Semih Yesilyurt 2583b781ec
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
feat(internal-admin): readonly impersonation for Süper Panel
Lets the founder open a target user's session in a new tab from the
panel for debugging. Read-only enforced server-side — any non-GET
request from an impersonated session returns 403.

Schema
- sessions.impersonated_by (uuid, nullable) — founder Better Auth user id
- sessions.impersonation_readonly (bool, default false)
- index on impersonated_by

Service
- ImpersonationService.createReadonlySession({ targetUserId, founderId,
  ttlMinutes, reason, ipAddress, userAgent }):
  - Random sessionId + token (32 bytes hex each)
  - TTL clamped 1..60 min, default 15
  - Refuses to impersonate admin users
  - Inserts sessions row; signs cookie value with HMAC-SHA256(BETTER_AUTH_SECRET)
    matching better-call's signCookieValue format
  - Returns { cookieName, cookieValue, expiresAt, sessionId }

Guard
- ImpersonationReadonlyGuard runs after AuthGuard, before RolesGuard.
- GET/HEAD/OPTIONS pass through.
- For other methods: looks up sessions.impersonated_by + impersonation_readonly
  by request.session.id; throws ForbiddenException if both truthy.

Endpoints (InternalAdminModule)
- POST /internal/admin/users/:id/impersonate-readonly [InternalTokenGuard]
  body: { ttlMinutes, reason, founderId }
  returns: { redirectUrl, expiresAt, sessionIdPrefix }
  Hand-off is via signed consume URL (cross-origin Set-Cookie limitations).
- GET /admin/impersonate/consume?t=<signed> [@Public]
  Verifies HMAC-signed payload (<=60s validity), sets the Better Auth session
  cookie on sase.tr, redirects to /. One-shot.

Wiring
- InternalAdminModule imported in AppModule.
- ImpersonationReadonlyGuard registered as APP_GUARD between Auth and Roles.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-18 00:48:39 +03:00
2026-02-12 00:26:34 +00:00

Sase

VIN/şase numarası sorgulama ve otomotiv yedek parça katalog platformu (Türkiye). Site: https://sase.tr · Staging: https://dev.sase.tr


Stack

Katman Teknoloji
Monorepo pnpm 10 + Turborepo
Backend NestJS 10, TypeScript 5.7, Node 22
DB PostgreSQL 17 + Drizzle ORM
Cache / Queue Redis 7 + BullMQ
Auth Better Auth (cookie session)
Frontend Vite 6, React 19, TanStack Router + Query
UI Tailwind v4, shadcn/ui (Radix)
Ödeme Stripe (kart)
Email Postal
Storage MinIO (S3)
Analitik PostHog
Test Vitest, Playwright
Deploy GitHub Actions → SSH → PM2

Yapı

ss/
├── apps/
│   ├── api/                NestJS (port 4000, /api)
│   └── web/                Vite + React (port 3000)
├── packages/
│   ├── shared/             Tipler, Zod şemaları
│   ├── config/             Env şeması (Zod)
│   └── ui/                 Paylaşılan shadcn bileşenleri
├── docker/                 docker-compose + nginx
├── scripts/                Deploy + bakım scriptleri
└── docs/                   Detay dökümantasyon (INDEX.md)

Komutlar

pnpm dev                    # tüm app'ler (Turbo)
pnpm build
pnpm test                   # Vitest
pnpm lint                   # Biome
pnpm typecheck

# DB (apps/api/)
pnpm db:push                # şemayı push
pnpm db:studio              # Drizzle Studio
pnpm db:generate            # migration üret

# Tek app
pnpm dev --filter=api
pnpm dev --filter=web

VIN Decode Akışı

Corgi (offline WMI) → PartsCatalogs API → PL24 API → EMEX scraper → NHTSA

Birden fazla araç eşleşmesi gelirse frontend seçim modalı gösterir.


Katalog Mimarisi

  • PL24 P5 Modern (REST/JSON) — VW Group, BMW, Mercedes, Renault, Toyota...
  • PL24 P4 Legacy (HTML scrape) — Ford, PSA, Hyundai/Kia, Nissan, Opel, Volvo
  • PartsCatalogs (REST + Playwright JWT) — geniş VIN kapsamı
  • EMEX (Playwright scrape, emexdwc.ae) — async BullMQ worker

EMEX & PartsCatalogs Türkçeleştirme

EMEX ve PartsCatalogs kaynakları kategori/parça isimlerini İngilizce (zaman zaman Rusça) döner. Çeviri akışı:

  1. TranslationsService (apps/api/src/translations/) — Redis cache → DB lookup (emex_category_translations) → orijinal döndür. Dictionary tabanlı word-by-word replace devre dışı (yarı-İngilizce çıktı yaratıyordu).
  2. Hot path (categories.service.ts) — EMEX/PCAT insert noktalarında translateMany() ile bulk lookup yapılır; cache miss varsa orijinal yazılır, sonraki bootstrap pass'inde LLM ile çevrilir.
  3. Bootstrap script (scripts/emex-translate-bootstrap.ts) — DB'deki tüm unique name_original değerlerini OpenRouter üzerinden DeepSeek V3 ile çevirir, emex_category_translations tablosuna yazar.
  4. Backfill script (scripts/emex-backfill-tr-names.ts) — translation tablosuna göre mevcut categories.name ve parts.name değerlerini günceller, Redis cache flush eder.
# 1) Tüm yeni terimleri çevir (~$0.50, ~30 dk)
pnpm exec tsx scripts/emex-translate-bootstrap.ts --dry-run
pnpm exec tsx scripts/emex-translate-bootstrap.ts

# 2) DB kayıtlarını güncelle
pnpm exec tsx scripts/emex-backfill-tr-names.ts --dry-run
pnpm exec tsx scripts/emex-backfill-tr-names.ts

# 3) API restart (yeni hot-path translateMany için)
pm2 restart sase-api

Env: OPENROUTER_API_KEY (apps/api/.env).


Test Bilgileri

  • Admin: admin@sase.tr / Sase2026
  • Test VIN (VW): WVWZZZ1JZ3W597935
  • Login: POST /api/auth/sign-in/email → cookie better-auth.session_token

Daha Fazla

  • docs/INDEX.md — kapsamlı proje rehberi (rotalar, API, DB şeması, bileşenler)
  • CLAUDE.md — Claude Code için proje rehberi
Description
sase.tr website
Readme 79 MiB
Languages
TypeScript 74.8%
HTML 20.2%
JavaScript 4%
Shell 0.5%
PLpgSQL 0.2%
Other 0.2%