sürekli
"Floxy unhealthy → DataImpulse failover"). Floxy-primary her çağrıda önce bir
başarısız deneme yakıp sonra failover ediyordu. DataImpulse zaten kanıtlanmış
çalışıyor (call-leg %97,6).

PCAT_PROXY_PROVIDER ve EMEX_PROXY_PROVIDER default'ları floxy→dataimpulse
(pcat auth + emex browser + emex HTTP ayağı). Floxy hâlâ env ile seçilebilir
(PCAT_PROXY_PROVIDER=floxy / EMEX_PROXY_PROVIDER=floxy); failover makinesi
dormant kalıyor.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 13:04:15 +03:00
bd134bba06 Merge pull request 'perf(pcat): capture widget asset cache — ~%90 capture bant genişliği' (#247) from dev into main 2026-07-16 12:52:59 +03:00
7fd486855f perf(pcat): capture'da widget asset'lerini cache'le — ~%90 capture bant genişliği
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Her JWT capture yeni context (boş cache) açıp aynı widget JS/CSS'ini residential
proxy'den yeniden indiriyordu — ölçüldü ~2,2 MB/capture, %93'ü static (en büyüğü
tüm sitelerde ORTAK `.../v3/bundle_<hash>.js`, 603 KB). ~3-4k capture/gün ile bu
en büyük kaçınılabilir proxy maliyeti (~20 GB/15g), sıfır ban riski.

URL-anahtarlı, disk-destekli (hot in-memory + best-effort disk) cache eklendi.
Sadece versiyonlu static JS/CSS cache'lenir (hash/`?_=` → invalidation otomatik);
token XHR (/v3/api/proxy/*) ve HTML document HER ZAMAN canlı geçer. HIT'te sıfır
proxy byte'ı; MISS'te bir kez route.fetch (context proxy'sinden) + sakla + servis.
PCAT_ASSET_CACHE=false ile redeploysuz kapatılabilir (kill switch).

Doğrulama (autotrade.md + e-trak.ru, gerçek yükleme, 2 ardışık capture):
warm capture canlı trafiği %89-91 düştü VE token XHR ikisinde de atıldı — yani
cache'ten JS servisi widget'ı bozmuyor (geçen capture-blocking olayının tersi).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 12:47:10 +03:00
8d07d9a31a Merge pull request 'fix(vinpin): blank Dialogys header retries instead of definitive not_found' (#246) from dev into main 2026-07-16 07:59:39 +03:00
fdbaaf375f fix(vinpin): blank Dialogys header → ambiguous (retry), not definitive not_found
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
A blank header region means the Dialogys vehicle result never rendered (transient/
slow), NOT a genuine miss — a decodable Renault (Megane) read "" here and was wrongly
returned not_found (made definitive by the Rpartstore-down gate). Return ambiguous so
the caller's cheap in-session reset retries; a real empty-form miss just exhausts the
bounded retries. A NON-empty unparseable header (old R19's garbled parts screen) stays
a fast definitive not_found.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 07:59:32 +03:00
ebbdb22e33 Merge pull request 'chore(compose): VINPIN_RPARTSTORE_ENABLED env ref' (#245) from dev into main 2026-07-16 07:41:23 +03:00
8e4581f1b5 chore(compose): add VINPIN_RPARTSTORE_ENABLED env ref (api+worker)
So the flag reaches the container (Coolify only injects compose-referenced ${VAR}).
Default true = unchanged; set false during a Rpartstore outage.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 07:41:16 +03:00
679664d7b0 Merge pull request 'feat(vinpin): VINPIN_RPARTSTORE_ENABLED flag — skip Rpartstore during outage (+pcat capture fix)' (#244) from dev into main 2026-07-16 07:39:43 +03:00
c3ea03db03 feat(vinpin): VINPIN_RPARTSTORE_ENABLED flag skips Rpartstore during known outage
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Rpartstore is DOWN upstream. Every Renault decode still tried to OPEN it
first → launch-error, stuck "Loading application..." app (dirty-resume for
the next decode), ~30-50s burned, and the in-memory down-cooldown resets on
every worker restart so the first decode after each restart repaid the full
cost. That overhead pushed decodes over VINPIN_DECODE_BUDGET_MS → budget
abort → sessionPoisoned → cascade.

Add a persistent kill-switch: VINPIN_RPARTSTORE_ENABLED=false makes BOTH
Renault paths (warm warmRenaultDecode + cold runRenaultFlow) skip opening
Rpartstore entirely and route straight to Dialogys — mirroring the existing
rpartstoreInCooldown() skip but surviving worker restarts. Flag-disabled is
treated as "Rpartstore unavailable" exactly like cooldown, so primaryRan
stays false and a clean Dialogys not_found is definitive (no retry thrash).
Also gated the _warmUp Rpartstore-open so a future warm session with the
flag off pays no launch cost / leaves no stray app.

DEFAULT true (only the exact string "false" disables) → behaviour with the
flag unset is completely unchanged. tsc clean; vinpin unit tests green
(+3 flag tests: warm/cold skip + Dialogys-definitive, and default-true still
attempts Rpartstore).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 07:36:20 +03:00
7ec4fb9297 Merge pull request 'fix(pcat): capture route'unu bilinen-iyi'ye döndür — prod token capture kurtar' (#243) from dev into main
Reviewed-on: #243
2026-07-16 07:00:24 +03:00
6df9c18efb fix(pcat): capture route'unu bilinen-iyi'ye döndür — prod token capture kurtar
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
0f2126d'deki agresif capture blocking (stylesheet + yastatic/google-font/ad
domain'leri) prod'da token capture'ı öldürdü: dataimpulse ile 425→0 capture/
saat, tam deploy anında (03:40 UTC), hepsi capture_timeout. RU katalog widget'ı
init olup /v3/api/proxy XHR'ını atmak için CSS'ine ve Yandex-hosted runtime'ına
ihtiyaç duyuyor. Aynı deploy'da emex (HTML-scrape, widget yok) aynı dataimpulse
üzerinden sağlıklı kaldı → sorun pcat-capture'a özgü.

pcat capture blocking'i orijinaline döndürüldü (image/font/media + tracker'lar)
— resim engellemesi zaten çalışıyordu, korunur. Emex blocking (kanıtlanmış
güvenli) ve ipify gate (PCAT_EXIT_IP_PROBE, kapalı) korunur.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 06:56:09 +03:00
f42f1888ae Merge pull request 'perf(proxy): capture/scrape browser'larında bant genişliği israfını kes' (#242) from dev into main
Reviewed-on: #242
2026-07-16 06:39:49 +03:00
0f2126d694 perf(proxy): capture/scrape browser'larında bant genişliği israfını kes
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
DataImpulse residential kotası hızlı tükeniyordu (15 günde 58.5 GB). CSV
analizi capture/scrape tarayıcılarının tam sayfa (resim/font/CSS/reklam/
CDN) yüklediğini gösterdi.

- pcat + emex capture: resource-blocking'e stylesheet + üçüncü-parti çöp
  (yastatic, google fonts/autofill, adsco.re, displayvertising, tidio,
  ipify) eklendi. Widget runtime CDN'leri (jsdelivr/unpkg) bilinçli hariç.
- emex: engelleme context seviyesine alındı → tüm tab'ları kapsıyor.
- pcat: ipify exit-IP probe artık PCAT_EXIT_IP_PROBE ile default-off
  (15 günde ~54k faturalı istek + 352 MB, sadece telemetri içindi).

Not: emex scraping resmi tarayıcıda yüklemiyor; URL'yi HTML'den parse edip
boyutu ayrı Range GET ile alıyor → resim engellemek scraping'i etkilemez.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 18:25:51 +03:00
3248ab1c3a Merge pull request 'test(shared): fix normalizeName hyphen test to correct tr-TR output' (#241) from dev into main 2026-07-15 16:55:43 +03:00
a6437dcd67 test(shared): correct normalizeName hyphen test expectation to tr-TR output
The failing test expected normalizeName("ANNA-MARIA")=="Anna-Maria" (dotted i),
but that is internally inconsistent with the suite's own Turkish tests that REQUIRE
the deliberate tr-TR locale: "ALİ YILMAZ"→"Ali Yılmaz" (dotless ı) and "ÇAĞRI"→
"Çağrı". Uppercase Latin "I" (U+0049) is the SAME codepoint as Turkish dotless-I,
so tr-TR lowercases it to "ı" — correct for a TR product (invariant casing would
break every Turkish name: Yilmaz/Çağri, and mangle İ→i̇ with a combining dot). Not
a code bug; expectation corrected to "Anna-Marıa" with an explanatory comment.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 16:55:35 +03:00
544b3f25d1 Merge pull request 'fix(vinpin): Rpartstore-down definitive not_found (no budget-burn+poison) + old-Renault tokens + year-cycle' (#240) from dev into main 2026-07-15 15:50:02 +03:00
cc543ace21 fix(vinpin): poll Dialogys header before a definitive not_found (fixA follow-up)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
FIX A made a CLEAN Dialogys not_found definitive on its own while Rpartstore is
down (no retry). But runDialogysSearch inferred not_found from a SINGLE OCR
sample taken after a blind fixed wait — a slow render or a transient OCR glitch
on a DECODABLE Renault read empty at t=afterDialogysSubmit and was mislabelled
not_found, and under FIX A that miss is now terminal (decodeRenaultLocked
returns null, no cheap retry).

Replace the blind wait + single sample with a poll (pollForState) over the
header region for a decodable render, capped at afterDialogysSubmit — mirrors
runRpartstore's poll-then-decide shape. Multi-samples across the same window and
returns early on a hit, so a slow render/OCR glitch no longer produces a false
not_found. Cap unchanged, so a genuine miss consumes no more time than before:
FIX A's no-budget-burn / no-seat-poison guarantee and the definitive-not_found
semantics both hold, and the full-frame fallback is preserved. Working Renault
decodes only get faster (early return). tsc clean; vinpin (119) + extractModelYear
(12) green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 15:48:44 +03:00
c03e7f4079 fix(vinpin): stop budget-burn + seat-poison on undecodable Renault when Rpartstore down
FIX A (runRenaultFlow): when Rpartstore is UNAVAILABLE (down-cooldown or it
never loaded, so `primary` is only a placeholder ambiguous), a CLEAN Dialogys
not_found is now DEFINITIVE. The old gate required BOTH catalogs to say
not_found, so every undecodable Renault while Rpartstore was down got
downgraded to ambiguous → 3x retry → 180s budget → sessionPoisoned, which
then degraded later decodes. A genuinely-ambiguous Dialogys (unreachable)
still retries. When Rpartstore actually ran, both-must-agree is preserved.
runDialogysSearch now logs its outcome + truncated OCR header so this class
is diagnosable from prod logs.

FIX B (vinpin.constants): add old R-number + TR-badge Renault model tokens
(R5/R9/R11/R12/R19/R21/R25, Europa/Broadway/Toros/Flash). R-prefixed form
only — no bare numerics that could false-match year/engine digits.

FIX C (vin-validator extractModelYear): the position-10 year code repeats every
30 years ("T" = 1996 or 2026) with no clean VIN-only rule. New optional
{modelResolved:false} signal: for a brand-only decode of an old-shaped Renault
VIN (Renault WMI + numeric-led VDS type code) whose code pins to the current
cycle's leading edge, roll back one 30-year cycle so a ~1996 R19 isn't labelled
2026. Narrow: model-resolved or modern-shaped VINs are unchanged. Corgi's
WMI-only decoder wired to pass modelResolved:false.

Keeps never-throw / VINPIN_DECODE_BUDGET_MS / sessionPoisoned semantics and the
Fiat + working Renault paths intact. tsc clean; vinpin + corgi + extractModelYear
tests green (new tests cover A and C).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 15:39:26 +03:00
41f2f1777f Merge pull request 'fix(vinpin): warm Fiat window-fault cold fallback' (#239) from dev into main 2026-07-15 13:56:47 +03:00
d7d78a77a6 fix(vinpin): warm Fiat window-fault falls back to cold (not throw→null)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
The last gap: when ensureWarmWindow('fiat') can't bring the Fiat ePER to its VIN
panel (partial Rpartstore-down session leaves it off-panel + re-nav can't recover),
warmDecode threw SessionDropped → re-warm → null, turning a DECODABLE Fiat VIN into
a not_found. Fall back to the proven cold Fiat path instead, so a warm-window fault
never loses a real decode. Completes the FIX2 cold-fallback (previously only the
unusable-parse branch had it; now the can't-reach-panel branch does too).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 13:56:40 +03:00
5a79e94df3 Merge pull request 'fix(vinpin): warm on Fiat+Dialogys anchor (no starvation)' (#238) from dev into main 2026-07-15 13:42:39 +03:00
dac0708cda fix(vinpin): claim warm on Fiat+Dialogys anchor (not full 3-window)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
The full 3-window gate never warmed during a prolonged Rpartstore outage, so the
daemon re-attempted warm-up every backoff cycle — each ~2min attempt holds the
single-seat mutex and STARVES real decodes. Anchor warm on Fiat ePER + Dialogys
(the two windows that serve both brands; the Rpartstore-down cooldown routes
Renault to Dialogys anyway, so Rpartstore is an optional bonus). Warm is then
claimed once and HELD (no re-warm loop → no starvation); the Поиск-token foreground
fix makes warm Fiat raise the correct window. Rpartstore rejoins on recovery.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 13:42:31 +03:00
5628cbceaf Merge pull request 'fix(vinpin): claim warm only on full 3-window session' (#237) from dev into main 2026-07-15 13:25:46 +03:00
aa798ec03d fix(vinpin): claim warm ONLY on a full 3-window session (Fiat+Rpartstore+Dialogys)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
A partial warm session (e.g. Rpartstore DOWN → only Fiat+Dialogys) is proven
unstable: re-warm cycles + the missing catalog's launch-error keep knocking the
Fiat window off its VIN panel, so warm Fiat decodes thrash to the 180s budget →
not_found. Require all three windows before this.warm=true; otherwise stay on the
reliable cold path (which decodes Fiat/Renault + cross-brand cleanly). The daemon
backs off + retries, so warm auto-resumes once Rpartstore recovers.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 13:25:39 +03:00
0011c80ec3 Merge pull request 'fix(vinpin): warm-Fiat decode (Поиск false-match + silent-null cold-fallback + strict not-found)' (#236) from dev into main 2026-07-15 13:03:30 +03:00
46f0210ba6 fix(vinpin): strict not-found for warm-Fiat full-frame garble check
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Review finding: warmDecode's genuine-not-found decision used VINPIN_OCR.notFound
(/…|Catalogue/i) against the FULL frame, where the 'Spare Parts Catalogue' header
always matches → every on-panel garble was flagged a genuine miss and null'd out
instead of falling back to the cold retry. Add notFoundStrict (no Catalogue token)
for the full-frame check so a transient on-panel garble (VIN exists) recovers via
the cold path; keep notFound for the runVinFlow modal-region settle poll.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 13:03:23 +03:00
31aabfc28f fix(vinpin): warm-path Fiat silent not_found (wrong-window raise + silent null)
When the warm daemon is up and Rpartstore is DOWN, a partial-warm session
(Fiat opened, Rpartstore launch-error, Dialogys opened last → foreground)
made a Fiat warm decode fail silently: the Fiat foreground regex shared the
`Поиск` token with the Dialogys "ПОИСК" button, so raiseWarmWindow reported
success without raising Fiat and the VIN was typed into Dialogys → garbage;
warmDecode's Fiat branch then did a bare `return null` (no log, no fallback).

- FIX 1: drop the ambiguous `Поиск` from VINPIN_WINDOW_FOREGROUND.fiat; keep
  Fiat-only chrome (Dealer/ePER) + VIN-panel model tokens.
- FIX 2: warmDecode Fiat unusable-parse no longer returns a silent null —
  OCR the frame; on-panel + genuine not-found → null (real miss), otherwise
  warn (cold-path parity) and fall back to the proven cold decodeFiatLocked.
- FIX 3: ensureWarmWindow panel-verifies a raised Fiat window (catalogueReady);
  if up but off the VIN panel, re-navigate via establishSession (bounded/never-throw).
- FIX 4: _warmUp records per-window availability (warmWindows) so a Fiat VIN
  routes straight to cold when no Fiat window opened; and dismisses a leftover
  Rpartstore launch-error modal before opening Dialogys so it can't dirty the
  desktop / drive the wrong-window state.

Adds ocrFrame() test seam + 4 unit tests. tsc clean; 114 vinpin tests green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 12:55:10 +03:00
0de05e5515 Merge pull request 'fix(vinpin): cheap in-session retry on ambiguous Renault decode' (#235) from dev into main 2026-07-15 10:28:57 +03:00
9cb58c583c fix(vinpin): cheap in-session grid reset on ambiguous Renault retry (no relaunch)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
An AMBIGUOUS Renault outcome is transient/state-dependent, but decodeRenaultLocked
retried it with a full browser teardown (this.close()). The next attempt then
re-launched chromium + re-did the web login + re-established from scratch
(~60-90s each), and each re-establish re-hit the seat's dirty-resume ("catalog
window resumed open" -> closeStrayRunningApps), so 3 attempts blew the 180s budget
-> not_found. Proven live: VF1RFE00653633190 decoded cleanly to KADJAR earlier
when the desktop state was favorable, then thrashed to not_found on relaunch.

Fix: on the ambiguous path, reset to a clean VinPower brand grid on the SAME live
session via ensureBrandGrid (closeStrayRunningApps DOM recovery first, canvas
tab-X fallback) instead of tearing the browser down. Keep the browser + authed so
the next iteration's ensureAuthenticated is a no-op (no relaunch, no web login),
and re-run runRenaultFlow from the clean grid (~30-40s). Graduated safety: if the
cheap reset can't confirm a clean grid or the session is broken (page
closed/disconnected), fall back to the old close() + cold re-establish. The reset
runs under the wall-clock deadline so an overrun still routes to the existing
VinpinBudgetError teardown+poison path. never-throw + budget/poison paths
unchanged; maxAttempts semantics unchanged.

Tests: +3 (ambiguous -> in-session ensureBrandGrid reset re-runs runRenaultFlow
with NO close(); graduated fallback close()s when the reset can't reach a grid;
broken session skips straight to close()). 110 vinpin tests green; tsc clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 10:27:17 +03:00
d55a2b570f Merge pull request 'fix(vinpin): DOM Running-panel recovery for dirty-resume + fail-safe stray close' (#234) from dev into main 2026-07-15 09:49:20 +03:00
cf36da07af fix(vinpin): fail-safe stray-app close — never terminate a row on an unreadable name
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Review finding: closeStrayRunningApps classified an unreadable/empty VinPower
running-app row as a stray and closed it (`/VinPower/i.test('')` is false),
needlessly killing+relaunching a healthy VinPower on a transient name-read miss.
Only close rows POSITIVELY identified as non-VinPower (non-empty name that fails
the VinPower match); treat unreadable names as keep.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 09:48:48 +03:00
814d11d03e fix(vinpin): DOM-based dirty-resume recovery via Horizon Running panel
On login the RDS seat resumes DIRTY (e.g. a Renault Rpartstore launch-error
modal + its taskbar window over the brand grid). The old recovery failed: the
canvas tab-✕ (93,45) only hits a TABBED catalog window's ✕, which a resumed
stray doesn't have, so 6 tries did nothing and escalated to logout+relogin —
counterproductive, since the seat publishes apps-only and the RDS session ends
only on server-side idle timeout, so a Connection-Server logout+relogin PROVABLY
resumes the same dirty window.

New state-agnostic recovery `closeStrayRunningApps`: reveal the Horizon sidebar
(#sidebar-toggler), enumerate ul.running-app rows, and terminate every app whose
name != VinPower via its per-app ✕ (li.icon-close-app-image) — real DOM outside
the Blast canvas, so it closes a window regardless of its modal/spinner/loading
state. Collapse the sidebar, OCR-confirm the brand grid; relaunch VinPower via
#available-VINPIN (or the vinpinApp canvas coord) if the app itself was gone.

Wired as the PRIMARY recovery in ensureBrandGrid — both the resumed-catalog
branch (before the canvas tab-✕ fallback) and the end-of-loop escalation, which
NO LONGER calls logout+relogin (method retired). Every DOM op is guarded
(try/catch + presence check) so a missing selector / canvas-only render degrades
gracefully to the existing dismissBlockingModal + tab-✕ / OCR path instead of
throwing. Bounded loop; the launch-error modal dismissal (OK 868,530 / Escape)
is kept as a fast pre-step and fallback.

Preserves the never-throw contract, 180s budget/poison, spinner-guard, acquire
cap, launch-error cooldown, ensureRpartstore fast-bail, and the Fiat ePER path.
tsc clean; 107 vinpin tests green (adds closeStrayRunningApps close/degrade tests
and the ensureBrandGrid-uses-closeStrayRunningApps escalation tests).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 09:43:53 +03:00
ee56dec2d5 Merge pull request 'fix(vinpin): ffmpeg OCR root-cause + robust DOWN-Rpartstore Renault decode (defense-in-depth + hardening)' (#233) from dev into main 2026-07-15 08:47:46 +03:00
8137845198 fix(vinpin): bail a DOWN Rpartstore on iteration 1, don't re-click the flyout 6×
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
When Rpartstore is DOWN, its hard launch-error modal ("Ошибка запуска каталога",
title "Renault Rpartstore") renders OVER the brand grid. The grid tiles stay
OCR-visible behind the small centered modal, so the full-frame read matches both
`brandGrid` and `renaultSubmenu` — making ensureRpartstore's flyout branch fire on
EVERY iteration, re-clicking renaultRpartstore(584,779) + langOk + a 12s full-frame
poll for all ~6 iterations (~72s) before finally returning false. That wastes ~60s on
the first cold DOWN decode AND repeatedly actuates coordinates on a wedged desktop.

Detect the launch-error modal (upscaled crop via the existing
`rpartstoreLaunchErrorPresent`) at the top of the per-iteration loop, BEFORE the
flyout branch: if present, return false on iteration 1 so the acquire loop's
`!present` path dismisses it, sets the down-cooldown, and routes straight to Dialogys.
Depends on the crop OCR being legible (ffmpeg upscale, added in 281c54a); when
illegible it's false and behaviour is exactly as before.

Adds two robustness tests: (1) modal-over-grid → false on the first iteration with no
flyout re-clicks; (2) illegible crop → flyout path still runs (unchanged).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 08:46:40 +03:00
c8d9e45207 fix(vinpin): don't cool down Rpartstore on transient born-stuck streak; don't relaunch on clean-logout launcher
Two review follow-ups to 281c54a:

1. born-stuck cooldown regression: acquireLoadedRpartstoreInner set the 10m
   down-cooldown when maxOpens was exhausted by a born-stuck-spinner streak — a
   TRANSIENT, reopen-recoverable blip, not a server outage. Because the cooldown
   can only self-clear from INSIDE the acquire loop (skipped while cooling down),
   one spinner streak suppressed the richer Rpartstore catalog for every Renault
   decode for 10m. Reserve the cooldown for the confirmed launch-error DOWN signal
   (unchanged at the two launch-error sites); the born-stuck give-up now just falls
   back to Dialogys for that one VIN and retries Rpartstore fresh next VIN.

2. clean-logout false disconnect-recovery: cleanTeardown's disconnect recovery
   gated on VINPIN_OCR.sessionDropped, whose broad "HTML Access" token also matches
   the clean-logout Horizon HTML-Access launcher. A clean log-off could then click
   disconnectedClose + RELAUNCH VinPower right before close(), leaving the exact
   dirty resumed session the teardown prevents (+~17s wasted). Veto the recovery
   with !VINPIN_OCR.launcher so it fires only on a real Disconnected drop.

Keeps never-throw, budget, spinner-guard, Fiat/Dialogys fallbacks intact. Adds a
born-stuck-no-cooldown test and a clean-logout-launcher-no-relaunch test.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 08:41:35 +03:00
281c54a423 fix(vinpin): Renault-decode robustness for a DOWN Rpartstore (ffmpeg + flyout/close/logout/cooldown)
Root cause: ffmpeg is absent in the prod worker, so vinpin.ocr cropScale silently
returns the full 1600x900 frame — the tiny centered Rpartstore launch-error modal
is illegible, so a DOWN Rpartstore is misread as a spinner and thrashes the seat.

- Dockerfile: install ffmpeg so cropScale actually crops+3x-upscales (restores all
  clipped OCR: modal-crop error detect, Fiat modal, Renault header).
- ensureRpartstore: gate the "already open" short-circuit on a CONTENT token
  (rpartstoreLoaded), not rpartstoreOpen which false-matches the flyout/title word
  "Rpartstore"; click the flyout entry when the submenu is up over the grid; keep a
  late open-window branch so a spinner/vehicle-page window still counts as present.
- closeRpartstoreTab: never click windowClose(1298,14) (it hits the language
  selector and wedges the grid); gate the retry on a content token; Escape after.
- cleanTeardown: dismiss any blocking modal BEFORE "Çıkış yap" so logout is a clean
  RDS log-off (not a dirty channel disconnect); recover a Disconnected dialog via
  disconnectedClose(953,505) + relaunch VINPIN app for a fresh grid.
- Rpartstore-down cooldown (10m): a launch-error / repeated load-failure routes
  Renault decodes straight to Dialogys (skip reopening a down catalog); a confirmed
  load clears it.
- ensureBrandGrid: dismiss a wedging launch-error modal + short-retry instead of
  burning the 84s dead-wait.
- parseRenaultHeader: ignore the status-bar license-expiry date when reading the
  model year; sessionAlive matches RDST01/RDST02 (seat load-balances).
- Keeps never-throw, VINPIN_DECODE_BUDGET_MS, sessionPoisoned, the acquire cap,
  spinner-guard, relogin-cap and the Fiat/Dialogys fallbacks intact.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 08:32:39 +03:00
5b93864dd5 Merge pull request 'fix(vinpin): dismiss leftover launch-error modal + cap relogin per decode (browser-disconnect loop)' (#232) from dev into main 2026-07-15 07:01:23 +03:00
f54511d393 fix(vinpin): clear leftover launch-error modal on acquire give-up + cap relogin
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
The Renault decode fell to not_found when Rpartstore is DOWN (hard
launch-error modal) even though Dialogys should take over. Root cause:

- acquireLoadedRpartstore's budget-exhausted / never-loaded return-false
  paths left the centered launch-error modal on screen (only the flaky
  OCR error-detect branch dismissed it). The modal then blocked the
  Dialogys grid-return.
- returnToBrandGrid's tab-✕ can't close a centered dialog, so every
  "not on brand grid (try N/4)" wedged and re-entered ensureBrandGrid,
  which escalated to logoutAndRelogin → close()+launch() ("browser
  disconnected — will relaunch") on EVERY iteration, thrashing on a stale
  page ref until the 180s budget → not_found.

Fixes (conservative, all safety nets intact):
1. Wrap acquireLoadedRpartstore so EVERY false return runs a best-effort
   defensive dismiss (Escape → click launch-error OK 868,530 → Escape),
   unconditional of the OCR read. Harmless when no modal is up.
2. returnToBrandGrid + ensureBrandGrid dismiss a possible centered modal
   before the tab-✕ close so a leftover dialog can't wedge the loop.
3. Cap the logout+relogin escalation to ONE attempt per decode/warm-up
   (reloginUsedThisDecode) — a capped exhaustion poisons the seat for a
   clean cold restart instead of looping close()+launch() until budget.

Keeps the OCR fast-path branch, maxOpens/acquireBudgetMs=14s, fcc0298,
61b5769, Fiat path, never-throw/budget/poison all intact.

Tests: +3 (budget-exhausted defensive dismiss; grid-return modal-clear
before tab-✕; relogin capped to one attempt) — 88 vinpin tests green,
tsc + biome clean. Needs prod validation.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 06:47:28 +03:00
9f6693e833 Merge pull request 'fix(vinpin): cap Rpartstore acquire at ~1 open via 14s sub-budget' (#231) from dev into main
Reviewed-on: #231
2026-07-15 06:25:45 +03:00
e0b3de8dc7 fix(vinpin): cap Rpartstore acquire at ~1 open via 14s sub-budget
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Rpartstore's launch-error modal OCR-detection is unreliable across renderings,
so a DOWN Rpartstore was grinding all 3 reopens (~54s) + dirtying the seat →
Dialogys fallback couldn't finish inside the decode budget → not_found.
Lower acquireBudgetMs 90s→14s so the loop bails after the first open+poll (~22s)
straight to Dialogys on a still-clean seat. Healthy Rpartstore loads on the first
open and is used as before; maxOpens kept so tests still exercise the reopen path.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 06:18:55 +03:00
6c5f8401f8 Merge pull request 'fix(vinpin): detect Rpartstore launch-error via upscaled modal crop, not full 1x frame' (#230) from dev into main
Reviewed-on: #230
2026-07-15 06:01:39 +03:00
542ab0cb2b fix(vinpin): detect Rpartstore launch-error via upscaled modal crop, not full 1x frame
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
The prod Rpartstore→Dialogys bail regressed: a DOWN Rpartstore was still
misclassified as a "born-stuck spinner", burning 3 reopens (~54s) and pushing
the decode past the 180s budget → not_found. The rpartstoreLaunchError regex
never matched because acquireLoadedRpartstore's load-poll OCR'd the FULL
1600x900 frame at 1x — at which the small centered Cyrillic modal ("Ошибка
запуска каталога") is illegible to tesseract (it returns the surrounding
brand-grid tiles and drops the modal text). The regex text was actually fine;
the modal was never fed to it.

Root cause (verified live 2026-07-15, seat trvinpin47828): wrong OCR
resolution/region, not wrong regex.

Fix:
- New VINPIN_RPARTSTORE_ERROR_REGION (centered modal crop); OCR it UPSCALED (3x)
  so "Ошибка запуска каталога" reads as "Owwu6ka 3anycka KaTanora" and matches.
- pollRpartstoreState(): each poll reads LOADED off the full frame (large Latin
  text, unchanged) AND the launch-error off the upscaled modal crop → bail on the
  FIRST open, no wasted reopens. Genuine-spinner reopen path preserved.
- Also catch the launch error when ensureRpartstore/raiseWarmWindow can't confirm
  a window (modal is over the grid, no catalog chrome) → dismiss + bail.
- rpartstoreLaunchError regex: add the verbatim live transliterations
  (Owwu6ka/OwwbKa); 3anycka+KaTanora remain the stable anchors.

Live verification (seat trvinpin47828, exclusive night access):
- Rpartstore is DOWN server-side (hard launch error, NOT a spinner).
- New detection returns launchError on open 1 → bail, no reopens.
- Dialogys fallback decoded VF1RFE00653633190 → RENAULT Kadjar (HFE) in 52.2s
  (well under the 180s budget).

Budget/poison/livelock/Fiat paths untouched. 85 vinpin unit tests green;
typecheck + biome clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 05:53:22 +03:00
74c718fb18 Merge pull request 'fix(vinpin): detect Rpartstore hard launch-error → bail straight to Dialogys' (#229) from dev into main
Reviewed-on: #229
2026-07-15 05:16:15 +03:00
0ad3f114f3 fix(vinpin): detect Rpartstore hard launch-error → bail straight to Dialogys
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Rpartstore currently throws an immediate hard launch-error modal ("Ошибка
запуска каталога" / title "Renault Rpartstore") within ~8-10s of every open —
a server-side/entitlement failure that reopening never fixes. The old code
misclassified it: the error dialog's title matched rpartstoreOpen so
ensureRpartstore returned true, but it lacked the rpartstoreLoaded content
markers, so acquireLoadedRpartstore judged it a born-stuck spinner and burned
all 3 reopens (~54s) before falling back to Dialogys — which then ran out of
the 150s decode budget → not_found. Dialogys itself decodes correctly (~25s).

Fix (detect-and-bail on the FIRST open, no wasted reopens):
- constants: add VINPIN_COORDS.rpartstoreLaunchErrorOk (868,530) + the
  VINPIN_OCR.rpartstoreLaunchError pattern (matches the real Cyrillic AND its
  stable eng-OCR transliteration "Owwnbka 3anycka KaTanora").
- acquireLoadedRpartstore step 2: poll now stops on loaded OR launch-error and
  classifies via the returned OCR text; a launch error dismisses the modal and
  returns false immediately → straight to Dialogys (reopen loop untouched for
  genuine spinners).
- ensureRpartstore: submenu-open poll also stops fast on the launch error
  instead of dead-waiting afterRenaultCatalogOpen.
- bump VINPIN_DECODE_BUDGET_MS 150s→180s (cheap safety margin).
- tests: launch-error → false after ONE open (no reopens, dismiss clicked);
  genuine spinner still reopens; OCR-pattern matches Cyrillic + transliteration.

Never-throw contract, sessionPoisoned, budget teardown, cold/Dialogys
fallbacks, the fcc0298 spinner-guard, the 61b5769 establish/teardown fix and
the Fiat ePER path are all intact. Skipped the warm-path Dialogys field-clear
tweak — runDialogysSearch is shared with the cold path and switching its clear
step would change cold behavior.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 04:24:02 +03:00
68e3eb4a61 Merge pull request 'dev' (#228) from dev into main
Reviewed-on: #228
2026-07-15 03:12:22 +03:00
61b5769e48 fix(vinpin): reliable warm-daemon establish (clean teardown + tab-close + backoff)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Root cause of warm-establish failures was resume-into-dirty-session +
broken window-close + no backoff, not OCR/detection. Four composing fixes:

A. Clean teardown (cleanTeardown): before the browser close(), close each
   open catalog window via the corrected tab-✕ then click "Çıkış yap" logout
   to END the RDS session, so the next warm-up starts from a fresh login/grid
   instead of resuming into the last-open 3-window desktop. Wired into
   teardownWarm() and both failed-warmUp exits. Bounded + never-throw.

B. Fix close coords + tab-✕ primary. catalogTabClose {135,45}→{93,45}
   (validated live). In ensureBrandGrid/returnToBrandGrid the tab-✕ is now the
   PRIMARY close; the windowClose {1298,14} click (which opens the HTML-Access
   language dropdown) is no longer used there. Escape pressed after each close
   to dismiss an accidental dropdown before re-OCR. After N failed closes,
   ensureBrandGrid escalates to logout+relogin (one-shot, no recursion) instead
   of limping into the ePER-open loop.

C. Realistic grid wait. afterLogin 20_000→45_000 (real grid render ~32-46s).

D. Backoff between re-warm attempts. A failed warmUp sets a cooldown (60s,
   exponential to 5min) that BOTH reconcile() and decode()'s warm-on-demand
   honour; a successful warm resets it — so a failing seat is no longer
   hammered every ~60s leaving fresh dirty windows.

Safety nets preserved: never-throw contract, VINPIN_DECODE_BUDGET_MS,
sessionPoisoned, cold/Dialogys fallbacks; fcc0298 Rpartstore spinner-guard,
Fiat ePER path, and Russian-dialog dismissal (746,454) untouched. Cannot be
exercised in dev (single seat on prod) — needs prod validation on a rested seat.

Tests: +8 unit tests (clean-teardown ordering, tab-✕ primary + relogin
escalation, warm-up backoff respected by reconcile + warm-on-demand + reset).
81 vinpin tests green; tsc + biome clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 19:11:21 +03:00
8e10ebc883 feat(web): redirect path-style /dashboard/settings/<tab> to ?tab= search param
Unsubscribe confirmations (and any stale links) used the path form which
had no route and fell to the SPA not-found screen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 17:47:24 +03:00
29e10b432f feat(notifications): visible unsubscribe footer link in lifecycle mails
- inject signed unsubscribeUrl into every optional-workflow Novu payload
  (templates render it via {{#if unsubscribeUrl}} footer)
- add 'conversion' campaign workflow to OPTIONAL_WORKFLOWS + email_marketing
  category so its one-click tokens validate and opt-outs suppress it
- declare UNSUBSCRIBE_SECRET/URL_BASE/EMAIL in env schema (""→undefined
  preprocess against the url().optional() boot-crash trap), .env.example and
  both compose env blocks
- fix confirmation-page settings link (?tab=notifications)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 16:35:47 +03:00
55dd34a450 Merge pull request 'dev' (#227) from dev into main
Reviewed-on: #227
2026-07-14 15:50:40 +03:00
66b39862c8 fix(part-prices): araç-marka etiketlerini de orijinal say (FORD/GM/BMW/Mercedes/VW)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Kullanıcı düzeltmesi: kokpit tur ham araç-marka etiketlerini "yansanayi"
sayıyordu — yanlış. FORD/GM/BMW/Mercedes/Volkswagen/Renault… OE etiketidir.
Orijinal tespiti artık kokpit tur='orjinal' setine değil, OE aile üyeliğine
dayanır: OE_SUPPLY_LABELS OE_FAMILIES'ten TÜRETİLİR (+ jenerik ORJINAL), böylece
OE-tespiti ile aile-filtresi drift etmez ve tüm araç markaları orijinal sayılır.
Gerçek yan sanayi PARÇA markaları (Bosch/Febi/Valeo/TRW) hiçbir ailede yok →
orijinal değil. GM Opel ailesine eklendi (TR'de Opel OE'si). Redis v3→v4 (eski
"miss" değerleri bayat). kokpit'e DOKUNULMADI.

Ölçülen etki (dev): grafikli kod %0,77→%0,84; artış sase kataloğu ile takip
beslemesinin bu markalardaki kod kesişimiyle sınırlı (ör. takip'te 4.859 Ford-
stokta koddan 335'i sase kataloğunda).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 15:34:10 +03:00
fcc02984dd fix(vinpin): Rpartstore acquire-with-spinner-guard for Renault decode
A freshly-opened Rpartstore instance sometimes gets "born stuck" on an
infinite spinner (survives raise/maximize). The only reliable fix, proven
in a live spike, is to CLOSE the stuck instance and reopen a FRESH one.

Replace the old "raise Rpartstore → if not focusable reopen → else fall to
Dialogys" with a bounded load-verify-else-reopen loop applied to BOTH the
warm-daemon Renault path (warmRenaultDecode) and the cold per-decode path
(runRenaultFlow):

- acquireLoadedRpartstore(): bring a Rpartstore window forward, OCR-verify it
  actually rendered its search-home landing markers (new rpartstoreLoaded set —
  content tokens the spinner lacks), and if still spinning close the tab and
  reopen a fresh instance. Retries up to VINPIN_RPARTSTORE.maxOpens (3) times.
- Bounded inside the decode wall-clock budget AND a tighter acquireBudgetMs
  (90s) sub-cap, so a permanently-stuck Rpartstore still leaves headroom to
  fall back to Dialogys — never a livelock.
- Rpartstore stays PRIMARY (richer Turkish catalog); Dialogys only as a
  last resort once reopen attempts are exhausted or it genuinely misses.
- Fiat ePER path unchanged; sessionPoisoned / never-throw contract preserved.

Adds unit tests for reuse / spinner→reopen→loaded / exhausted→false /
budget-bail / Rpartstore-primary-on-hit / exhausted→Dialogys-fallback.

Could not live-test (single Vinpin seat is held on prod) — needs prod
validation after promote.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 15:29:12 +03:00
edde2dc3b4 fix(part-prices): OEM fiyatını kodun araç markasına göre filtrele (PSA vs OPAR)
Aynı OEM koduna farklı OE dağıtıcıları düşebiliyor (Stellantis: PSA ₺5.531 vs
OPAR ₺3.459) → OE-only havuz bile iki dağıtıcıyı medyanlayıp hayalet fiyat
veriyordu. Artık kart, kodun kendi araç markasına göre tek OE ailesine süzer.

- part-prices.logic: marka→OE-dağıtıcı-ailesi haritası (OE_FAMILIES: PSA=
  Peugeot/Citroen/DS, FIAT=Fiat/OPAR/Tofaş, RENAULT=Renault/Dacia/MAIS, ...).
  filterOffersForBrand: araç markası → yalnız o ailenin orijinal teklifleri
  (jenerik ORJINAL aile-belirsiz olduğu için elenir); yan sanayi markası çipi
  → yalnız etiket-uyumlular; markasız → tüm OE aileleri (taban).
- Web: OEM kartı kodun araç markasını oem-vehicles'tan (en çok geçen brandName)
  türetip geçirir; başlık "Orijinal (OE) fiyat analizi · <Marka>". Kart marka
  çözümü için oem-vehicles'ı bekler.
- vehiclesByOem NORMALIZE eşleşmeye geçti + parts_oem_code_norm_idx functional
  index (migration 0033): PSA kodları boşluklu saklandığından ("9827 622 780")
  exact match onları kaçırıyordu — marka bu yüzden çözülemiyordu. Reverse
  "kataloğunuzda" bölümü de artık reformatlı kodları buluyor.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 14:07:55 +03:00
f52cafd622 Merge pull request 'dev' (#226) from dev into main
Reviewed-on: #226
2026-07-14 13:51:22 +03:00
d0caf57e89 fix(part-prices): OEM ana kartında yalnız orijinal (OE) fiyatları göster
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
OEM detay ana fiyat kartı seriyi markasız istiyordu; allowBrandless uzun
kodlarda orijinal + yan sanayi tekliflerini tek havuzda medyanlıyordu →
hiçbir satıcının fiyatı olmayan "hayalet medyan" ve marka stok girip-
çıkmasından fiyat değişmeden sahte grafik sıçraması (2026-07-14 ölçümü:
9827622780 pg p50 4.495₺ = PSA 5.531 ile OPAR 3.459'un ortası).

- filterOffersForBrand: markasız istek artık yalnız orijinal (OE/dağıtıcı
  etiketli) teklifleri kullanır; araç-markalı OE çapraz-ref çipleri de
  OE-only'ye iner, yan sanayi markasına orijinal fallback'i kaldırıldı.
- Orijinal sınıflaması otoritesi = kokpit marka tur='orjinal' seti (39
  marka, statik; PSA/MAIS/OPAR/ORJINAL... — FORD/GM/BMW/Mercedes/VW kokpit'te
  yansanayi, bilinçli dışarıda). Runtime kokpit bağımlılığı yok.
- Web: kart başlığı "Orijinal (OE) fiyat analizi" + açıklama/dipnot orijinal
  bilgisini yazıyor; ana OEM kodunun ölü markasız batch push'u kaldırıldı.
- Redis cache v2→v3 (anahtar üreticileri export'lanıp worker ile paylaşıldı);
  migration 0032 eski karma-havuz part_price satırlarını siler → OE-only
  kurallarla lazy re-backfill.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 13:28:27 +03:00
32655ead7b chore(vinpin): add VINPIN_WARM_DAEMON compose env ref (api+worker) so Coolify can inject the warm-daemon flag
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 13:21:35 +03:00
98376747cd feat(vinpin): persistent warm-session daemon (taskbar-raise decode) with cold fallback
Replace the per-decode "launch browser + login + open catalog" model with a
persistent warm Vinpin seat that eliminates cold-start, brand-switch cost and the
seat livelock. Additive + fail-safe: every warm operation degrades to the proven
cold per-decode path, so behaviour never regresses.

Warm daemon (VinpinDaemonService, worker-process singleton):
- Scheduler warms the seat at 08:00 and tears it down at 21:00 Europe/Istanbul
  (proper TZ via Intl, no hardcoded offset); warms on worker start if inside hours;
  reconcile() every 60s with a reentrancy guard.
- Keepalive nudges the RDS session (mouse.move) every ~75s while warm+idle; it
  SKIPS during any active seat op (busy flag) and never takes a lock that blocks a
  decode.
- decode(vin): inside hours ensure warm (warm-on-demand once) then delegate to the
  driver; off-hours delegate straight to the cold path. Never throws.

Driver warm path (VinpinDriverService):
- warmUp() launches+logs in ONCE and opens Fiat ePER + Renault Rpartstore + Renault
  Dialogys windows without closing each other, then OCR-binds each taskbar button
  (order read via OCR, not hardcoded; raise self-heals by probing slots + OCR
  verify). isWarm()/teardownWarm()/keepalivePing() added.
- warmDecode(): taskbar-raise the brand window (Fiat→ePER, Renault→Rpartstore w/
  Dialogys fallback), run the EXISTING in-catalog decode on the warm window, OCR
  the modal, parse, then Escape to ready the field for the next VIN. Runs under the
  wall-clock budget; a hang still aborts.
- Health-recovery: a dropped seat (Disconnected/no-free-sessions OCR marker) →
  teardown + re-warm ONCE, then retry the decode once.
- Refactored runDialogys into openDialogysSubmenu + runDialogysSearch so the warm
  path searches without a window-closing reopen; cold Dialogys flow unchanged.

Safety nets retained: VINPIN_DECODE_BUDGET_MS + sessionPoisoned breaker (warm
budget abort → teardown+poison+null), single-seat serialization (runExclusive),
decode() never throws. Gated by VINPIN_ENABLED; VINPIN_WARM_DAEMON=false forces the
legacy cold path (kill-switch). Widened VINPIN_MODAL_REGION to ~900px.

Wiring: processor calls getVinpinDaemon().decode(); worker starts the daemon on
boot and stops it (releasing the seat) on shutdown. BullMQ concurrency 1 +
attempts:1 unchanged.

Tests: business-hours warm/teardown scheduling (injected clock/TZ), brand→taskbar
routing, taskbar OCR-order binding, keepalive-skips-during-decode, and
session-drop→re-warm→retry recovery. All existing vinpin/queue tests stay green.

NOTE: un-dev-testable (prod holds the single seat) — pixel/taskbar coords are
OCR-verified + marked TUNE and need live prod validation; warm falls back to cold
until confirmed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 13:19:20 +03:00
ccf2417cc8 Merge pull request 'fix(vinpin): break the single-seat decode livelock (attempts:1 + budget + poison)' (#225) from dev into main
Reviewed-on: #225
2026-07-14 11:32:46 +03:00
d253a43ad2 fix(vinpin): break the single-seat decode livelock (attempts:1 + budget + poison)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
A bad/unresolvable VIN could leave a catalog window open on the shared Vinpin
seat; the next decode's ensureBrandGrid found it "resumed open" and looped
(close→brand-grid-not-confirmed→ePER-open→browser-disconnect→relaunch) forever.
BullMQ attempts:2 + 30s backoff auto-re-fed every failure straight back into the
stuck seat, starving all real decodes for minutes.

- queue: attempts:1, drop the 30s exponential backoff (extract VINPIN_DECODE_JOB_
  OPTIONS). The driver already runs its own bounded internal retries; a BullMQ
  retry on top is what compounded the livelock. Null decode still persists as
  not_found; a hard infra throw stays user-retriable (failed).
- driver: hard per-decode wall-clock budget (VINPIN_DECODE_BUDGET_MS, 150s) via
  withDeadline() racing each attempt; on abort → close() + poison seat + return
  null (no retry into the stuck state).
- driver: sessionPoisoned flag — set at nav-loop exhaustion (ensureBrandGrid /
  establishSession), budget abort, and failed post-decode cleanup; the NEXT
  decode forces a full cold re-establish instead of reconnecting to the resumed
  desktop. Cleared on any confirmed-clean grid/catalogue.
- driver: finally-cleanup after every decode — on failure/not-found return the
  seat to a clean brand grid; if that can't reach the grid, poison + tear down.
- driver: basic VIN sanity (17 alphanumerics) before touching the seat.

Healthy Fiat/Renault happy paths are byte-identical when nothing is stuck.
Cannot be live-tested (seat is on prod) — needs prod validation.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 11:29:43 +03:00
c2bb1e7382 Merge pull request 'fix(vinpin): prefer exact model over wrong-market catalog in matcher' (#224) from dev into main
Reviewed-on: #224
2026-07-14 10:55:06 +03:00
1fade89df4 fix(vinpin): prefer exact model over wrong-market catalog in matcher
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
The Vinpin catalog matcher could route a European Renault VIN
(VF1RFE00653633190, decoded "KADJAR") onto the China-market catalog
"KADJAR ÇİN" (source XZH, 22 categories) instead of the correct European
"KADJAR" (XFE, 44 categories), serving wrong parts. Root cause: the
Turkish "ÇİN" lost its Ç/İ to the ASCII token strip and collapsed to a
dropped 1-char "N", so "KADJAR ÇİN" tokenized identically to "KADJAR" —
the market qualifier was invisible to the scorer.

Fixes:
- modelTokens now folds diacritics (NFD + combining-mark strip) so
  "ÇİN" survives as the ASCII token "CIN".
- Scorer prefers an EXACT normalized model match (no extra tokens) over
  a superset, via a bonus kept smaller than the year-range swing so
  multi-generation routing (2022 TIPO-EGEA → MCA) is unaffected.
- New MARKET_QUALIFIERS set (ÇİN/CIN, CHINA, CHINE, RUSYA, ... grounded
  in the real Renault/Dacia catalog rows) heavily penalizes candidates
  whose EXTRA tokens are region qualifiers; generation tokens are not
  penalized, so generations stay matchable.
- Richer-catalog (categoryCount) tiebreak among equal-score candidates;
  match() query selects the category count via a correlated subquery.

Adds unit tests incl. the KADJAR case, CLIO/DUSTER generation cases, and
diacritic-folding. Fiat behavior unchanged; all 39 vinpin tests green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 10:47:55 +03:00
7387c02da0 Merge pull request 'fix(web): cover cold Vinpin decode + drop hardcoded Fiat no-catalog copy' (#223) from dev into main
Reviewed-on: #223
2026-07-14 10:22:48 +03:00
7069ceaeae fix(web): cover cold Vinpin decode + drop hardcoded Fiat no-catalog copy
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Two Vinpin decode-flow UX bugs in the search page:

1. Poll window (VINPIN_MAX_POLLS 6→30, still 3s interval) now covers a
   cold Vinpin VDI decode (~60-100s) instead of bailing at 18s. On
   poll-exhaust we no longer fall through to the no-catalog dead-end;
   instead a reassuring brand-neutral "still working, ready shortly"
   card (decodePendingHint) — the decode caches server-side so a later
   re-submit returns instantly.

2. The poll-exhaust fallback previously forced brandName:"Fiat" onto the
   no-catalog prompt, so a Renault VIN read "Fiat". Removed. The
   no-catalog copy is brand-aware via the API's noCatalog.brandName, with
   brand-neutral fallback keys (noCatalogHintNeutral / browseCatalogCtaNeutral)
   when no brand is available. A Renault VIN never says "Fiat".

Web-only, no flag. New i18n keys added to tr.json + en.json. No API change.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 10:21:43 +03:00
cf9454482f Merge pull request 'perf(vinpin): in-session Renault→Fiat swap + OCR-poll waits + input micro-trims' (#222) from dev into main
Reviewed-on: #222
2026-07-14 10:09:38 +03:00
eaa500ddd5 perf(vinpin): in-session Renault→Fiat swap + OCR-poll waits + input micro-trims
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
Latency optimizations in the flag-gated (VINPIN_ENABLED) Vinpin decode driver.
Every change keeps the existing fixed-wait value as a fallback cap, so
worst-case behaviour and robustness are unchanged — only the common case is
faster. No live seat session was run (prod holds the single Horizon seat).

#2 Renault→Fiat symmetric swap: ensureReady no longer tears the whole browser
down on a Renault→Fiat flow switch (was a ~60-80s cold restart). It now keeps
the authenticated Horizon/VinPower session, returns to the brand grid via the
existing ensureBrandGrid (which closes a resumed foreign catalog window) and
reopens Fiat via the normal tile flow — symmetric with the Fiat→Renault
direction. Guarded fallback: if the in-session swap can't reach the grid /
throws, it falls back to close()+cold re-establish.

#3 OCR-poll-until-ready: replaced big fixed post-action sleeps whose completion
is OCR-detectable with a capped poll (screenshot→ocrRegion→regex every ~700ms,
return on match, cap == old fixed wait). Converted: afterFiatOpen(12s),
afterVinSubmit(7s, Fiat modal), afterRpartstoreSubmit(8s),
afterRenaultCatalogOpen(12s, ×2), plus cold-path afterLogin(20s) and
afterVinPowerLogin(18s). Left afterVinpinLaunch(14s) fixed — the VinPower login
dialog has no reliable OCR marker (detected via DOM), and it doubles as a
generic connecting-screen settle. Left afterDialogysSubmit fixed (out of scope).

#4 Micro-trims: field-clear Backspace burst 40→5 (VINPIN_FIELD_CLEAR_BACKSPACES),
key-type delay 45-50ms→20ms (VINPIN_TYPE_DELAY_MS, 17-char VIN ~850→~340ms),
afterAlertDismiss 700→250ms.

New pure/injectable pollForText helper in vinpin.ocr.ts (unit-tested:
early-return, cap-never-exceeded, first-read match). typecheck + biome clean;
31 vinpin unit tests green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 09:57:40 +03:00
e47e795a09 Merge pull request 'dev' (#221) from dev into main
Reviewed-on: #221
2026-07-14 09:13:52 +03:00
77c93af9a0 feat(vinpin): Renault/Dacia decode akışı (Rpartstore + Dialogys)
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
VINPIN köprüsüne Fiat'ın yanına Renault/Dacia desteği eklendi.

- Marka yönlendirme: selectVinpinBrandFlow(vin) WMI'den akışı seçer
  (Renault/Dacia → Rpartstore/Dialogys, geri kalan → mevcut Fiat ePER,
  Fiat davranışı byte-identical). isVinpinBrandAllowed allowlist'i
  fiat + renault + dacia'ya genişletildi.
- Renault akışı durum-toleranslı: koltuk son katalogu (Rpartstore)
  sunucu-taraflı hatırlayıp açık resume ediyor; ensureRpartstore grid /
  submenu / açık-pencere / yükleniyor durumlarını tanıyıp kendini
  toparlıyor. Rpartstore ana akış, Dialogys best-effort fallback.
- Ortak ensureBrandGrid artık resume olmuş yabancı katalog penceresini
  (Rpartstore/Dialogys/ePER) kapatıp grid'e dönüyor → Renault↔Fiat
  ardışık decode'ları (tek koltuk) artık kırılmıyor.
- parseRenaultHeader/isUsableRenaultParse: OCR başlığından model+marka
  (RENAULT/DACIA) + yıl; bilinen-token allowlist ile contiguous model
  koşusu. Matcher + processor kararlaştırılan markaya göre PL24
  catalog_vehicle eşliyor (Fiat varsayılan korunur).
- Testler: Renault parser + marka-yönlendirme/allowlist birim testleri.

Flag-gated (VINPIN_ENABLED). Canlı doğrulama: 5/5 Renault/Dacia VIN
(Kadjar, Clio II, Clio IV, Dacia Duster, Latitude) doğru decode; Fiat
Egea spot-check korunuyor.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 08:44:09 +03:00
24716d03a9 Merge pull request 'revert(build): drop ineffective cache-bust (#219)' (#220) from revert/build-cache-web into dev 2026-07-14 08:13:46 +03:00
6de7839107 revert(build): drop ineffective per-commit cache-bust (#219)
SOURCE_COMMIT isn't substituted into docker-compose build args by Coolify
(resolved to a constant "unknown"), so the cache-bust never fired. Removing the
dead ARG/RUN + compose arg. Web-only deploys use a Coolify force-rebuild instead.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 08:13:44 +03:00
edcd168d48 Merge pull request 'fix(build): per-commit cache-bust for web-only deploys' (#219) from fix/build-cache-web into dev 2026-07-14 07:43:07 +03:00
4bba42fc13 Merge pull request 'promote: Fiat eper-default katalog (Orijinal→ePER, Birleşik→kanonik)' (#218) from dev into main 2026-07-14 07:35:32 +03:00
5697447988 Merge pull request 'fix(vinpin): reject stale-breadcrumb decodes (require SINCOM) + harden matcher' (#213) from fix/vinpin-false-positive into main 2026-07-13 12:09:15 +03:00
121 changed files with 14276 additions and 900 deletions

View File

@@ -21,14 +21,6 @@ COPY --from=deps /app/apps/web/node_modules ./apps/web/node_modules
COPY --from=deps /app/packages/shared/node_modules ./packages/shared/node_modules
COPY --from=deps /app/packages/config/node_modules ./packages/config/node_modules
COPY --from=deps /app/packages/ui/node_modules ./packages/ui/node_modules
# Cache-bust: web-only commits were sticking to a cached build layer, so
# auto-deploys shipped a stale bundle (only --no-cache/force rebuilds picked
# them up). Referencing the commit SHA *before* the source COPY makes this layer
# (and therefore COPY + `pnpm build`) invalidate on every commit; the deps stage
# above stays cached on the lockfile, so installs aren't repeated.
ARG SOURCE_COMMIT=unknown
RUN echo "Building commit ${SOURCE_COMMIT}"
COPY . .
# Vite env vars (baked at build time)
@@ -46,8 +38,12 @@ RUN pnpm build
# ── Stage 4: Production ───────────────────────────────
FROM node:22-alpine AS production
# Chromium for Playwright (EMEX/PartsCatalogs)
RUN apk add --no-cache chromium nss freetype harfbuzz ca-certificates ttf-freefont
# Chromium for Playwright (EMEX/PartsCatalogs). ffmpeg is required by the Vinpin
# OCR pipeline (vinpin.ocr cropScale): it crops+3x-upscales the tiny centered
# Rpartstore launch-error / decode-modal region so tesseract can read it. Without
# it cropScale silently returns the full 1600x900 frame and every clipped OCR
# degrades to an illegible full-frame 1x read (the DOWN-Rpartstore misclassify bug).
RUN apk add --no-cache chromium nss freetype harfbuzz ca-certificates ttf-freefont ffmpeg
ENV PLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH=/usr/bin/chromium-browser
ENV PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1

View File

@@ -23,3 +23,8 @@ NOVU_API_KEY=
APP_PUBLIC_URL=https://sase.tr
# HMAC secret for signed track.sase.tr click links (Bitwarden "mailtrack tracking (track.sase.tr)"). Empty → no click tracking.
MAILTRACK_SECRET=
# Unsubscribe links (List-Unsubscribe header + mail footer). Empty secret → mailto-only header, no footer link (dev default).
UNSUBSCRIBE_SECRET=
# Defaults to <APP_PUBLIC_URL>/api/email/unsubscribe when empty.
UNSUBSCRIBE_URL_BASE=
UNSUBSCRIBE_EMAIL=unsubscribe@sase.tr

View File

@@ -0,0 +1,8 @@
-- Fiyat görünümleri artık markasız/araç-markalı bağlamlarda yalnız ORİJİNAL
-- (kokpit tur='orjinal' etiketli) teklifleri içerir. Mevcut satırlar eski
-- kuralla (orijinal + yan sanayi tek havuz) hesaplandığından tutarsız — sil;
-- seriler ilk görüntülenmede takip history'sinden OE-only kurallarla yeniden
-- backfill edilir (product_history 2026-01-29 epoch'undan beri eksiksiz),
-- cron sonraki günleri aynı kuralla ekler. (~166 track / ~4,8k satır — ucuz.)
DELETE FROM "part_price_daily";--> statement-breakpoint
DELETE FROM "part_price_tracks";

View File

@@ -0,0 +1,9 @@
-- OEM kodu normalize-eşleşme index'i. Reverse-catalog (vehiclesByOem) ve
-- fiyat-kartı marka çözümü artık normalize edilmiş koda göre eşleşir: URL
-- kodu boşluksuz ("9827622780") gelirken katalog boşluklu saklayabilir
-- ("9827 622 780"; özellikle PSA/Peugeot/Citroen) → exact match kaçırıyordu.
-- Functional btree, sorgudaki ifadeyle birebir aynı olmalı ki planner kullansın.
-- Not: non-concurrent build kısa süreli YAZMA kilidi alır (prod ~10s, salt-okuma
-- etkilenmez); parts ~9,3M satır. IF NOT EXISTS → idempotent/yeniden koşulur.
CREATE INDEX IF NOT EXISTS "parts_oem_code_norm_idx"
ON "parts" (regexp_replace(upper("oem_code"), '[^A-Z0-9]', '', 'g'));

View File

@@ -0,0 +1,9 @@
-- Kalıcı tamlık işareti: prefetch zinciri parça ile bittiğinde true olur
-- (PrefetchWorkerService.incrementCompleted). Redis prefetch:complete:* (21g TTL,
-- operasyonel skip mantığı) yerine SÜRESİZ ölçüm — "% tam çekilmiş" güvenilir
-- takibi. _at son doğrulanma zamanını tutar. IF NOT EXISTS → idempotent.
ALTER TABLE "vehicles" ADD COLUMN IF NOT EXISTS "fully_fetched" boolean DEFAULT false NOT NULL;
--> statement-breakpoint
ALTER TABLE "vehicles" ADD COLUMN IF NOT EXISTS "fully_fetched_at" timestamp with time zone;
--> statement-breakpoint
CREATE INDEX IF NOT EXISTS "vehicles_fully_fetched_idx" ON "vehicles" USING btree ("fully_fetched");

View File

@@ -0,0 +1,9 @@
-- Dunning görünürlüğü: yenileme tahsilatı patlayınca (invoice.payment_failed)
-- damgalanır, fatura ödenince (invoice.paid) veya abonelik kesin iptal olunca
-- temizlenir. dunning_invoice_url = Stripe hosted fatura sayfası — kullanıcının
-- açık faturayı ödeyebileceği/yeni kart girebileceği TEK self-serve yüzey
-- (uygulamada kart-güncelleme yok; %0 dunning kurtarmanın kök nedeni buydu).
-- IF NOT EXISTS → idempotent.
ALTER TABLE "user_subscriptions" ADD COLUMN IF NOT EXISTS "dunning_since" timestamp with time zone;
--> statement-breakpoint
ALTER TABLE "user_subscriptions" ADD COLUMN IF NOT EXISTS "dunning_invoice_url" text;

View File

@@ -0,0 +1,20 @@
-- Mitsubishi'nin parça listesi grup sanılıyordu.
--
-- `/p5mitsubishi/extern/details/vinDetails` yanıtı `partno`/`qty` taşıyan bir
-- PARÇA listesi, ama her kaydın kendi linki `partInfoTable` (parça-detay) ve ne
-- wid ne de yol sınıflandırıcıda karşılık buluyordu. Sonuç: 2.193 parça listesi
-- grup düğümüne dönüştü ve içlerindeki 19.576 tekil parça ("SCREW,LOCK CYLINDER",
-- "BOLT,STEERING COLUMN WASHER") kategori olarak kaydedildi. Ölçüm (prod,
-- 2026-09-20): bu 19.576 sahte düğümün TOPLAM 2 tanesinde parça var, ve her
-- prefetch turunda yeniden çekiliyorlar.
--
-- Sınıflandırıcı düzeltildi (detailsTable artık yaprak, partInfoTable hiç
-- kuyruklanmıyor), ama okuma yolu bir düğümün ÖNCE çocuklarına bakıyor: sahte
-- çocuklar dururken parça listesi asla çekilmez. Bu yüzden satırların silinmesi
-- düzeltmenin parçası, ayrı bir temizlik değil.
--
-- Güvenli: yalnız pl24 kaynaklı ve yalnız bu iki imzayı taşıyan satırlar; ikisi
-- de prod'da %100 Mitsubishi. Silinen ~2 parça satırı üst listeden yeniden gelir.
DELETE FROM "categories"
WHERE "source" = 'pl24'
AND ("link_wid" = 'partInfoTable' OR "link_path" ILIKE '%/details/vinpartinfo%');

View File

@@ -0,0 +1,34 @@
-- RPartStore (rpartstore.renault.com, Renault Group dealer portal) VIN-decode
-- fallback cache (feature-flagged: RPARTSTORE_ENABLED). One row per VIN. The
-- rpartstore-decode BullMQ job asks the RPartStore BFF (STOMP over WebSocket)
-- for Renault/Dacia VINs the normal chain (pcat/PL24/emex) can't identify, then
-- matches the decoded model to an EXISTING PL24 catalog_vehicle. RPartStore is
-- ONLY a decode oracle here — parts are served from PL24's existing catalog.
-- status: 'pending' | 'decoded' | 'not_found' | 'capped' | 'failed'.
CREATE TABLE IF NOT EXISTS "rpartstore_decodes" (
"vin" text PRIMARY KEY NOT NULL,
"status" text DEFAULT 'pending' NOT NULL,
"brand_name" text,
"model" text,
"model_code" text,
"family_code" text,
"model_year" text,
"engine" text,
"gearbox" text,
"energy_type" text,
"manufacturing_date" text,
"catalog_vehicle_id" uuid,
"raw" jsonb,
"attempts" integer DEFAULT 0 NOT NULL,
"created_at" timestamp with time zone DEFAULT now() NOT NULL,
"updated_at" timestamp with time zone,
"decoded_at" timestamp with time zone
);
--> statement-breakpoint
DO $$ BEGIN
ALTER TABLE "rpartstore_decodes" ADD CONSTRAINT "rpartstore_decodes_catalog_vehicle_id_catalog_vehicles_id_fk" FOREIGN KEY ("catalog_vehicle_id") REFERENCES "public"."catalog_vehicles"("id") ON DELETE set null ON UPDATE no action;
EXCEPTION
WHEN duplicate_object THEN null;
END $$;
--> statement-breakpoint
CREATE INDEX IF NOT EXISTS "rpartstore_decodes_status_idx" ON "rpartstore_decodes" USING btree ("status");

View File

@@ -225,6 +225,48 @@
"when": 1783092194145,
"tag": "0031_canonical_template_entries",
"breakpoints": true
},
{
"idx": 32,
"version": "7",
"when": 1784023885041,
"tag": "0032_part_price_oe_reset",
"breakpoints": true
},
{
"idx": 33,
"version": "7",
"when": 1784027180912,
"tag": "0033_parts_oem_code_norm_idx",
"breakpoints": true
},
{
"idx": 34,
"version": "7",
"when": 1784965129879,
"tag": "0034_vehicle_fully_fetched",
"breakpoints": true
},
{
"idx": 35,
"version": "7",
"when": 1786435493000,
"tag": "0035_subscription_dunning",
"breakpoints": true
},
{
"idx": 36,
"version": "7",
"when": 1786521893000,
"tag": "0036_pl24_mitsubishi_partinfo_cleanup",
"breakpoints": true
},
{
"idx": 37,
"version": "7",
"when": 1790332800000,
"tag": "0037_rpartstore_decodes",
"breakpoints": true
}
]
}
}

View File

@@ -21,6 +21,7 @@ import { RolesGuard } from "./common/guards/roles.guard";
import { LoggingInterceptor } from "./common/interceptors/logging.interceptor";
import { TimeoutInterceptor } from "./common/interceptors/timeout.interceptor";
import { TransformInterceptor } from "./common/interceptors/transform.interceptor";
import { TelegramModule } from "./common/telegram.module";
import configuration from "./config/configuration";
import { validate } from "./config/env.validation";
import { ContactModule } from "./contact/contact.module";
@@ -79,6 +80,7 @@ import { VehiclesModule } from "./vehicles/vehicles.module";
]),
DatabaseModule,
RedisModule,
TelegramModule,
AuthModule,
UsersModule,
EmailModule,

View File

@@ -0,0 +1,192 @@
import { describe, expect, it, vi } from "vitest";
import { isStaleBrowseArchitecture } from "../integrations/pl24/pl24-tree";
import { CatalogService } from "./catalog.service";
/**
* Regression lock for the pinned-browse-rows bug (plv2.md, finding consumers-09).
*
* `catalog_vehicles` is a permanent cache: `getModels` returns early as soon as
* a brand has any row, so `fetchVehicleList` never runs again for that brand.
* The 188 rows listed while PSA and Volvo were still P4 (127 LEGACY_PSA + 61
* LEGACY_VOLVO on prod, 2026-09-20) were therefore stuck serving the frozen
* 2024-02-13 PSA snapshot and a Volvo endpoint that answers HTTP 503.
*/
type Row = {
id: string;
serviceName: string;
architecture: string | null;
brandId: string | null;
};
const psaRow = (id: string): Row => ({
id,
serviceName: "peugeot_parts",
architecture: "LEGACY_PSA",
brandId: "b1",
});
const freshRow = (id: string): Row => ({
id,
serviceName: "peugeot_parts",
architecture: "P5_MODERN",
brandId: "b1",
});
function makeService(opts: {
lockFree?: boolean;
fetched?: Array<{ model: string; vehicleId: string }>;
fetchThrows?: boolean;
refetched?: Row[];
}) {
const deleted: string[][] = [];
const inserted: unknown[][] = [];
const tx = {
insert: () => ({
values: (v: unknown[]) => {
inserted.push(v);
return { onConflictDoNothing: async () => undefined };
},
}),
delete: () => ({
where: async (cond: unknown) => {
// drizzle's inArray() puts its bound values in a `queryChunks` entry
// that is itself an array of Param objects; pull the plain ids back out
// so a test can assert WHICH rows were removed, not just how many.
const chunks = (cond as { queryChunks?: unknown[] })?.queryChunks ?? [];
const params = chunks.find((c): c is unknown[] => Array.isArray(c)) ?? [];
const ids = params
.map((param) => (param as { value?: unknown })?.value)
.filter((v): v is string => typeof v === "string");
deleted.push(ids);
return undefined;
},
}),
};
const db = {
select: () => ({ from: () => ({ where: async () => opts.refetched ?? [] }) }),
transaction: async (cb: (t: typeof tx) => Promise<void>) => cb(tx),
};
const redis = { setNx: vi.fn(async () => opts.lockFree !== false) };
const pl24Service = {
fetchVehicleList: vi.fn(async () => {
if (opts.fetchThrows) throw new Error("upstream 503");
return opts.fetched ?? [];
}),
};
const svc = new CatalogService(
db as never,
redis as never,
pl24Service as never,
{} as never,
) as never as {
healStaleBrowseRows: (brand: string, rows: Row[], where: unknown[]) => Promise<Row[] | null>;
};
return { svc, redis, pl24Service, deleted, inserted };
}
describe("isStaleBrowseArchitecture", () => {
it("flags a row whose stored architecture is not the current one", () => {
expect(
isStaleBrowseArchitecture({
storedArchitecture: "LEGACY_PSA",
currentArchitecture: "P5_MODERN",
}),
).toBe(true);
expect(
isStaleBrowseArchitecture({
storedArchitecture: "LEGACY_VOLVO",
currentArchitecture: "P5_MODERN",
}),
).toBe(true);
});
it("leaves a matching row alone", () => {
expect(
isStaleBrowseArchitecture({
storedArchitecture: "P5_MODERN",
currentArchitecture: "P5_MODERN",
}),
).toBe(false);
// Brands that are still P4 upstream must not be touched.
expect(
isStaleBrowseArchitecture({
storedArchitecture: "LEGACY_FORD",
currentArchitecture: "LEGACY_FORD",
}),
).toBe(false);
});
it("does nothing without both sides (unknown service / unlabelled row)", () => {
expect(
isStaleBrowseArchitecture({ storedArchitecture: null, currentArchitecture: "P5_MODERN" }),
).toBe(false);
expect(
isStaleBrowseArchitecture({ storedArchitecture: "LEGACY_PSA", currentArchitecture: null }),
).toBe(false);
});
});
describe("healStaleBrowseRows", () => {
it("does not touch PL24 when every row is current", async () => {
const { svc, pl24Service, redis } = makeService({});
const out = await svc.healStaleBrowseRows("Peugeot", [freshRow("a"), freshRow("b")], []);
expect(out).toBeNull();
expect(pl24Service.fetchVehicleList).not.toHaveBeenCalled();
expect(redis.setNx).not.toHaveBeenCalled();
});
it("re-lists a stale brand and replaces its rows", async () => {
const refetched = [freshRow("new1"), freshRow("new2")];
const { svc, pl24Service, deleted, inserted } = makeService({
fetched: [
{ model: "208", vehicleId: "p5-208" },
{ model: "308", vehicleId: "p5-308" },
],
refetched,
});
const out = await svc.healStaleBrowseRows("Peugeot", [psaRow("old1"), psaRow("old2")], []);
expect(pl24Service.fetchVehicleList).toHaveBeenCalledWith("peugeot_parts");
expect(inserted).toHaveLength(1);
expect(inserted[0]).toHaveLength(2);
expect(deleted).toHaveLength(1);
expect(out).toEqual(refetched);
});
it("deletes only the stale rows when a service holds a mix", async () => {
// A row already re-listed under the new architecture conflicts on insert and
// is skipped, so deleting it would drop it for good.
const { svc, deleted } = makeService({
fetched: [{ model: "208", vehicleId: "p5-208" }],
refetched: [freshRow("keep")],
});
await svc.healStaleBrowseRows("Peugeot", [psaRow("old1"), freshRow("keep")], []);
expect(deleted).toHaveLength(1);
expect(deleted).toEqual([["old1"]]);
});
it("keeps the stale rows when the re-list throws", async () => {
const { svc, deleted, inserted } = makeService({ fetchThrows: true });
const out = await svc.healStaleBrowseRows("Volvo", [psaRow("old1")], []);
expect(out).toBeNull();
expect(inserted).toHaveLength(0);
expect(deleted).toHaveLength(0);
});
it("keeps the stale rows when upstream returns an empty model list", async () => {
const { svc, deleted, inserted } = makeService({ fetched: [] });
const out = await svc.healStaleBrowseRows("Volvo", [psaRow("old1")], []);
expect(out).toBeNull();
expect(inserted).toHaveLength(0);
expect(deleted).toHaveLength(0);
});
it("attempts at most once a day per brand", async () => {
const { svc, pl24Service } = makeService({ lockFree: false });
const out = await svc.healStaleBrowseRows("Peugeot", [psaRow("old1")], []);
expect(out).toBeNull();
expect(pl24Service.fetchVehicleList).not.toHaveBeenCalled();
});
});

View File

@@ -19,6 +19,7 @@ import {
userBrands,
userSubscriptions,
} from "../database/schema/core";
import { isPl24LeafNode, isStaleBrowseArchitecture } from "../integrations/pl24/pl24-tree";
import { PL24Service } from "../integrations/pl24/pl24.service";
import {
type PL24DecodedCategory,
@@ -169,7 +170,8 @@ export class CatalogService {
.where(and(...whereConditions));
if (dbVehicles.length > 0) {
return dbVehicles;
const healed = await this.healStaleBrowseRows(brandName, dbVehicles, whereConditions);
return healed ?? dbVehicles;
}
// Fetch from PL24 for each service
@@ -224,6 +226,118 @@ export class CatalogService {
return allVehicles;
}
/**
* Re-list a brand whose stored browse rows were created under a retired PL24
* architecture, and replace them with the current ones.
*
* WHY (plv2.md, finding consumers-09): `getModels` treats `catalog_vehicles`
* as a permanent cache — one row for the brand and `fetchVehicleList` is never
* called again. The rows listed while PSA and Volvo were still P4 are pinned
* forever, so Peugeot/Citroën browse keeps serving the frozen 2024-02-13
* snapshot and Volvo/Polestar browse keeps calling an endpoint that answers
* HTTP 503. A code fix alone never reaches these rows.
*
* Deliberately conservative, mirroring `healStalePl24Architecture` on the
* VIN side:
* - only rows whose stored architecture disagrees with the service table;
* - one attempt per brand per day (Redis lock) so a permanently failing
* re-list cannot hammer the one surviving account on every page view;
* - a failed or empty re-list leaves the old rows in place — stale data
* beats an empty catalog;
* - the stale rows are deleted only once the replacements are committed,
* and per service, so one broken sub-catalog cannot wipe a working one.
*
* Deleting a browse row cascades to its categories and parts. That is
* intended: those rows describe the retired tree and would otherwise survive
* as unreachable orphans under the new listing.
*
* Returns the refreshed rows, or null when nothing was migrated (caller keeps
* what it already had).
*/
private async healStaleBrowseRows(
brandName: string,
dbVehicles: (typeof catalogVehicles.$inferSelect)[],
whereConditions: ReturnType<typeof eq>[],
): Promise<(typeof catalogVehicles.$inferSelect)[] | null> {
const isStale = (v: typeof catalogVehicles.$inferSelect) =>
isStaleBrowseArchitecture({
storedArchitecture: v.architecture,
currentArchitecture: PL24_SERVICE_CATALOGS[v.serviceName]?.architecture,
});
const staleServices = [...new Set(dbVehicles.filter(isStale).map((v) => v.serviceName))];
if (staleServices.length === 0) return null;
if (!(await this.redis.setNx(`pl24:browse-heal:${brandName}`, "1", 86_400))) return null;
this.logger.log(
`[pl24-browse-heal] ${brandName}: ${staleServices.join(", ")} listed under a retired architecture — re-listing`,
);
let migrated = 0;
for (const svc of staleServices) {
// ONLY the stale rows. A service can hold a mix — some rows already
// re-listed under the new architecture — and those must survive: the
// insert below skips them on conflict, so deleting them here would drop
// them for good.
const staleIds = dbVehicles
.filter((v) => v.serviceName === svc && isStale(v))
.map((v) => v.id);
try {
const fetched = await this.pl24Service.fetchVehicleList(svc);
if (fetched.length === 0) {
this.logger.warn(
`[pl24-browse-heal] ${svc}: upstream returned no models — keeping ${staleIds.length} stale row(s)`,
);
continue;
}
const config = PL24_SERVICE_CATALOGS[svc];
const brandId = dbVehicles.find((v) => v.serviceName === svc)?.brandId ?? null;
await this.db.transaction(async (tx) => {
await tx
.insert(catalogVehicles)
.values(
fetched.map((v) => ({
source: "pl24" as const,
serviceName: svc,
brandName,
brandId,
model: v.model,
year: v.year || null,
engine: v.engine || null,
bodyType: v.bodyType || null,
transmission: v.transmission || null,
market: v.market || null,
serviceVehicleId: v.vehicleId,
catalogPath: v.catalogPath || null,
architecture: config?.architecture || "P5_MODERN",
metadata: v.metadata || null,
categoriesFetched: false,
updatedAt: new Date(),
})),
)
.onConflictDoNothing();
if (staleIds.length > 0) {
await tx.delete(catalogVehicles).where(inArray(catalogVehicles.id, staleIds));
}
});
migrated += staleIds.length;
this.logger.log(
`[pl24-browse-heal] ${svc}: ${staleIds.length} stale row(s) → ${fetched.length} fresh model(s)`,
);
} catch (err) {
this.logger.warn(
`[pl24-browse-heal] ${svc} re-list failed, keeping stale rows: ${(err as Error).message}`,
);
}
}
if (migrated === 0) return null;
return await this.db
.select()
.from(catalogVehicles)
.where(and(...whereConditions));
}
/**
* Get a single catalog vehicle by ID.
*/
@@ -1249,18 +1363,10 @@ export class CatalogService {
return this.pl24Service.fetchFordModelConfig(vehicle.serviceName, familyId, mode, upds);
}
/** Shared PL24 leaf classifier — see integrations/pl24/pl24-tree. */
private isLeafPath(linkPath: string): boolean {
const lower = linkPath.toLowerCase();
return (
lower.includes("/bom/") ||
lower.includes("/bomdetails") ||
lower.includes("/partinfo/") ||
// PL24 P5 leaf items endpoints — chemicals, servicepart, accessories,
// any /extern/<kind>/(vin|mdl)_items combination. These return parts,
// not subgroups, so they must short-circuit drill-down.
/\/extern\/[^/]+\/(vin_items|mdl_items)\b/.test(lower) ||
lower.includes("image-board.action") || // PSA illustration leaf
lower.includes("json-vin-bom-detail.action")
isPl24LeafNode({ linkPath }) || linkPath.toLowerCase().includes("json-vin-bom-detail.action")
);
}
@@ -1367,13 +1473,9 @@ export class CatalogService {
return cats.map((c) => {
const dbChildCount = childCountMap.get(c.id) || 0;
const isLeaf =
c.linkPath?.includes("/bom/") ||
c.linkPath?.includes("/bomdetails") ||
c.linkPath?.includes("/partinfo/") ||
c.linkPath?.includes("/servicepart/vin_items") ||
c.linkPath?.includes("image-board.action") || // PSA illustration leaf
(!c.linkPath && dbChildCount === 0);
const isLeaf = c.linkPath
? isPl24LeafNode({ linkPath: c.linkPath, linkWid: c.linkWid })
: dbChildCount === 0;
return {
...c,
schemaImageUrl: picMap.get(c.id) || null,

View File

@@ -13,10 +13,7 @@ export class CategoriesController {
}
@Get("tree/:vehicleId")
async getCategoryTree(
@Param("vehicleId") vehicleId: string,
@Query("source") source?: string,
) {
async getCategoryTree(@Param("vehicleId") vehicleId: string, @Query("source") source?: string) {
return this.categoriesService.getCategoryTree(vehicleId, source);
}

View File

@@ -17,6 +17,8 @@ function createService(db: any) {
};
const pl24Service = {
getCategories: vi.fn().mockResolvedValue([]),
// P4→P5 onarma yolu bunu çağırır (plv2 Faz 2).
decodeVin: vi.fn().mockResolvedValue(null),
};
const emexService = {
isSupported: vi.fn().mockReturnValue(false),
@@ -462,3 +464,81 @@ describe("CategoriesService", () => {
});
});
});
// ── P4 → P5 kendi kendini onarma (plv2 Faz 2, bulgu psa-07) ──
// PSA/Volvo upstream'de P5'e taşındı; daha önce decode edilmiş araçlar donmuş
// 2024-02-13 PSA anlık görüntüsüne / ölü P4 Volvo ucuna işaret etmeye devam
// ediyor ve decodeVin'in db_hit kısa devresi kod düzeltmesini onlara ulaştırmıyor.
describe("CategoriesService — bayat PL24 mimarisini onarma", () => {
const makeVehicle = (catalogPath: string) => ({
id: "veh-1",
vin: "VF3MCBHZWHS150390",
rawData: { catalogInfo: { serviceName: "peugeot_parts", catalogPath } },
});
const setup = (catalogPath: string, decodeResult: unknown) => {
const { service, redis, pl24Service } = createService({} as never);
const p = service as unknown as {
healStalePl24Architecture(
id: string,
v: { vin: string | null; rawData: unknown },
n: number,
): Promise<boolean>;
db: unknown;
};
// setNx: ilk denemeye izin ver (günlük tek deneme kilidi)
(redis as unknown as { setNx: unknown }).setNx = vi.fn().mockResolvedValue(true);
(redis as unknown as { del: unknown }).del = vi.fn().mockResolvedValue(undefined);
pl24Service.decodeVin = vi.fn().mockResolvedValue(decodeResult);
return { service, p, redis, pl24Service, vehicle: makeVehicle(catalogPath) };
};
it("P4 PSA yolundaki araç yeniden decode edilir ve ağaç değişir", async () => {
const fresh = {
catalogInfo: { serviceName: "peugeot_parts", catalogPath: "/p5psa" },
categories: [
{
code: "_FCT0001",
nameTr: "Mekanik",
nameEn: "Mechanical",
linkPath: "/p5psa/x",
linkWid: "mainGroupTable",
},
],
};
const { p, pl24Service, vehicle } = setup("/psa/peugeot_parts", fresh);
const inserted: unknown[] = [];
(p as unknown as { db: unknown }).db = {
transaction: async (fn: (tx: unknown) => Promise<void>) => {
await fn({
delete: () => ({ where: async () => undefined }),
insert: () => ({ values: async (rows: unknown[]) => inserted.push(...rows) }),
update: () => ({ set: () => ({ where: async () => undefined }) }),
});
},
};
await expect(p.healStalePl24Architecture("veh-1", vehicle, 120)).resolves.toBe(true);
expect(pl24Service.decodeVin).toHaveBeenCalledWith("VF3MCBHZWHS150390");
expect(inserted).toHaveLength(1);
expect((inserted[0] as { name: string }).name).toBe("Mekanik");
});
it("zaten P5 olan araca dokunulmaz (decode çağrılmaz)", async () => {
const { p, pl24Service, vehicle } = setup("/p5psa", null);
await expect(p.healStalePl24Architecture("veh-1", vehicle, 6)).resolves.toBe(false);
expect(pl24Service.decodeVin).not.toHaveBeenCalled();
});
it("yeniden decode boş dönerse eski ağaç korunur", async () => {
const { p, vehicle } = setup("/psa/peugeot_parts", { categories: [] });
await expect(p.healStalePl24Architecture("veh-1", vehicle, 120)).resolves.toBe(false);
});
it("günde bir denenir (setNx kilidi)", async () => {
const { p, redis, pl24Service, vehicle } = setup("/psa/peugeot_parts", { categories: [] });
(redis as unknown as { setNx: unknown }).setNx = vi.fn().mockResolvedValue(false);
await expect(p.healStalePl24Architecture("veh-1", vehicle, 120)).resolves.toBe(false);
expect(pl24Service.decodeVin).not.toHaveBeenCalled();
});
});

View File

@@ -21,7 +21,13 @@ import { PartsCatalogsService } from "../integrations/parts-catalogs/parts-catal
import { PcatGroup } from "../integrations/parts-catalogs/parts-catalogs.types";
import { PL24FordLegacyService } from "../integrations/pl24/pl24-ford-legacy.service";
import { PL24PsaService } from "../integrations/pl24/pl24-psa.service";
import {
isPl24GroupNode,
isPl24LeafNode,
isStalePl24Architecture,
} from "../integrations/pl24/pl24-tree";
import { PL24Service } from "../integrations/pl24/pl24.service";
import { getServiceApiPath } from "../integrations/pl24/pl24.types";
import { classifyNode, foldName, mapToCanonical } from "../jobs/canonical-lexicon";
import { RedisService } from "../redis/redis.service";
import { StorageService } from "../storage/storage.service";
@@ -70,6 +76,20 @@ export class CategoriesService {
.from(categories)
.where(eq(categories.vehicleId, vehicleId));
// ── P4 → P5 self-healing (plv2.md Faz 2, bulgu psa-07) ──
// PSA and Volvo moved to P5 upstream; rows decoded before that still point at
// the frozen 2024-02-13 PSA snapshot or the dead P4 Volvo endpoint, and
// decodeVin's db_hit short-circuit means no code fix ever reaches them. Heal
// one vehicle per view instead of a bulk re-decode storm against the single
// surviving account.
const healed = await this.healStalePl24Architecture(vehicleId, vehicle, dbCategories.length);
if (healed) {
dbCategories = await this.db
.select()
.from(categories)
.where(eq(categories.vehicleId, vehicleId));
}
// If no categories in DB, fetch from PL24
if (dbCategories.length === 0 && vehicle.rawData) {
const rawData = vehicle.rawData as any;
@@ -896,17 +916,13 @@ export class CategoriesService {
// subgroups. Drilling into them used to insert per-part endpoints as
// ghost child categories — keep the regex wide so any /extern/{kind}/
// (vin|mdl)_items endpoint is recognised, not just /servicepart/.
const lp = linkPath.toLowerCase();
// One shared classifier (integrations/pl24/pl24-tree) — the inline lists here,
// in catalog.service and in the prefetch worker used to disagree, which is how
// p5psa/p5volvo camelCase `bomDetails` leaves and `illusTable` group levels
// ended up on the wrong side (silent empty panels / unfetched parts).
if (
lp.includes("/bom/") ||
lp.includes("/bomdetails") ||
lp.includes("/partinfo/") ||
/\/extern\/[^/]+\/(vin_items|mdl_items)\b/.test(lp) ||
// PSA / Hyundai / Opel / Volvo image-board pages and the Ford VIN
// vin-image-board.action equivalent. Drilling into them yields BOM rows,
// not sub-groups — let getCategoryWithParts handle those as parts.
lp.includes("image-board.action") ||
lp.includes("json-vin-bom-detail.action")
isPl24LeafNode({ linkPath }) ||
linkPath.toLowerCase().includes("json-vin-bom-detail.action")
) {
return [];
}
@@ -991,6 +1007,104 @@ export class CategoriesService {
* The per-node trail excludes the node itself, ordered root-first. Used by the
* catalog search so each hit can show where it sits in the tree.
*/
/**
* Re-decode a vehicle whose stored catalogInfo still points at a retired PL24
* architecture (P4 PSA/Volvo) and replace its category tree with the P5 one.
*
* Returns true when the tree was rebuilt. Deliberately conservative:
* - only PSA/Volvo rows whose service is P5 today are touched;
* - a failed or empty re-decode leaves the old tree in place (stale data beats
* no data), and the attempt is remembered for a day so a permanently
* unresolvable VIN cannot re-hit PL24 on every page view;
* - the old rows are deleted only once the new tree is in hand, because the
* unique (vehicle_id, name, source) index would otherwise reject the insert.
*/
private async healStalePl24Architecture(
vehicleId: string,
vehicle: { vin: string | null; rawData: unknown },
existingCategoryCount: number,
): Promise<boolean> {
const rawData = vehicle.rawData as {
catalogInfo?: { serviceName?: string; catalogPath?: string };
} | null;
const catalogInfo = rawData?.catalogInfo;
const serviceName = catalogInfo?.serviceName;
if (!vehicle.vin || !serviceName) return false;
if (
!isStalePl24Architecture({
catalogPath: catalogInfo?.catalogPath,
currentApiPath: getServiceApiPath(serviceName),
})
) {
return false;
}
const attemptKey = `pl24:heal:${vehicleId}`;
if (!(await this.redis.setNx(attemptKey, "1", 86_400))) return false;
this.logger.log(
`[pl24-heal] ${vehicle.vin} (${serviceName}) was decoded on ${catalogInfo?.catalogPath} — re-decoding on P5`,
);
let decoded: Awaited<ReturnType<PL24Service["decodeVin"]>> | null = null;
try {
await this.redis.del(`pl24:vehicle:${vehicle.vin}`);
decoded = await this.pl24Service.decodeVin(vehicle.vin);
} catch (err) {
this.logger.warn(`[pl24-heal] ${vehicle.vin} re-decode failed: ${(err as Error).message}`);
return false;
}
if (!decoded?.categories?.length) {
this.logger.warn(
`[pl24-heal] ${vehicle.vin} re-decode returned no categories — keeping old tree`,
);
return false;
}
await this.db.transaction(async (tx) => {
await tx.delete(categories).where(eq(categories.vehicleId, vehicleId));
const seen = new Set<string>();
const rows = decoded.categories
.filter((c) => {
const name = c.nameTr || c.nameEn;
if (!name || seen.has(name)) return false;
seen.add(name);
return true;
})
.map((c) => ({
vehicleId,
catalogVehicleId: null as string | null,
name: c.nameTr || c.nameEn,
nameOriginal: c.nameEn,
parentId: null as string | null,
externalId: c.code,
linkPath: c.linkPath || null,
linkWid: c.linkWid || null,
source: "pl24" as const,
}));
if (rows.length) await tx.insert(categories).values(rows);
await tx
.update(vehicles)
.set({
rawData: { ...(rawData ?? {}), catalogInfo: decoded.catalogInfo },
fullyFetched: false,
fullyFetchedAt: null,
})
.where(eq(vehicles.id, vehicleId));
});
await Promise.all([
this.redis.del(`cat:tree:${vehicleId}`),
this.redis.del(`prefetch:complete:${vehicleId}`),
this.redis.del(`prefetch:noresult:${vehicleId}`),
]);
this.logger.log(
`[pl24-heal] ${vehicle.vin} migrated to ${decoded.catalogInfo?.catalogPath}: ${existingCategoryCount} stale → ${decoded.categories.length} fresh categories`,
);
return true;
}
private async buildBreadcrumbs(
ids: string[],
): Promise<Map<string, Array<{ id: string; name: string }>>> {
@@ -1316,9 +1430,13 @@ export class CategoriesService {
// AND lowercase (groupReferenceTable, groupTable, groupsTable). The old
// case-sensitive includes("Group") missed the lowercase ones (~1157 nodes),
// so they skipped this group-drill branch and fell to the parts path.
// A PL24 node is a parent when the shared classifier says it is not a parts
// leaf. The old `linkWid.includes("group")` test missed p5psa `illusTable`
// and p5volvo/p5subaru `illustrationsTable`, so those levels were fetched as
// parts, parsed to zero rows and rendered as an empty panel with no error.
if (
category.source === "pl24" &&
category.linkWid?.toLowerCase().includes("group") &&
isPl24GroupNode({ linkPath: category.linkPath, linkWid: category.linkWid }) &&
category.vehicleId
) {
const groupChildren = await this.getChildren(categoryId);
@@ -2173,15 +2291,8 @@ export class CategoriesService {
return !!c.linkPath?.startsWith("pcat:"); // unknown → lazy-leaf heuristic
})()
: (() => {
const lp = c.linkPath?.toLowerCase() ?? "";
return (
lp.includes("/bom/") ||
lp.includes("/bomdetails") ||
lp.includes("/partinfo/") ||
/\/extern\/[^/]+\/(vin_items|mdl_items)\b/.test(lp) ||
lp.includes("image-board.action") ||
(!c.linkPath && dbChildCount === 0)
);
if (!c.linkPath) return dbChildCount === 0;
return isPl24LeafNode({ linkPath: c.linkPath, linkWid: c.linkWid });
})();
return {
...c,

View File

@@ -0,0 +1,10 @@
import { Global, Module } from "@nestjs/common";
import { TelegramService } from "./telegram.service";
/** Global so any module can raise an operational alert without extra wiring. */
@Global()
@Module({
providers: [TelegramService],
exports: [TelegramService],
})
export class TelegramModule {}

View File

@@ -0,0 +1,56 @@
import { Injectable, Logger } from "@nestjs/common";
/**
* Minimal Telegram alerting for operational failures that need a human now
* (currently: PL24 auth down for an hour — i.e. the account may be banned
* again). Fire-and-forget: a failed alert must never affect a request.
*
* Uses the same bot as the Süper Panel — set TELEGRAM_BOT_TOKEN and
* TELEGRAM_CHAT_ID. Unconfigured = silently disabled (local/dev).
*/
@Injectable()
export class TelegramService {
private readonly logger = new Logger(TelegramService.name);
private get token(): string {
return process.env.TELEGRAM_BOT_TOKEN ?? "";
}
private get chatId(): string {
return process.env.TELEGRAM_CHAT_ID ?? "";
}
isConfigured(): boolean {
return Boolean(this.token && this.chatId);
}
/** Send a message. Returns false when disabled or the API refused. */
async send(text: string, opts: { silent?: boolean } = {}): Promise<boolean> {
if (!this.isConfigured()) {
this.logger.warn(`Telegram not configured — alert dropped: ${text.slice(0, 120)}`);
return false;
}
try {
const res = await fetch(`https://api.telegram.org/bot${this.token}/sendMessage`, {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
chat_id: this.chatId,
text,
parse_mode: "HTML",
disable_notification: opts.silent ?? false,
disable_web_page_preview: true,
}),
signal: AbortSignal.timeout(10_000),
});
if (!res.ok) {
this.logger.warn(`Telegram sendMessage failed: HTTP ${res.status}`);
return false;
}
return true;
} catch (err) {
this.logger.warn(`Telegram sendMessage error: ${(err as Error).message}`);
return false;
}
}
}

View File

@@ -203,6 +203,12 @@ export const userSubscriptions = pgTable(
// NULL for trials and legacy one-time purchases. Renewal invoices resolve
// our row through this.
stripeSubscriptionId: text("stripe_subscription_id"),
// Dunning state — set on the first failed renewal charge, cleared when the
// invoice recovers (invoice.paid) or the sub is finally cancelled. The URL
// is Stripe's hosted invoice page: the ONLY self-serve surface where the
// user can pay the open invoice / enter a new card / pass 3DS.
dunningSince: timestamp("dunning_since", { withTimezone: true }),
dunningInvoiceUrl: text("dunning_invoice_url"),
createdAt: timestamp("created_at", { withTimezone: true }).defaultNow().notNull(),
updatedAt: timestamp("updated_at", { withTimezone: true }).defaultNow().notNull(),
},
@@ -403,6 +409,36 @@ export const vinpinDecodes = pgTable("vinpin_decodes", {
decodedAt: timestamp("decoded_at", { withTimezone: true }),
});
// ─── RPartStore decodes (Renault/Dacia decode-oracle cache — one row per VIN) ──
// Feature-flagged (RPARTSTORE_ENABLED). Populated by the rpartstore-decode BullMQ
// job which asks the RPartStore BFF (rpartstore.renault.com, STOMP/WebSocket) for
// Renault/Dacia VINs the normal chain (pcat/PL24/emex) can't identify. On success
// the decoded model is matched to an EXISTING PL24 catalog_vehicle and parts are
// served from there — RPartStore is ONLY a decode oracle. Hard daily cap on
// searches (RPARTSTORE_DAILY_CAP); over-cap VINs are 'capped' and retried after 24 h.
export const rpartstoreDecodes = pgTable("rpartstore_decodes", {
vin: text("vin").primaryKey(),
// 'pending' | 'decoded' | 'not_found' | 'capped' | 'failed'
status: text("status").notNull().default("pending"),
brandName: text("brand_name"),
model: text("model"),
modelCode: text("model_code"),
familyCode: text("family_code"),
modelYear: text("model_year"),
engine: text("engine"),
gearbox: text("gearbox"),
energyType: text("energy_type"),
manufacturingDate: text("manufacturing_date"),
catalogVehicleId: uuid("catalog_vehicle_id").references(() => catalogVehicles.id, {
onDelete: "set null",
}),
raw: jsonb("raw"),
attempts: integer("attempts").notNull().default(0),
createdAt: timestamp("created_at", { withTimezone: true }).defaultNow().notNull(),
updatedAt: timestamp("updated_at", { withTimezone: true }),
decodedAt: timestamp("decoded_at", { withTimezone: true }),
});
// ─── Vehicles (shared config — one record per VIN) ──
export const vehicles = pgTable(
"vehicles",
@@ -419,10 +455,20 @@ export const vehicles = pgTable(
market: varchar("market", { length: 100 }),
rawData: jsonb("raw_data"),
source: varchar("source", { length: 20 }).default("pl24").notNull(),
// Durable completeness marker: set true when the prefetch chain finishes with
// parts (see PrefetchWorkerService.incrementCompleted). Unlike the ephemeral
// Redis `prefetch:complete:*` marker (21-day TTL, operational skip logic) this
// never expires — it's the reliable "% fully fetched" measurement. `_at` tracks
// the last time completion was confirmed (re-set on each re-drill completion).
fullyFetched: boolean("fully_fetched").default(false).notNull(),
fullyFetchedAt: timestamp("fully_fetched_at", { withTimezone: true }),
createdAt: timestamp("created_at", { withTimezone: true }).defaultNow().notNull(),
updatedAt: timestamp("updated_at", { withTimezone: true }).defaultNow().notNull(),
},
(table) => [uniqueIndex("vehicles_vin_unique_idx").on(table.vin)],
(table) => [
uniqueIndex("vehicles_vin_unique_idx").on(table.vin),
index("vehicles_fully_fetched_idx").on(table.fullyFetched),
],
);
// ─── User Vehicles (junction — user ↔ shared vehicle) ─

View File

@@ -33,7 +33,11 @@ export class CorgiService {
}
private extractYear(vin: string): number | null {
return extractModelYear(vin);
// Corgi is a WMI-only decoder — it resolves brand + year but never a model.
// Signalling modelResolved:false lets extractModelYear roll a 30-year-ambiguous
// position-10 code (e.g. "T" = 1996-or-2026) back a cycle for an old-shaped
// Renault VIN, so a ~1996 R19 isn't mislabelled as a 2026 car (see vin-validator).
return extractModelYear(vin, undefined, { modelResolved: false });
}
getBrandFromWmi(wmi: string): string | null {

View File

@@ -94,14 +94,16 @@ export class EmexBrowserService implements OnModuleInit, OnModuleDestroy {
this.semaphore = new Semaphore(MAX_CONCURRENT_PAGES);
this.useProxy = this.configService.get<string>("EMEX_USE_PROXY", "true") === "true";
// Default dataimpulse: Floxy retired 2026-07 (permanently down). Set
// EMEX_PROXY_PROVIDER=floxy to re-enable it.
const rawProvider = this.configService
.get<string>("EMEX_PROXY_PROVIDER", "floxy")
.get<string>("EMEX_PROXY_PROVIDER", "dataimpulse")
.toLowerCase();
this.proxyProvider = !this.useProxy
? "none"
: rawProvider === "dataimpulse" || rawProvider === "none"
? (rawProvider as "dataimpulse" | "none")
: "floxy";
: rawProvider === "floxy" || rawProvider === "none"
? (rawProvider as "floxy" | "none")
: "dataimpulse";
this.proxyHost = this.configService.get<string>("EMEX_PROXY_HOST", "74.81.81.81");
this.proxyPortStart = this.configService.get<number>("EMEX_PROXY_PORT_START", 10001);
this.proxyPortEnd = this.configService.get<number>("EMEX_PROXY_PORT_END", 10099);
@@ -260,6 +262,42 @@ export class EmexBrowserService implements OnModuleInit, OnModuleDestroy {
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36",
});
// Block heavy resources to save proxy bandwidth. Scraping reads HTML/DOM
// only — schema-image URLs are parsed from the markup and their dims come
// from a separate Range GET, so the browser never needs images/fonts/CSS.
// Context-level route covers every tab (session establish + acquirePage).
await this.context.route("**/*", (route) => {
const url = route.request().url();
const type = route.request().resourceType();
if (["image", "font", "stylesheet", "media"].includes(type)) {
return route.abort();
}
// Third-party junk seen in proxy usage: analytics, ad networks, chat
// widgets, Google/Yandex assets, and our own ipify egress probe.
if (
url.includes("google-analytics.com") ||
url.includes("googletagmanager.com") ||
url.includes("mc.yandex.ru") ||
url.includes("yastatic.net") ||
url.includes("fonts.googleapis.com") ||
url.includes("fonts.gstatic.com") ||
url.includes("content-autofill.googleapis.com") ||
url.includes("facebook.net") ||
url.includes("doubleclick.net") ||
url.includes("hotjar.com") ||
url.includes("adsco.re") ||
url.includes("displayvertising.com") ||
url.includes("tidio.co") ||
url.includes("api.ipify.org")
) {
return route.abort();
}
return route.continue();
});
this.startedAt = Date.now();
this.sessionExpiry = 0; // force session establish on first acquirePage

View File

@@ -215,11 +215,15 @@ export class EmexService {
// random-port-per-call primary proved that), but a sticky Floxy IP across the
// chained flow is still the safest choice — and avoids DataImpulse's ~50% dead
// ports that were eating the decode budget before reaching the Floxy fallback.
// Default dataimpulse: Floxy retired 2026-07 (permanently down). Set
// EMEX_PROXY_PROVIDER=floxy to re-enable it.
this.emexProxyProvider = !useProxy
? "none"
: (() => {
const p = this.configService.get<string>("EMEX_PROXY_PROVIDER", "floxy").toLowerCase();
return p === "dataimpulse" || p === "none" ? p : "floxy";
const p = this.configService
.get<string>("EMEX_PROXY_PROVIDER", "dataimpulse")
.toLowerCase();
return p === "floxy" || p === "none" ? p : "dataimpulse";
})();
// Default agent for the low-stakes image-dims path; fetchEmexHtml builds a
// fresh agent per request so a flaky exit can't pin every call.

View File

@@ -0,0 +1,98 @@
/**
* Parts-Catalogs capture asset cache.
*
* Every JWT capture opens a fresh browser context (empty HTTP cache) and
* re-downloads the SAME static widget assets through the billed residential
* proxy — measured ~2.2 MB/capture, ~93% of it the parts-catalogs widget
* bundle (`.../v3/bundle_<hash>.js`, identical across all partner sites) plus
* the sites' own versioned JS/CSS. At ~3–4k captures/day that is the single
* largest avoidable proxy cost (~20 GB/15d) with zero ban risk: the widget
* still runs (served from here) and still fires its token XHR live.
*
* This is a URL-keyed byte cache with a hot in-memory layer and a best-effort
* disk layer (survives redeploys). Only versioned static assets are cached —
* their URLs carry a content hash / `?_=<ver>` so a bundle bump is a new URL
* (cache miss → refetched once), i.e. invalidation is automatic. The token XHR
* (`/v3/api/proxy/*`) and HTML documents are never cached; they stay live.
*/
import { createHash } from "node:crypto";
import { mkdir, readFile, writeFile } from "node:fs/promises";
import { tmpdir } from "node:os";
import { join } from "node:path";
export interface CachedAsset {
contentType: string;
body: Buffer;
}
export class PcatAssetCache {
private readonly dir: string;
private readonly mem = new Map<string, CachedAsset>();
private readonly maxMemEntries: number;
private readonly ready: Promise<void>;
constructor(opts: { dir?: string; maxMemEntries?: number } = {}) {
this.dir = opts.dir ?? join(tmpdir(), "pcat-asset-cache");
this.maxMemEntries = opts.maxMemEntries ?? 300;
this.ready = mkdir(this.dir, { recursive: true }).then(
() => undefined,
() => undefined,
);
}
/**
* Only versioned static JS/CSS is cacheable. Never the token/API path, never
* HTML documents (may carry a per-session nonce the token call needs).
*/
static isCacheable(resourceType: string, url: string): boolean {
if (resourceType !== "script" && resourceType !== "stylesheet") return false;
if (url.includes("/v3/api/proxy/")) return false;
return true;
}
private fileKey(url: string): string {
return createHash("sha1").update(url).digest("hex");
}
async get(url: string): Promise<CachedAsset | null> {
const hot = this.mem.get(url);
if (hot) return hot;
await this.ready;
const key = this.fileKey(url);
try {
const [meta, body] = await Promise.all([
readFile(join(this.dir, `${key}.json`), "utf8"),
readFile(join(this.dir, `${key}.bin`)),
]);
const asset: CachedAsset = { contentType: JSON.parse(meta).contentType, body };
this.remember(url, asset);
return asset;
} catch {
return null;
}
}
async put(url: string, contentType: string, body: Buffer): Promise<void> {
if (!body.length) return;
this.remember(url, { contentType, body });
await this.ready;
const key = this.fileKey(url);
try {
await Promise.all([
writeFile(join(this.dir, `${key}.bin`), body),
writeFile(join(this.dir, `${key}.json`), JSON.stringify({ contentType, url })),
]);
} catch {
// Disk is best-effort; the in-memory layer still serves this process.
}
}
private remember(url: string, asset: CachedAsset): void {
// Cheap FIFO bound — versioned URLs keep the working set small anyway.
if (this.mem.size >= this.maxMemEntries) {
const oldest = this.mem.keys().next().value;
if (oldest !== undefined) this.mem.delete(oldest);
}
this.mem.set(url, asset);
}
}

View File

@@ -30,6 +30,7 @@ import {
isProxyConnectFailure,
resolveExitIp,
} from "../proxy-telemetry/proxy-telemetry.service";
import { PcatAssetCache } from "./parts-catalogs-asset-cache";
import { JwtSlot, PcatJwtToken, PcatSession } from "./parts-catalogs.types";
// Shared single-slot cache so dev + prod (and any restarted container) can
@@ -195,6 +196,13 @@ export class PartsCatalogsAuthService implements OnModuleInit, OnModuleDestroy {
// the exact failure seen 2026-06-11 (Floxy 402) and 2026-07-03 (Floxy tunnel
// down). Disable with PCAT_CAPTURE_ALLOW_DIRECT=false.
private readonly captureAllowDirect: boolean;
// Exit-IP telemetry probe (one ipify call per capture). Off by default: it
// added ~54k billed proxy requests over 15 days for banned-IP telemetry only.
private readonly exitIpProbe: boolean;
// Cross-capture cache for the widget's static JS/CSS so each capture stops
// re-downloading ~2 MB of identical assets through the residential proxy.
// Null when disabled via PCAT_ASSET_CACHE=false (kill switch, no redeploy).
private readonly assetCache: PcatAssetCache | null;
constructor(
private configService: ConfigService,
@@ -216,13 +224,16 @@ export class PartsCatalogsAuthService implements OnModuleInit, OnModuleDestroy {
this.semaphore = new Semaphore(this.jwtSites.length);
// Provider selection. Back-compat: PCAT_USE_PROXY=false still forces direct.
const rawProvider = cfg.get<string>("PCAT_PROXY_PROVIDER", "floxy").toLowerCase();
// Default is dataimpulse: Floxy was retired 2026-07 (permanently down —
// balance/tunnel dead), so floxy-primary just burned a failed attempt per
// call before failing over. Set PCAT_PROXY_PROVIDER=floxy to re-enable it.
const rawProvider = cfg.get<string>("PCAT_PROXY_PROVIDER", "dataimpulse").toLowerCase();
const useProxy = cfg.get<string>("PCAT_USE_PROXY", "true") === "true";
this.proxyProvider = !useProxy
? "none"
: rawProvider === "dataimpulse" || rawProvider === "none"
: rawProvider === "floxy" || rawProvider === "none"
? (rawProvider as ProxyProvider)
: "floxy";
: "dataimpulse";
const toInt = (key: string, def: number): number => {
const n = Number(cfg.get(key, def));
@@ -242,6 +253,9 @@ export class PartsCatalogsAuthService implements OnModuleInit, OnModuleDestroy {
this.diHost = cfg.get<string>("PCAT_PROXY_HOST", DI_HOST);
this.diUser = cfg.get<string>("PCAT_PROXY_USER", DI_DEFAULT_USER);
this.diPass = cfg.get<string>("PCAT_PROXY_PASS", DI_DEFAULT_PASS);
this.exitIpProbe = cfg.get<string>("PCAT_EXIT_IP_PROBE", "false") === "true";
this.assetCache =
cfg.get<string>("PCAT_ASSET_CACHE", "true") === "true" ? new PcatAssetCache() : null;
this.captureAllowDirect =
cfg.get<string>("PCAT_CAPTURE_ALLOW_DIRECT", "true") !== "false" &&
@@ -806,7 +820,10 @@ export class PartsCatalogsAuthService implements OnModuleInit, OnModuleDestroy {
// The session is sticky, so a parallel ipify probe exits from the SAME IP
// the capture will use — that's what makes banned-IP tracking concrete.
// Resolves in ~1-2s while the capture itself takes 7s+; never throws.
const exitIpPromise = proxyUrl ? resolveExitIp(proxyUrl) : Promise.resolve(null);
// Gated off by default (PCAT_EXIT_IP_PROBE): the probe is billed proxy
// traffic and only feeds exit-IP telemetry, not the capture itself.
const exitIpPromise =
this.exitIpProbe && proxyUrl ? resolveExitIp(proxyUrl) : Promise.resolve(null);
const logCapture = (ok: boolean, errorKind?: string): void => {
void exitIpPromise.then((exitIp) =>
this.proxyTelemetry.record({
@@ -856,8 +873,15 @@ export class PartsCatalogsAuthService implements OnModuleInit, OnModuleDestroy {
this.logger.debug(`Token intercepted (key=${apiKey.slice(0, 16)}...)`);
});
// Block heavy resources to save proxy bandwidth
await page.route("**/*", (route) => {
// Block heavy resources to save proxy bandwidth. Kept intentionally
// minimal: an aggressive block (stylesheet + yastatic/font/ad domains)
// shipped 2026-07-16 killed token capture on prod (dataimpulse 425→0
// captures/h at deploy time — the RU catalog widget needs its CSS and
// Yandex-hosted runtime to init and fire the /v3/api/proxy XHR). Only
// block what the widget provably never needs: images, fonts, media, and
// a few pure analytics/ad domains.
const assetCache = this.assetCache;
await page.route("**/*", async (route) => {
const url = route.request().url();
const type = route.request().resourceType();
@@ -878,6 +902,29 @@ export class PartsCatalogsAuthService implements OnModuleInit, OnModuleDestroy {
return route.abort();
}
// Serve versioned static JS/CSS from the cross-capture cache; a hit
// costs zero proxy bytes. On miss, fetch once through the context proxy,
// store the decoded body, and serve it. Everything else (HTML document,
// the /v3/api/proxy token XHR, dynamic fetches) always goes live.
if (assetCache && PcatAssetCache.isCacheable(type, url)) {
const hit = await assetCache.get(url);
if (hit) {
return route.fulfill({ status: 200, contentType: hit.contentType, body: hit.body });
}
try {
const resp = await route.fetch({ timeout: 15_000 });
const body = await resp.body();
const contentType =
resp.headers()["content-type"] ??
(type === "script" ? "application/javascript" : "text/css");
if (resp.ok() && body.length) void assetCache.put(url, contentType, body);
return route.fulfill({ status: resp.status(), contentType, body });
} catch {
// Fetch failed (slow/dead proxy) — let the browser attempt it itself.
return route.continue();
}
}
return route.continue();
});

View File

@@ -0,0 +1,17 @@
<html><head>
<title>Ford WF0RXXGCDRAP80417: Kuga - CBV (2008, 2012) - partslink24</title>
<script>
</script></head><body>
<table>
<tr id="_nav-scope-table0" class="tc-row tc-data-row tc-selected" jsonurl="json-vin-main-group.action?lang=en&amp;openVinDialog=false&amp;startup=false&amp;vin=WF0RXXGCDRAP80417&amp;mode=A0LW0DEDE&amp;upds=2026.09.08+15%3A14%3A06+CEST" caption="Kuga - CBV (2008, 2012)"><td class="caption tc-lcell tc-rcell dynaheight"><div class="dynaheightWrapper"><div class="dblWrap">Kuga - CBV (2008, 2012)</div></div></td></tr>
<tr id="_nav-scope-table1" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?lang=en&amp;openVinDialog=false&amp;sharedCatCode=ZE&amp;startup=false&amp;vin=WF0RXXGCDRAP80417&amp;mode=A0LW0DEDE&amp;upds=2026.09.08+15%3A14%3A06+CEST" caption="ZE - Accessories (ZE)&lt;div class=&quot;restrictionBlockWithMargin&quot;&gt;&lt;/div&gt;"><td class="caption tc-lcell tc-rcell dynaheight"><div class="dynaheightWrapper"><div class="dblWrap">ZE - Accessories (ZE)<div class="restrictionBlockWithMargin"></div></div></div></td></tr>
<tr id="_nav-scope-table2" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?lang=en&amp;openVinDialog=false&amp;sharedCatCode=ZF&amp;startup=false&amp;vin=WF0RXXGCDRAP80417&amp;mode=A0LW0DEDE&amp;upds=2026.09.08+15%3A14%3A06+CEST" caption="ZF - Fluids &amp; Maintenance Products (ZF)&lt;div class=&quot;restrictionBlockWithMargin&quot;&gt;&lt;/div&gt;"><td class="caption tc-lcell tc-rcell dynaheight"><div class="dynaheightWrapper"><div class="dblWrap">ZF - Fluids &amp; Maintenance Products (ZF)<div class="restrictionBlockWithMargin"></div></div></div></td></tr>
<tr id="_nav-scope-table4" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?lang=en&amp;openVinDialog=false&amp;sharedCatCode=C20DD0X&amp;startup=false&amp;vin=WF0RXXGCDRAP80417&amp;mode=A0LW0DEDE&amp;upds=2026.09.08+15%3A14%3A06+CEST" caption="C20DD0X - 2.0 DI Diesel&lt;div class=&quot;restrictionBlockWithMargin&quot;&gt;&lt;span class=&quot;vinHit&quot; title=&quot;Attribute matches&quot;&gt;Engine Type = All 2.0L Duratorq Engines&amp;nbsp;&lt;/span&gt;&lt;/div&gt;"><td class="caption tc-lcell tc-rcell dynaheight"><div class="dynaheightWrapper"><div class="dblWrap">C20DD0X - 2.0 DI Diesel<div class="restrictionBlockWithMargin"><span class="vinHit" title="Attribute matches">Engine Type = All 2.0L Duratorq Engines&nbsp;</span></div></div></div></td></tr>
<tr id="_nav-scope-table5" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?lang=en&amp;openVinDialog=false&amp;sharedCatCode=CMPS6&amp;startup=false&amp;vin=WF0RXXGCDRAP80417&amp;mode=A0LW0DEDE&amp;upds=2026.09.08+15%3A14%3A06+CEST" caption="CMPS6 - 6 Speed Trans Powershift&lt;div class=&quot;restrictionBlockWithMargin&quot;&gt;&lt;span class=&quot;vinHit&quot; title=&quot;Attribute matches&quot;&gt;Transmission = 6 Speed Powershift 6DCT450 - MPS6&amp;nbsp;&lt;/span&gt;&lt;/div&gt;"><td class="caption tc-lcell tc-rcell dynaheight"><div class="dynaheightWrapper"><div class="dblWrap">CMPS6 - 6 Speed Trans Powershift<div class="restrictionBlockWithMargin"><span class="vinHit" title="Attribute matches">Transmission = 6 Speed Powershift 6DCT450 - MPS6&nbsp;</span></div></div></div></td></tr>
<tr id="_nav-scope-table6" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?lang=en&amp;openVinDialog=false&amp;sharedCatCode=CVPTO&amp;startup=false&amp;vin=WF0RXXGCDRAP80417&amp;mode=A0LW0DEDE&amp;upds=2026.09.08+15%3A14%3A06+CEST" caption="CVPTO - Transfer Case&lt;div class=&quot;restrictionBlockWithMargin&quot;&gt;&lt;span class=&quot;vinHit&quot; title=&quot;Attribute matches&quot;&gt;Transmission = 6 Speed Powershift 6DCT450 - MPS6&amp;nbsp;&lt;/span&gt;&lt;/div&gt;"><td class="caption tc-lcell tc-rcell dynaheight"><div class="dynaheightWrapper"><div class="dblWrap">CVPTO - Transfer Case<div class="restrictionBlockWithMargin"><span class="vinHit" title="Attribute matches">Transmission = 6 Speed Powershift 6DCT450 - MPS6&nbsp;</span></div></div></div></td></tr>
<tr class="tc-row tc-data-row " id="_nav-maingroup-table0"><td class="tc-lcell identifier">1</td><td class="tc-rcell caption">Information And Customisation</td></tr>
<tr class="tc-row tc-data-row " id="_nav-maingroup-table1"><td class="tc-lcell identifier">2</td><td class="tc-rcell caption">Chassis</td></tr>
<tr class="tc-row tc-data-row " id="_nav-maingroup-table2"><td class="tc-lcell identifier">4</td><td class="tc-rcell caption">Electrical</td></tr>
<tr class="tc-row tc-data-row " id="_nav-maingroup-table3"><td class="tc-lcell identifier">5</td><td class="tc-rcell caption">Body And Paint</td></tr>
</table></body></html>

View File

@@ -0,0 +1,13 @@
<html><head>
<title>Hyundai KMHCT41BAGU283791: ACCENT 15 - partslink24</title>
<script>
</script></head><body>
<table>
<tr id="_nav-mainGroup-table0" class="tc-row tc-data-row " url="vin-group.action?lang=en&amp;mainGroup=BO&amp;openVinDialog=false&amp;startup=false&amp;vin=KMHCT41BAGU283791&amp;mode=A0LW0DEDE&amp;upds=2026.09.05+11%3A12%3A58+CEST"><td class="mainGroup identifier tc-lcell"><a class="unlink">BO</a></td><td class="mainGroup caption tc-rcell"><a class="unlink">BODY</a></td></tr>
<tr id="_nav-mainGroup-table1" class="tc-row tc-data-row " url="vin-group.action?lang=en&amp;mainGroup=CH&amp;openVinDialog=false&amp;startup=false&amp;vin=KMHCT41BAGU283791&amp;mode=A0LW0DEDE&amp;upds=2026.09.05+11%3A12%3A58+CEST"><td class="mainGroup identifier tc-lcell"><a class="unlink">CH</a></td><td class="mainGroup caption tc-rcell"><a class="unlink">CHASSIS</a></td></tr>
<tr id="_nav-mainGroup-table2" class="tc-row tc-data-row " url="vin-group.action?lang=en&amp;mainGroup=EL&amp;openVinDialog=false&amp;startup=false&amp;vin=KMHCT41BAGU283791&amp;mode=A0LW0DEDE&amp;upds=2026.09.05+11%3A12%3A58+CEST"><td class="mainGroup identifier tc-lcell"><a class="unlink">EL</a></td><td class="mainGroup caption tc-rcell"><a class="unlink">ELECTRIC</a></td></tr>
<tr id="_nav-mainGroup-table3" class="tc-row tc-data-row " url="vin-group.action?lang=en&amp;mainGroup=EN&amp;openVinDialog=false&amp;startup=false&amp;vin=KMHCT41BAGU283791&amp;mode=A0LW0DEDE&amp;upds=2026.09.05+11%3A12%3A58+CEST"><td class="mainGroup identifier tc-lcell"><a class="unlink">EN</a></td><td class="mainGroup caption tc-rcell"><a class="unlink">ENGINE</a></td></tr>
<tr id="_nav-mainGroup-table4" class="tc-row tc-data-row " url="vin-group.action?lang=en&amp;mainGroup=MI&amp;openVinDialog=false&amp;startup=false&amp;vin=KMHCT41BAGU283791&amp;mode=A0LW0DEDE&amp;upds=2026.09.05+11%3A12%3A58+CEST"><td class="mainGroup identifier tc-lcell"><a class="unlink">MI</a></td><td class="mainGroup caption tc-rcell"><a class="unlink">TRANSMISSION</a></td></tr>
<tr id="_nav-mainGroup-table5" class="tc-row tc-data-row " url="vin-group.action?lang=en&amp;mainGroup=TR&amp;openVinDialog=false&amp;startup=false&amp;vin=KMHCT41BAGU283791&amp;mode=A0LW0DEDE&amp;upds=2026.09.05+11%3A12%3A58+CEST"><td class="mainGroup identifier tc-lcell"><a class="unlink">TR</a></td><td class="mainGroup caption tc-rcell"><a class="unlink">TRIM</a></td></tr>
</table></body></html>

View File

@@ -0,0 +1,109 @@
<html><head>
<title>Nissan - partslink24</title>
<script>
</script></head><body>
<table>
<tr id="_nav-model-table1" class="tc-row tc-data-row " caption="Repair &amp; Maintenance Information" ident="" urltype="EXTERN" url="https://eu.nissan.biz/" jsonurl="https://eu.nissan.biz/"><td colspan="2" class="model caption tc-rcell"><a class="unlink">Repair &amp; Maintenance Information</a></td></tr>
<tr id="_nav-model-table3" class="tc-row tc-data-row " caption="200SX (EL)" ident="S14_097_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=S14_097_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=S14_097_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">S14</td><td class="model caption tc-rcell"><a class="unlink">200SX</a></td></tr>
<tr id="_nav-model-table4" class="tc-row tc-data-row " caption="350Z (EL)" ident="Z33_007_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Z33_007_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Z33_007_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Z33</td><td class="model caption tc-rcell"><a class="unlink">350Z</a></td></tr>
<tr id="_nav-model-table5" class="tc-row tc-data-row " caption="370Z (EL)" ident="Z34_042_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Z34_042_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Z34_042_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Z34</td><td class="model caption tc-rcell"><a class="unlink">370Z</a></td></tr>
<tr id="_nav-model-table6" class="tc-row tc-data-row " caption="ALMERA (EL)" ident="B10RS_016_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=B10RS_016_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=B10RS_016_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">B10RS</td><td class="model caption tc-rcell"><a class="unlink">ALMERA</a></td></tr>
<tr id="_nav-model-table7" class="tc-row tc-data-row " caption="ALMERA (EL)" ident="G15RA_110_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=G15RA_110_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=G15RA_110_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">G15RA</td><td class="model caption tc-rcell"><a class="unlink">ALMERA</a></td></tr>
<tr id="_nav-model-table8" class="tc-row tc-data-row " caption="ALMERA (EL)" ident="N15_088_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=N15_088_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=N15_088_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">N15</td><td class="model caption tc-rcell"><a class="unlink">ALMERA</a></td></tr>
<tr id="_nav-model-table9" class="tc-row tc-data-row " caption="ALMERA JPN MAKE (EL)" ident="N16_298_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=N16_298_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=N16_298_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">N16</td><td class="model caption tc-rcell"><a class="unlink">ALMERA JPN MAKE</a></td></tr>
<tr id="_nav-model-table10" class="tc-row tc-data-row " caption="ALMERA TINO (EL)" ident="V10M_302_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=V10M_302_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=V10M_302_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">V10M</td><td class="model caption tc-rcell"><a class="unlink">ALMERA TINO</a></td></tr>
<tr id="_nav-model-table11" class="tc-row tc-data-row " caption="ALMERA UK MAKE (EL)" ident="N16E_307_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=N16E_307_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=N16E_307_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">N16E</td><td class="model caption tc-rcell"><a class="unlink">ALMERA UK MAKE</a></td></tr>
<tr id="_nav-model-table12" class="tc-row tc-data-row " caption="ALTIMA (EL)" ident="L33_138_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=L33_138_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=L33_138_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">L33</td><td class="model caption tc-rcell"><a class="unlink">ALTIMA</a></td></tr>
<tr id="_nav-model-table13" class="tc-row tc-data-row " caption="ALTIMA (EL)" ident="L34_155_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=L34_155_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=L34_155_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">L34</td><td class="model caption tc-rcell"><a class="unlink">ALTIMA</a></td></tr>
<tr id="_nav-model-table14" class="tc-row tc-data-row " caption="ARIYA (EL)" ident="FE0_158_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=FE0_158_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=FE0_158_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">FE0</td><td class="model caption tc-rcell"><a class="unlink">ARIYA</a></td></tr>
<tr id="_nav-model-table15" class="tc-row tc-data-row " caption="ATLEON (EL)" ident="TK3_059_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=TK3_059_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=TK3_059_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">TK3</td><td class="model caption tc-rcell"><a class="unlink">ATLEON</a></td></tr>
<tr id="_nav-model-table16" class="tc-row tc-data-row " caption="CABSTAR (EL)" ident="F24M_021_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=F24M_021_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=F24M_021_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">F24M</td><td class="model caption tc-rcell"><a class="unlink">CABSTAR</a></td></tr>
<tr id="_nav-model-table17" class="tc-row tc-data-row " caption="CUBE (EL)" ident="Z12_047_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Z12_047_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Z12_047_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Z12</td><td class="model caption tc-rcell"><a class="unlink">CUBE</a></td></tr>
<tr id="_nav-model-table18" class="tc-row tc-data-row " caption="DATSUN MI-DO (EL)" ident="HBD0R_149_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=HBD0R_149_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=HBD0R_149_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">HBD0R</td><td class="model caption tc-rcell"><a class="unlink">DATSUN MI-DO</a></td></tr>
<tr id="_nav-model-table19" class="tc-row tc-data-row " caption="DATSUN MI-DO (EL)" ident="HBD0_129_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=HBD0_129_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=HBD0_129_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">HBD0</td><td class="model caption tc-rcell"><a class="unlink">DATSUN MI-DO</a></td></tr>
<tr id="_nav-model-table20" class="tc-row tc-data-row " caption="DATSUN ON-DO (EL)" ident="BD0R_148_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=BD0R_148_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=BD0R_148_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">BD0R</td><td class="model caption tc-rcell"><a class="unlink">DATSUN ON-DO</a></td></tr>
<tr id="_nav-model-table21" class="tc-row tc-data-row " caption="DATSUN ON-DO (EL)" ident="BD0_121_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=BD0_121_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=BD0_121_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">BD0</td><td class="model caption tc-rcell"><a class="unlink">DATSUN ON-DO</a></td></tr>
<tr id="_nav-model-table22" class="tc-row tc-data-row " caption="E-NV200 SPAIN (EL)" ident="ME0M_122_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=ME0M_122_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=ME0M_122_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">ME0M</td><td class="model caption tc-rcell"><a class="unlink">E-NV200 SPAIN</a></td></tr>
<tr id="_nav-model-table23" class="tc-row tc-data-row " caption="GT-R (EL)" ident="R35_040_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=R35_040_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=R35_040_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">R35</td><td class="model caption tc-rcell"><a class="unlink">GT-R</a></td></tr>
<tr id="_nav-model-table24" class="tc-row tc-data-row " caption="HARDBODY (EL)" ident="D22S_014_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=D22S_014_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=D22S_014_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">D22S</td><td class="model caption tc-rcell"><a class="unlink">HARDBODY</a></td></tr>
<tr id="_nav-model-table25" class="tc-row tc-data-row " caption="INTERSTAR (EL)" ident="X70_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=X70_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=X70_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">X70</td><td class="model caption tc-rcell"><a class="unlink">INTERSTAR</a></td></tr>
<tr id="_nav-model-table26" class="tc-row tc-data-row " caption="INTERSTAR (EL)" ident="XDD_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=XDD_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=XDD_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">XDD</td><td class="model caption tc-rcell"><a class="unlink">INTERSTAR</a></td></tr>
<tr id="_nav-model-table27" class="tc-row tc-data-row " caption="INTERSTAR (EL)" ident="XDE_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=XDE_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=XDE_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">XDE</td><td class="model caption tc-rcell"><a class="unlink">INTERSTAR</a></td></tr>
<tr id="_nav-model-table28" class="tc-row tc-data-row " caption="JUKE (EL)" ident="F16E_157_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=F16E_157_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=F16E_157_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">F16E</td><td class="model caption tc-rcell"><a class="unlink">JUKE</a></td></tr>
<tr id="_nav-model-table29" class="tc-row tc-data-row " caption="JUKE JPN MAKE (EL)" ident="F15_052_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=F15_052_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=F15_052_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">F15</td><td class="model caption tc-rcell"><a class="unlink">JUKE JPN MAKE</a></td></tr>
<tr id="_nav-model-table30" class="tc-row tc-data-row " caption="JUKE UK MAKE (EL)" ident="F15E_056_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=F15E_056_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=F15E_056_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">F15E</td><td class="model caption tc-rcell"><a class="unlink">JUKE UK MAKE</a></td></tr>
<tr id="_nav-model-table31" class="tc-row tc-data-row " caption="KING CAB (EL)" ident="D22_073_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=D22_073_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=D22_073_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">D22</td><td class="model caption tc-rcell"><a class="unlink">KING CAB</a></td></tr>
<tr id="_nav-model-table32" class="tc-row tc-data-row " caption="KING CAB (EL)" ident="LCD22_030_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=LCD22_030_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=LCD22_030_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">LCD22</td><td class="model caption tc-rcell"><a class="unlink">KING CAB</a></td></tr>
<tr id="_nav-model-table33" class="tc-row tc-data-row " caption="KUBISTAR (EL)" ident="X76_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=X76_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=X76_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">X76</td><td class="model caption tc-rcell"><a class="unlink">KUBISTAR</a></td></tr>
<tr id="_nav-model-table34" class="tc-row tc-data-row " caption="LEAF (EL)" ident="ZE0_054_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=ZE0_054_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=ZE0_054_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">ZE0</td><td class="model caption tc-rcell"><a class="unlink">LEAF</a></td></tr>
<tr id="_nav-model-table35" class="tc-row tc-data-row " caption="LEAF UK MAKE (EL)" ident="ZE0E_111_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=ZE0E_111_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=ZE0E_111_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">ZE0E</td><td class="model caption tc-rcell"><a class="unlink">LEAF UK MAKE</a></td></tr>
<tr id="_nav-model-table36" class="tc-row tc-data-row " caption="LEAF UK MAKE (EL)" ident="ZE1E_152_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=ZE1E_152_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=ZE1E_152_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">ZE1E</td><td class="model caption tc-rcell"><a class="unlink">LEAF UK MAKE</a></td></tr>
<tr id="_nav-model-table37" class="tc-row tc-data-row " caption="LEAF UK MAKE (EL)" ident="ZE2E_166_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=ZE2E_166_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=ZE2E_166_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">ZE2E</td><td class="model caption tc-rcell"><a class="unlink">LEAF UK MAKE</a></td></tr>
<tr id="_nav-model-table38" class="tc-row tc-data-row " caption="MAXIMA (EL)" ident="A32_065_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=A32_065_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=A32_065_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">A32</td><td class="model caption tc-rcell"><a class="unlink">MAXIMA</a></td></tr>
<tr id="_nav-model-table39" class="tc-row tc-data-row " caption="MAXIMA (EL)" ident="A36_131_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=A36_131_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=A36_131_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">A36</td><td class="model caption tc-rcell"><a class="unlink">MAXIMA</a></td></tr>
<tr id="_nav-model-table40" class="tc-row tc-data-row " caption="MAXIMA (EL)" ident="CA33_305_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=CA33_305_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=CA33_305_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">CA33</td><td class="model caption tc-rcell"><a class="unlink">MAXIMA</a></td></tr>
<tr id="_nav-model-table41" class="tc-row tc-data-row " caption="MICRA (EL)" ident="K11E_081_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=K11E_081_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=K11E_081_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">K11E</td><td class="model caption tc-rcell"><a class="unlink">MICRA</a></td></tr>
<tr id="_nav-model-table42" class="tc-row tc-data-row " caption="MICRA (EL)" ident="K12E_005_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=K12E_005_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=K12E_005_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">K12E</td><td class="model caption tc-rcell"><a class="unlink">MICRA</a></td></tr>
<tr id="_nav-model-table43" class="tc-row tc-data-row " caption="MICRA (EL)" ident="K15_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=K15_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=K15_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">K15</td><td class="model caption tc-rcell"><a class="unlink">MICRA</a></td></tr>
<tr id="_nav-model-table44" class="tc-row tc-data-row " caption="MICRA C+C (EL)" ident="CK12E_012_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=CK12E_012_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=CK12E_012_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">CK12E</td><td class="model caption tc-rcell"><a class="unlink">MICRA C+C</a></td></tr>
<tr id="_nav-model-table45" class="tc-row tc-data-row " caption="MICRA FLIN MAKE (EL)" ident="K14FR_144_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=K14FR_144_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=K14FR_144_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">K14FR</td><td class="model caption tc-rcell"><a class="unlink">MICRA FLIN MAKE</a></td></tr>
<tr id="_nav-model-table46" class="tc-row tc-data-row " caption="MICRA IND MAKE (EL)" ident="K13KK_136_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=K13KK_136_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=K13KK_136_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">K13KK</td><td class="model caption tc-rcell"><a class="unlink">MICRA IND MAKE</a></td></tr>
<tr id="_nav-model-table47" class="tc-row tc-data-row " caption="MICRA IND MAKE (EL)" ident="K13K_051_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=K13K_051_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=K13K_051_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">K13K</td><td class="model caption tc-rcell"><a class="unlink">MICRA IND MAKE</a></td></tr>
<tr id="_nav-model-table48" class="tc-row tc-data-row " caption="MURANO (EL)" ident="Z50_008_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Z50_008_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Z50_008_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Z50</td><td class="model caption tc-rcell"><a class="unlink">MURANO</a></td></tr>
<tr id="_nav-model-table49" class="tc-row tc-data-row " caption="MURANO (EL)" ident="Z51_036_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Z51_036_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Z51_036_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Z51</td><td class="model caption tc-rcell"><a class="unlink">MURANO</a></td></tr>
<tr id="_nav-model-table50" class="tc-row tc-data-row " caption="MURANO RUS MAKE (EL)" ident="Z51R_057_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Z51R_057_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Z51R_057_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Z51R</td><td class="model caption tc-rcell"><a class="unlink">MURANO RUS MAKE</a></td></tr>
<tr id="_nav-model-table51" class="tc-row tc-data-row " caption="MURANO RUS MAKE (EL)" ident="Z52R_137_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Z52R_137_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Z52R_137_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Z52R</td><td class="model caption tc-rcell"><a class="unlink">MURANO RUS MAKE</a></td></tr>
<tr id="_nav-model-table52" class="tc-row tc-data-row " caption="NAVARA (EL)" ident="D40M_010_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=D40M_010_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=D40M_010_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">D40M</td><td class="model caption tc-rcell"><a class="unlink">NAVARA</a></td></tr>
<tr id="_nav-model-table53" class="tc-row tc-data-row " caption="NAVARA NP300 (EL)" ident="D23M_135_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=D23M_135_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=D23M_135_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">D23M</td><td class="model caption tc-rcell"><a class="unlink">NAVARA NP300</a></td></tr>
<tr id="_nav-model-table54" class="tc-row tc-data-row " caption="NOTE UK MAKE (EL)" ident="E11E_015_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=E11E_015_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=E11E_015_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">E11E</td><td class="model caption tc-rcell"><a class="unlink">NOTE UK MAKE</a></td></tr>
<tr id="_nav-model-table55" class="tc-row tc-data-row " caption="NOTE UK MAKE (EL)" ident="E12E_113_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=E12E_113_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=E12E_113_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">E12E</td><td class="model caption tc-rcell"><a class="unlink">NOTE UK MAKE</a></td></tr>
<tr id="_nav-model-table56" class="tc-row tc-data-row " caption="NP300 SAF MAKE (EL)" ident="D22SS_055_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=D22SS_055_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=D22SS_055_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">D22SS</td><td class="model caption tc-rcell"><a class="unlink">NP300 SAF MAKE</a></td></tr>
<tr id="_nav-model-table57" class="tc-row tc-data-row " caption="NV200 (EL)" ident="M20_046_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=M20_046_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=M20_046_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">M20</td><td class="model caption tc-rcell"><a class="unlink">NV200</a></td></tr>
<tr id="_nav-model-table58" class="tc-row tc-data-row " caption="NV200 SPAINMAKE (EL)" ident="M20M_050_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=M20M_050_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=M20M_050_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">M20M</td><td class="model caption tc-rcell"><a class="unlink">NV200 SPAINMAKE</a></td></tr>
<tr id="_nav-model-table59" class="tc-row tc-data-row " caption="NV250 (EL)" ident="X61_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=X61_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=X61_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">X61</td><td class="model caption tc-rcell"><a class="unlink">NV250</a></td></tr>
<tr id="_nav-model-table60" class="tc-row tc-data-row " caption="NV300/PRIMASTAR (EL)" ident="X82_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=X82_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=X82_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">X82</td><td class="model caption tc-rcell"><a class="unlink">NV300/PRIMASTAR</a></td></tr>
<tr id="_nav-model-table61" class="tc-row tc-data-row " caption="NV400 (EL)" ident="X62_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=X62_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=X62_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">X62</td><td class="model caption tc-rcell"><a class="unlink">NV400</a></td></tr>
<tr id="_nav-model-table62" class="tc-row tc-data-row " caption="NV400/INTERSTAR (EL)" ident="X62B_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=X62B_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=X62B_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">X62B</td><td class="model caption tc-rcell"><a class="unlink">NV400/INTERSTAR</a></td></tr>
<tr id="_nav-model-table63" class="tc-row tc-data-row " caption="PATHFINDER (EL)" ident="R51M_009_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=R51M_009_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=R51M_009_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">R51M</td><td class="model caption tc-rcell"><a class="unlink">PATHFINDER</a></td></tr>
<tr id="_nav-model-table64" class="tc-row tc-data-row " caption="PATHFINDER (EL)" ident="R52R_123_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=R52R_123_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=R52R_123_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">R52R</td><td class="model caption tc-rcell"><a class="unlink">PATHFINDER</a></td></tr>
<tr id="_nav-model-table65" class="tc-row tc-data-row " caption="PATHFINDER (EL)" ident="R53_159_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=R53_159_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=R53_159_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">R53</td><td class="model caption tc-rcell"><a class="unlink">PATHFINDER</a></td></tr>
<tr id="_nav-model-table66" class="tc-row tc-data-row " caption="PATHFINDER RUS (EL)" ident="R52RR_132_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=R52RR_132_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=R52RR_132_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">R52RR</td><td class="model caption tc-rcell"><a class="unlink">PATHFINDER RUS</a></td></tr>
<tr id="_nav-model-table67" class="tc-row tc-data-row " caption="PATROL (EL)" ident="Y62_048_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Y62_048_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Y62_048_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Y62</td><td class="model caption tc-rcell"><a class="unlink">PATROL</a></td></tr>
<tr id="_nav-model-table68" class="tc-row tc-data-row " caption="PATROL(GR) (EL)" ident="Y61_107_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Y61_107_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Y61_107_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Y61</td><td class="model caption tc-rcell"><a class="unlink">PATROL(GR)</a></td></tr>
<tr id="_nav-model-table69" class="tc-row tc-data-row " caption="PIXO (EL)" ident="UA0_043_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=UA0_043_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=UA0_043_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">UA0</td><td class="model caption tc-rcell"><a class="unlink">PIXO</a></td></tr>
<tr id="_nav-model-table70" class="tc-row tc-data-row " caption="PRIMASTAR (EL)" ident="X83_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=X83_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=X83_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">X83</td><td class="model caption tc-rcell"><a class="unlink">PRIMASTAR</a></td></tr>
<tr id="_nav-model-table71" class="tc-row tc-data-row " caption="PRIMERA (EL)" ident="P11E_090_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=P11E_090_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=P11E_090_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">P11E</td><td class="model caption tc-rcell"><a class="unlink">PRIMERA</a></td></tr>
<tr id="_nav-model-table72" class="tc-row tc-data-row " caption="PRIMERA (EL)" ident="P12E_001_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=P12E_001_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=P12E_001_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">P12E</td><td class="model caption tc-rcell"><a class="unlink">PRIMERA</a></td></tr>
<tr id="_nav-model-table73" class="tc-row tc-data-row " caption="PRIMERA WAGON (EL)" ident="W10_102_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=W10_102_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=W10_102_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">W10</td><td class="model caption tc-rcell"><a class="unlink">PRIMERA WAGON</a></td></tr>
<tr id="_nav-model-table74" class="tc-row tc-data-row " caption="PRIMERA WAGON (EL)" ident="WP11E_104_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=WP11E_104_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=WP11E_104_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">WP11E</td><td class="model caption tc-rcell"><a class="unlink">PRIMERA WAGON</a></td></tr>
<tr id="_nav-model-table75" class="tc-row tc-data-row " caption="PULSAR (EL)" ident="C13M_124_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=C13M_124_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=C13M_124_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">C13M</td><td class="model caption tc-rcell"><a class="unlink">PULSAR</a></td></tr>
<tr id="_nav-model-table76" class="tc-row tc-data-row " caption="QASHQAI (EL)" ident="J10E_023_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=J10E_023_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=J10E_023_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">J10E</td><td class="model caption tc-rcell"><a class="unlink">QASHQAI</a></td></tr>
<tr id="_nav-model-table77" class="tc-row tc-data-row " caption="QASHQAI (EL)" ident="J12E_160_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=J12E_160_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=J12E_160_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">J12E</td><td class="model caption tc-rcell"><a class="unlink">QASHQAI</a></td></tr>
<tr id="_nav-model-table78" class="tc-row tc-data-row " caption="QASHQAI RUSSIA (EL)" ident="J11R_134_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=J11R_134_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=J11R_134_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">J11R</td><td class="model caption tc-rcell"><a class="unlink">QASHQAI RUSSIA</a></td></tr>
<tr id="_nav-model-table79" class="tc-row tc-data-row " caption="QASHQAI UK MAKE (EL)" ident="J11E_120_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=J11E_120_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=J11E_120_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">J11E</td><td class="model caption tc-rcell"><a class="unlink">QASHQAI UK MAKE</a></td></tr>
<tr id="_nav-model-table80" class="tc-row tc-data-row " caption="QASHQAI+2 (EL)" ident="JJ10E_038_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=JJ10E_038_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=JJ10E_038_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">JJ10E</td><td class="model caption tc-rcell"><a class="unlink">QASHQAI+2</a></td></tr>
<tr id="_nav-model-table81" class="tc-row tc-data-row " caption="SENTRA RUS MAKE (EL)" ident="B17RR_126_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=B17RR_126_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=B17RR_126_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">B17RR</td><td class="model caption tc-rcell"><a class="unlink">SENTRA RUS MAKE</a></td></tr>
<tr id="_nav-model-table82" class="tc-row tc-data-row " caption="SENTRA RUS MAKE (EL)" ident="B17R_125_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=B17R_125_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=B17R_125_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">B17R</td><td class="model caption tc-rcell"><a class="unlink">SENTRA RUS MAKE</a></td></tr>
<tr id="_nav-model-table83" class="tc-row tc-data-row " caption="SERENA (EL)" ident="C23M_070_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=C23M_070_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=C23M_070_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">C23M</td><td class="model caption tc-rcell"><a class="unlink">SERENA</a></td></tr>
<tr id="_nav-model-table84" class="tc-row tc-data-row " caption="SUNNY WAGON (EL)" ident="Y10_105_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=Y10_105_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=Y10_105_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">Y10</td><td class="model caption tc-rcell"><a class="unlink">SUNNY WAGON</a></td></tr>
<tr id="_nav-model-table85" class="tc-row tc-data-row " caption="TEANA (EL)" ident="J31_017_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=J31_017_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=J31_017_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">J31</td><td class="model caption tc-rcell"><a class="unlink">TEANA</a></td></tr>
<tr id="_nav-model-table86" class="tc-row tc-data-row " caption="TEANA (EL)" ident="J32_031_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=J32_031_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=J32_031_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">J32</td><td class="model caption tc-rcell"><a class="unlink">TEANA</a></td></tr>
<tr id="_nav-model-table87" class="tc-row tc-data-row " caption="TEANA RUS MAKE (EL)" ident="J32R_041_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=J32R_041_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=J32R_041_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">J32R</td><td class="model caption tc-rcell"><a class="unlink">TEANA RUS MAKE</a></td></tr>
<tr id="_nav-model-table88" class="tc-row tc-data-row " caption="TEANA RUS MAKE (EL)" ident="L33R_118_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=L33R_118_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=L33R_118_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">L33R</td><td class="model caption tc-rcell"><a class="unlink">TEANA RUS MAKE</a></td></tr>
<tr id="_nav-model-table89" class="tc-row tc-data-row " caption="TERRANO (EL)" ident="D10_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=D10_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=D10_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">D10</td><td class="model caption tc-rcell"><a class="unlink">TERRANO</a></td></tr>
<tr id="_nav-model-table90" class="tc-row tc-data-row " caption="TERRANO (EL)" ident="R50_092_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=R50_092_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=R50_092_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">R50</td><td class="model caption tc-rcell"><a class="unlink">TERRANO</a></td></tr>
<tr id="_nav-model-table91" class="tc-row tc-data-row " caption="TERRANO2 (EL)" ident="R20_091_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=R20_091_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=R20_091_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">R20</td><td class="model caption tc-rcell"><a class="unlink">TERRANO2</a></td></tr>
<tr id="_nav-model-table92" class="tc-row tc-data-row " caption="TIIDA (EL)" ident="C11X_028_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=C11X_028_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=C11X_028_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">C11X</td><td class="model caption tc-rcell"><a class="unlink">TIIDA</a></td></tr>
<tr id="_nav-model-table93" class="tc-row tc-data-row " caption="TIIDA RUS MAKE (EL)" ident="C13R_128_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=C13R_128_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=C13R_128_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">C13R</td><td class="model caption tc-rcell"><a class="unlink">TIIDA RUS MAKE</a></td></tr>
<tr id="_nav-model-table94" class="tc-row tc-data-row " caption="TIIDA SEDAN (EL)" ident="SC11X_024_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=SC11X_024_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=SC11X_024_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">SC11X</td><td class="model caption tc-rcell"><a class="unlink">TIIDA SEDAN</a></td></tr>
<tr id="_nav-model-table95" class="tc-row tc-data-row " caption="TOWNSTAR/e-TOWNSTAR (EL)" ident="XFK_EL" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=XFK_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=XFK_EL&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">XFK</td><td class="model caption tc-rcell"><a class="unlink">TOWNSTAR/e-TOWNSTAR</a></td></tr>
<tr id="_nav-model-table96" class="tc-row tc-data-row " caption="X-TRAIL (EL)" ident="AGT32_151_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=AGT32_151_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=AGT32_151_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">AGT32</td><td class="model caption tc-rcell"><a class="unlink">X-TRAIL</a></td></tr>
<tr id="_nav-model-table97" class="tc-row tc-data-row " caption="X-TRAIL (EL)" ident="T30_002_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=T30_002_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=T30_002_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">T30</td><td class="model caption tc-rcell"><a class="unlink">X-TRAIL</a></td></tr>
<tr id="_nav-model-table98" class="tc-row tc-data-row " caption="X-TRAIL (EL)" ident="T32_117_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=T32_117_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=T32_117_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">T32</td><td class="model caption tc-rcell"><a class="unlink">X-TRAIL</a></td></tr>
<tr id="_nav-model-table99" class="tc-row tc-data-row " caption="X-TRAIL (EL)" ident="T33_163_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=T33_163_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=T33_163_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">T33</td><td class="model caption tc-rcell"><a class="unlink">X-TRAIL</a></td></tr>
<tr id="_nav-model-table100" class="tc-row tc-data-row " caption="X-TRAIL JPNMAKE (EL)" ident="T31_026_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=T31_026_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=T31_026_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">T31</td><td class="model caption tc-rcell"><a class="unlink">X-TRAIL JPNMAKE</a></td></tr>
<tr id="_nav-model-table101" class="tc-row tc-data-row " caption="X-TRAIL RUSMAKE (EL)" ident="T31R_045_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=T31R_045_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=T31R_045_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">T31R</td><td class="model caption tc-rcell"><a class="unlink">X-TRAIL RUSMAKE</a></td></tr>
<tr id="_nav-model-table102" class="tc-row tc-data-row " caption="X-TRAIL RUSMAKE (EL)" ident="T32RR_140_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=T32RR_140_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=T32RR_140_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">T32RR</td><td class="model caption tc-rcell"><a class="unlink">X-TRAIL RUSMAKE</a></td></tr>
<tr id="_nav-model-table103" class="tc-row tc-data-row " caption="X-TRAIL RUSMAKE (EL)" ident="T32R_127_3" urltype="INTERN" url="vehicle.action?lang=en&amp;localMarketOnly=true&amp;model=T32R_127_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST" jsonurl="json-model-config.action?lang=en&amp;localMarketOnly=true&amp;model=T32R_127_3&amp;spec=e30%3D&amp;startup=false&amp;mode=A0LW0DEDE&amp;upds=2026.09.02+10%3A52%3A21+CEST"><td class="model identifier tc-lcell">T32R</td><td class="model caption tc-rcell"><a class="unlink">X-TRAIL RUSMAKE</a></td></tr>
</table></body></html>

View File

@@ -0,0 +1,38 @@
<html><head>
<title>Opel W0LPD5EC9EG058575: P10 - ASTRA-J [2010-2020] - partslink24</title>
<script>
</script></head><body>
<table>
<tr id="_nav-mainGroup-table0" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=394&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="BODY SHELL AND PANELS" ident="394" maingroupcode="A"><td class="mainGroupCode tc-lcell ">A</td><td class="caption tc-rcell ">BODY SHELL AND PANELS</td></tr>
<tr id="_nav-mainGroup-table1" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=395&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="BODY EXTERIOR FITTINGS" ident="395" maingroupcode="B"><td class="mainGroupCode tc-lcell ">B</td><td class="caption tc-rcell ">BODY EXTERIOR FITTINGS</td></tr>
<tr id="_nav-mainGroup-table2" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=396&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="BODY INTERIOR FITTINGS" ident="396" maingroupcode="C"><td class="mainGroupCode tc-lcell ">C</td><td class="caption tc-rcell ">BODY INTERIOR FITTINGS</td></tr>
<tr id="_nav-mainGroup-table3" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=397&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="BODY INTERIOR TRIM" ident="397" maingroupcode="D"><td class="mainGroupCode tc-lcell ">D</td><td class="caption tc-rcell ">BODY INTERIOR TRIM</td></tr>
<tr id="_nav-mainGroup-table4" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=398&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="ENGINE AND CLUTCH" ident="398" maingroupcode="E"><td class="mainGroupCode tc-lcell ">E</td><td class="caption tc-rcell ">ENGINE AND CLUTCH</td></tr>
<tr id="_nav-mainGroup-table5" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=399&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="COOLING" ident="399" maingroupcode="F"><td class="mainGroupCode tc-lcell ">F</td><td class="caption tc-rcell ">COOLING</td></tr>
<tr id="_nav-mainGroup-table6" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=400&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="FUEL AND EXHAUST" ident="400" maingroupcode="G"><td class="mainGroupCode tc-lcell ">G</td><td class="caption tc-rcell ">FUEL AND EXHAUST</td></tr>
<tr id="_nav-mainGroup-table7" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=401&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="TRANSMISSION" ident="401" maingroupcode="H"><td class="mainGroupCode tc-lcell ">H</td><td class="caption tc-rcell ">TRANSMISSION</td></tr>
<tr id="_nav-mainGroup-table8" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=402&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="BRAKES" ident="402" maingroupcode="J"><td class="mainGroupCode tc-lcell ">J</td><td class="caption tc-rcell ">BRAKES</td></tr>
<tr id="_nav-mainGroup-table9" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=403&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="FRONT AXLE AND SUSPENSION" ident="403" maingroupcode="K"><td class="mainGroupCode tc-lcell ">K</td><td class="caption tc-rcell ">FRONT AXLE AND SUSPENSION</td></tr>
<tr id="_nav-mainGroup-table10" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=404&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="STEERING" ident="404" maingroupcode="L"><td class="mainGroupCode tc-lcell ">L</td><td class="caption tc-rcell ">STEERING</td></tr>
<tr id="_nav-mainGroup-table11" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=405&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="REAR AXLE AND SUSPENSION" ident="405" maingroupcode="M"><td class="mainGroupCode tc-lcell ">M</td><td class="caption tc-rcell ">REAR AXLE AND SUSPENSION</td></tr>
<tr id="_nav-mainGroup-table12" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=406&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="ROAD WHEELS" ident="406" maingroupcode="N"><td class="mainGroupCode tc-lcell ">N</td><td class="caption tc-rcell ">ROAD WHEELS</td></tr>
<tr id="_nav-mainGroup-table13" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=407&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="ELECTRICAL" ident="407" maingroupcode="P"><td class="mainGroupCode tc-lcell ">P</td><td class="caption tc-rcell ">ELECTRICAL</td></tr>
<tr id="_nav-mainGroup-table14" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=408&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="ACCESSORIES" ident="408" maingroupcode="Q"><td class="mainGroupCode tc-lcell ">Q</td><td class="caption tc-rcell ">ACCESSORIES</td></tr>
<tr id="_nav-mainGroup-table15" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=409&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="SPECIAL OPTIONS / DUAL FUEL" ident="409" maingroupcode="R"><td class="mainGroupCode tc-lcell ">R</td><td class="caption tc-rcell ">SPECIAL OPTIONS / DUAL FUEL</td></tr>
<tr id="_nav-mainGroup-table16" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=410&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="PAINTS" ident="410" maingroupcode="Z"><td class="mainGroupCode tc-lcell ">Z</td><td class="caption tc-rcell ">PAINTS</td></tr>
<tr id="_nav-mainGroup-table18" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=741&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="PAINTS" ident="741" maingroupcode="1"><td class="mainGroupCode tc-lcell ">1</td><td class="caption tc-rcell ">PAINTS</td></tr>
<tr id="_nav-mainGroup-table19" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=742&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="WIRING HARNESS REPAIR KITS" ident="742" maingroupcode="2"><td class="mainGroupCode tc-lcell ">2</td><td class="caption tc-rcell ">WIRING HARNESS REPAIR KITS</td></tr>
<tr id="_nav-mainGroup-table20" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=743&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="CAR CARE MATERIALS" ident="743" maingroupcode="3"><td class="mainGroupCode tc-lcell ">3</td><td class="caption tc-rcell ">CAR CARE MATERIALS</td></tr>
<tr id="_nav-mainGroup-table21" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=744&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="ADHESIVES / REPAIR KITS" ident="744" maingroupcode="4"><td class="mainGroupCode tc-lcell ">4</td><td class="caption tc-rcell ">ADHESIVES / REPAIR KITS</td></tr>
<tr id="_nav-mainGroup-table22" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=745&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="ANTI-FREEZE AND COOLANT" ident="745" maingroupcode="5"><td class="mainGroupCode tc-lcell ">5</td><td class="caption tc-rcell ">ANTI-FREEZE AND COOLANT</td></tr>
<tr id="_nav-mainGroup-table23" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=746&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="BODY REPAIR MATERIALS" ident="746" maingroupcode="6"><td class="mainGroupCode tc-lcell ">6</td><td class="caption tc-rcell ">BODY REPAIR MATERIALS</td></tr>
<tr id="_nav-mainGroup-table24" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=747&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="BRAKE AND CLUTCH FLUID" ident="747" maingroupcode="7"><td class="mainGroupCode tc-lcell ">7</td><td class="caption tc-rcell ">BRAKE AND CLUTCH FLUID</td></tr>
<tr id="_nav-mainGroup-table25" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=748&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="OIL" ident="748" maingroupcode="8"><td class="mainGroupCode tc-lcell ">8</td><td class="caption tc-rcell ">OIL</td></tr>
<tr id="_nav-mainGroup-table26" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=749&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="GREASES AND PASTES" ident="749" maingroupcode="9"><td class="mainGroupCode tc-lcell ">9</td><td class="caption tc-rcell ">GREASES AND PASTES</td></tr>
<tr id="_nav-mainGroup-table27" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=750&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="SEALANT" ident="750" maingroupcode="A"><td class="mainGroupCode tc-lcell ">A</td><td class="caption tc-rcell ">SEALANT</td></tr>
<tr id="_nav-mainGroup-table28" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=751&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="TOOLS AND PERSONAL PROTECTION" ident="751" maingroupcode="B"><td class="mainGroupCode tc-lcell ">B</td><td class="caption tc-rcell ">TOOLS AND PERSONAL PROTECTION</td></tr>
<tr id="_nav-mainGroup-table29" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=752&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="MISCELLANEOUS" ident="752" maingroupcode="C"><td class="mainGroupCode tc-lcell ">C</td><td class="caption tc-rcell ">MISCELLANEOUS</td></tr>
<tr id="_nav-mainGroup-table30" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=753&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="EMISSION CONTROL FLUID / FUEL ADDITIVES" ident="753" maingroupcode="D"><td class="mainGroupCode tc-lcell ">D</td><td class="caption tc-rcell ">EMISSION CONTROL FLUID / FUEL ADDITIVES</td></tr>
<tr id="_nav-mainGroup-table31" class="tc-row tc-data-row " jsonurl="json-vin-main-group.action?catId=25&amp;lang=en&amp;mainGroupId=754&amp;openVinDialog=true&amp;startup=false&amp;subGroupId=0&amp;vin=W0LPD5EC9EG058575&amp;mode=A0LW0DEDE&amp;upds=2026.09.07+21%3A00%3A03+CEST" caption="DIAGNOSTIC DEVICES" ident="754" maingroupcode="S"><td class="mainGroupCode tc-lcell ">S</td><td class="caption tc-rcell ">DIAGNOSTIC DEVICES</td></tr>
</table></body></html>

View File

@@ -0,0 +1,198 @@
{
"link": {
"wid": "mainGroupTable",
"path": "/p5volvo/extern/groups/vin/mainGroup?lang=en&model=308&modelYear=1620&partnerGroup=46&serviceName=volvo_parts&upds=2026-08-24--11-02&vin=YV1AS84ABD1168166"
},
"segments": {
"vinfoBasic": {
"records": [
{
"values": {
"description": "Vehicle Identification No.",
"value": "YV1AS84ABD1168166"
}
},
{
"values": {
"description": "Year",
"value": "2013"
}
},
{
"values": {
"description": "Model",
"value": "S80 (07\\-)"
}
},
{
"values": {
"description": "Km/h or mph",
"value": "K"
}
},
{
"values": {
"description": "Factory code",
"value": "21"
}
},
{
"values": {
"description": "Steering gear prod no",
"value": "31360538"
}
},
{
"values": {
"description": "Structure week",
"value": "201236"
}
},
{
"values": {
"description": "Type",
"value": "S80"
}
},
{
"values": {
"description": "Chassis",
"value": "168166"
}
},
{
"values": {
"description": "Partner group",
"value": "Europe"
}
},
{
"values": {
"description": "Upholstery/interior code",
"value": "210100"
}
},
{
"values": {
"description": "Upholstery/interior",
"value": "LEATHER/ANTHR/QRTZCEIL/NV"
}
},
{
"values": {
"description": "Exterior color",
"value": "61400"
}
},
{
"values": {
"description": "Exterior color",
"value": "WHITE SOLID ICE WHITE"
}
},
{
"values": {
"description": "Body style code",
"value": "0"
}
},
{
"values": {
"description": "Body style",
"value": "Sedan"
}
},
{
"values": {
"description": "Special vehicle code",
"value": " "
}
},
{
"values": {
"description": "Special vehicles",
"value": " "
}
},
{
"values": {
"description": "Sales type",
"value": "42"
}
},
{
"values": {
"description": "Sales type",
"value": "SALES VERSION 42"
}
},
{
"values": {
"description": "Market code",
"value": "49"
}
},
{
"values": {
"description": "Market",
"value": "TR"
}
},
{
"values": {
"description": "Engine Code",
"value": "84"
}
},
{
"values": {
"description": "Engine",
"value": "D4162T"
}
},
{
"values": {
"description": "Engine part no",
"value": "6906309"
}
},
{
"values": {
"description": "Engine serial no",
"value": "00000000000004138845 / 0ELD61 2208122233587"
}
},
{
"values": {
"description": "Transmission Code",
"value": "B"
}
},
{
"values": {
"description": "Transmission",
"value": "6\\-PSHIFT 2WD / MPS6"
}
},
{
"values": {
"description": "Transmission part no",
"value": "1285041"
}
},
{
"values": {
"description": "Transmission serial no",
"value": "00AWBB1 170812170654"
}
},
{
"values": {
"description": "Chassis code",
"value": "35659B7A6276"
}
}
]
}
}
}

View File

@@ -0,0 +1,198 @@
{
"link": {
"wid": "mainGroupTable",
"path": "/p5volvo/extern/groups/vin/mainGroup?lang=tr&model=308&modelYear=1620&partnerGroup=46&serviceName=volvo_parts&upds=2026-08-24--11-02&vin=YV1AS84ABD1168166"
},
"segments": {
"vinfoBasic": {
"records": [
{
"values": {
"description": "Sasi numarasi",
"value": "YV1AS84ABD1168166"
}
},
{
"values": {
"description": "Model yili",
"value": "2013"
}
},
{
"values": {
"description": "Model",
"value": "S80 (07\\-)"
}
},
{
"values": {
"description": "Hız Birimi",
"value": "K"
}
},
{
"values": {
"description": "Fabrika Kodu",
"value": "21"
}
},
{
"values": {
"description": "Direksiyon Kutusu Üretim No",
"value": "31360538"
}
},
{
"values": {
"description": "Üretim Haftası",
"value": "201236"
}
},
{
"values": {
"description": "Türü",
"value": "S80"
}
},
{
"values": {
"description": "Şasi",
"value": "168166"
}
},
{
"values": {
"description": "Ortak grubu",
"value": "Europe"
}
},
{
"values": {
"description": "Döşeme/iç mekan kodu",
"value": "210100"
}
},
{
"values": {
"description": "Döşeme",
"value": "LEATHER/ANTHR/QRTZCEIL/NV"
}
},
{
"values": {
"description": "Dis rengi",
"value": "61400"
}
},
{
"values": {
"description": "Dis rengi",
"value": "WHITE SOLID ICE WHITE"
}
},
{
"values": {
"description": "Karoseri Tipi Kodu",
"value": "0"
}
},
{
"values": {
"description": "Kaporta Stili",
"value": "Sedan"
}
},
{
"values": {
"description": "Özel Araç Kodu",
"value": " "
}
},
{
"values": {
"description": "Özel araçlar",
"value": " "
}
},
{
"values": {
"description": "Satis tipi",
"value": "42"
}
},
{
"values": {
"description": "Satis tipi",
"value": "SALES VERSION 42"
}
},
{
"values": {
"description": "Piyasa Kodu",
"value": "49"
}
},
{
"values": {
"description": "Market",
"value": "TR"
}
},
{
"values": {
"description": "Motor kodu",
"value": "84"
}
},
{
"values": {
"description": "Motor",
"value": "D4162T"
}
},
{
"values": {
"description": "Motor Parça No",
"value": "6906309"
}
},
{
"values": {
"description": "Motor Seri Numarası",
"value": "00000000000004138845 / 0ELD61 2208122233587"
}
},
{
"values": {
"description": "Şanzıman kodu",
"value": "B"
}
},
{
"values": {
"description": "Şanzıman",
"value": "6\\-PSHIFT 2WD / MPS6"
}
},
{
"values": {
"description": "Şanzıman Parça No",
"value": "1285041"
}
},
{
"values": {
"description": "Şanzıman Seri No",
"value": "00AWBB1 170812170654"
}
},
{
"values": {
"description": "Şasi Kodu",
"value": "35659B7A6276"
}
}
]
}
}
}

View File

@@ -0,0 +1,492 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import { PL24AuthService } from "./pl24-auth.service";
import { PL24BudgetExceededError } from "./pl24-budget.service";
// Oturum modeli (1 login → PL24TOKEN çerezi → yalnız authorize ile yenileme),
// PL24_TR_DISABLED köprüsü ve login devre kesici. Ağ yok: global fetch stub'ı;
// private durum repo genelindeki `as unknown as` kalıbıyla okunur.
type RedisStub = {
store: Map<string, unknown>;
get: (k: string) => Promise<string | null>;
set: (k: string, v: string, ttl?: number) => Promise<void>;
exists: (k: string) => Promise<boolean>;
getJson: (k: string) => Promise<unknown>;
setJson: (k: string, v: unknown) => Promise<void>;
del: (k: string) => Promise<void>;
setNx: (k: string, v: string, ttl: number) => Promise<boolean>;
incr: (k: string) => Promise<number>;
expire: (k: string, ttl: number) => Promise<void>;
};
const makeRedis = (opts: { lockTaken?: boolean } = {}): RedisStub => {
const store = new Map<string, unknown>();
const counters = new Map<string, number>();
return {
store,
get: async (k: string) => (store.has(k) ? String(store.get(k)) : null),
set: async (k: string, v: string) => {
store.set(k, v);
},
exists: async (k: string) => store.has(k),
getJson: async (k: string) => store.get(k) ?? null,
setJson: async (k: string, v: unknown) => {
store.set(k, v);
},
del: async (k: string) => {
store.delete(k);
},
// Gerçek SET NX semantiği: var olan anahtarı ikinci kez yazmaz. Alarm
// tekrarının bastırılması buna dayanıyor.
setNx: async (k: string, v: string) => {
if (opts.lockTaken && k.includes("login-lock")) return false;
if (store.has(k)) return false;
store.set(k, v);
return true;
},
incr: async (k: string) => {
const n = (counters.get(k) ?? 0) + 1;
counters.set(k, n);
return n;
},
expire: async () => {},
};
};
/** Bütçe servisi stub'ı: sayar ama engellemez, telemetriyi yutar. */
const makeBudget = () => ({
consumed: [] as string[],
recorded: [] as unknown[],
consume: async function (kind: string) {
this.consumed.push(kind);
},
record: function (e: unknown) {
this.recorded.push(e);
},
spentToday: async () => 0,
});
const makeService = (cfgOverrides: Record<string, string> = {}, redis = makeRedis()) => {
const cfg: Record<string, string> = {
"pl24.companyCode": "tr-000000",
"pl24.username": "admin",
"pl24.password": "pw-tr",
"pl24.companyCode2": "de-000000",
"pl24.username2": "admin",
"pl24.password2": "pw-de",
"pl24.proxyDe": "http://u:p@127.0.0.1:9",
...cfgOverrides,
};
const configService = { get: (k: string, d?: unknown) => cfg[k] ?? d } as never;
const budget = makeBudget();
const telegram = {
sent: [] as string[],
isConfigured: () => true,
send: async function (t: string) {
this.sent.push(t);
return true;
},
};
return {
svc: new PL24AuthService(configService, redis as never, budget as never, telegram as never),
redis,
budget,
telegram,
};
};
type Exposed = {
effectiveAccount(account: "tr" | "de"): "tr" | "de";
login(account: "tr" | "de"): Promise<unknown>;
ensureSession(account: "tr" | "de"): Promise<{ sessionToken: string }>;
sessions: Record<string, { sessionToken: string } | undefined>;
serviceTokens: Record<"tr" | "de", Map<string, { token: string; expiresAt: number }>>;
};
/** Portal login yanıtı: {loginStatus, sessionToken} + Set-Cookie PL24TOKEN. */
const loginOk = (token = "sess-token-1") => ({
ok: true,
status: 200,
statusText: "OK",
headers: {
get: (h: string) => (h.toLowerCase() === "set-cookie" ? `PL24TOKEN=${token}; Path=/` : null),
getSetCookie: () => [`PL24TOKEN=${token}; Path=/; Secure`],
},
json: async () => ({ loginStatus: "OK", sessionToken: token }),
});
const jwt = (payload: Record<string, unknown>) =>
`h.${Buffer.from(JSON.stringify(payload)).toString("base64url")}.s`;
const authorizeOk = (scope = "vw_parts pl24-usage", sessionStatus = "alive") => ({
ok: true,
status: 200,
statusText: "OK",
headers: { get: () => null, getSetCookie: () => [] },
json: async () => ({
access_token: jwt({ exp: Math.floor(Date.now() / 1000) + 600, sid: "sess-token-1" }),
expires_in: 600,
scope,
session_status: sessionStatus,
}),
});
const problem = (status: number, type: string) => ({
ok: false,
status,
statusText: "Precondition Failed",
headers: { get: () => null, getSetCookie: () => [] },
json: async () => ({ type, title: type, detail: type }),
});
const savedFlag = process.env.PL24_TR_DISABLED;
beforeEach(() => {
// "" ≠ "true" → bayrak kapalı; delete yerine atama (biome noDelete).
process.env.PL24_TR_DISABLED = "";
});
afterEach(() => {
process.env.PL24_TR_DISABLED = savedFlag ?? "";
vi.unstubAllGlobals();
});
describe("PL24AuthService — PL24_TR_DISABLED tr→de köprüsü", () => {
it("bayrak kapalıyken hesaplar olduğu gibi kalır", () => {
const { svc } = makeService();
const p = svc as unknown as Exposed;
expect(p.effectiveAccount("tr")).toBe("tr");
expect(p.effectiveAccount("de")).toBe("de");
});
it("bayrak açıkken tr → de'ye maplenir, de değişmez", () => {
process.env.PL24_TR_DISABLED = "true";
const { svc } = makeService();
const p = svc as unknown as Exposed;
expect(p.effectiveAccount("tr")).toBe("de");
expect(p.effectiveAccount("de")).toBe("de");
});
it("de hesabı tanımlı değilse mapleme yapılmaz (duvara yönlendirme yok)", () => {
process.env.PL24_TR_DISABLED = "true";
const { svc } = makeService({ "pl24.companyCode2": "" });
expect((svc as unknown as Exposed).effectiveAccount("tr")).toBe("tr");
});
it("bayrak açıkken tr login'i ağa çıkmadan reddedilir", async () => {
process.env.PL24_TR_DISABLED = "true";
const fetchSpy = vi.fn();
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
await expect((svc as unknown as Exposed).login("tr")).rejects.toThrow(/PL24_TR_DISABLED/);
expect(fetchSpy).not.toHaveBeenCalled();
});
it("legacy clearTokens (tr) bayrak altında de servis token'larını temizler", () => {
process.env.PL24_TR_DISABLED = "true";
const { svc } = makeService();
const p = svc as unknown as Exposed;
p.serviceTokens.de.set("vw_parts", { token: "x", expiresAt: Date.now() + 60_000 });
svc.clearTokens();
expect(p.serviceTokens.de.size).toBe(0);
});
});
describe("PL24AuthService — oturum modeli", () => {
it("bir kez login eder, sonraki çağrılar aynı oturumu kullanır (yeniden login yok)", async () => {
const fetchSpy = vi.fn().mockResolvedValue(loginOk());
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
const c1 = await svc.getSessionCookieForAccount("de");
const c2 = await svc.getSessionCookieForAccount("de");
expect(c1).toBe("PL24TOKEN=sess-token-1");
expect(c2).toBe(c1);
expect(fetchSpy).toHaveBeenCalledTimes(1);
});
it("eşzamanlı çağrılar tek login paylaşır (single-flight)", async () => {
const fetchSpy = vi.fn().mockImplementation(async () => {
await new Promise((r) => setTimeout(r, 10));
return loginOk();
});
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
await Promise.all([
svc.getSessionCookieForAccount("de"),
svc.getSessionCookieForAccount("de"),
svc.getSessionCookieForAccount("de"),
]);
expect(fetchSpy).toHaveBeenCalledTimes(1);
});
it("başka bir süreç oturumu tutuyorsa Redis'ten devralır, login etmez", async () => {
const redis = makeRedis();
redis.store.set("pl24:auth:session:de", {
sessionToken: "shared-token",
loginAt: Date.now(),
lastOkAt: Date.now(),
});
const fetchSpy = vi.fn();
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService({}, redis);
expect(await svc.getSessionCookieForAccount("de")).toBe("PL24TOKEN=shared-token");
expect(fetchSpy).not.toHaveBeenCalled();
});
it("login sadece çerez mint eder; servis token'ı authorize'dan gelir (Bearer'sız)", async () => {
const fetchSpy = vi.fn().mockImplementation(async (url: string) => {
if (String(url).includes("/login")) return loginOk();
return authorizeOk();
});
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
await svc.authorizeServiceForAccount("vw_parts", "de");
const authorizeCall = fetchSpy.mock.calls.find((c) => String(c[0]).includes("/authorize"));
expect(authorizeCall).toBeTruthy();
const headers = (authorizeCall?.[1] as { headers: Record<string, string> }).headers;
expect(headers.Cookie).toBe("PL24TOKEN=sess-token-1");
expect(headers.Authorization).toBeUndefined();
expect(headers["User-Agent"]).toMatch(/Chrome\/\d/);
});
it("servis token'ı süresi dolmadan yeniden authorize edilmez", async () => {
const fetchSpy = vi.fn().mockImplementation(async (url: string) => {
if (String(url).includes("/login")) return loginOk();
return authorizeOk();
});
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
await svc.authorizeServiceForAccount("vw_parts", "de");
await svc.authorizeServiceForAccount("vw_parts", "de");
const authorizeCalls = fetchSpy.mock.calls.filter((c) => String(c[0]).includes("/authorize"));
expect(authorizeCalls).toHaveLength(1);
});
it("session_status=gone → oturumu düşürür, bir kez yeniden login edip devam eder", async () => {
let authorizeCalls = 0;
const fetchSpy = vi.fn().mockImplementation(async (url: string) => {
if (String(url).includes("/login")) return loginOk(`sess-${authorizeCalls}`);
authorizeCalls += 1;
return authorizeCalls === 1 ? authorizeOk("vw_parts", "gone") : authorizeOk();
});
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
const token = await svc.authorizeServiceForAccount("vw_parts", "de");
expect(token).toBeTruthy();
expect(authorizeCalls).toBe(2);
expect(fetchSpy.mock.calls.filter((c) => String(c[0]).includes("/login"))).toHaveLength(2);
});
it("authorize 401 → oturumu düşürür ve tek sefer yeniden dener", async () => {
let authorizeCalls = 0;
const fetchSpy = vi.fn().mockImplementation(async (url: string) => {
if (String(url).includes("/login")) return loginOk();
authorizeCalls += 1;
if (authorizeCalls === 1) {
return {
ok: false,
status: 401,
statusText: "Unauthorized",
headers: { get: () => null, getSetCookie: () => [] },
json: async () => ({}),
};
}
return authorizeOk();
});
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
await expect(svc.authorizeServiceForAccount("vw_parts", "de")).resolves.toBeTruthy();
expect(authorizeCalls).toBe(2);
});
it("oturum sınırı aşıldı (412) → tek sefer squeezeOut ile tekrar dener", async () => {
const bodies: string[] = [];
let loginCalls = 0;
const fetchSpy = vi.fn().mockImplementation(async (url: string, opts: { body: string }) => {
if (!String(url).includes("/login")) return authorizeOk();
bodies.push(opts.body);
loginCalls += 1;
return loginCalls === 1
? problem(412, "urn:login:session-limit-exceeded")
: loginOk("after-squeeze");
});
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
expect(await svc.getSessionCookieForAccount("de")).toBe("PL24TOKEN=after-squeeze");
expect(JSON.parse(bodies[0]).squeezeOut).toBe(false);
expect(JSON.parse(bodies[1]).squeezeOut).toBe(true);
});
it("P4 header'ı yalnız çerez taşır (authorize isteği atmaz)", async () => {
const fetchSpy = vi.fn().mockResolvedValue(loginOk());
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
const headers = await svc.buildFordLegacyHeadersForAccount("opel_parts", "de");
expect(headers.Cookie).toBe("PL24TOKEN=sess-token-1");
expect(headers.Authorization).toBeUndefined();
expect(fetchSpy.mock.calls.filter((c) => String(c[0]).includes("/authorize"))).toHaveLength(0);
});
it("Ford hintstoken değeri oturum token'ıdır", async () => {
vi.stubGlobal("fetch", vi.fn().mockResolvedValue(loginOk("hint-1")));
const { svc } = makeService();
await svc.getSessionCookieForAccount("de");
expect(svc.getPL24TokenValueForAccount("de")).toBe("hint-1");
});
});
describe("PL24AuthService — login devre kesici", () => {
it("3 ardışık başarısız login'den sonra açılır ve yeni ağ denemesini keser", async () => {
const fetchSpy = vi.fn().mockRejectedValue(new Error("network down"));
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
const p = svc as unknown as Exposed;
for (let i = 0; i < 3; i++) {
await expect(p.login("de")).rejects.toThrow(/giris hatasi/);
}
// Ağ hatasında squeezeOut denemesi yapılmaz → login başına tek fetch.
expect(fetchSpy).toHaveBeenCalledTimes(3);
await expect(p.login("de")).rejects.toThrow(/breaker open/);
expect(fetchSpy).toHaveBeenCalledTimes(3);
});
it("hesap kapalı (account-not-active) → ilk hatada uzun süreli kesici", async () => {
const fetchSpy = vi.fn().mockResolvedValue(problem(400, "urn:login:account-not-active"));
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
const p = svc as unknown as Exposed;
await expect(p.login("de")).rejects.toThrow(/giris hatasi/);
await expect(p.login("de")).rejects.toThrow(/breaker open/);
expect(fetchSpy).toHaveBeenCalledTimes(1);
});
it("başarılı login kesici sayacını sıfırlar", async () => {
let failFirst = 2;
const fetchSpy = vi.fn().mockImplementation(async () => {
if (failFirst > 0) {
failFirst -= 1;
throw new Error("network down");
}
return loginOk();
});
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
const p = svc as unknown as Exposed;
await expect(p.login("de")).rejects.toThrow();
await expect(p.login("de")).rejects.toThrow();
await expect(p.login("de")).resolves.toBeTruthy();
await expect(p.login("de")).resolves.toBeTruthy();
expect(fetchSpy).toHaveBeenCalledTimes(4);
});
it("saatlik login tavanı aşılırsa yeni login denenmez", async () => {
const fetchSpy = vi.fn().mockResolvedValue(loginOk());
vi.stubGlobal("fetch", fetchSpy);
const { svc } = makeService();
const p = svc as unknown as Exposed;
for (let i = 0; i < 6; i++) await p.login("de");
await expect(p.login("de")).rejects.toThrow(/login rate limit/);
expect(fetchSpy).toHaveBeenCalledTimes(6);
});
});
describe("PL24AuthService — 1 saatlik kesinti alarmı (Telegram)", () => {
const loginFails = () => ({
ok: false,
status: 400,
statusText: "Bad Request",
headers: { get: () => null, getSetCookie: () => [] },
json: async () => ({ type: "urn:login:account-not-active", detail: "account not active" }),
});
it("ilk saat içinde alarm göndermez", async () => {
vi.stubGlobal("fetch", vi.fn().mockResolvedValue(loginFails()));
const { svc, telegram } = makeService();
await expect((svc as unknown as Exposed).login("de")).rejects.toThrow();
expect(telegram.sent).toHaveLength(0);
});
it("kesinti 1 saati geçince tek sefer alarm gönderir", async () => {
vi.stubGlobal("fetch", vi.fn().mockResolvedValue(loginFails()));
const redis = makeRedis();
// Kesinti 70 dakika önce başlamış gibi davran (paylaşılan Redis saati).
redis.store.set("pl24:auth:fail-since:de", String(Date.now() - 70 * 60_000));
const { svc, telegram } = makeService({}, redis);
await expect((svc as unknown as Exposed).login("de")).rejects.toThrow();
await new Promise((r) => setTimeout(r, 10)); // void alarm promise'i
expect(telegram.sent).toHaveLength(1);
expect(telegram.sent[0]).toContain("PL24 giriş yapılamıyor");
expect(telegram.sent[0]).toContain("70 dakika");
// Kesici açık olsa bile ikinci kez sızlanmaz (alerted anahtarı).
await expect((svc as unknown as Exposed).login("de")).rejects.toThrow();
await new Promise((r) => setTimeout(r, 10));
expect(telegram.sent).toHaveLength(1);
});
it("giriş düzelince kurtarma mesajı gönderir ve saati sıfırlar", async () => {
const redis = makeRedis();
redis.store.set("pl24:auth:fail-since:de", String(Date.now() - 90 * 60_000));
redis.store.set("pl24:auth:alerted:de", "1");
vi.stubGlobal("fetch", vi.fn().mockResolvedValue(loginOk()));
const { svc, telegram } = makeService({}, redis);
await svc.getSessionCookieForAccount("de");
await new Promise((r) => setTimeout(r, 10));
expect(telegram.sent.some((t) => t.includes("PL24 girişi düzeldi"))).toBe(true);
expect(redis.store.has("pl24:auth:fail-since:de")).toBe(false);
});
});
/**
* Kendi günlük tavanımız dolduğunda bu bir GİRİŞ HATASI değildir.
*
* Prod 2026-09-21: tavan dolunca `attemptLogin` içindeki `budget.consume()`
* fırlattı, dış `catch` bunu `{ error }` düzleştirdi, `loginWithLock` giriş
* hatası sanıp devre kesiciyi tetikledi ve kesinti sayacını başlattı — bir saat
* sonra Telegram "hesap banlanmış olabilir" dedi. Hesap sağlamdı (tarayıcıdan
* giriş çalışıyordu, aynı gün 143 başarılı auth ve 0 × 401).
*/
describe("bütçe reddi ban alarmı üretmemeli", () => {
it("bütçe hatası olduğu gibi yukarı çıkar, giriş hatasına çevrilmez", async () => {
const { svc, redis, telegram, budget } = makeService();
budget.consume = async () => {
throw new PL24BudgetExceededError("user", 1205, 1200);
};
const fetchSpy = vi.fn();
vi.stubGlobal("fetch", fetchSpy);
await expect((svc as never as Exposed).login("de")).rejects.toBeInstanceOf(
PL24BudgetExceededError,
);
// Kesinti sayacı başlamamalı → Telegram susmalı.
expect(telegram.sent).toHaveLength(0);
const failKeys = Object.keys(redis.store ?? {}).filter((k) => k.includes("fail-since"));
expect(failKeys).toHaveLength(0);
vi.unstubAllGlobals();
});
});

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,166 @@
import { describe, expect, it, vi } from "vitest";
import { backfillContext } from "../../jobs/prefetch-context";
import { PL24BudgetExceededError, PL24BudgetService } from "./pl24-budget.service";
// Günlük PL24 HTTP tavanı + kullanıcı rezervi + proxy_logs telemetrisi.
// Redis ve telemetri stub'lanır; ağ yok.
const makeRedis = (opts: { fail?: boolean } = {}) => {
const counters = new Map<string, number>();
return {
counters,
incr: async (k: string) => {
if (opts.fail) throw new Error("redis down");
const n = (counters.get(k) ?? 0) + 1;
counters.set(k, n);
return n;
},
expire: async () => {},
get: async (k: string) => (counters.has(k) ? String(counters.get(k)) : null),
};
};
const makeTelemetry = () => {
const events: Record<string, unknown>[] = [];
return { events, record: (e: Record<string, unknown>) => events.push(e) };
};
const make = (env: Record<string, string> = {}, redis = makeRedis()) => {
for (const [k, v] of Object.entries(env)) vi.stubEnv(k, v);
const telemetry = makeTelemetry();
return { svc: new PL24BudgetService(redis as never, telemetry as never), redis, telemetry };
};
const inBackfill = <T>(fn: () => Promise<T>) => backfillContext.run(true, fn);
describe("PL24BudgetService — günlük tavan", () => {
it("tavan altında çağrılara izin verir", async () => {
const { svc } = make({ PL24_HTTP_DAILY_MAX: "5" });
for (let i = 0; i < 5; i++) await svc.consume("catalog");
expect(await svc.spentToday()).toBe(5);
});
it("tavan aşılınca kullanıcı çağrısını da reddeder", async () => {
const { svc } = make({ PL24_HTTP_DAILY_MAX: "3" });
for (let i = 0; i < 3; i++) await svc.consume("catalog");
await expect(svc.consume("catalog")).rejects.toBeInstanceOf(PL24BudgetExceededError);
});
it("backfill kullanıcı rezervine dokunamaz, kullanıcı trafiği devam eder", async () => {
// tavan 10, rezerv %40 → backfill 6'da durur, kullanıcı 10'a kadar sürer
const { svc } = make({ PL24_HTTP_DAILY_MAX: "10", PL24_HTTP_USER_RESERVE: "0.4" });
for (let i = 0; i < 6; i++) await inBackfill(() => svc.consume("catalog"));
await expect(inBackfill(() => svc.consume("catalog"))).rejects.toBeInstanceOf(
PL24BudgetExceededError,
);
// Aynı gün, aynı sayaç: kullanıcı hâlâ geçebilmeli (7., 8. … 10. istek)
await expect(svc.consume("catalog")).resolves.toBeUndefined();
await expect(svc.consume("catalog")).resolves.toBeUndefined();
});
it("reddedilen çağrı yalnız reddedildiği yerde sayılır (ağ isteği yok)", async () => {
const { svc, telemetry } = make({ PL24_HTTP_DAILY_MAX: "1" });
await svc.consume("catalog");
await expect(svc.consume("catalog")).rejects.toBeInstanceOf(PL24BudgetExceededError);
expect(telemetry.events).toHaveLength(0);
});
it("Redis düşükse PL24'ü bloklamaz (fail-open)", async () => {
const { svc } = make({ PL24_HTTP_DAILY_MAX: "1" }, makeRedis({ fail: true }));
await expect(svc.consume("catalog")).resolves.toBeUndefined();
await expect(svc.consume("catalog")).resolves.toBeUndefined();
});
});
describe("PL24BudgetService — telemetri", () => {
it("katalog çağrısını proxy_logs biçiminde kaydeder", () => {
const { svc, telemetry } = make();
svc.record({
kind: "catalog",
url: "https://www.partslink24.com/p5psa/extern/group/vin/scope?vin=X",
proxied: true,
account: "de",
statusCode: 200,
success: true,
startedAt: Date.now() - 120,
});
const e = telemetry.events[0];
expect(e.service).toBe("pl24_http");
expect(e.provider).toBe("dataimpulse");
expect(e.targetHost).toBe("www.partslink24.com");
expect(e.success).toBe(true);
expect(e.errorKind).toBeNull();
});
it("login çağrısını pl24_auth olarak ayırır", () => {
const { svc, telemetry } = make();
svc.record({
kind: "auth",
url: "https://www.partslink24.com/auth/ext/api/1.1/login",
proxied: false,
account: "tr",
statusCode: 400,
success: false,
startedAt: Date.now(),
});
expect(telemetry.events[0].service).toBe("pl24_auth");
expect(telemetry.events[0].provider).toBe("none");
});
it("403/429'u ban sinyali olarak işaretler", () => {
const { svc, telemetry } = make();
svc.record({
kind: "catalog",
url: "https://www.partslink24.com/x",
proxied: true,
account: "de",
statusCode: 403,
success: false,
startedAt: Date.now(),
});
expect(telemetry.events[0].errorKind).toBe("banned");
});
it("taşıma hatasını sınıflandırır", () => {
const { svc, telemetry } = make();
const err = Object.assign(new Error("fetch failed"), { name: "TimeoutError" });
svc.record({
kind: "catalog",
url: "https://www.partslink24.com/x",
proxied: true,
account: "de",
success: false,
startedAt: Date.now(),
error: err,
});
expect(telemetry.events[0].errorKind).toBe("timeout");
expect(telemetry.events[0].statusCode).toBeNull();
});
});
/**
* Bütçe reddi bir giriş hatası DEĞİLDİR (plv2.md, bulgu auth-16).
*
* Prod 2026-09-21: günlük tavan dolunca `attemptLogin` içindeki
* `budget.consume()` fırlattı, dış `catch` bunu `{ error }` düzleştirdi,
* `loginWithLock` bunu giriş hatası sanıp devre kesiciyi tetikledi ve kesinti
* sayacını başlattı → bir saat sonra Telegram "hesap banlanmış olabilir" dedi.
* Oysa hesap sağlamdı: tarayıcıdan giriş çalışıyordu, aynı gün 143 başarılı
* auth çağrısı ve 0 × 401 vardı.
*/
describe("PL24BudgetExceededError — kendi frenimiz, upstream hatası değil", () => {
it("kendi hata sınıfını taşır, düz Error değil", () => {
const err = new PL24BudgetExceededError("user", 1205, 1200);
expect(err).toBeInstanceOf(PL24BudgetExceededError);
expect(err).toBeInstanceOf(Error);
});
it("mesajı hangi şeridin ve hangi sayının durduğunu söyler", () => {
const err = new PL24BudgetExceededError("user", 1205, 1200);
expect(err.message).toContain("1205");
expect(err.message).toContain("1200");
expect(err.message.toLowerCase()).toContain("user");
});
});

View File

@@ -0,0 +1,145 @@
import { Injectable, Logger } from "@nestjs/common";
import { isBackfillContext } from "../../jobs/prefetch-context";
import { RedisService } from "../../redis/redis.service";
import {
ProxyTelemetryService,
classifyTransportError,
isBanStatus,
} from "../proxy-telemetry/proxy-telemetry.service";
/**
* PL24 HTTP budget + telemetry.
*
* WHY (see /home/s/ss/plv2.md §2.2, findings consumers_jobs-03/07):
* Both PL24 account bans (tr 2026-07-24, de 2026-09-04) followed days that wrote
* 5-7k new category rows — roughly 10k+ upstream calls/day — while real user
* decodes never exceeded 14/day. The existing guards are all job-level
* (jobs/min, jobs/day); nothing counted actual HTTP requests, and PL24 calls
* were invisible in `proxy_logs` (only pcat/emex were logged), so the volume was
* only reconstructable after the fact from DB row counts.
*
* This service is the one choke point every PL24 upstream call passes through:
* - counts requests per UTC day in Redis and refuses new ones past the cap,
* - reserves a share of that cap for real users so a runaway backfill can
* never starve a paying customer's decode,
* - records every attempt into `proxy_logs` (service `pl24_http`/`pl24_auth`).
*
* The cap is deliberately low to start (PL24_HTTP_DAILY_MAX, default 1200);
* raise it only with telemetry in hand.
*/
@Injectable()
export class PL24BudgetService {
private readonly logger = new Logger(PL24BudgetService.name);
/** Log "budget exhausted" once per day per lane instead of on every call. */
private warnedFor = new Set<string>();
constructor(
private readonly redis: RedisService,
private readonly telemetry: ProxyTelemetryService,
) {}
private get dailyMax(): number {
const raw = Number(process.env.PL24_HTTP_DAILY_MAX);
return Number.isFinite(raw) && raw > 0 ? raw : 1200;
}
/** Fraction of the daily cap that only user-facing calls may spend. */
private get userReserve(): number {
const raw = Number(process.env.PL24_HTTP_USER_RESERVE);
return Number.isFinite(raw) && raw > 0 && raw < 1 ? raw : 0.4;
}
private dayKey(): string {
return `pl24:http:${new Date().toISOString().slice(0, 10)}`;
}
/**
* Count one upstream call and decide whether it may proceed.
* Backfill stops at (1 - userReserve) of the cap; user traffic gets the rest.
*/
async consume(kind: "auth" | "catalog"): Promise<void> {
const backfill = isBackfillContext();
let spent: number;
try {
const key = this.dayKey();
spent = await this.redis.incr(key);
if (spent === 1) await this.redis.expire(key, 8 * 86_400);
// Per-lane counters. The shared total tells us WHEN the cap was hit but not
// WHO spent it, and sizing the cap needs that split: on 2026-09-21 the
// total hit 1200 and every user decode after 16:10 UTC was refused, with
// no way to tell from `proxy_logs` how much of it was warm-up prefetch
// versus somebody waiting on a screen.
const laneKey = `${key}:${backfill ? "worker" : "user"}`;
const laneSpent = await this.redis.incr(laneKey);
if (laneSpent === 1) await this.redis.expire(laneKey, 8 * 86_400);
} catch {
return; // Redis down → never block PL24 on telemetry
}
const max = this.dailyMax;
const limit = backfill ? Math.floor(max * (1 - this.userReserve)) : max;
if (spent > limit) {
const lane = backfill ? "backfill" : "user";
if (!this.warnedFor.has(`${lane}:${this.dayKey()}`)) {
this.warnedFor.add(`${lane}:${this.dayKey()}`);
this.logger.warn(
`PL24 daily HTTP budget exhausted for the ${lane} lane (${spent}/${limit}, cap ${max}, kind=${kind}) — refusing further calls today`,
);
}
throw new PL24BudgetExceededError(lane, spent, limit);
}
}
/** Current spend (for /health and the Süper Panel). */
async spentToday(): Promise<number> {
try {
return Number((await this.redis.get(this.dayKey())) ?? 0);
} catch {
return 0;
}
}
record(opts: {
kind: "auth" | "catalog";
url: string;
proxied: boolean;
account: string;
statusCode?: number | null;
success: boolean;
startedAt: number;
error?: unknown;
}): void {
let targetHost: string | null = null;
try {
targetHost = new URL(opts.url).hostname;
} catch {
/* keep null */
}
this.telemetry.record({
service: opts.kind === "auth" ? "pl24_auth" : "pl24_http",
provider: opts.proxied ? "dataimpulse" : "none",
sessionKey: opts.account,
targetHost,
statusCode: opts.statusCode ?? null,
errorKind: opts.error
? classifyTransportError(opts.error)
: isBanStatus(opts.statusCode)
? "banned"
: null,
success: opts.success,
durationMs: Date.now() - opts.startedAt,
});
}
}
/** Thrown when the daily PL24 HTTP budget is used up for this lane. */
export class PL24BudgetExceededError extends Error {
constructor(
readonly lane: "user" | "backfill",
readonly spent: number,
readonly limit: number,
) {
super(`PL24 daily HTTP budget exhausted (${lane} lane: ${spent}/${limit})`);
this.name = "PL24BudgetExceededError";
}
}

View File

@@ -116,7 +116,7 @@ export class PL24FordLegacyService {
}
// Ford / Hyundai-Kia / Nissan / Opel / Volvo devam eder...
await this.authService.authorizeServiceForAccount(serviceName, account);
await this.authService.ensureSession(account);
const html = await this.fetchVinGroupPage(vin, serviceName, account);
if (!html) return null;
@@ -124,8 +124,8 @@ export class PL24FordLegacyService {
const support = this.extractScriptVariable<FordPL24Support>(html, "PL24_SUPPORT");
if (support?.demo || support?.role === "NOT_LOGGED_IN_DEMO") {
this.logger.warn(`P4 legacy: demo mode for ${serviceName}, retrying with fresh auth`);
this.authService.clearTokensForAccount(account);
await this.authService.authorizeServiceForAccount(serviceName, account);
await this.authService.dropSessionForAccount(account, "P4 page 401");
await this.authService.ensureSession(account);
const retryHtml = await this.fetchVinGroupPage(vin, serviceName, account);
if (!retryHtml) return null;
@@ -1110,7 +1110,7 @@ export class PL24FordLegacyService {
this.logger.log(`Ford: fetching vehicle list for ${serviceName}`);
try {
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
const config = getServiceConfig(serviceName);
const basePath = config ? `${config.basePath}/${serviceName}` : `/ford/${serviceName}`;
@@ -1126,8 +1126,8 @@ export class PL24FordLegacyService {
let support = this.extractScriptVariable<FordPL24Support>(html, "PL24_SUPPORT");
if (support?.demo || support?.role === "NOT_LOGGED_IN_DEMO") {
this.logger.warn(`Ford: demo mode for ${serviceName}, retrying with fresh auth`);
this.authService.clearTokens();
await this.authService.authorizeService(serviceName);
await this.authService.dropSessionForAccount("tr", "P4 page 401");
await this.authService.ensureSession("tr");
const retryHtml = await this.fetchP4Page(vinGroupUrl, serviceName, true);
if (!retryHtml) return [];
const retrySupport = this.extractScriptVariable<FordPL24Support>(retryHtml, "PL24_SUPPORT");
@@ -1221,7 +1221,7 @@ export class PL24FordLegacyService {
this.logger.log(`HyundaiKia: fetching vehicle list for ${serviceName}`);
try {
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
const config = getServiceConfig(serviceName);
const basePath = config
@@ -1306,7 +1306,7 @@ export class PL24FordLegacyService {
this.logger.log(`Nissan: fetching vehicle list for ${serviceName}`);
try {
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
const config = getServiceConfig(serviceName);
const basePath = config ? `${config.basePath}/${serviceName}` : `/nissan/${serviceName}`;
@@ -1377,7 +1377,7 @@ export class PL24FordLegacyService {
this.logger.log(`Opel: fetching vehicle list for ${serviceName}`);
try {
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
const config = getServiceConfig(serviceName);
const basePath = config ? `${config.basePath}/${serviceName}` : `/opel/${serviceName}`;
@@ -1452,7 +1452,7 @@ export class PL24FordLegacyService {
this.logger.log(`Volvo: fetching vehicle list for ${serviceName}`);
try {
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
const config = getServiceConfig(serviceName);
const basePath = config ? `${config.basePath}/${serviceName}` : `/volvo/${serviceName}`;
@@ -1556,7 +1556,7 @@ export class PL24FordLegacyService {
this.logger.log(`Volvo: fetching model config for ${serviceName} mdl=${mdlId}`);
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
try {
const config = getServiceConfig(serviceName);
@@ -1626,7 +1626,7 @@ export class PL24FordLegacyService {
this.logger.log(`Ford: fetching model config for ${serviceName} family=${familyId}`);
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
const config = getServiceConfig(serviceName);
const arch = config?.architecture;
@@ -1785,7 +1785,7 @@ export class PL24FordLegacyService {
: `Ford: fetching main groups for ${serviceName} family=${familyId} year=${modelYear} engine=${engine} gearbox=${gearbox}`,
);
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
try {
const basePath = config ? `${config.basePath}/${serviceName}` : `/ford/${serviceName}`;
@@ -1917,6 +1917,10 @@ export class PL24FordLegacyService {
* Fiat services always use 'de'; others use round-robin via Redis.
*/
private async resolveAccount(userId?: string, serviceName?: string): Promise<"tr" | "de"> {
// PL24_TR_DISABLED=true → the tr account is inactive on PL24's side; route
// everyone to de so page fetches, proxies and cache labels all agree with the
// auth layer's tr→de mapping (PL24AuthService.effectiveAccount).
if (process.env.PL24_TR_DISABLED === "true") return "de";
// Fiat always needs de account; Hyundai/Kia/Nissan parts are licensed only on de.
if (serviceName && ["fiatp_parts", "fiatt_parts"].includes(serviceName)) {
return "de";
@@ -1953,7 +1957,7 @@ export class PL24FordLegacyService {
cacheKey: string,
account: "tr" | "de",
): Promise<PL24DecodedVehicle | null> {
await this.authService.authorizeServiceForAccount(serviceName, account);
await this.authService.ensureSession(account);
const html = await this.fetchVinGroupPage(vin, serviceName, account);
if (!html) return null;
@@ -1961,8 +1965,8 @@ export class PL24FordLegacyService {
const support = this.extractScriptVariable<FordPL24Support>(html, "PL24_SUPPORT");
if (support?.demo || support?.role === "NOT_LOGGED_IN_DEMO") {
this.logger.warn(`Fiat: demo mode for ${serviceName}, retrying with fresh auth`);
this.authService.clearTokensForAccount(account);
await this.authService.authorizeServiceForAccount(serviceName, account);
await this.authService.dropSessionForAccount(account, "P4 demo page (session not accepted)");
await this.authService.ensureSession(account);
const retryHtml = await this.fetchVinGroupPage(vin, serviceName, account);
if (!retryHtml) return null;
@@ -2889,7 +2893,7 @@ export class PL24FordLegacyService {
private async initPsaSession(
serviceName: string,
): Promise<{ jsessionId: string; mode: string; upds: string } | null> {
await this.authService.authorizeService(serviceName);
await this.authService.ensureSession("tr");
const headers = await this.authService.buildFordLegacyHeaders(serviceName);
try {
@@ -3324,7 +3328,7 @@ export class PL24FordLegacyService {
const isDeOnly = LEGACY_DE_SERVICES.has(serviceName);
const account = isDeOnly ? "de" : accountParam;
if (isDeOnly) {
await this.authService.authorizeServiceForAccount(serviceName, "de");
await this.authService.ensureSession("de");
}
// Some catalogs (Volvo vin-group.action) store hrefs relative to the catalog
// directory (e.g. "vin-group.action?group1=…"). Prefix the service basePath
@@ -3354,8 +3358,8 @@ export class PL24FordLegacyService {
if (response.status === 401) {
this.logger.warn(`Ford legacy: 401, refreshing auth (account=${account})`);
this.authService.clearTokensForAccount(account);
await this.authService.authorizeServiceForAccount(serviceName, account);
await this.authService.dropSessionForAccount(account, "P4 page 401");
await this.authService.ensureSession(account);
const newHeaders = await this.authService.buildFordLegacyHeadersForAccount(
serviceName,
account,
@@ -3388,8 +3392,11 @@ export class PL24FordLegacyService {
const support = this.extractScriptVariable<FordPL24Support>(html, "PL24_SUPPORT");
if (support?.demo || support?.role === "NOT_LOGGED_IN_DEMO") {
this.logger.warn(`Ford legacy: demo page for ${serviceName}, re-authing + retry`);
this.authService.clearTokensForAccount(account);
await this.authService.authorizeServiceForAccount(serviceName, account);
await this.authService.dropSessionForAccount(
account,
"P4 demo page (session not accepted)",
);
await this.authService.ensureSession(account);
return this.fetchP4Page(url, serviceName, isFullUrl, account, true);
}
}
@@ -3434,8 +3441,8 @@ export class PL24FordLegacyService {
if (response.status === 401) {
this.logger.warn(`Ford legacy: 401, refreshing auth (account=${account})`);
this.authService.clearTokensForAccount(account);
await this.authService.authorizeServiceForAccount(serviceName, account);
await this.authService.dropSessionForAccount(account, "P4 page 401");
await this.authService.ensureSession(account);
const newHeaders = await this.authService.buildFordLegacyHeadersForAccount(
serviceName,
account,
@@ -3648,7 +3655,10 @@ export class PL24FordLegacyService {
segment.match(/\bjsonurl="([^"]+)"/);
if (!urlMatch) continue;
const url = urlMatch[1];
// Row attributes are HTML-escaped (`&amp;`), so every query-param check
// below — and the stored linkPath — must work on the decoded URL. Without
// this `[?&]mainGroup=` never matched Hyundai/Kia rows.
const url = urlMatch[1].replace(/&amp;/g, "&").replace(/&#38;/g, "&");
// Skip vehicle.action rows — those are sub-model selectors, not part group links
if (url.includes("vehicle.action")) continue;
// Skip header/breadcrumb navigation links that leak into the group table as
@@ -3657,7 +3667,16 @@ export class PL24FordLegacyService {
// categories use group.action / group-detail.action / json-(main|sub)-group.action,
// none of which match these. Volvo's vin-group.action?...group1=... is kept.
if (/(portal|logout)\.action/i.test(url)) continue;
if (url.includes("vin-group.action") && !url.includes("group1=")) continue;
// Volvo's vin-group.action rows are model pickers unless they carry
// group1=; Hyundai/Kia use the SAME endpoint for real main groups but key
// them with mainGroup= (BO/CH/EL/EN/MI/TR). Keep both, drop the rest.
if (
url.includes("vin-group.action") &&
!url.includes("group1=") &&
!/[?&]mainGroup=/i.test(url)
) {
continue;
}
if (/^https?:\/\//i.test(url) && !/\.action(\?|$)/i.test(url)) continue;
if (seen.has(url)) continue;
seen.add(url);
@@ -4051,6 +4070,15 @@ export class PL24FordLegacyService {
return [];
});
}
// Opel/Vauxhall and Hyundai/Kia ship their main groups as `tc-data-row`
// table rows whose link lives in a `url=`/`jsonurl=` ATTRIBUTE, not in an
// <a href>. parseP4NavigationCategories only reads anchors, so these brands
// decoded with ZERO categories (prod: Opel 169/173, Hyundai 11/11, Kia 5/5)
// even though the page carries the full list. parseFordGroupsFromHtml
// already understands those rows — it simply was never called from decode.
if (categories.length === 0) {
categories = this.parseFordGroupsFromHtml(html, serviceName, "");
}
if (categories.length === 0) {
categories = this.parseP4NavigationCategories(html);
}

View File

@@ -0,0 +1,127 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
import { PL24Service } from "./pl24.service";
/**
* Model-list entry point resolution (plv2.md, bulgu p5core-08).
*
* `BACKEND_MODEL_PATH` eksik kaldığında eski davranış yedi bilinen yolu sırayla
* denemekti: paylaşılan günlük bütçeden çağrı başına yedi isteğe kadar, ve
* listede olmayan bir yol için sessiz sıfır sonuç. Volvo tam olarak buydu —
* `/extern/vehicles/models` (çoğul "vehicles") listede yok, dolayısıyla
* Volvo/Polestar browse sıfır model tohumlayıp emekli P4 listesini sunmaya
* devam ediyordu.
*
* Otoritatif kaynak her P5 backend'inin kendi `/extern/catmeta` yanıtındaki
* `data.catalogEntryPoint.path`. Canlı doğrulama (2026-09-20):
* p5volvo → /p5volvo/extern/vehicles/models (60 model)
* p5psa → /p5psa/extern/vehicle/catalogs
*/
type Resolver = {
resolveModelPathFromCatmeta: (
base: string,
svc: string,
headers: Record<string, string>,
) => Promise<string | null>;
baseUrl: string;
language: string;
redis: {
get: (k: string) => Promise<string | null>;
set: (k: string, v: string, ttl?: number) => Promise<unknown>;
};
logger: { log: (m: string) => void; warn: (m: string) => void };
};
function makeService(opts: {
cached?: string | null;
catmeta?: unknown;
status?: number;
throws?: boolean;
}) {
const sets: Array<[string, string]> = [];
const svc = Object.create(PL24Service.prototype) as unknown as Resolver;
svc.baseUrl = "https://pl24.test";
svc.language = "tr";
svc.redis = {
get: vi.fn(async () => opts.cached ?? null),
set: vi.fn(async (k: string, v: string) => {
sets.push([k, v]);
return undefined;
}),
};
svc.logger = { log: vi.fn(), warn: vi.fn() };
const fetchMock = vi.fn(async () => {
if (opts.throws) throw new Error("network down");
return {
ok: (opts.status ?? 200) < 400,
status: opts.status ?? 200,
json: async () => opts.catmeta ?? {},
};
});
vi.stubGlobal("fetch", fetchMock);
return { svc, sets, fetchMock };
}
const volvoMeta = {
data: {
catalogEntryPoint: {
wid: "modelsTable",
path: "/p5volvo/extern/vehicles/models?lang=en&serviceName=volvo_parts",
},
},
};
describe("resolveModelPathFromCatmeta", () => {
beforeEach(() => vi.unstubAllGlobals());
it("catmeta'daki giriş noktasını backend'e göreli yola indirger", async () => {
const { svc } = makeService({ catmeta: volvoMeta });
const out = await svc.resolveModelPathFromCatmeta("/p5volvo", "volvo_parts", {});
expect(out).toBe("/extern/vehicles/models");
});
it("çözülen yolu 30 gün cache'ler", async () => {
const { svc, sets } = makeService({ catmeta: volvoMeta });
await svc.resolveModelPathFromCatmeta("/p5volvo", "volvo_parts", {});
expect(sets[0][0]).toBe("pl24:modelpath:p5volvo");
expect(sets[0][1]).toBe("/extern/vehicles/models");
});
it("cache'lenmiş yol için upstream'e hiç gitmez", async () => {
const { svc, fetchMock } = makeService({ cached: "/extern/vehicles/models" });
const out = await svc.resolveModelPathFromCatmeta("/p5volvo", "volvo_parts", {});
expect(out).toBe("/extern/vehicles/models");
expect(fetchMock).not.toHaveBeenCalled();
});
it("olumsuz sonuç da cache'lenir — her browse'da yeniden denenmez", async () => {
const { svc, fetchMock } = makeService({ cached: "none" });
expect(await svc.resolveModelPathFromCatmeta("/p5x", "x_parts", {})).toBeNull();
expect(fetchMock).not.toHaveBeenCalled();
});
it("catmeta yoksa veya şekil beklenmedikse null döner", async () => {
const { svc, sets } = makeService({ catmeta: { data: {} } });
expect(await svc.resolveModelPathFromCatmeta("/p5x", "x_parts", {})).toBeNull();
expect(sets[0][1]).toBe("none");
});
it("HTTP hatasında null döner", async () => {
const { svc } = makeService({ status: 403, catmeta: volvoMeta });
expect(await svc.resolveModelPathFromCatmeta("/p5volvo", "volvo_parts", {})).toBeNull();
});
it("ağ hatası fırlatmaz", async () => {
const { svc } = makeService({ throws: true });
await expect(
svc.resolveModelPathFromCatmeta("/p5volvo", "volvo_parts", {}),
).resolves.toBeNull();
});
it("/extern/ ile başlamayan yolu kabul etmez", async () => {
const { svc } = makeService({
catmeta: { data: { catalogEntryPoint: { path: "https://baska.site/kotu" } } },
});
expect(await svc.resolveModelPathFromCatmeta("/p5volvo", "volvo_parts", {})).toBeNull();
});
});

View File

@@ -0,0 +1,70 @@
import { readFileSync } from "node:fs";
import { join } from "node:path";
import { describe, expect, it } from "vitest";
import { PL24FordLegacyService } from "./pl24-ford-legacy.service";
/**
* Opel / Hyundai / Kia "0 kategori" regresyon kilidi (plv2.md, bulgu p4legacy-03).
*
* Bu markalar ana gruplarını <a href> DEĞİL, `<tr class="tc-data-row"
* url=…|jsonurl=…>` satır attribute'unda taşıyor. Decode yolu yalnız anchor
* tarayan parser'ı kullandığı için prod'da Opel 169/173, Hyundai 11/11, Kia 5/5
* araç SIFIR kategoriyle kaydedilmişti — sayfa listeyi taşıdığı hâlde.
*
* Fixture'lar 2026-09-16 canlı keşfinden (plv2-artefakt/), yalnız ana grup
* tablosuna kırpılmış hâlleri.
*/
const fixture = (name: string) =>
readFileSync(join(__dirname, "__fixtures__", `${name}.html`), "utf-8");
// parseFordGroupsFromHtml saf bir metin işleyicisi: bağımlılıklar kullanılmıyor.
const svc = new PL24FordLegacyService(
{} as never, // authService
{ get: (_k: string, d?: unknown) => d } as never, // configService
{} as never, // redis
{} as never, // storage
) as unknown as {
parseFordGroupsFromHtml(
html: string,
serviceName: string,
familyId: string,
): Array<{ code: string; nameEn: string; linkPath?: string }>;
parseP4NavigationCategories(html: string): Array<{ nameEn: string }>;
};
describe("P4 ana grup tablosu — Opel/Hyundai (0 kategori regresyonu)", () => {
it("Opel: jsonurl satırlarından 31 ana grubu çıkarır", () => {
const groups = svc.parseFordGroupsFromHtml(fixture("p4_opel"), "opel_parts", "");
expect(groups.length).toBe(31);
expect(groups[0].nameEn).toBe("BODY SHELL AND PANELS");
expect(groups[0].code).toContain("json-vin-main-group.action");
expect(groups[0].code).toContain("mainGroupId=394");
// Adların hepsi gerçek metin olmalı (kod artığı değil)
expect(groups.every((g) => /[A-Za-z]{3,}/.test(g.nameEn))).toBe(true);
});
it("Hyundai: mainGroup= anahtarlı vin-group satırları artık elenmez", () => {
const groups = svc.parseFordGroupsFromHtml(fixture("p4_hyundai"), "hyundai_parts", "");
expect(groups.length).toBe(6);
const names = groups.map((g) => g.nameEn);
expect(names).toContain("BODY");
expect(groups[0].code).toContain("mainGroup=BO");
});
it("anchor-only parser bu sayfalarda hâlâ boş döner (fallback'in gerekçesi)", () => {
expect(svc.parseP4NavigationCategories(fixture("p4_opel")).length).toBe(0);
expect(svc.parseP4NavigationCategories(fixture("p4_hyundai")).length).toBe(0);
});
it("Ford: scope satırları (sharedCatCode) bozulmadan okunur", () => {
const groups = svc.parseFordGroupsFromHtml(fixture("p4_ford"), "fordp_parts", "");
expect(groups.length).toBeGreaterThanOrEqual(6);
expect(groups.some((g) => g.code.includes("sharedCatCode=ZE"))).toBe(true);
});
it("Nissan: model seçim satırları ana grup sayılmaz (vehicle.action elenir)", () => {
const groups = svc.parseFordGroupsFromHtml(fixture("p4_nissan"), "nissan_parts", "");
expect(groups.every((g) => !g.code.includes("vehicle.action"))).toBe(true);
});
});

View File

@@ -442,31 +442,50 @@ export class PL24PsaService {
// ==================== PRIVATE: session + HTTP ====================
/**
* PSA requests must leave from the same egress as their auth account: under
* PL24_TR_DISABLED the legacy "tr" auth maps to de, whose session lives behind
* the DE proxy — the auth service picks the dispatcher (null for real tr).
*/
private async psaDispatcher(): Promise<any | null> {
return this.authService.getProxyAgent4Account("tr");
}
/**
* entry.action → startup=true (302) → 302 with mode+upds. Returns JSESSIONID/mode/upds.
*/
private async initPsaSession(serviceName: string): Promise<PsaSession | null> {
await this.authService.authorizeService(serviceName);
// P4 PSA pages authenticate off the session cookie alone — no service token.
await this.authService.ensureSession("tr");
const headers = await this.authService.buildFordLegacyHeaders(serviceName);
const dispatcher = await this.psaDispatcher();
const withDispatcher = (o: RequestInit): RequestInit & { dispatcher?: any } =>
dispatcher ? { ...o, dispatcher } : o;
try {
const entryRes = await fetch(`${this.baseUrl}/psa/pl24-entry.action?service=${serviceName}`, {
method: "GET",
headers,
redirect: "manual",
signal: AbortSignal.timeout(this.timeout),
});
const entryRes = await fetch(
`${this.baseUrl}/psa/pl24-entry.action?service=${serviceName}`,
withDispatcher({
method: "GET",
headers,
redirect: "manual",
signal: AbortSignal.timeout(this.timeout),
}),
);
const jsessionId = entryRes.headers.get("set-cookie")?.match(/JSESSIONID=([^;]+)/)?.[1] || "";
const loc1 = entryRes.headers.get("location");
if (!loc1) return null;
const hdrs2 = jsessionId
? { ...headers, Cookie: `${headers.Cookie}; JSESSIONID=${jsessionId}` }
: headers;
const startupRes = await fetch(loc1.startsWith("http") ? loc1 : `${this.baseUrl}${loc1}`, {
method: "GET",
headers: hdrs2,
redirect: "manual",
signal: AbortSignal.timeout(this.timeout),
});
const startupRes = await fetch(
loc1.startsWith("http") ? loc1 : `${this.baseUrl}${loc1}`,
withDispatcher({
method: "GET",
headers: hdrs2,
redirect: "manual",
signal: AbortSignal.timeout(this.timeout),
}),
);
const loc2 = startupRes.headers.get("location") || loc1;
const mode = loc2.match(/[?&]mode=([^&]+)/)?.[1] || "";
// Keep upds URL-encoded exactly as returned (e.g. "2024.02.13+09%3A27%3A21+CET");
@@ -494,12 +513,15 @@ export class PL24PsaService {
Accept: opts.json ? "application/json,*/*" : "text/html,application/xhtml+xml,*/*;q=0.9",
};
try {
const res = await fetch(url, {
const dispatcher = await this.psaDispatcher();
const fetchOpts: RequestInit & { dispatcher?: any } = {
method: "GET",
headers,
redirect: opts.manual ? "manual" : "follow",
signal: AbortSignal.timeout(this.timeout),
});
};
if (dispatcher) fetchOpts.dispatcher = dispatcher;
const res = await fetch(url, fetchOpts);
const location = res.headers.get("location");
if (opts.manual && res.status >= 300 && res.status < 400) {
return { status: res.status, text: null, location };
@@ -543,13 +565,19 @@ export class PL24PsaService {
Accept: "application/json,image/*,*/*;q=0.9",
Referer: `${this.baseUrl}/psa/${serviceName}/vin-image-board.action`,
};
const dispatcher = await this.psaDispatcher();
const withDispatcher = (o: RequestInit): RequestInit & { dispatcher?: any } =>
dispatcher ? { ...o, dispatcher } : o;
try {
const infoRes = await fetch(`${imageUrl}&request=GetImageInfo&cv=1`, {
method: "GET",
headers,
redirect: "follow",
signal: AbortSignal.timeout(this.timeout),
});
const infoRes = await fetch(
`${imageUrl}&request=GetImageInfo&cv=1`,
withDispatcher({
method: "GET",
headers,
redirect: "follow",
signal: AbortSignal.timeout(this.timeout),
}),
);
if (!infoRes.ok) return null;
const info = (await infoRes.json()) as {
imageWidth: number;
@@ -570,12 +598,15 @@ export class PL24PsaService {
const getImgUrl =
`${imageUrl}&request=GetImage&format=image%2Fpng` +
`&bbox=${encodeURIComponent(`0,0,${w},${h}`)}&width=${w}&height=${h}&scalefac=1.0&cv=1&rnd=${rnd}`;
const imgRes = await fetch(getImgUrl, {
method: "GET",
headers: { ...headers, Accept: "image/png,image/*,*/*;q=0.9" },
redirect: "follow",
signal: AbortSignal.timeout(this.timeout),
});
const imgRes = await fetch(
getImgUrl,
withDispatcher({
method: "GET",
headers: { ...headers, Accept: "image/png,image/*,*/*;q=0.9" },
redirect: "follow",
signal: AbortSignal.timeout(this.timeout),
}),
);
if (!imgRes.ok) return null;
const contentType = imgRes.headers.get("content-type") || "image/png";
const buffer = Buffer.from(await imgRes.arrayBuffer());

View File

@@ -0,0 +1,186 @@
import { describe, expect, it } from "vitest";
import {
isPl24GroupNode,
isPl24LeafNode,
isPl24PartDetailNode,
isStalePl24Architecture,
} from "./pl24-tree";
// Canlı P5 yanıtlarından (2026-09-16 keşfi, plv2-artefakt/) alınan gerçek
// wid + path çiftleri. Bu dosya "0 parça" sınıfı hatanın regresyon kilidi.
describe("isPl24LeafNode — canlı P5 şekilleri", () => {
it("VW (p5vwag): maingroups/subgroups grup, bom/vin yaprak", () => {
expect(
isPl24GroupNode({
linkWid: "mainGroupsTable",
linkPath: "/p5vwag/extern/groups/vin_maingroups?vin=X",
}),
).toBe(true);
expect(
isPl24GroupNode({
linkWid: "subGroupsIllusTable",
linkPath: "/p5vwag/extern/groups/vin_subgroups_illus?maingroup=4",
}),
).toBe(true);
expect(
isPl24LeafNode({
linkWid: "bomlist",
linkPath: "/p5vwag/extern/bom/vin?illustration=407-000",
}),
).toBe(true);
});
it("PSA (p5psa): scope + mainGroups + illusTable grup, bomDetails yaprak", () => {
expect(
isPl24GroupNode({
linkWid: "scopeTable",
linkPath: "/p5psa/extern/group/vin/scope?modelCode=1PD2",
}),
).toBe(true);
expect(
isPl24GroupNode({
linkWid: "mainGroupTable",
linkPath: "/p5psa/extern/group/vin/mainGroups?scope=_FCT0001",
}),
).toBe(true);
// Eski `includes("group")` kuralının kaçırdığı seviye — sessiz boş panelin kaynağı.
expect(
isPl24GroupNode({
linkWid: "illusTable",
linkPath: "/p5psa/extern/group/vin/illus?mainGroup=_FCT0001_FCT0512",
}),
).toBe(true);
// camelCase bomDetails — eski `includes("/bomdetails")` kaçırıyordu.
expect(
isPl24LeafNode({
linkWid: "bomlist",
linkPath: "/p5psa/extern/details/vin/bomDetails?illustration=D2F001A48A",
}),
).toBe(true);
});
it("Volvo (p5volvo): illustrationsTable grup, bom yaprak", () => {
expect(
isPl24GroupNode({
linkWid: "illustrationsTable",
linkPath: "/p5volvo/extern/groups/vin/illustration?group=0b00c8af80205942",
}),
).toBe(true);
expect(isPl24LeafNode({ linkWid: "bomlist", linkPath: "/p5volvo/extern/bom/vin?..." })).toBe(
true,
);
expect(
isPl24LeafNode({
linkWid: "partinfo",
linkPath: "/p5volvo/extern/partinfo/vin?partno=36050493",
}),
).toBe(true);
});
it("Subaru (p5subaru): subgroups/illustrations grup, bom/vin?figNum yaprak", () => {
expect(
isPl24GroupNode({
linkWid: "illustrationsTable",
linkPath: "/p5subaru/extern/groups/vin/illustrations?subGroup=001",
}),
).toBe(true);
expect(
isPl24LeafNode({ linkWid: "bomlist", linkPath: "/p5subaru/extern/bom/vin?figNum=01" }),
).toBe(true);
});
it("wid yoksa yol kalıbına düşer (eski DB satırları)", () => {
expect(isPl24LeafNode({ linkPath: "/p5vwag/extern/bom/vin?illustration=1" })).toBe(true);
expect(
isPl24LeafNode({ linkPath: "/psa/peugeot_parts/vin-image-board.action?illCode=1" }),
).toBe(true);
expect(
isPl24GroupNode({
linkPath: "/psa/peugeot_parts/json-vin-main-groups.action?scope=_FCT0001",
}),
).toBe(true);
});
it("hasSubgroups=true yol tahminini ezer", () => {
expect(isPl24LeafNode({ linkPath: "/p5x/extern/unknown", hasSubgroups: true })).toBe(false);
});
it("servicepart öğe listesi yapraktır", () => {
expect(
isPl24LeafNode({
linkWid: "servicePartsItemsTable",
linkPath: "/p5vwag/extern/servicepart/vin_items?x=1",
}),
).toBe(true);
});
});
describe("isStalePl24Architecture — P4→P5 göç tespiti", () => {
it("eski PSA/Volvo yolu + artık P5 olan servis → bayat", () => {
expect(
isStalePl24Architecture({ catalogPath: "/psa/peugeot_parts", currentApiPath: "/p5psa" }),
).toBe(true);
expect(isStalePl24Architecture({ catalogPath: "/volvo", currentApiPath: "/p5volvo" })).toBe(
true,
);
});
it("zaten P5 kaydı bayat değil", () => {
expect(isStalePl24Architecture({ catalogPath: "/p5psa", currentApiPath: "/p5psa" })).toBe(
false,
);
});
it("hâlâ P4 olan markalar (Ford/Opel/Hyundai) dokunulmaz", () => {
expect(isStalePl24Architecture({ catalogPath: "/ford", currentApiPath: "/ford" })).toBe(false);
expect(isStalePl24Architecture({ catalogPath: "/opel", currentApiPath: "/opel" })).toBe(false);
});
it("eksik bilgi → bayat sayma (güvenli taraf)", () => {
expect(isStalePl24Architecture({ catalogPath: null, currentApiPath: "/p5psa" })).toBe(false);
expect(isStalePl24Architecture({ catalogPath: "/psa/x", currentApiPath: null })).toBe(false);
});
});
/**
* Mitsubishi: parça listesi grup sanılıyordu (plv2.md, bulgu consumers-13).
*
* `/p5mitsubishi/extern/details/vinDetails` yanıtı `partno`/`qty` taşıyan bir
* PARÇA listesi (canlı doğrulama 2026-09-20: 16 kayıt), ama her kaydın linki
* `partInfoTable`. Ne wid ne yol sınıflandırıcıda karşılık bulmuyordu → 2.193
* parça listesi gruba, içlerindeki 19.576 tekil parça kategoriye dönüşmüştü;
* hepsinde toplam 2 parça vardı ve her prefetch turunda yeniden çekiliyorlardı.
*/
describe("Mitsubishi detailsTable / partInfoTable", () => {
const detailsPath =
"/p5mitsubishi/extern/details/vinDetails?bomDetails=133_110D00125Y&mainGroup=33";
const partInfoPath = "/p5mitsubishi/extern/details/vinpartinfo?bomDetails=142_7103K22Y5T";
it("detailsTable bir parça listesi — yaprak", () => {
expect(isPl24LeafNode({ linkWid: "detailsTable", linkPath: detailsPath })).toBe(true);
expect(isPl24GroupNode({ linkWid: "detailsTable", linkPath: detailsPath })).toBe(false);
});
it("partInfoTable tekil parça detayı — ne grup ne liste", () => {
expect(isPl24PartDetailNode({ linkWid: "partInfoTable", linkPath: partInfoPath })).toBe(true);
expect(isPl24GroupNode({ linkWid: "partInfoTable", linkPath: partInfoPath })).toBe(false);
});
it("wid yoksa yol kalıbı parça-detayını yine yakalar", () => {
expect(isPl24PartDetailNode({ linkPath: partInfoPath })).toBe(true);
});
it("gerçek parça uçlarını parça-detayı sanmaz", () => {
// Volvo'nun partinfo yaprağı ve VW'nin bom listesi etkilenmemeli.
expect(
isPl24PartDetailNode({
linkWid: "partinfo",
linkPath: "/p5volvo/extern/partinfo/vin?partno=1",
}),
).toBe(false);
expect(
isPl24PartDetailNode({ linkWid: "bomlist", linkPath: "/p5vwag/extern/bom/vin?x=1" }),
).toBe(false);
});
});

View File

@@ -0,0 +1,151 @@
/**
* One source of truth for "is this PL24 node a parts leaf or a group to drill?".
*
* WHY THIS FILE EXISTS (plv2.md, findings p5core-02 / psa-05 / consumers_jobs-01):
* the same question was answered by four independent heuristics —
* `categories.service` (twice), `catalog.service` and the prefetch worker — and
* they disagreed. Two failure modes shipped repeatedly:
*
* 1. `linkWid.includes("group")` as the "is a group" test. Live P5 PSA's second
* level has wid `illusTable`, Volvo's and Subaru's `illustrationsTable` —
* none contain "group", so those nodes fell through to the parts fetcher,
* which asked an *illustration list* for parts, got records with no partno,
* and rendered a silent empty panel (`parts: []`, no error). This is the same
* class of bug as the 2026-06 `isPsaParent` incident.
* 2. Case-sensitive `includes("/bomdetails")` while p5psa and p5volvo spell the
* endpoint `/details/vin/bomDetails` — so those leaves were queued as groups,
* `getChildren` returned [] and their parts were never prefetched (live today
* for Mitsubishi 99.9% / Fiat 80% / Renault 70% of bomDetails leaves).
*
* The reliable cross-brand marker is the response's own `link.wid`: `bomlist`
* (and the service-parts/partinfo variants) means parts, anything else means
* drill. Path matching stays as a fallback for stored rows without a wid.
*/
/**
* `link.wid` values that identify a parts (BOM) node across every P5 backend.
*
* `detailstable` is Mitsubishi's: `/p5mitsubishi/extern/details/vinDetails`
* answers with 16-ish records carrying `partno`/`qty`, i.e. it IS the parts
* list — but each record's own link is a `partInfoTable` per-part detail, and
* neither the wid nor the path matched anything here, so the whole list was
* drilled as a group. Prod on 2026-09-20: 2,193 Mitsubishi parts lists turned
* into group nodes and their 19,576 individual parts ("SCREW,LOCK CYLINDER",
* "BOLT,STEERING COLUMN WASHER") became categories — 19,576 fake tree nodes
* with 2 parts between them, each re-fetched on every prefetch pass.
*/
const LEAF_WIDS = new Set([
"bomlist",
"bomoverviewlist",
"servicepartsitemstable",
"partinfo",
"detailstable",
]);
/**
* Nodes that describe ONE part rather than a list of them. They are neither a
* group to drill nor a list to fetch: the parent's own response already carried
* the part. Queueing them buys nothing and costs one upstream request each —
* 19,576 of them on prod before this was recognised.
*/
const PART_DETAIL_WIDS = new Set(["partinfotable"]);
const PART_DETAIL_PATH = /\/details\/vinpartinfo\b/i;
/** True when this node is a single part's detail view, not a listing. */
export function isPl24PartDetailNode(opts: {
linkPath?: string | null;
linkWid?: string | null;
}): boolean {
const wid = opts.linkWid?.toLowerCase().trim();
if (wid && PART_DETAIL_WIDS.has(wid)) return true;
return PART_DETAIL_PATH.test(opts.linkPath ?? "");
}
/** `link.wid` values that identify a drillable group node. */
const GROUP_WID_PATTERN =
/(group|scope|illus|illustration|catalog|model|vpages|msppages|chemicals|category|categories)/i;
/**
* Path fragments that only ever appear on a parts endpoint. `image-board` has no
* leading slash on purpose: the legacy PSA leaf is `vin-image-board.action`.
*/
const LEAF_PATH_PATTERN =
/\/(bom|bomdetails|partinfo|vin_items|mdl_items|vin_bomdetails)\b|\/bom\/|\/details\/vin\/bomdetails|\/servicepart\/vin_items|image-board/i;
/** True when this node yields parts (never children). */
export function isPl24LeafNode(opts: {
linkPath?: string | null;
linkWid?: string | null;
hasSubgroups?: boolean | null;
}): boolean {
const wid = opts.linkWid?.toLowerCase().trim();
if (wid) {
if (LEAF_WIDS.has(wid)) return true;
if (GROUP_WID_PATTERN.test(wid)) return false;
}
// Explicit DB hint wins over path guessing when there is no usable wid.
if (opts.hasSubgroups === true) return false;
const lp = opts.linkPath?.toLowerCase() ?? "";
if (!lp) return false;
return LEAF_PATH_PATTERN.test(lp);
}
/** True when this node should be drilled for children. */
export function isPl24GroupNode(opts: {
linkPath?: string | null;
linkWid?: string | null;
hasSubgroups?: boolean | null;
}): boolean {
if (!opts.linkPath && !opts.linkWid) return false;
// A per-part detail node is not a group; drilling it returns nothing.
if (isPl24PartDetailNode(opts)) return false;
return !isPl24LeafNode(opts);
}
/**
* True when a stored vehicle's catalogInfo points at an architecture the service
* no longer uses — i.e. the row was decoded before PSA/Volvo moved to P5.
*
* These vehicles keep serving a tree built from the frozen P4 PSA snapshot
* (upds 2024-02-13) or the dead P4 Volvo endpoint (HTTP 503), and `decodeVin`'s
* db_hit short-circuit means a code fix never reaches them. Detecting the
* mismatch at read time lets each vehicle heal itself on first view instead of
* needing a bulk re-decode storm against the one surviving account.
*/
export function isStalePl24Architecture(opts: {
catalogPath?: string | null;
currentApiPath?: string | null;
}): boolean {
const stored = opts.catalogPath?.toLowerCase() ?? "";
const current = opts.currentApiPath?.toLowerCase() ?? "";
if (!stored || !current) return false;
// Only the two migrated legacy backends; unknown/other paths are left alone.
const storedIsLegacyPsaOrVolvo = stored.startsWith("/psa") || stored.startsWith("/volvo");
if (!storedIsLegacyPsaOrVolvo) return false;
return current.startsWith("/p5");
}
/**
* True when a stored `catalog_vehicles` browse row was listed under an
* architecture the service table no longer uses.
*
* Browse rows are a PERMANENT cache: `CatalogService.getModels` returns early
* whenever the brand already has rows, so `fetchVehicleList` is never called
* again for that brand. The 188 rows listed while PSA and Volvo were still P4
* (127 LEGACY_PSA + 61 LEGACY_VOLVO on prod, 2026-09-20) are therefore pinned
* forever: Peugeot/Citroën browse serves the frozen 2024-02-13 snapshot and
* Volvo/Polestar browse serves an endpoint that answers HTTP 503. Detecting the
* mismatch at list time lets the brand re-list itself once, the same way
* `isStalePl24Architecture` heals a VIN-decoded vehicle.
*/
export function isStaleBrowseArchitecture(opts: {
storedArchitecture?: string | null;
currentArchitecture?: string | null;
}): boolean {
const stored = opts.storedArchitecture?.trim();
const current = opts.currentArchitecture?.trim();
// An unknown service (no config) or an unlabelled row is left alone: without a
// current architecture to compare against there is nothing to migrate TO.
if (!stored || !current) return false;
return stored !== current;
}

View File

@@ -0,0 +1,68 @@
import { readFileSync } from "node:fs";
import { join } from "node:path";
import { describe, expect, it } from "vitest";
import { PL24Service } from "./pl24.service";
/**
* Volvo P5 vinfoBasic regression lock (plv2.md, finding p5core-09).
*
* Volvo emits BOTH a bare internal code and a readable description for the same
* attribute — "Şanzıman kodu" = "B" next to "Şanzıman" = "6-PSHIFT 2WD / MPS6",
* and "Satis tipi" = "42" next to "Türü" = "S80". The key order the parser needs
* for VAG (whose "Şanzıman kodu" IS the useful value, e.g. "MQ200") therefore
* rendered a single letter as the gearbox and a bare number as the series.
*
* Fixtures are the real 2026-09-16 discovery captures for VIN
* YV1AS84ABD1168166 (S80), trimmed to the segments the parser reads, in both
* the Turkish and the English label locale.
*/
const fixture = (name: string) =>
JSON.parse(readFileSync(join(__dirname, "__fixtures__", `${name}.json`), "utf-8"));
// parseVehicleResponse only touches the response and the service name.
const parse = (data: unknown, serviceName = "volvo_parts") => {
const svc = Object.create(PL24Service.prototype) as unknown as {
parseVehicleResponse: (v: string, d: unknown, s: string) => Record<string, unknown>;
isDaimlerService: (s: string) => boolean;
};
svc.isDaimlerService = () => false;
return svc.parseVehicleResponse("YV1AS84ABD1168166", data, serviceName);
};
describe("Volvo P5 vinfoBasic — kod yerine açıklama", () => {
it("Türkçe etiketlerde şanzımanı okunur değerinden alır", () => {
const out = parse(fixture("p5_volvo_tr"));
expect(out.transmission).toBe("6-PSHIFT 2WD / MPS6");
// Tek harflik "Şanzıman kodu" artık kazanmıyor.
expect(out.transmission).not.toBe("B");
});
it("İngilizce etiketlerde de aynı sonucu verir", () => {
const out = parse(fixture("p5_volvo_en"));
expect(out.transmission).toBe("6-PSHIFT 2WD / MPS6");
});
it("seri, çıplak satış kodu yerine gerçek tipi döner", () => {
expect(parse(fixture("p5_volvo_tr")).series).toBe("S80");
expect(parse(fixture("p5_volvo_en")).series).toBe("S80");
expect(parse(fixture("p5_volvo_tr")).series).not.toBe("42");
});
it("kaporta stili iki dilde de çözülür ve '0' kodu sızmaz", () => {
expect(parse(fixture("p5_volvo_tr")).bodyType).toBe("Sedan");
expect(parse(fixture("p5_volvo_en")).bodyType).toBe("Sedan");
});
it("motor alanları bozulmadan kalır", () => {
const out = parse(fixture("p5_volvo_tr"));
expect(out.engineCode).toBe("84");
expect(out.engineType).toBe("D4162T");
});
it("model ve yıl korunur", () => {
const out = parse(fixture("p5_volvo_tr"));
expect(out.model).toBe("S80 (07-)");
expect(out.year).toBe(2013);
});
});

View File

@@ -1,13 +1,29 @@
export const PL24_DEFAULTS = {
AUTH_TOKEN_TTL: 3600, // 1 hour in seconds
/** Service JWTs live 600s (measured); refresh this many ms before expiry. */
SERVICE_TOKEN_SKEW_MS: 60_000,
/** PL24TOKEN is a session cookie with no expiry — we keep our copy for a day. */
SESSION_TTL_S: 86_400,
CACHE_PREFIX: "pl24:",
REQUEST_TIMEOUT: 30000,
MAX_RETRIES: 3,
} as const;
/**
* Real Chrome UA. The old value ("…AppleWebKit/537.36" with no Chrome/Safari
* token) matches no real browser and is a cheap automation tell.
*/
export const PL24_USER_AGENT =
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36";
export const PL24_ENDPOINTS = {
// Auth
LOGIN: "/pl24-appgtw/ext/api/1.0/login",
// Auth — LOGIN is the portal/landing endpoint (returns {loginStatus, sessionToken}
// + Set-Cookie PL24TOKEN). LOGIN_LEGACY is the in-SPA one our old code used; it
// still works and returns a 600s base JWT we no longer need. PL24_LOGIN_API=legacy
// switches back for one release.
LOGIN: "/auth/ext/api/1.1/login",
LOGIN_LEGACY: "/pl24-appgtw/ext/api/1.0/login",
LOGOUT_LEGACY: "/pl24-appgtw/ext/api/1.0/logout",
SESSION: "/auth/ext/api/1.1/session",
AUTHORIZE: "/auth/ext/api/1.1/authorize",
// Catalog

View File

@@ -1,5 +1,7 @@
import { Module } from "@nestjs/common";
import { ProxyTelemetryModule } from "../proxy-telemetry/proxy-telemetry.module";
import { PL24AuthService } from "./pl24-auth.service";
import { PL24BudgetService } from "./pl24-budget.service";
import { PL24FordLegacyService } from "./pl24-ford-legacy.service";
import { PL24FordService } from "./pl24-ford.service";
import { PL24HyundaiKiaService } from "./pl24-hyundai-kia.service";
@@ -11,6 +13,7 @@ import { PL24Service } from "./pl24.service";
const PL24_PROVIDERS = [
PL24Service,
PL24AuthService,
PL24BudgetService,
PL24FordLegacyService,
PL24PsaService,
PL24VolvoService,
@@ -20,6 +23,7 @@ const PL24_PROVIDERS = [
];
@Module({
imports: [ProxyTelemetryModule],
providers: PL24_PROVIDERS,
exports: PL24_PROVIDERS,
})

View File

@@ -15,6 +15,7 @@ const svc = new PL24Service(
{} as never, // redis
{} as never, // storage
{} as never, // posthog
{} as never, // budget
);
const p = svc as unknown as {
parseVehicleResponse(

View File

@@ -20,6 +20,7 @@ import { PostHogService } from "../../posthog/posthog.service";
import { RedisService } from "../../redis/redis.service";
import { StorageService } from "../../storage/storage.service";
import { PL24AuthService } from "./pl24-auth.service";
import { PL24BudgetService } from "./pl24-budget.service";
import { PL24FordLegacyService } from "./pl24-ford-legacy.service";
import { PL24FordService } from "./pl24-ford.service";
import { PL24HyundaiKiaService } from "./pl24-hyundai-kia.service";
@@ -55,6 +56,65 @@ const LEGACY_ARCH_SOURCE_TAG: Record<string, string> = {
LEGACY_HYUNDAI_KIA: "hyundai-kia",
};
/**
* Normalise a vinfoBasic label into a lookup key.
*
* JS `toLowerCase()` maps Turkish "İ" to "i" + U+0307 (combining dot), so PSA
* labels like "AKTARMA SİSTEMLERİ" / "GÖVDE TİPİ" produced keys no lookup could
* ever match and the transmission/body fields silently stayed null. Lower-case
* with the Turkish locale, then strip combining marks and fold "ı" → "i" so a
* single spelling matches both "Model yılı" and "MODEL YILI".
*/
export function normalizeLabel(label: string): string {
return (
label
.toLocaleLowerCase("tr")
.normalize("NFD")
// \p{M} (all combining marks) rather than the U+0300–U+036F range: the range
// is a character class that can also match a base character followed by a
// combining one, which biome flags as misleading. NFD has already split every
// accent into its own mark, so matching marks directly is both correct and
// broader (Turkish, Latin-Extended, anything PL24 sends).
.replace(/\p{M}/gu, "")
.replace(/ı/g, "i")
.replace(/[\s/]+/g, "_")
.trim()
);
}
/**
* PSA model year: "AM 2005" → 2005. Index labels ("01 MAJÖR ENDEKS",
* 'MAJÖR ENDEKS "0C"') are NOT years — returning one there is how a Citroën
* ended up as a 2001 model. PSA VINs also don't encode the model year in
* position 10, so the caller must fall back to DAM or leave it null.
*/
export function parsePsaModelYear(value: string | null | undefined): number | null {
if (!value) return null;
if (/endeks/i.test(value)) return null;
const m = value.match(/\b(?:AM\s*)?((?:19|20)\d{2})\b/i);
if (m) return Number(m[1]);
const short = value.match(/^\s*AM\s*(\d{2})\s*$/i);
if (short) {
const n = Number(short[1]);
return n >= 70 ? 1900 + n : 2000 + n;
}
return null;
}
/**
* PSA "DAM" (e.g. "10479CJ") = days since 1976-01-01 + plant code → build date.
* PSA model years roll in July, so a build after June belongs to the next one.
*/
export function damToModelYear(dam: string | null | undefined): number | null {
if (!dam) return null;
const m = dam.match(/^(\d{4,5})/);
if (!m) return null;
const date = new Date(Date.UTC(1976, 0, 1) + Number(m[1]) * 86_400_000);
const year = date.getUTCFullYear();
if (year < 1980 || year > 2100) return null;
return date.getUTCMonth() >= 6 ? year + 1 : year;
}
@Injectable()
export class PL24Service {
private readonly logger = new Logger(PL24Service.name);
@@ -74,6 +134,7 @@ export class PL24Service {
private redis: RedisService,
private storage: StorageService,
private posthog: PostHogService,
private readonly budget: PL24BudgetService,
) {
this.baseUrl = this.configService.get<string>("pl24.baseUrl", "https://www.partslink24.com");
this.timeout = 30000;
@@ -944,15 +1005,28 @@ export class PL24Service {
return opts;
};
const response = await fetch(url, buildOpts(headers));
// Every PL24 upstream call is counted and logged here (the one choke point).
const response = await this.budgetedFetch(
url,
buildOpts(headers),
account,
Boolean(dispatcher),
);
if (response.status === 401) {
this.logger.warn(`Got 401 (account=${account}), refreshing token...`);
this.logger.warn(`Got 401 (account=${account}), refreshing service token...`);
// A stale *service* token is the cheap explanation; the session itself is
// only dropped if the re-authorize also fails (handled in the auth service).
this.authService.clearTokensForAccount(account);
await this.authService.authorizeServiceForAccount(serviceName, account);
const newHeaders = await this.authService.buildAuthHeadersForAccount(account, serviceName);
const retry = await fetch(url, buildOpts(newHeaders));
const retry = await this.budgetedFetch(
url,
buildOpts(newHeaders),
account,
Boolean(dispatcher),
);
if (!retry.ok) {
throw new Error(`HTTP ${retry.status}: ${retry.statusText}`);
@@ -971,6 +1045,50 @@ export class PL24Service {
return response;
}
/**
* Single gate for PL24 upstream traffic: daily budget first (a refusal costs
* no request at all), then the call, then telemetry into `proxy_logs`.
*/
private async budgetedFetch(
url: string,
opts: RequestInit & { dispatcher?: any },
account: "tr" | "de",
proxied: boolean,
): Promise<Response> {
// The kill switch used to gate decodeVin only, so drills, backfill and
// catalog browse kept hammering PL24 after the source was "killed".
if (!(await this.posthog.isSourceLive("pl24"))) {
throw new ServiceUnavailableException("PL24 kapali (kill-source-pl24)");
}
await this.budget.consume("catalog");
const startedAt = Date.now();
const activeAccount = this.authService.activeAccount(account);
try {
const response = await fetch(url, opts);
this.budget.record({
kind: "catalog",
url,
proxied,
account: activeAccount,
statusCode: response.status,
success: response.ok,
startedAt,
});
return response;
} catch (error) {
this.budget.record({
kind: "catalog",
url,
proxied,
account: activeAccount,
success: false,
startedAt,
error,
});
throw error;
}
}
// ==================== PRIVATE: Account routing ====================
/**
@@ -1026,6 +1144,78 @@ export class PL24Service {
// ==================== PRIVATE: Response parsers ====================
/**
* Ask a P5 backend where its own model list lives, instead of guessing.
*
* Every P5 backend serves `/extern/catmeta`, whose `data.catalogEntryPoint.path`
* is the authoritative browse entry point — e.g. p5psa answers
* `/p5psa/extern/vehicle/catalogs`, p5volvo `/p5volvo/extern/vehicles/models`.
* The old behaviour, when `BACKEND_MODEL_PATH` had no entry, was to fire the
* seven known paths in turn and keep whichever returned rows. That costs up to
* seven upstream requests per call on a shared daily budget, and it silently
* fails for any backend whose path is not already on the list — which is how
* Volvo/Polestar browse ended up seeding zero models while still serving the
* retired P4 listing.
*
* The resolved path is cached per backend (30 days) so this costs one request
* for a backend's whole lifetime, and it self-heals if PL24 moves an endpoint.
* Returns null on any failure; the caller then falls back as before.
*/
private async resolveModelPathFromCatmeta(
catalogBase: string,
serviceName: string,
headers: Record<string, string>,
): Promise<string | null> {
const cacheKey = `pl24:modelpath:${catalogBase.replace(/^\//, "")}`;
try {
const cached = await this.redis.get(cacheKey);
if (cached) return cached === "none" ? null : cached;
} catch {
// Redis down — resolve live rather than failing the listing.
}
let resolved: string | null = null;
try {
const url = `${this.baseUrl}${catalogBase}/extern/catmeta?serviceName=${serviceName}&country=DE&lang=${this.language}`;
const res = await fetch(url, { method: "GET", headers, signal: AbortSignal.timeout(15000) });
if (res.ok) {
const meta = (await res.json()) as {
data?: { catalogEntryPoint?: { path?: string } };
};
const full = meta.data?.catalogEntryPoint?.path;
if (full) {
// catmeta returns the absolute path with query string
// ("/p5volvo/extern/vehicles/models?lang=en&serviceName=…"); the caller
// appends its own lang/serviceName, so keep only the backend-relative
// path segment.
const withoutQuery = full.split("?")[0];
const relative = withoutQuery.startsWith(catalogBase)
? withoutQuery.slice(catalogBase.length)
: withoutQuery;
if (relative.startsWith("/extern/")) resolved = relative;
}
}
} catch (err) {
this.logger.warn(
`fetchVehicleList: catmeta lookup failed for ${serviceName}: ${(err as Error).message}`,
);
}
if (resolved) {
this.logger.log(
`fetchVehicleList: ${serviceName} model path resolved from catmeta → ${resolved}`,
);
}
try {
// Cache the negative too, so a backend without a usable catmeta does not
// re-probe on every browse.
await this.redis.set(cacheKey, resolved ?? "none", 30 * 86_400);
} catch {
// best effort
}
return resolved;
}
/**
* Parse vehicle data from directAccess response.
*/
@@ -1051,7 +1241,7 @@ export class PL24Service {
const label = (v.key !== undefined ? v.key : v.description) || "";
const value = (v.key !== undefined ? v.description : v.value) || "";
if (!label) continue;
const key = label.toLowerCase().replace(/[\s\/]+/g, "_");
const key = normalizeLabel(label);
if (!(key in vehicleData)) {
// Normalize like prNr col3: newlines→space, unescape the literal "\-" some P5
// backends emit (JLR "XJ 2010 \- 2019", Toyota/Suzuki dates "2023\-11\-29"/"2005\-07"),
@@ -1073,6 +1263,31 @@ export class PL24Service {
return null;
};
/**
* Like `lookup`, but prefers a human-readable value over a bare internal
* code when the record carries both.
*
* Volvo's vinfoBasic has BOTH "Şanzıman kodu" ("B") and "Şanzıman"
* ("6-PSHIFT 2WD / MPS6"), and BOTH "Satis tipi" ("42") and a second
* "Satis tipi" ("SALES VERSION 42"). The code-first key order that VAG needs
* (its "Şanzıman kodu" IS the useful value, e.g. "MQ200") therefore rendered
* a single letter as the Volvo gearbox and a bare number as its series.
*
* Falls back to the first present value, so a backend that only ever emits
* codes behaves exactly as before.
*/
const lookupDescriptive = (...keys: string[]): string | null => {
let firstPresent: string | null = null;
for (const k of keys) {
const v = vehicleData[k]?.trim();
if (!v) continue;
if (firstPresent === null) firstPresent = v;
// Two characters or fewer, or digits only → an index, not a description.
if (v.length > 2 && !/^\d+$/.test(v)) return v;
}
return firstPresent;
};
// Extract prNr records for richer vehicle attributes
const prNrRecords = segments.prNr?.records || [];
const prNrByCode: Record<string, string> = {};
@@ -1098,26 +1313,47 @@ export class PL24Service {
const engineCode = lookup("motor_kodu", "engine_code");
// Non-VAG P5 OEMs label the engine differently and give a description (sometimes with a
// code in parens): JLR "Motor Tipi", Toyota "ENGINE 1", MAN "Yedek motor", Suzuki "Motor No.".
const engineLabel = lookup("motor_tipi", "engine_1", "yedek_motor", "motor_no.");
// PSA labels the full designation "MOTOR" ("TÜRBO DİZEL DV6TED4…"), Volvo
// "Motor" ("D4162T"), Subaru "Engine" — none of which the VAG-shaped list had.
const engineLabel = lookup(
"motor_tipi",
"engine_1",
"yedek_motor",
"motor_no.",
"motor",
"engine",
);
// Transmission: VAG "Şanzıman kodu"; other OEMs use their own labels — JLR "Vites Kutusu",
// Toyota "ATM,MTM" (key "atm,mtm" — only spaces/slashes are underscored), MAN "Şanzıman",
// Suzuki "Şanzıman numarası".
const transmissionCode = lookup(
"şanzıman_kodu",
"sanzıman_kodu",
// normalizeLabel folds ı→i and strips diacritics, so "Şanzıman kodu" and
// "ŞANZIMAN KODU" both arrive as "sanziman_kodu". PSA uses "AKTARMA
// SİSTEMLERİ" ("5 MEKANİK VİTES KUTUSU"), Subaru "Mission".
const transmissionCode = lookupDescriptive(
"sanziman_kodu",
"transmission_code",
"vites_kutusu",
"atm,mtm",
"şanzıman",
"şanzıman_numarası",
"aktarma_sistemleri",
"sanziman",
// Volvo in the English locale: "Transmission code" ("B") plus the readable
// "Transmission" ("6-PSHIFT 2WD / MPS6"). Without the plain key the
// English response falls back to the single-letter code.
"transmission",
"sanziman_numarasi",
"mission",
);
// Build body type from prNr K8* (Kaporta formları); brands without a prNr segment
// (e.g. BMW) carry it in vinfoBasic "Karoseri" ("Limousine").
const bodyType =
Object.entries(prNrByCode).find(([code]) => code.startsWith("K8"))?.[1] ||
lookup("karoseri", "body", "body_type") ||
// PSA "GÖVDE TİPİ" ("4 KAPILI SEDAN"), Volvo "Kaporta Stili" ("Sedan").
// Volvo: TR "Kaporta Stili" / EN "Body style" ("Sedan"). Its
// "Karoseri Tipi Kodu" / "Body style code" is a bare "0" — never matched
// here because the lookup is exact-key, and that is deliberate.
lookup("karoseri", "body", "body_type", "govde_tipi", "kaporta_stili", "body_style") ||
null;
// Engine description from prNr D3* (Motor nitelikleri)
@@ -1140,7 +1376,7 @@ export class PL24Service {
// the friendly name is in "Araç" / description ("L200(EUR/MMTH)") — strip the region suffix.
const isMitsubishi = getServiceApiPath(serviceName) === "/p5mitsubishi";
const baseModel = isMitsubishi
? (lookup("araç") || (data.description as string) || lookup("model") || "")
? (lookup("arac") || (data.description as string) || lookup("model") || "")
.replace(/\s*\([^)]*\)\s*$/, "")
.trim()
: lookup("model_bilgisi", "model")?.trim() ||
@@ -1163,17 +1399,23 @@ export class PL24Service {
// production date ("05/09/2014"); p5daimler → only "Teslimat tarihi" (delivery, "04.05.2009").
// Falling through to the VIN year-char (extractModelYear) is the last resort and is often
// wrong for Mercedes (10th-char "1" → 2001 for a 2015 car), so read the dates first.
// PSA writes "AM 2005" (or an index label that is NOT a year) and its VINs
// do not encode the model year in position 10, so parse the PSA forms
// first and fall back to the DAM build date before ever touching the VIN.
year:
parsePsaModelYear(lookup("model_yili", "year")) ||
Number.parseInt(lookup("model_yili", "year") || "", 10) ||
Number.parseInt(
(lookup("my", "üretim_tarihi", "uretim_tarihi", "teslimat_tarihi") || "").match(
/(19|20)\d{2}/,
)?.[0] || "",
(lookup("my", "uretim_tarihi", "teslimat_tarihi") || "").match(/(19|20)\d{2}/)?.[0] || "",
10,
) ||
damToModelYear(lookup("dam")) ||
extractModelYear(vin) ||
0,
series: lookup("seri", "satis_tipi", "sales_type"),
// Volvo's "Satis tipi" is the bare sales code ("42") with the readable
// form ("SALES VERSION 42") in a duplicate row, and its "Türü" is the real
// series ("S80") — so prefer whichever of these is actually descriptive.
series: lookupDescriptive("seri", "satis_tipi", "sales_type", "turu", "type"),
bodyType,
engineCode:
engineCode ||
@@ -1187,7 +1429,7 @@ export class PL24Service {
colorCode:
lookup("dis_rengi_boya_numarasi", "exterior_color___paint_code") ||
lookup("tavan_rengi", "roof_color"),
productionDate: lookup("üretim_tarihi", "date_of_production"),
productionDate: lookup("uretim_tarihi", "date_of_production", "teslimat_tarihi"),
raw: data,
catalogInfo: {
serviceName,
@@ -1352,9 +1594,14 @@ export class PL24Service {
const values = (record.values as Record<string, string>) || {};
const link = (record.link as Record<string, unknown>) || {};
// PSA (p5psa) shares one `record.id` (the illusPath) across many
// illustrations — 36 live records had only 11 distinct ids — so the unique
// key is `values.illustration` ("D2F 0 01A 48A", spaces stripped). Without
// this the children collapse onto each other and most get dropped.
const code =
values.subgroup ||
values.illustrationNumber ||
values.illustration?.replace(/\s+/g, "") ||
values.id ||
values.code ||
String(record.id || "");
@@ -1432,11 +1679,14 @@ export class PL24Service {
records = responseData.parts as Array<Record<string, unknown>>;
}
const partRecords = records.filter(
(record) =>
record.characteristic !== "sectionrow" &&
(record.partno || (record.values as Record<string, unknown>)?.partno),
);
const partRecords = records.filter((record) => {
if (record.characteristic === "sectionrow") return false;
if (!(record.partno || (record.values as Record<string, unknown>)?.partno)) return false;
// Volvo (p5volvo) prefixes each BOM with a header row that carries a
// partno but no link and is flagged unavailable — a phantom part if kept.
if (record.id === "null_null" || (record.unavailable === true && !record.link)) return false;
return true;
});
return partRecords.map((part) => {
const values = (part.values as Record<string, string>) || {};
@@ -1444,11 +1694,14 @@ export class PL24Service {
const formattedPartNo = ((part.partno as string) || values.partno || "").trim();
const cleanPartNo = formattedPartNo.replace(/\s+/g, "");
const qtyStr = values.qty || "";
// qty (VAG/Subaru) · coef (PSA) · unit (Volvo) — same field, three names.
const qtyStr = values.qty || values.coef || values.unit || "";
const quantity = Number.parseInt(qtyStr.trim(), 10) || undefined;
const remark = values.remark?.trim() || undefined;
const modelCodes = values.modelDescription?.trim() || undefined;
// PSA/Volvo/Subaru express applicability as `restriction`
// ("+ DIESEL TURBO DV6TED4 WITHOUT FAP"); VAG uses modelDescription.
const modelCodes = (values.modelDescription || values.restriction)?.trim() || undefined;
let superseded: { oldCode: string; newCode: string } | undefined;
const supersededByValue = (part.supersededBy as string) || values.supersededBy || "";
@@ -2052,11 +2305,22 @@ export class PL24Service {
p5mitsubishi: "/extern/vehicles/vehiclesOverview", // Mitsubishi
p5suzuki: "/extern/vehicle/modelFamilies", // Suzuki
p5man: "/extern/model/categories", // MAN trucks
// Pinned 2026-09-20 from each backend's own catmeta `catalogEntryPoint`
// (see resolveModelPathFromCatmeta). Before this, p5psa needed five wasted
// probe requests to rediscover its path on every call, and p5volvo found
// nothing at all — none of the seven guessed paths matches its plural
// `/extern/vehicles/models`, so Volvo/Polestar browse silently seeded zero
// models and kept serving the dead P4 listing.
p5psa: "/extern/vehicle/catalogs", // Peugeot, Citroën, DS, psa_opel, psa_vauxhall
p5volvo: "/extern/vehicles/models", // Volvo, Polestar — NOTE: plural "vehicles"
};
// catalogBase is like "/p5vwag" — strip leading slash for map lookup
const backendKey = catalogBase.replace(/^\//, "");
const modelPath = BACKEND_MODEL_PATH[backendKey] ?? "/extern/vehicle/modelfamilies";
const modelPath =
BACKEND_MODEL_PATH[backendKey] ??
(await this.resolveModelPathFromCatmeta(catalogBase, serviceName, headers)) ??
"/extern/vehicle/modelfamilies";
const url = `${this.baseUrl}${catalogBase}${modelPath}?lang=${this.language}&serviceName=${serviceName}`;

View File

@@ -1,5 +1,5 @@
import { describe, expect, it } from "vitest";
import { PL24_WMI_SERVICE_MAP, SERVICE_TO_BRAND } from "./pl24.types";
import { PL24_SERVICE_CATALOGS, PL24_WMI_SERVICE_MAP, SERVICE_TO_BRAND } from "./pl24.types";
// Q6 routing additions (undecoded-vin-rca.md). Both target services are already
// live in prod (nissan_parts: JN1 success; mercedesvans_parts: WDF decodes today),
@@ -27,3 +27,71 @@ describe("PL24_WMI_SERVICE_MAP — Q6 routing additions", () => {
}
});
});
// PL24'te bulunmayan WMI'ler: haritada yer almamalı, yoksa her sorguda boşuna
// upstream isteği üretir ve gerçek kaynağa (pcat/emex/vinpin) geçişi geciktirir.
describe("PL24_WMI_SERVICE_MAP — kapsam dışı WMI'ler", () => {
it("VR7 haritada değil (canlı: HTTP 410 'no brands found for WMI = VR7')", () => {
expect(PL24_WMI_SERVICE_MAP.VR7).toBeUndefined();
});
it("NM4 (Tofaş) haritada değil (canlı: HTTP 410)", () => {
expect(PL24_WMI_SERVICE_MAP.NM4).toBeUndefined();
});
it("canlı doğrulanmış WMI'ler doğru katalogda", () => {
expect(PL24_WMI_SERVICE_MAP.JF1).toBe("subaru_parts");
expect(PL24_WMI_SERVICE_MAP.ZAR).toBe("alfa_parts");
expect(PL24_WMI_SERVICE_MAP.VXK).toBe("psa_opel_parts");
});
});
/**
* 2026-09-20 canlı WMI servisi taraması (plv2.md, bulgu types_wmi-06/09).
* Prod'daki 1.406 haritasız araçtan hangilerinin PL24'te gerçekten karşılığı
* olduğu `/pl24-wmi/ext/api/2.0/decode` ile tek tek soruldu; bu test o cevapları
* kilitliyor — özellikle "yok" cevaplarını, çünkü onları haritaya eklemek
* boşuna istek üretir.
*/
describe("WMI haritası — canlı WMI servisi taraması (2026-09-20)", () => {
it("Renault yeniden açıldı (VIN tanımlama askısı kalktı)", () => {
expect(PL24_WMI_SERVICE_MAP.VF1).toBe("renault_parts");
expect(PL24_WMI_SERVICE_MAP.VF6).toBe("renault_parts");
expect(PL24_WMI_SERVICE_MAP.VNE).toBe("renault_parts");
});
it("canlı servisin çözdüğü yeni WMI'ler haritada", () => {
expect(PL24_WMI_SERVICE_MAP.NLH).toBe("hyundai_parts");
expect(PL24_WMI_SERVICE_MAP.TMA).toBe("hyundai_parts");
expect(PL24_WMI_SERVICE_MAP.NLJ).toBe("hyundai_parts");
expect(PL24_WMI_SERVICE_MAP.KMF).toBe("hyundai_parts");
expect(PL24_WMI_SERVICE_MAP.KNE).toBe("kia_parts");
expect(PL24_WMI_SERVICE_MAP.KNC).toBe("kia_parts");
expect(PL24_WMI_SERVICE_MAP.MMC).toBe("mmc_parts");
expect(PL24_WMI_SERVICE_MAP.XMC).toBe("mmc_parts");
expect(PL24_WMI_SERVICE_MAP.JSA).toBe("suzuki_parts");
});
it("NMB binek Mercedes değil, kamyon kataloğuna gider", () => {
expect(PL24_WMI_SERVICE_MAP.NMB).toBe("mercedestrucks_parts");
// Binek WMI'leri bozulmadı.
expect(PL24_WMI_SERVICE_MAP.WDD).toBe("mercedes_parts");
});
it("PL24'te olmayan WMI'ler haritaya EKLENMEDİ (HTTP 410)", () => {
// Honda ve Chevrolet'nin PL24'te kataloğu yok; eklemek boşuna istek olurdu.
for (const wmi of ["JHM", "SHH", "SHS", "MAK", "NLA", "KL1", "NM4", "VR7"]) {
expect(PL24_WMI_SERVICE_MAP[wmi]).toBeUndefined();
}
});
it("JMZ (Mazda) eklenmedi — servis Ford kataloğu öneriyor, marka tutarsız", () => {
expect(PL24_WMI_SERVICE_MAP.JMZ).toBeUndefined();
});
it("eşlenen her servisin katalog tanımı var", () => {
for (const [wmi, svc] of Object.entries(PL24_WMI_SERVICE_MAP)) {
expect(PL24_SERVICE_CATALOGS[svc], `${wmi} → ${svc}`).toBeDefined();
}
});
});

View File

@@ -53,6 +53,58 @@ export interface PL24JWTPayload {
alo: string;
}
/** Portal login (`/auth/ext/api/1.1/login`) request + response. */
export interface PL24LoginRequestV2 {
account: string;
user: string;
password: string;
squeezeOut: boolean;
/** Two-factor confirmation code, when PL24 asks for one. */
code?: string;
}
export interface PL24LoginResponseV2 {
loginStatus?: "OK" | string;
sessionToken?: string;
}
/**
* RFC7807 body PL24 returns on a refused login (HTTP 400/412). `type` carries
* the reason; the UI bundle enumerates these.
*/
export interface PL24LoginProblem {
type?: string;
title?: string;
detail?: string;
/** For two-fa-required: "AUTHENTICATOR" | "EMAIL". */
method?: string;
code?: string;
token?: string;
completionToken?: string;
}
export const PL24_LOGIN_PROBLEM = {
SESSION_LIMIT_EXCEEDED: "urn:login:session-limit-exceeded",
TWO_FA_REQUIRED: "urn:login:two-factor-authentication-required",
TWO_FA_INVALID: "urn:login:two-factor-authentication-invalid-code",
ACCOUNT_PENDING: "urn:login:account-pending",
PRECONDITION_FAILED: "urn:login:precondition-failed",
ACCOUNT_NOT_ACTIVE: "urn:login:account-not-active",
USER_NOT_ACTIVE: "urn:login:user-not-active",
AUTHENTICATION_FAILED: "urn:login:authentication",
} as const;
/**
* One PL24 session = the PL24TOKEN cookie. It has no expiry of its own; it dies
* when PL24 squeezes it out (another login on the same account) or is revoked,
* which surfaces as authorize → 401 or `session_status: "gone"`.
*/
export interface PL24Session {
sessionToken: string;
loginAt: number;
lastOkAt: number;
}
export interface PL24TokenData {
accessToken: string;
refreshToken: string;
@@ -287,19 +339,61 @@ export const PL24_SERVICE_CATALOGS: Record<string, PL24CatalogConfig> = {
// PSA Group (Citroën, Peugeot)
citroen_parts: {
basePath: "/psa",
apiPath: "/psa",
architecture: "LEGACY_PSA",
basePath: "/pl24-app/citroen_parts",
apiPath: "/p5psa",
architecture: "P5_MODERN",
},
citroenDs_parts: {
basePath: "/psa",
apiPath: "/psa",
architecture: "LEGACY_PSA",
basePath: "/pl24-app/citroenDs_parts",
apiPath: "/p5psa",
architecture: "P5_MODERN",
},
peugeot_parts: {
basePath: "/psa",
apiPath: "/psa",
architecture: "LEGACY_PSA",
basePath: "/pl24-app/peugeot_parts",
apiPath: "/p5psa",
architecture: "P5_MODERN",
},
// Stellantis-era Opel/Vauxhall — the PSA-platform catalogue (Corsa F, Mokka B…).
// GM-era W0L/W0V cars stay in the legacy opel_parts P4 catalogue below.
psa_opel_parts: {
basePath: "/pl24-app/psa_opel_parts",
apiPath: "/p5psa",
architecture: "P5_MODERN",
},
psa_vauxhall_parts: {
basePath: "/pl24-app/psa_vauxhall_parts",
apiPath: "/p5psa",
architecture: "P5_MODERN",
},
// Subaru (own P5 backend)
subaru_parts: {
basePath: "/pl24-app/subaru_parts",
apiPath: "/p5subaru",
architecture: "P5_MODERN",
},
// Rest of the Fiat/Stellantis family — same /p5fiat backend as fiatp/fiatt
abarth_parts: {
basePath: "/pl24-app/abarth_parts",
apiPath: "/p5fiat",
architecture: "P5_MODERN",
},
alfa_parts: {
basePath: "/pl24-app/alfa_parts",
apiPath: "/p5fiat",
architecture: "P5_MODERN",
},
jeep_parts: {
basePath: "/pl24-app/jeep_parts",
apiPath: "/p5fiat",
architecture: "P5_MODERN",
},
lancia_parts: {
basePath: "/pl24-app/lancia_parts",
apiPath: "/p5fiat",
architecture: "P5_MODERN",
},
// Ford Group
@@ -352,14 +446,14 @@ export const PL24_SERVICE_CATALOGS: Record<string, PL24CatalogConfig> = {
// Volvo/Polestar
volvo_parts: {
basePath: "/volvo",
apiPath: "/volvo",
architecture: "LEGACY_VOLVO",
basePath: "/pl24-app/volvo_parts",
apiPath: "/p5volvo",
architecture: "P5_MODERN",
},
polestar_parts: {
basePath: "/volvo",
apiPath: "/volvo",
architecture: "LEGACY_VOLVO",
basePath: "/pl24-app/polestar_parts",
apiPath: "/p5volvo",
architecture: "P5_MODERN",
},
// Fiat Group (FCA) — P5 Modern catalog at /p5fiat, requires de-708171 account.
@@ -446,6 +540,10 @@ export const PL24_WMI_SERVICE_MAP: Record<string, string> = {
// Mercedes-Benz
WDB: "mercedes_parts",
// NMB: canlı WMI servisi bunu mercedes_parts'a DEĞİL mercedestrucks_parts'a
// çözüyor (error:false) — 30 prod aracı "Mercedes-Benz" etiketliydi ama binek
// kataloğunda yok.
NMB: "mercedestrucks_parts",
WDD: "mercedes_parts",
WDC: "mercedes_parts",
W1K: "mercedes_parts",
@@ -484,15 +582,21 @@ export const PL24_WMI_SERVICE_MAP: Record<string, string> = {
JTJ: "lexus_parts",
"2T2": "lexus_parts",
// Renault — DISABLED: PL24 has suspended Renault VIN identification ("Bu marka
// için şasi numarası tanımlamasının belirsiz bir süre için mevcut olmayacağını
// üzülerek bildiririz."). renault_parts authorizes fine but every decode throws
// that message → wasted ~1s call AND it trips the PL24 circuit breaker, which
// then skips PL24 for ALL brands. PCAT + EMEX cover Renault. Re-enable when PL24
// restores Renault VIN decode.
// VF1: "renault_parts",
// VF6: "renault_parts",
// VNE: "renault_parts",
// Renault — RE-ENABLED 2026-09-20. It was disabled while PL24 had suspended
// Renault VIN identification ("Bu marka için şasi numarası tanımlamasının
// belirsiz bir süre için mevcut olmayacağını üzülerek bildiririz."), which both
// wasted a call per decode and, back then, tripped the global PL24 breaker.
// BOTH reasons are gone, each verified against prod rather than assumed:
// 1. The suspension is over — live directAccess on /p5renault for a real
// customer VIN (VF14SRCL458170337) returns resultStatus
// VEHICLE_IDENTIFIED, "SYMBOL II/LOGAN II", and the WMI service answers
// {service: renault_parts, valid: true, error: false}.
// 2. The breaker no longer counts definitive upstream negatives, only
// transient transport faults (see vehicles.service `isTransient`).
// 450 prod vehicles carry VF1 and had no PL24 catalog at all.
VF1: "renault_parts",
VF6: "renault_parts",
VNE: "renault_parts",
// Dacia
UU1: "dacia_parts",
@@ -512,6 +616,10 @@ export const PL24_WMI_SERVICE_MAP: Record<string, string> = {
WMH: "man_parts",
// Mitsubishi
// XMC / MMC: canlı WMI servisi ikisini de mmc_parts'a çözüyor ve P5 doğruluyor
// (error:false) — 26 prod aracı haritasızdı.
MMC: "mmc_parts", // Mitsubishi Japan
XMC: "mmc_parts", // Mitsubishi (diğer pazarlar)
JMB: "mmc_parts",
JMY: "mmc_parts",
MMB: "mmc_parts",
@@ -521,6 +629,7 @@ export const PL24_WMI_SERVICE_MAP: Record<string, string> = {
JS2: "suzuki_parts",
JS3: "suzuki_parts",
TSM: "suzuki_parts",
JSA: "suzuki_parts", // Suzuki (canlı WMI: suzuki_parts, error:false)
MA3: "suzuki_parts",
MBH: "suzuki_parts",
@@ -536,18 +645,27 @@ export const PL24_WMI_SERVICE_MAP: Record<string, string> = {
ZFA: "fiatp_parts", // Fiat SpA Italy (most common)
ZCF: "fiatp_parts", // Tofaş Turkey (Linea, Fiorino, etc.)
ZFF: "fiatp_parts", // Abarth / Fiat Sport
ZAR: "fiatp_parts", // Alfa Romeo
ZLA: "fiatp_parts", // Lancia
ZAR: "alfa_parts", // Alfa Romeo (kendi kataloğu, /p5fiat backend)
ZLA: "lancia_parts", // Lancia (kendi kataloğu, /p5fiat backend)
// Fiat Commercial (fiatt_parts)
ZFC: "fiatt_parts", // Fiat Commercial
// Hyundai
KMH: "hyundai_parts", // Hyundai Korea Motor House
// Aşağıdakiler 2026-09-20'de canlı WMI servisinden alındı; hepsi hyundai_parts.
// TMA iki marka döndürüyor (hyundai_parts + kia_parts) — Hyundai Assan (Türkiye)
// üretimi olduğu için hyundai seçildi.
NLH: "hyundai_parts", // Hyundai Assan / Türkiye (106 prod aracı)
TMA: "hyundai_parts", // Hyundai Türkiye (49)
NLJ: "hyundai_parts", // Hyundai (8)
KMF: "hyundai_parts", // Hyundai (7)
TMK: "hyundai_parts", // Hyundai (Turkey/other markets)
// Kia
KNA: "kia_parts", // Kia (worldwide production)
KNE: "kia_parts", // Kia (canlı WMI, 31 prod aracı)
KNC: "kia_parts", // Kia (canlı WMI, 8)
U5Y: "kia_parts", // Kia Slovakia
// Nissan
@@ -563,9 +681,16 @@ export const PL24_WMI_SERVICE_MAP: Record<string, string> = {
JNK: "infiniti_parts", // Infiniti (Japan/Korea)
// Opel / Vauxhall
// Subaru (canlı WMI decode: JF1 → subaru_parts, error:false)
JF1: "subaru_parts",
JF2: "subaru_parts",
// Jeep (Stellantis; /p5fiat backend)
"1C4": "jeep_parts",
"1J4": "jeep_parts",
W0L: "opel_parts", // Opel AG (Germany)
W0V: "opel_parts", // Opel (newer Stellantis-era WMI)
VXK: "opel_parts", // PSA/Stellantis-platform Opel (Corsa F, Mokka B — France/Spain plants)
VXK: "psa_opel_parts", // PSA-platform Opel (Corsa F, Mokka B) → Stellantis kataloğu /p5psa
// Citroën (PSA)
VF7: "citroen_parts", // Citroën SA (France)
@@ -574,7 +699,19 @@ export const PL24_WMI_SERVICE_MAP: Record<string, string> = {
// Peugeot (PSA)
VF3: "peugeot_parts", // Peugeot SA (France)
VR3: "peugeot_parts", // Peugeot (newer WMI)
VR7: "peugeot_parts", // Peugeot (newer WMI)
// VR7: PL24'ün WMI veritabanında HİÇ YOK — canlı doğrulama (2026-09-19,
// /pl24-wmi/ext/api/2.0/decode): HTTP 410 "no brands found for WMI = VR7",
// tıpkı Tofaş NM4 gibi. Önceden peugeot_parts'a yönlendiriliyordu; prod'daki
// 17 VR7 aracının hepsi model çözülmeden ("Peugeot Peugeot") ve 0 kategoriyle
// kaydedilmişti. Haritada tutmak yalnız boşuna PL24 isteği üretir ve
// pcat/emex/vinpin fallback'ini geciktirir.
// PL24'TE HİÇ OLMAYANLAR — canlı WMI servisi HTTP 410 "no brands found for WMI"
// dedi (2026-09-20), tıpkı NM4 ve VR7 gibi. Haritaya eklenmemeleri kasıtlı:
// eklemek yalnız boşuna istek üretir ve pcat/emex/vinpin fallback'ini geciktirir.
// JHM, SHH, SHS, MAK, NLA (Honda) · KL1 (Chevrolet)
// JMZ (Mazda) 410 DEĞİL ama fordp/fordt döndürüyor (Ford-Mazda platform ortaklığı
// dönemi); marka tutarsız olduğu için eklenmedi — bir Mazda 3 Ford kataloğunda yok.
// Volvo
YV1: "volvo_parts", // Volvo Cars (Sweden)
@@ -794,6 +931,13 @@ export const SERVICE_TO_BRAND: Record<string, string> = {
vauxhall_parts: "Opel",
// Volvo/Polestar
volvo_parts: "Volvo",
subaru_parts: "Subaru",
psa_opel_parts: "Opel",
psa_vauxhall_parts: "Opel",
abarth_parts: "Abarth",
alfa_parts: "Alfa Romeo",
jeep_parts: "Jeep",
lancia_parts: "Lancia",
polestar_parts: "Polestar",
// Fiat Group
fiatp_parts: "Fiat",

View File

@@ -4,7 +4,7 @@ import { proxyLogs } from "../../database/schema/core";
/**
* Proxy telemetry — fire-and-forget logging of every proxied upstream attempt
* (pcat call/capture/validate, emex http) into `proxy_logs`, so the Süper Panel
* (pcat call/capture/validate, emex http, pl24 catalog/auth) into `proxy_logs`, so the Süper Panel
* can grade proxy providers per service and track banned exit IPs / sessions.
*
* Design constraints:
@@ -13,7 +13,13 @@ import { proxyLogs } from "../../database/schema/core";
* - Bounded memory: the buffer is capped; when full, oldest rows are dropped.
*/
export type ProxyServiceLeg = "pcat_call" | "pcat_capture" | "pcat_validate" | "emex_http";
export type ProxyServiceLeg =
| "pcat_call"
| "pcat_capture"
| "pcat_validate"
| "emex_http"
| "pl24_http"
| "pl24_auth";
export type ProxyProviderName = "floxy" | "dataimpulse" | "none";
export interface ProxyLogEvent {

View File

@@ -0,0 +1,148 @@
import { afterEach, describe, expect, it, vi } from "vitest";
import { RpartstoreAuthError, decodeJwtExpiry, loginRpartstore } from "./rpartstore.auth";
const b64url = (s: string): string => Buffer.from(s).toString("base64url");
const makeJwt = (claims: Record<string, unknown>): string =>
`${b64url('{"alg":"RS256"}')}.${b64url(JSON.stringify(claims))}.sig`;
function jsonResponse(
body: unknown,
init: { status?: number; headers?: Record<string, string> } = {},
) {
return new Response(JSON.stringify(body), {
status: init.status ?? 200,
headers: { "content-type": "application/json", ...(init.headers ?? {}) },
});
}
describe("loginRpartstore (Okta IDX, browser-free)", () => {
afterEach(() => vi.unstubAllGlobals());
it("walks authorize → introspect → identify → answer → redirect → token and returns the access token", async () => {
const exp = Math.floor(Date.now() / 1000) + 3600;
const jwt = makeJwt({ sub: "G123326", exp });
const calls: { url: string; body?: string; cookie?: string }[] = [];
let redirectState = "";
const fetchImpl = vi.fn(async (url: string | URL, init?: RequestInit) => {
const u = String(url);
const headers = (init?.headers ?? {}) as Record<string, string>;
calls.push({
url: u,
body: init?.body ? String(init.body) : undefined,
cookie: headers.Cookie,
});
if (u.includes("/v1/authorize")) {
redirectState = new URL(u).searchParams.get("state") ?? "";
return new Response("<script>var stateToken = '02.id.abc\\x2Ddef';</script>", {
status: 200,
headers: { "set-cookie": "JSESSIONID=js1; Path=/; HttpOnly" },
});
}
if (u.endsWith("/idp/idx/introspect")) return jsonResponse({ stateHandle: "sh-1" });
if (u.endsWith("/idp/idx/identify")) return jsonResponse({ stateHandle: "sh-2" });
if (u.endsWith("/idp/idx/challenge/answer")) {
return jsonResponse({
success: { href: "https://sso.renault.com/login/token/redirect?stateToken=st" },
});
}
if (u.includes("/login/token/redirect")) {
return new Response(null, {
status: 302,
headers: {
location: `https://rpartstore.renault.com/idp-redirect?code=CODE1&state=${redirectState}`,
},
});
}
if (u.endsWith("/v1/token")) {
return jsonResponse({
token_type: "Bearer",
expires_in: 3600,
access_token: jwt,
scope: "openid",
});
}
throw new Error(`unexpected url ${u}`);
});
const token = await loginRpartstore({
username: "G123326",
password: "pw",
fetchImpl: fetchImpl as unknown as typeof fetch,
});
expect(token.accessToken).toBe(jwt);
expect(token.subject).toBe("G123326");
expect(token.expiresAt).toBe(exp * 1000);
// stateToken unescaped (\x2D → "-") and carried into introspect
expect(calls[1].body).toBe(JSON.stringify({ stateToken: "02.id.abc-def" }));
// identify uses the introspect handle, answer the identify handle
expect(JSON.parse(calls[2].body!)).toEqual({ identifier: "G123326", stateHandle: "sh-1" });
expect(JSON.parse(calls[3].body!)).toEqual({
credentials: { passcode: "pw" },
stateHandle: "sh-2",
});
// cookies from the authorize page are replayed on later hops
expect(calls[3].cookie).toContain("JSESSIONID=js1");
// PKCE: the token exchange sends the code and a verifier, never the password
const tokenBody = new URLSearchParams(calls.at(-1)!.body);
expect(tokenBody.get("grant_type")).toBe("authorization_code");
expect(tokenBody.get("code")).toBe("CODE1");
expect(tokenBody.get("code_verifier")).toBeTruthy();
expect(calls.at(-1)!.body).not.toContain("pw");
});
it("fails with a challenge error when Okta returns no success redirect (bad password / MFA)", async () => {
const fetchImpl = vi.fn(async (url: string | URL) => {
const u = String(url);
if (u.includes("/v1/authorize")) return new Response("stateToken = 'x'", { status: 200 });
if (u.endsWith("/introspect")) return jsonResponse({ stateHandle: "sh" });
if (u.endsWith("/identify")) return jsonResponse({ stateHandle: "sh" });
if (u.endsWith("/challenge/answer")) {
return jsonResponse({ messages: { value: [{ message: "Authentication failed" }] } });
}
throw new Error(`unexpected url ${u}`);
});
await expect(
loginRpartstore({
username: "u",
password: "bad",
fetchImpl: fetchImpl as unknown as typeof fetch,
}),
).rejects.toMatchObject({ name: "RpartstoreAuthError", step: "challenge" });
});
it("rejects an OAuth state mismatch on the callback", async () => {
const fetchImpl = vi.fn(async (url: string | URL) => {
const u = String(url);
if (u.includes("/v1/authorize")) return new Response("stateToken = 'x'", { status: 200 });
if (u.endsWith("/introspect")) return jsonResponse({ stateHandle: "sh" });
if (u.endsWith("/identify")) return jsonResponse({ stateHandle: "sh" });
if (u.endsWith("/challenge/answer"))
return jsonResponse({ success: { href: "https://sso.renault.com/r" } });
if (u === "https://sso.renault.com/r") {
return new Response(null, {
status: 302,
headers: { location: "https://rpartstore.renault.com/idp-redirect?code=C&state=forged" },
});
}
throw new Error(`unexpected url ${u}`);
});
await expect(
loginRpartstore({
username: "u",
password: "p",
fetchImpl: fetchImpl as unknown as typeof fetch,
}),
).rejects.toBeInstanceOf(RpartstoreAuthError);
});
it("decodes exp/sub from the access token", () => {
expect(decodeJwtExpiry(makeJwt({ sub: "G1", exp: 1790334740 }))).toEqual({
exp: 1790334740,
sub: "G1",
});
expect(() => decodeJwtExpiry(makeJwt({ sub: "G1" }))).toThrow(RpartstoreAuthError);
});
});

View File

@@ -0,0 +1,238 @@
/**
* Browser-free Okta (OIE / IDX) login for rpartstore.renault.com.
*
* Flow (verified live 2026-09-25, ~1.8 s, no MFA / captcha):
* 1. GET {issuer}/v1/authorize?...PKCE... → hosted page HTML containing `stateToken`
* 2. POST /idp/idx/introspect {stateToken} → stateHandle
* 3. POST /idp/idx/identify {identifier, stateHandle}
* 4. POST /idp/idx/challenge/answer {credentials:{passcode}, stateHandle} → success.href
* 5. GET success.href (follow redirects manually) → …/idp-redirect?code=…&state=…
* 6. POST {issuer}/v1/token (authorization_code + code_verifier) → access_token (1 h, no refresh_token)
*/
import { createHash, randomBytes } from "node:crypto";
export interface RpartstoreAuthConfig {
username: string;
password: string;
issuer?: string;
clientId?: string;
redirectUri?: string;
scope?: string;
/** Injectable for tests. */
fetchImpl?: typeof fetch;
}
export interface RpartstoreToken {
accessToken: string;
/** Epoch ms. */
expiresAt: number;
subject: string;
}
export class RpartstoreAuthError extends Error {
constructor(
message: string,
readonly step: string,
readonly detail?: unknown,
) {
super(message);
this.name = "RpartstoreAuthError";
}
}
const DEFAULTS = {
issuer: "https://sso.renault.com/oauth2/aus133y6mks4ptDss417",
clientId: "irn-72795_ope_pkce_4hcafvxlbcil",
redirectUri: "https://rpartstore.renault.com/idp-redirect",
scope: "openid alliance_profile apis.default",
};
const USER_AGENT =
"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36";
const ION = "application/ion+json; okta-version=1.0.0";
const b64url = (buf: Buffer): string => buf.toString("base64url");
/** Tiny cookie jar: Okta needs `idx`/`JSESSIONID` cookies across the IDX steps. */
class CookieJar {
private readonly jar = new Map<string, string>();
absorb(res: Response): void {
const setCookies: string[] =
typeof (res.headers as { getSetCookie?: () => string[] }).getSetCookie === "function"
? (res.headers as unknown as { getSetCookie: () => string[] }).getSetCookie()
: [];
for (const sc of setCookies) {
const kv = sc.split(";")[0];
const i = kv.indexOf("=");
if (i > 0) this.jar.set(kv.slice(0, i).trim(), kv.slice(i + 1).trim());
}
}
header(): string {
return Array.from(this.jar.entries())
.map(([k, v]) => `${k}=${v}`)
.join("; ");
}
}
export function decodeJwtExpiry(accessToken: string): { exp: number; sub: string } {
const payload = JSON.parse(
Buffer.from(accessToken.split(".")[1], "base64url").toString("utf8"),
) as {
exp?: number;
sub?: string;
};
if (!payload.exp) throw new RpartstoreAuthError("access token has no exp claim", "token");
return { exp: payload.exp, sub: payload.sub ?? "" };
}
export async function loginRpartstore(cfg: RpartstoreAuthConfig): Promise<RpartstoreToken> {
const issuer = cfg.issuer ?? DEFAULTS.issuer;
const clientId = cfg.clientId ?? DEFAULTS.clientId;
const redirectUri = cfg.redirectUri ?? DEFAULTS.redirectUri;
const scope = cfg.scope ?? DEFAULTS.scope;
const doFetch = cfg.fetchImpl ?? fetch;
const jar = new CookieJar();
const request = async (url: string, init: RequestInit = {}): Promise<Response> => {
const res = await doFetch(url, {
redirect: "manual",
...init,
headers: {
"User-Agent": USER_AGENT,
Cookie: jar.header(),
...(init.headers as Record<string, string> | undefined),
},
});
jar.absorb(res);
return res;
};
const verifier = b64url(randomBytes(48));
const challenge = b64url(createHash("sha256").update(verifier).digest());
const state = randomBytes(16).toString("hex");
const nonce = randomBytes(16).toString("hex");
// 1. hosted authorize page → stateToken
const authorize = new URL(`${issuer}/v1/authorize`);
for (const [k, v] of Object.entries({
client_id: clientId,
redirect_uri: redirectUri,
response_type: "code",
scope,
state,
nonce,
code_challenge: challenge,
code_challenge_method: "S256",
response_mode: "query",
})) {
authorize.searchParams.set(k, v);
}
const authorizeRes = await request(authorize.toString());
const html = await authorizeRes.text();
const stateTokenMatch =
html.match(/stateToken\s*=\s*'([^']+)'/) ?? html.match(/"stateToken":"([^"]+)"/);
if (authorizeRes.status !== 200 || !stateTokenMatch) {
throw new RpartstoreAuthError(
`authorize page did not expose a stateToken (HTTP ${authorizeRes.status})`,
"authorize",
);
}
const stateToken = stateTokenMatch[1].replace(/\\x([0-9A-Fa-f]{2})/g, (_, hex: string) =>
String.fromCharCode(Number.parseInt(hex, 16)),
);
const idx = async (
path: string,
body: Record<string, unknown>,
step: string,
): Promise<Record<string, any>> => {
const res = await request(`https://sso.renault.com/idp/idx/${path}`, {
method: "POST",
headers: { "Content-Type": ION, Accept: ION, Origin: "https://sso.renault.com" },
body: JSON.stringify(body),
});
const json = (await res.json().catch(() => ({}))) as Record<string, any>;
if (!res.ok) {
throw new RpartstoreAuthError(
`Okta ${step} failed (HTTP ${res.status})`,
step,
json.messages ?? json,
);
}
return json;
};
// 2-4. IDX remediation
const introspected = await idx("introspect", { stateToken }, "introspect");
const identified = await idx(
"identify",
{ identifier: cfg.username, stateHandle: introspected.stateHandle },
"identify",
);
const answered = await idx(
"challenge/answer",
{
credentials: { passcode: cfg.password },
stateHandle: identified.stateHandle ?? introspected.stateHandle,
},
"challenge",
);
const successHref: string | undefined = answered.success?.href;
if (!successHref) {
throw new RpartstoreAuthError(
"Okta did not return a success redirect (wrong password, locked account or MFA now required)",
"challenge",
answered.messages,
);
}
// 5. follow the redirect chain until the app callback carries ?code=
let next = successHref;
let code: string | undefined;
for (let hop = 0; hop < 6 && !code; hop += 1) {
const res = await request(next);
const location = res.headers.get("location");
if (!location) break;
const target = new URL(location, next);
const gotCode = target.searchParams.get("code");
if (gotCode) {
if (target.searchParams.get("state") !== state)
throw new RpartstoreAuthError("OAuth state mismatch", "redirect");
code = gotCode;
}
next = target.toString();
}
if (!code)
throw new RpartstoreAuthError("redirect chain ended without an authorization code", "redirect");
// 6. PKCE token exchange
const tokenRes = await request(`${issuer}/v1/token`, {
method: "POST",
headers: {
"Content-Type": "application/x-www-form-urlencoded",
Origin: "https://rpartstore.renault.com",
},
body: new URLSearchParams({
grant_type: "authorization_code",
redirect_uri: redirectUri,
code,
code_verifier: verifier,
client_id: clientId,
}).toString(),
});
const token = (await tokenRes.json().catch(() => ({}))) as {
access_token?: string;
error?: string;
error_description?: string;
};
if (!tokenRes.ok || !token.access_token) {
throw new RpartstoreAuthError(
`token exchange failed (HTTP ${tokenRes.status}): ${token.error_description ?? token.error ?? ""}`,
"token",
);
}
const { exp, sub } = decodeJwtExpiry(token.access_token);
return { accessToken: token.access_token, expiresAt: exp * 1000, subject: sub };
}

View File

@@ -0,0 +1,157 @@
import { type RpartstoreToken, loginRpartstore } from "./rpartstore.auth";
import { canonicalRpartstoreBrand } from "./rpartstore.routing";
import {
RpartstoreBffError,
RpartstoreRateLimitError,
RpartstoreSession,
} from "./rpartstore.session";
import type {
RpartstoreDecoded,
RpartstoreVehicle,
SearchVehicleResponsePayload,
} from "./rpartstore.types";
export const RPARTSTORE_DEFAULTS = {
brokerUrl: "wss://1po-bff.renault-edh.com/ws",
appVersion: "1.34.0.6",
webLanguage: "tr",
country: "TR",
} as const;
/** Where the (1 h, non-refreshable) Okta access token is cached between decodes. */
export interface TokenStore {
get(): Promise<RpartstoreToken | null>;
set(token: RpartstoreToken, ttlSeconds: number): Promise<void>;
clear(): Promise<void>;
}
export interface RpartstoreClientOptions {
username: string;
password: string;
tokenStore: TokenStore;
brokerUrl?: string;
appVersion?: string;
webLanguage?: string;
country?: string;
/** Injectable for tests. */
login?: typeof loginRpartstore;
sessionFactory?: (opts: ConstructorParameters<typeof RpartstoreSession>[0]) => RpartstoreSession;
logger?: { log: (msg: string) => void; warn: (msg: string) => void };
}
/** Refresh the token this many ms before its `exp`. */
const TOKEN_SKEW_MS = 5 * 60 * 1000;
export class RpartstoreClient {
private readonly login: typeof loginRpartstore;
private readonly sessionFactory: NonNullable<RpartstoreClientOptions["sessionFactory"]>;
constructor(private readonly opts: RpartstoreClientOptions) {
this.login = opts.login ?? loginRpartstore;
this.sessionFactory = opts.sessionFactory ?? ((o) => new RpartstoreSession(o));
}
/** Cached token when still valid (with skew), otherwise a fresh Okta login. */
async getToken(force = false): Promise<RpartstoreToken> {
if (!force) {
const cached = await this.opts.tokenStore.get();
if (cached && cached.expiresAt - Date.now() > TOKEN_SKEW_MS) return cached;
}
const token = await this.login({ username: this.opts.username, password: this.opts.password });
const ttl = Math.max(60, Math.floor((token.expiresAt - Date.now() - TOKEN_SKEW_MS) / 1000));
await this.opts.tokenStore.set(token, ttl);
this.opts.logger?.log(`[rpartstore] logged in as ${token.subject}, token ttl ${ttl}s`);
return token;
}
/**
* One VIN search on a fresh STOMP session (volume is capped at a handful per
* day, so a persistent socket buys nothing). Resolves to the decoded vehicle,
* `null` when RPartStore answers NOT_FOUND, and throws `RpartstoreRateLimitError`
* / other errors for the caller to handle. A CONNECT failure is retried once
* with a forced re-login (expired or revoked token).
*/
async searchVin(vin: string): Promise<RpartstoreDecoded | null> {
let token = await this.getToken();
const session = await this.openSession(token.accessToken).catch(async (err: Error) => {
this.opts.logger?.warn(`[rpartstore] CONNECT failed (${err.message}); re-login and retry`);
await this.opts.tokenStore.clear();
token = await this.getToken(true);
return this.openSession(token.accessToken);
});
try {
const country = this.opts.country ?? RPARTSTORE_DEFAULTS.country;
const lang = this.opts.webLanguage ?? RPARTSTORE_DEFAULTS.webLanguage;
const msg = await session.request<SearchVehicleResponsePayload>(
"/vehicles/search/vin-or-vrn",
{
requestId: crypto.randomUUID(),
value: vin,
queryType: "VIN",
userContext: {
webLanguage: lang,
documentLanguage: lang,
documentCountryLanguage: country,
documentFallbackLanguage: lang,
documentFallbackCountryLanguage: country,
userCountry: country,
r1Country: country,
},
countryCode: country,
includeEstimate: false,
},
{ expect: ["1PO/CATALOG/SEARCH_VEHICLE_RESPONSE"], timeoutMs: 15_000 },
);
const vehicle = msg.payload?.vehicles?.[0];
if (!vehicle) return null;
return normalizeVehicle(vehicle);
} catch (err) {
if (err instanceof RpartstoreBffError) {
const errorType = (err.payload as { errorType?: string } | undefined)?.errorType;
if (err.type === "1PO/CATALOG/SEARCH_VEHICLE_ERROR" && errorType === "NOT_FOUND")
return null;
if (err.type === "1PO/CATALOG/SEARCH_VEHICLE_NOT_COVERED_IN_COUNTRY") return null;
}
if (err instanceof RpartstoreRateLimitError) throw err;
throw err;
} finally {
session.close();
}
}
private async openSession(accessToken: string): Promise<RpartstoreSession> {
const session = this.sessionFactory({
brokerUrl: this.opts.brokerUrl ?? RPARTSTORE_DEFAULTS.brokerUrl,
accessToken,
profile: this.opts.username,
appVersion: this.opts.appVersion ?? RPARTSTORE_DEFAULTS.appVersion,
webLanguage: this.opts.webLanguage ?? RPARTSTORE_DEFAULTS.webLanguage,
logger: this.opts.logger
? { debug: () => undefined, warn: (m) => this.opts.logger?.warn(`[rpartstore] ${m}`) }
: undefined,
});
await session.connect();
return session;
}
}
export function normalizeVehicle(v: RpartstoreVehicle): RpartstoreDecoded {
const dh = v.dataHubVehicle ?? {};
const brandName = canonicalRpartstoreBrand(v.vehicleBrand) ?? v.vehicleBrand;
const clean = (s: string | undefined): string | null => {
const t = (s ?? "").trim();
return t.length > 0 ? t : null;
};
return {
brandName,
model: clean(v.model),
modelCode: clean(dh.modelTypeCode),
familyCode: clean(dh.familyCode),
modelYear: clean(dh.modelYear),
engine: clean(dh.engine),
gearbox: clean(dh.gearbox),
energyType: clean(dh.energyType),
manufacturingDate: clean(v.manufacturingDate),
raw: v,
};
}

View File

@@ -0,0 +1,140 @@
import { describe, expect, it } from "vitest";
import {
type RpartstoreCatalogCandidate,
pickRpartstoreCatalogMatch,
rpartstoreModelTokens,
} from "./rpartstore.matcher";
// Real PL24 `catalog_vehicles.model` values for Renault (prod, 2026-09-25).
const RENAULT = [
"ALASKAN",
"ARKANA EUROPE / XM3",
"ARKANA RUSYA",
"AUSTRAL/ESPACE VI/RAFALE",
"CAPTUR / QM3",
"CAPTUR II EUROPE/SYMBIOZ",
"CAPTUR II ÇİN",
"CAPTUR/KAPTUR",
"CLIO 4 / LUTECIA 4",
"CLIO 5/LUTECIA 5",
"DUSTER 1",
"DUSTER 2",
"DUSTER III / BIGSTER",
"EXPRESS",
"FLUENCE / FLUENCE Z.E.",
"KADJAR",
"KADJAR ÇİN",
"KANGOO 1",
"KANGOO 2 / KANGOO Z.E.",
"KANGOO 3",
"LATITUDE / SAFRANE 2",
"LOGAN\\-SANDERO 1/TONDAR 1",
"LOGAN\\-SANDERO 3 / TALIANT",
"MASTER 3",
"MASTER 4 VAN",
"MEGANE 1",
"MEGANE 2 / SCENIC 2",
"MEGANE 3 / SCENIC 3",
"MEGANE 4",
"MEGANE 4 SEDAN",
"RENAULT 5 EXPRESS / RAPID",
"RENAULT 9 / 11",
"TRAFIC 2",
"TRAFIC 3",
"X62 CHINE",
];
const DACIA = [
"DOKKER",
"DUSTER 1",
"DUSTER 2",
"DUSTER 3/BIGSTER",
"LOGAN\\-SANDERO 1/TONDAR 1",
"LOGAN\\-SANDERO 2/SYMBOL 2",
"LOGAN\\-SANDERO 3 / TALIANT",
];
const cands = (models: string[]): RpartstoreCatalogCandidate[] =>
models.map((model) => ({ id: model, model }));
describe("rpartstoreModelTokens", () => {
it("drops the model code in parentheses and converts roman generations", () => {
expect(rpartstoreModelTokens("Clio IV / Lutecia IV (B98)")).toEqual([
"CLIO",
"4",
"LUTECIA",
"4",
]);
expect(rpartstoreModelTokens("Duster III (SUV)")).toEqual(["DUSTER", "3"]);
expect(rpartstoreModelTokens("Megane I Classic (L64)")).toEqual(["MEGANE", "1", "CLASSIC"]);
});
it("keeps single-digit generation tokens and folds diacritics", () => {
expect(rpartstoreModelTokens("MEGANE 4 SEDAN")).toEqual(["MEGANE", "4", "SEDAN"]);
expect(rpartstoreModelTokens("KADJAR ÇİN")).toEqual(["KADJAR", "CIN"]);
expect(rpartstoreModelTokens("LOGAN\\-SANDERO 3 / TALIANT")).toEqual([
"LOGAN",
"SANDERO",
"3",
"TALIANT",
]);
});
});
describe("pickRpartstoreCatalogMatch (prod benchmark models → PL24 Renault catalog)", () => {
const expectPick = (model: string, expected: string | null, pool = RENAULT) =>
expect(pickRpartstoreCatalogMatch(model, cands(pool))).toBe(expected);
it("matches roman-numeral generations to digit generations", () => {
expectPick("Clio IV / Lutecia IV (B98)", "CLIO 4 / LUTECIA 4");
expectPick("Trafic III (J82)", "TRAFIC 3");
expectPick("Master III (F62)", "MASTER 3");
expectPick("Kangoo II (K61)", "KANGOO 2 / KANGOO Z.E.");
expectPick("Logan III (LJF)", "LOGAN\\-SANDERO 3 / TALIANT");
expectPick("Duster III (SUV)", "DUSTER III / BIGSTER");
});
it("prefers the body-qualified catalog when the decode carries the qualifier, and the plain one otherwise", () => {
expectPick("Megane IV Sedan (LFF)", "MEGANE 4 SEDAN");
expectPick("Megane IV (BFB)", "MEGANE 4");
expectPick("Megane I Classic (L64)", "MEGANE 1");
});
it("never picks a wrong-market catalog when a mainstream one exists", () => {
expectPick("Kadjar (HFE)", "KADJAR");
expectPick("Captur II (HJB)", "CAPTUR II EUROPE/SYMBIOZ");
});
it("does not let a newer generation steal a decode without a generation", () => {
expectPick("Captur (J87)", "CAPTUR / QM3");
expectPick("Express (KJK)", "EXPRESS");
});
it("matches multi-name catalogs and pre-2000 models", () => {
expectPick("Latitude / Safrane II (L43)", "LATITUDE / SAFRANE 2");
expectPick("Fluence (L38)", "FLUENCE / FLUENCE Z.E.");
expectPick("Renault 9 / 11 (L42)", "RENAULT 9 / 11");
});
it("matches Dacia models within the Dacia catalog", () => {
expectPick("Duster I (H79)", "DUSTER 1", DACIA);
expectPick("Duster II (HJD)", "DUSTER 2", DACIA);
expectPick("Dokker (K67)", "DOKKER", DACIA);
expectPick("Logan I (L90)", "LOGAN\\-SANDERO 1/TONDAR 1", DACIA);
});
it("returns null when nothing qualifies or the model is missing", () => {
expectPick("Arkana (LJL)", "ARKANA EUROPE / XM3");
expectPick("Twingo Z.E.", null);
expect(pickRpartstoreCatalogMatch(undefined, cands(RENAULT))).toBeNull();
expect(pickRpartstoreCatalogMatch("", cands(RENAULT))).toBeNull();
});
it("breaks exact ties by the fuller catalog", () => {
const pool: RpartstoreCatalogCandidate[] = [
{ id: "a", model: "KADJAR", categoryCount: 12 },
{ id: "b", model: "KADJAR", categoryCount: 44 },
];
expect(pickRpartstoreCatalogMatch("Kadjar (HFE)", pool)).toBe("b");
});
});

View File

@@ -0,0 +1,133 @@
import { MARKET_QUALIFIERS } from "../vinpin/vinpin.matcher";
/**
* Map an RPartStore model label ("Megane IV Sedan (LFF)", "Clio IV / Lutecia IV
* (B98)", "Duster III (SUV)") onto an EXISTING PL24 `catalog_vehicles` row of the
* same brand ("MEGANE 4 SEDAN", "CLIO 4 / LUTECIA 4", "DUSTER III / BIGSTER").
*
* Differences from the Vinpin matcher that made a dedicated picker necessary:
* - RPartStore writes generations as roman numerals, PL24 mostly as digits
* ("IV" vs "4") — both sides are normalised to digits.
* - Generation digits are single characters; the Vinpin tokenizer drops tokens
* shorter than 2 chars, which would make "MEGANE 4" ≡ "MEGANE".
* - Body qualifiers (SEDAN, CLASSIC, …) are optional on the catalog side:
* "Megane I Classic" must still match "MEGANE 1".
* - PL24 Renault/Dacia rows carry no year, so there is no year scoring.
*/
export interface RpartstoreCatalogCandidate {
id: string;
model: string | null;
/** Tiebreak only: fuller catalog wins. */
categoryCount?: number | null;
}
const ROMAN: Record<string, string> = {
I: "1",
II: "2",
III: "3",
IV: "4",
V: "5",
VI: "6",
VII: "7",
VIII: "8",
};
/** Body / trim words that PL24 may omit; they only add a small bonus when both sides have them. */
const BODY_QUALIFIERS = new Set<string>([
"SEDAN",
"CLASSIC",
"HATCHBACK",
"HB",
"ESTATE",
"GRANDTOUR",
"SPORTTOURER",
"SW",
"BREAK",
"VAN",
"COMBI",
"KOMBI",
"CABRIO",
"COUPE",
"SASI",
"CHASSIS",
"PICKUP",
"PHASE",
"PH",
]);
/** Tokenize a model label: fold diacritics, drop parenthetical codes/years, split on
* non-alphanumerics, convert roman generation numerals to digits. Keeps 1-char
* numeric tokens (generations) and drops 1-char alpha noise ("Z.E." → "ZE" kept
* as-is is not needed for matching). */
export function rpartstoreModelTokens(s: string | null | undefined): string[] {
if (!s) return [];
return s
.toUpperCase()
.normalize("NFD")
.replace(/\p{M}/gu, "")
.replace(/\([^)]*\)/g, " ")
.replace(/[^A-Z0-9]+/g, " ")
.split(" ")
.map((t) => t.trim())
.filter((t) => t.length > 0)
.map((t) => ROMAN[t] ?? t)
.filter((t) => t.length >= 2 || /^\d$/.test(t));
}
const isNumeric = (t: string): boolean => /^\d+$/.test(t);
/**
* Returns the id of the best candidate or null. A candidate qualifies when every
* "core" decoded token (everything except body qualifiers) appears among its
* tokens. Score, strongest first: market-qualifier penalty (wrong-market catalogs
* only win when alone), exact-match bonus, body-qualifier overlap bonus, a hard
* penalty for candidates that add a generation number the decode lacks
* ("Captur" must not pick "CAPTUR II"), a mild penalty per extra token, then the
* fuller catalog as tiebreak.
*/
export function pickRpartstoreCatalogMatch(
model: string | null | undefined,
candidates: RpartstoreCatalogCandidate[],
): string | null {
const decoded = rpartstoreModelTokens(model);
if (decoded.length === 0) return null;
const core = decoded.filter((t) => !BODY_QUALIFIERS.has(t));
const required = core.length > 0 ? core : decoded;
const decodedSet = new Set(decoded);
const decodedHasGeneration = decoded.some(isNumeric);
let best: { id: string; score: number; categoryCount: number } | null = null;
for (const c of candidates) {
const tokens = rpartstoreModelTokens(c.model);
if (tokens.length === 0) continue;
const tokenSet = new Set(tokens);
if (!required.every((t) => tokenSet.has(t))) continue;
const extras = tokens.filter((t) => !decodedSet.has(t));
const marketExtras = extras.filter((t) => MARKET_QUALIFIERS.has(t)).length;
const generationExtras = decodedHasGeneration ? 0 : extras.filter(isNumeric).length;
const qualifierOverlap = decoded.filter(
(t) => BODY_QUALIFIERS.has(t) && tokenSet.has(t),
).length;
const exact = extras.length === 0 && tokens.length === decoded.length;
const score =
1000 -
marketExtras * 5000 -
generationExtras * 150 -
extras.length * 20 +
qualifierOverlap * 100 +
(exact ? 300 : 0);
const categoryCount = c.categoryCount ?? 0;
if (
!best ||
score > best.score ||
(score === best.score && categoryCount > best.categoryCount)
) {
best = { id: c.id, score, categoryCount };
}
}
return best?.id ?? null;
}

View File

@@ -0,0 +1,32 @@
import { getBrandFromWmi } from "@sase/shared";
/** WMIs routed to RPartStore even when the shared WMI table is silent. VF1/VF2 =
* Renault (France), VF6 = Renault (Trucks/Sofasa), UU1 = Dacia (Romania). VF7 is
* Citroën and is deliberately NOT here. */
const RPARTSTORE_WMIS = new Set<string>(["VF1", "VF2", "VF6", "UU1"]);
const RPARTSTORE_BRANDS = new Set<string>(["renault", "dacia"]);
/** Canonical brand names as they appear in `catalog_vehicles.brand_name`. */
export function canonicalRpartstoreBrand(
brand: string | null | undefined,
): "Renault" | "Dacia" | null {
const b = (brand ?? "").trim().toLowerCase();
if (b === "renault") return "Renault";
if (b === "dacia") return "Dacia";
return null;
}
/**
* Should this VIN be offered to the RPartStore decode fallback? Renault/Dacia
* only: decided by the WMI first (shared table, then the explicit allowlist),
* with the identified browse brand as a last resort (Dacia-badged cars built
* under a Renault WMI still say "Dacia" in the identification).
*/
export function isRpartstoreVin(vin: string, browseBrand?: string | null): boolean {
const wmi = (vin || "").toUpperCase().slice(0, 3);
const wmiBrand = getBrandFromWmi(wmi);
if (wmiBrand && RPARTSTORE_BRANDS.has(wmiBrand.toLowerCase())) return true;
if (RPARTSTORE_WMIS.has(wmi)) return true;
return !!browseBrand && RPARTSTORE_BRANDS.has(browseBrand.trim().toLowerCase());
}

View File

@@ -0,0 +1,256 @@
/**
* One STOMP-over-WebSocket session against the RPartStore BFF.
*
* Request/response is correlated by the `trace-id` header we send and the `traceId`
* header the server echoes. One request can yield several MESSAGE frames
* (e.g. a VIN search → SEARCH_VEHICLE_RESPONSE, COMMAND_PROCESSING_RESPONSE,
* EXPLODED_TREE_RESPONSE), so a request resolves on the first frame whose `type`
* matches one of the expected terminal types, and errors on a frame from
* `/user/queue/error` or a `*_RATE_LIMIT_EXCEEDED` type.
*
* Uses Node 22's built-in WebSocket (no Origin / subprotocol required by the server).
*/
import { randomUUID } from "node:crypto";
import { decodeFrame, encodeFrame } from "./rpartstore.stomp";
export interface BffMessage<T = unknown> {
type: string;
payload: T;
}
export interface SessionOptions {
brokerUrl: string;
accessToken: string;
profile: string;
appVersion: string;
webLanguage: string;
connectTimeoutMs?: number;
/** STOMP heart-beat interval (ms) negotiated with the server. */
heartbeatMs?: number;
onClose?: (reason: string) => void;
logger?: { debug: (msg: string) => void; warn: (msg: string) => void };
}
export interface RequestOptions {
/** Message `type`s that complete the request. */
expect: string[];
timeoutMs?: number;
}
export class RpartstoreRateLimitError extends Error {
constructor(
readonly retryAfterSeconds: number,
readonly limitType: string,
) {
super(`RPartStore rate limit (${limitType}), retry after ${retryAfterSeconds}s`);
this.name = "RpartstoreRateLimitError";
}
}
export class RpartstoreBffError extends Error {
constructor(
readonly type: string,
readonly payload: unknown,
) {
super(`RPartStore BFF error ${type}`);
this.name = "RpartstoreBffError";
}
}
interface Pending {
expect: Set<string>;
resolve: (msg: BffMessage) => void;
reject: (err: Error) => void;
timer: NodeJS.Timeout;
}
export class RpartstoreSession {
private ws: WebSocket | null = null;
private readonly pending = new Map<string, Pending>();
private heartbeatTimer: NodeJS.Timeout | null = null;
private closed = false;
constructor(private readonly opts: SessionOptions) {}
get isOpen(): boolean {
return !this.closed && this.ws !== null && this.ws.readyState === WebSocket.OPEN;
}
/** Opens the socket, sends CONNECT and subscribes to the user queues. Resolves on CONNECTED. */
connect(): Promise<void> {
const {
brokerUrl,
accessToken,
profile,
appVersion,
webLanguage,
connectTimeoutMs = 10_000,
heartbeatMs = 60_000,
} = this.opts;
return new Promise<void>((resolve, reject) => {
let settled = false;
const fail = (err: Error): void => {
if (!settled) {
settled = true;
reject(err);
}
this.teardown(err.message);
};
const timer = setTimeout(() => fail(new Error("STOMP CONNECT timeout")), connectTimeoutMs);
let ws: WebSocket;
try {
ws = new WebSocket(brokerUrl, ["v12.stomp"]);
} catch (err) {
clearTimeout(timer);
reject(err instanceof Error ? err : new Error(String(err)));
return;
}
this.ws = ws;
ws.onopen = () => {
ws.send(
encodeFrame("CONNECT", {
"trace-id": randomUUID(),
"x-auth-token": accessToken,
"selected-profile": profile,
"app-version": appVersion,
"web-language": webLanguage,
"accept-version": "1.2,1.1,1.0",
"heart-beat": `${heartbeatMs},${heartbeatMs}`,
}),
);
};
ws.onmessage = (event: MessageEvent) => {
const frame = decodeFrame(typeof event.data === "string" ? event.data : String(event.data));
if (!frame) return; // heartbeat
if (frame.command === "CONNECTED") {
clearTimeout(timer);
ws.send(encodeFrame("SUBSCRIBE", { id: "sub-0", destination: "/user/queue/main" }));
ws.send(encodeFrame("SUBSCRIBE", { id: "sub-1", destination: "/user/queue/error" }));
this.startHeartbeat(heartbeatMs);
settled = true;
resolve();
return;
}
if (frame.command === "ERROR") {
fail(
new Error(`STOMP ERROR: ${frame.headers.message ?? ""} ${frame.body.slice(0, 200)}`),
);
return;
}
if (frame.command === "MESSAGE") this.onMessage(frame.headers, frame.body);
};
ws.onerror = () => fail(new Error("WebSocket error"));
ws.onclose = (event: { code: number; reason: string }) => {
clearTimeout(timer);
const reason = `WebSocket closed (${event.code}${event.reason ? ` ${event.reason}` : ""})`;
if (!settled) fail(new Error(reason));
else this.teardown(reason);
};
});
}
/** Publishes `{payload}` to `/app/<path>` and resolves on the first expected message type. */
request<T = unknown>(
path: string,
payload: unknown,
options: RequestOptions,
): Promise<BffMessage<T>> {
const ws = this.ws;
if (!this.isOpen || !ws) return Promise.reject(new Error("STOMP session is not connected"));
const traceId = randomUUID();
const body = JSON.stringify({ payload });
const { expect, timeoutMs = 15_000 } = options;
return new Promise<BffMessage<T>>((resolve, reject) => {
const timer = setTimeout(() => {
this.pending.delete(traceId);
reject(new Error(`RPartStore request ${path} timed out after ${timeoutMs}ms`));
}, timeoutMs);
this.pending.set(traceId, {
expect: new Set(expect),
resolve: (msg) => resolve(msg as BffMessage<T>),
reject,
timer,
});
ws.send(encodeFrame("SEND", { destination: `/app${path}`, "trace-id": traceId }, body));
this.opts.logger?.debug(`→ ${path} trace=${traceId}`);
});
}
close(): void {
this.teardown("closed by client");
}
private onMessage(headers: Record<string, string>, body: string): void {
const traceId = headers.traceId;
const pending = traceId ? this.pending.get(traceId) : undefined;
let msg: BffMessage;
try {
msg = JSON.parse(body) as BffMessage;
} catch {
this.opts.logger?.warn(
`unparseable BFF message on ${headers.destination ?? "?"} trace=${traceId ?? "?"}`,
);
return;
}
if (!pending) return; // unsolicited push (search-history refresh etc.)
const isError = headers.destination === "/user/queue/error";
if (/RATE_LIMIT_EXCEEDED$/.test(msg.type)) {
const p = msg.payload as { retryAfterSeconds?: number; limitType?: string };
this.settle(traceId, pending, (pend) =>
pend.reject(
new RpartstoreRateLimitError(p.retryAfterSeconds ?? 10, p.limitType ?? "SHORT_TERM"),
),
);
return;
}
if (isError) {
this.settle(traceId, pending, (pend) =>
pend.reject(new RpartstoreBffError(msg.type, msg.payload)),
);
return;
}
if (pending.expect.has(msg.type)) {
this.settle(traceId, pending, (pend) => pend.resolve(msg));
}
// other frames on the same trace (COMMAND_PROCESSING_RESPONSE, EXPLODED_TREE_RESPONSE…) are ignored here
}
private settle(traceId: string, pending: Pending, fn: (p: Pending) => void): void {
clearTimeout(pending.timer);
this.pending.delete(traceId);
fn(pending);
}
private startHeartbeat(intervalMs: number): void {
this.stopHeartbeat();
this.heartbeatTimer = setInterval(() => {
if (this.isOpen) this.ws?.send("\n");
}, intervalMs);
}
private stopHeartbeat(): void {
if (this.heartbeatTimer) clearInterval(this.heartbeatTimer);
this.heartbeatTimer = null;
}
private teardown(reason: string): void {
if (this.closed) return;
this.closed = true;
this.stopHeartbeat();
for (const [traceId, p] of this.pending) {
clearTimeout(p.timer);
p.reject(new Error(`STOMP session ended: ${reason}`));
this.pending.delete(traceId);
}
const ws = this.ws;
this.ws = null;
if (ws && ws.readyState !== WebSocket.CLOSED) {
try {
ws.close();
} catch {
/* ignore */
}
}
this.opts.onClose?.(reason);
}
}

View File

@@ -0,0 +1,50 @@
import { describe, expect, it } from "vitest";
import { decodeFrame, encodeFrame } from "./rpartstore.stomp";
describe("rpartstore STOMP codec", () => {
it("encodes a SEND frame exactly like the RPartStore web app", () => {
const body = '{"payload":{"requestId":"r","value":"VF1RFE00653633190","queryType":"VIN"}}';
const frame = encodeFrame(
"SEND",
{ destination: "/app/vehicles/search/vin-or-vrn", "trace-id": "t-1" },
body,
);
expect(frame).toBe(
`SEND\ndestination:/app/vehicles/search/vin-or-vrn\ntrace-id:t-1\ncontent-length:${Buffer.byteLength(body)}\n\n${body}\u0000`,
);
});
it("does not escape CONNECT header values (STOMP 1.2 rule) but escapes others", () => {
expect(encodeFrame("CONNECT", { "x-auth-token": "a:b" })).toBe(
"CONNECT\nx-auth-token:a:b\n\n\u0000",
);
expect(encodeFrame("SEND", { destination: "/app/x", note: "a:b\nc" })).toContain(
"note:a\\cb\\nc",
);
});
it("decodes a live MESSAGE frame with headers and JSON body", () => {
const raw =
"MESSAGE\ntraceId:f68cc229\ncontent-type:text/plain;charset=UTF-8\ndestination:/user/queue/main\nsubscription:sub-0\nmessage-id:975afec7-1\ncontent-length:64\n\n" +
'{"type":"1PO/COMMON/COMMAND_PROCESSING_RESPONSE","payload":true}\u0000';
const frame = decodeFrame(raw);
expect(frame?.command).toBe("MESSAGE");
expect(frame?.headers.traceId).toBe("f68cc229");
expect(frame?.headers["content-type"]).toBe("text/plain;charset=UTF-8");
expect(JSON.parse(frame!.body)).toEqual({
type: "1PO/COMMON/COMMAND_PROCESSING_RESPONSE",
payload: true,
});
});
it("treats heartbeat newlines as no frame", () => {
expect(decodeFrame("\n")).toBeNull();
expect(decodeFrame("")).toBeNull();
});
it("keeps the first value of a repeated header", () => {
const frame = decodeFrame("MESSAGE\nk:first\nk:second\n\nbody\u0000");
expect(frame?.headers.k).toBe("first");
expect(frame?.body).toBe("body");
});
});

View File

@@ -0,0 +1,69 @@
/**
* Minimal STOMP 1.2 codec used by the RPartStore BFF client.
* The BFF speaks STOMP over a plain WebSocket (`wss://1po-bff.renault-edh.com/ws`):
* CONNECT → CONNECTED, SUBSCRIBE /user/queue/main + /user/queue/error,
* SEND /app/<path> with a `trace-id` header, and 1..N MESSAGE frames back
* carrying the same `traceId` header and a `{type, payload}` JSON body.
*/
export interface StompFrame {
command: string;
headers: Record<string, string>;
body: string;
}
const NULL = "\u0000";
/** STOMP 1.2 header value escaping (RFC: `\\`, `\n` → `\\n`, `:` → `\\c`, `\r` → `\\r`). */
function escapeHeader(value: string): string {
return value
.replace(/\\/g, "\\\\")
.replace(/\r/g, "\\r")
.replace(/\n/g, "\\n")
.replace(/:/g, "\\c");
}
function unescapeHeader(value: string): string {
return value
.replace(/\\n/g, "\n")
.replace(/\\r/g, "\r")
.replace(/\\c/g, ":")
.replace(/\\\\/g, "\\");
}
export function encodeFrame(
command: string,
headers: Record<string, string | number>,
body = "",
): string {
const lines = [command];
for (const [k, v] of Object.entries(headers)) {
lines.push(`${k}:${command === "CONNECT" ? String(v) : escapeHeader(String(v))}`);
}
if (body && headers["content-length"] === undefined) {
lines.push(`content-length:${Buffer.byteLength(body, "utf8")}`);
}
return `${lines.join("\n")}\n\n${body}${NULL}`;
}
/** Heartbeat frames are a bare newline; they decode to `null`. */
export function decodeFrame(raw: string): StompFrame | null {
if (raw === "\n" || raw === "\r\n" || raw === "") return null;
const headerEnd = raw.indexOf("\n\n");
if (headerEnd < 0) return null;
const headerBlock = raw.slice(0, headerEnd).split("\n");
const command = headerBlock[0].trim();
const headers: Record<string, string> = {};
for (const line of headerBlock.slice(1)) {
const i = line.indexOf(":");
if (i < 0) continue;
const key = line.slice(0, i);
// STOMP: the first occurrence of a repeated header wins.
if (headers[key] === undefined)
headers[key] =
command === "CONNECTED" ? line.slice(i + 1) : unescapeHeader(line.slice(i + 1));
}
let body = raw.slice(headerEnd + 2);
if (body.endsWith(NULL)) body = body.slice(0, -1);
return { command, headers, body };
}

View File

@@ -0,0 +1,54 @@
/**
* Shapes of the RPartStore BFF `SEARCH_VEHICLE_RESPONSE` payload (DATAHUB
* catalog source, TR market). Captured live 2026-09-25; see
* /home/s/ss/rpartstore-dogrudan-vin-decode-2026-09-25.md for the protocol notes.
*/
export interface RpartstoreDataHubVehicle {
name?: string; // "RENAULT Kadjar (HFE)"
modelType?: string; // "SUV"
modelTypeCode?: string; // "HFE"
familyCode?: string; // "XFE"
bodyType?: string; // "HFE"
engine?: string; // "1.5 DCI DİZEL MOTOR [K9K]"
gearbox?: string; // "6 VİTESLİ KAVRAMA VİTES KUTUSU:DC4 [DC4]"
energyType?: string; // "MOTORIN"
powerKw?: string; // "066 KW POWER" | ""
modelYear?: string; // "2015"
vehicleAge?: number;
wheelbaseLength?: string;
roofHeight?: string;
}
export interface RpartstoreVehicle {
catalogSource: string; // "DATAHUB"
vin: string;
vehicleKey: string;
model: string | undefined; // "Kadjar (HFE)" — undefined on some pre-2000 cars
vehicleBrand: string; // "RENAULT" | "DACIA"
country: string; // "TR"
manufacturingDate?: string; // "2015-07-28"
imageUrl?: string;
dataHubVehicle?: RpartstoreDataHubVehicle;
vehicleIdentifiedBy?: string;
}
export interface SearchVehicleResponsePayload {
vehicles: RpartstoreVehicle[];
requestId: string;
searchedCountry: string;
}
/** Normalised decode result stored in `rpartstore_decodes`. */
export interface RpartstoreDecoded {
brandName: string; // "Renault" | "Dacia" (canonical casing, matches catalog_vehicles.brand_name)
model: string | null; // "Kadjar (HFE)"
modelCode: string | null; // "HFE"
familyCode: string | null; // "XFE"
modelYear: string | null; // "2015"
engine: string | null;
gearbox: string | null;
energyType: string | null;
manufacturingDate: string | null;
raw: RpartstoreVehicle;
}

View File

@@ -0,0 +1,213 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import { VinpinDaemonService } from "./vinpin-daemon.service";
import type { VinpinDriverService } from "./vinpin-driver.service";
/**
* Unit tests for the Vinpin warm-session daemon lifecycle: the business-hours
* scheduler (warm/teardown reconciliation with an injected clock), warm-on-demand
* decode routing, and the reentrancy guard. The driver is a fake — the real seat
* lives on prod and can't be driven from a test.
*/
interface FakeDriver {
isWarm: ReturnType<typeof vi.fn>;
warmUp: ReturnType<typeof vi.fn>;
teardownWarm: ReturnType<typeof vi.fn>;
decode: ReturnType<typeof vi.fn>;
keepalivePing: ReturnType<typeof vi.fn>;
}
function makeDriver(warm = false): FakeDriver {
return {
isWarm: vi.fn(() => warm),
warmUp: vi.fn(async () => true),
teardownWarm: vi.fn(async () => undefined),
decode: vi.fn(async () => null),
keepalivePing: vi.fn(async () => undefined),
};
}
function daemon(driver: FakeDriver, opts: { hours: boolean; enabled?: boolean }) {
return new VinpinDaemonService({
driver: driver as unknown as VinpinDriverService,
isBusinessHours: () => opts.hours,
isEnabled: () => opts.enabled ?? true,
});
}
describe("VinpinDaemonService — scheduler reconcile", () => {
afterEach(() => vi.restoreAllMocks());
it("warms up inside business hours when enabled and not already warm", async () => {
const driver = makeDriver(false);
await daemon(driver, { hours: true }).reconcile();
expect(driver.warmUp).toHaveBeenCalledTimes(1);
expect(driver.teardownWarm).not.toHaveBeenCalled();
});
it("does NOT re-warm when already warm inside hours", async () => {
const driver = makeDriver(true);
await daemon(driver, { hours: true }).reconcile();
expect(driver.warmUp).not.toHaveBeenCalled();
expect(driver.teardownWarm).not.toHaveBeenCalled();
});
it("tears down the warm seat outside business hours", async () => {
const driver = makeDriver(true);
await daemon(driver, { hours: false }).reconcile();
expect(driver.teardownWarm).toHaveBeenCalledTimes(1);
expect(driver.warmUp).not.toHaveBeenCalled();
});
it("tears down a warm seat when the daemon is disabled (kill-switch)", async () => {
const driver = makeDriver(true);
await daemon(driver, { hours: true, enabled: false }).reconcile();
expect(driver.teardownWarm).toHaveBeenCalledTimes(1);
expect(driver.warmUp).not.toHaveBeenCalled();
});
it("does nothing when disabled and already cold", async () => {
const driver = makeDriver(false);
await daemon(driver, { hours: true, enabled: false }).reconcile();
expect(driver.warmUp).not.toHaveBeenCalled();
expect(driver.teardownWarm).not.toHaveBeenCalled();
});
it("does not stack overlapping reconciles (reentrancy guard)", async () => {
const driver = makeDriver(false);
let release!: () => void;
driver.warmUp.mockImplementation(
() =>
new Promise<boolean>((resolve) => {
release = () => resolve(true);
}),
);
const d = daemon(driver, { hours: true });
const first = d.reconcile();
const second = d.reconcile(); // should early-return while the first is in flight
release();
await Promise.all([first, second]);
expect(driver.warmUp).toHaveBeenCalledTimes(1);
});
});
describe("VinpinDaemonService — decode routing", () => {
afterEach(() => vi.restoreAllMocks());
it("warms on-demand then delegates when inside hours and cold", async () => {
const driver = makeDriver(false);
driver.decode.mockResolvedValue({ brand: "Fiat", model: "EGEA" });
const result = await daemon(driver, { hours: true }).decode("NM435600006H43436");
expect(driver.warmUp).toHaveBeenCalledTimes(1);
expect(driver.decode).toHaveBeenCalledWith("NM435600006H43436");
expect(result).toEqual({ brand: "Fiat", model: "EGEA" });
});
it("does NOT warm on-demand when already warm — just delegates", async () => {
const driver = makeDriver(true);
await daemon(driver, { hours: true }).decode("NM435600006H43436");
expect(driver.warmUp).not.toHaveBeenCalled();
expect(driver.decode).toHaveBeenCalledTimes(1);
});
it("off-hours delegates straight to the cold path (never holds the seat)", async () => {
const driver = makeDriver(false);
await daemon(driver, { hours: false }).decode("NM435600006H43436");
expect(driver.warmUp).not.toHaveBeenCalled();
expect(driver.decode).toHaveBeenCalledTimes(1);
});
it("returns null (never throws) if the driver decode rejects", async () => {
const driver = makeDriver(true);
driver.decode.mockRejectedValue(new Error("boom"));
const result = await daemon(driver, { hours: true }).decode("NM435600006H43436");
expect(result).toBeNull();
});
});
describe("VinpinDaemonService — warm-up backoff", () => {
afterEach(() => vi.restoreAllMocks());
function backoffDaemon(driver: FakeDriver, clock: { t: number }) {
return new VinpinDaemonService({
driver: driver as unknown as VinpinDriverService,
isBusinessHours: () => true,
isEnabled: () => true,
now: () => clock.t,
});
}
it("a failed warmUp sets a cooldown that reconcile() respects (no immediate re-warm)", async () => {
const driver = makeDriver(false);
driver.warmUp.mockResolvedValue(false); // warm-up keeps failing
const clock = { t: 0 };
const d = backoffDaemon(driver, clock);
await d.reconcile();
expect(driver.warmUp).toHaveBeenCalledTimes(1); // first attempt ran
// Still cold + in hours, but inside the cooldown → no second attempt.
clock.t = 30_000;
await d.reconcile();
expect(driver.warmUp).toHaveBeenCalledTimes(1);
// After the base cooldown (60s) elapses → it tries again.
clock.t = 61_000;
await d.reconcile();
expect(driver.warmUp).toHaveBeenCalledTimes(2);
});
it("warm-on-demand decode ALSO respects the cooldown, but still delegates the cold decode", async () => {
const driver = makeDriver(false);
driver.warmUp.mockResolvedValue(false);
const clock = { t: 0 };
const d = backoffDaemon(driver, clock);
await d.reconcile(); // fails → cooldown until 60_000
expect(driver.warmUp).toHaveBeenCalledTimes(1);
clock.t = 20_000;
await d.decode("NM435600006H43436"); // in cooldown → no warm-on-demand
expect(driver.warmUp).toHaveBeenCalledTimes(1);
expect(driver.decode).toHaveBeenCalledTimes(1); // still decodes via the cold path
});
it("a successful warm resets the backoff (next attempt is not blocked)", async () => {
const driver = makeDriver(false);
driver.warmUp.mockResolvedValueOnce(false).mockResolvedValueOnce(true).mockResolvedValue(false);
const clock = { t: 0 };
const d = backoffDaemon(driver, clock);
await d.reconcile(); // fail → cooldown until 60_000
clock.t = 61_000;
await d.reconcile(); // success → cooldown reset
expect(driver.warmUp).toHaveBeenCalledTimes(2);
// isWarm() is still false in the fake, so reconcile would warm again — and with
// the cooldown reset it may attempt immediately (no leftover backoff window).
clock.t = 61_500;
await d.reconcile();
expect(driver.warmUp).toHaveBeenCalledTimes(3);
});
});
describe("VinpinDaemonService — start/stop lifecycle", () => {
beforeEach(() => vi.useFakeTimers());
afterEach(() => {
vi.useRealTimers();
vi.restoreAllMocks();
});
it("reconciles on start and drives keepalive on the interval; stop tears down", async () => {
const driver = makeDriver(false);
const d = daemon(driver, { hours: true });
d.start();
// Immediate reconcile → warm.
await vi.waitFor(() => expect(driver.warmUp).toHaveBeenCalledTimes(1));
// Advance past a keepalive interval → a ping fires.
await vi.advanceTimersByTimeAsync(80_000);
expect(driver.keepalivePing).toHaveBeenCalled();
await d.stop();
expect(driver.teardownWarm).toHaveBeenCalled();
});
});

View File

@@ -0,0 +1,195 @@
/**
* Vinpin warm-session daemon (worker-process singleton).
*
* Owns the LIFECYCLE of the persistent warm Vinpin seat, on top of the browser
* mechanics in VinpinDriverService:
* - a scheduler that warms the seat at 08:00 and tears it down at 21:00
* Europe/Istanbul (and warms on worker start if already inside the window),
* - an idle keepalive that nudges the RDS session every ~75s so it never drops,
* - `decode(vin)` — the entry the vinpin-decode processor calls. Inside business
* hours it makes sure the seat is warm (warming on-demand once), then delegates
* to the driver, which self-routes to the HOT warm path when warm and the
* proven COLD per-decode path otherwise. Outside hours it never holds the seat
* — the driver's cold path handles the decode and is torn down after.
*
* ADDITIVE + fail-safe: every warm operation degrades to the cold path, and
* `decode()` never throws (the driver returns null on any failure). Gated by
* VINPIN_ENABLED (feature flag) and VINPIN_WARM_DAEMON (kill-switch: set to
* "false" to force the legacy per-decode cold path with the daemon inert).
*/
import { Logger } from "@nestjs/common";
import { getVinpinDriver } from "./vinpin-driver.service";
import type { VinpinDecodeResult, VinpinDriverService } from "./vinpin-driver.service";
import { VINPIN_WARM, isVinpinBusinessHours } from "./vinpin.constants";
/** Whether the warm daemon is allowed to run (feature flag + kill-switch). */
export function isVinpinWarmDaemonEnabled(): boolean {
return process.env.VINPIN_ENABLED === "true" && process.env.VINPIN_WARM_DAEMON !== "false";
}
export interface VinpinDaemonDeps {
/** Driver singleton (injectable for tests). Defaults to the process-wide one. */
driver?: VinpinDriverService;
/** Business-hours predicate (injectable so tests can drive the clock). */
isBusinessHours?: () => boolean;
/** Warm-daemon enabled predicate (injectable for tests). */
isEnabled?: () => boolean;
/** Monotonic-ish clock (injectable so tests can drive the warm-up backoff). */
now?: () => number;
}
export class VinpinDaemonService {
private readonly logger = new Logger(VinpinDaemonService.name);
private readonly driver: VinpinDriverService;
private readonly isBusinessHours: () => boolean;
private readonly isEnabled: () => boolean;
private readonly now: () => number;
private schedulerTimer: ReturnType<typeof setInterval> | null = null;
private keepaliveTimer: ReturnType<typeof setInterval> | null = null;
private reconciling = false;
private started = false;
// ─── Warm-up backoff ─────────────────────────────────────
/** Wall-clock time until which a re-warm is suppressed after a failed warmUp.
* Both reconcile() and decode()'s warm-on-demand honour this so a failing seat
* isn't hammered every ~60s (each failed attempt would leave a fresh dirty
* window). A successful warm resets it. */
private warmCooldownUntil = 0;
/** Current backoff span (ms): 0 when healthy, else base…max, doubling per
* consecutive failure. */
private warmBackoffMs = 0;
constructor(deps: VinpinDaemonDeps = {}) {
this.driver = deps.driver ?? getVinpinDriver();
this.isBusinessHours = deps.isBusinessHours ?? (() => isVinpinBusinessHours());
this.isEnabled = deps.isEnabled ?? isVinpinWarmDaemonEnabled;
this.now = deps.now ?? (() => Date.now());
}
/** True while a failed warmUp's cooldown is still in effect. */
private inWarmCooldown(): boolean {
return this.now() < this.warmCooldownUntil;
}
/**
* Record a warm-up outcome and update the backoff. Success clears the cooldown;
* failure sets/extends it (base, then exponential up to max). Returns `ok` so
* callers can chain.
*/
private noteWarmResult(ok: boolean): boolean {
if (ok) {
this.warmBackoffMs = 0;
this.warmCooldownUntil = 0;
} else {
this.warmBackoffMs =
this.warmBackoffMs === 0
? VINPIN_WARM.warmBackoffBaseMs
: Math.min(this.warmBackoffMs * 2, VINPIN_WARM.warmBackoffMaxMs);
this.warmCooldownUntil = this.now() + this.warmBackoffMs;
this.logger.warn(
`warmUp failed — backing off ${Math.round(this.warmBackoffMs / 1000)}s before the next attempt`,
);
}
return ok;
}
/** Start the scheduler + keepalive loops (idempotent). */
start(): void {
if (this.started) return;
this.started = true;
// Reconcile once now (warm immediately if the worker booted inside hours).
void this.reconcile();
this.schedulerTimer = setInterval(() => {
void this.reconcile();
}, VINPIN_WARM.schedulerIntervalMs);
this.keepaliveTimer = setInterval(() => {
void this.driver.keepalivePing();
}, VINPIN_WARM.keepaliveIntervalMs);
// Don't keep the event loop alive just for these timers.
this.schedulerTimer.unref?.();
this.keepaliveTimer.unref?.();
this.logger.log(
`Vinpin warm daemon started (enabled=${this.isEnabled()}, hours ${VINPIN_WARM.businessStartHour}:00–${VINPIN_WARM.businessEndHour}:00 Europe/Istanbul)`,
);
}
/** Stop the loops and tear the warm seat down (worker shutdown). */
async stop(): Promise<void> {
if (this.schedulerTimer) clearInterval(this.schedulerTimer);
if (this.keepaliveTimer) clearInterval(this.keepaliveTimer);
this.schedulerTimer = null;
this.keepaliveTimer = null;
this.started = false;
await this.driver.teardownWarm().catch(() => undefined);
}
/**
* Reconcile the warm seat against the schedule: warm up when enabled + inside
* hours + not already warm; tear down when warm but disabled or outside hours.
* Guards against overlapping runs (a slow warmUp must not stack). Never throws.
*/
async reconcile(): Promise<void> {
if (this.reconciling) return;
this.reconciling = true;
try {
const enabled = this.isEnabled();
const inHours = this.isBusinessHours();
if (enabled && inHours && !this.driver.isWarm()) {
if (this.inWarmCooldown()) {
this.logger.debug("scheduler: in warm-up backoff — skipping this cycle");
} else {
this.logger.log("scheduler: inside business hours — warming the seat");
this.noteWarmResult(await this.driver.warmUp());
}
} else if (this.driver.isWarm() && (!enabled || !inHours)) {
this.logger.log("scheduler: outside business hours / disabled — tearing the seat down");
await this.driver.teardownWarm();
// Intentional teardown → clear any stale warm-up backoff so the next window
// (e.g. tomorrow 08:00) isn't blocked by a leftover cooldown.
this.warmBackoffMs = 0;
this.warmCooldownUntil = 0;
}
} catch (err) {
this.logger.warn(`reconcile failed: ${(err as Error).message}`);
} finally {
this.reconciling = false;
}
}
/**
* Decode entry the processor calls. Inside hours, ensure the seat is warm (warm
* on-demand once), then delegate to the driver — which uses the hot warm path
* when warm, else the cold per-decode path. Off-hours, delegate straight to the
* driver's cold path (no seat held). Never throws — returns null on any failure.
*/
async decode(vin: string): Promise<VinpinDecodeResult | null> {
try {
if (
this.isEnabled() &&
this.isBusinessHours() &&
!this.driver.isWarm() &&
!this.inWarmCooldown()
) {
// Warm-on-demand: a decode arrived inside hours before the scheduler warmed
// (e.g. right after 08:00, or after a drop). Best-effort — if it fails the
// driver silently runs the cold path for this decode, and the backoff spaces
// out the next warm attempt (respected by both this check and reconcile()).
this.noteWarmResult(await this.driver.warmUp().catch(() => false));
}
return await this.driver.decode(vin);
} catch (err) {
// Defensive: driver.decode never throws, but guarantee the processor a null.
this.logger.warn(`decode(${vin}) unexpected error: ${(err as Error).message}`);
return null;
}
}
}
// ─── Worker singleton ────────────────────────────────────────
let daemonSingleton: VinpinDaemonService | null = null;
export function getVinpinDaemon(): VinpinDaemonService {
if (!daemonSingleton) daemonSingleton = new VinpinDaemonService();
return daemonSingleton;
}

View File

@@ -0,0 +1,680 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
/**
* Renault-decode robustness tests (Rpartstore-down hardening). These exercise the
* fixes that stop a DOWN Rpartstore from thrashing the shared seat:
* (2) ensureRpartstore no longer short-circuits "already open" on the flyout /
* window-title word "Rpartstore" — it gates on a CONTENT token and clicks the
* flyout entry when the submenu is up over the grid;
* (3) closeRpartstoreTab never clicks the language-selector coord (1298,14);
* (6) an in-memory cooldown routes Renault decodes straight to Dialogys during a
* persistent Rpartstore outage, and a successful load clears it.
* OCR is mocked so the screen-state sequence is fully controllable — the real seat
* lives on prod and can't be driven from a test.
*/
vi.mock("./vinpin.ocr", () => ({
ocrRegion: vi.fn(async () => ""),
pollForText: vi.fn(async () => ({ matched: false, text: "" })),
terminateOcr: vi.fn(async () => undefined),
}));
import { VinpinDriverService } from "./vinpin-driver.service";
import { VINPIN_COORDS } from "./vinpin.constants";
import { ocrRegion } from "./vinpin.ocr";
const mockOcr = vi.mocked(ocrRegion);
type AnyDriver = Record<string, unknown>;
function fakePage(sink?: (x: number, y: number) => void) {
return {
isClosed: () => false,
frames: () => [] as unknown[],
mouse: {
click: vi.fn(async (x: number, y: number) => sink?.(x, y)),
move: vi.fn(async () => undefined),
down: vi.fn(async () => undefined),
up: vi.fn(async () => undefined),
},
keyboard: { press: vi.fn(async () => undefined) },
waitForTimeout: vi.fn(async () => undefined),
locator: () => ({
first: () => ({
count: async () => 0,
isVisible: async () => false,
click: async () => undefined,
}),
}),
};
}
describe("VinpinDriverService — ensureRpartstore flyout false-positive (change 2)", () => {
const savedEnv = { ...process.env };
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
mockOcr.mockReset();
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
const ensure = (driver: VinpinDriverService, page: unknown) =>
((driver as unknown as AnyDriver).ensureRpartstore as (p: unknown) => Promise<boolean>).call(
driver,
page,
);
it("does NOT declare Rpartstore open on the FLYOUT — it clicks the Rpartstore entry (584,779)", async () => {
const driver = new VinpinDriverService();
const page = fakePage();
// Flyout is open OVER the grid: brand tiles visible + the Renault submenu items
// "Rpartstore"/"Dialogys" — matches renaultSubmenu but has NO search-home content.
mockOcr
.mockResolvedValueOnce("Volkswagen Mitsubishi TecDoc Renault Rpartstore Dialogys")
.mockResolvedValue("Şasi no ile arama Güncel araçlar"); // then the LOADED home
const ok = await ensure(driver, page);
expect(ok).toBe(true);
// The flyout Rpartstore entry was clicked (old code short-circuited without it).
expect(page.mouse.click).toHaveBeenCalledWith(
VINPIN_COORDS.renaultRpartstore.x,
VINPIN_COORDS.renaultRpartstore.y,
);
});
it("short-circuits (no flyout/tile click) when the LOADED search-home content is already on screen", async () => {
const driver = new VinpinDriverService();
const page = fakePage();
mockOcr.mockResolvedValue("Şasi no ile arama Ne arıyorsunuz Güncel araçlar");
expect(await ensure(driver, page)).toBe(true);
expect(page.mouse.click).not.toHaveBeenCalledWith(
VINPIN_COORDS.renaultRpartstore.x,
VINPIN_COORDS.renaultRpartstore.y,
);
expect(page.mouse.move).not.toHaveBeenCalledWith(
VINPIN_COORDS.renaultBrand.x,
VINPIN_COORDS.renaultBrand.y,
);
});
it("treats an open Rpartstore WINDOW (title only, no grid behind) as present without re-clicking the flyout", async () => {
const driver = new VinpinDriverService();
const page = fakePage();
// Window title bar "Renault Rpartstore" matches renaultSubmenu too, but there's
// NO grid behind it → must be handled by the open-window branch, not the flyout.
mockOcr.mockResolvedValue("Renault Rpartstore");
expect(await ensure(driver, page)).toBe(true);
expect(page.mouse.click).not.toHaveBeenCalledWith(
VINPIN_COORDS.renaultRpartstore.x,
VINPIN_COORDS.renaultRpartstore.y,
);
});
it("bails on the FIRST iteration when the DOWN launch-error modal is over the grid (no repeated flyout clicks)", async () => {
const driver = new VinpinDriverService();
const page = fakePage();
// DOWN Rpartstore: the launch-error modal sits OVER the brand grid. The FULL-frame
// read (no clip) sees the grid tiles + the modal TITLE "Renault Rpartstore" → it
// matches brandGrid AND renaultSubmenu, which — without the fix — makes the flyout
// branch re-click renaultRpartstore(584,779) on all ~6 iterations. The UPSCALED
// modal crop (clip passed) reads the Cyrillic launch error, so the launch-error
// short-circuit must fire and return false on iteration 1.
mockOcr.mockImplementation(async (_page: unknown, clip?: unknown) =>
clip
? "Owwu6ka 3anycka KaTanora" // upscaled modal crop → matches rpartstoreLaunchError
: "Volkswagen Mitsubishi Renault Rpartstore Dialogys",
);
const ok = await ensure(driver, page);
expect(ok).toBe(false);
// Never re-clicked the flyout Rpartstore entry (would be up to 6× without the fix).
expect(page.mouse.click).not.toHaveBeenCalledWith(
VINPIN_COORDS.renaultRpartstore.x,
VINPIN_COORDS.renaultRpartstore.y,
);
// Exactly ONE full-frame OCR read (no clip) proves it bailed on the first iteration
// rather than looping the 6-try budget.
const fullFrameReads = mockOcr.mock.calls.filter(([, clip]) => clip === undefined);
expect(fullFrameReads).toHaveLength(1);
});
it("still enters the flyout branch when the modal crop is ILLEGIBLE (no ffmpeg) — behaviour unchanged", async () => {
const driver = new VinpinDriverService();
const page = fakePage();
// Same grid+flyout-title screen, but the crop OCR yields no launch-error text (the
// no-ffmpeg / illegible case). The launch-error short-circuit must NOT fire, so the
// proven flyout path still runs and clicks the Rpartstore entry.
mockOcr.mockImplementation(async (_page: unknown, clip?: unknown) =>
clip
? "" // illegible crop → rpartstoreLaunchErrorPresent === false
: "Volkswagen Mitsubishi Renault Rpartstore Dialogys",
);
// Bounded loop; we only assert the flyout entry was clicked (grid+submenu branch).
await ensure(driver, page);
expect(page.mouse.click).toHaveBeenCalledWith(
VINPIN_COORDS.renaultRpartstore.x,
VINPIN_COORDS.renaultRpartstore.y,
);
});
});
describe("VinpinDriverService — closeRpartstoreTab never hits the language selector (change 3)", () => {
const savedEnv = { ...process.env };
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
mockOcr.mockReset();
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
const close = (driver: VinpinDriverService, page: unknown) =>
((driver as unknown as AnyDriver).closeRpartstoreTab as (p: unknown) => Promise<void>).call(
driver,
page,
);
it("uses the tab-✕ (93,45) + Escape and NEVER clicks windowClose (1298,14) on a stuck spinner", async () => {
const driver = new VinpinDriverService();
const page = fakePage();
// Chrome/spinner only (no search-home content) → the second close must NOT fire.
mockOcr.mockResolvedValue("Renault Rpartstore");
await close(driver, page);
expect(page.mouse.click).toHaveBeenCalledWith(
VINPIN_COORDS.catalogTabClose.x,
VINPIN_COORDS.catalogTabClose.y,
);
expect(page.mouse.click).not.toHaveBeenCalledWith(
VINPIN_COORDS.windowClose.x,
VINPIN_COORDS.windowClose.y,
);
expect(page.keyboard.press).toHaveBeenCalledWith("Escape");
// Exactly ONE close click (no content → no retry).
const closeClicks = page.mouse.click.mock.calls.filter(
([x, y]) => x === VINPIN_COORDS.catalogTabClose.x && y === VINPIN_COORDS.catalogTabClose.y,
);
expect(closeClicks).toHaveLength(1);
});
it("retries the tab-✕ (NOT windowClose) when a LOADED home is still up after the first close", async () => {
const driver = new VinpinDriverService();
const page = fakePage();
mockOcr.mockResolvedValue("Şasi no ile arama Güncel araçlar"); // loaded home persists
await close(driver, page);
const closeClicks = page.mouse.click.mock.calls.filter(
([x, y]) => x === VINPIN_COORDS.catalogTabClose.x && y === VINPIN_COORDS.catalogTabClose.y,
);
expect(closeClicks).toHaveLength(2); // first + one content-gated retry
expect(page.mouse.click).not.toHaveBeenCalledWith(
VINPIN_COORDS.windowClose.x,
VINPIN_COORDS.windowClose.y,
);
});
});
describe("VinpinDriverService — Rpartstore-down cooldown routes Renault → Dialogys (change 6)", () => {
const savedEnv = { ...process.env };
const FAR_DEADLINE = () => Date.now() + 5 * 60_000;
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
process.env.VINPIN_USER = "user";
process.env.VINPIN_PASS = "pass";
mockOcr.mockReset();
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
const inCooldown = (driver: VinpinDriverService) =>
((driver as unknown as AnyDriver).rpartstoreInCooldown as () => boolean).call(driver);
const acquire = (driver: VinpinDriverService, page: unknown, warm: boolean) =>
(
(driver as unknown as AnyDriver).acquireLoadedRpartstore as (
p: unknown,
c: unknown,
d: number,
w: boolean,
) => Promise<boolean>
).call(driver, page, {}, FAR_DEADLINE(), warm);
it("while in cooldown, warm Renault decode SKIPS Rpartstore entirely and uses Dialogys", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
any.rpartstoreCooldownUntil = Date.now() + 60_000; // cooldown active
const acquireSpy = vi.spyOn(any as never, "acquireLoadedRpartstore");
const runRpartstore = vi.spyOn(any as never, "runRpartstore");
vi.spyOn(any as never, "ensureWarmWindow").mockResolvedValue(true as never);
vi.spyOn(any as never, "runDialogysSearch").mockResolvedValue({
status: "found",
parsed: { brand: "RENAULT", model: "MEGANE", modelYear: null },
rawText: "Megane",
via: "dialogys",
} as never);
const page = { keyboard: { press: vi.fn(async () => undefined) } };
const result = await (
any.warmRenaultDecode as (p: unknown, v: string, c: unknown, d: number) => Promise<unknown>
).call(driver, page, "VF1LM1B0A37829019", { rpartstoreEnabled: true }, FAR_DEADLINE());
expect(acquireSpy).not.toHaveBeenCalled(); // Rpartstore never opened during the outage
expect(runRpartstore).not.toHaveBeenCalled();
expect(result).toMatchObject({
brand: "RENAULT",
model: "MEGANE",
raw: { source: "vinpin-dialogys" },
});
});
it("a hard launch-error SETS the cooldown", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
vi.spyOn(any as never, "pollRpartstoreState").mockResolvedValue({
loaded: false,
launchError: true,
text: "Owwu6ka 3anycka KaTanora",
} as never);
const page = fakePage();
expect(inCooldown(driver)).toBe(false);
expect(await acquire(driver, page, true)).toBe(false);
expect(inCooldown(driver)).toBe(true); // → next Renault VIN routes straight to Dialogys
});
it("a confirmed Rpartstore load CLEARS an active cooldown", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
any.rpartstoreCooldownUntil = Date.now() + 60_000; // pretend it was marked down
vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
vi.spyOn(any as never, "pollRpartstoreState").mockResolvedValue({
loaded: true,
launchError: false,
text: "Şasi no ile arama",
} as never);
const page = fakePage();
expect(inCooldown(driver)).toBe(true);
expect(await acquire(driver, page, true)).toBe(true);
expect(inCooldown(driver)).toBe(false); // healthy again → Rpartstore resumes as primary
});
it("a transient born-stuck-spinner streak (maxOpens exhausted) does NOT set the cooldown", async () => {
// A born-stuck spinner is a TRANSIENT reopen-recoverable blip, not a server
// outage — exhausting maxOpens must fall back to Dialogys for THIS vin only and
// leave Rpartstore healthy for the next one, NOT suppress it for the full
// cooldown (which can't self-clear while it's being skipped).
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
vi.spyOn(any as never, "reopenFreshRpartstore").mockResolvedValue(true as never);
vi.spyOn(any as never, "closeRpartstoreTab").mockResolvedValue(undefined as never);
// Every poll = still spinning (never loaded, no launch error) → born-stuck path.
vi.spyOn(any as never, "pollRpartstoreState").mockResolvedValue({
loaded: false,
launchError: false,
text: "",
} as never);
const page = fakePage();
expect(inCooldown(driver)).toBe(false);
expect(await acquire(driver, page, true)).toBe(false); // gave up → Dialogys
expect(inCooldown(driver)).toBe(false); // but NOT cooled down → next VIN retries Rpartstore
});
});
/**
* Ambiguous-retry cheap in-session reset (the dirty-resume relaunch-thrash fix).
* An AMBIGUOUS Renault outcome is transient/state-dependent, so the retry must NOT
* tear the browser down (a full teardown forces a ~60–90s relaunch + re-login that
* re-hits the seat's "catalog window resumed open" dirty-resume every attempt →
* 3 attempts blow the 180s budget → not_found). Instead it returns to a clean
* VinPower brand grid on the SAME live session via ensureBrandGrid (which runs the
* closeStrayRunningApps DOM recovery first), and re-runs runRenaultFlow — no
* close()/relaunch. GRADUATED safety: only when that cheap reset can't reach a clean
* grid does it fall back to close() + cold re-establish. OCR is mocked so the grid
* confirmation is controllable.
*/
describe("VinpinDriverService — ambiguous Renault retry is a CHEAP in-session grid reset (no relaunch)", () => {
const savedEnv = { ...process.env };
const FAR_DEADLINE = () => Date.now() + 5 * 60_000;
const RENAULT_VIN = "VF1RFE00653633190"; // the live-trace VIN that thrashed on relaunch
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
process.env.VINPIN_USER = "user";
process.env.VINPIN_PASS = "pass";
mockOcr.mockReset();
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
// Present the driver as a live, authenticated session so the cheap reset's
// precheck (browser connected + context + open page + authed) passes and it never
// short-circuits to a cold re-establish.
function liveSession(driver: VinpinDriverService): AnyDriver {
const any = driver as unknown as AnyDriver;
any.browser = { isConnected: () => true };
any.context = {};
any.page = fakePage();
any.authed = true;
return any;
}
const decodeRenault = (driver: VinpinDriverService, vin: string) =>
(
(driver as unknown as AnyDriver).decodeRenaultLocked as (
v: string,
c: unknown,
d: number,
) => Promise<unknown>
).call(driver, vin, { maxAttempts: 3, budgetMs: 5 * 60_000 }, FAR_DEADLINE());
it("first ambiguous retry returns to the grid IN-SESSION (ensureBrandGrid) and re-runs runRenaultFlow WITHOUT close()/relaunch", async () => {
const driver = new VinpinDriverService();
const any = liveSession(driver);
// ensureAuthenticated is a no-op (session already up → NO relaunch, NO web login).
vi.spyOn(any as never, "ensureAuthenticated").mockResolvedValue(undefined as never);
// The cheap reset reaches a clean grid: ensureBrandGrid runs on the SAME session
// and the OCR read confirms the brand grid.
const ensureGrid = vi
.spyOn(any as never, "ensureBrandGrid")
.mockResolvedValue(undefined as never);
mockOcr.mockResolvedValue("Volkswagen Mitsubishi TecDoc"); // matches VINPIN_OCR.brandGrid
const close = vi.spyOn(any as never, "close").mockResolvedValue(undefined as never);
// attempt 1 → ambiguous (transient); attempt 2, same live session → found.
const runFlow = vi
.spyOn(any as never, "runRenaultFlow")
.mockResolvedValueOnce({ status: "ambiguous" } as never)
.mockResolvedValueOnce({
status: "found",
parsed: { brand: "RENAULT", model: "KADJAR", modelYear: null },
rawText: "RENAULT Kadjar",
via: "dialogys",
} as never);
const result = await decodeRenault(driver, RENAULT_VIN);
expect(result).toMatchObject({ brand: "RENAULT", model: "KADJAR" });
expect(runFlow).toHaveBeenCalledTimes(2); // ambiguous, then a cheap in-session re-run
expect(ensureGrid).toHaveBeenCalled(); // the in-session grid reset ran (closeStrayRunningApps path)
expect(close).not.toHaveBeenCalled(); // NO teardown/relaunch on the cheap first retry
});
it("GRADUATED fallback: when the cheap grid reset can't confirm a clean grid, it close()s + cold re-establishes", async () => {
const driver = new VinpinDriverService();
const any = liveSession(driver);
vi.spyOn(any as never, "ensureAuthenticated").mockResolvedValue(undefined as never);
// ensureBrandGrid runs but the grid is NEVER confirmed (OCR reads no grid) → the
// cheap reset returns false → the graduated hard reset (close) must fire.
const ensureGrid = vi
.spyOn(any as never, "ensureBrandGrid")
.mockResolvedValue(undefined as never);
mockOcr.mockResolvedValue(""); // no brand grid → cheap reset fails
const close = vi.spyOn(any as never, "close").mockResolvedValue(undefined as never);
const runFlow = vi
.spyOn(any as never, "runRenaultFlow")
.mockResolvedValueOnce({ status: "ambiguous" } as never)
.mockResolvedValueOnce({
status: "found",
parsed: { brand: "RENAULT", model: "MEGANE", modelYear: null },
rawText: "Megane",
via: "dialogys",
} as never);
const result = await decodeRenault(driver, RENAULT_VIN);
expect(result).toMatchObject({ brand: "RENAULT", model: "MEGANE" });
expect(ensureGrid).toHaveBeenCalled(); // the CHEAP reset was attempted first…
expect(close).toHaveBeenCalledTimes(1); // …then the graduated hard reset fired exactly once
expect(runFlow).toHaveBeenCalledTimes(2);
});
it("does NOT cheap-reset when the session is already gone — falls straight to close() (graduated)", async () => {
const driver = new VinpinDriverService();
const any = liveSession(driver);
// Session looks broken: the page is closed → the cheap reset's precheck fails and
// it returns false without touching ensureBrandGrid, so the hard reset runs.
(any.page as { isClosed: () => boolean }).isClosed = () => true;
vi.spyOn(any as never, "ensureAuthenticated").mockResolvedValue(undefined as never);
const ensureGrid = vi
.spyOn(any as never, "ensureBrandGrid")
.mockResolvedValue(undefined as never);
const close = vi.spyOn(any as never, "close").mockResolvedValue(undefined as never);
vi.spyOn(any as never, "runRenaultFlow")
.mockResolvedValueOnce({ status: "ambiguous" } as never)
.mockResolvedValueOnce({ status: "not_found" } as never);
const result = await decodeRenault(driver, RENAULT_VIN);
expect(result).toBeNull(); // 2nd attempt not_found → null
expect(ensureGrid).not.toHaveBeenCalled(); // broken session → no in-session grid work
expect(close).toHaveBeenCalledTimes(1); // graduated hard reset on the broken session
});
});
/**
* runRenaultFlow definitive-not_found gate (the budget-burn + seat-poison fix).
* When Rpartstore is UNAVAILABLE (down-cooldown, or it never loaded so `primary`
* is only the placeholder ambiguous), a CLEAN Dialogys not_found is DEFINITIVE on
* its own — the old gate required BOTH catalogs to say not_found, so every
* undecodable Renault while Rpartstore was down got downgraded to ambiguous →
* retry loop → 180s budget → sessionPoisoned. A genuinely-ambiguous Dialogys
* (couldn't be reached) still returns ambiguous so the transient-failure retry
* survives. When Rpartstore actually RAN, the both-must-agree gate is preserved.
*/
describe("VinpinDriverService — runRenaultFlow definitive not_found when Rpartstore unavailable", () => {
const savedEnv = { ...process.env };
const FAR_DEADLINE = () => Date.now() + 5 * 60_000;
const VIN = "VF1553K05TR596166"; // old (~1996) Renault 19 — the live budget-burn case
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
mockOcr.mockReset();
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
const runFlow = (driver: VinpinDriverService, page: unknown) =>
(
(driver as unknown as AnyDriver).runRenaultFlow as (
p: unknown,
v: string,
c: unknown,
d: number,
) => Promise<{ status: string }>
).call(driver, page, VIN, { rpartstoreEnabled: true }, FAR_DEADLINE());
it("cooldown (Rpartstore down) + Dialogys not_found → DEFINITIVE not_found, no Rpartstore, no retry", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
any.rpartstoreCooldownUntil = Date.now() + 60_000; // Rpartstore in down-cooldown
const acquire = vi.spyOn(any as never, "acquireLoadedRpartstore");
const runRpartstore = vi.spyOn(any as never, "runRpartstore");
const runDialogys = vi
.spyOn(any as never, "runDialogys")
.mockResolvedValue({ status: "not_found" } as never);
const outcome = await runFlow(driver, fakePage());
expect(outcome.status).toBe("not_found"); // definitive — no ambiguous downgrade
expect(acquire).not.toHaveBeenCalled(); // Rpartstore skipped during the outage
expect(runRpartstore).not.toHaveBeenCalled();
expect(runDialogys).toHaveBeenCalledTimes(1); // single shot — no budget-burn retry
});
it("Rpartstore never loaded (not cooldown) + Dialogys not_found → DEFINITIVE not_found", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
// Not in cooldown, but the acquire fails to load Rpartstore → primary never ran.
vi.spyOn(any as never, "acquireLoadedRpartstore").mockResolvedValue(false as never);
const runRpartstore = vi.spyOn(any as never, "runRpartstore");
vi.spyOn(any as never, "runDialogys").mockResolvedValue({ status: "not_found" } as never);
const outcome = await runFlow(driver, fakePage());
expect(outcome.status).toBe("not_found");
expect(runRpartstore).not.toHaveBeenCalled(); // acquire failed → primary placeholder only
});
it("Rpartstore unavailable + Dialogys AMBIGUOUS (unreachable) → still ambiguous (transient retry survives)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
any.rpartstoreCooldownUntil = Date.now() + 60_000; // down-cooldown
vi.spyOn(any as never, "runDialogys").mockResolvedValue({ status: "ambiguous" } as never);
const outcome = await runFlow(driver, fakePage());
expect(outcome.status).toBe("ambiguous"); // couldn't confirm not_found → caller retries
});
it("REGRESSION: Rpartstore RAN + ambiguous, Dialogys not_found → still ambiguous (both-must-agree preserved)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
// Rpartstore is UP: it loads and runs but is unsure (ambiguous). Dialogys then
// cleanly misses. Because Rpartstore actually ran, we must NOT treat this as a
// definitive not_found — the pre-fix both-must-agree behaviour is preserved.
vi.spyOn(any as never, "acquireLoadedRpartstore").mockResolvedValue(true as never);
vi.spyOn(any as never, "runRpartstore").mockResolvedValue({ status: "ambiguous" } as never);
vi.spyOn(any as never, "runDialogys").mockResolvedValue({ status: "not_found" } as never);
const outcome = await runFlow(driver, fakePage());
expect(outcome.status).toBe("ambiguous");
});
it("REGRESSION: Rpartstore RAN + not_found, Dialogys not_found → definitive not_found (unchanged)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
vi.spyOn(any as never, "acquireLoadedRpartstore").mockResolvedValue(true as never);
vi.spyOn(any as never, "runRpartstore").mockResolvedValue({ status: "not_found" } as never);
vi.spyOn(any as never, "runDialogys").mockResolvedValue({ status: "not_found" } as never);
const outcome = await runFlow(driver, fakePage());
expect(outcome.status).toBe("not_found");
});
});
/**
* VINPIN_RPARTSTORE_ENABLED=false kill-switch (KNOWN Rpartstore outage). Unlike the
* in-memory down-cooldown (which resets on every worker restart, so the first decode
* after each restart pays the full Rpartstore launch cost + leaves a stuck app), this
* config flag persists: when set, BOTH Renault paths (warm + cold) skip opening
* Rpartstore entirely and go straight to Dialogys, and a clean Dialogys not_found is
* DEFINITIVE (a flag-disabled Rpartstore is "unavailable" exactly like the cooldown).
* Default (unset / not "false") is TRUE — behaviour completely unchanged.
*/
describe("VinpinDriverService — VINPIN_RPARTSTORE_ENABLED=false skips Rpartstore in both Renault paths", () => {
const savedEnv = { ...process.env };
const FAR_DEADLINE = () => Date.now() + 5 * 60_000;
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
mockOcr.mockReset();
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
it("COLD runRenaultFlow (flag=false): never opens Rpartstore, goes straight to Dialogys, and a Dialogys not_found is DEFINITIVE (no retry)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
// NOT in cooldown — the ONLY reason to skip is the disabled flag.
const acquire = vi.spyOn(any as never, "acquireLoadedRpartstore");
const ensureR = vi.spyOn(any as never, "ensureRpartstore");
const runRpartstore = vi.spyOn(any as never, "runRpartstore");
const runDialogys = vi
.spyOn(any as never, "runDialogys")
.mockResolvedValue({ status: "not_found" } as never);
const outcome = await (
(any as AnyDriver).runRenaultFlow as (
p: unknown,
v: string,
c: unknown,
d: number,
) => Promise<{ status: string }>
).call(driver, fakePage(), "VF1553K05TR596166", { rpartstoreEnabled: false }, FAR_DEADLINE());
expect(acquire).not.toHaveBeenCalled(); // Rpartstore never opened
expect(ensureR).not.toHaveBeenCalled();
expect(runRpartstore).not.toHaveBeenCalled();
expect(runDialogys).toHaveBeenCalledTimes(1); // single shot — no budget-burn retry
expect(outcome.status).toBe("not_found"); // definitive — no ambiguous downgrade
});
it("WARM warmRenaultDecode (flag=false): never opens Rpartstore, decodes via Dialogys", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const acquire = vi.spyOn(any as never, "acquireLoadedRpartstore");
const ensureR = vi.spyOn(any as never, "ensureRpartstore");
const runRpartstore = vi.spyOn(any as never, "runRpartstore");
vi.spyOn(any as never, "ensureWarmWindow").mockResolvedValue(true as never);
vi.spyOn(any as never, "runDialogysSearch").mockResolvedValue({
status: "found",
parsed: { brand: "RENAULT", model: "MEGANE", modelYear: null },
rawText: "Megane",
via: "dialogys",
} as never);
const page = { keyboard: { press: vi.fn(async () => undefined) } };
const result = await (
any.warmRenaultDecode as (p: unknown, v: string, c: unknown, d: number) => Promise<unknown>
).call(driver, page, "VF1LM1B0A37829019", { rpartstoreEnabled: false }, FAR_DEADLINE());
expect(acquire).not.toHaveBeenCalled(); // Rpartstore never opened
expect(ensureR).not.toHaveBeenCalled();
expect(runRpartstore).not.toHaveBeenCalled();
expect(result).toMatchObject({
brand: "RENAULT",
model: "MEGANE",
raw: { source: "vinpin-dialogys" },
});
});
it("DEFAULT (flag=true): COLD path still ATTEMPTS Rpartstore (behaviour unchanged)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const acquire = vi
.spyOn(any as never, "acquireLoadedRpartstore")
.mockResolvedValue(true as never);
vi.spyOn(any as never, "runRpartstore").mockResolvedValue({
status: "found",
parsed: { brand: "RENAULT", model: "CLIO", modelYear: null },
rawText: "Clio",
via: "rpartstore",
} as never);
const outcome = await (
(any as AnyDriver).runRenaultFlow as (
p: unknown,
v: string,
c: unknown,
d: number,
) => Promise<{ status: string }>
).call(driver, fakePage(), "VF1553K05TR596166", { rpartstoreEnabled: true }, FAR_DEADLINE());
expect(acquire).toHaveBeenCalledTimes(1); // Rpartstore still primary by default
expect(outcome.status).toBe("found");
});
});

View File

@@ -0,0 +1,707 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import { VinpinDriverService, VinpinSessionDroppedError } from "./vinpin-driver.service";
import { VINPIN_COORDS, VINPIN_OCR, VINPIN_WINDOW_FOREGROUND } from "./vinpin.constants";
/**
* Livelock-breaker unit tests for the Vinpin decode driver. These exercise the
* failure/abort machinery (wall-clock budget, sessionPoisoned cold re-establish,
* VIN sanity gate) in isolation by stubbing the browser-driving privates — the
* shared Vinpin seat lives on prod and can't be driven from a test.
*/
describe("VinpinDriverService — livelock breakers", () => {
const savedEnv = { ...process.env };
const VALID_FIAT_VIN = "NM435600006H43436"; // 17 alphanumerics → fiat flow
beforeEach(() => {
// afterEach restores the full env snapshot, so VINPIN_DECODE_BUDGET_MS set by
// the budget test never leaks into the others.
process.env.VINPIN_ENABLED = "true";
process.env.VINPIN_USER = "user";
process.env.VINPIN_PASS = "pass";
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
it("aborts a single decode that blows past the wall-clock budget, tears down and poisons the seat", async () => {
process.env.VINPIN_DECODE_BUDGET_MS = "50";
const driver = new VinpinDriverService();
const anyDriver = driver as unknown as Record<string, unknown>;
const closeSpy = vi.spyOn(anyDriver as never, "close").mockResolvedValue(undefined as never);
// ensureReady succeeds cheaply, then runVinFlow hangs forever → the budget
// timer must win the race.
vi.spyOn(anyDriver as never, "ensureReady").mockImplementation((async () => {
anyDriver.page = { isClosed: () => false };
}) as never);
vi.spyOn(anyDriver as never, "runVinFlow").mockReturnValue(
new Promise(() => {}) as never, // never resolves
);
const started = Date.now();
const result = await driver.decode(VALID_FIAT_VIN);
const elapsed = Date.now() - started;
expect(result).toBeNull();
expect(closeSpy).toHaveBeenCalled(); // torn down on abort
expect(anyDriver.sessionPoisoned).toBe(true); // seat marked poisoned
// Aborted near the budget, not after minutes / all 3 internal attempts.
expect(elapsed).toBeLessThan(2_000);
});
it("forces a full cold re-establish (close) when the seat was poisoned by a prior decode", async () => {
const driver = new VinpinDriverService();
const anyDriver = driver as unknown as Record<string, unknown>;
anyDriver.sessionPoisoned = true;
const closeSpy = vi.spyOn(anyDriver as never, "close").mockResolvedValue(undefined as never);
const fiatSpy = vi
.spyOn(anyDriver as never, "decodeFiatLocked")
.mockResolvedValue({ brand: "Fiat", model: "EGEA" } as never);
const result = await driver.decode(VALID_FIAT_VIN);
expect(closeSpy).toHaveBeenCalledTimes(1); // the poison-forced teardown
expect(anyDriver.sessionPoisoned).toBe(false); // flag consumed
expect(fiatSpy).toHaveBeenCalledTimes(1);
expect(result).toEqual({ brand: "Fiat", model: "EGEA" });
});
it("does NOT tear down a healthy warm session when the seat is not poisoned", async () => {
const driver = new VinpinDriverService();
const anyDriver = driver as unknown as Record<string, unknown>;
anyDriver.sessionPoisoned = false;
const closeSpy = vi.spyOn(anyDriver as never, "close").mockResolvedValue(undefined as never);
vi.spyOn(anyDriver as never, "decodeFiatLocked").mockResolvedValue({
brand: "Fiat",
model: "EGEA",
} as never);
const result = await driver.decode(VALID_FIAT_VIN);
expect(closeSpy).not.toHaveBeenCalled(); // healthy path untouched
expect(result).toEqual({ brand: "Fiat", model: "EGEA" });
});
it("skips obviously-junk input before it ever touches the shared seat", async () => {
const driver = new VinpinDriverService();
const anyDriver = driver as unknown as Record<string, unknown>;
const fiatSpy = vi.spyOn(anyDriver as never, "decodeFiatLocked");
expect(await driver.decode("SHORT")).toBeNull();
expect(await driver.decode("VF1RFE0065363319")).toBeNull(); // 16 chars
expect(await driver.decode("NM4356 0006H43436")).toBeNull(); // space (non-alnum)
expect(fiatSpy).not.toHaveBeenCalled();
});
it("still runs a well-formed VIN through the decode loop (sanity gate is not over-filtering)", async () => {
const driver = new VinpinDriverService();
const anyDriver = driver as unknown as Record<string, unknown>;
const fiatSpy = vi
.spyOn(anyDriver as never, "decodeFiatLocked")
.mockResolvedValue(null as never);
expect(await driver.decode(VALID_FIAT_VIN)).toBeNull();
expect(fiatSpy).toHaveBeenCalledTimes(1);
});
});
/**
* Warm-session daemon behaviours on the driver: warm-vs-cold routing, the
* keepalive that must SKIP while a decode holds the seat, and health-recovery
* (session-drop → teardown + re-warm + single retry). The browser-driving privates
* are stubbed — the real seat lives on prod.
*/
describe("VinpinDriverService — warm session", () => {
const savedEnv = { ...process.env };
const VALID_FIAT_VIN = "NM435600006H43436";
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
process.env.VINPIN_USER = "user";
process.env.VINPIN_PASS = "pass";
process.env.VINPIN_WARM_DAEMON = "true";
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
function makeWarm(driver: VinpinDriverService) {
const any = driver as unknown as Record<string, unknown>;
any.warm = true;
any.browser = { isConnected: () => true };
any.page = { isClosed: () => false, mouse: { move: vi.fn(async () => undefined) } };
return any;
}
it("routes a decode to the WARM path when a healthy warm session is up", async () => {
const driver = new VinpinDriverService();
const any = makeWarm(driver);
const warmSpy = vi
.spyOn(any as never, "warmDecodeWithRecovery")
.mockResolvedValue({ brand: "Fiat", model: "EGEA" } as never);
const coldSpy = vi.spyOn(any as never, "decodeFiatLocked");
const result = await driver.decode(VALID_FIAT_VIN);
expect(warmSpy).toHaveBeenCalledTimes(1);
expect(coldSpy).not.toHaveBeenCalled(); // cold path bypassed while warm
expect(result).toEqual({ brand: "Fiat", model: "EGEA" });
});
it("falls back to the COLD path when VINPIN_WARM_DAEMON=false even if warm is set", async () => {
process.env.VINPIN_WARM_DAEMON = "false";
const driver = new VinpinDriverService();
const any = makeWarm(driver);
const warmSpy = vi.spyOn(any as never, "warmDecodeWithRecovery");
const coldSpy = vi
.spyOn(any as never, "decodeFiatLocked")
.mockResolvedValue({ brand: "Fiat", model: "EGEA" } as never);
await driver.decode(VALID_FIAT_VIN);
expect(warmSpy).not.toHaveBeenCalled();
expect(coldSpy).toHaveBeenCalledTimes(1);
});
it("keepalive SKIPS while a decode holds the seat (busy), and nudges when idle", async () => {
const driver = new VinpinDriverService();
const any = makeWarm(driver);
const move = (any.page as { mouse: { move: ReturnType<typeof vi.fn> } }).mouse.move;
// Busy (a decode is in flight) → no nudge, no lock contention.
any.busy = true;
await driver.keepalivePing();
expect(move).not.toHaveBeenCalled();
// Idle → the keepalive nudges the harmless in-window point.
any.busy = false;
await driver.keepalivePing();
expect(move).toHaveBeenCalledTimes(1);
});
it("on a dropped warm session, tears down + re-warms ONCE, then retries the decode once", async () => {
const driver = new VinpinDriverService();
const any = makeWarm(driver);
const warmDecode = vi
.spyOn(any as never, "warmDecode")
.mockRejectedValueOnce(new VinpinSessionDroppedError("dropped") as never)
.mockResolvedValueOnce({ brand: "Fiat", model: "EGEA" } as never);
const rewarm = vi.spyOn(any as never, "_warmUp").mockResolvedValue(true as never);
const result = await driver.decode(VALID_FIAT_VIN);
expect(warmDecode).toHaveBeenCalledTimes(2); // initial + one retry
expect(rewarm).toHaveBeenCalledTimes(1); // re-warmed exactly once
expect(result).toEqual({ brand: "Fiat", model: "EGEA" });
});
it("session-drop recovery gives up (null) when the re-warm fails — never throws", async () => {
const driver = new VinpinDriverService();
const any = makeWarm(driver);
vi.spyOn(any as never, "warmDecode").mockRejectedValue(
new VinpinSessionDroppedError("dropped") as never,
);
vi.spyOn(any as never, "_warmUp").mockResolvedValue(false as never);
const result = await driver.decode(VALID_FIAT_VIN);
expect(result).toBeNull();
expect(any.warm).toBe(false); // dropped seat marked not-warm → cold path next time
});
});
/**
* Rpartstore acquire-with-spinner-guard. A freshly-opened Rpartstore instance
* sometimes gets "born stuck" on an infinite spinner; the fix is to close the
* stuck instance and reopen a FRESH one, up to N times, inside the wall-clock
* budget, and only then fall back to Dialogys. These stub the browser-driving
* privates (real seat lives on prod) and drive the OCR-load verdict via a mocked
* pollRpartstoreState, which reads LOADED off the full frame and the HARD
* launch-error modal off an UPSCALED crop (spinner = {loaded:false,launchError:
* false}, loaded = {loaded:true}, DOWN = {launchError:true}).
*/
describe("VinpinDriverService — Rpartstore spinner guard", () => {
const savedEnv = { ...process.env };
const FAR_DEADLINE = () => Date.now() + 5 * 60_000;
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
process.env.VINPIN_USER = "user";
process.env.VINPIN_PASS = "pass";
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
function acquire(driver: VinpinDriverService, warm: boolean, deadline: number): Promise<boolean> {
const any = driver as unknown as Record<string, unknown>;
return (
any.acquireLoadedRpartstore as (
page: unknown,
cfg: unknown,
deadline: number,
warm: boolean,
) => Promise<boolean>
).call(driver, {}, {}, deadline, warm);
}
it("reuses Rpartstore when the FIRST open already loaded (no reopen, no close)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
const reopen = vi.spyOn(any as never, "reopenFreshRpartstore");
const close = vi.spyOn(any as never, "closeRpartstoreTab");
vi.spyOn(any as never, "pollRpartstoreState").mockResolvedValue({
loaded: true,
launchError: false,
text: "Şasi no ile arama",
} as never);
expect(await acquire(driver, true, FAR_DEADLINE())).toBe(true);
expect(reopen).not.toHaveBeenCalled();
expect(close).not.toHaveBeenCalled();
});
it("closes a born-stuck spinner and reopens a FRESH instance that loads (warm)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
const raise = vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
const reopen = vi.spyOn(any as never, "reopenFreshRpartstore").mockResolvedValue(true as never);
const close = vi
.spyOn(any as never, "closeRpartstoreTab")
.mockResolvedValue(undefined as never);
// open 1 → spinner (not loaded); open 2 (fresh) → loaded.
vi.spyOn(any as never, "pollRpartstoreState")
.mockResolvedValueOnce({ loaded: false, launchError: false, text: "spinner" } as never)
.mockResolvedValueOnce({ loaded: true, launchError: false, text: "Ne arıyorsunuz" } as never);
expect(await acquire(driver, true, FAR_DEADLINE())).toBe(true);
expect(raise).toHaveBeenCalledTimes(1); // only the first attempt raises
expect(close).toHaveBeenCalledTimes(1); // the stuck instance was closed
expect(reopen).toHaveBeenCalledTimes(1); // one fresh reopen, which loaded
});
it("gives up (false) after maxOpens reopen attempts all spinner → caller falls to Dialogys", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
vi.spyOn(any as never, "ensureRpartstore").mockResolvedValue(true as never); // cold open path
const reopen = vi.spyOn(any as never, "reopenFreshRpartstore").mockResolvedValue(true as never);
const close = vi
.spyOn(any as never, "closeRpartstoreTab")
.mockResolvedValue(undefined as never);
vi.spyOn(any as never, "pollRpartstoreState").mockResolvedValue({
loaded: false,
launchError: false,
text: "spinner",
} as never); // never loads
expect(await acquire(driver, false, FAR_DEADLINE())).toBe(false);
// maxOpens = 3: open 1 (ensureRpartstore) + 2 reopens; a close after each miss.
expect(reopen).toHaveBeenCalledTimes(2);
expect(close).toHaveBeenCalledTimes(3);
});
it("bails immediately (false) without opening when the budget is already spent (no livelock)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
const raise = vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
const poll = vi.spyOn(any as never, "pollRpartstoreState");
expect(await acquire(driver, true, Date.now() - 1)).toBe(false);
expect(raise).not.toHaveBeenCalled();
expect(poll).not.toHaveBeenCalled();
});
it("HARD launch error (Rpartstore DOWN) → returns false after ONE open, NO reopens, dismiss clicked → caller falls to Dialogys", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
const raise = vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
const reopen = vi.spyOn(any as never, "reopenFreshRpartstore");
const close = vi.spyOn(any as never, "closeRpartstoreTab");
// Upscaled modal-crop OCR of "Ошибка запуска каталога" — the VERBATIM string
// captured live 2026-07-15 on seat trvinpin47828 (see rpartstoreLaunchError).
vi.spyOn(any as never, "pollRpartstoreState").mockResolvedValue({
loaded: false,
launchError: true,
text: "Rpartstore X Owwu6ka 3anycka KaTanora",
} as never);
const page = {
mouse: { click: vi.fn(async () => undefined) },
waitForTimeout: vi.fn(async () => undefined),
};
const result = await (
any.acquireLoadedRpartstore as (
p: unknown,
c: unknown,
d: number,
w: boolean,
) => Promise<boolean>
).call(driver, page, {}, FAR_DEADLINE(), true);
expect(result).toBe(false); // → warmRenaultDecode/runRenaultFlow go straight to Dialogys
expect(raise).toHaveBeenCalledTimes(1); // opened exactly ONCE
expect(reopen).not.toHaveBeenCalled(); // NO reopens burned (~54s saved)
expect(close).not.toHaveBeenCalled(); // not treated as a spinner
// The launch-error modal's OK button was clicked to dismiss it.
expect(page.mouse.click).toHaveBeenCalledWith(
VINPIN_COORDS.rpartstoreLaunchErrorOk.x,
VINPIN_COORDS.rpartstoreLaunchErrorOk.y,
);
});
it("genuine spinner (no launch-error string) STILL triggers the close+reopen loop (unchanged)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
const reopen = vi.spyOn(any as never, "reopenFreshRpartstore").mockResolvedValue(true as never);
const close = vi
.spyOn(any as never, "closeRpartstoreTab")
.mockResolvedValue(undefined as never);
// Bare chrome, no content AND no launch-error → born-stuck spinner. Reopen loop.
vi.spyOn(any as never, "pollRpartstoreState")
.mockResolvedValueOnce({ loaded: false, launchError: false, text: "RPartStore" } as never)
.mockResolvedValueOnce({ loaded: true, launchError: false, text: "Ne arıyorsunuz" } as never);
expect(await acquire(driver, true, FAR_DEADLINE())).toBe(true);
expect(close).toHaveBeenCalledTimes(1); // stuck instance closed (spinner path intact)
expect(reopen).toHaveBeenCalledTimes(1); // one fresh reopen, which loaded
});
it("launch-error OCR pattern matches the real Cyrillic and its live-captured eng-OCR transliterations", () => {
expect(VINPIN_OCR.rpartstoreLaunchError.test("Ошибка запуска каталога")).toBe(true);
// VERBATIM upscaled-crop OCR captured live 2026-07-15 (seat trvinpin47828): the
// "Ошибка" head varies (Owwu6ka/OwwbKa) but "3anycka"+"KaTanora" are stable.
expect(VINPIN_OCR.rpartstoreLaunchError.test("Rpartstore X Owwu6ka 3anycka KaTanora")).toBe(
true,
);
expect(VINPIN_OCR.rpartstoreLaunchError.test("Volvo (X) OwwbKa 3anycka KaTanora VY")).toBe(
true,
);
expect(VINPIN_OCR.rpartstoreLaunchError.test("Owwnbka 3anycka KaTanora")).toBe(true);
// Must NOT fire on a healthy loaded Rpartstore home (no false short-circuit) —
// this is the exact full-frame text a LOADED home shows.
expect(VINPIN_OCR.rpartstoreLaunchError.test("Şasi no ile arama Güncel araçlar")).toBe(false);
// Nor on the brand grid alone (the tiles behind the modal, read on a 1× frame).
expect(
VINPIN_OCR.rpartstoreLaunchError.test("Audi Fiat Renault KIA SEAT Volkswagen Toyota"),
).toBe(false);
});
it("launch error over the grid (ensureRpartstore couldn't confirm a window) → bail to Dialogys, NO reopens", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
// Cold path: ensureRpartstore returns false because the DOWN Rpartstore shows
// only the centered launch-error modal over the grid (no catalog chrome).
vi.spyOn(any as never, "ensureRpartstore").mockResolvedValue(false as never);
const reopen = vi.spyOn(any as never, "reopenFreshRpartstore");
const close = vi.spyOn(any as never, "closeRpartstoreTab");
// The upscaled modal crop DOES read the launch error → dismiss + bail.
vi.spyOn(any as never, "rpartstoreLaunchErrorPresent").mockResolvedValue(true as never);
const page = {
mouse: { click: vi.fn(async () => undefined) },
waitForTimeout: vi.fn(async () => undefined),
};
const result = await (
any.acquireLoadedRpartstore as (
p: unknown,
c: unknown,
d: number,
w: boolean,
) => Promise<boolean>
).call(driver, page, {}, FAR_DEADLINE(), false);
expect(result).toBe(false); // → straight to Dialogys
expect(reopen).not.toHaveBeenCalled(); // no reopens burned
expect(close).not.toHaveBeenCalled();
expect(page.mouse.click).toHaveBeenCalledWith(
VINPIN_COORDS.rpartstoreLaunchErrorOk.x,
VINPIN_COORDS.rpartstoreLaunchErrorOk.y,
);
});
it("warm Renault decode: loaded Rpartstore is PRIMARY — Dialogys is not touched on a hit", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
vi.spyOn(any as never, "acquireLoadedRpartstore").mockResolvedValue(true as never);
vi.spyOn(any as never, "runRpartstore").mockResolvedValue({
status: "found",
parsed: { brand: "RENAULT", model: "KADJAR", modelYear: null },
rawText: "RENAULT Kadjar",
via: "rpartstore",
} as never);
const dialogys = vi.spyOn(any as never, "ensureWarmWindow");
const page = { keyboard: { press: vi.fn(async () => undefined) } };
const result = await (
any.warmRenaultDecode as (p: unknown, v: string, c: unknown, d: number) => Promise<unknown>
).call(driver, page, "VF1RFE00653633190", { rpartstoreEnabled: true }, FAR_DEADLINE());
expect(result).toMatchObject({
brand: "RENAULT",
model: "KADJAR",
raw: { source: "vinpin-rpartstore" },
});
expect(dialogys).not.toHaveBeenCalled(); // Rpartstore hit → Dialogys never consulted
});
it("warm Renault decode: exhausted Rpartstore → LAST-RESORT Dialogys fallback still decodes", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
vi.spyOn(any as never, "acquireLoadedRpartstore").mockResolvedValue(false as never); // never loaded
const runRpartstore = vi.spyOn(any as never, "runRpartstore");
vi.spyOn(any as never, "ensureWarmWindow").mockResolvedValue(true as never);
vi.spyOn(any as never, "runDialogysSearch").mockResolvedValue({
status: "found",
parsed: { brand: "RENAULT", model: "MEGANE", modelYear: null },
rawText: "Megane II Classic",
via: "dialogys",
} as never);
const page = { keyboard: { press: vi.fn(async () => undefined) } };
const result = await (
any.warmRenaultDecode as (p: unknown, v: string, c: unknown, d: number) => Promise<unknown>
).call(driver, page, "VF1LM1B0A37829019", { rpartstoreEnabled: true }, FAR_DEADLINE());
expect(runRpartstore).not.toHaveBeenCalled(); // never ran the search on a stuck Rpartstore
expect(result).toMatchObject({
brand: "RENAULT",
model: "MEGANE",
raw: { source: "vinpin-dialogys" },
});
});
it("acquire give-up (budget-exhausted) DEFENSIVELY dismisses a leftover modal (Escape + launch-error OK) even when the OCR branch never fires", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
// Budget already spent → the inner acquire returns false at its first budget
// check WITHOUT ever hitting the OCR error-detect branch (raise/poll not called).
const raise = vi.spyOn(any as never, "raiseWarmWindow").mockResolvedValue(true as never);
const poll = vi.spyOn(any as never, "pollRpartstoreState");
const page = {
keyboard: { press: vi.fn(async () => undefined) },
mouse: { click: vi.fn(async () => undefined) },
waitForTimeout: vi.fn(async () => undefined),
};
const result = await (
any.acquireLoadedRpartstore as (
p: unknown,
c: unknown,
d: number,
w: boolean,
) => Promise<boolean>
).call(driver, page, {}, Date.now() - 1, true);
expect(result).toBe(false);
expect(raise).not.toHaveBeenCalled(); // budget already gone → never opened
expect(poll).not.toHaveBeenCalled();
// The wrapper's unconditional defensive clear ran on the false path: Escape +
// click the centered launch-error OK, so no modal is left to wedge the grid-return.
expect(page.keyboard.press).toHaveBeenCalledWith("Escape");
expect(page.mouse.click).toHaveBeenCalledWith(
VINPIN_COORDS.rpartstoreLaunchErrorOk.x,
VINPIN_COORDS.rpartstoreLaunchErrorOk.y,
);
});
it("grid-return dismisses a blocking modal BEFORE each tab-✕ close (can't wedge into a relogin thrash)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
const order: string[] = [];
// ocrRegion on a fake page fails-safe to "" (never the brand grid) → the loop runs.
const dismiss = vi.spyOn(any as never, "dismissBlockingModal").mockImplementation((async () => {
order.push("dismiss");
}) as never);
vi.spyOn(any as never, "ensureBrandGrid").mockResolvedValue(undefined as never);
const page = {
mouse: {
click: vi.fn(async () => {
order.push("click");
}),
},
keyboard: { press: vi.fn(async () => undefined) },
waitForTimeout: vi.fn(async () => undefined),
};
await (any.returnToBrandGrid as (p: unknown, c: unknown) => Promise<void>).call(
driver,
page,
{},
);
expect(dismiss).toHaveBeenCalled();
// The modal-clear precedes the tab-✕ click on the very first iteration.
expect(order[0]).toBe("dismiss");
expect(order[1]).toBe("click");
expect(page.mouse.click).toHaveBeenCalledWith(
VINPIN_COORDS.catalogTabClose.x,
VINPIN_COORDS.catalogTabClose.y,
);
});
it("caps the resumed-desktop escalation (closeStrayRunningApps, NOT logout+relogin) to ONE attempt per decode (no thrash)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
// Fresh decode → escalation budget starts unused.
any.reloginUsedThisDecode = false;
vi.spyOn(any as never, "submitVinPowerLogin").mockResolvedValue(false as never);
vi.spyOn(any as never, "dismissDisconnected").mockResolvedValue(undefined as never);
// logout+relogin is retired — it must not exist as a method any more.
expect(any.logoutAndRelogin).toBeUndefined();
// The escalation itself fails — the point is it's only TRIED once across two returns.
const escalate = vi
.spyOn(any as never, "closeStrayRunningApps")
.mockResolvedValue(false as never);
const page = {
waitForTimeout: vi.fn(async () => undefined),
keyboard: { press: vi.fn(async () => undefined) },
mouse: { click: vi.fn(async () => undefined) },
};
const ensureGrid = (p: unknown, c: unknown, allow?: boolean) =>
(any.ensureBrandGrid as (p: unknown, c: unknown, a?: boolean) => Promise<void>).call(
driver,
p,
c,
allow,
);
// Two grid-returns inside ONE decode (as returnToBrandGrid's loop would do). The
// 2nd must NOT re-escalate → no repeated recovery thrash.
await ensureGrid(page, {}, true);
await ensureGrid(page, {}, true);
expect(escalate).toHaveBeenCalledTimes(1); // one escalation only — the 2nd is capped
expect(any.reloginUsedThisDecode).toBe(true);
expect(any.sessionPoisoned).toBe(true); // capped path poisons for a clean cold restart
});
});
/**
* Warm-path Fiat fixes: the disambiguated foreground regex (Defect B) and the
* warmDecode Fiat branch that must never fail silently (Defect A) — genuine
* not-found → null, wrong/garbled window → cold fallback, no Fiat warm window →
* cold fallback.
*/
describe("VinpinDriverService — warm Fiat not-found / wrong-window hardening", () => {
const savedEnv = { ...process.env };
const VALID_FIAT_VIN = "NM435600006H43436"; // 17 alphanumerics → fiat warm window
const FAR_DEADLINE = () => Date.now() + 5 * 60_000;
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
process.env.VINPIN_USER = "user";
process.env.VINPIN_PASS = "pass";
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
function fakePage() {
return { isClosed: () => false, keyboard: { press: vi.fn(async () => undefined) } };
}
function callWarmDecode(driver: VinpinDriverService, vin: string, deadline: number) {
const any = driver as unknown as Record<string, unknown>;
return (any.warmDecode as (v: string, c: unknown, d: number) => Promise<unknown>).call(
driver,
vin,
{},
deadline,
);
}
it("FIX 1: VINPIN_WINDOW_FOREGROUND.fiat does NOT match a Dialogys 'ПОИСК' string but DOES match Fiat 'Dealer'/'ePER'/'TIPO-EGEA'", () => {
const fg = VINPIN_WINDOW_FOREGROUND.fiat;
// The shared-token bug: the Dialogys ПОИСК search button must NOT read as the
// Fiat foreground (this false-positive typed the VIN into Dialogys — Defect B).
expect(fg.test("ПОИСК Dialogys ИЗМЕНИТЬ")).toBe(false);
expect(fg.test("ПОИСК")).toBe(false);
// Fiat-window-only chrome + VIN-panel model tokens still match.
expect(fg.test("Fiat Dealer")).toBe(true);
expect(fg.test("ePER window")).toBe(true);
expect(fg.test("6J - TIPO - EGEA (2015-2021)")).toBe(true);
expect(fg.test("Spare Parts Catalogue")).toBe(true);
// Sanity: the Dialogys foreground regex STILL recognises ПОИСК (its own detection
// is unaffected — only the Fiat regex dropped the shared token).
expect(VINPIN_WINDOW_FOREGROUND.dialogys.test("ПОИСК Dialogys ИЗМЕНИТЬ")).toBe(true);
});
it("FIX 2: Fiat unusable-parse NOT-on-panel (wrong/garbled window) → falls back to decodeFiatLocked, not a silent null", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
any.warm = true;
any.page = fakePage();
any.warmWindows = { fiat: true }; // has a Fiat window → not the FIX-4 route
vi.spyOn(any as never, "assertSessionAlive").mockResolvedValue(undefined as never);
vi.spyOn(any as never, "ensureWarmWindow").mockResolvedValue(true as never);
vi.spyOn(any as never, "runVinFlow").mockResolvedValue(null as never); // no usable parse
// Frame shows the DIALOGYS window (Defect B), not the Fiat VIN panel.
vi.spyOn(any as never, "ocrFrame").mockResolvedValue("ПОИСК Dialogys ИЗМЕНИТЬ" as never);
const close = vi.spyOn(any as never, "close").mockResolvedValue(undefined as never);
const cold = vi
.spyOn(any as never, "decodeFiatLocked")
.mockResolvedValue({ brand: "Fiat", model: "TIPO" } as never);
const result = await callWarmDecode(driver, VALID_FIAT_VIN, FAR_DEADLINE());
expect(cold).toHaveBeenCalledTimes(1); // cold fallback, NOT a silent null
expect(result).toMatchObject({ brand: "Fiat", model: "TIPO" });
expect(any.warm).toBe(false); // warm dropped (untrusted Fiat window)
expect(close).toHaveBeenCalled();
});
it("FIX 2: Fiat genuine not-found (on the VIN panel + not-found string) → returns null, no cold fallback", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
any.warm = true;
any.page = fakePage();
any.warmWindows = { fiat: true };
vi.spyOn(any as never, "assertSessionAlive").mockResolvedValue(undefined as never);
vi.spyOn(any as never, "ensureWarmWindow").mockResolvedValue(true as never);
vi.spyOn(any as never, "runVinFlow").mockResolvedValue(null as never);
// Positively on the Fiat Spare-Parts catalogue AND a genuine "не найден" miss.
vi.spyOn(any as never, "ocrFrame").mockResolvedValue(
"Spare Parts Catalogue TIPO не найден" as never,
);
const cold = vi.spyOn(any as never, "decodeFiatLocked");
const result = await callWarmDecode(driver, VALID_FIAT_VIN, FAR_DEADLINE());
expect(result).toBeNull(); // a real miss is correctly null
expect(cold).not.toHaveBeenCalled(); // NOT re-driven cold
});
it("FIX 4: routes a Fiat VIN straight to the cold path when warmWindows.fiat is false (no Fiat warm window)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as Record<string, unknown>;
any.warm = true;
any.page = fakePage();
any.warmWindows = { fiat: false, dialogys: true }; // Renault-only partial warm
vi.spyOn(any as never, "assertSessionAlive").mockResolvedValue(undefined as never);
const ensure = vi.spyOn(any as never, "ensureWarmWindow");
const runVinFlow = vi.spyOn(any as never, "runVinFlow");
const close = vi.spyOn(any as never, "close").mockResolvedValue(undefined as never);
const cold = vi
.spyOn(any as never, "decodeFiatLocked")
.mockResolvedValue({ brand: "Fiat", model: "EGEA" } as never);
const result = await callWarmDecode(driver, VALID_FIAT_VIN, FAR_DEADLINE());
expect(cold).toHaveBeenCalledTimes(1); // straight to cold — never touched a warm window
expect(ensure).not.toHaveBeenCalled();
expect(runVinFlow).not.toHaveBeenCalled();
expect(result).toMatchObject({ brand: "Fiat", model: "EGEA" });
expect(any.warm).toBe(false);
expect(close).toHaveBeenCalled();
});
});

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,328 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
/**
* Clean-teardown + grid-return reliability tests for the Vinpin driver. These
* exercise the warm-establish fix: the clean-teardown routine (close resumed
* catalog windows via the corrected tab-✕, then log out of the RDS session before
* dropping the browser) and ensureBrandGrid's escalation to logout+relogin. OCR is
* mocked so the screen-state sequence is fully controllable — the real seat lives
* on prod and can't be driven from a test.
*/
vi.mock("./vinpin.ocr", () => ({
ocrRegion: vi.fn(async () => ""),
pollForText: vi.fn(async () => ({ matched: false, text: "" })),
terminateOcr: vi.fn(async () => undefined),
}));
import { VinpinDriverService } from "./vinpin-driver.service";
import { ocrRegion } from "./vinpin.ocr";
const mockOcr = vi.mocked(ocrRegion);
type AnyDriver = Record<string, unknown>;
function fakePage(sink: (x: number, y: number) => void) {
return {
isClosed: () => false,
frames: () => [] as unknown[],
mouse: { click: vi.fn(async (x: number, y: number) => sink(x, y)) },
keyboard: { press: vi.fn(async () => undefined) },
waitForTimeout: vi.fn(async () => undefined),
};
}
describe("VinpinDriverService — clean teardown", () => {
const savedEnv = { ...process.env };
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
process.env.VINPIN_USER = "user";
process.env.VINPIN_PASS = "pass";
process.env.VINPIN_WARM_DAEMON = "true";
mockOcr.mockReset();
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
it("teardownWarm closes each resumed catalog window (tab-✕) then logs out BEFORE closing the browser", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const events: string[] = [];
vi.spyOn(any as never, "close").mockImplementation((async () => {
events.push("close");
}) as never);
any.browser = { isConnected: () => true };
any.context = {};
any.warm = true;
any.page = fakePage((x, y) => {
if (x === 93 && y === 45) events.push("tabClose");
if (x === 1543 && y === 877) events.push("logout");
});
// Two catalog windows open, then a clear desktop.
mockOcr
.mockResolvedValueOnce("RPartStore")
.mockResolvedValueOnce("ePER Dealer")
.mockResolvedValue("");
await driver.teardownWarm();
// Both windows closed via the corrected tab-✕, then logout, then browser close.
expect(events).toEqual(["tabClose", "tabClose", "logout", "close"]);
expect(any.warm).toBe(false);
});
it("clean-teardown still logs out when no catalog window is open (bounded, no-op close loop)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const clicks: Array<[number, number]> = [];
any.browser = { isConnected: () => true };
any.context = {};
any.page = fakePage((x, y) => clicks.push([x, y]));
mockOcr.mockResolvedValue(""); // desktop already clear
await (any.cleanTeardown as () => Promise<void>).call(driver);
expect(clicks.filter(([x, y]) => x === 93 && y === 45)).toHaveLength(0); // nothing to close
expect(clicks).toContainEqual([1543, 877]); // still logs out to end the RDS session
});
it("logout dismisses any blocking modal FIRST, and recovers a Disconnected drop by closing it + relaunching VINPIN for a fresh grid", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const events: string[] = [];
any.browser = { isConnected: () => true };
any.context = {};
any.page = fakePage((x, y) => {
if (x === 868 && y === 530) events.push("dismissModal"); // rpartstoreLaunchErrorOk
if (x === 1543 && y === 877) events.push("logout"); // Çıkış yap
if (x === 953 && y === 505) events.push("disconnectedClose");
if (x === 40 && y === 256) events.push("relaunchVinpin"); // vinpinApp
});
// (1) close-loop: desktop already clear → break. (2) after logout: a Disconnected
// dialog surfaced (dirty channel drop). (3) closing it lands on the launcher.
mockOcr
.mockResolvedValueOnce("") // close-loop: nothing open
.mockResolvedValueOnce("You have been disconnected") // after Çıkış yap
.mockResolvedValueOnce("No Running Items Available"); // launcher after Close
await (any.cleanTeardown as () => Promise<void>).call(driver);
// Modal dismissed BEFORE logout; then the disconnect is closed and VINPIN relaunched.
expect(events).toEqual(["dismissModal", "logout", "disconnectedClose", "relaunchVinpin"]);
});
it("logout does NOT relaunch VINPIN when logout was a clean log-off (no Disconnected dialog)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const clicks: Array<[number, number]> = [];
any.browser = { isConnected: () => true };
any.context = {};
any.page = fakePage((x, y) => clicks.push([x, y]));
mockOcr.mockResolvedValue(""); // clear desktop, and no Disconnected dialog after logout
await (any.cleanTeardown as () => Promise<void>).call(driver);
expect(clicks).toContainEqual([1543, 877]); // logged out
expect(clicks).not.toContainEqual([953, 505]); // no disconnect to close
expect(clicks).not.toContainEqual([40, 256]); // VINPIN not relaunched
});
it("does NOT relaunch VINPIN when logout lands on the HTML-Access launcher (clean log-off, not a drop)", async () => {
// The clean-logout launcher OCRs its "HTML Access" branding, which the broad
// sessionDropped token matches — but the launcher tokens must veto the recovery
// so a clean log-off is never mistaken for a Disconnected drop (would spuriously
// relaunch VinPower and leave a dirty resumed session).
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const clicks: Array<[number, number]> = [];
any.browser = { isConnected: () => true };
any.context = {};
any.page = fakePage((x, y) => clicks.push([x, y]));
mockOcr
.mockResolvedValueOnce("") // close-loop: nothing open
.mockResolvedValueOnce("VMware Horizon HTML Access — No Running Items Available"); // clean launcher after logout
await (any.cleanTeardown as () => Promise<void>).call(driver);
expect(clicks).toContainEqual([1543, 877]); // logged out
expect(clicks).not.toContainEqual([953, 505]); // NOT treated as a disconnect
expect(clicks).not.toContainEqual([40, 256]); // VINPIN NOT relaunched
});
it("clean-teardown is a no-op when the browser/page is already gone", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
any.browser = null;
any.context = null;
any.page = null;
// Must not throw and must not touch OCR.
await expect((any.cleanTeardown as () => Promise<void>).call(driver)).resolves.toBeUndefined();
expect(mockOcr).not.toHaveBeenCalled();
});
});
/**
* A running-app row handle for the Horizon "Running" panel. `$` resolves the
* name element (textContent) and the per-app close ✕; clicking the ✕ removes the
* app from the shared running list (models a real window teardown).
*/
function fakeRunningApp(name: string, onClose: (n: string) => void) {
return {
$: async (sel: string) => {
if (/running-app-name|focused-app-name/.test(sel)) {
return { textContent: async () => name };
}
if (/icon-close-app-image/.test(sel)) {
return { click: async () => onClose(name) };
}
return null;
},
};
}
/**
* A fake page that also exposes the Horizon client-chrome DOM (`$`, `$$`,
* `page.click`) used by closeStrayRunningApps. `apps` is the mutable running list;
* closing a stray removes it. `closed` records the order strays were terminated.
*/
function fakeDomPage(apps: string[], sink?: (x: number, y: number) => void) {
const running = [...apps];
const closed: string[] = [];
const domClicks: string[] = [];
const page = {
isClosed: () => false,
frames: () => [] as unknown[],
mouse: { click: vi.fn(async (x: number, y: number) => sink?.(x, y)) },
keyboard: { press: vi.fn(async () => undefined) },
waitForTimeout: vi.fn(async () => undefined),
$: async (sel: string) =>
sel === "#sidebar-toggler" || sel === "#available-VINPIN" ? {} : null,
$$: async (sel: string) =>
sel === "ul.running-app"
? running.map((n) =>
fakeRunningApp(n, (name) => {
closed.push(name);
const idx = running.indexOf(name);
if (idx >= 0) running.splice(idx, 1);
}),
)
: [],
click: vi.fn(async (sel: string) => {
domClicks.push(sel);
}),
};
return { page, running, closed, domClicks };
}
describe("VinpinDriverService — ensureBrandGrid stray-app (Running-panel) recovery", () => {
const savedEnv = { ...process.env };
const cfg = { url: "https://vinpin.test", user: "user", pass: "pass" };
beforeEach(() => {
process.env.VINPIN_ENABLED = "true";
mockOcr.mockReset();
});
afterEach(() => {
vi.restoreAllMocks();
process.env = { ...savedEnv };
});
it("closeStrayRunningApps closes every non-VinPower app via the DOM ✕ and leaves only VinPower", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const { page, running, closed } = fakeDomPage([
"VinPower",
"Renault Rpartstore",
"Loading application...",
]);
// After the strays close + the sidebar collapses, the canvas is on the brand grid.
mockOcr.mockResolvedValue("Volkswagen SsangYong TecDoc");
const ok = await (
any.closeStrayRunningApps as (p: unknown, c: unknown) => Promise<boolean>
).call(driver, page, cfg);
expect(ok).toBe(true);
// Both non-VinPower apps terminated via their per-app ✕, in row order.
expect(closed).toEqual(["Renault Rpartstore", "Loading application..."]);
expect(running).toEqual(["VinPower"]); // VinPower kept
expect(any.sessionPoisoned).toBe(false); // reached a confirmed-clean grid
});
it("closeStrayRunningApps degrades gracefully (false, no throw) when the sidebar DOM is absent", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const page = fakePage(() => undefined); // no $ / $$ / page.click — canvas-only render
mockOcr.mockResolvedValue("");
await expect(
(any.closeStrayRunningApps as (p: unknown, c: unknown) => Promise<boolean>).call(
driver,
page,
cfg,
),
).resolves.toBe(false); // → caller falls back to the canvas tab-✕ / OCR path
});
it("ensureBrandGrid escalates via closeStrayRunningApps (NOT logout+relogin) + falls back to the tab-✕ (93,45), never the language-selector (1298,14)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const clicks: Array<[number, number]> = [];
const page = fakePage((x, y) => clicks.push([x, y]));
// Always a catalog window open → grid never reached → in-branch recovery + escalation.
mockOcr.mockResolvedValue("RPartStore catalog open");
// logout+relogin is retired — the method must not exist any more.
expect((any as Record<string, unknown>).logoutAndRelogin).toBeUndefined();
// DOM absent → the primary Running-panel recovery returns false → tab-✕ fallback.
const escalate = vi.spyOn(any as never, "closeStrayRunningApps");
await (any.ensureBrandGrid as (p: unknown, c: unknown, allow?: boolean) => Promise<void>).call(
driver,
page,
cfg,
true,
);
expect(escalate).toHaveBeenCalled(); // primary + escalation is the Running-panel recovery
expect(clicks).toContainEqual([93, 45]); // tab-✕ fallback still used
expect(clicks).not.toContainEqual([1298, 14]); // language-selector coord NEVER clicked
expect(any.sessionPoisoned).toBe(true); // recovery failed (DOM absent) → poison, no relogin
});
it("ensureBrandGrid clears the poison when closeStrayRunningApps reaches a clean grid", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const page = fakePage(() => undefined);
mockOcr.mockResolvedValue("RPartStore catalog open"); // never reaches grid by OCR
// The escalation succeeds (Running-panel recovery reached a fresh grid).
const escalate = vi
.spyOn(any as never, "closeStrayRunningApps")
.mockResolvedValue(true as never);
await (any.ensureBrandGrid as (p: unknown, c: unknown, allow?: boolean) => Promise<void>).call(
driver,
page,
cfg,
true,
);
expect(escalate).toHaveBeenCalled();
expect(any.sessionPoisoned).toBe(false); // recovery reached a confirmed-clean grid
});
it("with allowRelogin=false it does NOT run the end-of-loop escalation and poisons the seat (one-shot, no livelock)", async () => {
const driver = new VinpinDriverService();
const any = driver as unknown as AnyDriver;
const page = fakePage(() => undefined);
mockOcr.mockResolvedValue("RPartStore catalog open"); // never reaches grid
await (any.ensureBrandGrid as (p: unknown, c: unknown, allow?: boolean) => Promise<void>).call(
driver,
page,
cfg,
false,
);
expect(any.sessionPoisoned).toBe(true); // poisoned → next decode cold-restarts
});
});

View File

@@ -12,6 +12,8 @@
* coordinate if the brand-grid layout ever changes.
*/
import { getBrandFromWmi } from "@sase/shared";
/** Viewport the coordinates are calibrated for. */
export const VINPIN_VIEWPORT = { width: 1600, height: 900 } as const;
@@ -42,12 +44,106 @@ export const VINPIN_COORDS = {
vinSubmitArrow: { x: 1283, y: 189 },
/** "OK" button of the "vehicles not found" alert (genuine not-found result). */
notFoundOk: { x: 816, y: 448 },
// ─── Renault flow (Rpartstore primary + Dialogys fallback) ───
// Coordinates below are 1600x900 STARTING POINTS from the live benchmark on the
// permanent seat (trvinpin41080). They are OCR-verified+retried at runtime like
// the Fiat flow, so minor drift self-heals — but re-verify if layout changes.
// TUNE.
/** Window-close (X) button of an open catalog window. ⚠️ DO NOT USE on the
* HTML-Access desktop: this coord actually hits the LANGUAGE SELECTOR (it opens a
* dropdown that makes the brand grid unrecognizable and wedges the ensureBrandGrid
* thrash). It is NO LONGER clicked by ANY path — the browser-tab ✕ below is the
* only close action. Kept documented so the bad coordinate isn't re-introduced. */
windowClose: { x: 1298, y: 14 },
/** Browser-tab ✕ of an open catalog app — the PRIMARY window-close action. The
* tab sits just under the window title bar, e.g. "Renault Rpartstore ✕".
* Validated live: clicking (93,45) closed the catalog and returned to the clean
* brand grid (the old {135,45} missed the ✕). TUNE. */
catalogTabClose: { x: 93, y: 45 },
/** "Çıkış yap" logout button (bottom-right of the RDS/Horizon desktop). Ends the
* remote session so the NEXT warm-up starts from a fresh login/grid instead of
* resuming into the last-open dirty catalog desktop. Used by the clean-teardown
* routine. ⚠️ With a blocking modal up (e.g. the Rpartstore launch-error dialog)
* this becomes a channel DISCONNECT rather than a clean RDS log-off — so the
* teardown dismisses any modal BEFORE clicking it. TUNE. */
logoutButton: { x: 1543, y: 877 },
/** "Close" button of the Horizon "You have been disconnected" dialog. If "Çıkış
* yap" turned into a channel disconnect (dirty RDS resume), clicking this lands
* back on the HTML-Access launcher ("No Running Items") from which the VINPIN app
* is relaunched for a fresh VinPower grid. Verified @ 1600x900. TUNE. */
disconnectedClose: { x: 953, y: 505 },
/** Renault brand tile on the VinPower grid (opens the Rpartstore/Dialogys
* submenu). mousedown/up like the Fiat tile. TUNE. */
renaultBrand: { x: 450, y: 707 },
/** Rpartstore entry in the Renault submenu (PRIMARY catalog). TUNE. */
renaultRpartstore: { x: 584, y: 779 },
/** Dialogys entry in the Renault submenu (FALLBACK catalog). TUNE. */
renaultDialogys: { x: 584, y: 733 },
/** Both Renault catalogs pop a Russian-language dialog on open → its OK. TUNE. */
renaultLangOk: { x: 746, y: 454 },
/** Rpartstore "Şasi no ile arama" VIN field. Submit with Enter (NOT the yellow
* button — it moves). TUNE. */
rpartstoreVinField: { x: 735, y: 194 },
/** Rpartstore "RPartStore" home/logo (top-left) — resets to the search home
* between VINs (more reliable than close+reopen). TUNE. */
rpartstoreHome: { x: 110, y: 92 },
/** Rpartstore error-card close (✕) — dismisses the "Şasi seçilmedi" /
* "bulunamadı" overlay that otherwise covers the VIN field. TUNE. */
rpartstoreErrorClose: { x: 928, y: 167 },
/** Rpartstore yellow search button (fallback to Enter submit). TUNE. */
rpartstoreSearchBtn: { x: 975, y: 195 },
/** "OK" button of the Rpartstore hard launch-error modal ("Ошибка запуска
* каталога" / title "Renault Rpartstore") that fires when Rpartstore is DOWN
* server-side. Verified live @ 1600x900 (viewport frame) — dismisses the modal
* so the driver can fall straight back to Dialogys. TUNE. */
rpartstoreLaunchErrorOk: { x: 868, y: 530 },
/** Dialogys VIN field. TUNE. */
dialogysVinField: { x: 457, y: 258 },
/** Dialogys ПОИСК (search) button. TUNE. */
dialogysSearch: { x: 590, y: 382 },
/** Dialogys Home button (reset step 1). TUNE. */
dialogysHome: { x: 78, y: 102 },
/** Dialogys ИЗМЕНИТЬ А/М — change-vehicle (reset step 2). TUNE. */
dialogysChangeVehicle: { x: 1217, y: 160 },
} as const;
/** Screenshot clip (px) of the Renault Rpartstore/Dialogys vehicle-page HEADER
* region, fed to OCR. Rpartstore renders "RENAULT <model> (<code>)" /
* "DACIA <model>" + "Şasi: <VIN>" in x280–960,y182–258; Dialogys renders
* "<Model> (<platform>), <engine>" slightly higher. Captured a bit wider/taller
* than the benchmark box to tolerate drift. TUNE. */
export const VINPIN_RENAULT_HEADER_REGION = {
x: 260,
y: 150,
width: 720,
height: 140,
} as const;
/** Screenshot clip (px) of the decode-result modal body, fed to OCR. Captures
* the model line ("6J - TIPO - EGEA (2015-2021)"), SINCOM, trim, prod-date and
* the echoed VIN. Verified live. */
export const VINPIN_MODAL_REGION = { x: 250, y: 120, width: 820, height: 480 } as const;
* the echoed VIN. Verified live. Widened to ~900px for the warm-session daemon
* (some decode modals render wider on the permanent seat). */
export const VINPIN_MODAL_REGION = { x: 250, y: 120, width: 900, height: 500 } as const;
/** Screenshot clip (px) of the CENTERED Rpartstore hard launch-error modal
* ("Renault Rpartstore" / "Ошибка запуска каталога", OK ~868,530), fed to OCR
* UPSCALED (ocrRegion's default 3×). ⚠️ ROOT-CAUSE NOTE (verified live 2026-07-15
* on seat trvinpin47828): the modal is a small (~220×140px) centered Cyrillic
* dialog. OCR'ing the FULL 1600×900 frame at 1× (what the old load-poll did)
* CANNOT read it — tesseract returns the surrounding brand-grid tiles and drops
* the tiny modal text, so `rpartstoreLaunchError` never matched → the DOWN
* Rpartstore was misclassified as a "born-stuck spinner" and 3 reopens (~54s) were
* burned before Dialogys. Cropping to THIS region + 3× upscale makes the string
* legible ("Owwu6ka 3anycka KaTanora"), so the launch error is detected on the
* FIRST open and the flow bails straight to Dialogys. Sized generously around the
* screen-centered dialog to tolerate drift while excluding the right sidebar. */
export const VINPIN_RPARTSTORE_ERROR_REGION = {
x: 540,
y: 370,
width: 560,
height: 230,
} as const;
/** OCR keyword sets for state detection (case-insensitive). */
export const VINPIN_OCR = {
@@ -70,14 +166,236 @@ export const VINPIN_OCR = {
/** The decode modal actually carries a result (a model / prod-date / MVS). */
modalHit:
/MVS|найден|Prod\.?\s*date|TIPO|EGEA|DOBLO|PALIO|PANDA|PUNTO|LINEA|DUCATO|QUBO|FIORINO|ULYSSE/i,
/** Genuine "no vehicle found" outcome (the catalog has no record). */
/** Genuine "no vehicle found" outcome (the catalog has no record). Used against
* the cropped decode-modal region in runVinFlow, where the loose `Catalogue`
* token is a useful settle signal. */
notFound: /не\s*найден|not\s*found|Catalogue/i,
/** STRICT genuine not-found — requires an actual "не найден"/"not found" string,
* WITHOUT the loose `Catalogue` token. Use this against the FULL frame (where
* the "Spare Parts Catalogue" header is always present, so `notFound` would
* false-match), e.g. the warm-Fiat genuine-miss-vs-garble decision — so an
* on-panel transient garble falls through to the cold retry instead of null. */
notFoundStrict: /не\s*найден|not\s*found/i,
// ─── Renault flow OCR sets ───
/** A catalog app window (Rpartstore / Dialogys / Fiat ePER) is open OVER the
* brand grid — its chrome must be closed to fall back to the grid. Covers the
* Rpartstore/Dialogys titles + the ePER "Spare Parts" / "Son araca geri dön"
* navigation that only appear inside an open catalog. */
catalogWindowOpen:
/RPartStore|Rpartstore|Dialogys|Son\s*araca|Spare\s*Parts|Yedek\s*par|ePER|Üniversal\s*ürün/i,
/** Renault submenu is open (Rpartstore + Dialogys entries visible). */
renaultSubmenu: /Rpartstore|Rpart|Dialogys|Dialog/i,
/** Rpartstore app/window is open (home OR a vehicle page) — its chrome tokens
* ("RPartStore", "Güncel araçlar", "Ne arıyorsunuz", "Grup siparişi",
* "Şasi") appear only inside Rpartstore. */
rpartstoreOpen: /RPartStore|Rpartstore|Güncel\s*ara|Grup\s*sipariş|arıyor|Şasi|Sasi/i,
/** Rpartstore home/search page (the VIN search field is up). */
rpartstoreReady: /Güncel\s*ara|arıyor|Grup\s*sipariş|Şasi\s*no|Sasi\s*no|Ara\b/i,
/** Rpartstore search-home actually RENDERED its landing markers ("Şasi no ile
* arama" / "Ne arıyorsunuz" / "Güncel araçlar" / "Grup siparişi"). This is the
* spinner-guard signal: it distinguishes a LOADED home from the "born-stuck"
* infinite spinner, which shows only the window CHROME ("RPartStore" title —
* matched by rpartstoreOpen) with no search-home content. Kept strictly to
* content-only tokens so a spinning-but-titled window never false-passes. */
rpartstoreLoaded:
/Şasi\s*no\s*ile|Sasi\s*no\s*ile|Ne\s*arıyor|Ne\s*ariyor|Güncel\s*ara(ç|c)|Guncel\s*ara(ç|c)|Grup\s*sipariş|arıyorsunuz/i,
/** Rpartstore HARD launch-error modal — the Russian "Ошибка запуска каталога"
* (Catalog launch error) dialog that fires within ~8-10s of opening when
* Rpartstore is DOWN server-side (entitlement/backend failure). Reopening never
* helps, so detecting this must SHORT-CIRCUIT straight to Dialogys instead of
* burning the reopen budget. ⚠️ This must be read from an UPSCALED crop of
* `VINPIN_RPARTSTORE_ERROR_REGION` — on a full 1×frame the modal is illegible
* (see that region's note). The eng-OCR of the Cyrillic "Ошибка запуска
* каталога" transliterates to "Owwu6ka 3anycka KaTanora" / "OwwbKa 3anycka
* KaTanora" (captured verbatim live 2026-07-15). The `3anycka`+`KaTanora` tokens
* are the stable anchors; the "Ошибка" head transliterates variably
* (Owwu6ka/OwwbKa/Owwnbka) so all seen forms are listed. Its title alone
* ("Renault Rpartstore") false-matches rpartstoreOpen — this content string is
* what disambiguates the error. */
rpartstoreLaunchError: /запуска\s*катал|Ошибка\s*запуск|3anycka|KaTanora|Owwu6ka|OwwbKa|Owwnbka/i,
/** Rpartstore decoded a vehicle — header shows RENAULT/DACIA <model> + Şasi. */
rpartstoreHit: /RENAULT|DACIA|Şasi\s*:|Sasi\s*:/i,
/** Rpartstore genuine not-found — the error card ("İlişikli araç bulunamadı" /
* "Şasi ... bulunamadı" / "Şasi seçilmedi"). */
rpartstoreNotFound: /bulunamad|İlişikli|Ilisikli|araç\s*bulun|seçilmedi|secilmedi/i,
/** Dialogys form/vehicle page reached (Cyrillic UI, ПОИСК / ИЗМЕНИТЬ). */
dialogysReady: /ПОИСК|ПОИC|Dialogys|VIN|ИЗМЕНИТЬ/i,
// ─── Warm-session daemon OCR sets ───
/** The RDS/Horizon session is still ALIVE — the desktop status panel shows the
* host/seat identifiers ("HORIZON-RDST01"/"HORIZON-RDST02" / "trvinpin41080").
* The seat now LOAD-BALANCES across RDST01 and RDST02, so both host tags count.
* Their ABSENCE combined with a `sessionDropped` marker means the session dropped. */
sessionAlive: /HORIZON[- ]?RDST0[12]|RDST0[12]|trvinpin\d*/i,
/** The RDS/Horizon session DROPPED — a "Disconnected"/reconnect dialog or the
* "no free sessions" gate. Triggers a teardown + re-warm + single retry. */
sessionDropped:
/Disconnected|nofreesession|no\s*free\s*session|reconnect|Session\s*(has\s*)?(been\s*)?(disconnected|ended|expired|timed\s*out)|HTML\s*Access/i,
} as const;
/**
* Which taskbar button belongs to which catalog window. The warm daemon OCRs the
* bottom taskbar and matches these labels to bind brand→coordinate at runtime
* (the button ORDER depends on the open sequence, so we never hardcode the
* mapping — see `orderTaskbarWindows`). `grid` matches the VinPower brand-grid
* button used to open the next catalog without closing the current one.
*/
export const VINPIN_WINDOW_LABELS = {
fiat: /ePER|Dealer|Fiat/i,
rpartstore: /RPartStore|Rpart/i,
dialogys: /Dialogys|Dialog/i,
grid: /VinPower|VINPIN|Marka|Brand/i,
} as const;
export type VinpinWindowKey = keyof typeof VINPIN_WINDOW_LABELS;
/**
* OCR keyword that confirms a given catalog window is now in the FOREGROUND after
* a taskbar raise (reuses the existing state sets). Used to verify a raise landed
* on the right window before running a decode on it.
*/
export const VINPIN_WINDOW_FOREGROUND: Record<"fiat" | "rpartstore" | "dialogys", RegExp> = {
// ⚠️ Fiat-window-ONLY tokens. The old `Поиск` token was SHARED with the Dialogys
// "ПОИСК" search button (`/Поиск/i.test("ПОИСК") === true`), so in a partial-warm
// session where Dialogys ends up foreground the Fiat raise falsely reported success
// and the VIN was typed into Dialogys → silent garbage. `Dealer`/`ePER` are Fiat
// ePER chrome (never on Dialogys/Rpartstore); the rest are VIN-panel model tokens.
fiat: /Spare\s*Parts\s*Catalogue|GRANDE\s*PANDA|TIPO|EGEA|DOBLO|Dealer|ePER/i,
rpartstore: /RPartStore|Rpartstore|Güncel\s*ara|Grup\s*sipariş|Şasi|Sasi/i,
dialogys: /ПОИСК|ПОИC|Dialogys|ИЗМЕНИТЬ/i,
};
/**
* Horizon HTML-Access client-chrome DOM selectors (REAL DOM, outside the Blast
* canvas — hidden until the sidebar is opened). Used by the state-agnostic
* stray-app recovery (`closeStrayRunningApps`): the sidebar "Running" panel lists
* each RDS app with a per-app close ✕ that TERMINATES that specific app window
* regardless of its internal modal/spinner/loading state. Proven live to cleanly
* close both a Fiat "Fiat Dealer" window and a Renault Rpartstore launch-error
* resume, each returning to a pristine brand grid — the root fix for the
* dirty-resume failure the canvas tab-✕ (only hits a TABBED window's ✕) could not
* recover. Treated as GIVEN from the live probe; every use is guarded (try/catch +
* presence check) so a wrong/absent selector degrades to the canvas/OCR fallback
* rather than throwing. ⚠️ A Connection-Server logout+relogin is NOT a recovery
* here: the seat publishes apps-only (no desktop → no Start-menu Log Off), so the
* RDS session ends ONLY on server-side idle timeout — logout+relogin provably
* RESUMES the same dirty window. This DOM path is the recovery instead. */
export const VINPIN_DOM = {
/** Left-edge grip (~10,450) that reveals/collapses the Horizon sidebar. */
sidebarToggler: "#sidebar-toggler",
/** One <ul> per running RDS app in the sidebar "Running" panel. */
runningApp: "ul.running-app",
/** The app's display name inside a running-app row ("VinPower", "Fiat Dealer",
* "Renault Rpartstore", "Dialogys", "Loading application..."). */
runningAppName: "li.running-app-name, li.focused-app-name",
/** Per-app close ✕ inside a running-app row — terminates THAT app window. */
appCloseImage: "li.icon-close-app-image",
/** "Available → VINPIN" launch tile (relaunch VinPower if it was closed). */
availableVinpin: "#available-VINPIN",
/** App name to KEEP — every OTHER running app is a stray to terminate. */
vinPowerAppName: /VinPower/i,
/** Bounded passes over the Running panel (rows shift as apps close). */
maxClosePasses: 6,
} as const;
/** Bottom Horizon/RDS taskbar clip (px), fed to OCR to read the open windows'
* button labels left→right. TUNE against the permanent seat @ 1600x900. */
export const VINPIN_TASKBAR_REGION = { x: 0, y: 866, width: 1600, height: 34 } as const;
/** Candidate taskbar button CENTERS along the bottom bar, left→right. The daemon
* binds each open window to a slot by the OCR'd label order. Extra slots give
* headroom for drift; a raise is OCR-verified and re-tried on the next slot.
* TUNE against the permanent seat @ 1600x900. */
export const VINPIN_TASKBAR_SLOTS = [
{ x: 220, y: 884 },
{ x: 360, y: 884 },
{ x: 500, y: 884 },
{ x: 640, y: 884 },
{ x: 780, y: 884 },
] as const;
/** Global "VIN veya katalog ara" router box on the VinPower grid (~1455,96). Only
* used to OPEN a brand's window the first time (it routes, it does NOT decode and
* the VIN does not carry into the catalog). TUNE. */
export const VINPIN_ROUTER_BOX = { x: 1455, y: 96 } as const;
/** Warm-session daemon tunables. */
export const VINPIN_WARM = {
/** Business-hours window (Europe/Istanbul) the seat is held warm. */
businessStartHour: 8,
businessEndHour: 21,
/** Idle keepalive cadence — a `mouse.move` every ~75s held the RDS session
* 12.6 min with zero disconnect in the live proof. */
keepaliveIntervalMs: 75_000,
/** Harmless in-window point the keepalive nudges the cursor to. TUNE. */
keepalivePoint: { x: 800, y: 500 },
/** How often the scheduler reconciles warm-vs-hours. */
schedulerIntervalMs: 60_000,
/** Retries when verifying/re-trying a taskbar raise across slots. */
raiseVerifyRetries: 3,
/** After a taskbar-raise click, wait for the window to come forward. */
afterRaiseMs: 1_200,
/** Backoff after a FAILED warmUp: reconcile() and decode()'s warm-on-demand both
* skip re-warming until the cooldown elapses, so a failing seat is not hammered
* every ~60s (which leaves a fresh dirty window each attempt). Starts at the base
* and doubles per consecutive failure up to the max; a successful warm resets it. */
warmBackoffBaseMs: 60_000,
warmBackoffMaxMs: 300_000,
} as const;
/**
* Given the OCR'd taskbar text and the window labels, return the windows in the
* left→right order they appear in the bar. Pure + injectable so the brand→slot
* binding is unit-testable without a live seat. Windows whose label isn't found
* are omitted (the daemon then falls back to open-order for the missing ones).
*/
export function orderTaskbarWindows(
taskbarText: string,
keys: readonly ("fiat" | "rpartstore" | "dialogys")[] = ["fiat", "rpartstore", "dialogys"],
): ("fiat" | "rpartstore" | "dialogys")[] {
const found: { key: "fiat" | "rpartstore" | "dialogys"; idx: number }[] = [];
for (const key of keys) {
const label = VINPIN_WINDOW_LABELS[key];
const m = label.exec(taskbarText);
if (m) found.push({ key, idx: m.index });
}
return found.sort((a, b) => a.idx - b.idx).map((f) => f.key);
}
/**
* Pick which warm catalog WINDOW a VIN should be decoded on. Mirrors
* `selectVinpinBrandFlow`: Renault/Dacia → the Rpartstore window (Dialogys is the
* in-flow fallback), everything else (incl. Fiat) → the ePER window. Pure/testable.
*/
export function selectVinpinWarmWindow(vin: string): "fiat" | "rpartstore" {
return selectVinpinBrandFlow(vin) === "renault" ? "rpartstore" : "fiat";
}
/** Current hour (0–23) in Europe/Istanbul. Injectable clock for tests. */
export function vinpinIstanbulHour(now: Date = new Date()): number {
const hourStr = new Intl.DateTimeFormat("en-US", {
timeZone: "Europe/Istanbul",
hour: "numeric",
hour12: false,
}).format(now);
// Some runtimes emit "24" for midnight with hour12:false — normalise to 0–23.
return Number.parseInt(hourStr, 10) % 24;
}
/** Whether the seat should be held warm right now (08:00–21:00 Europe/Istanbul). */
export function isVinpinBusinessHours(now: Date = new Date()): boolean {
const h = vinpinIstanbulHour(now);
return h >= VINPIN_WARM.businessStartHour && h < VINPIN_WARM.businessEndHour;
}
/** Wait budgets (ms) for each step. Verified live @ 1600x900. */
export const VINPIN_WAITS = {
afterGoto: 7_000,
afterLogin: 20_000,
/** After submitting the web login: wait for the post-login screen (Horizon
* launcher or VinPower brand grid) to render. The real grid render measured
* ~32–46s on the permanent seat, so the old 20s always timed out (noise). */
afterLogin: 45_000,
/** After clicking the launcher's VINPIN app: wait for VinPower to connect and
* raise its login dialog (permanent seat only). */
afterVinpinLaunch: 14_000,
@@ -87,9 +405,91 @@ export const VINPIN_WAITS = {
afterLangDismiss: 2_500,
afterSearchOpen: 5_000,
afterVinSubmit: 7_000,
afterAlertDismiss: 700,
afterAlertDismiss: 250,
/** After toggling the Horizon sidebar open/closed (real DOM chrome reveal). */
afterSidebarToggle: 1_000,
/** Between per-app closes in the Horizon "Running" panel (window teardown settles). */
afterRunningAppClose: 2_000,
/** OCR poll cadence when waiting for a detectable end-state. Each poll is
* CAPPED at the corresponding fixed-wait budget above (kept as a fallback), so
* if OCR never catches the transition the total wait == the old fixed sleep and
* worst-case behaviour is unchanged. */
pollIntervalMs: 700,
// ─── Renault flow waits ───
/** After clicking the window-close (X) of an open catalog window. */
afterWindowClose: 3_500,
/** After clicking the Renault brand tile (submenu animates in). */
afterRenaultTile: 2_500,
/** After picking Rpartstore/Dialogys from the submenu (catalog window opens). */
afterRenaultCatalogOpen: 12_000,
/** After a Rpartstore (re)open — poll for the search-home landing markers to
* confirm it actually LOADED (vs the "born-stuck" infinite spinner). Short so
* a stuck instance is detected fast and reopened fresh within the budget. */
afterRpartstoreLoad: 12_000,
/** After submitting the Rpartstore VIN (Enter) — wait for the vehicle page. */
afterRpartstoreSubmit: 8_000,
/** After submitting the Dialogys VIN (ПОИСК) — wait for the vehicle page. */
afterDialogysSubmit: 8_000,
} as const;
/**
* Hard wall-clock budget (ms) for a SINGLE decode(vin) call, spanning all of its
* internal attempts. A single Vinpin seat is shared by every decode, so one VIN
* that gets stuck in a re-establish/relaunch livelock must never grind for
* minutes and starve real decodes. When the budget is exceeded the driver aborts,
* tears the browser down, poisons the seat (forcing the next decode to cold
* re-establish) and returns null. Kept well above the healthy p90 (a warm decode
* is seconds; a full cold re-establish is ~60-80s) so it only ever fires on a
* genuine stall. Bumped 150s→180s to leave a cheap safety margin for a slow cold
* establish stacking on the Rpartstore launch-error probe + the Dialogys fallback
* decode (~25s) — the Rpartstore launch-error short-circuit means we no longer
* waste ~54s of reopens, but the extra headroom covers a cold-establish edge.
* Override with VINPIN_DECODE_BUDGET_MS. */
export const VINPIN_DECODE_BUDGET_MS = 180_000;
/**
* Rpartstore acquire-with-spinner-guard tunables. A freshly-opened Rpartstore
* instance sometimes gets "born stuck" on an infinite spinner (survives
* raise/maximize); the only reliable fix is to CLOSE the stuck instance and
* reopen a FRESH one. `maxOpens` bounds the initial-open-plus-reopen attempts;
* `acquireBudgetMs` sub-caps the whole acquire loop so a hopeless Rpartstore
* still leaves wall-clock headroom (inside VINPIN_DECODE_BUDGET_MS) to fall back
* to Dialogys rather than burning the entire decode budget on reopens.
*/
export const VINPIN_RPARTSTORE = {
// Rpartstore has two failure modes: a genuine born-stuck spinner (reopen can
// recover it) and a hard server-side launch error "Ошибка запуска каталога"
// (reopen NEVER helps — Rpartstore is DOWN). Detecting the tiny centered error
// modal by OCR proved unreliable across renderings, and burning reopens on a
// DOWN Rpartstore (a) wastes ~54s and (b) dirties the RDS desktop so the
// Dialogys fallback then can't finish inside the budget.
// `maxOpens` still bounds reopen attempts (a real transient spinner can recover
// on a reopen), but `acquireBudgetMs` is the hard lever: one open+load-poll is
// ~22s, so a 14s wall-clock sub-cap makes the loop bail after the FIRST open if
// it hasn't loaded — straight to Dialogys on a still-clean seat (~25–52s decode)
// — instead of grinding 3 reopens. A healthy Rpartstore loads within the first
// open's poll and is used as before; the cap only prevents wasted reopens.
maxOpens: 3,
acquireBudgetMs: 14_000,
/** In-memory cooldown after a Rpartstore HARD launch-error (or repeated
* load-failure across all reopens): Rpartstore-down is server-side and
* PERSISTENT, so reopening it on every Renault VIN just re-dirties the RDS
* desktop (each failed open leaves a resumed window / launch-error modal). While
* the cooldown is active, Renault decodes route STRAIGHT to the proven ~30s
* Dialogys path (Rpartstore is never opened). A successful Rpartstore load clears
* it immediately, so a transient blip self-heals on the next decode. */
launchErrorCooldownMs: 10 * 60_000,
} as const;
/** Per-key delay (ms) when typing a VIN into a focused canvas field. A focused
* field keeps up at ~20ms; the old 45-50ms was conservative padding (17-char VIN
* ≈ 340ms vs ≈ 850ms). */
export const VINPIN_TYPE_DELAY_MS = 20;
/** Backspaces used to clear a VIN field after Ctrl+A + Delete. A few for
* insurance on a focused field — the old 40 was overkill. */
export const VINPIN_FIELD_CLEAR_BACKSPACES = 5;
/**
* Known Fiat model tokens used to extract the model name from the decode modal
* text. The modal interleaves Cyrillic boilerplate, a platform code, the model
@@ -125,11 +525,92 @@ export const FIAT_MODEL_TOKENS = [
] as const;
/**
* Brands for which the Vinpin fallback is enabled. Fiat-only for now (the
* Egea/NM4356 no-catalog cluster); a Set so it's trivially extensible later.
* Compared case-insensitively against the canonical browse brand.
* Known Renault/Dacia model tokens used to extract the model name from the
* Rpartstore/Dialogys vehicle-page header. Same token-matching strategy as the
* Fiat parser (far more robust than positional parsing against OCR noise).
* Generation numbers / roman numerals in the header are ignored — PL24 catalog
* rows carry their own generation suffixes and matching is best-effort.
*/
export const VINPIN_BRAND_ALLOWLIST = new Set<string>(["fiat"]);
export const RENAULT_MODEL_TOKENS = [
"CLIO",
"LUTECIA", // Clio's JP/TR export name — appears in PL24 rows ("CLIO 4 / LUTECIA 4")
"MEGANE",
"SCENIC",
"KANGOO",
"LAGUNA",
"LATITUDE",
"SAFRANE",
"FLUENCE",
"SYMBOL",
"THALIA",
"KADJAR",
"CAPTUR",
"DUSTER",
"SANDERO",
"LOGAN",
"TALISMAN",
"ESPACE",
"TWINGO",
"MODUS",
"KOLEOS",
"TRAFIC",
"MASTER",
"TALIANT",
"ARKANA",
"AUSTRAL",
"VELSATIS",
"TWIZY",
"ZOE",
"EXPRESS",
// Dacia
"DOKKER",
"LODGY",
"SPRING",
// Old R-number platforms + TR-market badges (pre-2000). These genuinely need
// Rpartstore to VIN-resolve, so this mostly future-proofs the header parse for
// an old Renault (e.g. VF1553… R19). The parser tokenises on non-alphanumerics,
// so a BARE "19" would collide with year/engine digits — the R-prefixed form
// ("R19") is required so it only matches the actual model badge, never a number.
"R5",
"R9",
"R11",
"R12",
"R19",
"R21",
"R25",
"EUROPA", // R19 Europa (TR)
"BROADWAY", // R9 Broadway (TR)
"TOROS", // R12 Toros (TR)
"FLASH", // R11 Flash (TR)
] as const;
/** WMIs that route to the Renault (Rpartstore/Dialogys) flow. VF1/VF2 are the
* common Renault WMIs; VF6/VF7 are included per the benchmark (some Renault/
* Dacia LCVs and older platforms). Dacia-badged cars often carry a Renault WMI
* (e.g. VF1 Duster) — the RENAULT-vs-DACIA distinction is read from the decode
* header, not the WMI. UU1 is the dedicated Dacia WMI. */
const RENAULT_FLOW_WMIS = new Set<string>(["VF1", "VF2", "VF6", "VF7", "UU1"]);
/**
* Pick the Vinpin catalog flow for a VIN by brand. Renault/Dacia → the new
* Rpartstore/Dialogys flow; everything else (including Fiat) → the existing ePER
* flow, so Fiat behaviour is byte-identical. Derived from the WMI: trusts
* `getBrandFromWmi` first (Renault/Dacia), then a Renault-WMI allowlist.
*/
export function selectVinpinBrandFlow(vin: string): "renault" | "fiat" {
const wmi = (vin || "").toUpperCase().slice(0, 3);
const brand = getBrandFromWmi(wmi);
if (brand === "Renault" || brand === "Dacia") return "renault";
if (RENAULT_FLOW_WMIS.has(wmi)) return "renault";
return "fiat";
}
/**
* Brands for which the Vinpin fallback is enabled. Fiat (Egea/NM4356 no-catalog
* cluster) + Renault/Dacia (Rpartstore/Dialogys flow). A Set so it's trivially
* extensible. Compared case-insensitively against the canonical browse brand.
*/
export const VINPIN_BRAND_ALLOWLIST = new Set<string>(["fiat", "renault", "dacia"]);
export function isVinpinBrandAllowed(brand: string | null | undefined): boolean {
if (!brand) return false;

View File

@@ -85,4 +85,103 @@ describe("pickBestCatalogMatch", () => {
// Identical tokens + no year → equal score → recency decides.
expect(pickBestCatalogMatch({ model: "PUNTO", modelYear: null }, puntos)).toBe("punto-new");
});
it("breaks a score tie toward the richer catalog (more categories)", () => {
const koleos: CatalogCandidate[] = [
{ id: "koleos-thin", model: "KOLEOS", year: null, categoryCount: 12 },
{ id: "koleos-full", model: "KOLEOS", year: null, categoryCount: 44 },
];
// Identical tokens + no year → equal score → category count decides.
expect(pickBestCatalogMatch({ model: "KOLEOS", modelYear: null }, koleos)).toBe("koleos-full");
});
});
describe("pickBestCatalogMatch — market-qualifier precision (Renault/Dacia)", () => {
it("prefers the EXACT model over a wrong-market superset (KADJAR beats KADJAR ÇİN)", () => {
// The confirmed prod bug: a European VF1 Renault decoded as "KADJAR" landed
// on the China-market "KADJAR ÇİN" catalog (fewer categories, wrong parts).
const candidates: CatalogCandidate[] = [
{ id: "kadjar-cn", model: "KADJAR ÇİN", year: null, categoryCount: 22 },
{ id: "kadjar-eu", model: "KADJAR", year: null, categoryCount: 44 },
];
expect(pickBestCatalogMatch({ model: "KADJAR", modelYear: "2018" }, candidates)).toBe(
"kadjar-eu",
);
});
it("still picks the exact model even when the market candidate is richer", () => {
// Market penalty must dominate — an exact match wins regardless of category
// count or ordering.
const candidates: CatalogCandidate[] = [
{ id: "kadjar-cn", model: "KADJAR ÇİN", year: null, categoryCount: 999 },
{ id: "kadjar-eu", model: "KADJAR", year: null, categoryCount: 1 },
];
expect(pickBestCatalogMatch({ model: "KADJAR", modelYear: null }, candidates)).toBe(
"kadjar-eu",
);
});
it("penalizes a market qualifier but NOT a generation token (CLIO)", () => {
const candidates: CatalogCandidate[] = [
{ id: "clio-cn", model: "CLIO ÇİN", year: null },
{ id: "clio", model: "CLIO", year: null },
];
// Exact "CLIO" beats the China-market superset.
expect(pickBestCatalogMatch({ model: "CLIO", modelYear: null }, candidates)).toBe("clio");
});
it("keeps generations matchable — a generation extra token is not a market penalty", () => {
// Decoded "CLIO" with only generation-qualified catalogs (no exact bare CLIO)
// and one China catalog. The generation candidate must win over the market one,
// proving the market penalty doesn't collateral-damage generations.
const candidates: CatalogCandidate[] = [
{ id: "clio-cn", model: "CLIO ÇİN", year: null },
{
id: "clio-4",
model: "CLIO 4 / LUTECIA 4 (2012-2019)",
year: "2012-2019",
categoryCount: 40,
},
{
id: "clio-3",
model: "CLIO 3 / LUTECIA 3 (2005-2014)",
year: "2005-2014",
categoryCount: 30,
},
];
const id = pickBestCatalogMatch({ model: "CLIO", modelYear: "2015" }, candidates);
// Year-overlap picks the 2012-2019 gen-4; the China catalog is penalized out.
expect(id).toBe("clio-4");
});
it("matches an exact generation model and penalizes only the market superset (DUSTER II)", () => {
// Roman-numeral generations survive tokenization (single digits are dropped by
// the length>=2 filter, an existing behavior). Decoded "DUSTER II" is exact on
// duster-2; "DUSTER II ÇİN" carries an extra market token and is penalized out.
const candidates: CatalogCandidate[] = [
{ id: "duster-2", model: "DUSTER II", year: null, categoryCount: 30 },
{ id: "duster-cn", model: "DUSTER II ÇİN", year: null, categoryCount: 30 },
];
expect(pickBestCatalogMatch({ model: "DUSTER II", modelYear: null }, candidates)).toBe(
"duster-2",
);
});
it("falls back to a market catalog only when it is the sole candidate", () => {
// If the ONLY catalog for a decoded model is a regional one, still match it —
// the penalty lowers the score but does not disqualify.
const candidates: CatalogCandidate[] = [{ id: "x62-cn", model: "X62 CHINE", year: null }];
expect(pickBestCatalogMatch({ model: "X62", modelYear: null }, candidates)).toBe("x62-cn");
});
});
describe("modelTokens — diacritic folding", () => {
it("folds Turkish diacritics so market qualifiers survive as ASCII tokens", () => {
// Without folding, ÇİN loses Ç/İ to the ASCII strip and collapses to a
// dropped 1-char "N", making KADJAR ÇİN tokenize identically to KADJAR.
expect(modelTokens("KADJAR ÇİN")).toEqual(["KADJAR", "CIN"]);
expect(modelTokens("ARKANA RUSYA")).toEqual(["ARKANA", "RUSYA"]);
// The single-digit "2" is dropped by the length>=2 filter (existing behavior).
expect(modelTokens("KOLEOS 2 - ÇİN")).toEqual(["KOLEOS", "CIN"]);
});
});

View File

@@ -18,11 +18,68 @@ export interface CatalogCandidate {
id: string;
model: string | null;
year: string | null;
/** How many catalog categories this vehicle has fetched. Used only as a final
* tiebreak among otherwise-equal candidates — the fuller catalog is the
* mainstream one. Optional so the pure picker can be unit-tested without it. */
categoryCount?: number | null;
}
/**
* Market/region qualifier tokens (diacritic-folded, upper-case). A catalog model
* that carries one of these tokens BEYOND the decoded model targets a specific
* regional market — e.g. "KADJAR ÇİN" is the China-market Kadjar catalog (source
* XZH, 22 categories) vs the mainstream European "KADJAR" (XFE, 44 categories).
* For a European (VF1…) VIN the regional catalog serves the wrong parts, so a
* candidate whose EXTRA tokens are region qualifiers is heavily penalized — but
* only when the token is extra (the decode itself doesn't carry a market today).
*
* Generation tokens (roman numerals, digits, platform codes like "II"/"3"/"XM3")
* are deliberately NOT here, so multi-generation models stay fully matchable;
* only MARKET qualifiers get the penalty.
*
* Grounded in prod data — the real Renault/Dacia catalog models that carry a
* region qualifier are: KADJAR ÇİN, CAPTUR II ÇİN, KOLEOS 2 - ÇİN, ARKANA RUSYA
* and X62 CHINE. ("EUROPE" appears too — ARKANA EUROPE, CAPTUR II EUROPE — but
* that is the mainstream market and is never penalized.)
*/
export const MARKET_QUALIFIERS = new Set<string>([
// China — "ÇİN" folds to CIN via diacritic normalization; CHINE is the French
// spelling seen in "X62 CHINE".
"CIN",
"CHINA",
"CHINE",
"CN",
// Russia
"RUSYA",
"RUSSIA",
"RU",
// Brazil
"BREZILYA",
"BRAZIL",
"BR",
// India
"HINDISTAN",
"INDIA",
"IN",
// Korea
"KORE",
"KOREA",
// Mexico / Mercosur
"MEKSIKA",
"MEXICO",
"MERCOSUR",
// Other regional
"GCC",
"USA",
"AMERIKA",
]);
export interface DecodedForMatch {
model: string | null;
modelYear: string | null;
/** Brand to match against (catalog_vehicles.brand_name). Defaults to Fiat when
* omitted, preserving the original Fiat-only behaviour. */
brand?: string | null;
}
/** Tokenize a model string into upper-case model tokens, dropping parenthetical
@@ -34,14 +91,23 @@ export interface DecodedForMatch {
* tiebreak over the modern Egea. */
export function modelTokens(s: string | null | undefined): string[] {
if (!s) return [];
return s
.toUpperCase()
.replace(/\([^)]*\)/g, " ") // drop parenthetical year ranges
.replace(/\b(19[5-9]\d|20[0-3]\d)\b/g, " ") // drop bare YEARS 1950-2039; keep displacements
.replace(/[^A-Z0-9]+/g, " ")
.split(" ")
.map((t) => t.trim())
.filter((t) => t.length >= 2);
return (
s
.toUpperCase()
// Fold diacritics to ASCII so market qualifiers survive tokenization. Without
// this the Turkish "ÇİN" (China) loses its Ç/İ to the [^A-Z0-9] strip below
// and collapses to a dropped 1-char "N" — making "KADJAR ÇİN" tokenize
// IDENTICALLY to "KADJAR" and defeating both the specificity tiebreak and the
// market penalty. NFD + combining-mark removal maps ÇİN→CIN, Ş→S, Ğ→G, Ö→O …
.normalize("NFD")
.replace(/\p{M}/gu, "") // strip the combining marks NFD split off
.replace(/\([^)]*\)/g, " ") // drop parenthetical year ranges
.replace(/\b(19[5-9]\d|20[0-3]\d)\b/g, " ") // drop bare YEARS 1950-2039; keep displacements
.replace(/[^A-Z0-9]+/g, " ")
.split(" ")
.map((t) => t.trim())
.filter((t) => t.length >= 2)
);
}
/** Parse a year range from free text. Returns {start, end} where end===null
@@ -74,8 +140,18 @@ function yearInRange(year: number, range: { start: number; end: number | null })
/**
* Pick the best catalog_vehicles row for a decoded model + year. A candidate
* qualifies only when EVERY decoded model token appears in the candidate's
* model tokens (subset match). Among qualifiers, prefer year-range overlap,
* then the most specific (fewest extra tokens). Returns the id or null.
* model tokens (subset match). Scoring, strongest signal first:
* 1. Year-range overlap — the strongest signal; routes multi-generation models
* (a 2022 "TIPO-EGEA" → the 2020+ MCA catalog, not the 2015-2021 one).
* 2. EXACT normalized model match (candidate tokens ≡ decoded tokens) — a
* smaller bonus that breaks the tie in favour of a plain "KADJAR" over the
* superset "KADJAR ÇİN" when no year distinguishes them.
* 3. Market-qualifier penalty — extra tokens that are region qualifiers (ÇİN,
* RUSYA, …) make this a WRONG-market catalog; penalized hard so it only ever
* wins as the sole candidate. Generation / other extra tokens keep only the
* mild "fewer extras = more specific" penalty, so generations stay matchable.
* 4. Tiebreaks on equal score: richer catalog (more categories), then newer.
* Returns the id or null.
*/
export function pickBestCatalogMatch(
decoded: DecodedForMatch,
@@ -85,7 +161,12 @@ export function pickBestCatalogMatch(
if (decTokens.length === 0) return null;
const decYear = decoded.modelYear ? Number.parseInt(decoded.modelYear, 10) : null;
let best: { id: string; score: number; startYear: number } | null = null;
let best: {
id: string;
score: number;
categoryCount: number;
startYear: number;
} | null = null;
for (const cand of candidates) {
const candText = `${cand.model ?? ""} ${cand.year ?? ""}`;
@@ -95,21 +176,47 @@ export function pickBestCatalogMatch(
// Subset requirement — all decoded model tokens must be present.
if (!decTokens.every((t) => candSet.has(t))) continue;
const extraTokens = candTokens.filter((t) => !decTokens.includes(t));
let score = 1000; // base for any qualifying candidate
// (1) EXACT normalized model-name match: candidate carries NO tokens beyond
// the decoded model. This breaks the tie in favour of the plain model over a
// superset (e.g. "KADJAR" over "KADJAR ÇİN" when neither has a distinguishing
// year). Kept SMALLER than the year-range swing (±700) on purpose, so a
// decisive model-year still routes generations correctly — a 2022 "TIPO-EGEA"
// must still land on the 2020+ MCA catalog, not the exact-named 2015-2021 one.
if (extraTokens.length === 0) score += 300;
// (2) Year-range overlap.
const range = parseYearRange(candText);
if (decYear && Number.isFinite(decYear) && range) {
score += yearInRange(decYear, range) ? 500 : -200;
}
// Tiebreak: fewer extra tokens = more specific match.
const extra = candTokens.filter((t) => !decTokens.includes(t)).length;
score -= extra;
// Final tiebreak on equal score: prefer the newer catalog. Without a year
// signal an ambiguous model (e.g. bare "TIPO") must never fall back onto an
// ancient generation — modern is the overwhelmingly likelier intent.
// (3) Extra-token penalties. A region-qualifier extra token means the
// candidate is a wrong-market catalog for a decode that carries no market —
// penalize hard so it can only win when it is the ONLY candidate. Everything
// else (generation numerals, platform codes) keeps the mild specificity
// penalty, leaving multi-generation models fully matchable.
const marketExtras = extraTokens.filter((t) => MARKET_QUALIFIERS.has(t)).length;
const otherExtras = extraTokens.length - marketExtras;
score -= otherExtras;
score -= marketExtras * 5000;
// (4) Tiebreaks on equal score: prefer the richer catalog (more categories —
// the fuller catalog is the mainstream one), then the newer generation. A
// bare, year-less model (e.g. "TIPO") must never fall back onto an ancient
// generation — modern is the overwhelmingly likelier intent.
const categoryCount = cand.categoryCount ?? 0;
const startYear = range?.start ?? 0;
if (!best || score > best.score || (score === best.score && startYear > best.startYear)) {
best = { id: cand.id, score, startYear };
const better =
!best ||
score > best.score ||
(score === best.score && categoryCount > best.categoryCount) ||
(score === best.score && categoryCount === best.categoryCount && startYear > best.startYear);
if (better) {
best = { id: cand.id, score, categoryCount, startYear };
}
}
@@ -123,25 +230,35 @@ export class VinpinCatalogMatcher {
constructor(@Inject(DATABASE) private readonly db: Database) {}
/**
* Find the best PL24 Fiat catalog_vehicle for a decoded model + year.
* Returns the catalog_vehicle id, or null when nothing matches.
* Find the best PL24 catalog_vehicle (of the decoded brand — Fiat by default,
* or Renault/Dacia) for a decoded model + year. Returns the id, or null.
*/
async match(decoded: DecodedForMatch): Promise<string | null> {
if (!decoded.model) return null;
const brand = (decoded.brand ?? "Fiat").toLowerCase();
const rows = await this.db
.select({
id: catalogVehicles.id,
model: catalogVehicles.model,
year: catalogVehicles.year,
// Category count feeds the richer-catalog tiebreak (more categories = the
// mainstream catalog). Correlated subquery keeps the row shape flat.
categoryCount: sql<number>`(
SELECT count(*)::int FROM categories
WHERE categories.catalog_vehicle_id = ${catalogVehicles.id}
)`,
})
.from(catalogVehicles)
.where(
and(sql`lower(${catalogVehicles.brandName}) = 'fiat'`, eq(catalogVehicles.source, "pl24")),
and(
sql`lower(${catalogVehicles.brandName}) = ${brand}`,
eq(catalogVehicles.source, "pl24"),
),
);
const id = pickBestCatalogMatch(decoded, rows as CatalogCandidate[]);
this.logger.log(
`match model="${decoded.model}" year=${decoded.modelYear ?? "?"} → ${id ?? "null"} (over ${rows.length} Fiat catalog vehicles)`,
`match brand=${brand} model="${decoded.model}" year=${decoded.modelYear ?? "?"} → ${id ?? "null"} (over ${rows.length} ${brand} catalog vehicles)`,
);
return id;
}

View File

@@ -0,0 +1,76 @@
import { describe, expect, it } from "vitest";
import { pollForText } from "./vinpin.ocr";
/** Deterministic fake clock: `sleep` advances virtual time; `now` reads it. */
function makeClock() {
let t = 0;
const slept: number[] = [];
return {
now: () => t,
sleep: async (ms: number) => {
slept.push(ms);
t += ms;
},
slept,
total: () => slept.reduce((a, b) => a + b, 0),
};
}
describe("pollForText", () => {
it("returns early as soon as the predicate matches (fast path)", async () => {
const clock = makeClock();
const reads = ["no", "no", "hit"];
let i = 0;
const res = await pollForText({
read: async () => reads[i++] ?? "",
predicate: (t) => t === "hit",
capMs: 10_000,
intervalMs: 700,
sleep: clock.sleep,
now: clock.now,
});
expect(res.matched).toBe(true);
expect(res.text).toBe("hit");
// Stopped at the 3rd read — well under the cap.
expect(i).toBe(3);
expect(clock.total()).toBe(2100);
expect(clock.total()).toBeLessThan(10_000);
});
it("caps total sleep at capMs when the predicate never matches (fallback == old fixed wait)", async () => {
const clock = makeClock();
let reads = 0;
const res = await pollForText({
read: async () => {
reads++;
return "no";
},
predicate: (t) => t === "hit",
capMs: 2_000,
intervalMs: 700,
sleep: clock.sleep,
now: clock.now,
});
expect(res.matched).toBe(false);
expect(res.text).toBe("no");
// Total sleep is exactly the cap — never longer than the old fixed wait.
expect(clock.total()).toBe(2_000);
// The final interval was clamped to the remaining budget (no overshoot).
expect(Math.max(...clock.slept)).toBeLessThanOrEqual(700);
expect(reads).toBeGreaterThan(0);
});
it("matches on the very first read without over-sleeping", async () => {
const clock = makeClock();
const res = await pollForText({
read: async () => "ready",
predicate: (t) => t.includes("ready"),
capMs: 12_000,
intervalMs: 750,
sleep: clock.sleep,
now: clock.now,
});
expect(res.matched).toBe(true);
expect(clock.total()).toBe(750); // one interval, then matched
});
});

View File

@@ -133,6 +133,43 @@ export async function ocrRegion(page: Page, clip?: OcrClip, scale = 3): Promise<
}
}
/**
* Poll a text `read` until `predicate(text)` holds, or the `capMs` budget is
* exhausted. Returns as soon as the predicate matches (the common, fast case);
* otherwise the total elapsed sleep equals `capMs` — the SAME fallback wait the
* old fixed `waitForTimeout(capMs)` used, so worst-case behaviour is unchanged.
*
* Pure/injectable (no Playwright/OCR deps) so it can be unit-tested directly:
* pass a fake `read`, `sleep` and `now`. The driver wraps it with an OCR read.
*/
export interface PollForTextOptions {
read: () => Promise<string>;
predicate: (text: string) => boolean;
/** Fallback cap — total sleep never exceeds this (== the old fixed wait). */
capMs: number;
/** Cadence between reads. */
intervalMs: number;
sleep: (ms: number) => Promise<void>;
/** Injectable clock (defaults to Date.now) — for deterministic tests. */
now?: () => number;
}
export async function pollForText(
opts: PollForTextOptions,
): Promise<{ matched: boolean; text: string }> {
const now = opts.now ?? (() => Date.now());
const interval = Math.max(1, opts.intervalMs);
const deadline = now() + opts.capMs;
let text = "";
while (now() < deadline) {
const remaining = deadline - now();
await opts.sleep(Math.min(interval, remaining));
text = await opts.read();
if (opts.predicate(text)) return { matched: true, text };
}
return { matched: false, text };
}
/** Tear down the shared tesseract worker (best-effort). */
export async function terminateOcr(): Promise<void> {
if (!workerPromise) return;

View File

@@ -1,5 +1,10 @@
import { describe, expect, it } from "vitest";
import { isUsableParse, parseVinpinModal } from "./vinpin.parser";
import {
isUsableParse,
isUsableRenaultParse,
parseRenaultHeader,
parseVinpinModal,
} from "./vinpin.parser";
const SAMPLE =
"MVS, найденные по vin NM435600006H43436 6J - TIPO - EGEA (2015-2021) 356G37001162 - 3V HIGH PLUS 1.6 120CV D5 CM E6 GS TR Двигатель: 8165300 Автомобиль: 279476 Prod. date: 2/8/2017 Vin: NM435600006H43436";
@@ -50,3 +55,56 @@ describe("parseVinpinModal", () => {
expect(isUsableParse(p)).toBe(false); // → not a real decode
});
});
describe("parseRenaultHeader", () => {
it("parses an Rpartstore RENAULT header (model + brand)", () => {
const p = parseRenaultHeader("RENAULT KADJAR (RFE) Şasi: VF1RFE00653633190");
expect(p.model).toBe("KADJAR");
expect(p.brand).toBe("RENAULT");
expect(isUsableRenaultParse(p)).toBe(true);
});
it("reads DACIA as the brand when the header carries it", () => {
const p = parseRenaultHeader("DACIA DUSTER (HSA) Şasi: VF1HJD40865644941");
expect(p.model).toBe("DUSTER");
expect(p.brand).toBe("DACIA");
});
it("extracts the base model and ignores the generation numeral (CLIO IV)", () => {
const p = parseRenaultHeader("RENAULT CLIO IV (R0G) Şasi: VF15R0G0H49335605");
expect(p.model).toBe("CLIO");
expect(p.brand).toBe("RENAULT");
});
it("handles a Dialogys header with no explicit brand (defaults RENAULT)", () => {
const p = parseRenaultHeader("Clio II (X65), 1.5 dCi");
expect(p.model).toBe("CLIO");
expect(p.brand).toBe("RENAULT");
});
it("captures a model year when the header carries one", () => {
const p = parseRenaultHeader("RENAULT LATITUDE (2011-2015)");
expect(p.model).toBe("LATITUDE");
expect(p.modelYear).toBe("2011");
});
it("does NOT mis-grab the status-bar license-expiry date as the model year", () => {
// The full-frame OCR fallback sweeps in the Rpartstore/Dialogys status bar,
// whose license EXPIRY date ("…14.07.2026") used to be read as the model year.
const p = parseRenaultHeader("RENAULT KADJAR (RFE) Şasi: VF1RFE00653633190 Lisans: 14.07.2026");
expect(p.model).toBe("KADJAR");
expect(p.modelYear).toBeNull(); // NOT "2026" from the expiry date
});
it("still prefers a genuine generation range even when an expiry date is present", () => {
const p = parseRenaultHeader("RENAULT LATITUDE (2011-2015) Lisans: 14.07.2026");
expect(p.modelYear).toBe("2011"); // the (2011-2015) range wins over the date
});
it("returns no model / unusable for headers without a known token", () => {
const p = parseRenaultHeader("İlişikli araç bulunamadı");
expect(p.model).toBeNull();
expect(isUsableRenaultParse(p)).toBe(false);
expect(isUsableRenaultParse(parseRenaultHeader(""))).toBe(false);
});
});

View File

@@ -13,7 +13,7 @@
* Kept dependency-free and side-effect-free so it can be unit-tested directly.
*/
import { FIAT_MODEL_TOKENS } from "./vinpin.constants";
import { FIAT_MODEL_TOKENS, RENAULT_MODEL_TOKENS } from "./vinpin.constants";
export interface VinpinParsed {
model: string | null;
@@ -106,3 +106,68 @@ export function parseVinpinModal(rawText: string | null | undefined): VinpinPars
export function isUsableParse(p: VinpinParsed): boolean {
return Boolean(p.sincom);
}
// ─── Renault (Rpartstore / Dialogys) header parser ───────────────
export interface VinpinRenaultParsed {
/** Extracted model, e.g. "KADJAR", "CLIO", "DUSTER". */
model: string | null;
/** "RENAULT" | "DACIA" — read from the header, else defaulted to "RENAULT". */
brand: "RENAULT" | "DACIA";
/** Model year if the header carried one (best-effort). */
modelYear: string | null;
}
const RENAULT_TOKEN_SET = new Set<string>(RENAULT_MODEL_TOKENS as readonly string[]);
/**
* Extract the Renault/Dacia model from an OCR'd vehicle-page header.
*
* Rpartstore header (primary): "RENAULT KADJAR (RFE)" / "DACIA DUSTER (...)" +
* "Şasi: VF1RFE00653633190".
* Dialogys header (fallback): "Clio II (X65), 1.5 dCi" (no explicit brand).
*
* Strategy (mirrors the Fiat token-run parser): collect the contiguous run of
* KNOWN Renault/Dacia model tokens (so "GRAND KOLEOS" → "KOLEOS", "CLIO II" →
* "CLIO"), and read the brand from a leading RENAULT/DACIA token (Dialogys omits
* it → default RENAULT). Generation numbers / roman numerals are intentionally
* dropped — PL24 rows carry their own generation suffixes and matching is
* best-effort.
*/
export function parseRenaultHeader(rawText: string | null | undefined): VinpinRenaultParsed {
const text = (rawText ?? "").replace(/\s+/g, " ").trim();
const upper = text.toUpperCase();
const brand: "RENAULT" | "DACIA" = /\bDACIA\b/.test(upper) ? "DACIA" : "RENAULT";
const tokens = upper.split(/[^A-Z0-9]+/).filter(Boolean);
const collected: string[] = [];
for (const tok of tokens) {
if (RENAULT_TOKEN_SET.has(tok)) {
collected.push(tok);
} else if (collected.length > 0) {
// Stop at the first non-model token after the model run has started.
break;
}
}
// De-dup consecutive repeats (e.g. "CLIO CLIO" OCR doubling) preserving order.
const deduped = collected.filter((t, i) => i === 0 || t !== collected[i - 1]);
const model = deduped.length > 0 ? deduped.join("-") : null;
// Model year: prefer an explicit generation range "(2015-2021)" from the header.
// A BARE year is only taken as a fallback AND only after stripping full calendar
// dates — the Rpartstore/Dialogys STATUS BAR carries the license EXPIRY date
// ("…14.07.2026") which the full-frame OCR fallback would otherwise mis-grab as
// the model year (the "2026" bug). Stripping dd.mm.yyyy / dd/mm/yyyy / dd-mm-yyyy
// first constrains the bare-year scan to real header text.
const withoutDates = text.replace(/\b\d{1,2}[./-]\d{1,2}[./-]\d{4}\b/g, " ");
const modelYear =
text.match(YEAR_RANGE_RE)?.[1] ?? withoutDates.match(/\b(19|20)\d{2}\b/)?.[0] ?? null;
return { model, brand, modelYear };
}
/** A Renault parse is usable once we have a model token. */
export function isUsableRenaultParse(p: VinpinRenaultParsed): boolean {
return Boolean(p.model);
}

View File

@@ -0,0 +1,94 @@
import { describe, expect, it } from "vitest";
import {
isVinpinBrandAllowed,
isVinpinBusinessHours,
orderTaskbarWindows,
selectVinpinBrandFlow,
selectVinpinWarmWindow,
} from "./vinpin.constants";
describe("selectVinpinBrandFlow", () => {
it("routes Renault WMIs (VF1/VF2) to the renault flow", () => {
expect(selectVinpinBrandFlow("VF1RFE00653633190")).toBe("renault"); // Kadjar
expect(selectVinpinBrandFlow("VF15R0G0H49335605")).toBe("renault"); // Clio IV
expect(selectVinpinBrandFlow("VF1LB030523661167")).toBe("renault"); // Clio II
expect(selectVinpinBrandFlow("VF2ABCDEFGH123456")).toBe("renault");
});
it("routes a Dacia-badged VF1 VIN to the renault flow (brand read from header)", () => {
expect(selectVinpinBrandFlow("VF1HJD40865644941")).toBe("renault"); // Dacia Duster
});
it("routes the dedicated Dacia WMI (UU1) to the renault flow", () => {
expect(selectVinpinBrandFlow("UU1ABCDEFGH123456")).toBe("renault");
});
it("keeps Fiat VINs on the fiat flow (byte-identical behaviour)", () => {
expect(selectVinpinBrandFlow("NM435600006H43436")).toBe("fiat"); // Tofaş Egea
expect(selectVinpinBrandFlow("ZFA31200000000000")).toBe("fiat");
});
it("defaults unknown/other WMIs to the fiat flow", () => {
expect(selectVinpinBrandFlow("WVWZZZ1JZ3W597935")).toBe("fiat"); // VW
expect(selectVinpinBrandFlow("")).toBe("fiat");
});
});
describe("isVinpinBrandAllowed", () => {
it("allows Fiat, Renault and Dacia (case-insensitive)", () => {
expect(isVinpinBrandAllowed("Fiat")).toBe(true);
expect(isVinpinBrandAllowed("renault")).toBe(true);
expect(isVinpinBrandAllowed("DACIA")).toBe(true);
expect(isVinpinBrandAllowed(" Renault ")).toBe(true);
});
it("rejects other brands and empty input", () => {
expect(isVinpinBrandAllowed("Peugeot")).toBe(false);
expect(isVinpinBrandAllowed(null)).toBe(false);
expect(isVinpinBrandAllowed(undefined)).toBe(false);
});
});
describe("selectVinpinWarmWindow — brand → taskbar window routing", () => {
it("routes Renault/Dacia VINs to the Rpartstore window (Dialogys is the in-flow fallback)", () => {
expect(selectVinpinWarmWindow("VF1RFE00653633190")).toBe("rpartstore"); // Renault Kadjar
expect(selectVinpinWarmWindow("UU1ABCDEFGH123456")).toBe("rpartstore"); // Dacia
});
it("routes Fiat (and everything else) to the ePER window", () => {
expect(selectVinpinWarmWindow("NM435600006H43436")).toBe("fiat"); // Tofaş Egea
expect(selectVinpinWarmWindow("WVWZZZ1JZ3W597935")).toBe("fiat"); // VW → fiat default
});
});
describe("orderTaskbarWindows — OCR-order taskbar binding", () => {
it("returns the windows in their left→right OCR order", () => {
const bar = "VinPower Fiat Dealer ePER Renault RPartStore Renault Dialogys";
expect(orderTaskbarWindows(bar)).toEqual(["fiat", "rpartstore", "dialogys"]);
});
it("respects a different open order (order is read, not hardcoded)", () => {
const bar = "Dialogys | RPartStore | ePER";
expect(orderTaskbarWindows(bar)).toEqual(["dialogys", "rpartstore", "fiat"]);
});
it("omits windows whose label isn't on the bar", () => {
const bar = "some noise ePER more noise RPartStore";
expect(orderTaskbarWindows(bar)).toEqual(["fiat", "rpartstore"]);
expect(orderTaskbarWindows("nothing recognizable")).toEqual([]);
});
});
describe("isVinpinBusinessHours — 08:00–21:00 Europe/Istanbul (UTC+3, no DST)", () => {
it("is true from 08:00 up to (not including) 21:00 local", () => {
expect(isVinpinBusinessHours(new Date("2026-07-14T05:00:00Z"))).toBe(true); // 08:00
expect(isVinpinBusinessHours(new Date("2026-07-14T12:00:00Z"))).toBe(true); // 15:00
expect(isVinpinBusinessHours(new Date("2026-07-14T17:59:00Z"))).toBe(true); // 20:59
});
it("is false before 08:00 and at/after 21:00 local", () => {
expect(isVinpinBusinessHours(new Date("2026-07-14T04:59:00Z"))).toBe(false); // 07:59
expect(isVinpinBusinessHours(new Date("2026-07-14T18:00:00Z"))).toBe(false); // 21:00
expect(isVinpinBusinessHours(new Date("2026-07-14T22:00:00Z"))).toBe(false); // 01:00
});
});

View File

@@ -122,3 +122,53 @@ export class BillingController {
}
}
}
/**
* User-scoped billing admin: start a fresh subscription for a user whose
* previous one is expired/cancelled (the panel's "Yeni abonelik başlat").
*/
@Controller("internal/admin/users")
@Public()
@UseGuards(InternalTokenGuard)
export class UserBillingController {
constructor(private billing: BillingService) {}
@Post(":id/subscriptions")
@HttpCode(HttpStatus.OK)
async startSubscription(
@Param("id") id: string,
@Body()
body: {
planId?: string;
billingPeriod?: string;
days?: number;
brandIds?: string[];
reason?: string;
founderId?: string;
},
) {
if (!body.founderId) throw new BadRequestException("founderId required");
if (!body.reason || body.reason.trim().length < 5) {
throw new BadRequestException("start-subscription requires reason (min 5 chars)");
}
if (!body.planId) throw new BadRequestException("planId required");
if (body.billingPeriod !== "monthly" && body.billingPeriod !== "yearly") {
throw new BadRequestException("billingPeriod must be monthly|yearly");
}
if (body.days !== undefined && (typeof body.days !== "number" || body.days <= 0)) {
throw new BadRequestException("days must be a positive number");
}
if (body.brandIds !== undefined && !Array.isArray(body.brandIds)) {
throw new BadRequestException("brandIds must be an array");
}
return this.billing.startSubscription({
userId: id,
planId: body.planId,
billingPeriod: body.billingPeriod,
days: body.days,
brandIds: body.brandIds,
reason: body.reason,
founderId: body.founderId,
});
}
}

View File

@@ -0,0 +1,181 @@
import { BadRequestException, ConflictException, NotFoundException } from "@nestjs/common";
import { describe, expect, it, vi } from "vitest";
import { BillingService } from "./billing.service";
/**
* Drizzle-shaped mock: every `db.select()` pops the next row-set from `selects`
* (order = order of queries in the service), `db.insert()` returns
* `insertRows` from `.returning()` and records `.values()` payloads.
*/
function createMockDb(selects: unknown[][], insertRows: unknown[] = []) {
const queue = [...selects];
const inserted: unknown[] = [];
function chain(terminal: unknown, onValues?: (v: unknown) => void) {
const c: Record<string, unknown> = {};
for (const m of [
"select",
"from",
"where",
"limit",
"insert",
"values",
"returning",
"update",
"set",
]) {
c[m] = vi.fn().mockReturnValue(c);
}
c.values = vi.fn().mockImplementation((v: unknown) => {
onValues?.(v);
return c;
});
// `await db.select()...where(...)` (no limit) resolves via thenable.
// biome-ignore lint/suspicious/noThenProperty: mimics Drizzle's thenable query builder
c.then = (res: (v: unknown) => unknown, rej?: (e: unknown) => unknown) =>
Promise.resolve(terminal).then(res, rej);
c.limit = vi.fn().mockReturnValue(Promise.resolve(terminal));
c.returning = vi.fn().mockReturnValue(Promise.resolve(terminal));
return c;
}
return {
inserted,
select: vi.fn().mockImplementation(() => chain(queue.shift() ?? [])),
insert: vi.fn().mockImplementation(() => chain(insertRows, (v) => inserted.push(v))),
update: vi.fn().mockImplementation(() => chain([])),
};
}
const USER = { id: "user-1" };
const FULL = { id: "plan-full", name: "Full Paket", brandCount: 0, isActive: true };
const ONE = { id: "plan-1", name: "1 Marka", brandCount: 1, isActive: true };
const BRANDS = [{ id: "b1" }, { id: "b2" }, { id: "b3" }];
const base = { userId: "user-1", reason: "manuel tanım", founderId: "founder-1" } as const;
function svc(db: unknown) {
return new BillingService(db as any, {} as any);
}
describe("BillingService.startSubscription", () => {
it("creates an active Full-plan subscription with every active brand and the given days", async () => {
const created = {
id: "sub-new",
startDate: new Date("2026-09-19T00:00:00Z"),
endDate: new Date("2029-09-19T00:00:00Z"),
};
const db = createMockDb([[USER], [], [FULL], BRANDS], [created]);
const res = await svc(db).startSubscription({
...base,
planId: FULL.id,
billingPeriod: "yearly",
days: 1095,
});
expect(res.success).toBe(true);
expect(res.subscriptionId).toBe("sub-new");
expect(res.brandCount).toBe(3);
// 1st insert = subscription row, 2nd = brand rows
expect(db.inserted).toHaveLength(2);
const subRow = db.inserted[0] as {
status: string;
billingPeriod: string;
startDate: Date;
endDate: Date;
};
expect(subRow.status).toBe("active");
expect(subRow.billingPeriod).toBe("yearly");
const diffDays = Math.round(
(subRow.endDate.getTime() - subRow.startDate.getTime()) / 86_400_000,
);
expect(diffDays).toBe(1095);
expect(db.inserted[1]).toEqual(
BRANDS.map((b) => ({ userId: "user-1", subscriptionId: "sub-new", brandId: b.id })),
);
});
it("defaults the period from billingPeriod when days is omitted", async () => {
const db = createMockDb([[USER], [], [FULL], BRANDS], [{ id: "sub-new" }]);
await svc(db).startSubscription({ ...base, planId: FULL.id, billingPeriod: "monthly" });
const subRow = db.inserted[0] as { startDate: Date; endDate: Date };
const expected = new Date(subRow.startDate);
expected.setMonth(expected.getMonth() + 1);
expect(subRow.endDate.getTime()).toBe(expected.getTime());
});
it("uses the requested brands for a brand-limited plan", async () => {
const db = createMockDb([[USER], [], [ONE], BRANDS], [{ id: "sub-new" }]);
const res = await svc(db).startSubscription({
...base,
planId: ONE.id,
billingPeriod: "monthly",
brandIds: ["b2"],
});
expect(res.brandCount).toBe(1);
expect(db.inserted[1]).toEqual([
{ userId: "user-1", subscriptionId: "sub-new", brandId: "b2" },
]);
});
it("rejects wrong brand count / unknown brands for a brand-limited plan", async () => {
await expect(
svc(createMockDb([[USER], [], [ONE], BRANDS])).startSubscription({
...base,
planId: ONE.id,
billingPeriod: "monthly",
brandIds: [],
}),
).rejects.toBeInstanceOf(BadRequestException);
await expect(
svc(createMockDb([[USER], [], [ONE], BRANDS])).startSubscription({
...base,
planId: ONE.id,
billingPeriod: "monthly",
brandIds: ["nope"],
}),
).rejects.toBeInstanceOf(BadRequestException);
});
it("refuses when the user already has an active or trial subscription", async () => {
const db = createMockDb([[USER], [{ id: "sub-live", status: "trial" }]]);
await expect(
svc(db).startSubscription({ ...base, planId: FULL.id, billingPeriod: "yearly" }),
).rejects.toBeInstanceOf(ConflictException);
expect(db.insert).not.toHaveBeenCalled();
});
it("404s on unknown user / plan and rejects inactive plans", async () => {
await expect(
svc(createMockDb([[]])).startSubscription({
...base,
planId: FULL.id,
billingPeriod: "yearly",
}),
).rejects.toBeInstanceOf(NotFoundException);
await expect(
svc(createMockDb([[USER], [], []])).startSubscription({
...base,
planId: "missing",
billingPeriod: "yearly",
}),
).rejects.toBeInstanceOf(NotFoundException);
await expect(
svc(createMockDb([[USER], [], [{ ...FULL, isActive: false }]])).startSubscription({
...base,
planId: FULL.id,
billingPeriod: "yearly",
}),
).rejects.toBeInstanceOf(ConflictException);
});
it("validates days range and billingPeriod before touching the db", async () => {
const db = createMockDb([]);
await expect(
svc(db).startSubscription({ ...base, planId: FULL.id, billingPeriod: "yearly", days: 0 }),
).rejects.toBeInstanceOf(BadRequestException);
await expect(
svc(db).startSubscription({ ...base, planId: FULL.id, billingPeriod: "yearly", days: 3651 }),
).rejects.toBeInstanceOf(BadRequestException);
await expect(
svc(db).startSubscription({ ...base, planId: FULL.id, billingPeriod: "weekly" as any }),
).rejects.toBeInstanceOf(BadRequestException);
expect(db.select).not.toHaveBeenCalled();
});
});

View File

@@ -6,9 +6,9 @@ import {
Logger,
NotFoundException,
} from "@nestjs/common";
import { eq } from "drizzle-orm";
import { and, eq, inArray } from "drizzle-orm";
import { DATABASE, type Database } from "../database/database.provider";
import { brands, plans, userBrands, userSubscriptions } from "../database/schema/core";
import { brands, plans, userBrands, userSubscriptions, users } from "../database/schema/core";
import { SubscriptionsService } from "../subscriptions/subscriptions.service";
@Injectable()
@@ -74,6 +74,133 @@ export class BillingService {
};
}
/**
* Start a brand-new ACTIVE subscription for a user whose previous one is
* expired/cancelled (or who has none). Mirrors what activateSubscription does
* for a paid checkout — status/dates/plan-based brand assignment — but does
* NOT emit revenue events (PostHog subscription_activated / Meta Purchase) or
* consume referral credit: this is a founder grant, no money moved here.
* `days` overrides the default period (monthly → +1 ay, yearly → +1 yıl).
*/
async startSubscription(input: {
userId: string;
planId: string;
billingPeriod: "monthly" | "yearly";
days?: number;
brandIds?: string[];
reason: string;
founderId: string;
}) {
if (input.billingPeriod !== "monthly" && input.billingPeriod !== "yearly") {
throw new BadRequestException("billingPeriod must be monthly|yearly");
}
if (input.days !== undefined) {
if (!Number.isFinite(input.days) || input.days <= 0 || input.days > 3650) {
throw new BadRequestException("days must be 1..3650");
}
}
const [user] = await this.db
.select({ id: users.id })
.from(users)
.where(eq(users.id, input.userId))
.limit(1);
if (!user) throw new NotFoundException("Kullanıcı bulunamadı");
const [live] = await this.db
.select({ id: userSubscriptions.id, status: userSubscriptions.status })
.from(userSubscriptions)
.where(
and(
eq(userSubscriptions.userId, input.userId),
inArray(userSubscriptions.status, ["active", "trial"]),
),
)
.limit(1);
if (live) {
throw new ConflictException(
`Kullanıcının zaten '${live.status}' bir subscription'ı var (${live.id}) — activate / plan değiştir / uzat kullanın`,
);
}
const [plan] = await this.db.select().from(plans).where(eq(plans.id, input.planId)).limit(1);
if (!plan) throw new NotFoundException("Plan bulunamadı");
if (!plan.isActive) throw new ConflictException("Plan aktif değil");
const activeBrands = await this.db.select().from(brands).where(eq(brands.isActive, true));
let brandIds: string[];
if (plan.brandCount === 0) {
// Full plan → every active brand, whatever the caller sent.
brandIds = activeBrands.map((b) => b.id);
} else {
const requested = input.brandIds ?? [];
if (requested.length !== plan.brandCount) {
throw new BadRequestException(
`Bu plan tam olarak ${plan.brandCount} marka gerektirir, ${requested.length} seçildi`,
);
}
if (new Set(requested).size !== requested.length) {
throw new BadRequestException("Marka listesi tekrar içeriyor");
}
const valid = new Set(activeBrands.map((b) => b.id));
for (const id of requested) {
if (!valid.has(id)) throw new BadRequestException(`Geçersiz veya pasif marka: ${id}`);
}
brandIds = requested;
}
const now = new Date();
const endDate = new Date(now);
if (input.days !== undefined) {
endDate.setDate(endDate.getDate() + input.days);
} else if (input.billingPeriod === "yearly") {
endDate.setFullYear(endDate.getFullYear() + 1);
} else {
endDate.setMonth(endDate.getMonth() + 1);
}
const [created] = await this.db
.insert(userSubscriptions)
.values({
userId: input.userId,
planId: input.planId,
status: "active",
billingPeriod: input.billingPeriod,
startDate: now,
endDate,
})
.returning();
if (brandIds.length > 0) {
await this.db.insert(userBrands).values(
brandIds.map((brandId) => ({
userId: input.userId,
subscriptionId: created.id,
brandId,
})),
);
}
this.logger.log(
`start: user=${input.userId} subscription=${created.id} plan=${plan.name} ` +
`${input.billingPeriod}${input.days !== undefined ? ` ${input.days}d` : ""} → ${endDate.toISOString()} ` +
`brands=${brandIds.length} founder=${input.founderId} reason="${input.reason.slice(0, 80)}"`,
);
return {
success: true,
subscriptionId: created.id,
userId: input.userId,
planId: plan.id,
planName: plan.name,
billingPeriod: input.billingPeriod,
status: "active",
startDate: created.startDate?.toISOString() ?? null,
endDate: created.endDate?.toISOString() ?? null,
brandCount: brandIds.length,
};
}
async manuallyActivate(input: {
subscriptionId: string;
reason: string;

View File

@@ -3,7 +3,7 @@ import { StripeModule } from "../payments/stripe/stripe.module";
import { PublicApiQuotaService } from "../public-api/public-api-quota.service";
import { SubscriptionsModule } from "../subscriptions/subscriptions.module";
import { ApiKeysAdminController } from "./api-keys.controller";
import { BillingController } from "./billing.controller";
import { BillingController, UserBillingController } from "./billing.controller";
import { BillingService } from "./billing.service";
import { ImpersonationController } from "./impersonation.controller";
import { ImpersonationService } from "./impersonation.service";
@@ -20,6 +20,7 @@ import { InternalVehiclesService } from "./vehicles.service";
ImpersonationController,
LifecycleController,
BillingController,
UserBillingController,
PaymentsAdminController,
InternalVehiclesController,
],

View File

@@ -36,5 +36,6 @@ export const QUEUE_NAMES = {
EXPERT_REWARDS: "expert-rewards",
PART_PRICE_REFRESH: "part-price-refresh",
VINPIN_DECODE: "vinpin-decode",
RPARTSTORE_DECODE: "rpartstore-decode",
CANONICAL_BACKFILL: "canonical-backfill",
} as const;

View File

@@ -21,6 +21,10 @@ import {
PartPriceRefreshQueueProvider,
} from "./queues/part-price-refresh.queue";
import { QUERY_CLEANUP_QUEUE, QueryCleanupQueueProvider } from "./queues/query-cleanup.queue";
import {
RPARTSTORE_DECODE_QUEUE,
RpartstoreDecodeQueueProvider,
} from "./queues/rpartstore-decode.queue";
import {
SUBSCRIPTION_EXPIRY_QUEUE,
SubscriptionExpiryQueueProvider,
@@ -39,6 +43,7 @@ import { VINPIN_DECODE_QUEUE, VinpinDecodeQueueProvider } from "./queues/vinpin-
ExpertRewardsQueueProvider,
PartPriceRefreshQueueProvider,
VinpinDecodeQueueProvider,
RpartstoreDecodeQueueProvider,
CanonicalBackfillQueueProvider,
PrefetchWorkerService,
],
@@ -52,6 +57,7 @@ import { VINPIN_DECODE_QUEUE, VinpinDecodeQueueProvider } from "./queues/vinpin-
EXPERT_REWARDS_QUEUE,
PART_PRICE_REFRESH_QUEUE,
VINPIN_DECODE_QUEUE,
RPARTSTORE_DECODE_QUEUE,
CANONICAL_BACKFILL_QUEUE,
],
})

View File

@@ -74,14 +74,21 @@ export async function checkCooldown(redis: RedisService, source: string): Promis
}
}
/** Current hour (0–23) in Europe/Istanbul. */
function currentIstanbulHour(): number {
/** Europe/Istanbul hour (0–23) at an arbitrary instant. */
function istanbulHourAt(ms: number): number {
const hourStr = new Intl.DateTimeFormat("en-US", {
timeZone: "Europe/Istanbul",
hour: "numeric",
hour12: false,
}).format(new Date());
return Number.parseInt(hourStr, 10);
}).format(new Date(ms));
// `% 24` because the h24 hour cycle renders midnight as "24", which would put
// the hour outside every window and silently park the source forever.
return Number.parseInt(hourStr, 10) % 24;
}
/** Current hour (0–23) in Europe/Istanbul. */
function currentIstanbulHour(): number {
return istanbulHourAt(Date.now());
}
/**
@@ -115,6 +122,35 @@ export function checkTimeWindow(source: string): void {
}
}
/**
* The first instant at or after `fromMs` that falls inside `source`'s scrape
* window. Returns `fromMs` unchanged when the window is disabled (the default
* 0–24) or when `fromMs` is already inside it.
*
* WHY (plv2.md, finding consumers_jobs-03 — the budget/window deadlock):
* `checkSourceDailyBudget` defers a spent source to the next UTC midnight. With
* PREFETCH_PL24_START=9 that midnight lands at 03:00 Europe/Istanbul — six hours
* BEFORE the window opens. The woken job therefore did no work, threw
* `time-window`, and was deferred again to 09:00 — by which point the fresh
* daily budget had already been spent by the same stampede of no-op wake-ups.
* Measured on prod 2026-09-20: 600/600 pl24 budget consumed, 0 catalog requests
* and 0 new categories for the whole day. Landing the deferral inside the window
* breaks the cycle.
*/
export function alignToWindow(source: string, fromMs: number): number {
if (source !== "pl24") return fromMs;
if (PL24_WINDOW_START <= 0 && PL24_WINDOW_END >= 24) return fromMs;
let t = fromMs;
// Step by the hour rather than constructing a local-midnight date: DST-safe and
// free of month/year rollover edge cases. 48 steps covers any window shape.
for (let i = 0; i < 48; i++) {
const h = istanbulHourAt(t);
if (h >= PL24_WINDOW_START && h < PL24_WINDOW_END) return t;
t += 3_600_000;
}
return t;
}
/**
* Milliseconds until the next 09:00 Europe/Istanbul.
*/

View File

@@ -0,0 +1,286 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
/**
* Regression lock for the PL24 budget/window DEADLOCK (plv2.md, consumers_jobs-03).
*
* Two bugs combined to kill PL24 prefetch outright on prod:
* 1. `checkSourceDailyBudget` was debited in `process()` while the
* business-hours gate still sat at the top of each handler — so a job that
* woke outside the window paid a budget unit to do nothing.
* 2. A spent source was deferred to the next UTC midnight, which is 03:00
* Europe/Istanbul — six hours BEFORE a 09:00 window opens. Every deferred
* job therefore woke early, burned a unit of the fresh daily budget, hit
* the window gate and was deferred again.
*
* Measured on prod 2026-09-20 before the fix: `prefetch:daily:pl24` at 600/600
* with ZERO catalog requests and ZERO new pl24 categories for the whole day.
*
* The window constants are read at module load, so every case imports the
* modules fresh with the env already set.
*/
const REAL_ENV = { ...process.env };
/** 2026-09-20 00:00 UTC = 03:00 Europe/Istanbul — outside a 09:00–18:00 window. */
const OUTSIDE_MS = Date.UTC(2026, 8, 20, 0, 0, 0);
/** 2026-09-20 09:00 UTC = 12:00 Europe/Istanbul — inside it. */
const INSIDE_MS = Date.UTC(2026, 8, 20, 9, 0, 0);
function istanbulHour(ms: number): number {
return (
Number.parseInt(
new Intl.DateTimeFormat("en-US", {
timeZone: "Europe/Istanbul",
hour: "numeric",
hour12: false,
}).format(new Date(ms)),
10,
) % 24
);
}
async function loadModules(env: Record<string, string | undefined>) {
vi.resetModules();
for (const [k, v] of Object.entries(env)) {
if (v === undefined) delete process.env[k];
else process.env[k] = v;
}
const utils = await import("./prefetch-utils");
const worker = await import("./prefetch-worker.service");
return { utils, worker };
}
/** Minimal deps: only what `process()` touches before dispatching a job. */
function makeDeps(redisOverrides: Record<string, unknown> = {}) {
const incrCalls: string[] = [];
const redis = {
exists: vi.fn(async (..._a: unknown[]) => false),
get: vi.fn(async (..._a: unknown[]): Promise<string | null> => null),
set: vi.fn(async (..._a: unknown[]) => undefined),
del: vi.fn(async (..._a: unknown[]) => undefined),
incr: vi.fn(async (k: string) => {
incrCalls.push(k);
return 1;
}),
expire: vi.fn(async (..._a: unknown[]) => undefined),
ttl: vi.fn(async (..._a: unknown[]) => -2), // no cooldown key
setNx: vi.fn(async (..._a: unknown[]) => true),
getJson: vi.fn(async (..._a: unknown[]): Promise<unknown> => null),
setJson: vi.fn(async (..._a: unknown[]) => undefined),
...redisOverrides,
};
const queue = {
name: "catalog-prefetch",
add: vi.fn(async (..._a: unknown[]) => undefined),
getJob: vi.fn(async (..._a: unknown[]): Promise<unknown> => null),
};
const categoriesService = {
getCategoryWithParts: vi.fn(async (..._a: unknown[]) => ({ parts: [] })),
getChildren: vi.fn(async (..._a: unknown[]) => []),
};
return { redis, queue, categoriesService, incrCalls };
}
function makeJob(name: string, data: Record<string, unknown>) {
return {
name,
data,
moveToDelayed: vi.fn(async (..._a: unknown[]) => undefined),
attemptsMade: 0,
};
}
const dailyIncrs = (keys: string[]) => keys.filter((k) => k.startsWith("prefetch:daily:pl24"));
describe("alignToWindow", () => {
afterEach(() => {
process.env = { ...REAL_ENV };
});
it("pushes a pre-window instant into the configured window", async () => {
const { utils } = await loadModules({ PREFETCH_PL24_START: "9", PREFETCH_PL24_END: "18" });
const aligned = utils.alignToWindow("pl24", OUTSIDE_MS);
expect(aligned).toBeGreaterThan(OUTSIDE_MS);
const h = istanbulHour(aligned);
expect(h).toBeGreaterThanOrEqual(9);
expect(h).toBeLessThan(18);
});
it("leaves an in-window instant untouched", async () => {
const { utils } = await loadModules({ PREFETCH_PL24_START: "9", PREFETCH_PL24_END: "18" });
expect(utils.alignToWindow("pl24", INSIDE_MS)).toBe(INSIDE_MS);
});
it("is a no-op for sources that have no window", async () => {
const { utils } = await loadModules({ PREFETCH_PL24_START: "9", PREFETCH_PL24_END: "18" });
expect(utils.alignToWindow("emex", OUTSIDE_MS)).toBe(OUTSIDE_MS);
expect(utils.alignToWindow("parts-catalogs", OUTSIDE_MS)).toBe(OUTSIDE_MS);
});
it("is a no-op when the window is disabled (the default 0–24)", async () => {
const { utils } = await loadModules({
PREFETCH_PL24_START: undefined,
PREFETCH_PL24_END: undefined,
});
expect(utils.alignToWindow("pl24", OUTSIDE_MS)).toBe(OUTSIDE_MS);
});
});
describe("process() gate order — window before daily budget", () => {
beforeEach(() => {
vi.useFakeTimers();
});
afterEach(() => {
vi.useRealTimers();
process.env = { ...REAL_ENV };
});
it("does NOT debit the daily budget for a job deferred by the window", async () => {
const { worker } = await loadModules({
PREFETCH_PL24_START: "9",
PREFETCH_PL24_END: "18",
PL24_TR_DISABLED: undefined,
});
vi.setSystemTime(OUTSIDE_MS);
const { redis, queue, categoriesService, incrCalls } = makeDeps();
const svc = new worker.PrefetchWorkerService(
queue as never,
queue as never,
categoriesService as never,
redis as never,
{ payload: vi.fn(async () => ({})) } as never,
{} as never,
);
const job = makeJob("prefetch-parts", {
vehicleId: "v1",
categoryId: "c1",
source: "pl24",
fast: true,
});
await expect(
(svc as never as { process: (j: unknown, t?: string) => Promise<void> }).process(job, "tok"),
).rejects.toThrow();
expect(job.moveToDelayed).toHaveBeenCalled();
expect(dailyIncrs(incrCalls)).toHaveLength(0);
// The per-minute counter is not charged either: the window gate is pure
// clock arithmetic and runs before any Redis write.
expect(incrCalls).toHaveLength(0);
// …and the handler never ran, so nothing was fetched upstream either.
expect(categoriesService.getCategoryWithParts).not.toHaveBeenCalled();
});
it("defers the window-blocked job to an instant inside the window", async () => {
const { worker } = await loadModules({
PREFETCH_PL24_START: "9",
PREFETCH_PL24_END: "18",
PL24_TR_DISABLED: undefined,
});
vi.setSystemTime(OUTSIDE_MS);
const { redis, queue, categoriesService } = makeDeps();
const svc = new worker.PrefetchWorkerService(
queue as never,
queue as never,
categoriesService as never,
redis as never,
{ payload: vi.fn(async () => ({})) } as never,
{} as never,
);
const job = makeJob("prefetch-parts", {
vehicleId: "v1",
categoryId: "c1",
source: "pl24",
fast: true,
});
await expect(
(svc as never as { process: (j: unknown, t?: string) => Promise<void> }).process(job, "tok"),
).rejects.toThrow();
const [when] = job.moveToDelayed.mock.calls[0] as [number];
const h = istanbulHour(when);
expect(h).toBeGreaterThanOrEqual(9);
expect(h).toBeLessThan(18);
});
it("debits the daily budget once the window is open", async () => {
const { worker } = await loadModules({
PREFETCH_PL24_START: "9",
PREFETCH_PL24_END: "18",
PL24_TR_DISABLED: undefined,
});
vi.setSystemTime(INSIDE_MS);
const { redis, queue, categoriesService, incrCalls } = makeDeps();
const svc = new worker.PrefetchWorkerService(
queue as never,
queue as never,
categoriesService as never,
redis as never,
{ payload: vi.fn(async () => ({})) } as never,
{} as never,
);
const job = makeJob("prefetch-parts", {
vehicleId: "v1",
categoryId: "c1",
source: "pl24",
fast: true,
});
await (svc as never as { process: (j: unknown, t?: string) => Promise<void> }).process(
job,
"tok",
);
expect(dailyIncrs(incrCalls)).toHaveLength(1);
expect(categoriesService.getCategoryWithParts).toHaveBeenCalledWith("c1");
});
});
describe("checkSourceDailyBudget — spent source retries inside the window", () => {
beforeEach(() => {
vi.useFakeTimers();
});
afterEach(() => {
vi.useRealTimers();
process.env = { ...REAL_ENV };
});
it("never parks a spent source at 03:00 Istanbul again", async () => {
const { worker } = await loadModules({
PREFETCH_PL24_START: "9",
PREFETCH_PL24_END: "18",
PREFETCH_DAILY_PL24: "600",
});
vi.setSystemTime(INSIDE_MS);
// Counter already at the fast-lane ceiling → the next job must be deferred.
const { redis, queue, categoriesService } = makeDeps({
get: vi.fn(async (k: string) => (String(k).startsWith("prefetch:daily:pl24") ? "600" : null)),
});
const svc = new worker.PrefetchWorkerService(
queue as never,
queue as never,
categoriesService as never,
redis as never,
{ payload: vi.fn(async () => ({})) } as never,
{} as never,
);
const job = makeJob("prefetch-parts", {
vehicleId: "v1",
categoryId: "c1",
source: "pl24",
fast: true,
});
await expect(
(svc as never as { process: (j: unknown, t?: string) => Promise<void> }).process(job, "tok"),
).rejects.toThrow();
const [when] = job.moveToDelayed.mock.calls[0] as [number];
// Past the UTC rollover…
expect(when).toBeGreaterThan(Date.UTC(2026, 8, 21, 0, 0, 0));
// …and inside the window, not at 03:00 Istanbul like the old deferral.
const h = istanbulHour(when);
expect(h).toBeGreaterThanOrEqual(9);
expect(h).toBeLessThan(18);
});
});

View File

@@ -17,17 +17,30 @@ function makeDb(limitResults: unknown[][]) {
}
function makeDeps(opts: { waiting: number; limitResults: unknown[][] }) {
const queue = {
// A queue double: getJob returns null (nothing deduped) and the ioredis client
// stub answers the delayed-ZSET zcount the pressure gate takes.
const makeQueue = (name: string, waiting: number) => ({
name,
// typed args so `.mock.calls[i]` is `unknown[]` (not a 0-length tuple) — the
// production `nest build` compiles spec files and rejects tuple-index access.
add: vi.fn((..._args: unknown[]) => Promise.resolve(undefined)),
getJobCounts: vi.fn(async () => ({ waiting: opts.waiting, delayed: 0, active: 0 })),
};
getJob: vi.fn(async (..._args: unknown[]): Promise<unknown> => null),
getJobCounts: vi.fn(async (..._args: unknown[]) => ({
waiting,
delayed: 0,
active: 0,
prioritized: 0,
})),
toKey: (t: string) => `bull:${name}:${t}`,
client: Promise.resolve({ zcount: vi.fn(async (..._args: unknown[]) => 0) }),
});
const queue = makeQueue("catalog-prefetch", opts.waiting);
const redis = {
// typed args (like queue.add) so mockImplementation((k)=>…) type-checks under
// the production nest build, which compiles spec files.
exists: vi.fn(async (..._args: unknown[]) => false), // no cooldown / guard / complete marker
get: vi.fn(async () => null), // no no-result residue
// null → no no-result residue AND daily budget counters read as 0 (unspent).
get: vi.fn(async (..._args: unknown[]): Promise<string | null> => null),
set: vi.fn(async (..._args: unknown[]) => undefined),
del: vi.fn(async (..._args: unknown[]) => undefined),
incr: vi.fn(async (..._args: unknown[]) => 1), // per-source rate window counter
@@ -39,7 +52,7 @@ function makeDeps(opts: { waiting: number; limitResults: unknown[][] }) {
};
const posthog = { payload: vi.fn(async () => ({})) }; // compiled-in defaults
const db = makeDb(opts.limitResults);
const fastQueue = { add: vi.fn(async (..._args: unknown[]) => ({ id: "fastjob" })) };
const fastQueue = makeQueue("catalog-prefetch-fast", 0);
const service = new PrefetchWorkerService(
queue as never,
fastQueue as never,
@@ -212,7 +225,18 @@ describe("PrefetchWorkerService — fast lane (lifo) + backlog gating", () => {
});
describe("checkSourceRate — per-source rate limit", () => {
type CSR = { checkSourceRate: (s: string) => Promise<void> };
type CSR = { checkSourceRate: (s: string, lane?: "main" | "fast") => Promise<void> };
// pl24's MAIN lane is parked whenever background backfill is off, which is
// the default — so these ceiling tests turn it on explicitly to exercise the
// rate limiter itself rather than the backfill gate (covered separately).
beforeEach(() => {
process.env.PL24_BACKFILL_ENABLED = "true";
process.env.PL24_TR_DISABLED = undefined;
});
afterEach(() => {
process.env.PL24_BACKFILL_ENABLED = undefined;
});
it("passes when under the source ceiling", async () => {
const { service, redis } = makeDeps({ waiting: 0, limitResults: [] });
@@ -228,6 +252,24 @@ describe("PrefetchWorkerService — fast lane (lifo) + backlog gating", () => {
});
});
it("pl24 MAIN lane parkta iken hiç sayaç harcamaz (varsayılan)", async () => {
process.env.PL24_BACKFILL_ENABLED = undefined;
const { service, redis } = makeDeps({ waiting: 0, limitResults: [] });
await expect((service as never as CSR).checkSourceRate("pl24", "main")).rejects.toMatchObject(
{ cause: "source-rate" },
);
expect(redis.incr).not.toHaveBeenCalled();
});
it("kullanıcı (fast) şeridi backfill anahtarından etkilenmez", async () => {
process.env.PL24_BACKFILL_ENABLED = undefined;
const { service, redis } = makeDeps({ waiting: 0, limitResults: [] });
redis.incr.mockResolvedValueOnce(1);
await expect(
(service as never as CSR).checkSourceRate("pl24", "fast"),
).resolves.toBeUndefined();
});
it("is unlimited (no counter) for a source without a configured ceiling", async () => {
const { service, redis } = makeDeps({ waiting: 0, limitResults: [] });
await (service as never as CSR).checkSourceRate("unknown-source");
@@ -238,11 +280,10 @@ describe("PrefetchWorkerService — fast lane (lifo) + backlog gating", () => {
describe("poison guard (Faz 6: category cap — brand-agnostic anti-explosion)", () => {
type PC = { processChildren: (j: unknown) => Promise<void> };
it("processChildren marks poison once progress.total exceeds CATEGORY_CAP", async () => {
const { service, queue, redis } = makeDeps({ waiting: 0, limitResults: [] });
redis.getJson.mockImplementation(async (...a: unknown[]) =>
String(a[0]).includes("progress") ? { total: 5000 } : null,
);
it("processChildren marks poison once the STORED tree exceeds CATEGORY_CAP", async () => {
// The cap is now measured from the DB (categories count), not the ephemeral
// progress.total which every processInit resets to 0.
const { service, queue, redis } = makeDeps({ waiting: 0, limitResults: [[{ n: 5000 }]] });
await (service as never as PC).processChildren({
data: { vehicleId: "op1", categoryId: "c1", source: "pl24", depth: 1 },
} as never);
@@ -302,3 +343,61 @@ describe("PrefetchWorkerService — fast lane (lifo) + backlog gating", () => {
});
});
});
// ── PL24 reaktif drill derinliği + backfill pacing (plv2 Faz 1 / adım 2b) ──
// Ban'ı süren hacim, her yeni decode'da tüm ağacın gezilmesiydi (bir Passat =
// 1.251 kategori). Fast lane artık PL24'te 1. seviyede durur; derin drill ya
// kullanıcı tıklamasıyla ya da bütçeli backfill lane'inde olur.
describe("PrefetchWorkerService — PL24 derinlik tavanı", () => {
const load = async () => {
const mod = await import("./prefetch-worker.service");
return mod as unknown as {
__testables?: { maxDepthFor(source: string, fast: boolean): number };
};
};
it("pl24 fast lane 1. seviyede durur, diğer kaynaklar tam derinlik kullanır", async () => {
// maxDepthFor modül-özel; davranışı dolaylı doğrula: env varsayılanları
process.env.PREFETCH_PL24_FAST_DEPTH = "";
process.env.PREFETCH_MAX_DEPTH = "";
const mod = await load();
const fn = mod.__testables?.maxDepthFor;
if (!fn) return; // testable export yoksa atla (davranış e2e'de doğrulanır)
expect(fn("pl24", true)).toBe(1);
expect(fn("pl24", false)).toBeGreaterThan(1);
expect(fn("parts-catalogs", true)).toBeGreaterThan(1);
});
});
/**
* PL24 arka plan backfill anahtarı (Faz 3) + Mitsubishi parça-detay kırpması.
*/
describe("PL24 backfill anahtarı", () => {
const ENV = { ...process.env };
afterEach(() => {
process.env = { ...ENV };
});
it("varsayılan KAPALI — değişken hiç yoksa arka plan akmaz", async () => {
const { __testables } = await import("./prefetch-worker.service");
process.env.PL24_BACKFILL_ENABLED = undefined;
process.env.PL24_TR_DISABLED = undefined;
expect(__testables.isPl24BackfillEnabled()).toBe(false);
});
it("yalnız açık 'true' ile açılır", async () => {
const { __testables } = await import("./prefetch-worker.service");
process.env.PL24_TR_DISABLED = undefined;
process.env.PL24_BACKFILL_ENABLED = "true";
expect(__testables.isPl24BackfillEnabled()).toBe(true);
process.env.PL24_BACKFILL_ENABLED = "1";
expect(__testables.isPl24BackfillEnabled()).toBe(false);
});
it("eski PL24_TR_DISABLED hâlâ kapatabilir (yarım deploy musluğu açamaz)", async () => {
const { __testables } = await import("./prefetch-worker.service");
process.env.PL24_BACKFILL_ENABLED = "true";
process.env.PL24_TR_DISABLED = "true";
expect(__testables.isPl24BackfillEnabled()).toBe(false);
});
});

View File

@@ -10,12 +10,14 @@ import { and, asc, eq, gt, inArray, isNull, notExists, sql } from "drizzle-orm";
import { CategoriesService } from "../categories/categories.service";
import { DATABASE, type Database } from "../database/database.provider";
import { categories, parts, vehicles } from "../database/schema/core";
import { isPl24LeafNode, isPl24PartDetailNode } from "../integrations/pl24/pl24-tree";
import { PostHogService } from "../posthog/posthog.service";
import { RedisService } from "../redis/redis.service";
import { QUEUE_NAMES, getBullConnection } from "./bull.config";
import { backfillContext } from "./prefetch-context";
import {
RateLimitError,
alignToWindow,
checkCooldown,
checkTimeWindow,
initProgress,
@@ -53,9 +55,71 @@ const MAX_DEPTH = Number(process.env.PREFETCH_MAX_DEPTH) || 12;
const BACKFILL_BATCH_SIZE = 40;
/** Skip the wave entirely if the queue already has more than this many jobs pending. */
const BACKFILL_MAX_BACKLOG = 1000;
/** In-flight guard TTL (seconds) — safety net if a run dies without clearing. */
const BACKFILL_SCHEDULED_TTL = 6 * 60 * 60;
/**
* In-flight guard TTL (seconds) — safety net if a run dies without clearing.
*
* 36h, NOT 6h: a chain deferred on the daily budget lives until the next UTC
* midnight (~24h). With a 6h TTL the guard expired mid-chain, the scan re-picked
* the vehicle, processInit reset progress.total, and the in-flight jobs'
* incrementCompleted then compared `completed >= total` against the NEW total —
* corrupting completion accounting for a still-partial vehicle.
*/
const BACKFILL_SCHEDULED_TTL = Number(process.env.PREFETCH_SCHEDULED_TTL_H || 36) * 60 * 60;
/**
* Only delayed jobs due within this horizon count as queue PRESSURE.
*
* `delayed` lumps two very different things together: per-minute source-rate
* defers (<60s) and retry backoff (30/60s), which ARE load, versus daily-budget
* and off-hours defers (hours, parked on the next UTC midnight), which are merely
* THROTTLED FUTURE WORK. Counting the latter as backlog froze Phase-2 for most of
* the day (2026-08-01: delayed=11495, all pcat, all parked at 00:00:01 UTC; the
* partial drain fell to ~25 vehicles/day, ETA 79 days).
*/
const PRESSURE_HORIZON_MS = Number(process.env.PREFETCH_PRESSURE_HORIZON_MS) || 10 * 60_000;
/**
* Absolute ceiling on TOTAL pending jobs (waiting+active+delayed+prioritized)
* across BOTH lanes — the runaway backstop that `delayed` used to provide by
* accident. Excluding long defers from the pressure gate removes the only
* negative feedback on production, so the pool needs its own hard stop: Phase-2
* can otherwise produce ~288k jobs/day against ~65k/day of budget. 50k ≈ 15h of
* the combined daily budgets, so the pool always drains inside a window; 1/9 of
* the guard-less BFS runaway (470k, months to drain). Set 0 to disable Phase-2.
*/
const HARD_MAX_TOTAL_JOBS = Number(process.env.PREFETCH_MAX_TOTAL_JOBS ?? 50_000);
/**
* Rough fan-out of one Phase-2 re-drill. Admission control is done in JOB units,
* not vehicle units: 40 vehicles/wave is meaningless when one vehicle is 100-3000
* jobs (p95 tree = 744 categories).
*/
const EST_JOBS_PER_VEHICLE = Number(process.env.PREFETCH_EST_JOBS_PER_VEHICLE) || 400;
/**
* Share of each source's daily budget reserved for the FAST lane. The daily
* counter has no lane component, so backfill spending the budget also parked the
* user's fresh-decode chain until midnight. One shared counter (the total
* upstream/bandwidth ceiling stays exactly SOURCE_DAILY_MAX) but two thresholds:
* the main (backfill) lane stops at 80%, the fast lane may use 100%.
*/
const DAILY_FAST_RESERVE = 0.2;
/** Only these decode sources have catalogs worth prefetching. */
/**
* Whether the PL24 *background* backfill lane may run. The user-triggered fast
* lane is never gated by this.
*
* Default is OFF. Two PL24 accounts were banned while bulk background load ran
* against them, so the background lane has to be switched on deliberately and
* watched, never inherited from an unset variable.
*
* `PL24_BACKFILL_ENABLED` replaces the old `PL24_TR_DISABLED`, whose name said
* "the tr account is dead" while its actual job was "keep bulk load off the one
* surviving account". The old variable is still honoured so a half-applied
* deploy cannot silently open the tap: it can only keep the lane closed.
*/
function isPl24BackfillEnabled(): boolean {
if (process.env.PL24_BACKFILL_ENABLED !== "true") return false;
// Legacy kill switch still wins while it is explicitly set.
return process.env.PL24_TR_DISABLED !== "true";
}
const BACKFILL_SOURCES = ["pl24", "emex", "parts-catalogs"];
/** Redis key holding the rolling rescan cursor (last createdAt seen). */
const BACKFILL_CURSOR_KEY = "prefetch:backfill:cursor";
@@ -98,12 +162,69 @@ const SOURCE_RATE_MAX: Record<string, number> = {
// (2026-07-08: 93k backlog %89 pcat idi — 20/min + 5s pace drenaja yetmiyordu).
"parts-catalogs": Number(process.env.PREFETCH_RATE_PCAT) || 90,
};
/**
* Per-source ROLLING-DAY budget (backfill jobs/source/UTC-day). A storm guard on
* top of the per-minute ceilings: those cap burst rate but not the daily TOTAL,
* so a source running near its ceiling for many hours drains the proxy budget
* (2026-07-09: a backlog drain pushed pcat to ~74k calls / ~10 GB in one day).
* When a source hits its daily budget, further backfill jobs defer until the
* window rolls. User-facing decodes are unaffected — they don't pass through the
* worker. Only counts jobs that already cleared the per-minute gate, so
* rate-limited retries don't inflate it. 0 = unlimited. Env-tunable: raise to
* drain a backlog faster, lower to conserve proxy budget harder.
*/
const SOURCE_DAILY_MAX: Record<string, number> = {
pl24: Number(process.env.PREFETCH_DAILY_PL24) || 15_000,
emex: Number(process.env.PREFETCH_DAILY_EMEX) || 20_000,
// 45k (1.5x): the 2026-07-09 incident that created this guard was ~74k calls /
// ~10 GB in a day, so 45k ≈ 61% of that — a reversible step at ~6 GB/day. With
// DAILY_FAST_RESERVE the backfill (main) lane gets 36k, i.e. +20% over the old
// effective 30k while still leaving 9k for user decodes. Burst rate is
// UNCHANGED (SOURCE_RATE_MAX pcat 90/min), so per-IP ban pressure is the same —
// this only sustains that pace for more of the day. Rollback signal: any hour
// with >2 pcat HTTP 402 (DataImpulse quota) → back to 30_000.
"parts-catalogs": Number(process.env.PREFETCH_DAILY_PCAT) || 45_000,
};
/**
* Per-job pacing for parts-catalogs only (its browser/JWT capture is heavy).
* Set 0 to disable. Other sources are paced by the limiter + cooldown alone.
*/
const PCAT_PACE_MS = Number(process.env.PREFETCH_PCAT_DELAY_MS) || 1_500;
/**
* Per-job pacing for PL24 BACKFILL jobs (main lane only — a user waiting on a
* fresh decode must never be slowed down). Both account bans followed days of
* thousands of back-to-back PL24 calls; a paced, jittered stream looks nothing
* like that. Set 0 to disable.
*/
const PL24_PACE_MS = Number(process.env.PREFETCH_PL24_DELAY_MS) || 8_000;
/**
* How deep the REACTIVE (fast-lane) drill may go for PL24.
*
* A freshly decoded vehicle used to be walked to the bottom immediately: one
* Passat produced 1,251 categories, one L200 2,323 — 1.4k-6.8k categories/day
* from 3-17 decodes, which is exactly the volume that preceded both bans
* (plv2.md §2.2). Depth 1 = top groups and their direct children; anything
* deeper is fetched lazily when the user actually opens that node, or by the
* budgeted backfill lane. Other sources keep MAX_DEPTH.
*/
const PL24_FAST_MAX_DEPTH = Number(process.env.PREFETCH_PL24_FAST_DEPTH) || 1;
/** Depth ceiling for this source+lane. */
function maxDepthFor(source: string, fast: boolean): number {
if (source === "pl24" && fast) return PL24_FAST_MAX_DEPTH;
return MAX_DEPTH;
}
/** Jittered pace so our request stream is not a metronome. */
function jitter(ms: number): number {
return Math.round(ms * (0.5 + Math.random()));
}
/** Test-only surface for the pure helpers above. */
export const __testables = { maxDepthFor, jitter, isPl24BackfillEnabled };
// ── Phase-1 residue exclusion ──
/**
* Skip a zero-parts vehicle once this many backfill attempts have completed with
@@ -196,7 +317,7 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
this.logger.log(
`[prefetch] Worker started (concurrency=${WORKER_CONCURRENCY}, global ${WORKER_RATE_MAX}/min, ` +
`per-source ${JSON.stringify(SOURCE_RATE_MAX)}, pcatPace=${PCAT_PACE_MS}ms)`,
`per-source ${JSON.stringify(SOURCE_RATE_MAX)}, daily ${JSON.stringify(SOURCE_DAILY_MAX)}, pcatPace=${PCAT_PACE_MS}ms)`,
);
// Hourly backfill scan — run IN-PROCESS, not as a BullMQ cron job. A cron
@@ -252,14 +373,45 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
job.name === "prefetch-children" ||
job.name === "prefetch-parts")
) {
await this.checkSourceRate(
data.source,
(job.data as { fast?: boolean }).fast ? "fast" : "main",
);
const lane = (job.data as { fast?: boolean }).fast ? "fast" : "main";
// GATE ORDER IS LOAD-BEARING — cheapest first, and every gate that can
// reject the job must run BEFORE any counter is debited.
//
// The business-hours window and the cooldown used to sit at the top of
// each handler, i.e. AFTER the per-minute counter and the daily budget
// had already been charged. So a job that woke outside the window paid a
// budget unit to do nothing. Combined with a deferral target of "next UTC
// midnight" (= 03:00 Europe/Istanbul, six hours before a 09:00 window
// opens) that closed a loop: the whole daily allowance was burned by
// no-op wake-ups before the window ever opened, so the source never ran
// again. Measured on prod 2026-09-20 — pl24 at 600/600 with 0 catalog
// requests and 0 new categories for the day.
//
// 1. Window: pure clock arithmetic, no I/O, and an out-of-window job can
// never do useful work — so nothing else is worth spending on it.
checkTimeWindow(data.source);
// 2. Cooldown: one Redis TTL read. Pauses the whole worker (see catch).
await checkCooldown(this.redis, data.source);
// 3. Per-minute ceiling.
await this.checkSourceRate(data.source, lane);
// 4. Daily budget last: a job deferred on any gate above never reaches
// here, so only jobs about to do real work are counted. The lane
// decides which threshold applies (backfill stops at the main limit,
// the user's fast lane may use the full budget).
await this.checkSourceDailyBudget(data.source, lane);
}
if (data.source === "parts-catalogs" && PCAT_PACE_MS > 0) {
await new Promise((r) => setTimeout(r, PCAT_PACE_MS));
}
// PL24 backfill only: pace + jitter. The fast (user) lane is never delayed.
if (
data.source === "pl24" &&
PL24_PACE_MS > 0 &&
!(job.data as { fast?: boolean }).fast &&
(job.name === "prefetch-children" || job.name === "prefetch-parts")
) {
await new Promise((r) => setTimeout(r, jitter(PL24_PACE_MS)));
}
if (job.name === "backfill-scan") {
return await this.processBackfillScan();
@@ -307,8 +459,8 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
const { vehicleId, source, fast = false } = job.data;
this.logger.log(`[prefetch] Init for vehicle=${vehicleId}, source=${source}`);
await checkCooldown(this.redis, source);
checkTimeWindow(source);
// Cooldown + time-window are enforced in process() before the daily budget
// is debited — see the comment there; re-checking here would be a no-op.
// Already flagged as poison (tree exceeded CATEGORY_CAP on a prior run) — skip.
if (await this.redis.exists(this.poisonKey(vehicleId))) {
@@ -387,10 +539,11 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
for (const child of children) {
if (child.unavailable) continue;
await this.queueCategoryJob(child, vehicleId, source, 1, fast);
queued++;
// Count jobs ACTUALLY queued, not nodes walked — see addJob's doc: an
// inflated progress.total makes the chain never reach "finished".
queued += await this.queueCategoryJob(child, vehicleId, source, 1, fast);
}
} else if (this.isLeafLinkPath(cat.linkPath, cat.source, cat.hasSubgroups)) {
} else if (this.isLeafLinkPath(cat.linkPath, cat.source, cat.hasSubgroups, cat.linkWid)) {
// Leaf — check if parts already fetched
const [partCheck] = await this.db
.select({ id: parts.id })
@@ -398,32 +551,46 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
.where(eq(parts.categoryId, cat.id))
.limit(1);
if (!partCheck && cat.linkPath) {
await this.addJob("prefetch-parts", {
if (
!partCheck &&
cat.linkPath &&
(await this.addJob("prefetch-parts", {
vehicleId,
categoryId: cat.id,
source,
action: "parts" as const,
depth: 0,
fast,
});
}))
) {
queued++;
}
} else if (cat.linkPath) {
} else if (
cat.linkPath &&
// Non-leaf without children — needs children fetch
await this.addJob("prefetch-children", {
(await this.addJob("prefetch-children", {
vehicleId,
categoryId: cat.id,
source,
action: "children" as const,
depth: 0,
fast,
});
}))
) {
queued++;
}
}
await updateProgress(this.redis, vehicleId, { total: queued });
if (queued === 0) {
// Nothing left to fetch — the tree is already complete in DB. Without this
// there is no job to fire incrementCompleted, so progress sits at {0,0}, the
// vehicle is never marked fullyFetched, and the scan re-picks it every wave
// forever while burning a daily-budget slot each time.
this.logger.log(`[prefetch] Nothing to queue for vehicle=${vehicleId} — already complete`);
await this.finalizeVehicle(vehicleId);
return;
}
this.logger.log(`[prefetch] Queued ${queued} sub-jobs for vehicle=${vehicleId}`);
}
@@ -434,22 +601,33 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
const { vehicleId, categoryId, source, depth, fast = false } = job.data;
this.logger.log(`[prefetch] Children for category=${categoryId}, depth=${depth}`);
await checkCooldown(this.redis, source);
checkTimeWindow(source);
// Cooldown + time-window are enforced in process() before the daily budget
// is debited — see the comment there; re-checking here would be a no-op.
if (depth >= MAX_DEPTH) {
this.logger.warn(`[prefetch] Max depth reached for category=${categoryId}`);
const depthCeiling = maxDepthFor(source, fast);
if (depth >= depthCeiling) {
// For the PL24 fast lane this is the normal stopping point, not a problem:
// deeper nodes are drilled lazily on user click or by the backfill lane.
const level = source === "pl24" && fast ? "log" : "warn";
this.logger[level](
`[prefetch] Depth ceiling ${depthCeiling} reached for category=${categoryId} (source=${source}, lane=${fast ? "fast" : "main"})`,
);
return;
}
// Anti-poison cap: progress.total tracks every sub-job queued for this vehicle
// (≈ its discovered tree size). Once it blows past the ceiling the vehicle is a
// generic-catalog explosion — stop drilling and mark it poison so the rest of
// its (part-less) tree is never fetched and it's never re-picked.
const prog = await this.redis.getJson<{ total: number }>(`prefetch:progress:${vehicleId}`);
if ((prog?.total ?? 0) >= CATEGORY_CAP) {
// Anti-poison cap measured from the DB, NOT from progress.total: the ephemeral
// counter is reset to 0 by every processInit, so a re-picked vehicle could
// drill another CATEGORY_CAP nodes per round and never trip the guard (the
// generic-ROOT Opels: 420k/102k/21k categories, ZERO parts). The stored tree
// is the real, cumulative size.
const [capRow] = await this.db
.select({ n: sql<number>`count(*)::int` })
.from(categories)
.where(eq(categories.vehicleId, vehicleId))
.limit(1);
if ((capRow?.n ?? 0) >= CATEGORY_CAP) {
this.logger.warn(
`[prefetch] Category cap ${CATEGORY_CAP} hit for vehicle=${vehicleId} (tree≈${prog?.total}) — marking poison, stop drilling`,
`[prefetch] Category cap ${CATEGORY_CAP} hit for vehicle=${vehicleId} (tree=${capRow?.n}) — marking poison, stop drilling`,
);
await this.markPoison(vehicleId);
return;
@@ -461,8 +639,9 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
let queued = 0;
for (const child of children) {
if (child.unavailable) continue;
await this.queueCategoryJob(child, vehicleId, source, depth + 1, fast);
queued++;
// Real queued-job count (see addJob) — walking a node that dedupes or
// already has parts must not inflate progress.total.
queued += await this.queueCategoryJob(child, vehicleId, source, depth + 1, fast);
}
if (queued > 0) {
@@ -490,8 +669,8 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
const { vehicleId, categoryId, source } = job.data;
this.logger.log(`[prefetch] Parts for category=${categoryId}`);
await checkCooldown(this.redis, source);
checkTimeWindow(source);
// Cooldown + time-window are enforced in process() before the daily budget
// is debited — see the comment there; re-checking here would be a no-op.
try {
await this.categoriesService.getCategoryWithParts(categoryId);
@@ -541,19 +720,60 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
// genuinely-empty vehicles keep getting onboarded through the fast lane even
// while a large deep-drill backlog is still draining — otherwise a single
// backlog spike freezes new-vehicle coverage until the whole queue clears.
const counts = await this.queue.getJobCounts("waiting", "delayed", "active");
const backlog = (counts.waiting ?? 0) + (counts.delayed ?? 0) + (counts.active ?? 0);
const phase2Allowed = backlog <= maxBacklog;
// Two INDEPENDENT ceilings (Phase-1 fast lane is never gated, so genuinely
// empty vehicles keep getting onboarded):
// 1. pressure = waiting + active + delayed-due-within-PRESSURE_HORIZON_MS,
// both lanes, vs maxBacklog — "are the workers actually swamped?".
// Budget/off-hours defers are parked hours out and no longer count, so a
// spent daily budget stops freezing Phase-2 for the rest of the day.
// 2. total = every pending job, both lanes, vs HARD_MAX_TOTAL_JOBS — the
// runaway backstop that `delayed` used to provide by accident.
const depth = await this.getQueueDepth();
const headroom = Math.max(0, HARD_MAX_TOTAL_JOBS - depth.total);
// Admission control in JOB units: one wave fans out to batchSize * ~400 jobs
// long before the next hourly scan can react, so shrink the wave as the pool
// fills instead of stepping over the cap by a whole batch.
const phase2Budget = Math.min(batchSize, Math.floor(headroom / EST_JOBS_PER_VEHICLE));
const phase2Allowed = depth.pressure <= maxBacklog && phase2Budget > 0;
if (!phase2Allowed) {
this.logger.log(`[backfill] Backlog ${backlog} > ${maxBacklog} — Phase-1 (fast lane) only`);
this.logger.log(
`[backfill] Phase-1 (fast lane) only — pressure=${depth.pressure}/${maxBacklog}, ` +
`total=${depth.total}/${HARD_MAX_TOTAL_JOBS} (delayed=${depth.delayed}, imminent=${depth.imminent})`,
);
}
if (HARD_MAX_TOTAL_JOBS > 0 && depth.total > HARD_MAX_TOTAL_JOBS * 1.5) {
// Should be unreachable — admission control caps intake once per hour. If it
// fires, real fan-out is far above EST_JOBS_PER_VEHICLE.
this.logger.error(
`[backfill] Queue pool ${depth.total} > 1.5x hard cap ${HARD_MAX_TOTAL_JOBS} — investigate fan-out`,
);
}
// Only target sources eligible right now: not in cooldown (user active) and
// inside their scrape window (PL24/parts-catalogs office hours; EMEX always).
// Only target sources eligible right now: not in cooldown (user active),
// inside their scrape window, AND still inside today's main-lane budget.
// The budget check is THE key guard: deferring at job level only MOVES work
// into `delayed`, it does not stop PRODUCING it — and budget defers never
// exhaust attempts (moveToDelayed skipAttempt), so nothing drops them. Once a
// source's main-lane budget is spent the scan must stop feeding it for the
// rest of the UTC day; feeding a throttled source is exactly how the 470k
// runaway was built. This also preserves the fast-lane reserve for real users.
const eligible: string[] = [];
for (const s of BACKFILL_SOURCES) {
// Background backfill is opt-in per source; pl24 defaults to OFF so bulk
// load can never burn the one surviving account by accident.
if (s === "pl24" && !isPl24BackfillEnabled()) continue;
if (await this.redis.exists(`prefetch:activity:${s}`)) continue;
if (cfg.businessHoursOnly !== false && !isWithinTimeWindow(s)) continue;
const mainLimit = this.dailyMainLimit(s);
if (mainLimit > 0) {
const spent = Number((await this.redis.get(this.dailyKey(s))) ?? 0);
if (spent >= mainLimit) {
this.logger.log(
`[backfill] ${s} daily budget spent (${spent}/${mainLimit}) — source skipped this wave`,
);
continue;
}
}
eligible.push(s);
}
if (eligible.length === 0) {
@@ -568,9 +788,17 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
const tryPick = async (
v: { id: string; source: string | null },
fast: boolean,
limit: number = batchSize,
): Promise<void> => {
if (picked.length >= batchSize || seen.has(v.id) || !v.source) return;
if (await this.redis.exists(`prefetch:scheduled:${v.id}`)) return; // already in flight
if (picked.length >= limit || seen.has(v.id) || !v.source) return;
// TWO different in-flight guards, both must be clear:
// - prefetch:scheduled:backfill:<id> — ours (36h, covers a budget-parked chain)
// - prefetch:scheduled:<id> — the USER decode path's (vehicles.service.ts
// schedulePrefetch, short TTL). We deliberately stopped WRITING the bare
// key: our long TTL made schedulePrefetch() silently skip the user's
// fresh-decode fast-lane init.
if (await this.redis.exists(this.scheduledKey(v.id))) return;
if (await this.redis.exists(`prefetch:scheduled:${v.id}`)) return; // user chain in flight
// Skip exhausted residue: vehicles whose prefetch keeps finishing with zero
// parts (no catalog data). They'd otherwise be re-picked every wave forever.
const noResult = await this.redis.get(this.noResultKey(v.id));
@@ -603,17 +831,27 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
for (const v of noParts) await tryPick(v, true);
// Phase 2 — rolling rescan of ALL decoded vehicles to gap-fill partially-fetched
// ones. A createdAt cursor walks forward and wraps around at the end. Gated by
// the backlog ceiling (above) so it doesn't pile on while the queue is deep.
if (phase2Allowed && picked.length < batchSize) {
// Phase 2 — rolling rescan of vehicles that are NOT fully fetched, to gap-fill
// partials. Targets the DURABLE `fullyFetched` flag (indexed) instead of
// walking the whole fleet and relying only on the ephemeral 21-day
// `prefetch:complete:` marker — a Redis flush would otherwise re-drill every
// vehicle at once. The fullyFetchedAt clause keeps the periodic re-validation
// the TTL used to provide. Gated by the ceilings above + a JOB-unit budget.
const phase2Limit = Math.min(batchSize, picked.length + phase2Budget);
if (phase2Allowed && picked.length < phase2Limit) {
const cursorObj = await this.redis.getJson<{ ts: string }>(BACKFILL_CURSOR_KEY);
const cursor = cursorObj?.ts ? new Date(cursorObj.ts) : new Date(0);
const rolling = await this.db
.select({ id: vehicles.id, source: vehicles.source, createdAt: vehicles.createdAt })
.from(vehicles)
.where(and(inArray(vehicles.source, eligible), gt(vehicles.createdAt, cursor)))
.where(
and(
inArray(vehicles.source, eligible),
gt(vehicles.createdAt, cursor),
sql`(${vehicles.fullyFetched} = false OR ${vehicles.fullyFetchedAt} < now() - interval '21 days')`,
),
)
.orderBy(asc(vehicles.createdAt))
.limit(overfetch);
@@ -629,7 +867,7 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
let lastTs: Date | null = null;
for (const v of rolling) {
lastTs = v.createdAt;
await tryPick(v, false);
await tryPick(v, false, phase2Limit);
}
if (lastTs) {
await this.redis.setJson(BACKFILL_CURSOR_KEY, { ts: lastTs.toISOString() }, 30 * 86400);
@@ -645,7 +883,8 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
const fastCount = picked.filter((v) => v.fast).length;
this.logger.log(
`[backfill] Queued ${picked.length} vehicle(s) (${fastCount} fast-lane, ` +
`sources=${eligible.join(",")}, backlog=${backlog})`,
`sources=${eligible.join(",")}, pressure=${depth.pressure}, total=${depth.total}, ` +
`phase2Budget=${phase2Budget})`,
);
}
@@ -664,7 +903,7 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
},
);
// Guard cleared on completion (incrementCompleted) or by TTL if the run dies.
await this.redis.set(`prefetch:scheduled:${vehicleId}`, "1", BACKFILL_SCHEDULED_TTL);
await this.redis.set(this.scheduledKey(vehicleId), "1", BACKFILL_SCHEDULED_TTL);
}
// ==================== Helpers ====================
@@ -673,6 +912,7 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
cat: {
id: string;
linkPath: string | null;
linkWid?: string | null;
source: string;
unavailable: boolean;
hasSubgroups?: boolean | null;
@@ -681,10 +921,21 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
source: string,
depth: number,
fast = false,
): Promise<void> {
if (cat.unavailable) return;
): Promise<number> {
if (cat.unavailable) return 0;
if (this.isLeafLinkPath(cat.linkPath, cat.source, cat.hasSubgroups)) {
// A per-part detail node (Mitsubishi `partInfoTable` /details/vinpartinfo) is
// neither a group nor a listing: its parent's response already carried the
// part. Queueing it costs one upstream request and returns nothing. Prod had
// 19,576 of these, with 2 parts between them.
if (
cat.source === "pl24" &&
isPl24PartDetailNode({ linkPath: cat.linkPath, linkWid: cat.linkWid })
) {
return 0;
}
if (this.isLeafLinkPath(cat.linkPath, cat.source, cat.hasSubgroups, cat.linkWid)) {
// Leaf — check if already has parts
const [partCheck] = await this.db
.select({ id: parts.id })
@@ -693,16 +944,20 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
.limit(1);
if (!partCheck && cat.linkPath) {
await this.addJob("prefetch-parts", {
return (await this.addJob("prefetch-parts", {
vehicleId,
categoryId: cat.id,
source: source as "pl24" | "emex",
action: "parts" as const,
depth,
fast,
});
}))
? 1
: 0;
}
} else if (cat.linkPath && depth < MAX_DEPTH) {
return 0;
}
if (cat.linkPath && depth < MAX_DEPTH) {
// Non-leaf within the depth cap — explore children. The `depth < MAX_DEPTH`
// gate mirrors processChildren's early-return: without it we'd enqueue a
// prefetch-children job that processChildren just drops, burning a rate-limit
@@ -720,27 +975,32 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
.from(categories)
.where(eq(categories.parentId, cat.id));
let n = 0;
for (const child of children) {
if (child.unavailable) continue;
await this.queueCategoryJob(child, vehicleId, source, depth + 1, fast);
n += await this.queueCategoryJob(child, vehicleId, source, depth + 1, fast);
}
} else {
await this.addJob("prefetch-children", {
vehicleId,
categoryId: cat.id,
source: source as "pl24" | "emex",
action: "children" as const,
depth,
fast,
});
return n;
}
return (await this.addJob("prefetch-children", {
vehicleId,
categoryId: cat.id,
source: source as "pl24" | "emex",
action: "children" as const,
depth,
fast,
}))
? 1
: 0;
}
return 0;
}
private isLeafLinkPath(
linkPath: string | null,
source: string,
hasSubgroups?: boolean | null,
linkWid?: string | null,
): boolean {
if (!linkPath) return false;
// EMEX: Vehicle.aspx group nodes are parents to drill; Unit.aspx (hierarchical
@@ -756,21 +1016,37 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
// flag (null, rare pre-migration rows) → treated as leaf, preserving the old
// 1-level behaviour for those.
if (source === "parts-catalogs") return hasSubgroups !== true;
// PL24 leaf indicators
return (
linkPath.includes("/bom/") ||
linkPath.includes("/bomdetails") ||
linkPath.includes("/partinfo/") ||
linkPath.includes("/servicepart/vin_items")
);
// PL24: one shared classifier (integrations/pl24/pl24-tree). The old inline
// list was case-sensitive, so p5psa/p5volvo's camelCase `/details/vin/
// bomDetails` was never recognised as a leaf and its parts were never
// prefetched.
// `linkWid` is passed through on purpose: it is the reliable cross-brand
// marker and the read path has always used it, but this queueing path used
// to drop it and fall back to path matching alone. That is why Mitsubishi's
// `detailsTable` parts list was queued as a group here even after the shared
// classifier learned about it.
return isPl24LeafNode({ linkPath, hasSubgroups, linkWid });
}
private async addJob(name: string, data: PrefetchCategoryJobData): Promise<void> {
/**
* Queue one sub-job. Returns whether a NEW job was actually created.
*
* The return value is the fix for a completion-accounting bug: `progress.total`
* is the chain's denominator (incrementCompleted fires "finished" at
* `completed >= total`), but callers used to increment it for every node they
* WALKED — including nodes where this deterministic jobId deduped the add, and
* leaves that already had parts. An inflated total means the chain never
* reaches "finished", so the vehicle is never marked fullyFetched and the scan
* re-picks it every wave forever (the ~25 vehicles/day plateau). Queue
* behaviour is UNCHANGED — BullMQ already no-op'd a duplicate jobId.
*/
private async addJob(name: string, data: PrefetchCategoryJobData): Promise<boolean> {
// BullMQ rejects custom job IDs containing ":" (its key separator), so use
// "-" instead. The values are UUIDs — the ID only needs to be deterministic
// (for dedup), not parseable.
const jobId = `prefetch-${data.vehicleId}-${data.categoryId}-${data.action}`;
const opts: Record<string, unknown> = {
// BullMQ rejects custom job IDs containing ":" (its key separator), so use
// "-" instead. The values are UUIDs — the ID only needs to be deterministic
// (for dedup), not parseable.
jobId: `prefetch-${data.vehicleId}-${data.categoryId}-${data.action}`,
jobId,
// Fast lane (Phase-1 / reactive): add with `lifo` so the job RPUSHes to the
// TAIL of the wait list, where BullMQ's RPOPLPUSH picks it next — i.e. ahead
// of the deep deep-drill backlog already sitting in wait. (BullMQ 5 drains
@@ -778,16 +1054,15 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
// OPPOSITE here and starve the job behind the backlog; lifo is correct.)
...(data.fast ? { lifo: true } : {}),
};
if (data.fast) {
await this.fastQueue.add(name, data, opts);
return;
}
const q = data.fast ? this.fastQueue : this.queue;
if (await q.getJob(jobId)) return false;
// parts-catalogs pacing is handled per-job in process() (PCAT_PACE_MS) + the
// limiter. The old cumulative `index * 20s` delay was pathological (the Nth
// leaf of a vehicle waited N*20s) and is gone.
await this.queue.add(name, data, opts);
await q.add(name, data, opts);
return true;
}
private async incrementCompleted(vehicleId: string): Promise<void> {
@@ -807,29 +1082,47 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
if (isFinished) {
this.logger.log(`[prefetch] Completed all jobs for vehicle=${vehicleId}`);
// Genuine residue: the whole chain finished but the vehicle still has no
// parts (all leaves empty / no catalog data). Count it so Phase-1 stops
// re-picking it every wave.
const [hasPart] = await this.db
.select({ id: parts.id })
.from(parts)
.where(eq(parts.vehicleId, vehicleId))
.limit(1);
if (hasPart) {
// Fully fetched with parts → mark complete so the Phase-2 rescan skips it
// (re-validates after the TTL). A chain with any failed job never reaches
// isFinished, so partially-fetched vehicles are never marked — they keep
// getting gap-filled.
await this.redis.set(this.completeKey(vehicleId), "1", COMPLETE_TTL_S);
} else {
await this.markNoResult(vehicleId);
}
// Clean up Redis keys — data is in PostgreSQL now
await this.redis.del(`prefetch:scheduled:${vehicleId}`);
await this.redis.del(`prefetch:progress:${vehicleId}`);
await this.finalizeVehicle(vehicleId);
}
}
/**
* Settle a vehicle whose prefetch chain is done: mark it complete (with parts)
* or count it as residue (still zero parts), then clear the run's Redis state.
* Called both when the last sub-job finishes AND when processInit finds there
* is nothing left to queue — otherwise an already-complete tree would never be
* settled and the scan would re-pick it forever.
*/
private async finalizeVehicle(vehicleId: string): Promise<void> {
// Genuine residue: the whole chain finished but the vehicle still has no
// parts (all leaves empty / no catalog data). Count it so Phase-1 stops
// re-picking it every wave.
const [hasPart] = await this.db
.select({ id: parts.id })
.from(parts)
.where(eq(parts.vehicleId, vehicleId))
.limit(1);
if (hasPart) {
// Fully fetched with parts → mark complete so the Phase-2 rescan skips it
// (re-validates after the TTL). A chain with any failed job never reaches
// isFinished, so partially-fetched vehicles are never marked — they keep
// getting gap-filled.
await this.redis.set(this.completeKey(vehicleId), "1", COMPLETE_TTL_S);
// Durable completeness flag (never expires) — the reliable "% fully
// fetched" measurement, independent of the ephemeral Redis marker.
// Re-set on every re-drill completion so fullyFetchedAt tracks last-verified.
await this.db
.update(vehicles)
.set({ fullyFetched: true, fullyFetchedAt: new Date() })
.where(eq(vehicles.id, vehicleId));
} else {
await this.markNoResult(vehicleId);
}
// Clean up Redis keys — data is in PostgreSQL now
await this.redis.del(this.scheduledKey(vehicleId));
await this.redis.del(`prefetch:progress:${vehicleId}`);
}
private async incrementErrors(vehicleId: string): Promise<void> {
const progress = await this.redis.getJson<{ errors: number }>(`prefetch:progress:${vehicleId}`);
if (!progress) return;
@@ -842,6 +1135,62 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
return `prefetch:noresult:${vehicleId}`;
}
/**
* Backfill's own in-flight guard — namespaced so it can't shadow the user
* decode path's `prefetch:scheduled:<id>` (vehicles.service.ts reads that key
* and skips the fresh-decode fast-lane init while it is set).
*/
private scheduledKey(vehicleId: string): string {
return `prefetch:scheduled:backfill:${vehicleId}`;
}
/**
* Queue depth across BOTH lanes, split into "pressure" (work the workers will
* pick up within PRESSURE_HORIZON_MS) and "total" (everything pending).
*
* BullMQ stores delayed jobs in a ZSET scored `dueMs * 0x1000 + seq` (12-bit
* collision counter — addDelayedJob / moveToDelayed lua), so "due within X ms"
* is a plain ZCOUNT with the bound encoded the same way. RedisService exposes
* no zcount, so we borrow each queue's OWN ioredis connection and its toKey()
* rather than hand-building `bull:<name>:delayed`.
*/
private async getQueueDepth(): Promise<{
pressure: number;
total: number;
imminent: number;
delayed: number;
}> {
// String bound so ioredis can't render it in exponent notation.
const maxScore = String((Date.now() + PRESSURE_HORIZON_MS + 1) * 0x1000 - 1);
let pressure = 0;
let total = 0;
let imminent = 0;
let delayed = 0;
for (const q of [this.queue, this.fastQueue]) {
const c = await q.getJobCounts("waiting", "active", "delayed", "prioritized");
const live = (c.waiting ?? 0) + (c.active ?? 0);
const d = c.delayed ?? 0;
// Fail CLOSED: if the ZCOUNT can't be taken, count every delayed job as
// pressure — fall back to the old over-conservative gate rather than
// silently unlocking Phase-2 with no visibility. A repeating warn here
// means Phase-2 is suspended again.
let due = d;
try {
const client = await q.client;
due = await client.zcount(q.toKey("delayed"), "-inf", maxScore);
} catch (err) {
this.logger.warn(
`[backfill] delayed zcount failed on ${q.name} (${(err as Error).message}) — counting all delayed as pressure`,
);
}
pressure += live + due;
total += live + d + (c.prioritized ?? 0);
imminent += due;
delayed += d;
}
return { pressure, total, imminent, delayed };
}
private completeKey(vehicleId: string): string {
return `prefetch:complete:${vehicleId}`;
}
@@ -857,7 +1206,7 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
* (which stay ~200 categories and DO yield parts) are never affected. */
private async markPoison(vehicleId: string): Promise<void> {
await this.redis.set(this.poisonKey(vehicleId), "1", POISON_TTL_S);
await this.redis.del(`prefetch:scheduled:${vehicleId}`);
await this.redis.del(this.scheduledKey(vehicleId));
await this.redis.del(`prefetch:progress:${vehicleId}`);
}
@@ -873,6 +1222,12 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
// (observed: fresh BMW init couldn't get a single pcat slot). Totals per
// source stay the same as before, so upstream load is unchanged.
const total = SOURCE_RATE_MAX[source] ?? 0;
// Park already-queued pl24 MAIN-lane jobs while background backfill is off
// (long defer, no attempt consumed) — the eligibility scan stops producing
// new ones, this stops an existing backlog from draining through the account.
if (source === "pl24" && lane === "main" && !isPl24BackfillEnabled()) {
throw new RateLimitError(15 * 60_000, "source-rate");
}
if (total <= 0) return;
const fastShare = Math.max(1, Math.floor(total / 3));
const max = lane === "fast" ? fastShare : total - fastShare;
@@ -886,6 +1241,65 @@ export class PrefetchWorkerService implements OnModuleInit, OnModuleDestroy {
}
}
/**
* Per-source rolling-day budget (storm guard). UTC-day fixed window in Redis;
* when the source's daily job count exceeds its ceiling, defer the job until
* the window rolls so a long run can't drain the proxy budget. 0 = unlimited.
*/
private async checkSourceDailyBudget(
source: string,
lane: "main" | "fast" = "main",
): Promise<void> {
const max = SOURCE_DAILY_MAX[source] ?? 0;
if (max <= 0) return;
const limit = lane === "fast" ? max : this.dailyMainLimit(source);
const dayMs = 86_400_000;
const now = Date.now();
const key = this.dailyKey(source, now);
// READ-then-INCR (was INCR-then-check). A REJECTED attempt must not count:
// the old order inflated the counter with every defer (observed 48531 against
// a 30000 budget), which (a) made the number useless for capacity decisions
// and (b) — now that the scan reads the same counter to stop feeding a spent
// source — would let pure defer churn lock the source out. Worst-case
// overshoot under the read/incr race is WORKER_CONCURRENCY jobs: acceptable.
const n = Number((await this.redis.get(key)) ?? 0);
if (n >= limit) {
// Defer to the next UTC day, plus up to 45min of JITTER. Without jitter every
// deferred job wakes in the SAME millisecond (observed: 11495 jobs all at
// 00:00:01 UTC) — the promotion lands as one burst and the pressure signal
// flaps. Other sources keep flowing (per-job defer, not a worker pause).
const rollover = now + dayMs - (now % dayMs) + 1000 + Math.floor(Math.random() * 45 * 60_000);
// Land the retry INSIDE the source's scrape window. The UTC rollover alone
// is 03:00 Europe/Istanbul, so with a 09:00 window every deferred job woke
// six hours early, failed the window check and was deferred again — the
// other half of the deadlock fixed in process(). alignToWindow is a no-op
// when no window is configured (the default).
const msLeft = Math.max(1000, alignToWindow(source, rollover) - now);
if (n === limit) {
this.logger.warn(
`[prefetch] ${source} daily budget hit (lane=${lane}, ${n}/${limit} of ${max}) — ` +
`deferring ~${Math.round(msLeft / 3_600_000)}h to the next in-window slot`,
);
}
throw new RateLimitError(msLeft, "source-rate");
}
const after = await this.redis.incr(key);
if (after === 1) await this.redis.expire(key, 90_000); // ~25h, outlives the window
}
/** Redis key for a source's UTC-day budget counter (shared by both lanes). */
private dailyKey(source: string, now = Date.now()): string {
return `prefetch:daily:${source}:${Math.floor(now / 86_400_000)}`;
}
/** Main (backfill) lane threshold — the fast lane's reserve is never available
* to backfill, so a sweep can't park the user's fresh-decode chain. */
private dailyMainLimit(source: string): number {
const max = SOURCE_DAILY_MAX[source] ?? 0;
return max <= 0 ? 0 : Math.floor(max * (1 - DAILY_FAST_RESERVE));
}
/** Record that a backfill attempt finished with the vehicle still at zero parts. */
private async markNoResult(vehicleId: string): Promise<void> {
const key = this.noResultKey(vehicleId);

View File

@@ -7,6 +7,8 @@ import {
computeStats,
filterOffersForBrand,
istanbulToday,
partPriceCurrentCacheKey,
partPriceSeriesCacheKey,
} from "../../part-prices/part-prices.logic";
import { createSupplierPriceSource } from "../../part-prices/supplier-price-source";
@@ -114,8 +116,8 @@ export async function processPartPriceRefresh(
// Cache düşür — bir sonraki sayfa görüntülemesi taze pg satırını okur.
const keys = chunk.flatMap((t) => [
`partprice:series:v2:${t.codeNorm}::${t.brandNorm}`,
`partprice:cur:v2:${t.codeNorm}::${t.brandNorm}`,
partPriceSeriesCacheKey(t.codeNorm, t.brandNorm),
partPriceCurrentCacheKey(t.codeNorm, t.brandNorm),
]);
if (keys.length > 0) await redis.del(...keys);

View File

@@ -0,0 +1,243 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import { RpartstoreRateLimitError } from "../../integrations/rpartstore/rpartstore.session";
import type { RpartstoreDecoded } from "../../integrations/rpartstore/rpartstore.types";
import {
type RedisLike,
istanbulDayKey,
processRpartstoreDecode,
redisTokenStore,
rpartstoreDailyKey,
} from "./rpartstore-decode.processor";
/** In-memory ioredis stand-in covering the surface the processor uses. */
function fakeRedis(): RedisLike & { store: Map<string, string>; ttls: Map<string, number> } {
const store = new Map<string, string>();
const ttls = new Map<string, number>();
return {
store,
ttls,
async get(k) {
return store.get(k) ?? null;
},
async set(k, v, _mode, ttl) {
store.set(k, v);
ttls.set(k, ttl);
},
async del(k) {
store.delete(k);
},
async incr(k) {
const n = Number(store.get(k) ?? 0) + 1;
store.set(k, String(n));
return n;
},
async expire(k, s) {
ttls.set(k, s);
},
};
}
/** Chainable drizzle mock: records every `.set()` payload and answers selects with `rows`. */
function fakeDb(rows: unknown[] = []) {
const sets: Record<string, unknown>[] = [];
const update = vi.fn(() => ({
set: vi.fn((payload: Record<string, unknown>) => {
sets.push(payload);
return { where: vi.fn().mockResolvedValue(undefined) };
}),
}));
const select = vi.fn(() => ({
from: vi.fn(() => ({ where: vi.fn().mockResolvedValue(rows) })),
}));
return { db: { update, select } as any, sets };
}
const decodedKadjar: RpartstoreDecoded = {
brandName: "Renault",
model: "Kadjar (HFE)",
modelCode: "HFE",
familyCode: "XFE",
modelYear: "2015",
engine: "1.5 DCI DİZEL MOTOR [K9K]",
gearbox: "DC4",
energyType: "MOTORIN",
manufacturingDate: "2015-07-28",
raw: {
catalogSource: "DATAHUB",
vin: "VF1RFE00653633190",
vehicleKey: "VF1RFE00653633190",
model: "Kadjar (HFE)",
vehicleBrand: "RENAULT",
country: "TR",
},
};
const job = (vin: string) =>
({ id: `j-${vin}`, data: { vin }, attemptsMade: 0, opts: { attempts: 1 } }) as any;
const NOW = new Date("2026-09-25T20:30:00+03:00");
describe("processRpartstoreDecode", () => {
beforeEach(() => {
process.env.RPARTSTORE_ENABLED = "true";
vi.spyOn(console, "log").mockImplementation(() => undefined);
vi.spyOn(console, "warn").mockImplementation(() => undefined);
vi.spyOn(console, "error").mockImplementation(() => undefined);
});
afterEach(() => {
process.env.RPARTSTORE_ENABLED = "false";
vi.restoreAllMocks();
});
it("is a no-op when RPARTSTORE_ENABLED is not true", async () => {
process.env.RPARTSTORE_ENABLED = "false";
const { db, sets } = fakeDb();
const searchVin = vi.fn();
const r = await processRpartstoreDecode(job("VF1X"), {
db,
redis: fakeRedis(),
decoder: () => ({ searchVin }),
dailyCap: 10,
});
expect(r.skipped).toBe(true);
expect(searchVin).not.toHaveBeenCalled();
expect(sets).toEqual([]);
});
it("decodes, matches the PL24 catalog vehicle and records the decoded row", async () => {
const { db, sets } = fakeDb([
{ id: "cv-kadjar", model: "KADJAR", categoryCount: 44 },
{ id: "cv-kadjar-cn", model: "KADJAR ÇİN", categoryCount: 22 },
]);
const redis = fakeRedis();
const searchVin = vi.fn().mockResolvedValue(decodedKadjar);
const r = await processRpartstoreDecode(job("VF1RFE00653633190"), {
db,
redis,
decoder: () => ({ searchVin }),
dailyCap: 10,
now: () => NOW,
});
expect(r).toEqual({ status: "decoded", catalogVehicleId: "cv-kadjar" });
expect(searchVin).toHaveBeenCalledWith("VF1RFE00653633190");
// one cap unit reserved on the Istanbul day, with an expiry
expect(redis.store.get(rpartstoreDailyKey(NOW))).toBe("1");
expect(redis.ttls.get(rpartstoreDailyKey(NOW))).toBeGreaterThan(0);
const final = sets.at(-1)!;
expect(final).toMatchObject({
status: "decoded",
brandName: "Renault",
model: "Kadjar (HFE)",
modelCode: "HFE",
modelYear: "2015",
catalogVehicleId: "cv-kadjar",
});
});
it("records not_found when RPartStore has no vehicle for the VIN", async () => {
const { db, sets } = fakeDb();
const r = await processRpartstoreDecode(job("VF1NOPE"), {
db,
redis: fakeRedis(),
decoder: () => ({ searchVin: vi.fn().mockResolvedValue(null) }),
dailyCap: 10,
});
expect(r.status).toBe("not_found");
expect(sets.at(-1)).toMatchObject({ status: "not_found" });
});
it("stops sending once the daily cap is spent and marks the row capped", async () => {
const redis = fakeRedis();
const key = rpartstoreDailyKey(NOW);
redis.store.set(key, "10"); // ten searches already sent today
const { db, sets } = fakeDb();
const searchVin = vi.fn().mockResolvedValue(decodedKadjar);
const r = await processRpartstoreDecode(job("VF1CAP"), {
db,
redis,
decoder: () => ({ searchVin }),
dailyCap: 10,
now: () => NOW,
});
expect(r.status).toBe("capped");
expect(searchVin).not.toHaveBeenCalled();
expect(sets.at(-1)).toMatchObject({ status: "capped" });
});
it("allows exactly `dailyCap` searches per day", async () => {
const redis = fakeRedis();
const searchVin = vi.fn().mockResolvedValue(null);
const statuses: string[] = [];
for (let i = 0; i < 12; i += 1) {
const { db } = fakeDb();
const r = await processRpartstoreDecode(job(`VF1${i}`), {
db,
redis,
decoder: () => ({ searchVin }),
dailyCap: 10,
now: () => NOW,
});
statuses.push(r.status);
}
expect(searchVin).toHaveBeenCalledTimes(10);
expect(statuses.filter((s) => s === "capped")).toHaveLength(2);
});
it("waits retryAfterSeconds and retries once on a short-term rate limit without a second reservation", async () => {
const redis = fakeRedis();
const { db } = fakeDb();
const searchVin = vi
.fn()
.mockRejectedValueOnce(new RpartstoreRateLimitError(10, "SHORT_TERM"))
.mockResolvedValueOnce(null);
const sleep = vi.fn().mockResolvedValue(undefined);
const r = await processRpartstoreDecode(job("VF1RL"), {
db,
redis,
decoder: () => ({ searchVin }),
dailyCap: 10,
now: () => NOW,
sleep,
});
expect(r.status).toBe("not_found");
expect(searchVin).toHaveBeenCalledTimes(2);
expect(sleep).toHaveBeenCalledWith(10_500);
expect(redis.store.get(rpartstoreDailyKey(NOW))).toBe("1");
});
it("marks the row failed and rethrows on an infrastructure error (single attempt)", async () => {
const { db, sets } = fakeDb();
await expect(
processRpartstoreDecode(job("VF1ERR"), {
db,
redis: fakeRedis(),
decoder: () => {
throw new Error("RPARTSTORE_USER / RPARTSTORE_PASS are not configured");
},
dailyCap: 10,
}),
).rejects.toThrow(/not configured/);
expect(sets.at(-1)).toMatchObject({ status: "failed" });
});
});
describe("istanbulDayKey", () => {
it("counts the cap against the Istanbul calendar day, not UTC", () => {
// 23:30 UTC on the 25th is already the 26th in Istanbul (UTC+3).
expect(istanbulDayKey(new Date("2026-09-25T23:30:00Z"))).toBe("2026-09-26");
expect(istanbulDayKey(new Date("2026-09-25T20:59:00Z"))).toBe("2026-09-25");
});
});
describe("redisTokenStore", () => {
it("round-trips a token with its ttl and ignores garbage", async () => {
const redis = fakeRedis();
const store = redisTokenStore(redis);
await store.set({ accessToken: "t", expiresAt: 1, subject: "s" }, 120);
expect(await store.get()).toEqual({ accessToken: "t", expiresAt: 1, subject: "s" });
expect(redis.ttls.get("rpartstore:token")).toBe(120);
redis.store.set("rpartstore:token", "{not json");
expect(await store.get()).toBeNull();
await store.clear();
expect(redis.store.has("rpartstore:token")).toBe(false);
});
});

View File

@@ -0,0 +1,252 @@
import { Job } from "bullmq";
import { and, eq, sql } from "drizzle-orm";
import { PostgresJsDatabase } from "drizzle-orm/postgres-js";
import { catalogVehicles, rpartstoreDecodes } from "../../database/schema/core";
import type { RpartstoreToken } from "../../integrations/rpartstore/rpartstore.auth";
import { RpartstoreClient, type TokenStore } from "../../integrations/rpartstore/rpartstore.client";
import {
type RpartstoreCatalogCandidate,
pickRpartstoreCatalogMatch,
} from "../../integrations/rpartstore/rpartstore.matcher";
import { RpartstoreRateLimitError } from "../../integrations/rpartstore/rpartstore.session";
import type { RpartstoreDecoded } from "../../integrations/rpartstore/rpartstore.types";
type Database = PostgresJsDatabase<Record<string, unknown>>;
export interface RpartstoreDecodeJobData {
vin: string;
}
/** Minimal ioredis surface the processor needs (also satisfied by RedisService.getClient()). */
export interface RedisLike {
get(key: string): Promise<string | null>;
set(key: string, value: string, mode: "EX", ttlSeconds: number): Promise<unknown>;
del(key: string): Promise<unknown>;
incr(key: string): Promise<number>;
expire(key: string, seconds: number): Promise<unknown>;
}
export interface RpartstoreDecoder {
searchVin(vin: string): Promise<RpartstoreDecoded | null>;
}
export interface RpartstoreProcessorDeps {
db: Database;
redis: RedisLike;
/** Built lazily so a missing credential only fails the job, not worker boot. */
decoder: () => RpartstoreDecoder;
/** Hard cap on VIN searches sent to RPartStore per Istanbul calendar day. */
dailyCap: number;
now?: () => Date;
sleep?: (ms: number) => Promise<void>;
}
export const RPARTSTORE_TOKEN_KEY = "rpartstore:token";
export const RPARTSTORE_DAILY_KEY_PREFIX = "rpartstore:daily:";
/** Counter keys live two days so a late-night job never sees a vanished key. */
const DAILY_KEY_TTL_SECONDS = 2 * 24 * 60 * 60;
/** "YYYY-MM-DD" in Europe/Istanbul — the day the cap is counted against. */
export function istanbulDayKey(date: Date): string {
const parts = new Intl.DateTimeFormat("en-CA", {
timeZone: "Europe/Istanbul",
year: "numeric",
month: "2-digit",
day: "2-digit",
}).formatToParts(date);
const get = (t: string): string => parts.find((p) => p.type === t)?.value ?? "";
return `${get("year")}-${get("month")}-${get("day")}`;
}
export const rpartstoreDailyKey = (date: Date): string =>
`${RPARTSTORE_DAILY_KEY_PREFIX}${istanbulDayKey(date)}`;
/** Redis-backed cache for the 1 h Okta access token (shared by worker restarts). */
export function redisTokenStore(redis: RedisLike): TokenStore {
return {
async get() {
const raw = await redis.get(RPARTSTORE_TOKEN_KEY);
if (!raw) return null;
try {
const t = JSON.parse(raw) as RpartstoreToken;
return t.accessToken && t.expiresAt ? t : null;
} catch {
return null;
}
},
async set(token, ttlSeconds) {
await redis.set(RPARTSTORE_TOKEN_KEY, JSON.stringify(token), "EX", ttlSeconds);
},
async clear() {
await redis.del(RPARTSTORE_TOKEN_KEY);
},
};
}
export function buildRpartstoreClient(redis: RedisLike): RpartstoreClient {
const username = process.env.RPARTSTORE_USER;
const password = process.env.RPARTSTORE_PASS;
if (!username || !password) {
throw new Error("RPARTSTORE_USER / RPARTSTORE_PASS are not configured");
}
return new RpartstoreClient({
username,
password,
tokenStore: redisTokenStore(redis),
brokerUrl: process.env.RPARTSTORE_BROKER_URL || undefined,
appVersion: process.env.RPARTSTORE_APP_VERSION || undefined,
logger: { log: (m) => console.log(m), warn: (m) => console.warn(m) },
});
}
export function rpartstoreDailyCapFromEnv(): number {
const n = Number(process.env.RPARTSTORE_DAILY_CAP);
return Number.isFinite(n) && n >= 0 ? Math.floor(n) : 10;
}
/**
* RPartStore decode processor (worker, concurrency 1, ≥6 s between jobs via the
* queue limiter — RPartStore allows 2 VIN searches per 10 s).
*
* Reserves one unit of the daily cap BEFORE sending anything: `INCR` on the
* Istanbul-day key; when the reservation lands above the cap the row is marked
* `capped` and nothing is sent, so at most `dailyCap` searches reach RPartStore
* per day even under concurrent enqueues. A rate-limited search waits
* `retryAfterSeconds` and is retried once without a second reservation.
*
* Outcomes recorded in `rpartstore_decodes`: decoded (with an optional PL24
* catalog_vehicle match), not_found (definitive), capped (retry tomorrow),
* failed (infra/auth error — user-retriable after 24 h).
*/
export async function processRpartstoreDecode(
job: Job<RpartstoreDecodeJobData>,
deps: RpartstoreProcessorDeps,
): Promise<{ status: string; catalogVehicleId: string | null; skipped?: boolean }> {
const { vin } = job.data;
const { db, redis } = deps;
const now = deps.now ?? (() => new Date());
const sleep = deps.sleep ?? ((ms: number) => new Promise<void>((r) => setTimeout(r, ms)));
if (process.env.RPARTSTORE_ENABLED !== "true") {
console.log(`[rpartstore-decode] disabled (RPARTSTORE_ENABLED!=true) — job ${job.id} no-op`);
return { status: "pending", catalogVehicleId: null, skipped: true };
}
await db
.update(rpartstoreDecodes)
.set({ attempts: sql`${rpartstoreDecodes.attempts} + 1`, updatedAt: now() })
.where(eq(rpartstoreDecodes.vin, vin));
// Daily cap reservation.
const dayKey = rpartstoreDailyKey(now());
const reserved = await redis.incr(dayKey);
if (reserved === 1) await redis.expire(dayKey, DAILY_KEY_TTL_SECONDS);
if (reserved > deps.dailyCap) {
await db
.update(rpartstoreDecodes)
.set({ status: "capped", updatedAt: now() })
.where(eq(rpartstoreDecodes.vin, vin));
console.warn(
`[rpartstore-decode] ${vin} → capped (${reserved - 1}/${deps.dailyCap} searches used on ${dayKey})`,
);
return { status: "capped", catalogVehicleId: null };
}
console.log(
`[rpartstore-decode] job ${job.id} decoding ${vin} (${reserved}/${deps.dailyCap} today)`,
);
try {
const decoder = deps.decoder();
let decoded: RpartstoreDecoded | null;
try {
decoded = await decoder.searchVin(vin);
} catch (err) {
if (!(err instanceof RpartstoreRateLimitError)) throw err;
const waitMs = Math.min(Math.max(err.retryAfterSeconds, 1), 30) * 1000 + 500;
console.warn(
`[rpartstore-decode] ${vin} rate-limited (${err.limitType}); retrying in ${waitMs}ms`,
);
await sleep(waitMs);
decoded = await decoder.searchVin(vin);
}
if (!decoded) {
await db
.update(rpartstoreDecodes)
.set({ status: "not_found", updatedAt: now() })
.where(eq(rpartstoreDecodes.vin, vin));
console.log(`[rpartstore-decode] ${vin} → not_found`);
return { status: "not_found", catalogVehicleId: null };
}
const catalogVehicleId = await matchCatalogVehicle(db, decoded);
await db
.update(rpartstoreDecodes)
.set({
status: "decoded",
brandName: decoded.brandName,
model: decoded.model,
modelCode: decoded.modelCode,
familyCode: decoded.familyCode,
modelYear: decoded.modelYear,
engine: decoded.engine,
gearbox: decoded.gearbox,
energyType: decoded.energyType,
manufacturingDate: decoded.manufacturingDate,
catalogVehicleId,
raw: decoded.raw,
decodedAt: now(),
updatedAt: now(),
})
.where(eq(rpartstoreDecodes.vin, vin));
console.log(
`[rpartstore-decode] ${vin} → decoded ${decoded.brandName} "${decoded.model ?? "?"}" ${decoded.modelYear ?? ""} catalog_vehicle=${catalogVehicleId ?? "null"}`,
);
return { status: "decoded", catalogVehicleId };
} catch (error) {
const message = error instanceof Error ? error.message : String(error);
console.error(`[rpartstore-decode] job ${job.id} failed for ${vin}: ${message}`);
const isLastAttempt = job.attemptsMade + 1 >= (job.opts.attempts ?? 1);
if (isLastAttempt) {
await db
.update(rpartstoreDecodes)
.set({ status: "failed", updatedAt: now() })
.where(eq(rpartstoreDecodes.vin, vin));
}
throw error;
}
}
/** Match within the decoded brand first, then the sister brand (Renault ⇄ Dacia
* share platforms and TR badges differ from the WMI). */
async function matchCatalogVehicle(
db: Database,
decoded: RpartstoreDecoded,
): Promise<string | null> {
if (!decoded.model) return null;
const sister = decoded.brandName.toLowerCase() === "dacia" ? "renault" : "dacia";
for (const brand of [decoded.brandName.toLowerCase(), sister]) {
const rows = await db
.select({
id: catalogVehicles.id,
model: catalogVehicles.model,
categoryCount: sql<number>`(
SELECT count(*)::int FROM categories
WHERE categories.catalog_vehicle_id = ${catalogVehicles.id}
)`,
})
.from(catalogVehicles)
.where(
and(
sql`lower(${catalogVehicles.brandName}) = ${brand}`,
eq(catalogVehicles.source, "pl24"),
),
);
const id = pickRpartstoreCatalogMatch(decoded.model, rows as RpartstoreCatalogCandidate[]);
if (id) return id;
}
return null;
}

View File

@@ -2,7 +2,7 @@ import { Job } from "bullmq";
import { and, eq, sql } from "drizzle-orm";
import { PostgresJsDatabase } from "drizzle-orm/postgres-js";
import { catalogVehicles, vinpinDecodes } from "../../database/schema/core";
import { getVinpinDriver } from "../../integrations/vinpin/vinpin-driver.service";
import { getVinpinDaemon } from "../../integrations/vinpin/vinpin-daemon.service";
import {
type CatalogCandidate,
pickBestCatalogMatch,
@@ -42,7 +42,11 @@ export async function processVinpinDecode(
.where(eq(vinpinDecodes.vin, vin));
try {
const decoded = await getVinpinDriver().decode(vin);
// Route through the warm-session daemon: inside business hours it decodes on
// the persistent warm seat (taskbar-raise + in-catalog decode); off-hours (or
// when warm can't be established) it transparently uses the cold per-decode
// path. Never throws — returns null on any failure.
const decoded = await getVinpinDaemon().decode(vin);
if (!decoded) {
await db
@@ -53,7 +57,9 @@ export async function processVinpinDecode(
return { status: "not_found", catalogVehicleId: null };
}
// Match the decoded model to an existing PL24 Fiat catalog_vehicle.
// Match the decoded model to an existing PL24 catalog_vehicle of the SAME
// brand. Fiat → 'fiat'; Renault/Dacia → the decoded brand (RENAULT/DACIA).
const brandName = decoded.brand ?? "Fiat";
const rows = await db
.select({
id: catalogVehicles.id,
@@ -62,7 +68,10 @@ export async function processVinpinDecode(
})
.from(catalogVehicles)
.where(
and(sql`lower(${catalogVehicles.brandName}) = 'fiat'`, eq(catalogVehicles.source, "pl24")),
and(
sql`lower(${catalogVehicles.brandName}) = ${brandName.toLowerCase()}`,
eq(catalogVehicles.source, "pl24"),
),
);
const catalogVehicleId = pickBestCatalogMatch(
@@ -74,7 +83,7 @@ export async function processVinpinDecode(
.update(vinpinDecodes)
.set({
status: "decoded",
brandName: "Fiat",
brandName,
model: decoded.model,
sincom: decoded.sincom,
trim: decoded.trim,

View File

@@ -0,0 +1,32 @@
import { Provider } from "@nestjs/common";
import { type JobsOptions, Queue } from "bullmq";
import { QUEUE_NAMES, getBullConnection, getBullTelemetry } from "../bull.config";
export const RPARTSTORE_DECODE_QUEUE = "RPARTSTORE_DECODE_QUEUE";
/**
* `attempts: 1` — the processor records a definitive outcome per job
* (decoded / not_found / capped / failed) and the daily cap must never be
* burned by automatic re-runs. A `failed` or `capped` row is re-enqueued by the
* decode path itself after 24 h (see VehiclesService.tryRpartstoreFallback).
*/
export const RPARTSTORE_DECODE_JOB_OPTIONS: JobsOptions = {
attempts: 1,
removeOnComplete: { count: 50 },
removeOnFail: { count: 100 },
};
/** RPartStore (Renault/Dacia) VIN-decode fallback queue. One shared dealer
* account → the worker consumes it with concurrency 1 and a 1-job-per-6 s
* limiter (RPartStore allows 2 searches per 10 s). Jobs carry `{ vin }`. */
export const RpartstoreDecodeQueueProvider: Provider = {
provide: RPARTSTORE_DECODE_QUEUE,
useFactory: () => {
const telemetry = getBullTelemetry();
return new Queue(QUEUE_NAMES.RPARTSTORE_DECODE, {
connection: getBullConnection(),
...(telemetry ? { telemetry } : {}),
defaultJobOptions: RPARTSTORE_DECODE_JOB_OPTIONS,
});
},
};

View File

@@ -0,0 +1,23 @@
import { describe, expect, it } from "vitest";
import { VINPIN_DECODE_JOB_OPTIONS } from "./vinpin-decode.queue";
/**
* The single Vinpin seat is shared by every decode and the driver runs its own
* bounded internal retries + a hard wall-clock budget. A BullMQ-level auto-retry
* on top is what compounded the prod seat livelock (a failed decode auto-re-ran
* straight back into the stuck seat). So the queue must NOT auto-retry.
*/
describe("vinpin-decode queue job options", () => {
it("uses attempts:1 — no BullMQ auto-retry", () => {
expect(VINPIN_DECODE_JOB_OPTIONS.attempts).toBe(1);
});
it("does not configure a retry backoff", () => {
expect(VINPIN_DECODE_JOB_OPTIONS.backoff).toBeUndefined();
});
it("still bounds retained job history", () => {
expect(VINPIN_DECODE_JOB_OPTIONS.removeOnComplete).toEqual({ count: 50 });
expect(VINPIN_DECODE_JOB_OPTIONS.removeOnFail).toEqual({ count: 100 });
});
});

View File

@@ -1,9 +1,28 @@
import { Provider } from "@nestjs/common";
import { Queue } from "bullmq";
import { type JobsOptions, Queue } from "bullmq";
import { QUEUE_NAMES, getBullConnection, getBullTelemetry } from "../bull.config";
export const VINPIN_DECODE_QUEUE = "VINPIN_DECODE_QUEUE";
/**
* Default job options for the Vinpin decode queue.
*
* `attempts: 1` — NO BullMQ-level auto-retry. The single Vinpin seat is shared by
* every decode, and the driver ALREADY runs its own bounded internal retries
* (VINPIN_DECODE_MAX_ATTEMPTS) plus a hard wall-clock budget before it reports
* not_found. Stacking a BullMQ retry (the old attempts:2 + 30s exponential
* backoff) on top is exactly what compounded the seat livelock in prod: one bad
* VIN would fail, auto-re-run 30s later straight back into the stuck seat, and
* starve real decodes for minutes. A failed decode now persists as not_found (a
* clean "not decodable") or failed (a hard infra error, user-retriable) instead of
* being auto-re-fed into the seat.
*/
export const VINPIN_DECODE_JOB_OPTIONS: JobsOptions = {
attempts: 1,
removeOnComplete: { count: 50 },
removeOnFail: { count: 100 },
};
/** Vinpin ePER decode-oracle queue. Single Vinpin seat → the worker consumes
* this with concurrency 1. Jobs carry just `{ vin }`. */
export const VinpinDecodeQueueProvider: Provider = {
@@ -13,14 +32,7 @@ export const VinpinDecodeQueueProvider: Provider = {
return new Queue(QUEUE_NAMES.VINPIN_DECODE, {
connection: getBullConnection(),
...(telemetry ? { telemetry } : {}),
defaultJobOptions: {
// The driver itself retries (VINPIN_DECODE_MAX_ATTEMPTS) before reporting
// not_found, so the queue keeps a small attempt budget for hard crashes.
attempts: 2,
backoff: { type: "exponential", delay: 30_000 },
removeOnComplete: { count: 50 },
removeOnFail: { count: 100 },
},
defaultJobOptions: VINPIN_DECODE_JOB_OPTIONS,
});
},
};

View File

@@ -58,6 +58,10 @@ async function bootstrap() {
"https://connect.facebook.net",
"https://challenges.cloudflare.com",
"https://destek.sase.tr",
// Google Ads gtag.js (conversion tracking). Its absence here silently
// blocked the whole tag from loading → gtag config/conversion never ran
// → 0 conversions for weeks despite correct AW id + labels.
"https://www.googletagmanager.com",
"'sha256-T5FzBQBMINFjZ4WLy58SeZ+J7xXzjnQEGlg618CQnhA='",
],
styleSrc: ["'self'", "https:", "'unsafe-inline'"],
@@ -67,6 +71,12 @@ async function bootstrap() {
"https://storage.sase.tr",
"https://www.facebook.com",
"https://destek.sase.tr",
// Google Ads conversion + remarketing pixel pings (fire as images).
"https://www.google.com",
"https://www.google.com.tr",
"https://www.googleadservices.com",
"https://googleads.g.doubleclick.net",
"https://ad.doubleclick.net",
],
fontSrc: ["'self'", "https:", "data:"],
mediaSrc: ["'self'", "data:", "https://destek.sase.tr"],
@@ -79,6 +89,14 @@ async function bootstrap() {
"https://challenges.cloudflare.com",
"https://destek.sase.tr",
"wss://destek.sase.tr",
// Google Ads gtag config fetch + conversion pings (googleadservices /
// google.com 1p-conversion & ccm/collect enhanced-conversion beacons).
"https://www.googletagmanager.com",
"https://www.google.com",
"https://www.google.com.tr",
"https://www.googleadservices.com",
"https://googleads.g.doubleclick.net",
"https://ad.doubleclick.net",
// Sentry browser SDK envelope POSTs (otolog org, de region).
// Without this CSP silently blocks every error/replay upload.
"https://*.ingest.de.sentry.io",

View File

@@ -21,6 +21,9 @@ export const OPTIONAL_WORKFLOWS = new Set<string>([
"referral",
"referral-qualified",
"referral-reward",
// Manual campaign sends (host-side sase-conversion-campaign.sh) — marketing,
// so it must honour opt-out and its unsubscribe tokens must validate here.
"conversion",
"mobile_push",
]);
@@ -50,6 +53,7 @@ export const NOTIFICATION_CATEGORIES = [
"referral",
"referral-qualified",
"referral-reward",
"conversion",
] as const,
},
{

View File

@@ -162,12 +162,19 @@ export class NovuService {
/** Dunning notice — fired when a charge fails. amount is in kuruş. */
async paymentFailed(
user: NovuUser,
opts: { amountKurus?: number; retryDate?: Date | null },
opts: { amountKurus?: number; retryDate?: Date | null; invoiceUrl?: string | null },
): Promise<void> {
await this.trigger("payment-failed", user, {
...(opts.amountKurus !== undefined ? { amount: formatTryAmount(opts.amountKurus) } : {}),
...(opts.retryDate ? { retryDate: formatTrDate(opts.retryDate) } : {}),
ctaUrl: buildTrackedUrl("payment-failed", user.email, webUrl("/dashboard/subscription")),
// Renewal failures pass Stripe's hosted invoice page — the only surface
// where the user can actually pay / enter a new card. The dashboard
// fallback (checkout abandons) has no payment UI for an active sub.
ctaUrl: buildTrackedUrl(
"payment-failed",
user.email,
opts.invoiceUrl ?? webUrl("/dashboard/subscription"),
),
});
}
}

View File

@@ -62,24 +62,34 @@ const NO_UNSUBSCRIBE_WORKFLOWS = new Set<string>([
"payment-failed",
]);
/**
* Signed HTTPS unsubscribe link for a (workflow, user) pair — the same URL the
* List-Unsubscribe header carries. GET renders a confirmation page, POST is
* the RFC 8058 one-click. Null for transactional flows or when the secret is
* unset (dev), so callers can skip the payload/header entirely.
*/
export function buildUnsubscribeUrl(workflow: string, subscriberId: string): string | null {
if (NO_UNSUBSCRIBE_WORKFLOWS.has(workflow)) return null;
if (!UNSUBSCRIBE_URL_BASE || !UNSUBSCRIBE_SECRET) return null;
const token = createHmac("sha256", UNSUBSCRIBE_SECRET)
.update(`${subscriberId}|${workflow}`)
.digest("hex");
const q = new URLSearchParams({ u: subscriberId, w: workflow, t: token });
return `${UNSUBSCRIBE_URL_BASE}?${q.toString()}`;
}
function buildUnsubscribeHeaders(workflow: string, subscriberId: string): Record<string, string> {
if (NO_UNSUBSCRIBE_WORKFLOWS.has(workflow)) return {};
const targets: string[] = [];
if (UNSUBSCRIBE_URL_BASE && UNSUBSCRIBE_SECRET) {
const token = createHmac("sha256", UNSUBSCRIBE_SECRET)
.update(`${subscriberId}|${workflow}`)
.digest("hex");
const q = new URLSearchParams({ u: subscriberId, w: workflow, t: token });
targets.push(`<${UNSUBSCRIBE_URL_BASE}?${q.toString()}>`);
}
const httpsUrl = buildUnsubscribeUrl(workflow, subscriberId);
if (httpsUrl) targets.push(`<${httpsUrl}>`);
targets.push(
`<mailto:${UNSUBSCRIBE_EMAIL}?subject=unsubscribe%3A${encodeURIComponent(workflow)}>`,
);
const headers: Record<string, string> = { "List-Unsubscribe": targets.join(", ") };
// RFC 8058 one-click — only assert when an HTTPS endpoint is wired; Gmail
// will probe the HTTPS target with POST when this header is present, so
// gate it behind both env vars being set.
if (UNSUBSCRIBE_URL_BASE && UNSUBSCRIBE_SECRET) {
// will probe the HTTPS target with POST when this header is present.
if (httpsUrl) {
headers["List-Unsubscribe-Post"] = "List-Unsubscribe=One-Click";
}
return headers;
@@ -176,7 +186,14 @@ export async function triggerNovu(
// Postal only AFTER the host-side Novu NodemailerProvider patch is applied —
// see postal/novu-patches/apply-headers-patch.sh.
const unsubHeaders = buildUnsubscribeHeaders(name, to.subscriberId);
const body: Record<string, unknown> = { name, to, payload };
// Visible body-footer variant of the same link — templates render it via
// `{{#if unsubscribeUrl}}` so mails stay valid when the secret is unset.
const unsubscribeUrl = buildUnsubscribeUrl(name, to.subscriberId);
const fullPayload =
unsubscribeUrl && payload.unsubscribeUrl === undefined
? { ...payload, unsubscribeUrl }
: payload;
const body: Record<string, unknown> = { name, to, payload: fullPayload };
if (Object.keys(unsubHeaders).length > 0) {
body.overrides = { email: { headers: unsubHeaders } };
}

View File

@@ -113,6 +113,7 @@ const WORKFLOW_LABELS: Record<string, string> = {
referral: "Davet hatırlatması",
"referral-qualified": "Davet bildirimleri",
"referral-reward": "Ödül bildirimleri",
conversion: "Kampanya mailleri",
};
/**
@@ -141,7 +142,7 @@ function renderPage(ok: boolean, workflow: string): string {
<h1 style="font-size:20px;margin:22px 0 14px;">Abonelikten çıkıldı</h1>
<p style="color:#4a4a4a;line-height:1.6;">Artık <strong>${escapeHtml(label)}</strong> almayacaksın. Hesabınla ilgili önemli bilgilendirme mailleri (e-posta doğrulama, ödeme bildirimleri) gelmeye devam eder.</p>
<p style="color:#777;font-size:14px;margin-top:24px;">Fikrini değiştirirsen ayarlar &gt; bildirimler sayfasından geri açabilirsin.</p>
<p style="margin-top:22px;"><a href="https://sase.tr/dashboard/settings/notifications" style="display:inline-block;background:#111;color:#fff;text-decoration:none;padding:12px 26px;border-radius:8px;font-weight:600;">Ayarları aç</a></p>
<p style="margin-top:22px;"><a href="https://sase.tr/dashboard/settings?tab=notifications" style="display:inline-block;background:#111;color:#fff;text-decoration:none;padding:12px 26px;border-radius:8px;font-weight:600;">Ayarları aç</a></p>
</main></body>`;
}

View File

@@ -6,10 +6,13 @@ import {
brandCompatible,
computeStats,
filterOffersForBrand,
isOeSupplyLabel,
istanbulToday,
normPartCode,
oeFamilyOf,
percentile,
reconstructDailySeries,
selectOeOffers,
} from "./part-prices.logic";
describe("normPartCode", () => {
@@ -174,17 +177,139 @@ describe("filterOffersForBrand", () => {
expect(filterOffersForBrand(offers, "", "27155")).toEqual([]);
});
it("uzun kodda markasız istek tüm teklifleri kullanır (OE vakası)", () => {
const oe = [
{ brandNorm: "MAIS", price: 195 },
{ brandNorm: "RENAULT", price: 247 },
it("uzun kodda markasız istek YALNIZ orijinal teklifleri kullanır", () => {
// 2026-07-14 vakası: orijinal+yan sanayi tek havuzda "hayalet medyan"
// üretiyordu (9827622780 → 4.495₺, hiçbir satıcının fiyatı değil).
// kokpit tur'una göre MAIS+OPAR orijinal; SAGEMFRANS/FEBI değil.
const mixed = [
{ brandNorm: "MAIS", price: 245 },
{ brandNorm: "OPAR", price: 247 },
{ brandNorm: "SAGEMFRANS", price: 210 },
{ brandNorm: "FEBI", price: 160 },
];
expect(filterOffersForBrand(oe, "", "8200768913")).toHaveLength(2);
const out = filterOffersForBrand(mixed, "", "8200768913");
expect(out.map((o) => o.brandNorm).sort()).toEqual(["MAIS", "OPAR"]);
});
it("uzun kod + uyumsuz marka etiketi → dağıtıcı fallback'i (tümü)", () => {
const oe = [{ brandNorm: "MAIS", price: 195 }];
expect(filterOffersForBrand(oe, "RENAULT", "8200768913")).toHaveLength(1);
it("markasız istekte hiç orijinal teklif yoksa boş (yan sanayi OE gibi gösterilmez)", () => {
const amOnly = [{ brandNorm: "BRUCKE", price: 890 }];
expect(filterOffersForBrand(amOnly, "", "46456072")).toEqual([]);
});
it("araç markası → SADECE o markanın OE ailesi (PSA vs OPAR ayrışır)", () => {
// 9827622780 vakası: aynı koda PSA (Peugeot ailesi) ve OPAR (Fiat ailesi)
// düşüyor. Peugeot kodu istenince yalnız PSA gelir, OPAR elenir → medyan
// artık iki dağıtıcının ortası (hayalet) değil.
const mixed = [
{ brandNorm: "PSA", price: 5531 },
{ brandNorm: "OPAR", price: 3459 },
{ brandNorm: "FEBI", price: 900 },
];
expect(filterOffersForBrand(mixed, "PEUGEOT", "9827622780")).toEqual([
{ brandNorm: "PSA", price: 5531 },
]);
// Aynı kod Fiat aracından istenirse OPAR gelir.
expect(filterOffersForBrand(mixed, "FIAT", "9827622780")).toEqual([
{ brandNorm: "OPAR", price: 3459 },
]);
});
it("araç markası dağıtıcı etiketine eşlenir (RENAULT → MAIS), yan sanayi elenir", () => {
const oe = [
{ brandNorm: "MAIS", price: 195 },
{ brandNorm: "FEBI", price: 90 },
{ brandNorm: "OPAR", price: 210 }, // farklı aile → elenir
];
expect(filterOffersForBrand(oe, "RENAULT", "8200768913")).toEqual([
{ brandNorm: "MAIS", price: 195 },
]);
});
it("araç markası + jenerik ORJINAL → elenir (aile belirsiz)", () => {
const oe = [
{ brandNorm: "PSA", price: 5531 },
{ brandNorm: "ORJINAL", price: 111 },
];
expect(filterOffersForBrand(oe, "CITROEN", "9827622780")).toEqual([
{ brandNorm: "PSA", price: 5531 },
]);
});
it("yan sanayi markası çipi → yalnız etiketi uyumlular, OE'ye düşmez", () => {
const oe = [
{ brandNorm: "MAIS", price: 195 },
{ brandNorm: "FEBI", price: 160 },
];
// FEBI çipi FEBI'yi alır; MAIS (orijinal) gösterilmez.
expect(filterOffersForBrand(oe, "FEBIBILSTEIN", "8200768913")).toEqual([
{ brandNorm: "FEBI", price: 160 },
]);
});
});
describe("isOeSupplyLabel / selectOeOffers (OE aileleri + jenerik ORJINAL)", () => {
it("dağıtıcı ve orijinal etiketleri tanır", () => {
expect(isOeSupplyLabel("MAIS")).toBe(true); // Renault dağıtıcısı
expect(isOeSupplyLabel("OPAR")).toBe(true); // Fiat/Tofaş
expect(isOeSupplyLabel("PSA")).toBe(true);
expect(isOeSupplyLabel("ORJINAL")).toBe(true); // jenerik orijinal
expect(isOeSupplyLabel("VECO")).toBe(true); // Iveco OE alias'ı
});
it("ham araç-marka etiketleri de ORİJİNALDİR (kokpit'in yansanayi demesi yanlış)", () => {
// 2026-07-14 kullanıcı düzeltmesi: FORD/GM/BMW/Mercedes/VW OE etiketidir.
expect(isOeSupplyLabel("FORD")).toBe(true);
expect(isOeSupplyLabel("GM")).toBe(true); // Opel OE'si
expect(isOeSupplyLabel("BMW")).toBe(true);
expect(isOeSupplyLabel("MERCEDES")).toBe(true);
expect(isOeSupplyLabel("VOLKSWAGEN")).toBe(true);
expect(isOeSupplyLabel("RENAULT")).toBe(true);
});
it("gerçek yan sanayi PARÇA markaları orijinal DEĞİL", () => {
expect(isOeSupplyLabel("BOSCH")).toBe(false);
expect(isOeSupplyLabel("FEBI")).toBe(false);
expect(isOeSupplyLabel("VALEO")).toBe(false);
expect(isOeSupplyLabel("TRW")).toBe(false);
expect(isOeSupplyLabel("")).toBe(false);
});
it("GM Opel ailesine, FORD kendi ailesine eşlenir", () => {
expect(oeFamilyOf("GM")).toBe("OPEL");
expect(oeFamilyOf("FORD")).toBe("FORD");
expect(oeFamilyOf("MERCEDES")).toBe("MERCEDES");
});
it("selectOeOffers karma havuzdan orijinalleri (araç markaları dahil) seçer", () => {
const out = selectOeOffers([
{ brandNorm: "OPAR", price: 767 },
{ brandNorm: "FORD", price: 480 }, // artık orijinal
{ brandNorm: "IBR", price: 909 }, // İbraş = yan sanayi
]);
expect(out.map((o) => o.brandNorm).sort()).toEqual(["FORD", "OPAR"]);
});
it("Ford kodu araç markası FORD → FORD teklifi gelir", () => {
const offers = [
{ brandNorm: "FORD", price: 480 },
{ brandNorm: "BOSCH", price: 300 },
];
expect(filterOffersForBrand(offers, "FORD", "1234567890")).toEqual([
{ brandNorm: "FORD", price: 480 },
]);
});
it("Opel kodu → OPEL + GM aynı aile, ikisi de gelir; PSA farklı aile elenir", () => {
const offers = [
{ brandNorm: "GM", price: 500 },
{ brandNorm: "OPEL", price: 520 },
{ brandNorm: "PSA", price: 610 },
];
expect(
filterOffersForBrand(offers, "OPEL", "9827622780")
.map((o) => o.brandNorm)
.sort(),
).toEqual(["GM", "OPEL"]);
});
});

View File

@@ -31,6 +31,104 @@ export function normPartCode(code: string): string {
// süzülür. Tedarikçiler markayı kısaltarak yazar (BCH/B→Bosch, BLP→Blue
// Print, IBR→İbraş) — eşleşme önek VEYA sıralı-altdizi ile yapılır.
// ─── Orijinal (OE) etiketleri ve marka aileleri ────────────────────────────
// Markasız/araç-markalı bağlam (OEM detay kartı) yalnız ORİJİNAL teklifleri
// gösterir: orijinal + yan sanayi tek havuzda medyanlanınca hiçbir gerçek
// ürünün fiyatı olmayan "hayalet fiyat" çıkar (2026-07-14: 9827622780 →
// 4.495₺ = PSA 5.531 ile OPAR 3.459'un ortası).
//
// Bir OEM kodu tek bir araç markasına aittir → teklifleri o markanın OE
// ailesine süzeriz (aynı koda düşen PSA vs OPAR karışmaz). `family → üyeler`;
// üyeler hem araç markası adları (istek/sase brands) hem dağıtıcı etiketleridir
// (teklif/takip: MAIS=Renault, OPAR=Fiat, PSA, VECO=Iveco, GM=Opel).
//
// ORİJİNAL TESPİTİ: bir teklif etiketi orijinal sayılır ancak bir OE ailesinin
// üyesiyse ya da jenerik "ORJINAL" ise. Kaynak = sase araç markaları + Türkiye
// OE-dağıtıcı etiketleri. NOT (2026-07-14 kullanıcı düzeltmesi): ham araç-marka
// etiketleri (FORD, GM, BMW, MERCEDES, VOLKSWAGEN, RENAULT, FIAT…) ORİJİNALDİR
// — kokpit `tur` bunları 'yansanayi' sayıyordu, bu YANLIŞ; burada aileleriyle
// birlikte orijinal kabul edilir. Gerçek yan sanayi PARÇA markaları (Bosch/
// Febi/Valeo/TRW…) hiçbir ailede değildir → orijinal sayılmaz.
const OE_FAMILIES: Readonly<Record<string, readonly string[]>> = {
RENAULT: ["RENAULT", "DACIA", "ALPINE", "MAIS"],
FIAT: ["FIAT", "ALFAROMEO", "LANCIA", "ABARTH", "OPAR", "TOFAS"],
PSA: ["PEUGEOT", "CITROEN", "DS", "PSA"],
OPEL: ["OPEL", "VAUXHALL", "GM"], // GM = General Motors, TR'de Opel OE'si
VAG: ["VOLKSWAGEN", "VW", "AUDI", "SEAT", "SKODA", "CUPRA", "BENTLEY"],
FORD: ["FORD"],
BMW: ["BMW", "MINI"],
MERCEDES: ["MERCEDESBENZ", "MERCEDES", "SMART"],
TOYOTA: ["TOYOTA", "TOYOTAORJINAL", "LEXUS"],
HONDA: ["HONDA"],
NISSAN: ["NISSAN", "INFINITI"],
HYUNDAI: ["HYUNDAI"],
KIA: ["KIA"],
MAZDA: ["MAZDA"],
VOLVO: ["VOLVO", "POLESTAR"],
PORSCHE: ["PORSCHE"],
JLR: ["JAGUAR", "LANDROVER"],
MAN: ["MAN"],
MITSUBISHI: ["MITSUBISHI"],
SUBARU: ["SUBARU"],
SUZUKI: ["SUZUKI"],
IVECO: ["IVECO", "VECO", "OEVECO"],
// sase araç listesinde olmayan ama teklif/istek olarak gelebilecek markalar.
CHRYSLER: ["CHRYSLER", "DODGE", "JEEP", "MOPAR", "LINCOLN", "BUICK"],
CHEVROLET: ["CHEVROLET"],
DAEWOO: ["DAEWOO"],
DAIHATSU: ["DAIHATSU"],
DFM: ["DFM"],
LADA: ["LADA"],
PROTON: ["PROTON"],
ROVER: ["ROVER", "RANGE"],
SAAB: ["SAAB"],
SSANGYONG: ["SSANGYONG"],
TATA: ["TATA"],
TESLA: ["TESLA"],
TOGG: ["TOGG"],
};
const OE_FAMILY_OF: ReadonlyMap<string, string> = new Map(
Object.entries(OE_FAMILIES).flatMap(([family, members]) =>
members.map((m) => [m, family] as [string, string]),
),
);
/** Markanın (araç ya da dağıtıcı etiketi) OE ailesi; bilinmiyorsa null.
* Jenerik "ORJINAL" hiçbir aileye ait değildir (markası belirsiz) → null. */
export function oeFamilyOf(brandNorm: string): string | null {
return OE_FAMILY_OF.get(brandNorm) ?? null;
}
// Orijinal etiket seti = tüm OE aile üyeleri + jenerik "ORJINAL" (orijinal ama
// aile-belirsiz: markasız/taban görünümde sayılır, aile filtresinde elenir).
// Aileden TÜRETİLİR → OE-tespiti ile aile-filtresi asla drift etmez; yeni bir
// marka eklemek için tek yer OE_FAMILIES.
const OE_SUPPLY_LABELS: ReadonlySet<string> = new Set([
...Object.values(OE_FAMILIES).flat(),
"ORJINAL",
]);
/** Teklifin etiketi orijinal mi (bir OE ailesinin üyesi ya da jenerik ORJINAL). */
export function isOeSupplyLabel(brandNorm: string): boolean {
return OE_SUPPLY_LABELS.has(brandNorm);
}
/** Yalnız orijinal (OE) etiketli teklifler. */
export function selectOeOffers<T extends { brandNorm: string }>(offers: T[]): T[] {
return offers.filter((o) => isOeSupplyLabel(o.brandNorm));
}
// ─── Redis cache anahtarları ───────────────────────────────────────────────
// Service ve worker processor'ı AYNI üreticileri kullanır (literal kopya
// drift'i olmasın). v4 = OE seti araç-marka etiketlerini (FORD/GM/BMW/MERCEDES/
// VW…) de kapsayacak şekilde genişledi → v3'teki "miss" değerleri bayat.
export const PART_PRICE_CACHE_VERSION = "v4";
export const partPriceSeriesCacheKey = (codeNorm: string, brandNorm: string) =>
`partprice:series:${PART_PRICE_CACHE_VERSION}:${codeNorm}::${brandNorm}`;
export const partPriceCurrentCacheKey = (codeNorm: string, brandNorm: string) =>
`partprice:cur:${PART_PRICE_CACHE_VERSION}:${codeNorm}::${brandNorm}`;
/** a'nın tüm karakterleri b içinde aynı sırayla geçiyor mu (BCH ⊂ BOSCH). */
export function inOrderSubsequence(a: string, b: string): boolean {
let i = 0;
@@ -61,10 +159,17 @@ export function allowBrandless(codeNorm: string): boolean {
/**
* Teklifleri istenen markaya süz:
* - marka istendi → uyumlular; hiçbiri uymuyorsa ve kod markasız-güvenliyse
* hepsi (OE/dağıtıcı etiketi vakası: RENAULT istenir, teklifler MAIS taşır);
* kısa kodda boş (yanlış veri göstermekten iyidir),
* - marka istenmedi → kod markasız-güvenliyse hepsi, değilse boş.
* - istenen marka bir ARAÇ/OE markasıysa (OEM kartına o kodun araç markası
* geçer, ör. PEUGEOT) → yalnız o markanın OE ailesinden orijinal teklifler
* (PEUGEOT → PSA ailesi; OPAR/MAIS gibi başka aile dağıtıcıları elenir).
* Böylece aynı koda düşen PSA vs OPAR karışıp medyanı bozmaz. Jenerik
* "ORJINAL" (aile belirsiz) bu süzgeçte elenir,
* - istenen marka bir YAN SANAYİ markasıysa (FEBI çipi) → etiketi uyumlu
* teklifler (kısaltma/önek eşleşmesi); OE'ye düşme YOK,
* - marka istenmedi (kodun markası bilinmiyor) → yalnız orijinal (tüm OE
* aileleri) — güvenli taban; yan sanayi karışımı hayalet medyan üretirdi,
* - kısa/çakışmaya açık kodlarda (allowBrandless=false) araç-markası ve
* markasız yolları kapalıdır (yanlış veri göstermekten iyidir).
*/
export function filterOffersForBrand<T extends { brandNorm: string }>(
offers: T[],
@@ -72,11 +177,17 @@ export function filterOffersForBrand<T extends { brandNorm: string }>(
codeNorm: string,
): T[] {
if (requestedBrandNorm) {
const compat = offers.filter((o) => brandCompatible(o.brandNorm, requestedBrandNorm));
if (compat.length > 0) return compat;
return allowBrandless(codeNorm) ? offers : [];
const family = oeFamilyOf(requestedBrandNorm);
if (family) {
if (!allowBrandless(codeNorm)) return [];
return offers.filter(
(o) => isOeSupplyLabel(o.brandNorm) && oeFamilyOf(o.brandNorm) === family,
);
}
// Aile eşlemesi yok → yan sanayi markası: etiket uyumuna göre süz.
return offers.filter((o) => brandCompatible(o.brandNorm, requestedBrandNorm));
}
return allowBrandless(codeNorm) ? offers : [];
return allowBrandless(codeNorm) ? selectOeOffers(offers) : [];
}
export interface SupplierOffer {

View File

@@ -17,6 +17,8 @@ import {
filterOffersForBrand,
istanbulToday,
normPartCode,
partPriceCurrentCacheKey,
partPriceSeriesCacheKey,
reconstructDailySeries,
} from "./part-prices.logic";
import { type SupplierPriceSource, createSupplierPriceSource } from "./supplier-price-source";
@@ -54,10 +56,8 @@ const BATCH_CACHE_TTL = 1800;
const MAX_BATCH_PARTS = 400;
export const partPriceKey = (codeNorm: string, brandNorm: string) => `${codeNorm}::${brandNorm}`;
const seriesKey = (codeNorm: string, brandNorm: string) =>
`partprice:series:v2:${codeNorm}::${brandNorm}`;
const currentKey = (codeNorm: string, brandNorm: string) =>
`partprice:cur:v2:${codeNorm}::${brandNorm}`;
const seriesKey = partPriceSeriesCacheKey;
const currentKey = partPriceCurrentCacheKey;
/**
* Parça (kod + marka) bazlı tedarikçi fiyat görünümleri. P-servisi sözleşmesi:
@@ -67,7 +67,8 @@ const currentKey = (codeNorm: string, brandNorm: string) =>
* Kimlik (kod, marka): kısa sayısal kodlar markalar arası çakışır (FEBI 27155
* ≠ GROS 27155 ≠ İBRAŞ 27155 — farklı fiziksel parçalar). Teklifler sku_map'in
* marka etiketiyle istenen markaya süzülür (filterOffersForBrand); markasız
* sorgu yalnızca uzun/benzersiz kodlarda tüm teklifleri kullanır.
* sorgu (OEM detay ana kartı) yalnızca ORİJİNAL (OE/dağıtıcı) teklifleri
* kullanır — orijinal+yan-sanayi havuzu hayalet medyan üretir (2026-07-14).
*
* - Seri: parça ilk kez istendiğinde takip history'sinden lazy-backfill edilir
* ve pg'ye (part_price_tracks + part_price_daily) kalıcı yazılır; sonraki

View File

@@ -147,13 +147,15 @@ export class PartsService {
* Reverse catalog: the user's own decoded vehicles whose parts list contains
* this exact OEM code. Powers the "bu kod kataloğunuzda şu araçlarda var"
* section of the OEM detail page — pure sase data, no TecDoc/vehicle-structure
* dependency. Exact match on the indexed `oem_code` (the code came from a real
* part row, so the spelling matches). One representative `categoryId` per
* vehicle lets the UI deep-link straight to a schema page showing the part.
* dependency. NORMALIZE-eşleşme: URL kodu boşluksuz ("9827622780") gelirken
* katalog aynı kodu boşluklu saklayabilir ("9827 622 780" — özellikle PSA);
* exact match bunları kaçırıyordu (fiyat kartı marka çözümü de buna dayanır).
* `parts_oem_code_norm_idx` functional index'iyle aynı ifade → index kullanır.
* Vitrin `categoryId`'si UI'ı doğrudan şema sayfasına götürür.
*/
async vehiclesByOem(oemCode: string) {
const code = (oemCode ?? "").trim();
if (!code) return [];
const norm = (oemCode ?? "").toUpperCase().replace(/[^A-Z0-9]/g, "");
if (!norm) return [];
return this.db
.select({
vehicleId: vehicles.id,
@@ -165,7 +167,7 @@ export class PartsService {
})
.from(parts)
.innerJoin(vehicles, eq(parts.vehicleId, vehicles.id))
.where(eq(parts.oemCode, code))
.where(sql`regexp_replace(upper(${parts.oemCode}), '[^A-Z0-9]', '', 'g') = ${norm}`)
.groupBy(vehicles.id, vehicles.brandName, vehicles.model, vehicles.year)
.orderBy(vehicles.brandName, vehicles.model)
.limit(50);

View File

@@ -163,16 +163,26 @@ describe("StripeService recurring webhooks", () => {
});
describe("handleInvoiceFailed", () => {
it("mails dunning with Stripe's retry date and leaves the paid-through date alone", async () => {
it("persists dunning state, mails with retry date + hosted invoice URL, leaves end_date alone", async () => {
// selects: resolve sub → user
const { service, db, posthog, novu } = createMocks([[activeSub], [user]]);
const { service, db, updateChains, posthog, novu } = createMocks([[activeSub], [user]]);
await service.handleInvoiceFailed(invoiceFixture());
await service.handleInvoiceFailed(
invoiceFixture({ attempt_count: 1, hosted_invoice_url: "https://invoice.stripe.com/i/x" }),
);
// dunning stamped (so /subscriptions/me + banner can surface it) — but
// end_date untouched: access keeps running to the paid-through date.
expect(db.update).toHaveBeenCalledTimes(1);
const setArg = updateChains[0].set.mock.calls[0][0] as Record<string, unknown>;
expect(setArg.dunningSince).toBeInstanceOf(Date);
expect(setArg.dunningInvoiceUrl).toBe("https://invoice.stripe.com/i/x");
expect(setArg.endDate).toBeUndefined();
expect(db.update).not.toHaveBeenCalled(); // access keeps running to end_date
expect(novu.paymentFailed).toHaveBeenCalledTimes(1);
const opts = novu.paymentFailed.mock.calls[0][1] as { retryDate?: Date };
const opts = novu.paymentFailed.mock.calls[0][1] as { retryDate?: Date; invoiceUrl?: string };
expect(opts.retryDate?.getTime()).toBe(RETRY_AT_SEC * 1000);
expect(opts.invoiceUrl).toBe("https://invoice.stripe.com/i/x");
expect(posthog.captureForUser).toHaveBeenCalledWith(
"user-1",
"payment_failed",
@@ -180,6 +190,28 @@ describe("StripeService recurring webhooks", () => {
);
});
it("suppresses the mail on non-milestone attempts but still records the failure", async () => {
const { service, db, posthog, novu } = createMocks([[activeSub], [user]]);
await service.handleInvoiceFailed(invoiceFixture({ attempt_count: 2 }));
expect(db.update).toHaveBeenCalledTimes(1); // dunning state still stamped
expect(posthog.captureForUser).toHaveBeenCalledTimes(1);
expect(novu.paymentFailed).not.toHaveBeenCalled(); // attempt 2 ≠ 1/3/final
});
it("sends the final notice when Stripe schedules no further retry", async () => {
const { service, novu } = createMocks([[activeSub], [user]]);
await service.handleInvoiceFailed(
invoiceFixture({ attempt_count: 7, next_payment_attempt: null }),
);
expect(novu.paymentFailed).toHaveBeenCalledTimes(1);
const opts = novu.paymentFailed.mock.calls[0][1] as { retryDate?: Date | null };
expect(opts.retryDate).toBeNull();
});
it("ignores first-charge failures (checkout flow owns those)", async () => {
const { service, posthog, novu } = createMocks([[activeSub]]);

View File

@@ -634,17 +634,24 @@ export class StripeService {
if (!recovered) {
// Normal renewal — extend. A 'cancelled' row that still got billed keeps
// its status; access is governed by end_date either way.
// its status; access is governed by end_date either way. A paid invoice
// also ends any dunning episode.
await this.db
.update(userSubscriptions)
.set({ endDate: newEndDate, updatedAt: now })
.set({ endDate: newEndDate, dunningSince: null, dunningInvoiceUrl: null, updatedAt: now })
.where(eq(userSubscriptions.id, sub.id));
} else {
// Late dunning recovery: the nightly cron already expired the row and
// purged its brand grants. Restore access for the freshly paid period.
await this.db
.update(userSubscriptions)
.set({ status: "active", endDate: newEndDate, updatedAt: now })
.set({
status: "active",
endDate: newEndDate,
dunningSince: null,
dunningInvoiceUrl: null,
updatedAt: now,
})
.where(eq(userSubscriptions.id, sub.id));
if (plan?.brandCount === 0) {
await this.db.delete(userBrands).where(eq(userBrands.subscriptionId, sub.id));
@@ -745,6 +752,19 @@ export class StripeService {
const retryDate = invoice.next_payment_attempt
? new Date(invoice.next_payment_attempt * 1000)
: null;
const hostedUrl = invoice.hosted_invoice_url ?? null;
// Persist the dunning episode so /subscriptions/me (and the dashboard
// banner) can surface it — before this, the app had no record that a
// subscription was failing and the user saw nothing until hard cutoff.
await this.db
.update(userSubscriptions)
.set({
dunningSince: sub.dunningSince ?? new Date(),
...(hostedUrl ? { dunningInvoiceUrl: hostedUrl } : {}),
updatedAt: new Date(),
})
.where(eq(userSubscriptions.id, sub.id));
this.posthog.captureForUser(sub.userId, "payment_failed", {
method: "stripe",
@@ -752,28 +772,42 @@ export class StripeService {
reason: "renewal_charge_failed",
amount: invoice.amount_due ?? null,
stripe_invoice_id: invoice.id,
attempt_count: invoice.attempt_count ?? null,
next_retry_at: retryDate ? retryDate.toISOString() : null,
});
try {
const [user] = await this.db
.select({ id: users.id, email: users.email, name: users.name })
.from(users)
.where(eq(users.id, sub.userId))
.limit(1);
if (user) {
await this.novu.paymentFailed(user, {
amountKurus: invoice.amount_due ?? undefined,
retryDate,
});
// Mail on milestones only — first failure, mid-cycle nudge, final notice.
// Stripe retries ~4-9 times; one identical mail per attempt trained users
// to ignore them (measured recovery: 0%).
const attempt = invoice.attempt_count ?? 1;
const isFinal = !invoice.next_payment_attempt;
const shouldMail = attempt <= 1 || attempt === 3 || isFinal;
if (shouldMail) {
try {
const [user] = await this.db
.select({ id: users.id, email: users.email, name: users.name })
.from(users)
.where(eq(users.id, sub.userId))
.limit(1);
if (user) {
await this.novu.paymentFailed(user, {
amountKurus: invoice.amount_due ?? undefined,
retryDate,
// CTA goes to Stripe's hosted invoice page (pay now / new card /
// 3DS) — the dashboard has no self-serve payment surface.
invoiceUrl: hostedUrl,
});
}
} catch (err) {
this.logger.error(`renewal dunning mail failed (user=${sub.userId}): ${String(err)}`);
}
} catch (err) {
this.logger.error(`renewal dunning mail failed (user=${sub.userId}): ${String(err)}`);
}
this.logger.warn(
`Renewal charge failed: sub ${sub.id} (invoice ${invoice.id}), ` +
`next retry ${retryDate ? retryDate.toISOString() : "none (final)"}`,
`Renewal charge failed: sub ${sub.id} (invoice ${invoice.id}, attempt ${attempt}), ` +
`next retry ${retryDate ? retryDate.toISOString() : "none (final)"}` +
`${shouldMail ? "" : " — mail suppressed (non-milestone attempt)"}`,
);
}
@@ -790,14 +824,35 @@ export class StripeService {
.limit(1);
if (!sub) return;
const wasDunning = !!sub.dunningSince;
// Flip to 'cancelled' (not just stamp cancelledAt): create() rejects new
// checkouts only while a row is 'active', so leaving a dunning-cancelled
// sub as 'active' silently BLOCKED the customer from re-subscribing — one
// of the root causes of 0% dunning recovery. Access still runs to end_date
// via the nightly expiry cron.
await this.db
.update(userSubscriptions)
.set({ cancelledAt: sub.cancelledAt ?? new Date(), updatedAt: new Date() })
.set({
status: "cancelled",
cancelledAt: sub.cancelledAt ?? new Date(),
dunningSince: null,
dunningInvoiceUrl: null,
updatedAt: new Date(),
})
.where(eq(userSubscriptions.id, sub.id));
this.logger.log(
`Stripe subscription ${subscription.id} deleted — our sub ${sub.id} ` +
`(status=${sub.status}) will not renew; access runs out at its end_date`,
// Churn was previously invisible in analytics (this handler captured
// nothing) — reason distinguishes dunning losses from voluntary cancels.
this.posthog.captureForUser(sub.userId, "subscription_churned", {
reason: wasDunning ? "payment_failure" : "cancelled",
subscription_id: sub.id,
stripe_subscription_id: subscription.id,
prior_status: sub.status,
});
this.logger.warn(
`Stripe subscription ${subscription.id} deleted (${wasDunning ? "dunning exhausted" : "cancel executed"}) — ` +
`our sub ${sub.id} → cancelled; access runs out at its end_date`,
);
}

View File

@@ -1,6 +1,11 @@
import { BadRequestException, ForbiddenException, NotFoundException } from "@nestjs/common";
import { beforeEach, describe, expect, it, vi } from "vitest";
import { catalogVehicles, queryLogs, vinpinDecodes } from "../database/schema/core";
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import {
catalogVehicles,
queryLogs,
rpartstoreDecodes,
vinpinDecodes,
} from "../database/schema/core";
import { VehiclesService } from "./vehicles.service";
vi.mock("@sase/shared", () => ({
@@ -93,10 +98,15 @@ function createService(dbOrOverrides: any = {}) {
add: vi.fn().mockResolvedValue(undefined),
};
const rpartstoreQueue = {
add: vi.fn().mockResolvedValue(undefined),
};
const service = new VehiclesService(
db as any,
prefetchQueue as any,
vinpinQueue as any,
rpartstoreQueue as any,
corgiService as any,
pl24Service as any,
vinApiService as any,
@@ -115,6 +125,7 @@ function createService(dbOrOverrides: any = {}) {
partsCatalogsService,
redisService,
vinpinQueue,
rpartstoreQueue,
};
}
@@ -340,9 +351,7 @@ describe("VehiclesService", () => {
selectChain.limit = vi
.fn()
.mockImplementation(() =>
currentTable === vinpinDecodes
? [{ vin: "NM435600006123456", status: "pending" }]
: [],
currentTable === vinpinDecodes ? [{ vin: "NM435600006123456", status: "pending" }] : [],
);
const insertChain = {
values: vi.fn().mockReturnThis(),
@@ -992,3 +1001,168 @@ describe("VehiclesService", () => {
});
});
});
describe("VehiclesService — RPartStore fallback (Renault/Dacia, after the pcat/PL24/emex race)", () => {
const VIN = "VF1RFE00653633190";
function noCatalogDb() {
const selectChain = {
from: vi.fn().mockReturnThis(),
where: vi.fn().mockReturnThis(),
limit: vi.fn().mockReturnValue([]),
};
const insertChain = {
values: vi.fn().mockReturnThis(),
returning: vi.fn().mockReturnValue([]),
onConflictDoNothing: vi.fn().mockReturnThis(),
};
return {
select: vi.fn().mockReturnValue(selectChain),
insert: vi.fn().mockReturnValue(insertChain),
};
}
function renaultIdent(svc: ReturnType<typeof createService>) {
svc.corgiService.decodeVin.mockReturnValue({
isKnown: true,
brandName: "Renault",
modelYear: 2015,
});
svc.vinApiService.decodeVin.mockResolvedValue({
make: "RENAULT",
model: "Kadjar",
modelYear: "2015",
});
}
let prevRparts: string | undefined;
let prevVinpin: string | undefined;
beforeEach(() => {
prevRparts = process.env.RPARTSTORE_ENABLED;
prevVinpin = process.env.VINPIN_ENABLED;
process.env.VINPIN_ENABLED = "false";
vi.mocked(isValidVin).mockReturnValue(true);
});
afterEach(() => {
process.env.RPARTSTORE_ENABLED = prevRparts ?? "false";
process.env.VINPIN_ENABLED = prevVinpin ?? "false";
});
it("[off] leaves the no-catalog path untouched and never touches the queue", async () => {
process.env.RPARTSTORE_ENABLED = "false";
const db = noCatalogDb();
const svc = createService(db);
renaultIdent(svc);
const result: any = await svc.service.decodeVin(VIN, "u1");
expect(result).toMatchObject({ noCatalog: { brandName: "Renault" }, vin: VIN });
expect(svc.rpartstoreQueue.add).not.toHaveBeenCalled();
expect(db.insert.mock.calls.some((c: unknown[]) => c[0] === rpartstoreDecodes)).toBe(false);
});
it("[on] records a pending row, enqueues a day-scoped job and answers `decoding` for an unseen Renault VIN", async () => {
process.env.RPARTSTORE_ENABLED = "true";
const db = noCatalogDb();
const svc = createService(db);
renaultIdent(svc);
const result: any = await svc.service.decodeVin(VIN, "u1");
expect(result).toMatchObject({ decoding: { vin: VIN }, vin: VIN });
expect(result.decoding.display).toContain("Renault");
expect(svc.rpartstoreQueue.add).toHaveBeenCalledTimes(1);
const [name, data, opts] = svc.rpartstoreQueue.add.mock.calls[0];
expect(name).toBe("rpartstore-decode");
expect(data).toEqual({ vin: VIN });
expect(opts.jobId).toMatch(new RegExp(`^rpartstore-${VIN}-\\d{4}-\\d{2}-\\d{2}$`));
expect(db.insert.mock.calls.some((c: unknown[]) => c[0] === rpartstoreDecodes)).toBe(true);
// Exactly ONE coverage-gap failure row at first sighting.
expect(db.insert.mock.calls.filter((c: unknown[]) => c[0] === queryLogs)).toHaveLength(1);
// Vinpin (disabled) is never consulted.
expect(svc.vinpinQueue.add).not.toHaveBeenCalled();
});
it("[on] does not enqueue a non-Renault VIN", async () => {
process.env.RPARTSTORE_ENABLED = "true";
const db = noCatalogDb();
const svc = createService(db);
svc.corgiService.decodeVin.mockReturnValue({
isKnown: true,
brandName: "Fiat",
modelYear: 2018,
});
svc.vinApiService.decodeVin.mockResolvedValue({
make: "FIAT",
model: "Tipo",
modelYear: "2018",
});
const result: any = await svc.service.decodeVin("NM435600006123456", "u1");
expect(result).toMatchObject({ noCatalog: { brandName: "Fiat" } });
expect(svc.rpartstoreQueue.add).not.toHaveBeenCalled();
});
it("[on] falls through to noCatalog without queueing once today's cap is spent", async () => {
process.env.RPARTSTORE_ENABLED = "true";
process.env.RPARTSTORE_DAILY_CAP = "10";
const db = noCatalogDb();
const svc = createService(db);
renaultIdent(svc);
svc.redisService.get.mockImplementation(async (key: string) =>
key.startsWith("rpartstore:daily:") ? "10" : null,
);
const result: any = await svc.service.decodeVin(VIN, "u1");
expect(result).toMatchObject({ noCatalog: { brandName: "Renault" } });
expect(svc.rpartstoreQueue.add).not.toHaveBeenCalled();
expect(db.insert.mock.calls.some((c: unknown[]) => c[0] === rpartstoreDecodes)).toBe(false);
process.env.RPARTSTORE_DAILY_CAP = "";
});
it("[on] a decoded row with a catalog match answers `catalogVehicle` and logs one success row", async () => {
process.env.RPARTSTORE_ENABLED = "true";
const rpartsRow = {
vin: VIN,
status: "decoded",
catalogVehicleId: "cv-1",
createdAt: new Date(),
updatedAt: new Date(),
};
const cv = { id: "cv-1", brandId: null, brandName: "Renault", model: "KADJAR", year: null };
let selectCalls = 0;
const selectChain = {
from: vi.fn().mockReturnThis(),
where: vi.fn().mockReturnThis(),
limit: vi.fn().mockImplementation(() => {
// Call order inside decodeVin: vehicles lookup → rpartstore row → catalog vehicle.
selectCalls += 1;
if (selectCalls === 2) return [rpartsRow];
if (selectCalls === 3) return [cv];
return [];
}),
};
const insertChain = {
values: vi.fn().mockReturnThis(),
returning: vi.fn().mockReturnValue([]),
onConflictDoNothing: vi.fn().mockReturnThis(),
};
const db = {
select: vi.fn().mockReturnValue(selectChain),
insert: vi.fn().mockReturnValue(insertChain),
};
const svc = createService(db);
renaultIdent(svc);
const result: any = await svc.service.decodeVin(VIN, "u1");
expect(result).toEqual({
catalogVehicle: { id: "cv-1", brandName: "Renault", model: "KADJAR", year: null },
vin: VIN,
});
expect(svc.rpartstoreQueue.add).not.toHaveBeenCalled();
const logRows = db.insert.mock.calls.filter((c: unknown[]) => c[0] === queryLogs);
expect(logRows).toHaveLength(1);
expect(insertChain.values.mock.calls.at(-1)?.[0]).toMatchObject({
source: "rpartstore",
success: true,
});
});
});

Some files were not shown because too many files have changed in this diff Show More