Compare commits

..

39 Commits

Author SHA1 Message Date
f2e20b32eb Merge pull request 'YARA-1164' (#222) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#222
2026-07-27 11:39:39 +03:30
SepehrYahyaee
c94dd27a96 YARA-1164 2026-07-27 11:38:54 +03:30
6e1405c309 Merge pull request 'main' (#221) from s.hajizadeh/yara724api:main into main
Reviewed-on: Yara724/api#221
2026-07-27 10:39:57 +03:30
f053ee1348 merge upstream 2026-07-27 10:39:17 +03:30
182db56e15 the serial letter normalization added to the code to normalize the Heh , Ya , Kaf and etc to the correct character 2026-07-27 10:38:35 +03:30
9b348d567d Merge pull request 'YARA-1162' (#220) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#220
2026-07-27 10:16:22 +03:30
SepehrYahyaee
e4c3b7a16a YARA-1162 2026-07-27 10:15:46 +03:30
23fca04705 Merge pull request 'YARA-1154' (#219) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#219
2026-07-27 09:39:08 +03:30
SepehrYahyaee
4b9d946bfd YARA-1154 2026-07-27 09:31:07 +03:30
c85503e598 Merge pull request 'YARA-1136' (#218) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#218
2026-07-26 11:35:59 +03:30
SepehrYahyaee
9828aee8af YARA-1136 2026-07-26 11:35:21 +03:30
778544c321 Merge pull request 'YARA-1147' (#217) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#217
2026-07-25 12:32:22 +03:30
SepehrYahyaee
3afff67336 YARA-1147 2026-07-25 12:31:54 +03:30
793ff639ba Merge pull request 'Added insurer capabilities for super-admin' (#216) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#216
2026-07-25 11:55:42 +03:30
SepehrYahyaee
ec15cff557 Added insurer capabilities for super-admin 2026-07-25 11:55:00 +03:30
fd42adf9d6 Merge pull request 'Added inner parts to APIs for expert claim' (#215) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#215
2026-07-25 11:10:38 +03:30
SepehrYahyaee
4272790fad Added inner parts to APIs for expert claim 2026-07-25 11:10:02 +03:30
ac65cdb77b Merge pull request 'lookups and inquiries in lookups added' (#214) from s.hajizadeh/yara724api:main into main
Reviewed-on: Yara724/api#214
2026-07-25 11:04:42 +03:30
8430c68e3a lookups and inquiries in lookups added 2026-07-25 11:03:58 +03:30
49fe548215 Merge pull request 'Fixed v5 file maker approval field' (#213) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#213
2026-07-25 10:25:10 +03:30
SepehrYahyaee
777eae1028 Fixed v5 file maker approval field 2026-07-25 10:24:34 +03:30
b67dd733cd Merge pull request 'Fixed upload documents counting for v4' (#212) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#212
2026-07-25 09:53:07 +03:30
SepehrYahyaee
4818f73252 Fixed upload documents counting for v4 2026-07-25 09:52:42 +03:30
cc8a5354c7 Merge pull request 'v4 bug fixed' (#211) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#211
2026-07-25 09:29:42 +03:30
SepehrYahyaee
2d5ade33d2 v4 bug fixed 2026-07-25 09:29:12 +03:30
b73c92c21f Merge pull request 'Fixed Bugs: 1) V4 incorrect advancement to file maker approval state, 2) V4 race condition for finishing file maker steps' (#210) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#210
2026-07-23 13:44:05 +03:30
f9f462d47b Fixed Bugs: 1) V4 incorrect advancement to file maker approval state, 2) V4 race condition for finishing file maker steps 2026-07-23 13:43:37 +03:30
c3eb36dc41 Merge pull request 'Fixed v4 sign' (#209) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#209
2026-07-22 17:37:00 +03:30
SepehrYahyaee
f75ecf5c2c Fixed v4 sign 2026-07-22 17:36:29 +03:30
75c4cb6a05 Merge pull request 'Fixed v4/v5 flow' (#208) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#208
2026-07-22 17:22:55 +03:30
SepehrYahyaee
7a4277f8b2 Fixed v4/v5 flow 2026-07-22 17:22:27 +03:30
e50bc78344 Merge pull request 'Fixed sign' (#207) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#207
2026-07-22 15:47:02 +03:30
SepehrYahyaee
2c1cd93dd0 Fixed sign 2026-07-22 15:46:33 +03:30
ffd44df718 Merge pull request 'Fix v2 flow sign of second party' (#206) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#206
2026-07-22 15:35:53 +03:30
SepehrYahyaee
64865b70f2 Fix v2 flow sign of second party 2026-07-22 15:35:14 +03:30
c207c30be9 Merge pull request 'Fixed v2 flow' (#205) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#205
2026-07-22 15:10:00 +03:30
SepehrYahyaee
fcb169e9ac Fixed v2 flow 2026-07-22 15:09:34 +03:30
1867292499 Merge pull request 'Fixed v2 flow' (#204) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#204
2026-07-22 14:53:33 +03:30
SepehrYahyaee
2cc96f6132 Fixed v2 flow 2026-07-22 14:52:51 +03:30
44 changed files with 2102 additions and 125 deletions

View File

@@ -274,6 +274,20 @@ curl -X GET "$FANAVARAN_BIME_URL/car/code-list/accident-culprit-type" \
-H "ContractId: $CONTRACT_ID" \
-H "Location: $LOCATION" \
-H "Content-Type: application/json"
curl -X GET "$FANAVARAN_BIME_URL/car/base-info/vehicle-kinds" \
-H "authenticationToken: $AUTHENTICATION_TOKEN" \
-H "CorpId: $CORP_ID" \
-H "ContractId: $CONTRACT_ID" \
-H "Location: $LOCATION" \
-H "Content-Type: application/json"
curl -X GET "$FANAVARAN_BIME_URL/car/vehicles/inquiry-by-vin?vin=IRNKAEK4150012345" \
-H "authenticationToken: $AUTHENTICATION_TOKEN" \
-H "CorpId: $CORP_ID" \
-H "ContractId: $CONTRACT_ID" \
-H "Location: $LOCATION" \
-H "Content-Type: application/json"
```
### 3B. Policy Inquiry By National Code

View File

@@ -0,0 +1,86 @@
#!/usr/bin/env node
/**
* Quick manual verification for plate normalization.
*
* Usage: node scripts/verify-plate-normalization.mjs
*
* Demonstrates that:
* 339ه77 (ه + U+200D) -> 339ه77 -> letter ه -> code 15
* 339ي77 (Arabic ي) -> 339ی77 -> letter ی -> code 16
*/
// ---------- paste the pure function here so no build needed ----------
function normalizePlateText(text) {
if (!text) return text;
let result = String(text);
result = result.normalize("NFKC");
result = result.replace(/[\u200C\u200D\u200E\u200F\uFEFF]/g, "");
result = result.replace(/\u064A/g, "\u06CC"); // Arabic ي → Persian ی
result = result.trim();
return result;
}
// ---------- the canonical plate-letter → code mapping ----------
const PLATE_LETTER_MAP = {
الف: 1, ب: 2, پ: 3, ج: 4, د: 5,
س: 6, ص: 7, ط: 8, ع: 9, ق: 10,
ل: 11, م: 12, ن: 13, و: 14, ه: 15,
ی: 16, ک: 17, ژ: 18, ت: 19, ث: 20,
ز: 21, ش: 22, ف: 23, گ: 24,
};
function extractAndMap(plateString) {
const normalized = normalizePlateText(plateString);
// Simple parser: digits | letter | digits (left+right digits, 1 letter)
const match = normalized.match(/^(\d+)([^\d]+)(\d+)$/);
if (!match) return { input: plateString, normalized, error: "no match" };
const [, leftDigits, letterRaw, rightDigits] = match;
const letter = normalizePlateText(letterRaw);
const code = PLATE_LETTER_MAP[letter];
return {
input: plateString,
normalized,
leftDigits,
letter,
rightDigits,
code,
ok: code !== undefined,
};
}
// ---------- test cases ----------
const cases = [
{ desc: "ه + ZWJ (the original bug)", plate: "339ه\u200D77" },
{ desc: "Arabic ي → Persian ی", plate: "339ي77" },
{ desc: "ه + ZWNJ", plate: "339ه\u200C77" },
{ desc: "RTL mark around letter", plate: "339\u200Fه\u200E77" },
{ desc: "BOM + ZWJ combined", plate: "\uFEFF339ه\u200D77" },
{ desc: "clean letter (no junk)", plate: "339ه77" },
{ desc: "full plate: الف", plate: "11الف22" },
{ desc: "full plate: ی", plate: "55ی99" },
];
console.log("Plate Normalization Verification\n");
console.log("=".repeat(72));
let allPassed = true;
for (const { desc, plate } of cases) {
const r = extractAndMap(plate);
const status = r.ok ? "PASS" : "FAIL";
if (!r.ok) allPassed = false;
console.log(`\n[${status}] ${desc}`);
console.log(` Input: ${JSON.stringify(plate)}`);
console.log(` Normalized: ${JSON.stringify(r.normalized)}`);
if (r.letter) {
console.log(` Letter: ${r.letter} (U+${r.letter.charCodeAt(0).toString(16).toUpperCase().padStart(4, "0")})`);
}
console.log(` Code: ${r.code ?? "undefined"}`);
}
console.log("\n" + "=".repeat(72));
console.log(allPassed ? "\n All tests PASSED ✓" : "\n Some tests FAILED ✗");
process.exit(allPassed ? 0 : 1);

View File

@@ -9,4 +9,5 @@ export enum RoleEnum {
FILE_MAKER = "file_maker",
FILE_REVIEWER = "file_reviewer",
SUPER_ADMIN = "super_admin",
CALL_CENTER = "call_center",
}

View File

@@ -29,6 +29,7 @@ import { FieldExpertDbService } from "src/users/entities/db-service/field-expert
import { RegistrarDbService } from "src/users/entities/db-service/registrar.db.service";
import { FileMakerDbService } from "src/users/entities/db-service/file-maker.db.service";
import { FileReviewerDbService } from "src/users/entities/db-service/file-reviewer.db.service";
import { CallCenterAgentDbService } from "src/users/entities/db-service/call-center-agent.db.service";
import { HashService } from "src/utils/hash/hash.service";
import { OtpGeneratorService } from "src/sms-orchestration/otp-generator.service";
import { SuperAdminDbService } from "src/super-admin/entities/db-service/super-admin.db.service";
@@ -58,6 +59,7 @@ export class ActorAuthService {
private readonly fileMakerDbService: FileMakerDbService,
private readonly fileReviewerDbService: FileReviewerDbService,
private readonly superAdminDbService: SuperAdminDbService,
private readonly callCenterAgentDbService: CallCenterAgentDbService,
) {}
// TODO convrt to class for dynamic controller
@@ -123,6 +125,14 @@ export class ActorAuthService {
});
else res = await this.superAdminDbService.findByLoginIdentifier(username);
break;
case RoleEnum.CALL_CENTER:
if (username == null && userId)
res = await this.callCenterAgentDbService.findOne({
_id: new Types.ObjectId(userId),
});
else
res = await this.callCenterAgentDbService.findByLoginIdentifier(username);
break;
default:
return null;
}

View File

@@ -57,6 +57,7 @@ import { JwtModule } from "@nestjs/jwt";
import { MediaPolicyModule } from "src/media-policy/media-policy.module";
import { FanavaranAuditModule } from "src/fanavaran/fanavaran-audit.module";
import { FanavaranLookupModule } from "src/fanavaran/fanavaran-lookup.module";
import { PlateNormalizerModule } from "src/utils/plate-normalizer/plate-normalizer.module";
@Module({
imports: [
@@ -67,6 +68,7 @@ import { FanavaranLookupModule } from "src/fanavaran/fanavaran-lookup.module";
}),
FanavaranAuditModule,
FanavaranLookupModule,
PlateNormalizerModule,
PublicIdModule,
UsersModule,
RequestManagementModule,

View File

@@ -156,6 +156,7 @@ import {
resolvePartCaptureIndex,
} from "src/helpers/outer-damage-parts";
import { normalizeMoneyAmountString } from "src/utils/unicode-digits";
import { PlateNormalizerService } from "src/utils/plate-normalizer/plate-normalizer.service";
import {
CAPTURE_PHASE_DAMAGED_PARTY_DOC_KEYS,
@@ -352,6 +353,7 @@ export class ClaimRequestManagementService {
private readonly fanavaranLookupService: FanavaranLookupService,
private readonly fileMakerDbService: FileMakerDbService,
private readonly fieldExpertDbService: FieldExpertDbService,
private readonly plateNormalizer: PlateNormalizerService,
) {}
private requiredDocumentKeysV2(isCarBody: boolean): string[] {
@@ -419,8 +421,10 @@ export class ClaimRequestManagementService {
claimCase: any,
isCarBody: boolean,
assumeUploadedKey?: string,
skipMetalPlate?: boolean,
): boolean {
for (const k of this.v3PreCaptureDocumentKeys(isCarBody)) {
if (skipMetalPlate && OPTIONAL_CAPTURE_PHASE_DOC_KEYS_V4V5.includes(k as any)) continue;
const ok =
k === assumeUploadedKey
? true
@@ -442,9 +446,11 @@ export class ClaimRequestManagementService {
claimCase: any,
isCarBody: boolean,
assumeUploadedKey?: string,
skipMetalPlate?: boolean,
): number {
let n = 0;
for (const k of this.v3PreCaptureDocumentKeys(isCarBody)) {
if (skipMetalPlate && OPTIONAL_CAPTURE_PHASE_DOC_KEYS_V4V5.includes(k as any)) continue;
const ok =
k === assumeUploadedKey
? true
@@ -499,7 +505,7 @@ export class ClaimRequestManagementService {
const ir = Number(irRaw);
const leftDigits = Number(leftRaw);
const centerDigits = Number(centerRaw);
const centerAlphabet = String(alphaRaw || "").trim();
const centerAlphabet = this.plateNormalizer.normalizePlateText(String(alphaRaw || ""));
if (
!Number.isFinite(ir) ||
!Number.isFinite(leftDigits) ||
@@ -526,11 +532,11 @@ export class ClaimRequestManagementService {
Number.isFinite(Number(p.leftDigits)) &&
Number.isFinite(Number(p.centerDigits)) &&
Number.isFinite(Number(p.ir)) &&
String(p.centerAlphabet || "").trim()
this.plateNormalizer.normalizePlateText(String(p.centerAlphabet || ""))
) {
return {
leftDigits: Number(p.leftDigits),
centerAlphabet: String(p.centerAlphabet).trim(),
centerAlphabet: this.plateNormalizer.normalizePlateText(String(p.centerAlphabet)),
centerDigits: Number(p.centerDigits),
ir: Number(p.ir),
};
@@ -3598,9 +3604,10 @@ export class ClaimRequestManagementService {
if (centerAlphabet == null) return null;
const raw = String(centerAlphabet).trim();
if (!raw) return null;
const asNumber = Number(raw);
const normalized = this.plateNormalizer.normalizePlateText(raw);
const asNumber = Number(normalized);
if (Number.isFinite(asNumber)) return asNumber;
return FANAVARAN_PLATE_LETTER_CODE[raw] ?? null;
return this.plateNormalizer.resolvePlateLetterCode(normalized, FANAVARAN_PLATE_LETTER_CODE);
}
private formatFanavaranPlateNo(
@@ -6331,27 +6338,41 @@ export class ClaimRequestManagementService {
}
// V5 flow: FileMaker approval required before fanavaran.
// Instead of submitting, hold the claim at WAITING_FOR_FILE_MAKER_APPROVAL.
// Cross-check the blame record — only V5 blame files carry requiresFileMakerApproval.
// V4 claims may have the flag set from an old bug; we ignore it if the blame
// itself does not carry the flag.
if ((claimCase as any).requiresFileMakerApproval) {
await this.claimCaseDbService.findByIdAndUpdate(claimCaseId, {
$set: { status: ClaimCaseStatus.WAITING_FOR_FILE_MAKER_APPROVAL },
$push: {
history: {
type: "V5_HELD_FOR_FILE_MAKER_APPROVAL",
actor: { actorType: "system" },
timestamp: new Date(),
metadata: { claimCaseId },
const blameId = (claimCase as any).blameRequestId;
const blame = blameId
? await this.blameRequestDbService.findById(String(blameId))
: null;
const isV5 = !!(blame as any)?.requiresFileMakerApproval;
if (isV5) {
await this.claimCaseDbService.findByIdAndUpdate(claimCaseId, {
$set: { status: ClaimCaseStatus.WAITING_FOR_FILE_MAKER_APPROVAL },
$push: {
history: {
type: "V5_HELD_FOR_FILE_MAKER_APPROVAL",
actor: { actorType: "system" },
timestamp: new Date(),
metadata: { claimCaseId },
},
},
},
});
return {
attempted: false,
submitted: false,
skipped: true,
skipReason:
"V5 flow: FileMaker approval required before Fanavaran submission. " +
"Claim is now in WAITING_FOR_FILE_MAKER_APPROVAL.",
};
}
// V4 claim with stale flag — clear it so this path is not hit again.
await this.claimCaseDbService.findByIdAndUpdate(claimCaseId, {
$unset: { requiresFileMakerApproval: "" },
});
return {
attempted: false,
submitted: false,
skipped: true,
skipReason:
"V5 flow: FileMaker approval required before Fanavaran submission. " +
"Claim is now in WAITING_FOR_FILE_MAKER_APPROVAL.",
};
}
const skipReason = await this.getFanavaranAutoSubmitSkipReason(claimCase);
@@ -8606,6 +8627,7 @@ export class ClaimRequestManagementService {
claimCase,
isCarBodyUpload,
body.documentKey,
options?.skipMetalPlate,
);
allDocumentsUploaded = options?.v3InPersonFlow
@@ -8620,6 +8642,7 @@ export class ClaimRequestManagementService {
claimCase,
isCarBodyUpload,
body.documentKey,
options?.skipMetalPlate,
)
: this.countRemainingV2OwnerDocuments(
claimCase,
@@ -8629,31 +8652,10 @@ export class ClaimRequestManagementService {
if (allDocumentsUploaded) {
if (options?.v3InPersonFlow) {
// V4 split flow: mark the claim as waiting for the FileReviewer.
// The FileReviewer calls accident-fields then select-outer-parts, at
// which point advanceV3ClaimToOuterPartsIfReady() moves the claim to
// SELECTING_OUTER_PARTS / SELECT_OUTER_PARTS.
$set["status"] = ClaimCaseStatus.WAITING_FOR_FILE_REVIEWER;
$set["workflow.nextStep"] = ClaimWorkflowStep.SELECT_OUTER_PARTS;
completedStepsEntries.push(
ClaimWorkflowStep.UPLOAD_REQUIRED_DOCUMENTS,
);
historyEntries.push({
type: "STEP_COMPLETED",
actor: {
actorId: new Types.ObjectId(currentUserId),
actorName: claimCase.owner?.fullName || "User",
actorType: "user",
},
timestamp: new Date(),
metadata: {
stepKey: ClaimWorkflowStep.UPLOAD_REQUIRED_DOCUMENTS,
description:
"FileMaker documents complete. File sealed — awaiting FileReviewer.",
v3InPersonFlow: true,
},
});
// V4/V5 split flow: the status transition to WAITING_FOR_FILE_REVIEWER is
// deferred to a post-write re-check (see below) to eliminate the race
// condition where two concurrent uploads each see a stale snapshot and
// neither fires the transition. We skip adding it to $set here.
} else {
$set["status"] = ClaimCaseStatus.WAITING_FOR_DAMAGE_EXPERT;
$set["claimStatus"] = ClaimStatus.PENDING;
@@ -8720,6 +8722,88 @@ export class ClaimRequestManagementService {
updatePayload,
);
// ─── V4/V5 in-person flow: post-write race-safe status transition ──────
// After the write we re-read the actual DB state. If all pre-capture
// documents are now present but the status has not yet advanced (i.e. a
// concurrent request uploaded the last doc a split-second before us and
// the stale snapshot we read earlier missed it — or vice-versa), we apply
// WAITING_FOR_FILE_REVIEWER atomically using findOneAndUpdate with a status
// condition, so exactly one writer wins regardless of concurrency.
if (options?.v3InPersonFlow && !isResendUpload && !isCapturePhaseDocUpload) {
const afterWrite = await this.claimCaseDbService.findById(claimRequestId);
if (afterWrite) {
const blameForRecheck = afterWrite.blameRequestId
? await this.blameRequestDbService.findById(
afterWrite.blameRequestId.toString(),
)
: null;
const isCarBodyRecheck = blameForRecheck?.type === BlameRequestType.CAR_BODY;
const skipMetalPlateRecheck = !!(blameForRecheck as any)?.isMadeByFileMaker;
const allDoneNow =
afterWrite.status === ClaimCaseStatus.UPLOADING_REQUIRED_DOCUMENTS &&
afterWrite.workflow?.currentStep === ClaimWorkflowStep.UPLOAD_REQUIRED_DOCUMENTS &&
this.allV3PreCaptureDocumentsComplete(afterWrite, isCarBodyRecheck, undefined, skipMetalPlateRecheck);
if (allDoneNow) {
// Atomic conditional update: only succeeds when status is still
// UPLOADING_REQUIRED_DOCUMENTS, preventing double-application.
const advanced = await this.claimCaseDbService.findOneAndUpdate(
{
_id: afterWrite._id,
status: ClaimCaseStatus.UPLOADING_REQUIRED_DOCUMENTS,
},
{
$set: {
status: ClaimCaseStatus.WAITING_FOR_FILE_REVIEWER,
"workflow.nextStep": ClaimWorkflowStep.SELECT_OUTER_PARTS,
},
$push: {
"workflow.completedSteps": ClaimWorkflowStep.UPLOAD_REQUIRED_DOCUMENTS,
history: {
type: "STEP_COMPLETED",
actor: {
actorId: new Types.ObjectId(currentUserId),
actorName: afterWrite.owner?.fullName || "User",
actorType: "user",
},
timestamp: new Date(),
metadata: {
stepKey: ClaimWorkflowStep.UPLOAD_REQUIRED_DOCUMENTS,
description:
"FileMaker documents complete. File sealed — awaiting FileReviewer.",
v3InPersonFlow: true,
},
},
},
},
);
if (advanced) {
// This request won the race — reflect the final state in the response.
allDocumentsUploaded = true;
// Now that the FileMaker's document phase is complete, promote the
// blame file to WAITING_FOR_FILE_REVIEWER so the frontend shows the
// correct sealed state when the FileMaker returns.
const blameId = (afterWrite as any).blameRequestId;
if (blameId) {
await this.blameRequestDbService.findByIdAndUpdate(
String(blameId),
{ $set: { status: BlameCaseStatus.WAITING_FOR_FILE_REVIEWER } },
);
}
}
} else if (
afterWrite.status === ClaimCaseStatus.WAITING_FOR_FILE_REVIEWER ||
(afterWrite.workflow?.completedSteps ?? []).includes(
ClaimWorkflowStep.UPLOAD_REQUIRED_DOCUMENTS,
)
) {
// Another concurrent request already advanced the status — treat
// this upload as the completing upload for response purposes.
allDocumentsUploaded = true;
}
}
}
// Auto-submit Fanavaran attachments when all documents are uploaded
if (allDocumentsUploaded && !isResendUpload && !options?.v3InPersonFlow) {
this.submitFanavaranAttachmentsV2(claimRequestId, resolveFanavaranClientKey()).catch(

View File

@@ -4,9 +4,12 @@ import {
Body,
Controller,
Get,
HttpException,
InternalServerErrorException,
Param,
Patch,
Post,
Put,
Query,
UploadedFile,
UseGuards,
@@ -516,6 +519,73 @@ Returns status of each item (uploaded/captured or not).
);
}
// ─── Owner signature on expert pricing ───────────────────────────────────────
@Put("claim-sign/:claimRequestId")
@ApiParam({ name: "claimRequestId" })
@ApiConsumes("multipart/form-data")
@ApiBody({
description: "Signature file, agreement, and branch",
schema: {
type: "object",
required: ["sign", "agree", "branchId"],
properties: {
sign: { type: "string", format: "binary", description: "Signature image" },
agree: { type: "boolean", description: "true to accept, false to reject" },
branchId: { type: "string", description: "Insurer branch ID" },
},
},
})
@ApiOperation({
summary: "Owner signature on expert pricing (Flow 3 — expert acts on behalf of user)",
description:
"Field expert submits the damaged party's signature during the final approval stage. " +
"Delegates to the same service method as the user sign endpoint; the expert's " +
"identity is resolved to the claim owner via `resolveClaimEffectiveUserId`.",
})
@UseInterceptors(
FileInterceptor("sign", {
limits: { fileSize: DEFAULT_MEDIA_MAX_BYTES },
storage: diskStorage({
destination: "./files/claim-sign",
filename: (req, file, callback) => {
const unique = Date.now();
const ex = extname(file.originalname);
const base = file.originalname.split(/[.,\s-]/)[0] || "sign";
callback(null, `${base}-${unique}${ex}`);
},
}),
}),
)
async submitOwnerSign(
@Param("claimRequestId") claimRequestId: string,
@Body("agree") agree: string | boolean,
@Body("branchId") branchId: string,
@CurrentUser() expert: any,
@UploadedFile() sign: Express.Multer.File,
) {
await this.mediaPolicyService.assertForClaim(sign, claimRequestId, "image");
const agreed =
typeof agree === "string"
? agree === "true" || agree === "1"
: Boolean(agree);
try {
return await this.claimRequestManagementService.submitOwnerInsurerApprovalSignV2(
claimRequestId,
agreed,
typeof branchId === "string" ? branchId : "",
sign,
expert.sub,
expert,
);
} catch (error) {
if (error instanceof HttpException) throw error;
throw new InternalServerErrorException(
error instanceof Error ? error.message : "Failed to submit signature",
);
}
}
@Patch("car-capture/:claimRequestId")
@ApiConsumes("multipart/form-data")
@UseInterceptors(

View File

@@ -1871,6 +1871,7 @@ export class ExpertBlameService {
link: this.smsOrchestrationService.buildBlamePartyLink(
requestIdToken,
role,
"v1",
),
});
}
@@ -2065,6 +2066,7 @@ export class ExpertBlameService {
link: this.smsOrchestrationService.buildBlamePartyLink(
requestIdToken,
linkRole,
"v1",
),
});
}

View File

@@ -3164,7 +3164,7 @@ export class ExpertClaimService {
receptor: ownerPhoneResend,
fileKind: "claim",
publicId: claim.publicId,
link: this.smsOrchestrationService.buildClaimLink(String(claim._id)),
link: this.smsOrchestrationService.buildClaimLink(String(claim._id), "v1"),
});
}
@@ -3462,7 +3462,7 @@ export class ExpertClaimService {
fileKind: "claim",
publicId: claim.publicId,
expertLastName,
link: this.smsOrchestrationService.buildClaimLink(String(claim._id)),
link: this.smsOrchestrationService.buildClaimLink(String(claim._id), "v1"),
});
}
@@ -3716,14 +3716,19 @@ export class ExpertClaimService {
let claims: any[] = [];
if (actor.role === RoleEnum.FIELD_EXPERT) {
const expertOid = new Types.ObjectId(actor.sub);
// Exclude V4/V5 blame files — same rule as getFieldExpertClaimListV2.
const expertBlameIds = await this.blameRequestDbService
.find(
{ expertInitiated: true, initiatedByFieldExpertId: expertOid },
{
expertInitiated: true,
initiatedByFieldExpertId: expertOid,
isMadeByFileMaker: { $ne: true },
},
{ select: "_id", lean: true },
)
.then((docs) => docs.map((d) => (d as { _id: unknown })._id));
const claimOr: Record<string, unknown>[] = [
{ initiatedByFieldExpertId: expertOid },
{ initiatedByFieldExpertId: expertOid, requiresFileMakerApproval: { $ne: true } },
];
if (expertBlameIds.length > 0) {
claimOr.push({ blameRequestId: { $in: expertBlameIds } });
@@ -4052,15 +4057,22 @@ export class ExpertClaimService {
query: ListQueryV2Dto = {},
): Promise<GetClaimListV2ResponseDto> {
const expertOid = new Types.ObjectId(actor.sub);
// Exclude V4/V5 blame files (isMadeByFileMaker=true) — those belong to
// the FILE_MAKER/FILE_REVIEWER flows, not the V3 field-expert flow.
const expertBlameIds = await this.blameRequestDbService
.find(
{ expertInitiated: true, initiatedByFieldExpertId: expertOid },
{
expertInitiated: true,
initiatedByFieldExpertId: expertOid,
isMadeByFileMaker: { $ne: true },
},
{ select: "_id", lean: true },
)
.then((docs) => docs.map((d) => (d as { _id: unknown })._id));
const claimOr: Record<string, unknown>[] = [
{ initiatedByFieldExpertId: expertOid },
// Direct claim link: exclude V5 claims that require FileMaker approval
{ initiatedByFieldExpertId: expertOid, requiresFileMakerApproval: { $ne: true } },
];
if (expertBlameIds.length > 0) {
claimOr.push({ blameRequestId: { $in: expertBlameIds } });
@@ -4738,8 +4750,19 @@ export class ExpertClaimService {
"This file has been taken by another reviewer.",
);
}
} else if (!claimCaseInitiatedByFieldExpert(claim, actor, linkedBlame)) {
throw new ForbiddenException("This claim is not accessible to you.");
} else {
// FIELD_EXPERT: V3 flow only. Reject V4/V5 files (isMadeByFileMaker)
// even if their ID matches initiatedByFieldExpertId on the blame —
// those are FILE_MAKER files, accessible via the FILE_MAKER role only.
const isV4V5Blame = !!(linkedBlame as any)?.isMadeByFileMaker;
if (isV4V5Blame) {
throw new ForbiddenException(
"Field experts can only access V3 expert-initiated files.",
);
}
if (!claimCaseInitiatedByFieldExpert(claim, actor, linkedBlame)) {
throw new ForbiddenException("This claim is not accessible to you.");
}
}
// Fall through to the detail build below (skip the damage-expert gate)
} else if (actor.role !== RoleEnum.FILE_MAKER) {

View File

@@ -1,3 +1,4 @@
import { readFile } from "node:fs/promises";
import {
Body,
Controller,
@@ -117,6 +118,21 @@ export class ExpertClaimV2Controller {
return this.claimRequestManagementService.getOuterPartsCatalogV2(carType);
}
@Get("inner-parts-catalog")
@ApiOperation({
summary: "Get inner parts catalog",
description: "Returns the full list of inner car parts from the static catalog.",
})
@ApiResponse({ status: 200, description: "Inner parts catalog (object keyed by part name)" })
async getInnerPartsCatalog() {
const raw = await readFile(`${process.cwd()}/src/static/car-part.json`, "utf-8");
try {
return JSON.parse(raw);
} catch {
return raw;
}
}
@Get("branches")
@ApiOperation({
summary: "List insurer branches for this damage expert (V2)",

View File

@@ -86,6 +86,27 @@ export const FANAVARAN_REMOTE_LOOKUPS: FanavaranRemoteLookupDefinition[] = [
url: `${FANAVARAN_LOOKUP_BASE_URL}/common/base-info/file-types`,
cacheFile: "file-types.json",
},
// NEW LOOKUPS ADDED
{
name: "cities",
url: `${FANAVARAN_LOOKUP_BASE_URL}/common/base-info/cities`,
cacheFile: "cities.json",
},
{
name: "dmg-case-type",
url: `${FANAVARAN_LOOKUP_BASE_URL}/car/code-list/dmg-case-type`,
cacheFile: "dmg-case-type.json",
},
{
name: "dmg-history-status",
url: `${FANAVARAN_LOOKUP_BASE_URL}/car/code-list/dmg-case-history-status`,
cacheFile: "dmg-history-status.json",
},
{
name: "provinces",
url: `${FANAVARAN_LOOKUP_BASE_URL}/common/base-info/Provinces`,
cacheFile: "provinces.json",
},
];
export const TEJARAT_STATIC_ACCIDENT_FILES = {

View File

@@ -265,6 +265,23 @@ export class FanavaranLookupService {
return this.fetchFromFanavaran(clientKey, url);
}
async vehicleById(
clientKey: FanavaranClientKey,
vehicleId: number,
versionNo: number = 1,
): Promise<unknown> {
const url = `${FANAVARAN_LOOKUP_BASE_URL}/car/vehicles/${vehicleId}?versionno=${versionNo}`;
return this.fetchFromFanavaran(clientKey, url);
}
async customerById(
clientKey: FanavaranClientKey,
customerId: number,
): Promise<unknown> {
const url = `${FANAVARAN_LOOKUP_BASE_URL}/common/customers/${customerId}`;
return this.fetchFromFanavaran(clientKey, url);
}
async inquiryByUniqueIdentifier(
clientKey: FanavaranClientKey,
params: {

View File

@@ -238,6 +238,59 @@ export class LookupsController {
return await this.lookupsService.getFileTypes();
}
@Get("cities")
@ApiOperation({
summary: "Fanavaran cities lookup",
description: "Returns city codes from common/base-info/cities.",
})
@ApiOkResponse({
description: "Returns Fanavaran cities lookup data",
schema: { type: "array", items: { type: "object" } },
})
async cities() {
return await this.lookupsService.getCities();
}
@Get("provinces")
@ApiOperation({
summary: "Fanavaran provinces lookup",
description: "Returns province codes from common/base-info/provinces.",
})
@ApiOkResponse({
description: "Returns Fanavaran provinces lookup data",
schema: { type: "array", items: { type: "object" } },
})
async provinces() {
return await this.lookupsService.getProvinces();
}
@Get("dmg-case-type")
@ApiOperation({
summary: "Fanavaran damage case type lookup",
description: "Returns damage case type codes from car/code-list/dmg-case-type.",
})
@ApiOkResponse({
description: "Returns Fanavaran damage case type lookup data",
schema: { type: "array", items: { type: "object" } },
})
async dmgCaseType() {
return await this.lookupsService.getDmgCaseType();
}
@Get("dmg-history-status")
@ApiOperation({
summary: "Fanavaran damage history status lookup",
description:
"Returns damage history status codes from car/code-list/dmg-case-history-status.",
})
@ApiOkResponse({
description: "Returns Fanavaran damage history status lookup data",
schema: { type: "array", items: { type: "object" } },
})
async dmgHistoryStatus() {
return await this.lookupsService.getDmgHistoryStatus();
}
@Get("inquiry-by-vin")
@ApiOperation({
summary: "Fanavaran vehicle inquiry by VIN",

View File

@@ -127,6 +127,22 @@ export class LookupsService {
return await this.getClientRemoteLookup("file-types");
}
async getCities(): Promise<any> {
return await this.getClientRemoteLookup("cities");
}
async getProvinces(): Promise<any> {
return await this.getClientRemoteLookup("provinces");
}
async getDmgCaseType(): Promise<any> {
return await this.getClientRemoteLookup("dmg-case-type");
}
async getDmgHistoryStatus(): Promise<any> {
return await this.getClientRemoteLookup("dmg-history-status");
}
async inquiryByVin(vin: string): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.inquiryByVin(clientKey, vin);
@@ -144,14 +160,70 @@ export class LookupsService {
);
}
async mapPolicyDetails(policy: any): Promise<any> {
if (!policy || typeof policy !== "object") {
return policy;
}
const mappedPolicy = { ...policy };
// 1. Map PreviousInsuranceCorpId and TransferorInsuranceCorpId
try {
const companies = (await this.getClientRemoteLookup("insurance-corp")) as any[];
if (Array.isArray(companies)) {
if (typeof policy.PreviousInsuranceCorpId === "number") {
const match = companies.find((c) => c.Id === policy.PreviousInsuranceCorpId);
if (match) {
mappedPolicy.PreviousInsuranceCorpName = match.Caption;
}
}
if (typeof policy.TransferorInsuranceCorpId === "number") {
const match = companies.find((c) => c.Id === policy.TransferorInsuranceCorpId);
if (match) {
mappedPolicy.TransferorInsuranceCorpName = match.Caption;
}
}
}
} catch (e) {
this.logger.warn(`Failed to map insurance-corp lookups: ${e.message}`);
}
// 2. Map PolicyUsageTypeId
try {
const useTypes = (await this.getClientRemoteLookup("vehicle-use-types")) as any[];
if (Array.isArray(useTypes) && typeof policy.PolicyUsageTypeId === "number") {
const match = useTypes.find((t) => t.Id === policy.PolicyUsageTypeId);
if (match) {
mappedPolicy.PolicyUsageTypeName = match.Caption;
}
}
} catch (e) {
this.logger.warn(`Failed to map vehicle-use-types lookups: ${e.message}`);
}
return mappedPolicy;
}
async thirdPartyPolicyById(policyId: number): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.thirdPartyPolicyById(clientKey, policyId);
const policy = await this.fanavaranLookupService.thirdPartyPolicyById(clientKey, policyId);
return this.mapPolicyDetails(policy);
}
async bodyPolicyById(policyId: number): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.bodyPolicyById(clientKey, policyId);
const policy = await this.fanavaranLookupService.bodyPolicyById(clientKey, policyId);
return this.mapPolicyDetails(policy);
}
async vehicleById(vehicleId: number, versionNo: number = 1): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.vehicleById(clientKey, vehicleId, versionNo);
}
async customerById(customerId: number): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.customerById(clientKey, customerId);
}
async getAccidentWay(): Promise<{ id: number; label: string }[]> {

View File

@@ -4,6 +4,7 @@ import { ClientModule } from "src/client/client.module";
import { PlateDbService } from "src/plates/entites/db-service/plate.db.service";
import { SandHubModule } from "src/sand-hub/sand-hub.module";
import { UsersModule } from "src/users/users.module";
import { PlateNormalizerModule } from "src/utils/plate-normalizer/plate-normalizer.module";
import { PlatesModel, PlatesSchema } from "./entites/schema/plate.schema";
import { PlatesService } from "./plates.service";
@@ -12,6 +13,7 @@ import { PlatesService } from "./plates.service";
UsersModule,
SandHubModule,
ClientModule,
PlateNormalizerModule,
MongooseModule.forFeature([
{ name: PlatesModel.name, schema: PlatesSchema },
]),

View File

@@ -7,20 +7,23 @@ import {
import { Types } from "mongoose";
import { PlateDbService } from "src/plates/entites/db-service/plate.db.service";
import { AddPlateDto } from "src/profile/dto/user/AddPlateDto";
import { PlateNormalizerService } from "src/utils/plate-normalizer/plate-normalizer.service";
@Injectable()
export class PlatesService {
constructor(
private readonly plateDbService: PlateDbService,
private readonly plateNormalizer: PlateNormalizerService,
) {}
async addPlate(currentUser, body: AddPlateDto) {
const { plate, nationalCodeOfInsurer } = body;
const normalizedAlphabet = this.plateNormalizer.normalizePlateText(String(plate.centerAlphabet || ""));
const duplicate = await this.plateDbService.findOne({
userId: currentUser,
leftDigits: plate.leftDigits,
centerAlphabet: plate.centerAlphabet,
centerAlphabet: normalizedAlphabet,
centerDigits: plate.centerDigits,
ir: plate.ir,
nationalCodeOfInsurer,
@@ -31,6 +34,7 @@ export class PlatesService {
const newPlateData = await this.plateDbService.create({
...plate,
centerAlphabet: normalizedAlphabet,
userId: currentUser,
nationalCodeOfInsurer: body.nationalCodeOfInsurer,
});

View File

@@ -0,0 +1,154 @@
import {
Body,
Controller,
Get,
Param,
Post,
UseGuards,
} from "@nestjs/common";
import {
ApiBearerAuth,
ApiBody,
ApiOperation,
ApiParam,
ApiResponse,
ApiTags,
} from "@nestjs/swagger";
import { LocalActorAuthGuard } from "src/auth/guards/actor-local.guard";
import { RolesGuard } from "src/auth/guards/role.guard";
import { Roles } from "src/decorators/roles.decorator";
import { CurrentUser } from "src/decorators/user.decorator";
import { RoleEnum } from "src/Types&Enums/role.enum";
import { RequestManagementService } from "./request-management.service";
import { RunCallCenterInquiryV6Dto } from "./dto/run-call-center-inquiry-v6.dto";
/**
* V6 call-center blame API.
*
* A call-center agent takes the guilty party's details over the phone
* (plate, national code, birthday), runs the insurance inquiry, then sends
* the blame link via SMS. The user (guilty party) opens the link and
* completes the form through the standard v2 user flow — except the
* initial-form / inquiry step is skipped (`skipInitialFormStep=true`) because
* the agent already did it.
*
* For THIRD_PARTY files: only the guilty party's data is collected here.
* The damaged party sees their own portion of the page and fills their info
* as normal after the blame link is opened.
*/
@ApiTags("call-center-blame (v6)")
@Controller("v6/call-center-blame")
@ApiBearerAuth()
@UseGuards(LocalActorAuthGuard, RolesGuard)
@Roles(RoleEnum.CALL_CENTER)
export class CallCenterBlameV6Controller {
constructor(
private readonly requestManagementService: RequestManagementService,
) {}
@Get("my-files")
@ApiOperation({ summary: "[V6] List blame files created by this call-center agent" })
@ApiResponse({ status: 200, description: "List of blame files started by this agent" })
getMyFiles(@CurrentUser() agent: any) {
return this.requestManagementService.getMyCallCenterFilesV6(agent);
}
@Post("create")
@ApiOperation({
summary: "[V6] Create a call-centerinitiated blame file",
description:
"Creates a LINK blame file. The call-center agent collects the guilty " +
"party's plate + national-code over the phone, calls run-inquiry to store " +
"the results, then calls send-link to SMS the blame URL to the user. " +
"The user opens the link and fills the form via the normal v2 flow; the " +
"initial-form/inquiry step is automatically skipped because the agent " +
"already ran it.",
})
@ApiBody({
schema: {
type: "object",
required: ["type"],
properties: {
type: {
type: "string",
enum: ["THIRD_PARTY", "CAR_BODY"],
example: "THIRD_PARTY",
},
},
},
})
createFile(
@CurrentUser() agent: any,
@Body("type") type: "THIRD_PARTY" | "CAR_BODY",
) {
return this.requestManagementService.createCallCenterInitiatedBlameV6(agent, { type });
}
@Post("run-inquiry/:requestId")
@ApiOperation({
summary: "[V6] Run plate + insurance inquiry for the guilty party",
description:
"Call after `create`. The agent supplies the plate and national-code data " +
"collected from the caller. Plate + third-party block inquiry is executed " +
"and the results are stored on the blame document. " +
"For THIRD_PARTY files only the guilty party (first party) is inquired here; " +
"the damaged party's inquiry is handled later by the user via the link. " +
"Sheba (IBAN) is not collected here — the user adds it themselves.",
})
@ApiParam({ name: "requestId", description: "Blame request ID from `create`" })
@ApiBody({ type: RunCallCenterInquiryV6Dto })
runInquiry(
@CurrentUser() agent: any,
@Param("requestId") requestId: string,
@Body() dto: RunCallCenterInquiryV6Dto,
) {
return this.requestManagementService.runCallCenterInquiryV6(agent, requestId, dto);
}
@Post("send-link/:requestId")
@ApiOperation({
summary: "[V6] Send blame link to the guilty party via SMS",
description:
"Call after `run-inquiry`. Provide the guilty party's phone number; " +
"the service registers the user if needed, stores them as the first party, " +
"and sends the blame invite link via SMS. The user opens the link and " +
"completes the blame form via the standard v2 user flow (initial-form step skipped).",
})
@ApiParam({ name: "requestId", description: "Blame request ID" })
@ApiBody({
schema: {
type: "object",
required: ["phoneNumber"],
properties: {
phoneNumber: {
type: "string",
example: "09121234567",
description: "Mobile number of the guilty party",
},
},
},
})
sendLink(
@CurrentUser() agent: any,
@Param("requestId") requestId: string,
@Body("phoneNumber") phoneNumber: string,
) {
return this.requestManagementService.sendCallCenterLinkV6(agent, requestId, { phoneNumber });
}
@Get("blame/:requestId")
@ApiOperation({
summary: "[V6] Get a single blame file created by this agent",
description:
"Returns the current status, workflow step, and party data for one blame " +
"file started by this call-center agent. Useful for checking whether the " +
"user has opened the link and progressed through the form.",
})
@ApiParam({ name: "requestId", description: "Blame request ID" })
getBlame(
@CurrentUser() agent: any,
@Param("requestId") requestId: string,
) {
return this.requestManagementService.getCallCenterBlameDetailV6(agent, requestId);
}
}

View File

@@ -1,5 +1,5 @@
import { ApiProperty, ApiPropertyOptional } from "@nestjs/swagger";
import { IsEnum, IsOptional, IsString } from "class-validator";
import { IsBoolean, IsEnum, IsOptional } from "class-validator";
import { CreationMethod } from "../entities/schema/request-management.schema";
export class CreateExpertInitiatedFileDto {
@@ -18,4 +18,17 @@ export class CreateExpertInitiatedFileDto {
})
@IsEnum(CreationMethod)
creationMethod: CreationMethod;
/**
* V5 only. When true the resulting claim will require FileMaker approval
* before fanavaran submission. V4 files must leave this unset (or false).
*/
@ApiPropertyOptional({
description:
"V5 only — when true the claim requires FileMaker approval before fanavaran submission.",
example: false,
})
@IsBoolean()
@IsOptional()
requiresFileMakerApproval?: boolean;
}

View File

@@ -0,0 +1,85 @@
import { ApiProperty, ApiPropertyOptional } from "@nestjs/swagger";
import {
IsBoolean,
IsNotEmpty,
IsOptional,
IsString,
ValidateNested,
} from "class-validator";
import { Type } from "class-transformer";
class PlateV6Dto {
@ApiProperty({ example: "44", description: "Left two digits" })
@IsString()
@IsNotEmpty()
leftDigits: string;
@ApiProperty({ example: "ب", description: "Center alphabet letter" })
@IsString()
@IsNotEmpty()
centerAlphabet: string;
@ApiProperty({ example: "111", description: "Center three digits" })
@IsString()
@IsNotEmpty()
centerDigits: string;
@ApiProperty({ example: "22", description: "Right two digits (Iran region code)" })
@IsString()
@IsNotEmpty()
ir: string;
}
/**
* Inquiry body for the V6 call-center flow.
* Same as V3 but without `sheba` — the user adds their own IBAN later via the link.
*/
export class RunCallCenterInquiryV6Dto {
@ApiProperty({
type: PlateV6Dto,
description: "Plate segments — Tejarat block / third-party inquiry.",
})
@ValidateNested()
@Type(() => PlateV6Dto)
plate: PlateV6Dto;
@ApiProperty({ example: "1234567890", description: "National code of the policyholder (insurer)" })
@IsString()
@IsNotEmpty()
nationalCodeOfInsurer: string;
@ApiProperty({ example: "1234567890", description: "National code of the driver" })
@IsString()
@IsNotEmpty()
nationalCodeOfDriver: string;
@ApiProperty({ example: true, description: "Whether the driver is the same person as the insurer" })
@IsBoolean()
driverIsInsurer: boolean;
@ApiProperty({ example: 13780624, description: "Insurer birth date (Jalali)" })
insurerBirthday: number | string;
@ApiPropertyOptional({
example: 13780624,
description: "Driver birth date (Jalali). Required when driverIsInsurer is false.",
})
@IsOptional()
driverBirthday?: number | string | null;
@ApiPropertyOptional({
example: "123456789",
description: "Driver license (required when driverIsInsurer is false).",
})
@IsOptional()
@IsString()
driverLicense?: string;
@ApiPropertyOptional({
example: "123456789",
description: "Insurer license (required when driverIsInsurer is true).",
})
@IsOptional()
@IsString()
insurerLicense?: string;
}

View File

@@ -117,12 +117,40 @@ export class BlameRequest {
@Prop({ default: false })
isMadeByFileMaker?: boolean;
/**
* V5 only. When true the resulting claim requires FileMaker approval before
* fanavaran submission. V4 files never set this; it is written at creation
* time by the V5 controller and propagated to the linked claim.
*/
@Prop({ default: false })
requiresFileMakerApproval?: boolean;
/**
* The FileReviewer who claimed this file for completion (V4 flow only).
* Set when a FileReviewer calls assign on this file; enforces one-reviewer-per-file.
*/
@Prop({ type: Types.ObjectId })
assignedFileReviewerId?: Types.ObjectId;
/**
* V6 call-center flow: true when this blame was started by a call-center agent
* on behalf of the guilty party who called in.
*/
@Prop({ default: false })
callCenterInitiated?: boolean;
/**
* V6 call-center flow: the call-center agent who created this file.
*/
@Prop({ type: Types.ObjectId })
initiatedByCallCenterId?: Types.ObjectId;
/**
* V6 call-center flow: when true the user-side blame page should skip the
* inquiry / initial-form step (the call-center agent already ran the inquiry).
*/
@Prop({ default: false })
skipInitialFormStep?: boolean;
}
export type BlameRequestDocument = HydratedDocument<BlameRequest>;

View File

@@ -34,6 +34,7 @@ import {
LocationDto,
} from "./dto/create-request-management.dto";
import { CreateExpertInitiatedFileDto } from "./dto/expert-initiated.dto";
import { CreationMethod } from "./entities/schema/request-management.schema";
import { SendPartyOtpsDto } from "./dto/send-party-otps.dto";
import { VerifyPartyOtpsDto } from "./dto/verify-party-otps.dto";
import { SendPartyOtpDto, VerifyPartyOtpDto } from "./dto/party-otp.dto";
@@ -75,17 +76,17 @@ export class ExpertInitiatedBlameMirrorController {
@ApiOperation({
summary: "[Expert mirror] Create expert-initiated blame file",
description:
"Use creationMethod=IN_PERSON for the on-site flow. Creates a BlameRequest owned by the parties but filled by the expert.",
"Creates an IN_PERSON blame file filled by the expert on behalf of both parties. creationMethod is always forced to IN_PERSON regardless of what is sent.",
})
@ApiBody({ type: CreateExpertInitiatedFileDto })
async create(
@CurrentUser() expert: any,
@Body() dto: CreateExpertInitiatedFileDto,
) {
return this.requestManagementService.createExpertInitiatedBlameV2(
expert,
dto,
);
return this.requestManagementService.createExpertInitiatedBlameV2(expert, {
...dto,
creationMethod: CreationMethod.IN_PERSON,
});
}
@Post("send-link/:requestId")

View File

@@ -87,7 +87,9 @@ export class FileMakerBlameV4Controller {
) {
return this.requestManagementService.createExpertInitiatedBlameV2(
fileMaker,
{ ...dto, creationMethod: CreationMethod.IN_PERSON },
// requiresFileMakerApproval is V5-only; explicitly exclude it from V4 so
// a client that accidentally sends the field cannot poison the blame record.
{ ...dto, creationMethod: CreationMethod.IN_PERSON, requiresFileMakerApproval: false },
);
}

View File

@@ -88,7 +88,7 @@ export class FileMakerBlameV5Controller {
) {
return this.requestManagementService.createExpertInitiatedBlameV2(
fileMaker,
{ ...dto, creationMethod: CreationMethod.IN_PERSON },
{ ...dto, creationMethod: CreationMethod.IN_PERSON, requiresFileMakerApproval: true },
);
}

View File

@@ -1,11 +1,15 @@
import { extname } from "node:path";
import {
BadRequestException,
Body,
Controller,
Get,
HttpException,
InternalServerErrorException,
Param,
Patch,
Post,
Put,
UploadedFile,
UseGuards,
UseInterceptors,
@@ -316,6 +320,73 @@ export class FileReviewerBlameV4Controller {
);
}
// ─── Owner signature on expert pricing ───────────────────────────────────────
@Put("claim-sign/:claimRequestId")
@ApiParam({ name: "claimRequestId" })
@ApiConsumes("multipart/form-data")
@ApiBody({
description: "Signature file, agreement, and branch",
schema: {
type: "object",
required: ["sign", "agree", "branchId"],
properties: {
sign: { type: "string", format: "binary", description: "Signature image" },
agree: { type: "boolean", description: "true to accept, false to reject" },
branchId: { type: "string", description: "Insurer branch ID" },
},
},
})
@ApiOperation({
summary: "Owner signature on expert pricing (V4 — FileReviewer acts on behalf of user)",
description:
"FileReviewer submits the damaged party's signature during the final approval stage. " +
"Delegates to the same service method as the user sign endpoint; the FileReviewer's " +
"identity is resolved to the claim owner via `resolveClaimEffectiveUserId`.",
})
@UseInterceptors(
FileInterceptor("sign", {
limits: { fileSize: DEFAULT_MEDIA_MAX_BYTES },
storage: diskStorage({
destination: "./files/claim-sign",
filename: (req, file, callback) => {
const unique = Date.now();
const ex = extname(file.originalname);
const base = file.originalname.split(/[.,\s-]/)[0] || "sign";
callback(null, `${base}-${unique}${ex}`);
},
}),
}),
)
async submitOwnerSign(
@Param("claimRequestId") claimRequestId: string,
@Body("agree") agree: string | boolean,
@Body("branchId") branchId: string,
@CurrentUser() fileReviewer: any,
@UploadedFile() sign: Express.Multer.File,
) {
await this.mediaPolicyService.assertForClaim(sign, claimRequestId, "image");
const agreed =
typeof agree === "string"
? agree === "true" || agree === "1"
: Boolean(agree);
try {
return await this.claimRequestManagementService.submitOwnerInsurerApprovalSignV2(
claimRequestId,
agreed,
typeof branchId === "string" ? branchId : "",
sign,
fileReviewer.sub,
fileReviewer,
);
} catch (error) {
if (error instanceof HttpException) throw error;
throw new InternalServerErrorException(
error instanceof Error ? error.message : "Failed to submit signature",
);
}
}
// ─── Walk-around video ────────────────────────────────────────────────────────
@Patch("car-capture/:claimRequestId")

View File

@@ -3,9 +3,12 @@ import {
Body,
Controller,
Get,
HttpException,
InternalServerErrorException,
Param,
Patch,
Post,
Put,
UploadedFile,
UseGuards,
UseInterceptors,
@@ -315,6 +318,73 @@ export class FileReviewerBlameV5Controller {
);
}
// ─── Owner signature on expert pricing ───────────────────────────────────────
@Put("claim-sign/:claimRequestId")
@ApiParam({ name: "claimRequestId" })
@ApiConsumes("multipart/form-data")
@ApiBody({
description: "Signature file, agreement, and branch",
schema: {
type: "object",
required: ["sign", "agree", "branchId"],
properties: {
sign: { type: "string", format: "binary", description: "Signature image" },
agree: { type: "boolean", description: "true to accept, false to reject" },
branchId: { type: "string", description: "Insurer branch ID" },
},
},
})
@ApiOperation({
summary: "Owner signature on expert pricing (V5 — FileReviewer acts on behalf of user)",
description:
"FileReviewer submits the damaged party's signature during the final approval stage. " +
"Delegates to the same service method as the user sign endpoint; the FileReviewer's " +
"identity is resolved to the claim owner via `resolveClaimEffectiveUserId`.",
})
@UseInterceptors(
FileInterceptor("sign", {
limits: { fileSize: DEFAULT_MEDIA_MAX_BYTES },
storage: diskStorage({
destination: "./files/claim-sign",
filename: (req, file, callback) => {
const unique = Date.now();
const ex = extname(file.originalname);
const base = file.originalname.split(/[.,\s-]/)[0] || "sign";
callback(null, `${base}-${unique}${ex}`);
},
}),
}),
)
async submitOwnerSign(
@Param("claimRequestId") claimRequestId: string,
@Body("agree") agree: string | boolean,
@Body("branchId") branchId: string,
@CurrentUser() fileReviewer: any,
@UploadedFile() sign: Express.Multer.File,
) {
await this.mediaPolicyService.assertForClaim(sign, claimRequestId, "image");
const agreed =
typeof agree === "string"
? agree === "true" || agree === "1"
: Boolean(agree);
try {
return await this.claimRequestManagementService.submitOwnerInsurerApprovalSignV2(
claimRequestId,
agreed,
typeof branchId === "string" ? branchId : "",
sign,
fileReviewer.sub,
fileReviewer,
);
} catch (error) {
if (error instanceof HttpException) throw error;
throw new InternalServerErrorException(
error instanceof Error ? error.message : "Failed to submit signature",
);
}
}
// ─── Walk-around video ────────────────────────────────────────────────────────
@Patch("car-capture/:claimRequestId")

View File

@@ -7,6 +7,7 @@ import {
import { Types } from "mongoose";
import { ClaimCaseDbService } from "src/claim-request-management/entites/db-service/claim-case.db.service";
import { SandHubService } from "src/sand-hub/sand-hub.service";
import { PlateNormalizerService } from "src/utils/plate-normalizer/plate-normalizer.service";
import { BlameRequestType } from "src/Types&Enums/blame-request-management/blameRequestType.enum";
import { BlameRequestDbService } from "./entities/db-service/blame-request.db.service";
import { PartyRole } from "./entities/schema/partyRole.enum";
@@ -33,6 +34,7 @@ export class InquiryRefreshService {
private readonly blameRequestDbService: BlameRequestDbService,
private readonly claimCaseDbService: ClaimCaseDbService,
private readonly sandHubService: SandHubService,
private readonly plateNormalizer: PlateNormalizerService,
) {}
async reinquiryInquiries(
@@ -592,7 +594,7 @@ export class InquiryRefreshService {
centerDigits !== undefined &&
ir !== undefined
) {
const plateLetter = String(centerAlphabet).trim();
const plateLetter = this.plateNormalizer.normalizePlateText(String(centerAlphabet));
const parsed: PlateParts = {
leftDigits: Number(leftDigits),
centerAlphabet: plateLetter,
@@ -622,8 +624,7 @@ export class InquiryRefreshService {
const ir = Number(irRaw);
const leftDigits = Number(leftRaw);
const centerDigits = Number(centerRaw);
const centerAlphabet = String(alphaRaw || "").trim();
const centerAlphabet = this.plateNormalizer.normalizePlateText(String(alphaRaw || ""));
if (
!Number.isFinite(ir) ||
!Number.isFinite(leftDigits) ||

View File

@@ -12,6 +12,7 @@ import { UsersModule } from "src/users/users.module";
import { CronModule } from "src/utils/cron/cron.module";
import { PublicIdModule } from "src/utils/public-id/public-id.module";
import { HashModule } from "src/utils/hash/hash.module";
import { PlateNormalizerModule } from "src/utils/plate-normalizer/plate-normalizer.module";
import { SmsOrchestrationModule } from "src/sms-orchestration/sms-orchestration.module";
import { WorkflowStepManagementModule } from "src/workflow-step-management/workflow-step-management.module";
import { AuthModule } from "src/auth/auth.module";
@@ -50,6 +51,7 @@ import { FileReviewerBlameV5Controller } from "./file-reviewer-blame-v5.controll
import { FileMakerClaimApprovalV5Controller } from "./file-maker-claim-approval-v5.controller";
import { InquiryRefreshController } from "./inquiry-refresh.controller";
import { InquiryRefreshService } from "./inquiry-refresh.service";
import { CallCenterBlameV6Controller } from "./call-center-blame-v6.controller";
@Module({
imports: [
@@ -59,6 +61,7 @@ import { InquiryRefreshService } from "./inquiry-refresh.service";
SmsOrchestrationModule,
PublicIdModule,
HashModule,
PlateNormalizerModule,
WorkflowStepManagementModule,
PlatesModule,
MulterModule.register({
@@ -92,6 +95,7 @@ import { InquiryRefreshService } from "./inquiry-refresh.service";
FileReviewerBlameV5Controller,
FileMakerClaimApprovalV5Controller,
InquiryRefreshController,
CallCenterBlameV6Controller,
],
providers: [
RequestManagementService,

View File

@@ -278,6 +278,32 @@ export class RequestManagementService {
return;
}
// IN_PERSON THIRD_PARTY (expert/registrar-initiated): after first-party description
// the expert collects the first party's signature before moving to the second party.
// Skip FIRST_INVITE_SECOND and hold at WAITING_FOR_SIGNATURES so the sign endpoint
// can be called for the first party. The workflow advances to FIRST_INVITE_SECOND
// only after expertUploadPartySignatureV2/V3 records the first-party confirmation.
if (
req.type === BlameRequestType.THIRD_PARTY &&
req.creationMethod === CreationMethod.IN_PERSON &&
(req.expertInitiated || req.registrarInitiated) &&
submittedStepKey === WorkflowStep.FIRST_DESCRIPTION
) {
const completed = Array.isArray(req.workflow.completedSteps)
? req.workflow.completedSteps
: [];
if (!completed.includes(submittedStepKey))
completed.push(submittedStepKey);
req.workflow.completedSteps = completed;
req.workflow.currentStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.workflow.nextStep = undefined;
req.status = CaseStatus.WAITING_FOR_SIGNATURES;
this.logger.debug(
"[WORKFLOW] IN_PERSON THIRD_PARTY: advanced to WAITING_FOR_SIGNATURES after FIRST_DESCRIPTION (first-party sign before second-party invite)",
);
return;
}
// IN_PERSON THIRD_PARTY: guilt is decided on-site by the expert — there is
// no waiting-for-field-expert phase. Replace WAITING_FOR_GUILT_DECISION
// with WAITING_FOR_SIGNATURES wherever it would surface as current/next step.
@@ -2087,13 +2113,9 @@ export class RequestManagementService {
? req.workflow.completedSteps
: [];
if (!completed.includes(stepKey)) completed.push(stepKey);
// Same as postfield-expert reply: guilt phase is satisfied without an expert; parties must still sign.
if (!completed.includes(WorkflowStep.WAITING_FOR_GUILT_DECISION)) {
completed.push(WorkflowStep.WAITING_FOR_GUILT_DECISION);
}
req.workflow.completedSteps = completed;
req.workflow.currentStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.workflow.nextStep = undefined;
req.workflow.nextStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.status = CaseStatus.WAITING_FOR_SIGNATURES;
closedByMutualAgreement = true;
@@ -2174,12 +2196,9 @@ export class RequestManagementService {
? req.workflow.completedSteps
: [];
if (!completed.includes(stepKey)) completed.push(stepKey);
if (!completed.includes(WorkflowStep.WAITING_FOR_GUILT_DECISION)) {
completed.push(WorkflowStep.WAITING_FOR_GUILT_DECISION);
}
req.workflow.completedSteps = completed;
req.workflow.currentStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.workflow.nextStep = undefined;
req.workflow.nextStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.status = CaseStatus.WAITING_FOR_SIGNATURES;
} else if (!closedByMutualAgreement) {
if (stepKey === WorkflowStep.SECOND_DESCRIPTION) {
@@ -2300,6 +2319,7 @@ export class RequestManagementService {
const url = this.smsOrchestrationService.buildInviteLink(
frontendRoute,
requestId,
"v1",
);
await this.smsOrchestrationService.sendInviteLink(
secondPartyPhone,
@@ -2353,6 +2373,7 @@ export class RequestManagementService {
const url = this.smsOrchestrationService.buildInviteLink(
frontendRoute,
requestId,
"v1",
);
await this.smsOrchestrationService.sendInviteLink(
phoneNumber,
@@ -3466,6 +3487,7 @@ export class RequestManagementService {
const URL = this.smsOrchestrationService.buildInviteLink(
frontendRoutes,
requestId,
"v1",
);
await this.smsOrchestrationService.sendInviteLink(
phoneNumber,
@@ -4816,6 +4838,9 @@ export class RequestManagementService {
? FilledBy.EXPERT
: FilledBy.CUSTOMER,
...(isFileMakerRole ? { isMadeByFileMaker: true } : {}),
// V5 only: flag that causes the resulting claim to require FileMaker
// approval before fanavaran submission. V4 files never set this.
...(dto.requiresFileMakerApproval ? { requiresFileMakerApproval: true } : {}),
});
const requestId = String((created as any)._id);
@@ -4905,6 +4930,7 @@ export class RequestManagementService {
const firstLink = this.smsOrchestrationService.buildBlamePartyLink(
requestId,
"FIRST",
"v2",
);
const smsSent = await this.smsOrchestrationService.sendFieldExpertLink({
receptor: phone,
@@ -6637,11 +6663,11 @@ export class RequestManagementService {
);
}
await this.verifyExpertAccessForBlameV2(req, expert);
// if (req.status !== CaseStatus.WAITING_FOR_SIGNATURES) {
// throw new BadRequestException(
// "Request is not waiting for signatures. Current status: " + req.status,
// );
// }
if (req.status !== CaseStatus.WAITING_FOR_SIGNATURES) {
throw new BadRequestException(
"Request is not waiting for signatures. Current status: " + req.status,
);
}
const partyIndex = this.getPartyIndex(req, partyRole);
if (partyIndex === -1) {
throw new BadRequestException(
@@ -6728,6 +6754,23 @@ export class RequestManagementService {
},
});
}
} else if (
// THIRD_PARTY IN_PERSON: first party just signed — advance workflow to
// FIRST_INVITE_SECOND so the frontend knows to proceed to the second-party
// registration step. Status stays WAITING_FOR_SIGNATURES.
req.type === BlameRequestType.THIRD_PARTY &&
req.creationMethod === CreationMethod.IN_PERSON &&
(req.expertInitiated || req.registrarInitiated) &&
partyRole === PartyRole.FIRST
) {
await this.blameRequestDbService.findByIdAndUpdate(requestId, {
$set: {
"workflow.currentStep": WorkflowStep.FIRST_INVITE_SECOND as any,
"workflow.nextStep": WorkflowStep.SECOND_INITIAL_FORM as any,
},
});
message =
"First party signature recorded. Proceed to register the second party.";
}
return {
requestId: String(req._id),
@@ -6753,6 +6796,18 @@ export class RequestManagementService {
);
}
await this.verifyExpertAccessForBlameV2(req, expert);
// In the V2 IN_PERSON mirror flow guilt is resolved automatically after both
// parties complete their narrative steps (addDescriptionV2). The sign step for
// both parties must happen BEFORE accident-fields is called — calling it earlier
// would overwrite the workflow and cause the frontend to skip the sign page.
if (
req.creationMethod === CreationMethod.IN_PERSON &&
req.status !== CaseStatus.COMPLETED
) {
throw new BadRequestException(
`accident-fields can only be submitted after both parties have signed (current status: ${req.status}). Complete both signatures first.`,
);
}
if (!req.expert) req.expert = {} as any;
if (!req.expert.decision) req.expert.decision = {} as any;
@@ -6781,29 +6836,24 @@ export class RequestManagementService {
},
};
// For IN_PERSON expert files: after accident fields are filled, guilt is
// decided and we can go straight to signatures (no separate review needed).
// IN_PERSON V2 mirror: accident-fields is a post-sign supplemental step called
// only after COMPLETED (both parties have signed). Record WAITING_FOR_GUILT_DECISION
// in completedSteps here — it was intentionally omitted from description so the
// frontend does not route to this page before signatures are collected.
if (req.creationMethod === CreationMethod.IN_PERSON) {
const completed = Array.isArray(req.workflow?.completedSteps)
? req.workflow.completedSteps
: [];
const currentStep = req.workflow?.currentStep as WorkflowStep | undefined;
if (currentStep && !completed.includes(currentStep)) {
completed.push(currentStep);
}
if (!completed.includes(WorkflowStep.WAITING_FOR_GUILT_DECISION)) {
completed.push(WorkflowStep.WAITING_FOR_GUILT_DECISION);
}
if (req.workflow) {
req.workflow.completedSteps = completed;
req.workflow.currentStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.workflow.nextStep = undefined;
}
req.status = CaseStatus.WAITING_FOR_SIGNATURES;
if (!Array.isArray(req.history)) req.history = [];
req.history.push({
type: "ACCIDENT_FIELDS_SAVED_ADVANCED_TO_SIGNATURES",
type: "ACCIDENT_FIELDS_SAVED",
actor: {
actorId: new Types.ObjectId(String(expert.sub)),
actorName:
@@ -6812,7 +6862,6 @@ export class RequestManagementService {
},
metadata: {
accidentWay: fields.accidentWay,
advancedTo: WorkflowStep.WAITING_FOR_SIGNATURES,
},
} as any);
}
@@ -8320,6 +8369,7 @@ export class RequestManagementService {
targetPhone === request?.parties[0]?.person.phoneNumber
? "FIRST"
: "SECOND",
"v1",
);
await this.smsOrchestrationService.sendThirdPartyDamagedPartyClaimLinkNotice(
{
@@ -8834,9 +8884,10 @@ export class RequestManagementService {
},
}
: {}),
// V5 (isMadeByFileMaker): mark approval gate at claim creation so the flag
// is always present regardless of whether upload-video is called.
...((req as any).isMadeByFileMaker
// V5 only: propagate the approval gate from the blame record to the claim.
// isMadeByFileMaker is true for both V4 and V5; only V5 blame records also
// carry requiresFileMakerApproval=true (set at create time by the V5 controller).
...((req as any).requiresFileMakerApproval
? {
requiresFileMakerApproval: true,
fileMakerApprovalActorId: new Types.ObjectId(actor.sub),
@@ -9242,12 +9293,11 @@ export class RequestManagementService {
fresh.workflow.currentStep = WorkflowStep.FIRST_INVITE_SECOND;
fresh.workflow.nextStep = WorkflowStep.SECOND_INITIAL_FORM;
} else {
// CAR_BODY: FileMaker is done — seal the file for FileReviewer pickup
// CAR_BODY: FileMaker's narrative is done — move to document-upload step.
// blame.status transitions to WAITING_FOR_FILE_REVIEWER only after the
// FileMaker completes all document uploads, not here at sign time.
fresh.workflow.currentStep = WorkflowStep.FIRST_COMPLETED;
fresh.workflow.nextStep = WorkflowStep.WAITING_FOR_GUILT_DECISION;
if (isFileMakerActor) {
fresh.status = CaseStatus.WAITING_FOR_FILE_REVIEWER;
}
}
} else {
this.pushWorkflowSteps(fresh, [
@@ -9259,10 +9309,8 @@ export class RequestManagementService {
]);
fresh.workflow.currentStep = WorkflowStep.SECOND_COMPLETED;
fresh.workflow.nextStep = WorkflowStep.WAITING_FOR_GUILT_DECISION;
// THIRD_PARTY: second party sign is FileMaker's last step — seal for FileReviewer
if (isFileMakerActor) {
fresh.status = CaseStatus.WAITING_FOR_FILE_REVIEWER;
}
// blame.status transitions to WAITING_FOR_FILE_REVIEWER only after the
// FileMaker completes all document uploads, not here at sign time.
}
await (fresh as any).save();
}
@@ -9325,16 +9373,26 @@ export class RequestManagementService {
},
};
if (typeof (req as any).markModified === "function") {
(req as any).markModified("expert");
}
if (!Array.isArray(req.history)) req.history = [];
req.history.push({
type: "V3_ACCIDENT_FIELDS_SAVED",
actor: {
actorId: new Types.ObjectId(String(expert.sub)),
actorName: `${expert.firstName || ""} ${expert.lastName || ""}`.trim(),
actorType: "field_expert",
},
metadata: { accidentWay: fields.accidentWay },
} as any);
// Avoid duplicate history entries on idempotent retries.
const alreadyRecorded = (req.history as any[]).some(
(e: any) => e?.type === "V3_ACCIDENT_FIELDS_SAVED",
);
if (!alreadyRecorded) {
req.history.push({
type: "V3_ACCIDENT_FIELDS_SAVED",
actor: {
actorId: new Types.ObjectId(String(expert.sub)),
actorName: `${expert.firstName || ""} ${expert.lastName || ""}`.trim(),
actorType: "field_expert",
},
metadata: { accidentWay: fields.accidentWay },
} as any);
}
await (req as any).save();
@@ -10032,4 +10090,251 @@ export class RequestManagementService {
);
}
}
// ── V6 call-center flow ────────────────────────────────────────────────
/**
* V6: Create a LINK blame file initiated by a call-center agent.
* Always LINK + CUSTOMER-filled (user fills the form after receiving the SMS).
* `skipInitialFormStep` is set so the user-side page skips the inquiry step
* (the agent already ran it via runCallCenterInquiryV6).
*/
async createCallCenterInitiatedBlameV6(
agent: any,
dto: { type: "THIRD_PARTY" | "CAR_BODY" },
): Promise<{ requestId: string; publicId: string }> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const agentId = new Types.ObjectId(agent.sub);
const type =
dto.type === "CAR_BODY"
? BlameRequestType.CAR_BODY
: BlameRequestType.THIRD_PARTY;
const firstStep = await this.getWorkflowStep({ stepNumber: 1 });
if (!firstStep?.stepKey) {
throw new InternalServerErrorException(
"Workflow stepNumber=1 not configured in step manager",
);
}
const nextStepFromManager = firstStep.nextPossibleSteps?.[0];
const nextStep =
type === BlameRequestType.CAR_BODY
? (WorkflowStep.CAR_BODY_ACCIDENT_TYPE as WorkflowStep)
: (nextStepFromManager as WorkflowStep);
if (!nextStep) {
throw new InternalServerErrorException(
"Workflow stepNumber=1 has no nextPossibleSteps configured",
);
}
const publicId = await this.publicIdService.generateRequestPublicId();
const created = await this.blameRequestDbService.create({
publicId,
requestNo: publicId,
type,
parties: [{ role: PartyRole.FIRST, person: {} }],
workflow: {
currentStep: firstStep.stepKey as WorkflowStep,
nextStep,
completedSteps: [firstStep.stepKey as WorkflowStep],
locked: false,
},
history: [],
callCenterInitiated: true,
initiatedByCallCenterId: agentId,
creationMethod: CreationMethod.LINK,
filledBy: FilledBy.CUSTOMER,
// User-side page should skip the inquiry/initial-form step
skipInitialFormStep: true,
});
const requestId = String((created as any)._id);
if (!Array.isArray((created as any).history)) (created as any).history = [];
(created as any).history.push({
type: "FILE_CREATED_BY_CALL_CENTER",
actor: {
actorId: agentId,
actorName: `${agent.firstName || ""} ${agent.lastName || ""}`.trim(),
actorType: RoleEnum.CALL_CENTER,
},
metadata: { creationMethod: CreationMethod.LINK, type: dto.type },
});
await (created as any).save();
return { requestId, publicId: (created as any).publicId };
}
/**
* V6: Run plate + personal inquiry for the guilty party on behalf of the caller.
* Stores the inquiry results on the blame's first party (same as V3 guilty-party path)
* but does NOT create a claim — the user will do that after filling the form via the link.
* Note: sheba is intentionally absent — the user provides their own IBAN later.
*/
async runCallCenterInquiryV6(
agent: any,
requestId: string,
dto: Omit<RunInquiriesV3Dto, "sheba">,
): Promise<{ blameRequestId: string; message: string }> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const req = await this.blameRequestDbService.findById(requestId);
if (!req) throw new NotFoundException("Blame request not found");
if (!req.callCenterInitiated || String(req.initiatedByCallCenterId) !== String(agent.sub)) {
throw new ForbiddenException("You can only access files that you have initiated.");
}
const firstIdx = this.getPartyIndex(req, PartyRole.FIRST);
if (firstIdx === -1) throw new BadRequestException("First party not found");
const firstParty = req.parties[firstIdx];
await this.runPartyInquiriesV3Internal(req, dto, PartyRole.FIRST, firstParty);
this.markPartyInquiriesCompleteOnBlame(req, PartyRole.FIRST, agent);
if (!Array.isArray((req as any).history)) (req as any).history = [];
(req as any).history.push({
type: "CALL_CENTER_INQUIRY_COMPLETED",
actor: {
actorId: new Types.ObjectId(agent.sub),
actorName: `${agent.firstName || ""} ${agent.lastName || ""}`.trim(),
actorType: RoleEnum.CALL_CENTER,
},
metadata: { partyRole: PartyRole.FIRST },
});
await (req as any).save();
return {
blameRequestId: requestId,
message: "Guilty-party inquiry complete. You can now send the blame link to the user.",
};
}
/**
* V6: Send the blame link to the guilty party's phone number.
* Registers/looks up the user by phone and stores them as the first party, then
* sends the SMS link so the user can fill in the rest of the form via the v2 flow.
*/
async sendCallCenterLinkV6(
agent: any,
requestId: string,
dto: { phoneNumber: string },
): Promise<{ sent: boolean; sentTo: { role: string; phoneNumber: string; smsSent: boolean; linkUrl: string }[] }> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const req = await this.blameRequestDbService.findById(requestId);
if (!req) throw new NotFoundException("Request not found");
if (!req.callCenterInitiated || String(req.initiatedByCallCenterId) !== String(agent.sub)) {
throw new ForbiddenException("You can only access files that you have initiated.");
}
if (!process.env.URL) {
throw new InternalServerErrorException("URL environment variable is not configured");
}
const phone = (dto?.phoneNumber || "").trim();
if (!phone) throw new BadRequestException("phoneNumber is required");
const firstIdx = this.getPartyIndex(req, PartyRole.FIRST);
if (firstIdx === -1) throw new BadRequestException("First party not found on request");
const userId = await this.getOrCreateUserByPhoneNumber(phone);
if (!req.parties[firstIdx].person) req.parties[firstIdx].person = {} as any;
req.parties[firstIdx].person.phoneNumber = normalizeIranMobile(phone) ?? phone;
req.parties[firstIdx].person.userId = userId;
const expertName = `${agent?.lastName || ""}`.trim() || "اپراتور";
const firstLink = this.smsOrchestrationService.buildBlamePartyLink(requestId, "FIRST", "v6");
const smsSent = await this.smsOrchestrationService.sendFieldExpertLink({
receptor: phone,
type: req.type,
expertLastName: expertName,
link: firstLink,
});
const sentTo = [{ role: PartyRole.FIRST, phoneNumber: phone, smsSent, linkUrl: firstLink }];
if (!Array.isArray((req as any).history)) (req as any).history = [];
(req as any).history.push({
type: "CALL_CENTER_LINK_SENT",
actor: {
actorId: new Types.ObjectId(agent.sub),
actorName: `${agent.firstName || ""} ${agent.lastName || ""}`.trim(),
actorType: RoleEnum.CALL_CENTER,
},
metadata: { sentTo },
});
await (req as any).save();
return { sent: smsSent, sentTo };
}
/**
* V6: Get a single blame file detail for the call-center agent who created it.
*/
async getCallCenterBlameDetailV6(agent: any, requestId: string): Promise<any> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const req = await this.blameRequestDbService.findById(requestId);
if (!req) throw new NotFoundException("Blame request not found");
if (!req.callCenterInitiated || String(req.initiatedByCallCenterId) !== String(agent.sub)) {
throw new ForbiddenException("You can only access files that you have initiated.");
}
return {
_id: (req as any)._id,
publicId: (req as any).publicId,
requestNo: (req as any).requestNo,
type: (req as any).type,
status: (req as any).status,
blameStatus: (req as any).blameStatus,
workflow: (req as any).workflow,
skipInitialFormStep: (req as any).skipInitialFormStep,
parties: ((req as any).parties ?? []).map((p: any) => ({
role: p.role,
person: {
phoneNumber: p.person?.phoneNumber,
nationalCodeOfInsurer: p.person?.nationalCodeOfInsurer,
clientId: p.person?.clientId,
},
insurance: p.insurance
? {
company: p.insurance.company,
policyNumber: p.insurance.policyNumber,
startDate: p.insurance.startDate,
endDate: p.insurance.endDate,
}
: undefined,
vehicle: p.vehicle
? { plateId: p.vehicle.plateId, name: p.vehicle.name }
: undefined,
})),
createdAt: (req as any).createdAt,
};
}
/**
* V6: List blame files created by this call-center agent.
*/
async getMyCallCenterFilesV6(agent: any): Promise<any[]> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const agentId = new Types.ObjectId(agent.sub);
const files = await this.blameRequestDbService.find({
callCenterInitiated: true,
initiatedByCallCenterId: agentId,
});
return (files || []).map((f: any) => ({
_id: f._id,
publicId: f.publicId,
requestNo: f.requestNo,
type: f.type,
status: f.status,
blameStatus: f.blameStatus,
workflow: f.workflow,
skipInitialFormStep: f.skipInitialFormStep,
createdAt: f.createdAt,
}));
}
}

View File

@@ -5,6 +5,7 @@ import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
import { MongooseModule } from "@nestjs/mongoose";
import { ClientModule } from "src/client/client.module";
import { SystemSettingsModule } from "src/system-settings/system-settings.module";
import { PlateNormalizerModule } from "src/utils/plate-normalizer/plate-normalizer.module";
import { SandHubDbService } from "src/sand-hub/entity/db-service/sand-hub.db.service";
import { SandHubModel, SandHubSchema } from "./entity/schema/sand-hub.schema";
import { SandHubService } from "./sand-hub.service";
@@ -17,6 +18,7 @@ import { SandHubService } from "./sand-hub.service";
useFactory: createHttpModuleOptions,
}),
SystemSettingsModule,
PlateNormalizerModule,
ClientModule,
MongooseModule.forFeature([
{ name: SandHubModel.name, schema: SandHubSchema },

View File

@@ -9,6 +9,9 @@ describe("SandHubService inquiry mocks", () => {
isInquiryLive: jest.fn(),
getMockCompanyContext: jest.fn(),
};
const plateNormalizer = {
normalizePlateText: (text: string) => text,
};
let service: SandHubService;
@@ -30,6 +33,7 @@ describe("SandHubService inquiry mocks", () => {
httpService as any,
sandHubDbService as any,
externalInquirySettings as unknown as ExternalInquirySettingsService,
plateNormalizer as any,
);
externalInquirySettings.isInquiryLive.mockResolvedValue(false);
externalInquirySettings.getMockCompanyContext.mockResolvedValue({

View File

@@ -12,6 +12,7 @@ import {
import { SandHubDbService } from "src/sand-hub/entity/db-service/sand-hub.db.service";
import { SandHubModel } from "src/sand-hub/entity/schema/sand-hub.schema";
import { ExternalInquirySettingsService } from "src/client/external-inquiry-settings.service";
import { PlateNormalizerService } from "src/utils/plate-normalizer/plate-normalizer.service";
import type { ExternalInquiryType } from "src/common/types/external-inquiry.types";
import type { MockInquiryCompanyContext } from "src/common/types/external-inquiry.types";
import { SandHubDetailDto, SandHubInquiryOptions } from "./dto/sand-hub.dto";
@@ -39,6 +40,7 @@ export class SandHubService {
private readonly httpService: HttpService,
private readonly sandHubDbService: SandHubDbService,
private readonly externalInquirySettings: ExternalInquirySettingsService,
private readonly plateNormalizer: PlateNormalizerService,
) {}
private clientRefFrom(options?: SandHubInquiryOptions): string | undefined {
@@ -162,8 +164,8 @@ export class SandHubService {
nationalCodeOfInsurer: nationalCode,
plate: {
leftDigits: Number(payload.part1 ?? payload.leftTwoDigits ?? 16),
centerAlphabet: String(
payload.part2 ?? payload.serialLetter ?? "12",
centerAlphabet: this.plateNormalizer.normalizePlateText(
String(payload.part2 ?? payload.serialLetter ?? "12"),
),
centerDigits: Number(payload.part3 ?? payload.threeDigits ?? 498),
ir: Number(payload.part4 ?? payload.rightTwoDigits ?? 60),

View File

@@ -1,6 +1,7 @@
import { HttpModule } from "@nestjs/axios";
import { Module } from "@nestjs/common";
import { ConfigModule } from "@nestjs/config";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
import { KavenegarService } from "./kavenegar.service";
import { KavenegarSmsGateway } from "./kavenegar-sms.gateway";
@@ -8,7 +9,14 @@ import { ParsianSmsGateway } from "./parsian-sms.gateway";
import { SmsGatewayService } from "./sms-gateway.service";
@Module({
imports: [HttpModule, ConfigModule],
imports: [
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
ConfigModule,
],
providers: [
KavenegarService,
KavenegarSmsGateway,

View File

@@ -6,10 +6,16 @@ import { SmsGatewayModule } from "./provider/sms-gateway.module";
import { OtpGeneratorService } from "./otp-generator.service";
import { SmsOrchestrationService } from "./sms-orchestration.service";
import { HttpModule } from "@nestjs/axios";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
@Module({
imports: [
HttpModule,
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
SmsGatewayModule,
MongooseModule.forFeature([{ name: SmsText.name, schema: SmsTextSchema }]),
],

View File

@@ -37,20 +37,25 @@ export class SmsOrchestrationService implements OnModuleInit {
);
}
buildInviteLink(frontendRoute: string, requestId: string): string {
return `${process.env.URL}/${process.env.USER_BASE_PATH}/${frontendRoute}?token=${requestId}`;
buildInviteLink(
frontendRoute: string,
requestId: string,
versionPrefix: string,
): string {
return `${process.env.URL}/${versionPrefix}/${frontendRoute}?token=${requestId}`;
}
buildBlamePartyLink(
requestId: string,
partyRole: "FIRST" | "SECOND",
versionPrefix: string,
): string {
const route = partyRole === "SECOND" ? "user2" : "user";
return `${process.env.URL}/${process.env.USER_BASE_PATH}/${route}?token=${requestId}`;
return `${process.env.URL}/${versionPrefix}/${route}?token=${requestId}`;
}
buildClaimLink(claimRequestId: string): string {
return `${process.env.URL}/${process.env.USER_BASE_PATH}/caseClaim?token=${claimRequestId}`;
buildClaimLink(claimRequestId: string, versionPrefix: string): string {
return `${process.env.URL}/${versionPrefix}/caseClaim?token=${claimRequestId}`;
}
async sendInviteLink(

View File

@@ -74,3 +74,37 @@ export class CreateRegistrarAdminDto {
@IsNotEmpty()
clientId: string;
}
export class CreateCallCenterAgentDto {
@ApiProperty({ example: "agent@insurer.ir" })
@IsEmail()
email: string;
@ApiProperty({ example: "CallCenter@724" })
@IsString()
@IsNotEmpty()
password: string;
@ApiProperty({ example: "Sara" })
@IsString()
@IsNotEmpty()
firstName: string;
@ApiProperty({ example: "Hosseini" })
@IsString()
@IsNotEmpty()
lastName: string;
@ApiProperty({
example: "664a1b2c3d4e5f6789012345",
description: "Mongo ObjectId of the insurer client this agent belongs to.",
})
@IsString()
@IsNotEmpty()
clientId: string;
@ApiPropertyOptional({ example: "09121234567" })
@IsOptional()
@IsString()
mobile?: string;
}

View File

@@ -1,24 +1,32 @@
import {
BadRequestException,
Body,
Controller,
Get,
Param,
Patch,
Post,
Put,
Query,
UseGuards,
} from "@nestjs/common";
import {
ApiBearerAuth,
ApiBody,
ApiOperation,
ApiParam,
ApiQuery,
ApiResponse,
ApiTags,
} from "@nestjs/swagger";
import { Types } from "mongoose";
import { SuperAdminGuard } from "./guards/super-admin.guard";
import { SuperAdminService } from "./super-admin.service";
import {
CreateSuperAdminDto,
CreateFieldExpertAdminDto,
CreateRegistrarAdminDto,
CreateCallCenterAgentDto,
} from "./dto/super-admin.dto";
import { ClientDto } from "src/client/dto/create-client.dto";
import {
@@ -32,6 +40,20 @@ import {
UpdateSystemSettingsDto,
} from "src/system-settings/dto/system-settings.dto";
import { SetExternalInquiriesLiveDto } from "src/client/dto/external-inquiries-live.dto";
import { ExpertInsurerService } from "src/expert-insurer/expert-insurer.service";
import { ListQueryV2Dto } from "src/common/dto/list-query-v2.dto";
import {
UnifiedFileStatusReportDto,
UnifiedFileStatusReportQueryDto,
} from "src/common/dto/unified-file-status-report.dto";
import { CreateBranchDto } from "src/client/dto/create-branch.dto";
import { FileRating } from "src/request-management/entities/schema/request-management.schema";
import {
CreateBlameExpertByInsurerDto,
CreateClaimExpertByInsurerDto,
CreateFileMakerByInsurerDto,
CreateFileReviewerByInsurerDto,
} from "src/expert-insurer/dto/create-insurer-expert.dto";
@ApiTags("super-admin")
@ApiBearerAuth()
@@ -41,6 +63,7 @@ export class SuperAdminController {
constructor(
private readonly superAdminService: SuperAdminService,
private readonly systemSettingsService: SystemSettingsService,
private readonly expertInsurerService: ExpertInsurerService,
) {}
// ── Super-admin account management ───────────────────────────────────────
@@ -129,6 +152,13 @@ export class SuperAdminController {
return this.superAdminService.createRegistrar(body);
}
@Post("create-call-center-agent")
@ApiOperation({ summary: "Create a call-center agent for a given client" })
@ApiBody({ type: CreateCallCenterAgentDto })
createCallCenterAgent(@Body() body: CreateCallCenterAgentDto) {
return this.superAdminService.createCallCenterAgent(body);
}
// ── System settings ──────────────────────────────────────────────────────
@Get("system-settings")
@@ -159,4 +189,313 @@ export class SuperAdminController {
externalApis: { sandHubUseLiveApi: body?.enabled === true },
});
}
// ── Insurer panel (super-admin proxy) ────────────────────────────────────
@Get("insurer/branches")
@ApiOperation({ summary: "List branches for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
@ApiQuery({ name: "search", required: false, type: String })
@ApiQuery({ name: "from", required: false, description: "Optional start datetime (ISO string)" })
@ApiQuery({ name: "to", required: false, description: "Optional end datetime (ISO string)" })
@ApiQuery({ name: "isActive", required: false, description: "Filter active state (true/false)" })
getInsuranceBranches(
@Query("clientId") clientId: string,
@Query("search") search?: string,
@Query("from") from?: string,
@Query("to") to?: string,
@Query("isActive") isActive?: string,
) {
return this.expertInsurerService.retrieveInsuranceBranches(
clientId,
{ search, from, to, isActive },
);
}
@Post("insurer/branches")
@ApiOperation({ summary: "Add a branch for a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateBranchDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addBranch(
@Body("clientId") clientId: string,
@Body() createBranchDto: CreateBranchDto,
) {
return this.expertInsurerService.addBranch(clientId, createBranchDto);
}
@Put("insurer/branches/:branchId/status")
@ApiOperation({ summary: "Set branch active/inactive for a given client" })
@ApiParam({ name: "branchId" })
@ApiBody({
schema: {
type: "object",
properties: {
clientId: { type: "string", description: "Client ObjectId" },
isActive: { type: "boolean" },
},
required: ["clientId", "isActive"],
},
})
setBranchStatus(
@Param("branchId") branchId: string,
@Body("clientId") clientId: string,
@Body("isActive") isActive: unknown,
) {
let active: boolean;
if (typeof isActive === "boolean") {
active = isActive;
} else {
const normalized = String(isActive ?? "").trim().toLowerCase();
if (!["true", "false", "1", "0", "yes", "no"].includes(normalized)) {
throw new BadRequestException("isActive must be a boolean");
}
active = ["true", "1", "yes"].includes(normalized);
}
return this.expertInsurerService.setBranchActive(clientId, branchId, active);
}
@Post("insurer/experts/blame")
@ApiOperation({ summary: "Create a blame expert under a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateBlameExpertByInsurerDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addBlameExpert(
@Body("clientId") clientId: string,
@Body() body: CreateBlameExpertByInsurerDto,
) {
return this.expertInsurerService.addBlameExpert(clientId, body);
}
@Post("insurer/experts/claim")
@ApiOperation({ summary: "Create a claim expert under a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateClaimExpertByInsurerDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addClaimExpert(
@Body("clientId") clientId: string,
@Body() body: CreateClaimExpertByInsurerDto,
) {
return this.expertInsurerService.addClaimExpert(clientId, body);
}
@Post("insurer/experts/file-maker")
@ApiOperation({ summary: "Create a FileMaker account under a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateFileMakerByInsurerDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addFileMaker(
@Body("clientId") clientId: string,
@Body() body: CreateFileMakerByInsurerDto,
) {
return this.expertInsurerService.addFileMaker(clientId, body);
}
@Post("insurer/experts/file-reviewer")
@ApiOperation({ summary: "Create a FileReviewer account under a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateFileReviewerByInsurerDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addFileReviewer(
@Body("clientId") clientId: string,
@Body() body: CreateFileReviewerByInsurerDto,
) {
return this.expertInsurerService.addFileReviewer(clientId, body);
}
@Get("insurer/experts/list")
@ApiOperation({ summary: "List all experts of a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
@ApiQuery({ name: "page", type: Number })
@ApiQuery({ name: "response_count", type: Number })
getAllExperts(
@Query("clientId") clientId: string,
@Query("page") page: number,
@Query("response_count") count: number,
) {
return this.expertInsurerService.retrieveAllExpertsOfClient(
{ clientKey: clientId },
page,
count,
);
}
@Get("insurer/experts/top")
@ApiOperation({ summary: "Top blame vs claim experts for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
getTopExperts(@Query("clientId") clientId: string) {
return this.expertInsurerService.getTopExpertsForClient({ clientKey: clientId });
}
@Get("insurer/files")
@ApiOperation({ summary: "List files (blame + claim merged) for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
getAllFiles(
@Query("clientId") clientId: string,
@Query() query: ListQueryV2Dto,
) {
return this.expertInsurerService.retrieveAllFilesOfClient(clientId, query);
}
@Get("insurer/report/unified-file-statuses")
@ApiOperation({ summary: "Unified file status catalog + counts for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
@ApiResponse({ status: 200, type: UnifiedFileStatusReportDto })
getUnifiedFileStatusReport(
@Query("clientId") clientId: string,
@Query() query: UnifiedFileStatusReportQueryDto,
): Promise<UnifiedFileStatusReportDto> {
return this.expertInsurerService.getInsurerUnifiedFileStatusReport(
{ clientKey: clientId },
query,
);
}
@Get("insurer/report/status-counts")
@ApiOperation({
summary: "Legacy status counts for a given client",
deprecated: true,
description: "Prefer GET insurer/report/unified-file-statuses.",
})
@ApiQuery({ name: "clientId", required: true, type: String })
@ApiQuery({ name: "from", required: false, description: "Optional start datetime (ISO string)" })
@ApiQuery({ name: "to", required: false, description: "Optional end datetime (ISO string)" })
getInsurerStatusReport(
@Query("clientId") clientId: string,
@Query("from") from?: string,
@Query("to") to?: string,
) {
return this.expertInsurerService.getInsurerFileStatusCounts(
{ clientKey: clientId },
from,
to,
);
}
@Get("insurer/files/:publicId/timeline")
@ApiOperation({ summary: "Activity timeline for a case of a given client" })
@ApiParam({ name: "publicId" })
@ApiQuery({ name: "clientId", required: true, type: String })
getFileTimeline(
@Query("clientId") clientId: string,
@Param("publicId") publicId: string,
) {
return this.expertInsurerService.getFileTimeline(clientId, publicId);
}
@Get("insurer/files/:publicId")
@ApiOperation({ summary: "File details by publicId for a given client" })
@ApiParam({ name: "publicId" })
@ApiQuery({ name: "clientId", required: true, type: String })
getFileDetailsByPublicId(
@Query("clientId") clientId: string,
@Param("publicId") publicId: string,
) {
return this.expertInsurerService.retrieveFileDetailsByPublicId(clientId, publicId);
}
// @Put("insurer/files/:publicId/rating")
// @ApiOperation({ summary: "Rate experts by publicId for a given client" })
// @ApiParam({ name: "publicId" })
// @ApiBody({
// schema: {
// type: "object",
// required: [
// "clientId",
// "collisionMethodAccuracy",
// "evaluationTimeliness",
// "accidentCauseAccuracy",
// "guiltyVehicleIdentification",
// "botRating",
// ],
// properties: {
// clientId: { type: "string", description: "Client ObjectId" },
// collisionMethodAccuracy: { type: "number", minimum: 0, maximum: 5 },
// evaluationTimeliness: { type: "number", minimum: 0, maximum: 5 },
// accidentCauseAccuracy: { type: "number", minimum: 0, maximum: 5 },
// guiltyVehicleIdentification: { type: "number", minimum: 0, maximum: 5 },
// botRating: { type: "number", minimum: 0, maximum: 5 },
// },
// },
// })
// rateExpertsByPublicId(
// @Param("publicId") publicId: string,
// @Body() body: FileRating & { clientId: string },
// ) {
// const { clientId, ...rating } = body;
// return this.expertInsurerService.rateExpertByPublicId(publicId, rating as FileRating, clientId);
// }
@Get("insurer/top-files")
@ApiOperation({ summary: "Top-rated files for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
getTopFiles(@Query("clientId") clientId: string) {
return this.expertInsurerService.getTopFilesForClient(clientId);
}
@Get("insurer/statistics")
@ApiOperation({ summary: "Expert statistics report for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
getExpertStatistics(@Query("clientId") clientId: string) {
return this.expertInsurerService.getExpertStatisticsReport({ clientKey: clientId });
}
@Get("insurer/:expertId")
@ApiOperation({ summary: "Files handled by one roster expert for a given client" })
@ApiParam({ name: "expertId" })
@ApiQuery({ name: "clientId", required: true, type: String })
getExpertFiles(
@Query("clientId") clientId: string,
@Param("expertId") expertId: string,
) {
if (!Types.ObjectId.isValid(expertId)) {
throw new BadRequestException("Invalid expert ID");
}
return this.expertInsurerService.getAllFilesForInsurerExpert(expertId, clientId);
}
}

View File

@@ -3,6 +3,7 @@ import { ClientModule } from "src/client/client.module";
import { SystemSettingsModule } from "src/system-settings/system-settings.module";
import { HashModule } from "src/utils/hash/hash.module";
import { UsersModule } from "src/users/users.module";
import { ExpertInsurerModule } from "src/expert-insurer/expert-insurer.module";
import { SuperAdminController } from "./super-admin.controller";
import { SuperAdminService } from "./super-admin.service";
import { SuperAdminGuard } from "./guards/super-admin.guard";
@@ -26,6 +27,7 @@ import { SuperAdminGuard } from "./guards/super-admin.guard";
SystemSettingsModule,
HashModule,
UsersModule,
ExpertInsurerModule,
],
controllers: [SuperAdminController],
providers: [SuperAdminService, SuperAdminGuard],

View File

@@ -19,10 +19,12 @@ import {
CreateSuperAdminDto,
CreateFieldExpertAdminDto,
CreateRegistrarAdminDto,
CreateCallCenterAgentDto,
} from "./dto/super-admin.dto";
import { RoleEnum } from "src/Types&Enums/role.enum";
import { FieldExpertDbService } from "src/users/entities/db-service/field-expert.db.service";
import { RegistrarDbService } from "src/users/entities/db-service/registrar.db.service";
import { CallCenterAgentDbService } from "src/users/entities/db-service/call-center-agent.db.service";
@Injectable()
export class SuperAdminService {
@@ -33,6 +35,7 @@ export class SuperAdminService {
private readonly actorAuthService: ActorAuthService,
private readonly fieldExpertDbService: FieldExpertDbService,
private readonly registrarDbService: RegistrarDbService,
private readonly callCenterAgentDbService: CallCenterAgentDbService,
) {}
/** List all super-admin accounts (sans password). */
@@ -99,4 +102,28 @@ export class SuperAdminService {
async createRegistrar(body: CreateRegistrarAdminDto) {
return this.actorAuthService.createRegistrarMock(body);
}
async createCallCenterAgent(body: CreateCallCenterAgentDto) {
const email = body.email.toLowerCase().trim();
const existing = await this.callCenterAgentDbService.findOne({ email });
if (existing) {
throw new ConflictException(
"A call-center agent with this email already exists.",
);
}
const password = await this.hashService.hash(body.password);
const created = await this.callCenterAgentDbService.create({
email,
password,
firstName: body.firstName,
lastName: body.lastName,
clientKey: new Types.ObjectId(body.clientId),
mobile: body.mobile,
role: RoleEnum.CALL_CENTER,
});
const { password: _pw, ...rest } = (created as any).toObject
? (created as any).toObject()
: (created as any);
return rest;
}
}

View File

@@ -0,0 +1,50 @@
import { Injectable } from "@nestjs/common";
import { InjectModel } from "@nestjs/mongoose";
import { FilterQuery, Model, Types } from "mongoose";
import { CallCenterAgentModel } from "../schema/call-center-agent.schema";
@Injectable()
export class CallCenterAgentDbService {
constructor(
@InjectModel(CallCenterAgentModel.name)
private readonly model: Model<CallCenterAgentModel>,
) {}
async create(
data: Partial<CallCenterAgentModel> & { password: string },
): Promise<CallCenterAgentModel> {
return this.model.create(data);
}
async findOne(
filter: FilterQuery<CallCenterAgentModel>,
): Promise<CallCenterAgentModel | null> {
return this.model.findOne(filter);
}
async findById(id: string): Promise<CallCenterAgentModel | null> {
return this.model.findOne({ _id: new Types.ObjectId(id) });
}
async findByLoginIdentifier(
identifier: string,
): Promise<CallCenterAgentModel | null> {
const id = identifier.trim();
const or: FilterQuery<CallCenterAgentModel>[] = [
{ email: id },
{ username: id },
];
if (/^\d{10}$/.test(id)) {
or.push({ nationalCode: id });
}
return this.model.findOne({ $or: or });
}
async findAll(
filter: FilterQuery<CallCenterAgentModel>,
): Promise<(CallCenterAgentModel & { _id: Types.ObjectId })[]> {
return this.model.find(filter).lean() as Promise<
(CallCenterAgentModel & { _id: Types.ObjectId })[]
>;
}
}

View File

@@ -0,0 +1,61 @@
import { Prop, Schema, SchemaFactory } from "@nestjs/mongoose";
import { Types } from "mongoose";
import { RoleEnum } from "src/Types&Enums/role.enum";
/**
* Call-center agent actor. Works under an insurance company (clientKey) and
* can start V6 LINK blame files on behalf of callers.
*/
@Schema({
collection: "call-center-agents",
versionKey: false,
timestamps: true,
})
export class CallCenterAgentModel {
_id?: Types.ObjectId;
@Prop({ required: true })
firstName: string;
@Prop({ required: true })
lastName: string;
@Prop({ type: String, unique: true, sparse: true, required: false })
email?: string;
@Prop({ type: String })
username?: string;
@Prop({ type: String, index: true, sparse: true })
nationalCode?: string;
@Prop({ type: Types.ObjectId, index: true })
clientKey?: Types.ObjectId;
@Prop({ required: true })
password: string;
@Prop({ required: false })
mobile?: string;
@Prop({ required: false })
phone?: string;
@Prop({ default: RoleEnum.CALL_CENTER })
role: RoleEnum;
@Prop({ type: "string", default: "" })
otp: string;
createdAt: Date;
}
export const CallCenterAgentDbSchema =
SchemaFactory.createForClass(CallCenterAgentModel);
CallCenterAgentDbSchema.pre("save", function (next) {
if (!this.username) {
this.username = (this as any).email || (this as any).nationalCode;
}
next();
});

View File

@@ -11,6 +11,7 @@ import { UserDbService } from "./entities/db-service/user.db.service";
import { ExpertFileActivityDbService } from "./entities/db-service/expert-file-activity.db.service";
import { FileMakerDbService } from "./entities/db-service/file-maker.db.service";
import { FileReviewerDbService } from "./entities/db-service/file-reviewer.db.service";
import { CallCenterAgentDbService } from "./entities/db-service/call-center-agent.db.service";
import {
DamageExpertDbSchema,
DamageExpertModel,
@@ -41,6 +42,10 @@ import {
FileReviewerDbSchema,
FileReviewerModel,
} from "./entities/schema/file-reviewer.schema";
import {
CallCenterAgentDbSchema,
CallCenterAgentModel,
} from "./entities/schema/call-center-agent.schema";
@Module({
imports: [
@@ -54,6 +59,7 @@ import {
{ name: ExpertFileActivity.name, schema: ExpertFileActivitySchema },
{ name: FileMakerModel.name, schema: FileMakerDbSchema },
{ name: FileReviewerModel.name, schema: FileReviewerDbSchema },
{ name: CallCenterAgentModel.name, schema: CallCenterAgentDbSchema },
]),
HashModule,
],
@@ -68,6 +74,7 @@ import {
ExpertFileActivityDbService,
FileMakerDbService,
FileReviewerDbService,
CallCenterAgentDbService,
],
exports: [
UserDbService,
@@ -79,6 +86,7 @@ import {
ExpertFileActivityDbService,
FileMakerDbService,
FileReviewerDbService,
CallCenterAgentDbService,
],
})
export class UsersModule {}

View File

@@ -0,0 +1,8 @@
import { Module } from "@nestjs/common";
import { PlateNormalizerService } from "./plate-normalizer.service";
@Module({
providers: [PlateNormalizerService],
exports: [PlateNormalizerService],
})
export class PlateNormalizerModule {}

View File

@@ -0,0 +1,79 @@
import { Injectable, Logger } from "@nestjs/common";
/**
* Characters stripped from plate text during normalization.
* These invisible Unicode code-points can sneak in via copy-paste
* or OCR and break exact-match lookups against the plate letter map.
*/
const INVISIBLE_CHARS = [
"\u200C", // Zero-Width Non-Joiner
"\u200D", // Zero-Width Joiner
"\u200E", // Left-to-Right Mark
"\u200F", // Right-to-Left Mark
"\uFEFF", // BOM / Zero-Width No-Break Space
];
const INVISIBLE_RE = new RegExp(`[${INVISIBLE_CHARS.join("")}]`, "g");
/**
* Normalize a Persian license-plate character (or short text) so that
* visually-identical Unicode variants collapse to the canonical form
* used in the plate letter mapping.
*
* Steps (in order):
* 1. NFKC normalization — folds compatibility equivalents
* 2. Strip invisible Unicode characters (ZWJ, ZWNJ, LTR/RTL marks, BOM)
* 3. Convert Arabic ي (U+064A) → Persian ی (U+06CC)
* 4. Trim leading/trailing whitespace
*/
export function normalizePlateText(text: string): string {
if (!text) return text;
let result = String(text);
// 1. Unicode NFKC normalization
result = result.normalize("NFKC");
// 2. Remove invisible characters
result = result.replace(INVISIBLE_RE, "");
// 3. Arabic ي → Persian ی
result = result.replace(/\u064A/g, "\u06CC");
// 4. Trim whitespace
result = result.trim();
return result;
}
@Injectable()
export class PlateNormalizerService {
private readonly logger = new Logger(PlateNormalizerService.name);
/** @see module-level {@link normalizePlateText} */
normalizePlateText(text: string): string {
return normalizePlateText(text);
}
/**
* Normalize a plate letter and, if it doesn't resolve in the given
* mapping, log the raw Unicode code-points for debugging.
*
* @returns the numeric code from `mapping`, or `null` when the letter
* is unknown after normalization.
*/
resolvePlateLetterCode(
letter: string,
mapping: Record<string, number>,
): number | null {
const normalized = this.normalizePlateText(letter);
const code = mapping[normalized];
if (code !== undefined) return code;
this.logger.debug(
`Unknown plate letter: ${normalized} [${Array.from(normalized).map((c) => `U+${c.charCodeAt(0).toString(16).toUpperCase().padStart(4, "0")}`).join(", ")}]`,
);
return null;
}
}

View File

@@ -0,0 +1,131 @@
import { PlateNormalizerService, normalizePlateText } from "./plate-normalizer.service";
describe("normalizePlateText (pure function)", () => {
it("returns unchanged text for a clean plate letter", () => {
expect(normalizePlateText("ه")).toBe("ه");
expect(normalizePlateText("الف")).toBe("الف");
});
it("strips Zero-Width Joiner (U+200D)", () => {
// ه + ZWJ — the exact scenario from the issue
const input = "ه\u200D";
expect(normalizePlateText(input)).toBe("ه");
});
it("strips Zero-Width Non-Joiner (U+200C)", () => {
expect(normalizePlateText("ه\u200C")).toBe("ه");
});
it("strips Left-to-Right Mark (U+200E)", () => {
expect(normalizePlateText("ه\u200E")).toBe("ه");
});
it("strips Right-to-Left Mark (U+200F)", () => {
expect(normalizePlateText("ه\u200F")).toBe("ه");
});
it("strips BOM (U+FEFF)", () => {
expect(normalizePlateText("\uFEFFه")).toBe("ه");
});
it("converts Arabic ي (U+064A) to Persian ی (U+06CC)", () => {
expect(normalizePlateText("\u064A")).toBe("\u06CC");
});
it("does not alter already-Persian ی (U+06CC)", () => {
expect(normalizePlateText("\u06CC")).toBe("\u06CC");
});
it("handles a full plate string: 339ه\u200D77 → 339ه77", () => {
expect(normalizePlateText("339ه\u200D77")).toBe("339ه77");
});
it("handles multiple invisible chars interleaved", () => {
const input = "\u200F339\u200Cه\u200D\uFEFF77\u200E";
expect(normalizePlateText(input)).toBe("339ه77");
});
it("trims whitespace", () => {
expect(normalizePlateText(" ه ")).toBe("ه");
});
it("applies NFKC normalization", () => {
// Full-width digit (U+FF13) → ASCII 3
expect(normalizePlateText("")).toBe("3");
});
it("returns empty string for empty input", () => {
expect(normalizePlateText("")).toBe("");
});
});
describe("PlateNormalizerService", () => {
let service: PlateNormalizerService;
beforeEach(() => {
service = new PlateNormalizerService();
});
describe("normalizePlateText", () => {
it("delegates to the pure function", () => {
expect(service.normalizePlateText("ه\u200D")).toBe("ه");
});
});
describe("resolvePlateLetterCode", () => {
const PLATE_LETTER_MAP: Record<string, number> = {
"\u0627\u0644\u0641": 1, // الف
"\u0628": 2,
"\u067E": 3,
"\u062C": 4,
"\u062F": 5,
"\u0633": 6,
"\u0635": 7,
"\u0637": 8,
"\u0639": 9,
"\u0642": 10,
"\u0644": 11,
"\u0645": 12,
"\u0646": 13,
"\u0648": 14,
"\u0647": 15, // ه
"\u06CC": 16, // ی
"\u06A9": 17,
"\u0698": 18,
"\u062A": 19,
"\u062B": 20,
"\u0632": 21,
"\u0634": 22,
"\u0641": 23,
"\u06AF": 24,
};
it("returns 15 for clean ه", () => {
expect(service.resolvePlateLetterCode("ه", PLATE_LETTER_MAP)).toBe(15);
});
it("returns 15 for ه + ZWJ (the bug scenario)", () => {
expect(service.resolvePlateLetterCode("ه\u200D", PLATE_LETTER_MAP)).toBe(
15,
);
});
it("returns 16 for Arabic ي (mapped to Persian ی)", () => {
expect(
service.resolvePlateLetterCode("\u064A", PLATE_LETTER_MAP),
).toBe(16);
});
it("returns null for an unknown letter and logs it", () => {
const spy = jest.spyOn(
(service as any).logger,
"debug",
);
expect(service.resolvePlateLetterCode("؟", PLATE_LETTER_MAP)).toBeNull();
expect(spy).toHaveBeenCalledWith(
expect.stringContaining("Unknown plate letter"),
);
spy.mockRestore();
});
});
});