Semih Yesilyurt 3613caa072
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled
fix(catalog-source): gate emex parts behind allowlist (safety)
The catalog-wide bridge in EmexSourceDbService.fetchCategoryParts was
measured against vehicle_parts on 2026-06-01 and found to return 7-114x
more parts than belong to the requesting vehicle, with 49-98 wrong OEM
codes per 100 served. That directly violates the project rule that the
user must never see a wrong OEM.

Per-catalog noiseRatio sample (catalog-wide / per-vehicle):
  RENAULT201910 51x | FFIAT84 45x | VOLVO201410 24x | MB201810 14x
  AU1587 8x | BMW202501 70x (+ gid namespace mismatch ETK vs numeric)
  GM_C201809 114x | MINI202501 12x | LRE201412 7x | MAZDA2020 54x
  GM_OP201809 dump has only 1 wildcard vehicle (unique_key="_") so the
  single Crossland X "owns" all 47k Opel parts — same firehose served
  to any Opel sub-model in sase prod.

All alternative bridges were proven dead:
  SSD eşleştirme        - session-bound, 0/91 sase SSDs match dump
  scrape_queue_v2.vehicle_ssd - same session SSD format
  api_cache replay      - table empty (0 rows)
  wizard_parameters     - table empty (0 rows)
  VIN direct            - no VIN column in dump
The only viable per-vehicle bridge is vehicles.unique_key reconstruction
from raw_data.parsedOptions, but sase currently stores the required 4
wizard fields on just 5/103 emex vehicles (all Renault). That work is
follow-up; this patch only stops the bleeding.

Change:
- Add EMEX_SOURCE_DB_ALLOWED_CATALOGS env (comma-separated, default "")
- EmexSourceDbService.fetchCategoryParts returns null unless catalogCode
  is in the allowlist. Empty allowlist = service is effectively off for
  parts, full fallthrough to live emex.
- Connection pool stays alive so the follow-up per-vehicle bridge /
  schema-only path can use it without flipping env.
- Boot logs warn loudly when connected with an empty allowlist.

Prod was never affected — CATALOG_SOURCE_DB_ENABLED was unset there. This
fixes dev branch behaviour (default-on since commit 3a3a7d3) and keeps
prod safe by default once main is promoted.

Files:
- packages/config/src/index.ts        env schema + audit notes
- apps/api/src/config/configuration.ts parse allowlist into string[]
- apps/api/src/integrations/catalog-source-db/emex-source-db.service.ts
  allowlist field, init logging, fetchCategoryParts gate, class doc
- docker-compose.coolify.yml          env injection for api + worker

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-01 18:39:59 +03:00
2026-02-12 00:26:34 +00:00

Sase

VIN/şase numarası sorgulama ve otomotiv yedek parça katalog platformu (Türkiye). Site: https://sase.tr · Staging: https://dev.sase.tr


Stack

Katman Teknoloji
Monorepo pnpm 10 + Turborepo
Backend NestJS 10, TypeScript 5.7, Node 22
DB PostgreSQL 17 + Drizzle ORM
Cache / Queue Redis 7 + BullMQ
Auth Better Auth (cookie session)
Frontend Vite 6, React 19, TanStack Router + Query
UI Tailwind v4, shadcn/ui (Radix)
Ödeme Stripe (kart)
Email Postal
Storage MinIO (S3)
Analitik PostHog
Test Vitest, Playwright
Deploy GitHub Actions → SSH → PM2

Yapı

ss/
├── apps/
│   ├── api/                NestJS (port 4000, /api)
│   └── web/                Vite + React (port 3000)
├── packages/
│   ├── shared/             Tipler, Zod şemaları
│   ├── config/             Env şeması (Zod)
│   └── ui/                 Paylaşılan shadcn bileşenleri
├── docker/                 docker-compose + nginx
├── scripts/                Deploy + bakım scriptleri
└── docs/                   Detay dökümantasyon (INDEX.md)

Komutlar

pnpm dev                    # tüm app'ler (Turbo)
pnpm build
pnpm test                   # Vitest
pnpm lint                   # Biome
pnpm typecheck

# DB (apps/api/)
pnpm db:push                # şemayı push
pnpm db:studio              # Drizzle Studio
pnpm db:generate            # migration üret

# Tek app
pnpm dev --filter=api
pnpm dev --filter=web

VIN Decode Akışı

Corgi (offline WMI) → PartsCatalogs API → PL24 API → EMEX scraper → NHTSA

Birden fazla araç eşleşmesi gelirse frontend seçim modalı gösterir.


Katalog Mimarisi

  • PL24 P5 Modern (REST/JSON) — VW Group, BMW, Mercedes, Renault, Toyota...
  • PL24 P4 Legacy (HTML scrape) — Ford, PSA, Hyundai/Kia, Nissan, Opel, Volvo
  • PartsCatalogs (REST + Playwright JWT) — geniş VIN kapsamı
  • EMEX (Playwright scrape, emexdwc.ae) — async BullMQ worker

EMEX & PartsCatalogs Türkçeleştirme

EMEX ve PartsCatalogs kaynakları kategori/parça isimlerini İngilizce (zaman zaman Rusça) döner. Çeviri akışı:

  1. TranslationsService (apps/api/src/translations/) — Redis cache → DB lookup (emex_category_translations) → orijinal döndür. Dictionary tabanlı word-by-word replace devre dışı (yarı-İngilizce çıktı yaratıyordu).
  2. Hot path (categories.service.ts) — EMEX/PCAT insert noktalarında translateMany() ile bulk lookup yapılır; cache miss varsa orijinal yazılır, sonraki bootstrap pass'inde LLM ile çevrilir.
  3. Bootstrap script (scripts/emex-translate-bootstrap.ts) — DB'deki tüm unique name_original değerlerini OpenRouter üzerinden DeepSeek V3 ile çevirir, emex_category_translations tablosuna yazar.
  4. Backfill script (scripts/emex-backfill-tr-names.ts) — translation tablosuna göre mevcut categories.name ve parts.name değerlerini günceller, Redis cache flush eder.
# 1) Tüm yeni terimleri çevir (~$0.50, ~30 dk)
pnpm exec tsx scripts/emex-translate-bootstrap.ts --dry-run
pnpm exec tsx scripts/emex-translate-bootstrap.ts

# 2) DB kayıtlarını güncelle
pnpm exec tsx scripts/emex-backfill-tr-names.ts --dry-run
pnpm exec tsx scripts/emex-backfill-tr-names.ts

# 3) API restart (yeni hot-path translateMany için)
pm2 restart sase-api

Env: OPENROUTER_API_KEY (apps/api/.env).


Test Bilgileri

  • Admin: admin@sase.tr / Sase2026
  • Test VIN (VW): WVWZZZ1JZ3W597935
  • Login: POST /api/auth/sign-in/email → cookie better-auth.session_token

Daha Fazla

  • docs/INDEX.md — kapsamlı proje rehberi (rotalar, API, DB şeması, bileşenler)
  • CLAUDE.md — Claude Code için proje rehberi
Description
sase.tr website
Readme 80 MiB
Languages
TypeScript 75.2%
HTML 19.8%
JavaScript 4%
Shell 0.5%
PLpgSQL 0.2%
Other 0.2%