1
0
forked from Yara724/api

Compare commits

..

62 Commits

Author SHA1 Message Date
SepehrYahyaee
61684156c6 YARA-1133 2026-07-27 14:00:54 +03:30
SepehrYahyaee
588a92c4b4 YARA-1165 2026-07-27 11:46:03 +03:30
SepehrYahyaee
c94dd27a96 YARA-1164 2026-07-27 11:38:54 +03:30
SepehrYahyaee
e4c3b7a16a YARA-1162 2026-07-27 10:15:46 +03:30
SepehrYahyaee
4b9d946bfd YARA-1154 2026-07-27 09:31:07 +03:30
SepehrYahyaee
9828aee8af YARA-1136 2026-07-26 11:35:21 +03:30
778544c321 Merge pull request 'YARA-1147' (#217) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#217
2026-07-25 12:32:22 +03:30
SepehrYahyaee
3afff67336 YARA-1147 2026-07-25 12:31:54 +03:30
793ff639ba Merge pull request 'Added insurer capabilities for super-admin' (#216) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#216
2026-07-25 11:55:42 +03:30
SepehrYahyaee
ec15cff557 Added insurer capabilities for super-admin 2026-07-25 11:55:00 +03:30
fd42adf9d6 Merge pull request 'Added inner parts to APIs for expert claim' (#215) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#215
2026-07-25 11:10:38 +03:30
SepehrYahyaee
4272790fad Added inner parts to APIs for expert claim 2026-07-25 11:10:02 +03:30
ac65cdb77b Merge pull request 'lookups and inquiries in lookups added' (#214) from s.hajizadeh/yara724api:main into main
Reviewed-on: Yara724/api#214
2026-07-25 11:04:42 +03:30
8430c68e3a lookups and inquiries in lookups added 2026-07-25 11:03:58 +03:30
49fe548215 Merge pull request 'Fixed v5 file maker approval field' (#213) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#213
2026-07-25 10:25:10 +03:30
SepehrYahyaee
777eae1028 Fixed v5 file maker approval field 2026-07-25 10:24:34 +03:30
b67dd733cd Merge pull request 'Fixed upload documents counting for v4' (#212) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#212
2026-07-25 09:53:07 +03:30
SepehrYahyaee
4818f73252 Fixed upload documents counting for v4 2026-07-25 09:52:42 +03:30
cc8a5354c7 Merge pull request 'v4 bug fixed' (#211) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#211
2026-07-25 09:29:42 +03:30
SepehrYahyaee
2d5ade33d2 v4 bug fixed 2026-07-25 09:29:12 +03:30
b73c92c21f Merge pull request 'Fixed Bugs: 1) V4 incorrect advancement to file maker approval state, 2) V4 race condition for finishing file maker steps' (#210) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#210
2026-07-23 13:44:05 +03:30
f9f462d47b Fixed Bugs: 1) V4 incorrect advancement to file maker approval state, 2) V4 race condition for finishing file maker steps 2026-07-23 13:43:37 +03:30
c3eb36dc41 Merge pull request 'Fixed v4 sign' (#209) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#209
2026-07-22 17:37:00 +03:30
SepehrYahyaee
f75ecf5c2c Fixed v4 sign 2026-07-22 17:36:29 +03:30
75c4cb6a05 Merge pull request 'Fixed v4/v5 flow' (#208) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#208
2026-07-22 17:22:55 +03:30
SepehrYahyaee
7a4277f8b2 Fixed v4/v5 flow 2026-07-22 17:22:27 +03:30
e50bc78344 Merge pull request 'Fixed sign' (#207) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#207
2026-07-22 15:47:02 +03:30
SepehrYahyaee
2c1cd93dd0 Fixed sign 2026-07-22 15:46:33 +03:30
ffd44df718 Merge pull request 'Fix v2 flow sign of second party' (#206) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#206
2026-07-22 15:35:53 +03:30
SepehrYahyaee
64865b70f2 Fix v2 flow sign of second party 2026-07-22 15:35:14 +03:30
c207c30be9 Merge pull request 'Fixed v2 flow' (#205) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#205
2026-07-22 15:10:00 +03:30
SepehrYahyaee
fcb169e9ac Fixed v2 flow 2026-07-22 15:09:34 +03:30
1867292499 Merge pull request 'Fixed v2 flow' (#204) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#204
2026-07-22 14:53:33 +03:30
SepehrYahyaee
2cc96f6132 Fixed v2 flow 2026-07-22 14:52:51 +03:30
4d5b91d4fe Merge pull request 'update the fanavaran for both tejarat no and parsian clients , dont forget about the env files' (#203) from s.hajizadeh/yara724api:main into main
Reviewed-on: Yara724/api#203
2026-07-20 16:30:15 +03:30
8ba97537a4 update the fanavaran for both tejarat no and parsian clients , dont forget about the env files 2026-07-20 16:28:25 +03:30
70160543a2 Merge pull request 'Fixed v2 mirror' (#202) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#202
2026-07-20 11:45:26 +03:30
SepehrYahyaee
8460c86820 Fixed v2 mirror 2026-07-20 11:44:50 +03:30
61f4181065 Merge pull request 'BUG fix of status' (#201) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#201
2026-07-19 16:51:15 +03:30
SepehrYahyaee
4058cb4a61 BUG fix of status 2026-07-19 16:50:45 +03:30
b2ad43d050 Merge pull request 'YARA-1020' (#200) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#200
2026-07-19 16:35:15 +03:30
SepehrYahyaee
9fc4ad9931 YARA-1020 2026-07-19 16:34:44 +03:30
213cdd765b Merge pull request 'YARA-985' (#199) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#199
2026-07-19 11:47:12 +03:30
SepehrYahyaee
06d69aa4d0 YARA-985 2026-07-19 11:44:15 +03:30
318a5c74dd Merge pull request 'removed guard' (#198) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#198
2026-07-18 16:14:59 +03:30
SepehrYahyaee
7241ae3270 removed guard 2026-07-18 16:14:27 +03:30
1f4a520145 Merge pull request 'Removed the guard of accidentWay' (#197) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#197
2026-07-18 16:03:55 +03:30
SepehrYahyaee
59a1b9064e Removed the guard of accidentWay 2026-07-18 16:03:32 +03:30
0420eda35f Merge pull request 'Edited 2 APIs names' (#196) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#196
2026-07-18 15:28:27 +03:30
SepehrYahyaee
482d2b01f1 Edited API route 2026-07-18 15:27:23 +03:30
SepehrYahyaee
04d7966776 Changed API name of v2 blame mirror 2026-07-18 15:25:59 +03:30
b129c1ef9b Merge pull request 'YARA-1061, Fixed v3 mirror flow' (#195) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#195
2026-07-18 15:02:18 +03:30
SepehrYahyaee
a1fca82cb2 Fixed v3 mirror flow 2026-07-18 15:01:13 +03:30
SepehrYahyaee
5b114c2069 YARA-1061 2026-07-18 14:30:26 +03:30
5e4897f609 Fix empty Rocket.Chat notify (Woodpecker ${} escaping) 2026-07-15 17:06:27 +03:30
a79c3ca05f Fix git pull SSH in pipeline (host keys + known_hosts) 2026-07-15 16:59:46 +03:30
36fa1c552e Allow git in bind-mounted workspace (safe.directory) 2026-07-15 16:43:31 +03:30
9742fecc11 Update .woodpecker.yml 2026-07-15 16:35:40 +03:30
8007c30efd Fix path typo of workspace 2026-07-15 16:26:06 +03:30
144f8f3e2a Update .woodpecker.yml docker repositories 2026-07-15 16:05:01 +03:30
8674dd8762 Merge pull request 'Fixed v4/v5 car capture flow' (#194) from s.yahyaee/yara724-api:main into main
Reviewed-on: Yara724/api#194
2026-07-15 16:00:01 +03:30
SepehrYahyaee
f39c50aeb0 Fixed v4/v5 car capture flow 2026-07-15 15:59:21 +03:30
60 changed files with 3901 additions and 617 deletions

View File

@@ -5,6 +5,10 @@ NODE_ENV =
PORT =
CLIENT_ID =
CLIENT_NAME =
FANAVARAN_CLIENT=parsian
INSURANCE_CORP_ID='شرکت بيمه پارسيان(بيمه گر)'
CLAIM_V2_TOTAL_PAYMENT_CAP_ENABLED=false
CLAIM_V2_TOTAL_PAYMENT_CAP_TOMAN=53000000
# ---------------------------------------------
# 🌐 Application URLs
# ---------------------------------------------
@@ -63,6 +67,23 @@ AUTH_SMS_TEMPLATE =
EXP_OTP_TIME =
FAKE_OTP =
# ---------------------------------------------
# 🌐 Proxy Configuration (Local Development Only)
# ---------------------------------------------
# NOTE: These proxy settings are for local development only.
# When deploying to the server, comment out or remove these lines
# as the server IP is already whitelisted by Fanavaran.
# SOCKS_PROXY_HOST = localhost
# SOCKS_PROXY_PORT = 6565
# ---------------------------------------------
# 🏢 Fanavaran Insurance Corp
# ---------------------------------------------
# Caption from Fanavaran insurance-corp lookup used to resolve InsuranceCorpId
# for damage-case payloads. Must match a Caption in the insurance-corp code-list.
# Example: "شرکت بيمه تجارت نو"
INSURANCE_CORP_ID =
# ---------------------------------------------
# ⚙️ Application Features / Flags
# ---------------------------------------------

View File

@@ -10,8 +10,11 @@ when:
skip_clone: true
variables:
- &host_workspace /data/1-deploy/gitea/yara724/api
- &workspace_volume /data/1-deploy/gitea/yara724/api:/workspace
- &host_ssh /home/talieh/.ssh:/root/.ssh:ro
- &pipeline_env
WORKSPACE: /data/1-delploy/gitea/yara724/api
WORKSPACE: *host_workspace
PROJECT_NAME: Yara724 API
ENVIRONMENT: Development
APPLICATION_URL: https://y724-user.ittalie.ir/api
@@ -23,41 +26,46 @@ variables:
steps:
pull:
image: alpine/git:latest
image: docker.arvancloud.ir/alpine/git:latest
environment:
<<: *pipeline_env
GIT_SSH_COMMAND: ssh -o UserKnownHostsFile=/tmp/known_hosts -o StrictHostKeyChecking=yes
volumes:
- /data/1-delploy/gitea/yara724/api:/workspace
- *workspace_volume
- *host_ssh
commands:
- git config --global --add safe.directory /workspace
- mkdir -p /tmp && ssh-keyscan -H git.ittalie.com >> /tmp/known_hosts
- cd /workspace
- git pull origin main
- date +%s > /workspace/.wp-deploy-start
deploy:
image: docker:24-cli
image: docker.arvancloud.ir/docker:24-cli
environment:
<<: *pipeline_env
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /data/1-delploy/gitea/yara724/api:/workspace
- *workspace_volume
commands:
- cd /workspace
- docker compose -f docker-compose.yml up -d --build
notify-success:
image: alpine:3.20
image: docker.arvancloud.ir/alpine:3.20
environment:
<<: *pipeline_env
ROCKETCHAT_WEBHOOK:
from_secret: rocketchat_webhook
volumes:
- /data/1-delploy/gitea/yara724/api:/workspace
- *workspace_volume
when:
- status: success
commands:
- apk add --no-cache curl jq git > /dev/null
- |
set -euo pipefail
git config --global --add safe.directory /workspace
cd /workspace
COMMIT_HASH="$(git rev-parse --short HEAD)"
@@ -69,20 +77,20 @@ steps:
COMMIT_2="$(git log -2 --pretty=format:'%s' | tail -n1)"
COMMIT_3="$(git log -3 --pretty=format:'%s' | tail -n1)"
TITLE="✅ ${PROJECT_NAME} - ${ENVIRONMENT} ✅"
TEXT="🌐 **URL**: ${APPLICATION_URL}
TITLE="✅ $PROJECT_NAME - $ENVIRONMENT ✅"
TEXT="🌐 **URL**: $APPLICATION_URL
🔖 **Commit Hash**: [${COMMIT_HASH}](${GIT_COMMIT_URL}${COMMIT_HASH})
🔖 **Commit Hash**: [$COMMIT_HASH]($GIT_COMMIT_URL$COMMIT_HASH)
📝 **Recent Changes**:
• ${COMMIT_1}
• $COMMIT_1
• ${COMMIT_2}
• $COMMIT_2
• ${COMMIT_3}
• $COMMIT_3
⏱️ **Deployment Duration**: ${DEPLOY_DURATION}s"
⏱️ **Deployment Duration**: $${DEPLOY_DURATION}s"
payload="$(jq -n \
--arg title "$TITLE" \
@@ -94,31 +102,32 @@ steps:
rm -f /workspace/.wp-deploy-start
notify-failure:
image: alpine:3.20
image: docker.arvancloud.ir/alpine:3.20
environment:
<<: *pipeline_env
ROCKETCHAT_WEBHOOK:
from_secret: rocketchat_webhook
volumes:
- /data/1-delploy/gitea/yara724/api:/workspace
- *workspace_volume
when:
- status: failure
commands:
- apk add --no-cache curl jq git > /dev/null
- |
set -euo pipefail
git config --global --add safe.directory /workspace
cd /workspace
COMMIT_HASH="$(git rev-parse --short HEAD 2>/dev/null || echo unknown)"
TITLE="💥 ${PROJECT_NAME} - ${ENVIRONMENT} 💥"
TITLE="💥 $PROJECT_NAME - $ENVIRONMENT 💥"
TEXT="━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌐 **Application URL**
${APPLICATION_URL}
$APPLICATION_URL
🔖 **Commit**
\`${COMMIT_HASH}\`
\`$COMMIT_HASH\`
⚠️ **Pipeline failed** — check Woodpecker for the failing step.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"

View File

@@ -274,6 +274,20 @@ curl -X GET "$FANAVARAN_BIME_URL/car/code-list/accident-culprit-type" \
-H "ContractId: $CONTRACT_ID" \
-H "Location: $LOCATION" \
-H "Content-Type: application/json"
curl -X GET "$FANAVARAN_BIME_URL/car/base-info/vehicle-kinds" \
-H "authenticationToken: $AUTHENTICATION_TOKEN" \
-H "CorpId: $CORP_ID" \
-H "ContractId: $CONTRACT_ID" \
-H "Location: $LOCATION" \
-H "Content-Type: application/json"
curl -X GET "$FANAVARAN_BIME_URL/car/vehicles/inquiry-by-vin?vin=IRNKAEK4150012345" \
-H "authenticationToken: $AUTHENTICATION_TOKEN" \
-H "CorpId: $CORP_ID" \
-H "ContractId: $CONTRACT_ID" \
-H "Location: $LOCATION" \
-H "Content-Type: application/json"
```
### 3B. Policy Inquiry By National Code

View File

@@ -45,6 +45,7 @@
"pdfkit": "^0.19.1",
"reflect-metadata": "^0.2.2",
"rxjs": "^7.8.1",
"socks-proxy-agent": "^8.0.4",
"svg-captcha": "^1.4.0"
},
"devDependencies": {

View File

@@ -9,4 +9,5 @@ export enum RoleEnum {
FILE_MAKER = "file_maker",
FILE_REVIEWER = "file_reviewer",
SUPER_ADMIN = "super_admin",
CALL_CENTER = "call_center",
}

View File

@@ -1,9 +1,8 @@
import { HttpModule } from "@nestjs/axios";
import { Module } from "@nestjs/common";
import { AiService } from "./ai.service";
@Module({
imports: [HttpModule],
imports: [],
providers: [AiService],
exports: [AiService],
})

View File

@@ -1,7 +1,8 @@
import { join } from "node:path";
import { APP_INTERCEPTOR, APP_PIPE } from "@nestjs/core";
import { Module } from "@nestjs/common";
import { ConfigService } from "@nestjs/config";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { HttpModule } from "@nestjs/axios";
import { UnicodeDigitsNormalizeInterceptor } from "./common/interceptors/unicode-digits-normalize.interceptor";
import { MongooseModule } from "@nestjs/mongoose";
import { ServeStaticModule } from "@nestjs/serve-static";
@@ -28,9 +29,15 @@ import { WorkflowStepManagementModule } from "./workflow-step-management/workflo
import { DatabaseModule } from "./core/database/database.module";
import { AppConfigModule } from "./core/config/config.module";
import { SuperAdminModule } from "./super-admin/super-admin.module";
import { createHttpModuleOptions } from "./core/config/http-proxy.factory";
@Module({
imports: [
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
AppConfigModule,
DatabaseModule,
CronModule,

View File

@@ -29,6 +29,7 @@ import { FieldExpertDbService } from "src/users/entities/db-service/field-expert
import { RegistrarDbService } from "src/users/entities/db-service/registrar.db.service";
import { FileMakerDbService } from "src/users/entities/db-service/file-maker.db.service";
import { FileReviewerDbService } from "src/users/entities/db-service/file-reviewer.db.service";
import { CallCenterAgentDbService } from "src/users/entities/db-service/call-center-agent.db.service";
import { HashService } from "src/utils/hash/hash.service";
import { OtpGeneratorService } from "src/sms-orchestration/otp-generator.service";
import { SuperAdminDbService } from "src/super-admin/entities/db-service/super-admin.db.service";
@@ -58,6 +59,7 @@ export class ActorAuthService {
private readonly fileMakerDbService: FileMakerDbService,
private readonly fileReviewerDbService: FileReviewerDbService,
private readonly superAdminDbService: SuperAdminDbService,
private readonly callCenterAgentDbService: CallCenterAgentDbService,
) {}
// TODO convrt to class for dynamic controller
@@ -123,6 +125,14 @@ export class ActorAuthService {
});
else res = await this.superAdminDbService.findByLoginIdentifier(username);
break;
case RoleEnum.CALL_CENTER:
if (username == null && userId)
res = await this.callCenterAgentDbService.findOne({
_id: new Types.ObjectId(userId),
});
else
res = await this.callCenterAgentDbService.findByLoginIdentifier(username);
break;
default:
return null;
}

View File

@@ -1,5 +1,8 @@
import { Module } from "@nestjs/common";
import { MongooseModule } from "@nestjs/mongoose";
import { HttpModule } from "@nestjs/axios";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
import { AiModule } from "src/ai/ai.module";
import { SandHubModule } from "src/sand-hub/sand-hub.module";
import { RequestManagementModule } from "src/request-management/request-management.module";
@@ -52,13 +55,16 @@ import { ClientModule } from "src/client/client.module";
import { ClaimAccessGuard } from "src/auth/guards/claim-access.guard";
import { JwtModule } from "@nestjs/jwt";
import { MediaPolicyModule } from "src/media-policy/media-policy.module";
import { HttpModule } from "@nestjs/axios";
import { FanavaranAuditModule } from "src/fanavaran/fanavaran-audit.module";
import { FanavaranLookupModule } from "src/fanavaran/fanavaran-lookup.module";
@Module({
imports: [
HttpModule,
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
FanavaranAuditModule,
FanavaranLookupModule,
PublicIdModule,

View File

@@ -13,6 +13,7 @@ import {
Get,
UseInterceptors,
UploadedFile,
UploadedFiles,
} from "@nestjs/common";
import { readFile } from "node:fs/promises";
import {
@@ -24,7 +25,7 @@ import {
ApiBody,
ApiConsumes,
} from "@nestjs/swagger";
import { FileInterceptor } from "@nestjs/platform-express";
import { FileInterceptor, FilesInterceptor } from "@nestjs/platform-express";
import { diskStorage } from "multer";
import { extname } from "node:path";
import { Types } from "mongoose";
@@ -188,8 +189,10 @@ export class ClaimRequestManagementV2Controller {
/**
* V2: User objection after expert resend (same intent as v1 PUT …/request/resend/:id/objection).
* Accepts multipart/form-data so optional supporting invoices can be attached in the same request.
*/
@Put("request/:claimRequestId/objection")
@ApiConsumes("multipart/form-data")
@ApiOperation({
summary: "Submit user objection (V2)",
description:
@@ -197,14 +200,38 @@ export class ClaimRequestManagementV2Controller {
"(2) **Legacy resend:** active expert resend (`WAITING_FOR_USER_RESEND` @ `USER_EXPERT_RESEND`).\n\n" +
"`objectionParts` may only reference **priced** repair lines (`factorNeeded=false`). Factor-only lines cannot be disputed until they have expert pricing.\n\n" +
"After **`damageExpertReplyFinal`** exists (final reply following a prior objection), **no second objection** — owner uses **owner-insurer-approval/sign** to accept/reject and close the case.\n\n" +
"Stores `evaluation.objection`, clears partial/final owner approval fields, merges `newParts` into `damage.selectedParts`, returns case to `WAITING_FOR_DAMAGE_EXPERT`.",
"Stores `evaluation.objection`, clears partial/final owner approval fields, merges `newParts` into `damage.selectedParts`, returns case to `WAITING_FOR_DAMAGE_EXPERT`.\n\n" +
"**Invoices:** optionally attach up to 5 supporting documents (images/PDFs) as `invoices` file fields. Stored in `evaluation.objection.invoices[]` and visible to the reviewing expert.",
})
@ApiParam({
name: "claimRequestId",
description: "The claim case ID (MongoDB ObjectId)",
example: "507f1f77bcf86cd799439011",
})
@ApiBody({ type: UserObjectionV2Dto })
@ApiBody({
description:
"Objection payload as multipart form fields. `objectionParts` and `newParts` are JSON-encoded strings.",
schema: {
type: "object",
properties: {
objectionParts: {
type: "string",
description:
'JSON-encoded array of disputed priced parts. Example: `[{"partId":201,"reason":"Price too high"}]`',
},
newParts: {
type: "string",
description:
'JSON-encoded array of new parts to add. Example: `[{"partName":"سپر جلو","side":"front"}]`',
},
invoices: {
type: "array",
items: { type: "string", format: "binary" },
description: "Up to 5 supporting invoice or document files (image or PDF).",
},
},
},
})
@ApiResponse({ status: 200, description: "Objection stored" })
@ApiResponse({
status: 400,
@@ -213,17 +240,35 @@ export class ClaimRequestManagementV2Controller {
@ApiResponse({ status: 403, description: "Not the claim owner" })
@ApiResponse({ status: 404, description: "Claim not found" })
@ApiResponse({ status: 409, description: "Objection already submitted" })
@UseInterceptors(
FilesInterceptor("invoices", 5, {
limits: { fileSize: DEFAULT_MEDIA_MAX_BYTES },
storage: diskStorage({
destination: "./files/claim-objection-invoices",
filename: (req, file, callback) => {
const unique = Date.now() + "-" + Math.round(Math.random() * 1e6);
const ex = extname(file.originalname);
callback(null, `objection-invoice-${unique}${ex}`);
},
}),
}),
)
async submitUserObjectionV2(
@Param("claimRequestId") claimRequestId: string,
@Body() body: UserObjectionV2Dto,
@CurrentUser() user: any,
@UploadedFiles() invoices?: Express.Multer.File[],
) {
for (const file of invoices ?? []) {
await this.mediaPolicyService.assertForClaim(file, claimRequestId, "image");
}
try {
return await this.claimRequestManagementService.handleUserObjectionV2(
claimRequestId,
body,
user.sub,
user,
invoices,
);
} catch (error) {
if (error instanceof HttpException) throw error;

View File

@@ -106,14 +106,16 @@ export class SelectOtherPartsV2ResponseDto {
@ApiProperty({
description: 'Sheba number (masked for security)',
example: 'IR12************1234',
required: false,
})
shebaNumber: string;
shebaNumber?: string;
@ApiProperty({
description: 'National code of owner (masked)',
example: '12******90',
required: false,
})
nationalCodeOfOwner: string;
nationalCodeOfOwner?: string;
@ApiProperty({
description: 'Current workflow step',

View File

@@ -1,5 +1,5 @@
import { ApiPropertyOptional } from "@nestjs/swagger";
import { Type } from "class-transformer";
import { Type, Transform } from "class-transformer";
import {
IsArray,
IsOptional,
@@ -10,23 +10,52 @@ import { HasObjectionEntriesConstraint } from "src/common/validators/has-objecti
import { NewPartDto, UserObjectionPartDto } from "./user-objection.dto";
/**
* V2 user objection body — same shape as v1 {@link UserObjectionDto}
* with nested validation enabled for the v2 controller pipeline.
* V2 user objection body — submitted as multipart/form-data.
* `objectionParts` and `newParts` are JSON-encoded strings in the form fields.
* Optional `invoices` files are uploaded as a `invoices` file array.
*/
export class UserObjectionV2Dto {
@ApiPropertyOptional({ type: [UserObjectionPartDto] })
@ApiPropertyOptional({
type: [UserObjectionPartDto],
description:
"JSON-encoded array of disputed priced parts. Pass as a JSON string in the multipart field.",
})
@Validate(HasObjectionEntriesConstraint)
@IsOptional()
@IsArray()
@ValidateNested({ each: true })
@Type(() => UserObjectionPartDto)
@Transform(({ value }) => {
if (typeof value === "string") {
try {
return JSON.parse(value);
} catch {
return value;
}
}
return value;
})
objectionParts?: UserObjectionPartDto[];
@ApiPropertyOptional({ type: [NewPartDto] })
@ApiPropertyOptional({
type: [NewPartDto],
description:
"JSON-encoded array of new parts to add. Pass as a JSON string in the multipart field.",
})
@Validate(HasObjectionEntriesConstraint)
@IsOptional()
@IsArray()
@ValidateNested({ each: true })
@Type(() => NewPartDto)
@Transform(({ value }) => {
if (typeof value === "string") {
try {
return JSON.parse(value);
} catch {
return value;
}
}
return value;
})
newParts?: NewPartDto[];
}

View File

@@ -180,6 +180,27 @@ export class ClaimUserObjectionNewPart {
export const ClaimUserObjectionNewPartSchema =
SchemaFactory.createForClass(ClaimUserObjectionNewPart);
// ---------------------------------------------------------------------------
// Objection invoice (supporting document uploaded alongside the objection)
// ---------------------------------------------------------------------------
@Schema({ _id: false })
export class ClaimObjectionInvoice {
@Prop({ type: Types.ObjectId, default: () => new Types.ObjectId() })
fileId: Types.ObjectId;
@Prop({ type: String, required: true })
path: string;
@Prop({ type: String, required: true })
fileName: string;
@Prop({ type: Date, default: () => new Date() })
uploadedAt: Date;
}
export const ClaimObjectionInvoiceSchema =
SchemaFactory.createForClass(ClaimObjectionInvoice);
/**
* Full user objection payload (matches v1 DTO: objectionParts + newParts).
* Stored on {@link ClaimEvaluation.objection}.
@@ -194,6 +215,10 @@ export class ClaimUserObjectionPayload {
@Prop({ type: Date, default: () => new Date() })
submittedAt?: Date;
/** Optional supporting invoices uploaded at objection time. */
@Prop({ type: [ClaimObjectionInvoiceSchema], default: [] })
invoices?: ClaimObjectionInvoice[];
}
export const ClaimUserObjectionPayloadSchema =
SchemaFactory.createForClass(ClaimUserObjectionPayload);

View File

@@ -86,6 +86,15 @@ export class FanavaranSyncStage {
@Prop({ type: MongooseSchema.Types.Mixed })
response?: unknown;
@Prop({ type: Number, default: 0 })
retryCount?: number;
@Prop({ type: Number, default: 2 })
maxRetries?: number;
@Prop({ type: Date })
nextRetryAt?: Date;
}
export const FanavaranSyncStageSchema =
SchemaFactory.createForClass(FanavaranSyncStage);

View File

@@ -4,9 +4,12 @@ import {
Body,
Controller,
Get,
HttpException,
InternalServerErrorException,
Param,
Patch,
Post,
Put,
Query,
UploadedFile,
UseGuards,
@@ -516,6 +519,73 @@ Returns status of each item (uploaded/captured or not).
);
}
// ─── Owner signature on expert pricing ───────────────────────────────────────
@Put("claim-sign/:claimRequestId")
@ApiParam({ name: "claimRequestId" })
@ApiConsumes("multipart/form-data")
@ApiBody({
description: "Signature file, agreement, and branch",
schema: {
type: "object",
required: ["sign", "agree", "branchId"],
properties: {
sign: { type: "string", format: "binary", description: "Signature image" },
agree: { type: "boolean", description: "true to accept, false to reject" },
branchId: { type: "string", description: "Insurer branch ID" },
},
},
})
@ApiOperation({
summary: "Owner signature on expert pricing (Flow 3 — expert acts on behalf of user)",
description:
"Field expert submits the damaged party's signature during the final approval stage. " +
"Delegates to the same service method as the user sign endpoint; the expert's " +
"identity is resolved to the claim owner via `resolveClaimEffectiveUserId`.",
})
@UseInterceptors(
FileInterceptor("sign", {
limits: { fileSize: DEFAULT_MEDIA_MAX_BYTES },
storage: diskStorage({
destination: "./files/claim-sign",
filename: (req, file, callback) => {
const unique = Date.now();
const ex = extname(file.originalname);
const base = file.originalname.split(/[.,\s-]/)[0] || "sign";
callback(null, `${base}-${unique}${ex}`);
},
}),
}),
)
async submitOwnerSign(
@Param("claimRequestId") claimRequestId: string,
@Body("agree") agree: string | boolean,
@Body("branchId") branchId: string,
@CurrentUser() expert: any,
@UploadedFile() sign: Express.Multer.File,
) {
await this.mediaPolicyService.assertForClaim(sign, claimRequestId, "image");
const agreed =
typeof agree === "string"
? agree === "true" || agree === "1"
: Boolean(agree);
try {
return await this.claimRequestManagementService.submitOwnerInsurerApprovalSignV2(
claimRequestId,
agreed,
typeof branchId === "string" ? branchId : "",
sign,
expert.sub,
expert,
);
} catch (error) {
if (error instanceof HttpException) throw error;
throw new InternalServerErrorException(
error instanceof Error ? error.message : "Failed to submit signature",
);
}
}
@Patch("car-capture/:claimRequestId")
@ApiConsumes("multipart/form-data")
@UseInterceptors(

View File

@@ -20,7 +20,9 @@ export class AuthGuard implements CanActivate {
}
try {
const payload: JwtPayload =
await this.jwtService.verifyAsync<JwtPayload>(token);
await this.jwtService.verifyAsync<JwtPayload>(token, {
secret: `${process.env.JWT_SECRET}`,
});
request["user"] = payload;
} catch {
throw new UnauthorizedException("Invalid or expired token");

View File

@@ -37,6 +37,7 @@ export interface FanavaranPayloadDefaults {
AccidentReportTypeId: number;
AccidentVehicleUsedId: number;
ClaimExpertId: number;
ExpertiseClaimExpertId: number;
CompensationReferenceId: number;
CulpritLicenceTypeId: number;
CulpritTypeId: number;
@@ -74,7 +75,8 @@ const FANAVARAN_CLIENT_PROFILES: Record<
AccidentCityId: 701,
AccidentReportTypeId: 155,
AccidentVehicleUsedId: 1,
ClaimExpertId: 1589,
ClaimExpertId: 4543092,
ExpertiseClaimExpertId: 4543092,
CompensationReferenceId: 167,
CulpritLicenceTypeId: 2,
CulpritTypeId: 337,
@@ -84,7 +86,7 @@ const FANAVARAN_CLIENT_PROFILES: Record<
PlaqueSampleId: 10,
DriverIsOwner: 0,
FaultPercent: 100,
ClaimFileTypeId: 70,
ClaimFileTypeId: 23,
},
},
parsian: {
@@ -103,6 +105,7 @@ const FANAVARAN_CLIENT_PROFILES: Record<
AccidentReportTypeId: 155,
AccidentVehicleUsedId: 1,
ClaimExpertId: 154,
ExpertiseClaimExpertId: 29,
CompensationReferenceId: 167,
CulpritLicenceTypeId: 2,
CulpritTypeId: 337,

View File

@@ -0,0 +1,26 @@
import { ConfigService } from "@nestjs/config";
import { HttpModuleOptions } from "@nestjs/axios";
import { SocksProxyAgent } from "socks-proxy-agent";
/**
* Shared HttpModule.registerAsync factory that applies the SOCKS proxy
* when SOCKS_PROXY_HOST + SOCKS_PROXY_PORT env vars are set.
* Used by every module that imports HttpModule.
*/
export function createHttpModuleOptions(
configService: ConfigService,
): HttpModuleOptions | Promise<HttpModuleOptions> {
const socksHost = configService.get<string>("SOCKS_PROXY_HOST");
const socksPort = configService.get<string>("SOCKS_PROXY_PORT");
if (socksHost && socksPort) {
const proxyUrl = `socks5://${socksHost}:${socksPort}`;
const agent = new SocksProxyAgent(proxyUrl);
return {
httpsAgent: agent,
httpAgent: agent,
proxy: false,
};
}
return {};
}

View File

@@ -1871,6 +1871,7 @@ export class ExpertBlameService {
link: this.smsOrchestrationService.buildBlamePartyLink(
requestIdToken,
role,
"v1",
),
});
}
@@ -2065,6 +2066,7 @@ export class ExpertBlameService {
link: this.smsOrchestrationService.buildBlamePartyLink(
requestIdToken,
linkRole,
"v1",
),
});
}

View File

@@ -1,5 +1,7 @@
import { HttpModule } from "@nestjs/axios";
import { Module } from "@nestjs/common";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
import { MongooseModule } from "@nestjs/mongoose";
import { AiModule } from "src/ai/ai.module";
import { AuthModule } from "src/auth/auth.module";
@@ -21,7 +23,11 @@ import { ExpertClaimService } from "./expert-claim.service";
@Module({
imports: [
HttpModule,
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
SandHubModule,
MongooseModule.forFeature([
{ name: ClaimFactorsImage.name, schema: ClaimFactorsImageSchema },

View File

@@ -372,6 +372,21 @@ export class ExpertClaimService {
await enrichApproval("ownerInsurerApproval");
await enrichApproval("ownerPricedPartsApproval");
// Resolve objection invoice paths to downloadable URLs.
const objection = ev.objection as Record<string, unknown> | undefined;
if (objection) {
const invoices = objection.invoices as Array<Record<string, unknown>> | undefined;
if (Array.isArray(invoices) && invoices.length > 0) {
ev.objection = {
...objection,
invoices: invoices.map((inv) => ({
...inv,
url: inv.path ? buildFileLink(inv.path as string) : undefined,
})),
};
}
}
return ev;
}
@@ -3149,7 +3164,7 @@ export class ExpertClaimService {
receptor: ownerPhoneResend,
fileKind: "claim",
publicId: claim.publicId,
link: this.smsOrchestrationService.buildClaimLink(String(claim._id)),
link: this.smsOrchestrationService.buildClaimLink(String(claim._id), "v1"),
});
}
@@ -3447,21 +3462,11 @@ export class ExpertClaimService {
fileKind: "claim",
publicId: claim.publicId,
expertLastName,
link: this.smsOrchestrationService.buildClaimLink(String(claim._id)),
link: this.smsOrchestrationService.buildClaimLink(String(claim._id), "v1"),
});
}
const fanavaranExpertise = !needsFactorUpload
? await this.claimRequestManagementService.autoSubmitFanavaranExpertiseOnExpertReply(
claimRequestId,
)
: {
attempted: false,
submitted: false,
skipped: true,
skipReason:
"Expertise submit waits until factor-needed repair lines are validated.",
};
// Fanavaran expertise is now triggered on owner final sign, not here.
return {
claimRequestId,
@@ -3475,7 +3480,6 @@ export class ExpertClaimService {
mixedPricingAndFactors: mixedFactorAndPrice,
allPartsFactorNeeded: !!needsFactorUpload && !!allFactorLines,
isFinalReplyAfterObjection,
fanavaranExpertise,
};
}
@@ -3712,14 +3716,19 @@ export class ExpertClaimService {
let claims: any[] = [];
if (actor.role === RoleEnum.FIELD_EXPERT) {
const expertOid = new Types.ObjectId(actor.sub);
// Exclude V4/V5 blame files — same rule as getFieldExpertClaimListV2.
const expertBlameIds = await this.blameRequestDbService
.find(
{ expertInitiated: true, initiatedByFieldExpertId: expertOid },
{
expertInitiated: true,
initiatedByFieldExpertId: expertOid,
isMadeByFileMaker: { $ne: true },
},
{ select: "_id", lean: true },
)
.then((docs) => docs.map((d) => (d as { _id: unknown })._id));
const claimOr: Record<string, unknown>[] = [
{ initiatedByFieldExpertId: expertOid },
{ initiatedByFieldExpertId: expertOid, requiresFileMakerApproval: { $ne: true } },
];
if (expertBlameIds.length > 0) {
claimOr.push({ blameRequestId: { $in: expertBlameIds } });
@@ -4048,15 +4057,22 @@ export class ExpertClaimService {
query: ListQueryV2Dto = {},
): Promise<GetClaimListV2ResponseDto> {
const expertOid = new Types.ObjectId(actor.sub);
// Exclude V4/V5 blame files (isMadeByFileMaker=true) — those belong to
// the FILE_MAKER/FILE_REVIEWER flows, not the V3 field-expert flow.
const expertBlameIds = await this.blameRequestDbService
.find(
{ expertInitiated: true, initiatedByFieldExpertId: expertOid },
{
expertInitiated: true,
initiatedByFieldExpertId: expertOid,
isMadeByFileMaker: { $ne: true },
},
{ select: "_id", lean: true },
)
.then((docs) => docs.map((d) => (d as { _id: unknown })._id));
const claimOr: Record<string, unknown>[] = [
{ initiatedByFieldExpertId: expertOid },
// Direct claim link: exclude V5 claims that require FileMaker approval
{ initiatedByFieldExpertId: expertOid, requiresFileMakerApproval: { $ne: true } },
];
if (expertBlameIds.length > 0) {
claimOr.push({ blameRequestId: { $in: expertBlameIds } });
@@ -4734,8 +4750,19 @@ export class ExpertClaimService {
"This file has been taken by another reviewer.",
);
}
} else if (!claimCaseInitiatedByFieldExpert(claim, actor, linkedBlame)) {
throw new ForbiddenException("This claim is not accessible to you.");
} else {
// FIELD_EXPERT: V3 flow only. Reject V4/V5 files (isMadeByFileMaker)
// even if their ID matches initiatedByFieldExpertId on the blame —
// those are FILE_MAKER files, accessible via the FILE_MAKER role only.
const isV4V5Blame = !!(linkedBlame as any)?.isMadeByFileMaker;
if (isV4V5Blame) {
throw new ForbiddenException(
"Field experts can only access V3 expert-initiated files.",
);
}
if (!claimCaseInitiatedByFieldExpert(claim, actor, linkedBlame)) {
throw new ForbiddenException("This claim is not accessible to you.");
}
}
// Fall through to the detail build below (skip the damage-expert gate)
} else if (actor.role !== RoleEnum.FILE_MAKER) {
@@ -4998,6 +5025,10 @@ export class ExpertClaimService {
if (enrichedEvaluation.priceDrop !== undefined) {
evaluationForApi.priceDrop = enrichedEvaluation.priceDrop;
}
// objection: include when present so experts can see the disputed parts and any attached invoices.
if (enrichedEvaluation.objection !== undefined) {
evaluationForApi.objection = enrichedEvaluation.objection;
}
if (Object.keys(evaluationForApi).length === 0) {
evaluationForApi = undefined;
}

View File

@@ -1,3 +1,4 @@
import { readFile } from "node:fs/promises";
import {
Body,
Controller,
@@ -117,6 +118,21 @@ export class ExpertClaimV2Controller {
return this.claimRequestManagementService.getOuterPartsCatalogV2(carType);
}
@Get("inner-parts-catalog")
@ApiOperation({
summary: "Get inner parts catalog",
description: "Returns the full list of inner car parts from the static catalog.",
})
@ApiResponse({ status: 200, description: "Inner parts catalog (object keyed by part name)" })
async getInnerPartsCatalog() {
const raw = await readFile(`${process.cwd()}/src/static/car-part.json`, "utf-8");
try {
return JSON.parse(raw);
} catch {
return raw;
}
}
@Get("branches")
@ApiOperation({
summary: "List insurer branches for this damage expert (V2)",

View File

@@ -240,6 +240,23 @@ export class ExpertInsurerController {
);
}
@Get("files/:publicId/timeline")
@ApiParam({ name: "publicId" })
@ApiOperation({
summary: "Activity timeline for a case",
description:
"Returns a chronological list of all history events for the blame and/or claim associated with the given publicId. Each event has: source, type, timestamp, actor, metadata.",
})
async getFileTimeline(
@CurrentUser() insurer,
@Param("publicId") publicId: string,
) {
return await this.expertInsurerService.getFileTimeline(
insurer.clientKey,
publicId,
);
}
@Get("files/:publicId")
@ApiParam({ name: "publicId" })
async getFileDetailsByPublicId(

View File

@@ -75,6 +75,7 @@ import {
extractExpertNamesFromBlame,
extractExpertNamesFromClaim,
} from "./helper/insurer.helper";
import { getEventFaLabel } from "./helper/timeline-fa-labels";
import { buildEnrichedDamagedParts } from "src/expert-claim/dto/claim-damaged-part.enricher";
@Injectable()
@@ -2088,4 +2089,77 @@ export class ExpertInsurerService {
waiting_for_documents_resend: counts.WAITING_FOR_DOCUMENT_RESEND ?? 0,
};
}
async getFileTimeline(
insurerId: string,
publicId: string,
): Promise<{ publicId: string; events: object[] }> {
if (!publicId?.trim()) {
throw new BadRequestException("publicId is required");
}
const id = this.getClientId(insurerId);
const [blameFiles, claimFiles] = await Promise.all([
this.getClientBlameFiles(id),
this.getClientClaimFiles(id),
]);
const blame = blameFiles.find(
(b) => String((b as any).publicId) === publicId,
);
const claim = claimFiles.find(
(c) => String((c as any).publicId) === publicId,
);
if (!blame && !claim) {
throw new NotFoundException("File not found for this publicId");
}
const events: object[] = [];
if (blame) {
const blameDoc = await this.blameRequestDbService.findById(
String((blame as any)._id),
);
const blameHistory: any[] = (blameDoc as any)?.history ?? [];
for (const ev of blameHistory) {
events.push({
source: "blame",
type: ev.type,
faLabel: getEventFaLabel(ev),
timestamp: ev.timestamp,
actor: ev.actor ?? null,
metadata: ev.metadata ?? null,
});
}
}
if (claim) {
const claimId = String((claim as any)._id);
const rows = (await this.claimCaseDbService.find(
{ _id: new Types.ObjectId(claimId) },
{ lean: true, select: "history createdAt" },
)) as Record<string, unknown>[];
const claimHistory: any[] = (rows[0] as any)?.history ?? [];
for (const ev of claimHistory) {
events.push({
source: "claim",
type: ev.type,
faLabel: getEventFaLabel(ev),
timestamp: ev.timestamp,
actor: ev.actor ?? null,
metadata: ev.metadata ?? null,
});
}
}
events.sort((a: any, b: any) => {
const ta = a.timestamp ? new Date(a.timestamp).getTime() : 0;
const tb = b.timestamp ? new Date(b.timestamp).getTime() : 0;
return ta - tb;
});
// Resolve insurer's client name for context if needed — just return raw events
return { publicId, events };
}
}

View File

@@ -0,0 +1,196 @@
/**
* Persian (Farsi) display labels for every timeline event `type` that can
* appear in a blame or claim history array.
*
* For generic `STEP_COMPLETED` / `V3_STEP_COMPLETED` events the label is
* derived from the `metadata.stepKey` value; those keys are listed at the
* bottom under STEP_KEY_FA_LABELS.
*
* Usage:
* const label = EVENT_TYPE_FA_LABELS[event.type]
* ?? resolveStepCompletedFaLabel(event)
* ?? event.type;
*/
// ---------------------------------------------------------------------------
// Blame-phase events (recorded on BlameRequest.history)
// ---------------------------------------------------------------------------
export const EVENT_TYPE_FA_LABELS: Record<string, string> = {
// File creation
FILE_CREATED_BY_REGISTRAR: "پرونده توسط ثبت‌کننده ایجاد شد",
FILE_CREATED_BY_FIELD_EXPERT: "پرونده توسط کارشناس میدانی ایجاد شد",
// Expert link / OTP flow
LINK_SENT: "لینک ارسال شد",
PARTY_OTP_SENT: "کد تأیید ارسال شد",
PARTY_OTP_VERIFIED: "کد تأیید تأیید شد",
PARTY_OTPS_VERIFIED: "کدهای تأیید هر دو طرف تأیید شدند",
SECOND_PARTY_OTP_SENT: "کد تأیید طرف دوم ارسال شد",
SECOND_PARTY_OTP_VERIFIED_ADVANCED: "کد طرف دوم تأیید و پیشرفت انجام شد",
// Confession / accident type
FIRST_BLAME_CONFESSION_SUBMITTED: "اقرار اولیه طرف اول ثبت شد",
CAR_BODY_ACCIDENT_TYPE_SUBMITTED: "نوع تصادف بدنه خودرو ثبت شد",
AUTO_ADVANCED_TO_CAR_BODY_FORM: "پیشرفت خودکار به فرم بدنه خودرو",
AUTO_CONFESSION_SKIPPED: "مرحله اقرار به‌صورت خودکار رد شد",
// First video
FIRST_VIDEO_UPLOADED: "ویدیوی اول بارگذاری شد",
// Second party invitation
SECOND_PARTY_INVITED: "طرف دوم دعوت شد",
// Accident fields / expert in-person completion
ACCIDENT_FIELDS_SAVED_ADVANCED_TO_SIGNATURES:
"اطلاعات تصادف ذخیره و به مرحله امضاها پیشرفت شد",
EXPERT_COMPLETED_CAR_BODY_FORM_V2: "کارشناس فرم بدنه خودرو را تکمیل کرد",
EXPERT_COMPLETED_THIRD_PARTY_FORM_V2: "کارشناس فرم شخص ثالث را تکمیل کرد",
EXPERT_ADDED_LOCATIONS_V2: "کارشناس موقعیت مکانی را ثبت کرد",
EXPERT_UPLOADED_VIDEO_V2: "کارشناس ویدیو را بارگذاری کرد",
EXPERT_UPLOADED_VOICE_V2: "کارشناس صدا را بارگذاری کرد",
// Party rejection / disagreement
PARTY_REJECTED_EXPERT_DECISION: "طرف حساب با نظر کارشناس مخالفت کرد",
PARTIES_DISAGREED_ON_EXPERT_DECISION: "طرفین با نظر کارشناس توافق نکردند",
// Document resend (blame)
BLAME_DOCUMENT_RESEND_STARTED: "درخواست ارسال مجدد مدارک پرونده شروع شد",
BLAME_DOCUMENT_RESEND_CLEARED: "ارسال مجدد مدارک پرونده پاک‌سازی شد",
// Expert assignment (blame)
BLAME_ASSIGNED: "پرونده به کارشناس تخصیص داده شد",
AUTO_ASSIGNED_TO_EXPERT: "پرونده به‌صورت خودکار به کارشناس تخصیص یافت",
// Auto-assignment helpers
READY_FOR_EXPERT_EVALUATION: "پرونده آماده ارزیابی کارشناس شد",
SECOND_PARTY_DESCRIPTION_COMPLETED: "توضیحات طرف دوم تکمیل شد",
// V3 blame steps
V3_PARTY_SIGNATURE_RECORDED: "امضای طرف ثبت شد",
V3_ACCIDENT_FIELDS_SAVED: "اطلاعات تصادف ثبت شد",
V3_BLAME_ACCIDENT_VIDEO_UPLOADED: "ویدیوی تصادف بارگذاری شد",
V3_PARTY_VOICE_UPLOADED: "صدای طرف بارگذاری شد",
V3_PARTY_LOCATION_SAVED: "موقعیت مکانی طرف ذخیره شد",
V3_PARTY_DESCRIPTION_SAVED: "توضیحات طرف ذخیره شد",
V3_CAR_BODY_ACCIDENT_TYPE_SAVED: "نوع تصادف بدنه خودرو ذخیره شد",
// V5 blame steps
V5_BLAME_ACCIDENT_VIDEO_UPLOADED: "ویدیوی تصادف (نسخه ۵) بارگذاری شد",
V5_FILE_MAKER_APPROVED: "پرونده‌ساز پرونده را تأیید کرد",
V5_FILE_MAKER_REJECTED: "پرونده‌ساز پرونده را رد کرد",
// ---------------------------------------------------------------------------
// Claim-phase events (recorded on ClaimCase.history)
// ---------------------------------------------------------------------------
// Claim creation
CLAIM_CREATED: "پرونده خسارت ایجاد شد",
// Expert assignment (claim)
CLAIM_ASSIGNED: "پرونده خسارت به کارشناس ارزیابی تخصیص داده شد",
// Expert actions on claim
EXPERT_RESEND_REQUESTED: "کارشناس درخواست ارسال مجدد مدارک داد",
EXPERT_RESEND_FULFILLED: "مدارک درخواستی ارسال شد",
IN_PERSON_VISIT_REQUESTED: "کارشناس بازدید حضوری درخواست کرد",
EXPERT_DAMAGED_PARTS_UPDATED: "کارشناس قطعات آسیب‌دیده را به‌روزرسانی کرد",
// Workflow steps (generic)
STEP_COMPLETED: "مرحله تکمیل شد",
V3_STEP_COMPLETED: "مرحله تکمیل شد",
// Documents & media
DOCUMENT_UPLOADED: "مدرک بارگذاری شد",
VIDEO_CAPTURE_UPLOADED: "تصویر ویدیویی بارگذاری شد",
ALL_FACTORS_UPLOADED_PENDING_VALIDATION:
"تمام فاکتورها بارگذاری شدند و در انتظار تأیید هستند",
// User responses
USER_OBJECTION_SUBMITTED: "اعتراض کاربر ثبت شد",
USER_RATING_SUBMITTED: "امتیاز کاربر ثبت شد",
// Owner insurer approval
OWNER_SIGNED_INSURER_APPROVAL: "صاحب خودرو قرارداد بیمه را امضا کرد",
OWNER_REJECTED_INSURER_APPROVAL_PRICING: "صاحب خودرو قیمت‌گذاری بیمه را رد کرد",
OWNER_SIGNED_PRICED_PARTS_PENDING_FACTOR_UPLOAD:
"صاحب خودرو قطعات قیمت‌گذاری‌شده را امضا کرد و در انتظار بارگذاری فاکتور",
OWNER_REJECTED_PRICED_PARTS_BEFORE_FACTORS:
"صاحب خودرو قطعات قیمت‌گذاری‌شده را پیش از فاکتور رد کرد",
// Fanavaran sync
FANAVARAN_AUTO_SUBMIT_SUCCEEDED: "ارسال خودکار به فناوران موفق بود",
FANAVARAN_AUTO_SUBMIT_FAILED: "ارسال خودکار به فناوران ناموفق بود",
FANAVARAN_EARLY_AUTO_SUBMIT_SUCCEEDED: "ارسال زودهنگام خودکار به فناوران موفق بود",
FANAVARAN_EARLY_AUTO_SUBMIT_FAILED: "ارسال زودهنگام خودکار به فناوران ناموفق بود",
FANAVARAN_EXPERTISE_AUTO_SUBMIT_SUCCEEDED:
"ارسال خودکار کارشناسی به فناوران موفق بود",
FANAVARAN_EXPERTISE_AUTO_SUBMIT_FAILED:
"ارسال خودکار کارشناسی به فناوران ناموفق بود",
FANAVARAN_ATTACHMENT_AUTO_SUBMIT_SUCCEEDED:
"ارسال خودکار پیوست به فناوران موفق بود",
FANAVARAN_ATTACHMENT_AUTO_SUBMIT_FAILED:
"ارسال خودکار پیوست به فناوران ناموفق بود",
FANAVARAN_DAMAGE_CASE_AUTO_SUBMIT_SUCCEEDED:
"ارسال خودکار پرونده خسارت به فناوران موفق بود",
FANAVARAN_DAMAGE_CASE_AUTO_SUBMIT_FAILED:
"ارسال خودکار پرونده خسارت به فناوران ناموفق بود",
// V5 claim
V5_HELD_FOR_FILE_MAKER_APPROVAL: "پرونده در انتظار تأیید پرونده‌ساز متوقف شد",
};
// ---------------------------------------------------------------------------
// Persian labels for `metadata.stepKey` inside STEP_COMPLETED events
// ---------------------------------------------------------------------------
export const STEP_KEY_FA_LABELS: Record<string, string> = {
// Claim workflow steps
CLAIM_CREATED: "ایجاد پرونده خسارت",
SELECT_OUTER_PARTS: "انتخاب قطعات بیرونی آسیب‌دیده",
SELECT_OTHER_PARTS: "انتخاب سایر اطلاعات و قطعات",
CAPTURE_PART_DAMAGES: "عکس‌برداری از آسیب‌های قطعات",
UPLOAD_REQUIRED_DOCUMENTS: "بارگذاری مدارک مورد نیاز",
USER_SUBMISSION_COMPLETE: "ارسال اطلاعات توسط کاربر",
USER_EXPERT_RESEND: "ارسال مجدد مدارک توسط کاربر",
EXPERT_DAMAGE_ASSESSMENT: "ارزیابی خسارت توسط کارشناس",
EXPERT_FINAL_REPLY: "پاسخ نهایی کارشناس",
EXPERT_COST_EVALUATION: "ارزیابی هزینه توسط کارشناس",
OWNER_UPLOAD_FACTOR_DOCUMENTS: "بارگذاری فاکتورهای تعمیر توسط مالک",
INSURER_REVIEW: "بررسی توسط بیمه‌گر",
CLAIM_COMPLETED: "پرونده خسارت تکمیل شد",
};
/**
* For `STEP_COMPLETED` and `V3_STEP_COMPLETED` events whose final label
* depends on the `metadata.stepKey` value, this function returns the
* most specific Persian label available.
*/
export function resolveStepCompletedFaLabel(event: {
type: string;
metadata?: any;
}): string | undefined {
if (
event.type !== "STEP_COMPLETED" &&
event.type !== "V3_STEP_COMPLETED"
) {
return undefined;
}
const stepKey: string | undefined = event.metadata?.stepKey;
if (stepKey && STEP_KEY_FA_LABELS[stepKey]) {
return STEP_KEY_FA_LABELS[stepKey];
}
return "مرحله تکمیل شد";
}
/**
* Returns the best Persian label for any timeline event.
*/
export function getEventFaLabel(event: {
type: string;
metadata?: any;
}): string {
return (
resolveStepCompletedFaLabel(event) ??
EVENT_TYPE_FA_LABELS[event.type] ??
event.type
);
}

View File

@@ -76,6 +76,37 @@ export const FANAVARAN_REMOTE_LOOKUPS: FanavaranRemoteLookupDefinition[] = [
url: `${FANAVARAN_LOOKUP_BASE_URL}/common/code-list/person-role`,
cacheFile: "person-role.json",
},
{
name: "insurance-corp",
url: `${FANAVARAN_LOOKUP_BASE_URL}/common/code-list/insurance-corp`,
cacheFile: "insurance-corp.json",
},
{
name: "file-types",
url: `${FANAVARAN_LOOKUP_BASE_URL}/common/base-info/file-types`,
cacheFile: "file-types.json",
},
// NEW LOOKUPS ADDED
{
name: "cities",
url: `${FANAVARAN_LOOKUP_BASE_URL}/common/base-info/cities`,
cacheFile: "cities.json",
},
{
name: "dmg-case-type",
url: `${FANAVARAN_LOOKUP_BASE_URL}/car/code-list/dmg-case-type`,
cacheFile: "dmg-case-type.json",
},
{
name: "dmg-history-status",
url: `${FANAVARAN_LOOKUP_BASE_URL}/car/code-list/dmg-case-history-status`,
cacheFile: "dmg-history-status.json",
},
{
name: "provinces",
url: `${FANAVARAN_LOOKUP_BASE_URL}/common/base-info/Provinces`,
cacheFile: "provinces.json",
},
];
export const TEJARAT_STATIC_ACCIDENT_FILES = {

View File

@@ -1,9 +1,17 @@
import { Module } from "@nestjs/common";
import { HttpModule } from "@nestjs/axios";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
import { FanavaranLookupService } from "./fanavaran-lookup.service";
@Module({
imports: [HttpModule],
imports: [
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
],
providers: [FanavaranLookupService],
exports: [FanavaranLookupService],
})

View File

@@ -183,24 +183,6 @@ export class FanavaranLookupService {
this.logger.log(
`[${clientKey}] Fanavaran lookup response status=${response.status} dataCount=${dataCount}`,
);
this.logger.log(
`[${clientKey}] Fanavaran lookup raw response: ${JSON.stringify(
response.data,
null,
2,
)}`,
);
if (Array.isArray(response.data) && response.data.length > 0) {
const firstItem = response.data[0];
if (firstItem && typeof firstItem === "object") {
this.logger.log(
`[${clientKey}] Fanavaran lookup first item keys: ${Object.keys(
firstItem,
).join(", ")}`,
);
}
}
return response.data;
} catch (error) {
@@ -255,6 +237,51 @@ export class FanavaranLookupService {
return this.fetchFromFanavaran(clientKey, url);
}
async myPolicies(
clientKey: FanavaranClientKey,
nationalCode: string,
insuranceLineId: number = 5,
): Promise<unknown> {
const url =
`${FANAVARAN_LOOKUP_BASE_URL}/common/Policies/inquiry-my-policies` +
`?InsuranceLineId=${insuranceLineId}` +
`&NationalCode=${encodeURIComponent(nationalCode)}`;
return this.fetchFromFanavaran(clientKey, url);
}
async thirdPartyPolicyById(
clientKey: FanavaranClientKey,
policyId: number,
): Promise<unknown> {
const url = `${FANAVARAN_LOOKUP_BASE_URL}/car/third-party-car-policies/${policyId}`;
return this.fetchFromFanavaran(clientKey, url);
}
async bodyPolicyById(
clientKey: FanavaranClientKey,
policyId: number,
): Promise<unknown> {
const url = `${FANAVARAN_LOOKUP_BASE_URL}/car/vehicle-hull-policies/${policyId}`;
return this.fetchFromFanavaran(clientKey, url);
}
async vehicleById(
clientKey: FanavaranClientKey,
vehicleId: number,
versionNo: number = 1,
): Promise<unknown> {
const url = `${FANAVARAN_LOOKUP_BASE_URL}/car/vehicles/${vehicleId}?versionno=${versionNo}`;
return this.fetchFromFanavaran(clientKey, url);
}
async customerById(
clientKey: FanavaranClientKey,
customerId: number,
): Promise<unknown> {
const url = `${FANAVARAN_LOOKUP_BASE_URL}/common/customers/${customerId}`;
return this.fetchFromFanavaran(clientKey, url);
}
async inquiryByUniqueIdentifier(
clientKey: FanavaranClientKey,
params: {
@@ -273,6 +300,91 @@ export class FanavaranLookupService {
return this.fetchFromFanavaran(clientKey, url);
}
async resolveInsuranceCorpId(
clientKey: FanavaranClientKey,
): Promise<number | null> {
const caption = process.env.INSURANCE_CORP_ID?.trim();
if (!caption) {
this.logger.warn("resolveInsuranceCorpId: INSURANCE_CORP_ID env not set");
return null;
}
// Check resolved cache first
const cachedId = await this.readCacheFile<number>(clientKey, "insurance-corp-id-resolved.json");
if (cachedId !== null) {
this.logger.log(`resolveInsuranceCorpId: using cached id=${cachedId} for "${caption}"`);
return cachedId;
}
// Try fetching the full list directly from Fanavaran
let companies: unknown;
const url = `${FANAVARAN_LOOKUP_BASE_URL}/common/code-list/insurance-corp`;
try {
companies = await this.fetchFromFanavaran(clientKey, url);
} catch (error) {
this.logger.warn(
`resolveInsuranceCorpId: Fanavaran fetch failed, trying local lookup endpoint`,
);
// Fallback: call our own local lookup endpoint
try {
const localPort = process.env.PORT || 3000;
const response = await firstValueFrom(
this.httpService.get(`http://localhost:${localPort}/lookups/fanavaran/insurance-corp`, {
timeout: 10000,
}),
);
companies = response.data;
} catch (localError) {
this.logger.error(
`resolveInsuranceCorpId: both Fanavaran and local lookup failed`,
);
return null;
}
}
if (!Array.isArray(companies)) {
this.logger.warn(
`resolveInsuranceCorpId: insurance-corp response is not an array, type=${typeof companies}`,
);
return null;
}
this.logger.log(
`resolveInsuranceCorpId: got ${companies.length} companies, searching for "${caption}"`,
);
const normalizedCaption = caption
.replace(/\s+/g, " ")
.toLowerCase()
.trim();
const match = companies.find((c: any) => {
if (c?.IsActive !== 1) return false;
if (typeof c?.Id !== "number") return false;
const cCaption = typeof c?.Caption === "string" ? c.Caption : "";
const normalized = cCaption.replace(/\s+/g, " ").toLowerCase().trim();
return normalized.includes(normalizedCaption) || normalizedCaption.includes(normalized);
});
if (!match) {
this.logger.warn(
`resolveInsuranceCorpId: no active company matching "${caption}". Available: ` +
companies
.filter((c: any) => c?.IsActive === 1)
.map((c: any) => `${c.Caption} (${c.Id})`)
.join(", "),
);
return null;
}
const corpId = match.Id as number;
// Cache both the resolved id and the full list for future use
await this.writeCacheFile(clientKey, "insurance-corp-id-resolved.json", corpId);
await this.writeCacheFile(clientKey, "insurance-corp.json", companies);
this.logger.log(`resolveInsuranceCorpId: resolved id=${corpId} for "${caption}"`);
return corpId;
}
mapFanavaranAccidentCausesToReasonOptions(
causes: unknown,
): { id: number; label: string; fanavaran: number }[] {
@@ -297,4 +409,5 @@ export class FanavaranLookupService {
};
});
}
}

View File

@@ -1,14 +1,18 @@
import { Controller, Get, Param, Query } from "@nestjs/common";
import { Controller, Get, Param, ParseIntPipe, Query, UseGuards } from "@nestjs/common";
import {
ApiBearerAuth,
ApiOkResponse,
ApiOperation,
ApiParam,
ApiQuery,
ApiTags,
} from "@nestjs/swagger";
import { AuthGuard } from "src/common/auth/guards";
import { LookupsService } from "./lookups.service";
@ApiTags("lookups")
@ApiBearerAuth()
@UseGuards(AuthGuard)
@Controller("lookups")
export class LookupsController {
constructor(private readonly lookupsService: LookupsService) {}
@@ -210,6 +214,83 @@ export class LookupsController {
return await this.lookupsService.getPersonRole();
}
@Get("file-types")
@ApiOperation({
summary: "Fanavaran file types lookup",
description:
"Returns file type codes from common/base-info/file-types. Use FileTypeId in attachment uploads.",
})
@ApiOkResponse({
description: "Returns Fanavaran file types lookup data",
schema: {
type: "array",
items: {
type: "object",
properties: {
Caption: { type: "string" },
Id: { type: "number" },
IsActive: { type: "number" },
},
},
},
})
async getFileTypes() {
return await this.lookupsService.getFileTypes();
}
@Get("cities")
@ApiOperation({
summary: "Fanavaran cities lookup",
description: "Returns city codes from common/base-info/cities.",
})
@ApiOkResponse({
description: "Returns Fanavaran cities lookup data",
schema: { type: "array", items: { type: "object" } },
})
async cities() {
return await this.lookupsService.getCities();
}
@Get("provinces")
@ApiOperation({
summary: "Fanavaran provinces lookup",
description: "Returns province codes from common/base-info/provinces.",
})
@ApiOkResponse({
description: "Returns Fanavaran provinces lookup data",
schema: { type: "array", items: { type: "object" } },
})
async provinces() {
return await this.lookupsService.getProvinces();
}
@Get("dmg-case-type")
@ApiOperation({
summary: "Fanavaran damage case type lookup",
description: "Returns damage case type codes from car/code-list/dmg-case-type.",
})
@ApiOkResponse({
description: "Returns Fanavaran damage case type lookup data",
schema: { type: "array", items: { type: "object" } },
})
async dmgCaseType() {
return await this.lookupsService.getDmgCaseType();
}
@Get("dmg-history-status")
@ApiOperation({
summary: "Fanavaran damage history status lookup",
description:
"Returns damage history status codes from car/code-list/dmg-case-history-status.",
})
@ApiOkResponse({
description: "Returns Fanavaran damage history status lookup data",
schema: { type: "array", items: { type: "object" } },
})
async dmgHistoryStatus() {
return await this.lookupsService.getDmgHistoryStatus();
}
@Get("inquiry-by-vin")
@ApiOperation({
summary: "Fanavaran vehicle inquiry by VIN",
@@ -371,4 +452,75 @@ export class LookupsController {
async getAccidentFields() {
return await this.lookupsService.getAccidentFields();
}
@Get("my-policies")
@ApiOperation({
summary: "My policies inquiry",
description:
"Returns the list of policies for the given national code via common/Policies/inquiry-my-policies.",
})
@ApiQuery({
name: "nationalCode",
description: "National code of the insured person",
example: "0012345678",
})
@ApiQuery({
name: "insuranceLineId",
description: "Insurance line ID (default: 5 for car)",
required: false,
example: 5,
})
@ApiOkResponse({
description: "Returns list of policies",
schema: { type: "array", items: { type: "object" } },
})
async myPolicies(
@Query("nationalCode") nationalCode: string,
@Query("insuranceLineId") insuranceLineId?: number,
) {
return await this.lookupsService.myPolicies(
nationalCode,
insuranceLineId ?? 5,
);
}
@Get("third-party-policy/:policyId")
@ApiOperation({
summary: "Third-party car policy inquiry by policy ID",
description:
"Returns third-party car insurance policy details for the given policy ID via car/third-party-car-policies/{policyId}.",
})
@ApiParam({
name: "policyId",
description: "Fanavaran policy ID",
example: 12345,
})
@ApiOkResponse({
description: "Returns third-party policy details",
schema: { type: "object" },
})
async thirdPartyPolicyById(
@Param("policyId", ParseIntPipe) policyId: number,
) {
return await this.lookupsService.thirdPartyPolicyById(policyId);
}
@Get("body-policy/:policyId")
@ApiOperation({
summary: "Vehicle hull (body) policy inquiry by policy ID",
description:
"Returns vehicle hull (body) insurance policy details for the given policy ID via car/vehicle-hull-policies/{policyId}.",
})
@ApiParam({
name: "policyId",
description: "Fanavaran policy ID",
example: 12345,
})
@ApiOkResponse({
description: "Returns body policy details",
schema: { type: "object" },
})
async bodyPolicyById(@Param("policyId", ParseIntPipe) policyId: number) {
return await this.lookupsService.bodyPolicyById(policyId);
}
}

View File

@@ -123,11 +123,109 @@ export class LookupsService {
return await this.getClientRemoteLookup("person-role");
}
async getFileTypes(): Promise<any> {
return await this.getClientRemoteLookup("file-types");
}
async getCities(): Promise<any> {
return await this.getClientRemoteLookup("cities");
}
async getProvinces(): Promise<any> {
return await this.getClientRemoteLookup("provinces");
}
async getDmgCaseType(): Promise<any> {
return await this.getClientRemoteLookup("dmg-case-type");
}
async getDmgHistoryStatus(): Promise<any> {
return await this.getClientRemoteLookup("dmg-history-status");
}
async inquiryByVin(vin: string): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.inquiryByVin(clientKey, vin);
}
async myPolicies(
nationalCode: string,
insuranceLineId: number = 5,
): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.myPolicies(
clientKey,
nationalCode,
insuranceLineId,
);
}
async mapPolicyDetails(policy: any): Promise<any> {
if (!policy || typeof policy !== "object") {
return policy;
}
const mappedPolicy = { ...policy };
// 1. Map PreviousInsuranceCorpId and TransferorInsuranceCorpId
try {
const companies = (await this.getClientRemoteLookup("insurance-corp")) as any[];
if (Array.isArray(companies)) {
if (typeof policy.PreviousInsuranceCorpId === "number") {
const match = companies.find((c) => c.Id === policy.PreviousInsuranceCorpId);
if (match) {
mappedPolicy.PreviousInsuranceCorpName = match.Caption;
}
}
if (typeof policy.TransferorInsuranceCorpId === "number") {
const match = companies.find((c) => c.Id === policy.TransferorInsuranceCorpId);
if (match) {
mappedPolicy.TransferorInsuranceCorpName = match.Caption;
}
}
}
} catch (e) {
this.logger.warn(`Failed to map insurance-corp lookups: ${e.message}`);
}
// 2. Map PolicyUsageTypeId
try {
const useTypes = (await this.getClientRemoteLookup("vehicle-use-types")) as any[];
if (Array.isArray(useTypes) && typeof policy.PolicyUsageTypeId === "number") {
const match = useTypes.find((t) => t.Id === policy.PolicyUsageTypeId);
if (match) {
mappedPolicy.PolicyUsageTypeName = match.Caption;
}
}
} catch (e) {
this.logger.warn(`Failed to map vehicle-use-types lookups: ${e.message}`);
}
return mappedPolicy;
}
async thirdPartyPolicyById(policyId: number): Promise<unknown> {
const clientKey = this.activeClientKey();
const policy = await this.fanavaranLookupService.thirdPartyPolicyById(clientKey, policyId);
return this.mapPolicyDetails(policy);
}
async bodyPolicyById(policyId: number): Promise<unknown> {
const clientKey = this.activeClientKey();
const policy = await this.fanavaranLookupService.bodyPolicyById(clientKey, policyId);
return this.mapPolicyDetails(policy);
}
async vehicleById(vehicleId: number, versionNo: number = 1): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.vehicleById(clientKey, vehicleId, versionNo);
}
async customerById(customerId: number): Promise<unknown> {
const clientKey = this.activeClientKey();
return this.fanavaranLookupService.customerById(clientKey, customerId);
}
async getAccidentWay(): Promise<{ id: number; label: string }[]> {
const clientKey = this.activeClientKey();
const fileName = TEJARAT_STATIC_ACCIDENT_FILES.accidentWay;

View File

@@ -0,0 +1,154 @@
import {
Body,
Controller,
Get,
Param,
Post,
UseGuards,
} from "@nestjs/common";
import {
ApiBearerAuth,
ApiBody,
ApiOperation,
ApiParam,
ApiResponse,
ApiTags,
} from "@nestjs/swagger";
import { LocalActorAuthGuard } from "src/auth/guards/actor-local.guard";
import { RolesGuard } from "src/auth/guards/role.guard";
import { Roles } from "src/decorators/roles.decorator";
import { CurrentUser } from "src/decorators/user.decorator";
import { RoleEnum } from "src/Types&Enums/role.enum";
import { RequestManagementService } from "./request-management.service";
import { RunCallCenterInquiryV6Dto } from "./dto/run-call-center-inquiry-v6.dto";
/**
* V6 call-center blame API.
*
* A call-center agent takes the guilty party's details over the phone
* (plate, national code, birthday), runs the insurance inquiry, then sends
* the blame link via SMS. The user (guilty party) opens the link and
* completes the form through the standard v2 user flow — except the
* initial-form / inquiry step is skipped (`skipInitialFormStep=true`) because
* the agent already did it.
*
* For THIRD_PARTY files: only the guilty party's data is collected here.
* The damaged party sees their own portion of the page and fills their info
* as normal after the blame link is opened.
*/
@ApiTags("call-center-blame (v6)")
@Controller("v6/call-center-blame")
@ApiBearerAuth()
@UseGuards(LocalActorAuthGuard, RolesGuard)
@Roles(RoleEnum.CALL_CENTER)
export class CallCenterBlameV6Controller {
constructor(
private readonly requestManagementService: RequestManagementService,
) {}
@Get("my-files")
@ApiOperation({ summary: "[V6] List blame files created by this call-center agent" })
@ApiResponse({ status: 200, description: "List of blame files started by this agent" })
getMyFiles(@CurrentUser() agent: any) {
return this.requestManagementService.getMyCallCenterFilesV6(agent);
}
@Post("create")
@ApiOperation({
summary: "[V6] Create a call-centerinitiated blame file",
description:
"Creates a LINK blame file. The call-center agent collects the guilty " +
"party's plate + national-code over the phone, calls run-inquiry to store " +
"the results, then calls send-link to SMS the blame URL to the user. " +
"The user opens the link and fills the form via the normal v2 flow; the " +
"initial-form/inquiry step is automatically skipped because the agent " +
"already ran it.",
})
@ApiBody({
schema: {
type: "object",
required: ["type"],
properties: {
type: {
type: "string",
enum: ["THIRD_PARTY", "CAR_BODY"],
example: "THIRD_PARTY",
},
},
},
})
createFile(
@CurrentUser() agent: any,
@Body("type") type: "THIRD_PARTY" | "CAR_BODY",
) {
return this.requestManagementService.createCallCenterInitiatedBlameV6(agent, { type });
}
@Post("run-inquiry/:requestId")
@ApiOperation({
summary: "[V6] Run plate + insurance inquiry for the guilty party",
description:
"Call after `create`. The agent supplies the plate and national-code data " +
"collected from the caller. Plate + third-party block inquiry is executed " +
"and the results are stored on the blame document. " +
"For THIRD_PARTY files only the guilty party (first party) is inquired here; " +
"the damaged party's inquiry is handled later by the user via the link. " +
"Sheba (IBAN) is not collected here — the user adds it themselves.",
})
@ApiParam({ name: "requestId", description: "Blame request ID from `create`" })
@ApiBody({ type: RunCallCenterInquiryV6Dto })
runInquiry(
@CurrentUser() agent: any,
@Param("requestId") requestId: string,
@Body() dto: RunCallCenterInquiryV6Dto,
) {
return this.requestManagementService.runCallCenterInquiryV6(agent, requestId, dto);
}
@Post("send-link/:requestId")
@ApiOperation({
summary: "[V6] Send blame link to the guilty party via SMS",
description:
"Call after `run-inquiry`. Provide the guilty party's phone number; " +
"the service registers the user if needed, stores them as the first party, " +
"and sends the blame invite link via SMS. The user opens the link and " +
"completes the blame form via the standard v2 user flow (initial-form step skipped).",
})
@ApiParam({ name: "requestId", description: "Blame request ID" })
@ApiBody({
schema: {
type: "object",
required: ["phoneNumber"],
properties: {
phoneNumber: {
type: "string",
example: "09121234567",
description: "Mobile number of the guilty party",
},
},
},
})
sendLink(
@CurrentUser() agent: any,
@Param("requestId") requestId: string,
@Body("phoneNumber") phoneNumber: string,
) {
return this.requestManagementService.sendCallCenterLinkV6(agent, requestId, { phoneNumber });
}
@Get("blame/:requestId")
@ApiOperation({
summary: "[V6] Get a single blame file created by this agent",
description:
"Returns the current status, workflow step, and party data for one blame " +
"file started by this call-center agent. Useful for checking whether the " +
"user has opened the link and progressed through the form.",
})
@ApiParam({ name: "requestId", description: "Blame request ID" })
getBlame(
@CurrentUser() agent: any,
@Param("requestId") requestId: string,
) {
return this.requestManagementService.getCallCenterBlameDetailV6(agent, requestId);
}
}

View File

@@ -1,5 +1,5 @@
import { ApiProperty, ApiPropertyOptional } from "@nestjs/swagger";
import { IsEnum, IsOptional, IsString } from "class-validator";
import { IsBoolean, IsEnum, IsOptional } from "class-validator";
import { CreationMethod } from "../entities/schema/request-management.schema";
export class CreateExpertInitiatedFileDto {
@@ -18,4 +18,17 @@ export class CreateExpertInitiatedFileDto {
})
@IsEnum(CreationMethod)
creationMethod: CreationMethod;
/**
* V5 only. When true the resulting claim will require FileMaker approval
* before fanavaran submission. V4 files must leave this unset (or false).
*/
@ApiPropertyOptional({
description:
"V5 only — when true the claim requires FileMaker approval before fanavaran submission.",
example: false,
})
@IsBoolean()
@IsOptional()
requiresFileMakerApproval?: boolean;
}

View File

@@ -0,0 +1,85 @@
import { ApiProperty, ApiPropertyOptional } from "@nestjs/swagger";
import {
IsBoolean,
IsNotEmpty,
IsOptional,
IsString,
ValidateNested,
} from "class-validator";
import { Type } from "class-transformer";
class PlateV6Dto {
@ApiProperty({ example: "44", description: "Left two digits" })
@IsString()
@IsNotEmpty()
leftDigits: string;
@ApiProperty({ example: "ب", description: "Center alphabet letter" })
@IsString()
@IsNotEmpty()
centerAlphabet: string;
@ApiProperty({ example: "111", description: "Center three digits" })
@IsString()
@IsNotEmpty()
centerDigits: string;
@ApiProperty({ example: "22", description: "Right two digits (Iran region code)" })
@IsString()
@IsNotEmpty()
ir: string;
}
/**
* Inquiry body for the V6 call-center flow.
* Same as V3 but without `sheba` — the user adds their own IBAN later via the link.
*/
export class RunCallCenterInquiryV6Dto {
@ApiProperty({
type: PlateV6Dto,
description: "Plate segments — Tejarat block / third-party inquiry.",
})
@ValidateNested()
@Type(() => PlateV6Dto)
plate: PlateV6Dto;
@ApiProperty({ example: "1234567890", description: "National code of the policyholder (insurer)" })
@IsString()
@IsNotEmpty()
nationalCodeOfInsurer: string;
@ApiProperty({ example: "1234567890", description: "National code of the driver" })
@IsString()
@IsNotEmpty()
nationalCodeOfDriver: string;
@ApiProperty({ example: true, description: "Whether the driver is the same person as the insurer" })
@IsBoolean()
driverIsInsurer: boolean;
@ApiProperty({ example: 13780624, description: "Insurer birth date (Jalali)" })
insurerBirthday: number | string;
@ApiPropertyOptional({
example: 13780624,
description: "Driver birth date (Jalali). Required when driverIsInsurer is false.",
})
@IsOptional()
driverBirthday?: number | string | null;
@ApiPropertyOptional({
example: "123456789",
description: "Driver license (required when driverIsInsurer is false).",
})
@IsOptional()
@IsString()
driverLicense?: string;
@ApiPropertyOptional({
example: "123456789",
description: "Insurer license (required when driverIsInsurer is true).",
})
@IsOptional()
@IsString()
insurerLicense?: string;
}

View File

@@ -4,6 +4,7 @@ import {
IsNotEmpty,
IsOptional,
IsString,
MaxLength,
ValidateNested,
} from "class-validator";
import { Type } from "class-transformer";
@@ -89,3 +90,66 @@ export class RunInquiriesV3Dto {
@IsString()
insurerLicense?: string;
}
/**
* Body for `POST run-inquiries-vin/:requestId`.
* Identical to RunInquiriesV3Dto but uses `vin` (17-char chassis number) instead of `plate`.
* First call = guilty party (+ auto claim). Second call = damaged party (THIRD_PARTY only).
*/
export class RunInquiriesVinV3Dto {
@ApiProperty({
example: "NAAM01E15HK123456",
description: "17-character VIN / chassis number (شماره شاسی)",
maxLength: 17,
})
@IsString()
@IsNotEmpty()
@MaxLength(17)
vin: string;
@ApiProperty({ example: "1234567890", description: "National code of the policyholder (insurer)" })
@IsString()
@IsNotEmpty()
nationalCodeOfInsurer: string;
@ApiProperty({ example: "1234567890", description: "National code of the driver" })
@IsString()
@IsNotEmpty()
nationalCodeOfDriver: string;
@ApiProperty({ example: true, description: "Whether the driver is the same person as the insurer" })
@IsBoolean()
driverIsInsurer: boolean;
@ApiProperty({ example: 13780624, description: "Insurer birth date (Jalali)" })
insurerBirthday: number | string;
@ApiPropertyOptional({ example: 13780624, description: "Driver birth date (Jalali). Required when driverIsInsurer is false." })
@IsOptional()
driverBirthday?: number | string | null;
@ApiPropertyOptional({
example: "IR123456789012345678901234",
description:
"Sheba (IBAN). Required on the damaged party call (CAR_BODY first call; THIRD_PARTY second call).",
})
@IsOptional()
@IsString()
sheba?: string;
@ApiPropertyOptional({
example: "123456789",
description: "Driver license (required when driverIsInsurer is false).",
})
@IsOptional()
@IsString()
driverLicense?: string;
@ApiPropertyOptional({
example: "123456789",
description: "Insurer license (required when driverIsInsurer is true).",
})
@IsOptional()
@IsString()
insurerLicense?: string;
}

View File

@@ -117,12 +117,40 @@ export class BlameRequest {
@Prop({ default: false })
isMadeByFileMaker?: boolean;
/**
* V5 only. When true the resulting claim requires FileMaker approval before
* fanavaran submission. V4 files never set this; it is written at creation
* time by the V5 controller and propagated to the linked claim.
*/
@Prop({ default: false })
requiresFileMakerApproval?: boolean;
/**
* The FileReviewer who claimed this file for completion (V4 flow only).
* Set when a FileReviewer calls assign on this file; enforces one-reviewer-per-file.
*/
@Prop({ type: Types.ObjectId })
assignedFileReviewerId?: Types.ObjectId;
/**
* V6 call-center flow: true when this blame was started by a call-center agent
* on behalf of the guilty party who called in.
*/
@Prop({ default: false })
callCenterInitiated?: boolean;
/**
* V6 call-center flow: the call-center agent who created this file.
*/
@Prop({ type: Types.ObjectId })
initiatedByCallCenterId?: Types.ObjectId;
/**
* V6 call-center flow: when true the user-side blame page should skip the
* inquiry / initial-form step (the call-center agent already ran the inquiry).
*/
@Prop({ default: false })
skipInitialFormStep?: boolean;
}
export type BlameRequestDocument = HydratedDocument<BlameRequest>;

View File

@@ -41,6 +41,10 @@ export class Person {
@Prop({ type: String })
driverBirthday?: string | null;
/** Cached Fanavaran party ID resolved from nationalCodeOfDriver + driverBirthday + driverIsInsurer */
@Prop({ type: Number })
fanavaranDriverId?: number;
}
export const PersonSchema = SchemaFactory.createForClass(Person);

View File

@@ -31,7 +31,7 @@ import { RoleEnum } from "src/Types&Enums/role.enum";
import { CreationMethod } from "./entities/schema/request-management.schema";
import { CreateExpertInitiatedFileDto } from "./dto/expert-initiated.dto";
import { SendPartyOtpDto, VerifyPartyOtpDto } from "./dto/party-otp.dto";
import { RunInquiriesV3Dto } from "./dto/run-inquiries-v3.dto";
import { RunInquiriesV3Dto, RunInquiriesVinV3Dto } from "./dto/run-inquiries-v3.dto";
import {
CarBodyFormDto,
DescriptionDto,
@@ -181,6 +181,23 @@ export class ExpertInitiatedBlameV3MirrorController {
return this.requestManagementService.runInquiriesV3(requestId, expert, dto);
}
@Post("run-inquiries-vin/:requestId")
@ApiParam({ name: "requestId" })
@ApiBody({ type: RunInquiriesVinV3Dto })
@ApiOperation({
summary: "Run VIN/chassis inquiries for the current party (V3)",
description:
"VIN alternative to run-inquiries. Uses ESG chassis lookup instead of plate-based inquiry. " +
"1st call = guilty party (+ auto claim). 2nd call = damaged party (THIRD_PARTY, after guilty sign).",
})
async runInquiriesVin(
@CurrentUser() expert: any,
@Param("requestId") requestId: string,
@Body() dto: RunInquiriesVinV3Dto,
) {
return this.requestManagementService.runInquiriesVinV3(requestId, expert, dto);
}
@Post("add-detail-location/:requestId")
@ApiParam({ name: "requestId" })
@ApiBody({ type: LocationDto })

View File

@@ -1,6 +1,5 @@
import { extname } from "node:path";
import {
BadRequestException,
Body,
Controller,
Param,
@@ -28,6 +27,7 @@ import { MediaPolicyService } from "src/media-policy/media-policy.service";
import { DEFAULT_MEDIA_MAX_BYTES } from "src/client/client.service";
import { RoleEnum } from "src/Types&Enums/role.enum";
import { AddPlateDto } from "src/profile/dto/user/AddPlateDto";
import { InitialFormVinDto } from "./dto/create-request-management.dto";
import {
BlameConfessionDtoV2,
CarBodyFormDto,
@@ -35,6 +35,7 @@ import {
LocationDto,
} from "./dto/create-request-management.dto";
import { CreateExpertInitiatedFileDto } from "./dto/expert-initiated.dto";
import { CreationMethod } from "./entities/schema/request-management.schema";
import { SendPartyOtpsDto } from "./dto/send-party-otps.dto";
import { VerifyPartyOtpsDto } from "./dto/verify-party-otps.dto";
import { SendPartyOtpDto, VerifyPartyOtpDto } from "./dto/party-otp.dto";
@@ -76,17 +77,17 @@ export class ExpertInitiatedBlameMirrorController {
@ApiOperation({
summary: "[Expert mirror] Create expert-initiated blame file",
description:
"Use creationMethod=IN_PERSON for the on-site flow. Creates a BlameRequest owned by the parties but filled by the expert.",
"Creates an IN_PERSON blame file filled by the expert on behalf of both parties. creationMethod is always forced to IN_PERSON regardless of what is sent.",
})
@ApiBody({ type: CreateExpertInitiatedFileDto })
async create(
@CurrentUser() expert: any,
@Body() dto: CreateExpertInitiatedFileDto,
) {
return this.requestManagementService.createExpertInitiatedBlameV2(
expert,
dto,
);
return this.requestManagementService.createExpertInitiatedBlameV2(expert, {
...dto,
creationMethod: CreationMethod.IN_PERSON,
});
}
@Post("send-link/:requestId")
@@ -159,7 +160,7 @@ export class ExpertInitiatedBlameMirrorController {
);
}
@Post("/initial-form/:requestId")
@Post("/run-inquiries/:requestId")
@ApiParam({ name: "requestId" })
@ApiBody({ type: AddPlateDto })
@ApiOperation({
@@ -181,6 +182,29 @@ export class ExpertInitiatedBlameMirrorController {
);
}
@Post("/run-inquiries-vin/:requestId")
@ApiParam({ name: "requestId" })
@ApiBody({ type: InitialFormVinDto })
@ApiOperation({
summary: "[Expert mirror] Initial form via VIN/chassis inquiry for current party",
description:
"VIN alternative to run-inquiries. Uses ESG chassis lookup instead of plate-based inquiry. " +
"Fills the FIRST or SECOND party insurance/vehicle data depending on the current workflow step.",
})
async initialFormVin(
@Param("requestId") requestId: string,
@Body() body: InitialFormVinDto,
@CurrentUser() expert: any,
@Body("partyRole") partyRole?: string,
) {
return this.requestManagementService.initialFormVinV2(
requestId,
body,
expert,
partyRole,
);
}
@ApiBody({
schema: {
type: "object",
@@ -362,20 +386,6 @@ export class ExpertInitiatedBlameMirrorController {
@CurrentUser() expert: any,
@UploadedFile() sign: Express.Multer.File,
) {
// Guard: accident fields (accidentWay, etc.) must be filled before signing.
// This prevents the expert from bypassing add-accident-fields and avoids the
// double-sign bug where add-accident-fields re-enters WAITING_FOR_SIGNATURES
// after a signature was already recorded.
const requestData = await this.requestManagementService.getBlameRequestV2(
requestId,
expert,
);
if (!(requestData?.expert?.decision as any)?.fields?.accidentWay) {
throw new BadRequestException(
"Accident fields (accidentWay, accidentReason, accidentType) must be submitted via add-accident-fields before signing.",
);
}
await this.mediaPolicyService.assertForBlame(sign, requestId, "image");
const partyRole =
body?.partyRole === "SECOND" ? PartyRole.SECOND : PartyRole.FIRST;
@@ -389,7 +399,7 @@ export class ExpertInitiatedBlameMirrorController {
);
}
@Post("add-accident-fields/:requestId")
@Post("accident-fields/:requestId")
@ApiParam({ name: "requestId" })
@ApiBody({ type: ExpertAccidentFieldsDto })
@ApiOperation({

View File

@@ -30,7 +30,7 @@ import { RoleEnum } from "src/Types&Enums/role.enum";
import { CreationMethod } from "./entities/schema/request-management.schema";
import { CreateExpertInitiatedFileDto } from "./dto/expert-initiated.dto";
import { SendPartyOtpDto, VerifyPartyOtpDto } from "./dto/party-otp.dto";
import { RunInquiriesV3Dto } from "./dto/run-inquiries-v3.dto";
import { RunInquiriesV3Dto, RunInquiriesVinV3Dto } from "./dto/run-inquiries-v3.dto";
import {
CarBodyFormDto,
DescriptionDto,
@@ -87,7 +87,9 @@ export class FileMakerBlameV4Controller {
) {
return this.requestManagementService.createExpertInitiatedBlameV2(
fileMaker,
{ ...dto, creationMethod: CreationMethod.IN_PERSON },
// requiresFileMakerApproval is V5-only; explicitly exclude it from V4 so
// a client that accidentally sends the field cannot poison the blame record.
{ ...dto, creationMethod: CreationMethod.IN_PERSON, requiresFileMakerApproval: false },
);
}
@@ -191,6 +193,27 @@ export class FileMakerBlameV4Controller {
);
}
@Post("run-inquiries-vin/:requestId")
@ApiParam({ name: "requestId" })
@ApiBody({ type: RunInquiriesVinV3Dto })
@ApiOperation({
summary: "Run VIN/chassis inquiries for the current party (V4)",
description:
"VIN alternative to run-inquiries. Uses ESG chassis lookup instead of plate-based inquiry. " +
"1st call = guilty party (+ auto claim). 2nd call = damaged party (THIRD_PARTY, after guilty sign).",
})
async runInquiriesVin(
@CurrentUser() fileMaker: any,
@Param("requestId") requestId: string,
@Body() dto: RunInquiriesVinV3Dto,
) {
return this.requestManagementService.runInquiriesVinV3(
requestId,
fileMaker,
dto,
);
}
// ─── Party details ────────────────────────────────────────────────────────────
@Post("add-detail-location/:requestId")

View File

@@ -30,7 +30,7 @@ import { RoleEnum } from "src/Types&Enums/role.enum";
import { CreationMethod } from "./entities/schema/request-management.schema";
import { CreateExpertInitiatedFileDto } from "./dto/expert-initiated.dto";
import { SendPartyOtpDto, VerifyPartyOtpDto } from "./dto/party-otp.dto";
import { RunInquiriesV3Dto } from "./dto/run-inquiries-v3.dto";
import { RunInquiriesV3Dto, RunInquiriesVinV3Dto } from "./dto/run-inquiries-v3.dto";
import {
CarBodyFormDto,
DescriptionDto,
@@ -88,7 +88,7 @@ export class FileMakerBlameV5Controller {
) {
return this.requestManagementService.createExpertInitiatedBlameV2(
fileMaker,
{ ...dto, creationMethod: CreationMethod.IN_PERSON },
{ ...dto, creationMethod: CreationMethod.IN_PERSON, requiresFileMakerApproval: true },
);
}
@@ -192,6 +192,27 @@ export class FileMakerBlameV5Controller {
);
}
@Post("run-inquiries-vin/:requestId")
@ApiParam({ name: "requestId" })
@ApiBody({ type: RunInquiriesVinV3Dto })
@ApiOperation({
summary: "Run VIN/chassis inquiries for the current party (V5)",
description:
"VIN alternative to run-inquiries. Uses ESG chassis lookup instead of plate-based inquiry. " +
"1st call = guilty party (+ auto claim). 2nd call = damaged party (THIRD_PARTY, after guilty sign).",
})
async runInquiriesVin(
@CurrentUser() fileMaker: any,
@Param("requestId") requestId: string,
@Body() dto: RunInquiriesVinV3Dto,
) {
return this.requestManagementService.runInquiriesVinV3(
requestId,
fileMaker,
dto,
);
}
// ─── Party details ────────────────────────────────────────────────────────────
@Post("add-detail-location/:requestId")

View File

@@ -1,11 +1,15 @@
import { extname } from "node:path";
import {
BadRequestException,
Body,
Controller,
Get,
HttpException,
InternalServerErrorException,
Param,
Patch,
Post,
Put,
UploadedFile,
UseGuards,
UseInterceptors,
@@ -51,8 +55,7 @@ import { GetCaptureRequirementsV2ResponseDto } from "src/claim-request-managemen
*
* The FileReviewer picks up a sealed file (both signatures collected by the
* FileMaker) and completes the damage-assessment portion: accident fields,
* documents, part selection, photo capture, walk-around video, and the final
* blame accident video that moves the file to WAITING_FOR_EXPERT.
* documents, part selection, photo capture, and walk-around video (final step).
*
* Sequence:
* accident-fields
@@ -61,9 +64,11 @@ import { GetCaptureRequirementsV2ResponseDto } from "src/claim-request-managemen
* → select-outer-parts
* → select-other-parts
* → capture-part (damaged-part photos + four angles)
* → upload-document (chassis / engine / metal plate — capture phase)
* → car-capture (walk-around video)
* → upload-video (blame accident video — final, moves to WAITING_FOR_EXPERT)
* → upload-document (chassis / engine — capture phase)
* → car-capture (walk-around video — FINAL FileReviewer step)
* ↳ claim → WAITING_FOR_DAMAGE_EXPERT, blame → COMPLETED
*
* NOTE: upload-video is a no-op for V4 (blame is already COMPLETED by car-capture).
*/
@ApiTags("v4 FileReviewer — blame file review & capture")
@Controller("v4/file-reviewer/blame-request-management")
@@ -315,6 +320,73 @@ export class FileReviewerBlameV4Controller {
);
}
// ─── Owner signature on expert pricing ───────────────────────────────────────
@Put("claim-sign/:claimRequestId")
@ApiParam({ name: "claimRequestId" })
@ApiConsumes("multipart/form-data")
@ApiBody({
description: "Signature file, agreement, and branch",
schema: {
type: "object",
required: ["sign", "agree", "branchId"],
properties: {
sign: { type: "string", format: "binary", description: "Signature image" },
agree: { type: "boolean", description: "true to accept, false to reject" },
branchId: { type: "string", description: "Insurer branch ID" },
},
},
})
@ApiOperation({
summary: "Owner signature on expert pricing (V4 — FileReviewer acts on behalf of user)",
description:
"FileReviewer submits the damaged party's signature during the final approval stage. " +
"Delegates to the same service method as the user sign endpoint; the FileReviewer's " +
"identity is resolved to the claim owner via `resolveClaimEffectiveUserId`.",
})
@UseInterceptors(
FileInterceptor("sign", {
limits: { fileSize: DEFAULT_MEDIA_MAX_BYTES },
storage: diskStorage({
destination: "./files/claim-sign",
filename: (req, file, callback) => {
const unique = Date.now();
const ex = extname(file.originalname);
const base = file.originalname.split(/[.,\s-]/)[0] || "sign";
callback(null, `${base}-${unique}${ex}`);
},
}),
}),
)
async submitOwnerSign(
@Param("claimRequestId") claimRequestId: string,
@Body("agree") agree: string | boolean,
@Body("branchId") branchId: string,
@CurrentUser() fileReviewer: any,
@UploadedFile() sign: Express.Multer.File,
) {
await this.mediaPolicyService.assertForClaim(sign, claimRequestId, "image");
const agreed =
typeof agree === "string"
? agree === "true" || agree === "1"
: Boolean(agree);
try {
return await this.claimRequestManagementService.submitOwnerInsurerApprovalSignV2(
claimRequestId,
agreed,
typeof branchId === "string" ? branchId : "",
sign,
fileReviewer.sub,
fileReviewer,
);
} catch (error) {
if (error instanceof HttpException) throw error;
throw new InternalServerErrorException(
error instanceof Error ? error.message : "Failed to submit signature",
);
}
}
// ─── Walk-around video ────────────────────────────────────────────────────────
@Patch("car-capture/:claimRequestId")
@@ -341,9 +413,10 @@ export class FileReviewerBlameV4Controller {
},
})
@ApiOperation({
summary: "Walk-around video",
summary: "Walk-around video (final FileReviewer step — V4)",
description:
"Upload after capture-part is complete (parts, angles, capture-phase docs). Required before the final blame accident video.",
"Last FileReviewer action. Upload after capture-part is complete (parts, angles, chassis/engine docs). " +
"Finalises the claim → WAITING_FOR_DAMAGE_EXPERT and marks the blame as COMPLETED.",
})
async carCapture(
@Param("claimRequestId") claimRequestId: string,
@@ -384,10 +457,10 @@ export class FileReviewerBlameV4Controller {
@Post("upload-video/:requestId")
@ApiParam({ name: "requestId" })
@ApiOperation({
summary: "Blame accident video (FileReviewer final step — optional)",
summary: "Blame accident video (no-op for V4 — car-capture is the final step)",
description:
"Last step of the V4 flow. Requires claim walk-around video and completed capture. " +
"File is optional — omit it to complete the blame without attaching a video.",
"Deprecated for V4. The blame is already COMPLETED by car-capture. " +
"Calling this endpoint returns an idempotent success response.",
})
async uploadBlameVideo(
@Param("requestId") requestId: string,

View File

@@ -3,9 +3,12 @@ import {
Body,
Controller,
Get,
HttpException,
InternalServerErrorException,
Param,
Patch,
Post,
Put,
UploadedFile,
UseGuards,
UseInterceptors,
@@ -47,11 +50,9 @@ import {
import { GetCaptureRequirementsV2ResponseDto } from "src/claim-request-management/dto/capture-requirements-v2.dto";
/**
* V5 FileReviewer flow — same as V4 except the final blame accident video moves
* the file to WAITING_FOR_FINANCIAL_EXPERT instead of WAITING_FOR_EXPERT.
*
* A FinancialExpert must then approve the file (→ WAITING_FOR_EXPERT) or
* reject it back (→ FINANCIAL_EXPERT_REJECTED) for the FileReviewer to correct.
* V5 FileReviewer flow — same as V4 except after the damage expert completes
* their review, the claim goes to WAITING_FOR_FILE_MAKER_APPROVAL instead of
* being submitted directly to fanavaran.
*
* Sequence:
* accident-fields
@@ -60,9 +61,12 @@ import { GetCaptureRequirementsV2ResponseDto } from "src/claim-request-managemen
* → select-outer-parts
* → select-other-parts
* → capture-part (damaged-part photos + four angles)
* → upload-document (chassis / engine / metal plate — capture phase)
* → car-capture (walk-around video)
* → upload-video (blame accident video — final, moves to WAITING_FOR_FINANCIAL_EXPERT)
* → upload-document (chassis / engine — capture phase)
* → car-capture (walk-around video — FINAL FileReviewer step)
* ↳ claim → WAITING_FOR_DAMAGE_EXPERT, blame → COMPLETED
* ↳ after expert review: claim → WAITING_FOR_FILE_MAKER_APPROVAL
*
* NOTE: upload-video is a no-op for V5 (blame is already COMPLETED by car-capture).
*/
@ApiTags("v5 FileReviewer — blame file review & capture (with FinancialExpert approval)")
@Controller("v5/file-reviewer/blame-request-management")
@@ -314,6 +318,73 @@ export class FileReviewerBlameV5Controller {
);
}
// ─── Owner signature on expert pricing ───────────────────────────────────────
@Put("claim-sign/:claimRequestId")
@ApiParam({ name: "claimRequestId" })
@ApiConsumes("multipart/form-data")
@ApiBody({
description: "Signature file, agreement, and branch",
schema: {
type: "object",
required: ["sign", "agree", "branchId"],
properties: {
sign: { type: "string", format: "binary", description: "Signature image" },
agree: { type: "boolean", description: "true to accept, false to reject" },
branchId: { type: "string", description: "Insurer branch ID" },
},
},
})
@ApiOperation({
summary: "Owner signature on expert pricing (V5 — FileReviewer acts on behalf of user)",
description:
"FileReviewer submits the damaged party's signature during the final approval stage. " +
"Delegates to the same service method as the user sign endpoint; the FileReviewer's " +
"identity is resolved to the claim owner via `resolveClaimEffectiveUserId`.",
})
@UseInterceptors(
FileInterceptor("sign", {
limits: { fileSize: DEFAULT_MEDIA_MAX_BYTES },
storage: diskStorage({
destination: "./files/claim-sign",
filename: (req, file, callback) => {
const unique = Date.now();
const ex = extname(file.originalname);
const base = file.originalname.split(/[.,\s-]/)[0] || "sign";
callback(null, `${base}-${unique}${ex}`);
},
}),
}),
)
async submitOwnerSign(
@Param("claimRequestId") claimRequestId: string,
@Body("agree") agree: string | boolean,
@Body("branchId") branchId: string,
@CurrentUser() fileReviewer: any,
@UploadedFile() sign: Express.Multer.File,
) {
await this.mediaPolicyService.assertForClaim(sign, claimRequestId, "image");
const agreed =
typeof agree === "string"
? agree === "true" || agree === "1"
: Boolean(agree);
try {
return await this.claimRequestManagementService.submitOwnerInsurerApprovalSignV2(
claimRequestId,
agreed,
typeof branchId === "string" ? branchId : "",
sign,
fileReviewer.sub,
fileReviewer,
);
} catch (error) {
if (error instanceof HttpException) throw error;
throw new InternalServerErrorException(
error instanceof Error ? error.message : "Failed to submit signature",
);
}
}
// ─── Walk-around video ────────────────────────────────────────────────────────
@Patch("car-capture/:claimRequestId")
@@ -340,9 +411,11 @@ export class FileReviewerBlameV5Controller {
},
})
@ApiOperation({
summary: "Walk-around video",
summary: "Walk-around video (final FileReviewer step — V5)",
description:
"Upload after capture-part is complete (parts, angles, capture-phase docs). Required before the final blame accident video.",
"Last FileReviewer action. Upload after capture-part is complete (parts, angles, chassis/engine docs). " +
"Finalises the claim → WAITING_FOR_DAMAGE_EXPERT and marks the blame as COMPLETED. " +
"After the damage expert review completes the claim moves to WAITING_FOR_FILE_MAKER_APPROVAL.",
})
async carCapture(
@Param("claimRequestId") claimRequestId: string,
@@ -360,7 +433,6 @@ export class FileReviewerBlameV5Controller {
// ─── Final blame video ─────────────────────────────────────────────────────────
//
// V5 difference: moves file to WAITING_FOR_FINANCIAL_EXPERT, not WAITING_FOR_EXPERT.
@ApiBody({
schema: {
@@ -385,10 +457,10 @@ export class FileReviewerBlameV5Controller {
@Post("upload-video/:requestId")
@ApiParam({ name: "requestId" })
@ApiOperation({
summary: "Blame accident video (FileReviewer final step — V5, optional)",
summary: "Blame accident video (no-op for V5 — car-capture is the final step)",
description:
"Last step of the V5 FileReviewer flow. Requires claim walk-around video and completed capture. " +
"File is optional — omit it to complete the blame without attaching a video.",
"Deprecated for V5. The blame is already COMPLETED by car-capture. " +
"Calling this endpoint returns an idempotent success response.",
})
async uploadBlameVideo(
@Param("requestId") requestId: string,

View File

@@ -368,6 +368,8 @@ export class InquiryRefreshService {
next.insurance.policyNumber =
mapped.PrntPlcyCmpDocNo ||
mapped.printNumber ||
mapped.insuranceNumber ||
next.insurance.policyNumber;
next.insurance.company =
mapped.companyPersianName || mapped.CompanyName || next.insurance.company;

View File

@@ -28,6 +28,7 @@ import { MediaPolicyService } from "src/media-policy/media-policy.service";
import { DEFAULT_MEDIA_MAX_BYTES } from "src/client/client.service";
import { RoleEnum } from "src/Types&Enums/role.enum";
import { AddPlateDto } from "src/profile/dto/user/AddPlateDto";
import { InitialFormVinDto } from "./dto/create-request-management.dto";
import {
CarBodyFormDto,
DescriptionDto,
@@ -165,6 +166,29 @@ export class RegistrarBlameMirrorController {
);
}
@Post("/initial-form-vin/:requestId")
@ApiParam({ name: "requestId" })
@ApiBody({ type: InitialFormVinDto })
@ApiOperation({
summary: "[Registrar mirror] Initial form via VIN/chassis inquiry for current party",
description:
"VIN alternative to initial-form. Uses ESG chassis lookup instead of plate-based inquiry. " +
"Fills the FIRST or SECOND party insurance/vehicle data depending on the current workflow step.",
})
async initialFormVin(
@Param("requestId") requestId: string,
@Body() body: InitialFormVinDto,
@CurrentUser() registrar: any,
@Body("partyRole") partyRole?: string,
) {
return this.requestManagementService.initialFormVinV2(
requestId,
body,
registrar,
partyRole,
);
}
@ApiBody({
schema: {
type: "object",

View File

@@ -50,6 +50,7 @@ import { FileReviewerBlameV5Controller } from "./file-reviewer-blame-v5.controll
import { FileMakerClaimApprovalV5Controller } from "./file-maker-claim-approval-v5.controller";
import { InquiryRefreshController } from "./inquiry-refresh.controller";
import { InquiryRefreshService } from "./inquiry-refresh.service";
import { CallCenterBlameV6Controller } from "./call-center-blame-v6.controller";
@Module({
imports: [
@@ -92,6 +93,7 @@ import { InquiryRefreshService } from "./inquiry-refresh.service";
FileReviewerBlameV5Controller,
FileMakerClaimApprovalV5Controller,
InquiryRefreshController,
CallCenterBlameV6Controller,
],
providers: [
RequestManagementService,

View File

@@ -42,7 +42,7 @@ import { ClaimStatus } from "src/Types&Enums/claim-request-management/claimStatu
import { ClaimWorkflowStep } from "src/Types&Enums/claim-request-management/claim-workflow-steps.enum";
import { resolveClaimOwnerFieldsFromBlame } from "src/helpers/blame-damaged-party";
import { ExpertAccidentFieldsDto } from "./dto/expert-accident-fields.dto";
import { RunInquiriesV3Dto } from "./dto/run-inquiries-v3.dto";
import { RunInquiriesV3Dto, RunInquiriesVinV3Dto } from "./dto/run-inquiries-v3.dto";
import { SandHubService } from "src/sand-hub/sand-hub.service";
import { ReqBlameStatus } from "src/Types&Enums/blame-request-management/status.enum";
import { StepsEnum } from "src/Types&Enums/blame-request-management/steps.enum";
@@ -278,6 +278,50 @@ export class RequestManagementService {
return;
}
// IN_PERSON THIRD_PARTY (expert/registrar-initiated): after first-party description
// the expert collects the first party's signature before moving to the second party.
// Skip FIRST_INVITE_SECOND and hold at WAITING_FOR_SIGNATURES so the sign endpoint
// can be called for the first party. The workflow advances to FIRST_INVITE_SECOND
// only after expertUploadPartySignatureV2/V3 records the first-party confirmation.
if (
req.type === BlameRequestType.THIRD_PARTY &&
req.creationMethod === CreationMethod.IN_PERSON &&
(req.expertInitiated || req.registrarInitiated) &&
submittedStepKey === WorkflowStep.FIRST_DESCRIPTION
) {
const completed = Array.isArray(req.workflow.completedSteps)
? req.workflow.completedSteps
: [];
if (!completed.includes(submittedStepKey))
completed.push(submittedStepKey);
req.workflow.completedSteps = completed;
req.workflow.currentStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.workflow.nextStep = undefined;
req.status = CaseStatus.WAITING_FOR_SIGNATURES;
this.logger.debug(
"[WORKFLOW] IN_PERSON THIRD_PARTY: advanced to WAITING_FOR_SIGNATURES after FIRST_DESCRIPTION (first-party sign before second-party invite)",
);
return;
}
// IN_PERSON THIRD_PARTY: guilt is decided on-site by the expert — there is
// no waiting-for-field-expert phase. Replace WAITING_FOR_GUILT_DECISION
// with WAITING_FOR_SIGNATURES wherever it would surface as current/next step.
const isInPersonThirdParty =
req.type === BlameRequestType.THIRD_PARTY &&
req.creationMethod === CreationMethod.IN_PERSON &&
(req.expertInitiated || req.registrarInitiated);
const resolveStep = (step: WorkflowStep | undefined): WorkflowStep | undefined => {
if (
isInPersonThirdParty &&
step === WorkflowStep.WAITING_FOR_GUILT_DECISION
) {
return WorkflowStep.WAITING_FOR_SIGNATURES;
}
return step;
};
const submittedStep = await this.getWorkflowStep({
stepKey: submittedStepKey,
});
@@ -299,8 +343,10 @@ export class RequestManagementService {
submittedStep.stepNumber + 1,
);
const nextStepKey = (sequentialNextStep?.stepKey ??
submittedStep.nextPossibleSteps?.[0]) as WorkflowStep | undefined;
const nextStepKey = resolveStep(
(sequentialNextStep?.stepKey ??
submittedStep.nextPossibleSteps?.[0]) as WorkflowStep | undefined,
);
if (!nextStepKey) {
// Terminal state: no more steps
@@ -348,7 +394,7 @@ export class RequestManagementService {
nextStepDoc.nextPossibleSteps?.[0]) as WorkflowStep | undefined;
req.workflow.currentStep = nextStepKey;
req.workflow.nextStep = afterNextKey;
req.workflow.nextStep = resolveStep(afterNextKey);
this.logger.debug(
`[WORKFLOW] Advanced to currentStep=${req.workflow.currentStep}, nextStep=${req.workflow.nextStep ?? "undefined"}`,
@@ -2067,13 +2113,9 @@ export class RequestManagementService {
? req.workflow.completedSteps
: [];
if (!completed.includes(stepKey)) completed.push(stepKey);
// Same as postfield-expert reply: guilt phase is satisfied without an expert; parties must still sign.
if (!completed.includes(WorkflowStep.WAITING_FOR_GUILT_DECISION)) {
completed.push(WorkflowStep.WAITING_FOR_GUILT_DECISION);
}
req.workflow.completedSteps = completed;
req.workflow.currentStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.workflow.nextStep = undefined;
req.workflow.nextStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.status = CaseStatus.WAITING_FOR_SIGNATURES;
closedByMutualAgreement = true;
@@ -2154,12 +2196,9 @@ export class RequestManagementService {
? req.workflow.completedSteps
: [];
if (!completed.includes(stepKey)) completed.push(stepKey);
if (!completed.includes(WorkflowStep.WAITING_FOR_GUILT_DECISION)) {
completed.push(WorkflowStep.WAITING_FOR_GUILT_DECISION);
}
req.workflow.completedSteps = completed;
req.workflow.currentStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.workflow.nextStep = undefined;
req.workflow.nextStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.status = CaseStatus.WAITING_FOR_SIGNATURES;
} else if (!closedByMutualAgreement) {
if (stepKey === WorkflowStep.SECOND_DESCRIPTION) {
@@ -2280,6 +2319,7 @@ export class RequestManagementService {
const url = this.smsOrchestrationService.buildInviteLink(
frontendRoute,
requestId,
"v1",
);
await this.smsOrchestrationService.sendInviteLink(
secondPartyPhone,
@@ -2333,6 +2373,7 @@ export class RequestManagementService {
const url = this.smsOrchestrationService.buildInviteLink(
frontendRoute,
requestId,
"v1",
);
await this.smsOrchestrationService.sendInviteLink(
phoneNumber,
@@ -3446,6 +3487,7 @@ export class RequestManagementService {
const URL = this.smsOrchestrationService.buildInviteLink(
frontendRoutes,
requestId,
"v1",
);
await this.smsOrchestrationService.sendInviteLink(
phoneNumber,
@@ -4796,6 +4838,9 @@ export class RequestManagementService {
? FilledBy.EXPERT
: FilledBy.CUSTOMER,
...(isFileMakerRole ? { isMadeByFileMaker: true } : {}),
// V5 only: flag that causes the resulting claim to require FileMaker
// approval before fanavaran submission. V4 files never set this.
...(dto.requiresFileMakerApproval ? { requiresFileMakerApproval: true } : {}),
});
const requestId = String((created as any)._id);
@@ -4885,6 +4930,7 @@ export class RequestManagementService {
const firstLink = this.smsOrchestrationService.buildBlamePartyLink(
requestId,
"FIRST",
"v2",
);
const smsSent = await this.smsOrchestrationService.sendFieldExpertLink({
receptor: phone,
@@ -6708,6 +6754,23 @@ export class RequestManagementService {
},
});
}
} else if (
// THIRD_PARTY IN_PERSON: first party just signed — advance workflow to
// FIRST_INVITE_SECOND so the frontend knows to proceed to the second-party
// registration step. Status stays WAITING_FOR_SIGNATURES.
req.type === BlameRequestType.THIRD_PARTY &&
req.creationMethod === CreationMethod.IN_PERSON &&
(req.expertInitiated || req.registrarInitiated) &&
partyRole === PartyRole.FIRST
) {
await this.blameRequestDbService.findByIdAndUpdate(requestId, {
$set: {
"workflow.currentStep": WorkflowStep.FIRST_INVITE_SECOND as any,
"workflow.nextStep": WorkflowStep.SECOND_INITIAL_FORM as any,
},
});
message =
"First party signature recorded. Proceed to register the second party.";
}
return {
requestId: String(req._id),
@@ -6733,6 +6796,18 @@ export class RequestManagementService {
);
}
await this.verifyExpertAccessForBlameV2(req, expert);
// In the V2 IN_PERSON mirror flow guilt is resolved automatically after both
// parties complete their narrative steps (addDescriptionV2). The sign step for
// both parties must happen BEFORE accident-fields is called — calling it earlier
// would overwrite the workflow and cause the frontend to skip the sign page.
if (
req.creationMethod === CreationMethod.IN_PERSON &&
req.status !== CaseStatus.COMPLETED
) {
throw new BadRequestException(
`accident-fields can only be submitted after both parties have signed (current status: ${req.status}). Complete both signatures first.`,
);
}
if (!req.expert) req.expert = {} as any;
if (!req.expert.decision) req.expert.decision = {} as any;
@@ -6761,29 +6836,24 @@ export class RequestManagementService {
},
};
// For IN_PERSON expert files: after accident fields are filled, guilt is
// decided and we can go straight to signatures (no separate review needed).
// IN_PERSON V2 mirror: accident-fields is a post-sign supplemental step called
// only after COMPLETED (both parties have signed). Record WAITING_FOR_GUILT_DECISION
// in completedSteps here — it was intentionally omitted from description so the
// frontend does not route to this page before signatures are collected.
if (req.creationMethod === CreationMethod.IN_PERSON) {
const completed = Array.isArray(req.workflow?.completedSteps)
? req.workflow.completedSteps
: [];
const currentStep = req.workflow?.currentStep as WorkflowStep | undefined;
if (currentStep && !completed.includes(currentStep)) {
completed.push(currentStep);
}
if (!completed.includes(WorkflowStep.WAITING_FOR_GUILT_DECISION)) {
completed.push(WorkflowStep.WAITING_FOR_GUILT_DECISION);
}
if (req.workflow) {
req.workflow.completedSteps = completed;
req.workflow.currentStep = WorkflowStep.WAITING_FOR_SIGNATURES;
req.workflow.nextStep = undefined;
}
req.status = CaseStatus.WAITING_FOR_SIGNATURES;
if (!Array.isArray(req.history)) req.history = [];
req.history.push({
type: "ACCIDENT_FIELDS_SAVED_ADVANCED_TO_SIGNATURES",
type: "ACCIDENT_FIELDS_SAVED",
actor: {
actorId: new Types.ObjectId(String(expert.sub)),
actorName:
@@ -6792,7 +6862,6 @@ export class RequestManagementService {
},
metadata: {
accidentWay: fields.accidentWay,
advancedTo: WorkflowStep.WAITING_FOR_SIGNATURES,
},
} as any);
}
@@ -8300,6 +8369,7 @@ export class RequestManagementService {
targetPhone === request?.parties[0]?.person.phoneNumber
? "FIRST"
: "SECOND",
"v1",
);
await this.smsOrchestrationService.sendThirdPartyDamagedPartyClaimLinkNotice(
{
@@ -8814,9 +8884,10 @@ export class RequestManagementService {
},
}
: {}),
// V5 (isMadeByFileMaker): mark approval gate at claim creation so the flag
// is always present regardless of whether upload-video is called.
...((req as any).isMadeByFileMaker
// V5 only: propagate the approval gate from the blame record to the claim.
// isMadeByFileMaker is true for both V4 and V5; only V5 blame records also
// carry requiresFileMakerApproval=true (set at create time by the V5 controller).
...((req as any).requiresFileMakerApproval
? {
requiresFileMakerApproval: true,
fileMakerApprovalActorId: new Types.ObjectId(actor.sub),
@@ -9082,6 +9153,399 @@ export class RequestManagementService {
};
}
/**
* VIN variant of `runInquiriesV3`.
* Identical flow, but calls `getPolicyByChassisInquiry` instead of
* `getTejaratBlockInquiry` for the primary policy lookup.
*/
async runInquiriesVinV3(
requestId: string,
actor: any,
dto: RunInquiriesVinV3Dto,
): Promise<{
blameRequestId: string;
partyRole: PartyRole;
claimRequestId?: string;
claimPublicId?: string;
message: string;
}> {
const req = await this.blameRequestDbService.findById(requestId);
if (!req) throw new NotFoundException("Blame request not found");
this.assertBlameV3ExpertInPerson(req);
await this.verifyExpertAccessForBlameV2(req, actor);
const partyRole = this.resolveV3InquiryPartyRole(req);
if (!partyRole) {
throw new ConflictException("All party inquiries are already complete.");
}
if (partyRole === PartyRole.FIRST) {
const firstIdx = this.getPartyIndex(req, PartyRole.FIRST);
if (firstIdx === -1)
throw new BadRequestException("First party not found");
const firstParty = req.parties[firstIdx];
if (!firstParty?.person?.userId) {
throw new BadRequestException(
"Guilty party OTP must be verified before running inquiries.",
);
}
if (req.type === BlameRequestType.CAR_BODY) {
const form = firstParty.carBodyFirstForm as any;
if (form?.car == null && form?.object == null) {
throw new BadRequestException(
"Submit car-body-form before running inquiries (CAR_BODY).",
);
}
}
await this.runPartyInquiriesVinV3Internal(
req,
dto,
PartyRole.FIRST,
firstParty,
);
if (req.type === BlameRequestType.CAR_BODY) {
await this.validateShebaV3(
dto as any,
firstParty.person?.clientId?.toString(),
);
}
this.markPartyInquiriesCompleteOnBlame(req, PartyRole.FIRST, actor);
await (req as any).save();
const nationalCode =
dto.nationalCodeOfInsurer || dto.nationalCodeOfDriver || "";
const newClaim = await this.createV3ClaimFromBlame(req, actor, {
sheba: req.type === BlameRequestType.CAR_BODY ? dto.sheba : undefined,
nationalCode:
req.type === BlameRequestType.CAR_BODY ? nationalCode : undefined,
interimThirdParty: req.type === BlameRequestType.THIRD_PARTY,
});
return {
blameRequestId: requestId,
partyRole: PartyRole.FIRST,
claimRequestId: String(newClaim._id),
claimPublicId: req.publicId,
message:
"Guilty-party inquiries complete and claim created. Proceed with location, description, voice, and signature.",
};
}
// Damaged party (THIRD_PARTY only)
if (!this.partyHasSigned(req, PartyRole.FIRST)) {
throw new BadRequestException(
"Guilty party must sign before running damaged-party inquiries.",
);
}
const secondIdx = this.getPartyIndex(req, PartyRole.SECOND);
if (secondIdx === -1 || !req.parties[secondIdx]?.person?.userId) {
throw new BadRequestException(
"Damaged party OTP must be verified before running inquiries.",
);
}
const secondParty = req.parties[secondIdx];
const firstIdx = this.getPartyIndex(req, PartyRole.FIRST);
const firstUserId =
firstIdx !== -1 ? req.parties[firstIdx]?.person?.userId : null;
const secondUserId = secondParty.person?.userId;
if (
firstUserId &&
secondUserId &&
String(firstUserId) === String(secondUserId)
) {
throw new BadRequestException(
"Guilty and damaged parties are bound to the same user account. " +
"Re-verify the second party OTP using a different phone number.",
);
}
await this.runPartyInquiriesVinV3Internal(
req,
dto,
PartyRole.SECOND,
secondParty,
);
await this.validateShebaV3(
dto as any,
secondParty.person?.clientId?.toString(),
);
this.ensureV3GuiltyPartyDecision(req);
if (typeof (req as any).markModified === "function") {
(req as any).markModified("parties");
}
await (req as any).save();
await this.syncV3ClaimDamagedPartyFromBlame(req, dto as any);
this.markPartyInquiriesCompleteOnBlame(req, PartyRole.SECOND, actor);
await (req as any).save();
return {
blameRequestId: requestId,
partyRole: PartyRole.SECOND,
message:
"Damaged-party inquiries complete. Proceed with location, description, voice, and signature.",
};
}
/**
* VIN variant of `runPartyInquiriesV3Internal`.
* Calls `getPolicyByChassisInquiry` (ESG chassis lookup) instead of
* `getTejaratBlockInquiry` (plate-based). All other inquiries (personal,
* driving licence, car-body for CAR_BODY) are unchanged.
*/
private async runPartyInquiriesVinV3Internal(
req: any,
partyData: RunInquiriesVinV3Dto,
partyRole: PartyRole,
party: any,
): Promise<{ clientId?: string }> {
const roleLabel = partyRole === PartyRole.FIRST ? "FIRST" : "SECOND";
let clientId: string | undefined;
const inquiryOptions = (cid?: string) =>
cid ? { clientId: cid } : undefined;
let inquiryRaw: any;
let inquiryMapped: any;
try {
const inquiry = await this.sandHubService.getPolicyByChassisInquiry(
partyData.vin,
inquiryOptions(party?.person?.clientId?.toString()),
);
inquiryRaw = inquiry.raw;
inquiryMapped = inquiry.mapped;
this.recordPartyCaseInquiryStatus(req, "thirdParty", partyRole, true, {
source: "ESG_VIN_INQUIRY",
raw: inquiryRaw,
mapped: inquiryMapped,
});
} catch (err: any) {
this.logger.error(
`[V3-VIN] vin inquiry failed for ${roleLabel} party (request=${req._id}): ${err?.message || err}`,
);
this.recordPartyCaseInquiryStatus(
req,
"thirdParty",
partyRole,
false,
{},
err,
);
throw new BadRequestException(
`${roleLabel} party VIN inquiry failed: ${err?.message || "استعلام در دسترس نیست"}`,
);
}
if (inquiryMapped?.Error) {
throw new BadRequestException(
inquiryMapped.Error.Message ||
`${roleLabel} party VIN inquiry returned an error`,
);
}
const clientName = inquiryMapped?.CompanyName;
const companyCode = inquiryMapped?.CompanyCode;
if (!clientName) {
throw new BadRequestException(
`CompanyName missing from ${roleLabel} party VIN inquiry response`,
);
}
const client = await this.clientService.findOrCreateClientByCompanyCode(
companyCode,
clientName,
);
if (!client) {
throw new BadRequestException(
`CompanyCode missing or invalid in ${roleLabel} party VIN inquiry response`,
);
}
const resolvedClientId = (client as any)?._id ?? (client as any)?._doc?._id;
clientId = resolvedClientId ? String(resolvedClientId) : undefined;
if (!party.person) party.person = {} as any;
party.person.clientId = resolvedClientId;
party.person.nationalCodeOfInsurer = partyData.nationalCodeOfInsurer;
party.person.nationalCodeOfDriver = partyData.nationalCodeOfDriver;
party.person.driverIsInsurer = partyData.driverIsInsurer;
party.person.insurerBirthday = partyData.insurerBirthday;
party.person.driverBirthday =
partyData.driverBirthday ??
(partyData.driverIsInsurer ? String(partyData.insurerBirthday) : null);
if (partyData.insurerLicense)
party.person.insurerLicense = partyData.insurerLicense;
if (partyData.driverLicense)
party.person.driverLicense = partyData.driverLicense;
if (!party.vehicle) party.vehicle = {} as any;
party.vehicle.plateId = partyData.vin; // store VIN as vehicle identifier
party.vehicle.name = inquiryMapped?.MapTypNam;
party.vehicle.type = `${inquiryMapped?.UsageField ?? ""} / ${inquiryMapped?.UsageName ?? inquiryMapped?.MapUsageName ?? "-"}`;
party.vehicle.inquiry = {
source: "ESG_VIN_INQUIRY",
raw: inquiryRaw,
mapped: inquiryMapped,
};
if (!party.insurance) party.insurance = {} as any;
party.insurance.policyNumber = inquiryMapped?.PrntPlcyCmpDocNo;
party.insurance.company = clientName;
party.insurance.financialCeiling = inquiryMapped?.FinancialCvrCptl;
party.insurance.startDate = inquiryMapped?.IssueDate;
party.insurance.endDate = inquiryMapped?.EndDate;
if (
req.type === BlameRequestType.CAR_BODY &&
partyRole === PartyRole.FIRST
) {
try {
const carBodyInfo = await this.sandHubService.getTejaratCarBodyInquiry(
{
nationalCodeOfInsurer: partyData.nationalCodeOfInsurer,
plate: partyData.vin as any, // VIN used as identifier for CAR_BODY
},
clientId ? { clientId } : undefined,
);
this.recordPartyCaseInquiryStatus(req, "carBody", partyRole, true, {
source: "TEJARAT_CAR_BODY_VIN_INQUIRY",
raw: carBodyInfo.raw,
mapped: carBodyInfo.mapped,
});
party.vehicle.inquiry = {
...party.vehicle.inquiry,
carBody: {
source: "TEJARAT_CAR_BODY_VIN_INQUIRY",
raw: carBodyInfo.raw,
mapped: carBodyInfo.mapped,
},
};
const m = carBodyInfo.mapped;
(party.insurance as any).carBodyInsurance = {
policyNumber: m.policyNumber ?? null,
companyId: m.companyId ?? null,
companyName: m.CompanyName ?? null,
};
const cbCompanyCode = m.companyId ?? m.CompanyCode;
const cbCompanyName = m.CompanyName ?? m.companyPersianName;
if (cbCompanyCode && cbCompanyName) {
const cbClient =
await this.clientService.findOrCreateClientByCompanyCode(
Number(cbCompanyCode),
String(cbCompanyName),
);
const cbClientId =
(cbClient as any)?._id ?? (cbClient as any)?._doc?._id;
if (cbClientId) {
party.person.clientId = cbClientId;
clientId = String(cbClientId);
}
}
} catch (err: any) {
this.logger.error(
`[V3-VIN] car body inquiry failed for request=${req._id}: ${err?.message || err}`,
);
this.recordPartyCaseInquiryStatus(
req,
"carBody",
partyRole,
false,
{},
err,
);
throw new BadRequestException(
`CAR_BODY VIN inquiry failed: ${err?.message || "استعلام در دسترس نیست"}`,
);
}
}
const nationalCode =
partyData.nationalCodeOfInsurer || partyData.nationalCodeOfDriver;
const birthDate = partyData.insurerBirthday ?? partyData.driverBirthday;
if (nationalCode && birthDate != null) {
try {
const personalInquiry = await this.sandHubService.getPersonalInquiry(
nationalCode,
birthDate as string | number,
clientId ? { clientId } : undefined,
);
this.recordPartyCaseInquiryStatus(
req,
"person",
partyRole,
true,
personalInquiry,
);
} catch (err: any) {
this.logger.error(
`[V3-VIN] personal inquiry failed for ${roleLabel} party request=${req._id}: ${err?.message || err}`,
);
this.recordPartyCaseInquiryStatus(
req,
"person",
partyRole,
false,
{},
err,
);
throw new BadRequestException(
`${roleLabel} party personal identity inquiry failed: ${err?.message || "استعلام در دسترس نیست"}`,
);
}
}
const licenseNationalCode = partyData.driverIsInsurer
? partyData.nationalCodeOfInsurer
: partyData.nationalCodeOfDriver;
const licenseNumber = partyData.driverIsInsurer
? partyData.insurerLicense
: partyData.driverLicense;
if (!licenseNumber) {
this.recordPartyCaseInquiryStatus(
req,
"drivingLicence",
partyRole,
false,
{ skipped: true, reason: "No license number provided" },
);
} else {
try {
const licenseInquiry = await this.sandHubService.getDrivingLicenseInfo(
licenseNationalCode,
licenseNumber,
clientId ? { clientId } : undefined,
);
this.recordPartyCaseInquiryStatus(
req,
"drivingLicence",
partyRole,
true,
licenseInquiry,
);
} catch (err: any) {
this.logger.error(
`[V3-VIN] driving license inquiry failed for ${roleLabel} party request=${req._id}: ${err?.message || err}`,
);
this.recordPartyCaseInquiryStatus(
req,
"drivingLicence",
partyRole,
false,
{},
err,
);
throw new BadRequestException(
`${roleLabel} party driving license inquiry failed: ${err?.message || "استعلام در دسترس نیست"}`,
);
}
}
return { clientId };
}
private assertBlameV3PartyDetailPhase(req: any, partyRole: PartyRole): void {
this.assertBlameV3ExpertInPerson(req);
if (partyRole === PartyRole.FIRST) {
@@ -9222,12 +9686,11 @@ export class RequestManagementService {
fresh.workflow.currentStep = WorkflowStep.FIRST_INVITE_SECOND;
fresh.workflow.nextStep = WorkflowStep.SECOND_INITIAL_FORM;
} else {
// CAR_BODY: FileMaker is done — seal the file for FileReviewer pickup
// CAR_BODY: FileMaker's narrative is done — move to document-upload step.
// blame.status transitions to WAITING_FOR_FILE_REVIEWER only after the
// FileMaker completes all document uploads, not here at sign time.
fresh.workflow.currentStep = WorkflowStep.FIRST_COMPLETED;
fresh.workflow.nextStep = WorkflowStep.WAITING_FOR_GUILT_DECISION;
if (isFileMakerActor) {
fresh.status = CaseStatus.WAITING_FOR_FILE_REVIEWER;
}
}
} else {
this.pushWorkflowSteps(fresh, [
@@ -9239,10 +9702,8 @@ export class RequestManagementService {
]);
fresh.workflow.currentStep = WorkflowStep.SECOND_COMPLETED;
fresh.workflow.nextStep = WorkflowStep.WAITING_FOR_GUILT_DECISION;
// THIRD_PARTY: second party sign is FileMaker's last step — seal for FileReviewer
if (isFileMakerActor) {
fresh.status = CaseStatus.WAITING_FOR_FILE_REVIEWER;
}
// blame.status transitions to WAITING_FOR_FILE_REVIEWER only after the
// FileMaker completes all document uploads, not here at sign time.
}
await (fresh as any).save();
}
@@ -9305,16 +9766,26 @@ export class RequestManagementService {
},
};
if (typeof (req as any).markModified === "function") {
(req as any).markModified("expert");
}
if (!Array.isArray(req.history)) req.history = [];
req.history.push({
type: "V3_ACCIDENT_FIELDS_SAVED",
actor: {
actorId: new Types.ObjectId(String(expert.sub)),
actorName: `${expert.firstName || ""} ${expert.lastName || ""}`.trim(),
actorType: "field_expert",
},
metadata: { accidentWay: fields.accidentWay },
} as any);
// Avoid duplicate history entries on idempotent retries.
const alreadyRecorded = (req.history as any[]).some(
(e: any) => e?.type === "V3_ACCIDENT_FIELDS_SAVED",
);
if (!alreadyRecorded) {
req.history.push({
type: "V3_ACCIDENT_FIELDS_SAVED",
actor: {
actorId: new Types.ObjectId(String(expert.sub)),
actorName: `${expert.firstName || ""} ${expert.lastName || ""}`.trim(),
actorType: "field_expert",
},
metadata: { accidentWay: fields.accidentWay },
} as any);
}
await (req as any).save();
@@ -10012,4 +10483,251 @@ export class RequestManagementService {
);
}
}
// ── V6 call-center flow ────────────────────────────────────────────────
/**
* V6: Create a LINK blame file initiated by a call-center agent.
* Always LINK + CUSTOMER-filled (user fills the form after receiving the SMS).
* `skipInitialFormStep` is set so the user-side page skips the inquiry step
* (the agent already ran it via runCallCenterInquiryV6).
*/
async createCallCenterInitiatedBlameV6(
agent: any,
dto: { type: "THIRD_PARTY" | "CAR_BODY" },
): Promise<{ requestId: string; publicId: string }> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const agentId = new Types.ObjectId(agent.sub);
const type =
dto.type === "CAR_BODY"
? BlameRequestType.CAR_BODY
: BlameRequestType.THIRD_PARTY;
const firstStep = await this.getWorkflowStep({ stepNumber: 1 });
if (!firstStep?.stepKey) {
throw new InternalServerErrorException(
"Workflow stepNumber=1 not configured in step manager",
);
}
const nextStepFromManager = firstStep.nextPossibleSteps?.[0];
const nextStep =
type === BlameRequestType.CAR_BODY
? (WorkflowStep.CAR_BODY_ACCIDENT_TYPE as WorkflowStep)
: (nextStepFromManager as WorkflowStep);
if (!nextStep) {
throw new InternalServerErrorException(
"Workflow stepNumber=1 has no nextPossibleSteps configured",
);
}
const publicId = await this.publicIdService.generateRequestPublicId();
const created = await this.blameRequestDbService.create({
publicId,
requestNo: publicId,
type,
parties: [{ role: PartyRole.FIRST, person: {} }],
workflow: {
currentStep: firstStep.stepKey as WorkflowStep,
nextStep,
completedSteps: [firstStep.stepKey as WorkflowStep],
locked: false,
},
history: [],
callCenterInitiated: true,
initiatedByCallCenterId: agentId,
creationMethod: CreationMethod.LINK,
filledBy: FilledBy.CUSTOMER,
// User-side page should skip the inquiry/initial-form step
skipInitialFormStep: true,
});
const requestId = String((created as any)._id);
if (!Array.isArray((created as any).history)) (created as any).history = [];
(created as any).history.push({
type: "FILE_CREATED_BY_CALL_CENTER",
actor: {
actorId: agentId,
actorName: `${agent.firstName || ""} ${agent.lastName || ""}`.trim(),
actorType: RoleEnum.CALL_CENTER,
},
metadata: { creationMethod: CreationMethod.LINK, type: dto.type },
});
await (created as any).save();
return { requestId, publicId: (created as any).publicId };
}
/**
* V6: Run plate + personal inquiry for the guilty party on behalf of the caller.
* Stores the inquiry results on the blame's first party (same as V3 guilty-party path)
* but does NOT create a claim — the user will do that after filling the form via the link.
* Note: sheba is intentionally absent — the user provides their own IBAN later.
*/
async runCallCenterInquiryV6(
agent: any,
requestId: string,
dto: Omit<RunInquiriesV3Dto, "sheba">,
): Promise<{ blameRequestId: string; message: string }> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const req = await this.blameRequestDbService.findById(requestId);
if (!req) throw new NotFoundException("Blame request not found");
if (!req.callCenterInitiated || String(req.initiatedByCallCenterId) !== String(agent.sub)) {
throw new ForbiddenException("You can only access files that you have initiated.");
}
const firstIdx = this.getPartyIndex(req, PartyRole.FIRST);
if (firstIdx === -1) throw new BadRequestException("First party not found");
const firstParty = req.parties[firstIdx];
await this.runPartyInquiriesV3Internal(req, dto, PartyRole.FIRST, firstParty);
this.markPartyInquiriesCompleteOnBlame(req, PartyRole.FIRST, agent);
if (!Array.isArray((req as any).history)) (req as any).history = [];
(req as any).history.push({
type: "CALL_CENTER_INQUIRY_COMPLETED",
actor: {
actorId: new Types.ObjectId(agent.sub),
actorName: `${agent.firstName || ""} ${agent.lastName || ""}`.trim(),
actorType: RoleEnum.CALL_CENTER,
},
metadata: { partyRole: PartyRole.FIRST },
});
await (req as any).save();
return {
blameRequestId: requestId,
message: "Guilty-party inquiry complete. You can now send the blame link to the user.",
};
}
/**
* V6: Send the blame link to the guilty party's phone number.
* Registers/looks up the user by phone and stores them as the first party, then
* sends the SMS link so the user can fill in the rest of the form via the v2 flow.
*/
async sendCallCenterLinkV6(
agent: any,
requestId: string,
dto: { phoneNumber: string },
): Promise<{ sent: boolean; sentTo: { role: string; phoneNumber: string; smsSent: boolean; linkUrl: string }[] }> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const req = await this.blameRequestDbService.findById(requestId);
if (!req) throw new NotFoundException("Request not found");
if (!req.callCenterInitiated || String(req.initiatedByCallCenterId) !== String(agent.sub)) {
throw new ForbiddenException("You can only access files that you have initiated.");
}
if (!process.env.URL) {
throw new InternalServerErrorException("URL environment variable is not configured");
}
const phone = (dto?.phoneNumber || "").trim();
if (!phone) throw new BadRequestException("phoneNumber is required");
const firstIdx = this.getPartyIndex(req, PartyRole.FIRST);
if (firstIdx === -1) throw new BadRequestException("First party not found on request");
const userId = await this.getOrCreateUserByPhoneNumber(phone);
if (!req.parties[firstIdx].person) req.parties[firstIdx].person = {} as any;
req.parties[firstIdx].person.phoneNumber = normalizeIranMobile(phone) ?? phone;
req.parties[firstIdx].person.userId = userId;
const expertName = `${agent?.lastName || ""}`.trim() || "اپراتور";
const firstLink = this.smsOrchestrationService.buildBlamePartyLink(requestId, "FIRST", "v6");
const smsSent = await this.smsOrchestrationService.sendFieldExpertLink({
receptor: phone,
type: req.type,
expertLastName: expertName,
link: firstLink,
});
const sentTo = [{ role: PartyRole.FIRST, phoneNumber: phone, smsSent, linkUrl: firstLink }];
if (!Array.isArray((req as any).history)) (req as any).history = [];
(req as any).history.push({
type: "CALL_CENTER_LINK_SENT",
actor: {
actorId: new Types.ObjectId(agent.sub),
actorName: `${agent.firstName || ""} ${agent.lastName || ""}`.trim(),
actorType: RoleEnum.CALL_CENTER,
},
metadata: { sentTo },
});
await (req as any).save();
return { sent: smsSent, sentTo };
}
/**
* V6: Get a single blame file detail for the call-center agent who created it.
*/
async getCallCenterBlameDetailV6(agent: any, requestId: string): Promise<any> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const req = await this.blameRequestDbService.findById(requestId);
if (!req) throw new NotFoundException("Blame request not found");
if (!req.callCenterInitiated || String(req.initiatedByCallCenterId) !== String(agent.sub)) {
throw new ForbiddenException("You can only access files that you have initiated.");
}
return {
_id: (req as any)._id,
publicId: (req as any).publicId,
requestNo: (req as any).requestNo,
type: (req as any).type,
status: (req as any).status,
blameStatus: (req as any).blameStatus,
workflow: (req as any).workflow,
skipInitialFormStep: (req as any).skipInitialFormStep,
parties: ((req as any).parties ?? []).map((p: any) => ({
role: p.role,
person: {
phoneNumber: p.person?.phoneNumber,
nationalCodeOfInsurer: p.person?.nationalCodeOfInsurer,
clientId: p.person?.clientId,
},
insurance: p.insurance
? {
company: p.insurance.company,
policyNumber: p.insurance.policyNumber,
startDate: p.insurance.startDate,
endDate: p.insurance.endDate,
}
: undefined,
vehicle: p.vehicle
? { plateId: p.vehicle.plateId, name: p.vehicle.name }
: undefined,
})),
createdAt: (req as any).createdAt,
};
}
/**
* V6: List blame files created by this call-center agent.
*/
async getMyCallCenterFilesV6(agent: any): Promise<any[]> {
if (agent?.role !== RoleEnum.CALL_CENTER) {
throw new ForbiddenException("Only call-center agents can use this endpoint.");
}
const agentId = new Types.ObjectId(agent.sub);
const files = await this.blameRequestDbService.find({
callCenterInitiated: true,
initiatedByCallCenterId: agentId,
});
return (files || []).map((f: any) => ({
_id: f._id,
publicId: f.publicId,
requestNo: f.requestNo,
type: f.type,
status: f.status,
blameStatus: f.blameStatus,
workflow: f.workflow,
skipInitialFormStep: f.skipInitialFormStep,
createdAt: f.createdAt,
}));
}
}

View File

@@ -1,5 +1,7 @@
import { Module } from "@nestjs/common";
import { HttpModule } from "@nestjs/axios";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
import { MongooseModule } from "@nestjs/mongoose";
import { ClientModule } from "src/client/client.module";
import { SystemSettingsModule } from "src/system-settings/system-settings.module";
@@ -9,7 +11,11 @@ import { SandHubService } from "./sand-hub.service";
@Module({
imports: [
HttpModule,
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
SystemSettingsModule,
ClientModule,
MongooseModule.forFeature([

View File

@@ -81,5 +81,33 @@ describe("SandHubService inquiry mocks", () => {
expect(httpService.post).not.toHaveBeenCalled();
expect(result.mapped?.CompanyName).toBe("بیمه پارسیان");
expect(result.mapped?.CompanyCode).toBe("8");
// PrntPlcyCmpDocNo must be populated from the mock raw field
expect(result.mapped?.PrntPlcyCmpDocNo).toBe("1404/1143-70591/200/123");
});
it("maps printNumber → PrntPlcyCmpDocNo when raw response uses new field name", async () => {
// Simulate a real-API response where the policy number arrives as printNumber
const rawNewFormat = {
printNumber: "1405/1143-NEWAPI/200/1",
CompanyName: "بیمه آزمایشی",
CompanyCode: "99",
FinancialCvrCptl: "5000000000",
IssueDate: "1405/01/01",
EndDate: "1406/01/01",
};
const mapped = (service as any).mapNewApiResponseToOldFormat(rawNewFormat);
expect(mapped.PrntPlcyCmpDocNo).toBe("1405/1143-NEWAPI/200/1");
});
it("maps insuranceNumber → PrntPlcyCmpDocNo when raw response uses legacy field name", async () => {
const rawLegacy = {
insuranceNumber: "1405/1143-LEGACY/200/1",
CompanyName: "بیمه آزمایشی",
CompanyCode: "99",
};
const mapped = (service as any).mapNewApiResponseToOldFormat(rawLegacy);
expect(mapped.PrntPlcyCmpDocNo).toBe("1405/1143-LEGACY/200/1");
});
});

View File

@@ -1012,11 +1012,20 @@ export class SandHubService {
IssueDate: newResponse.persianStartDate || newResponse.IssueDate,
EndDate: newResponse.persianEndDate || newResponse.EndDate,
// Insurance policy number — canonical Tejarat name is PrntPlcyCmpDocNo;
// newer API formats surface it as printNumber or insuranceNumber.
PrntPlcyCmpDocNo:
newResponse.PrntPlcyCmpDocNo ||
newResponse.printNumber ||
newResponse.insuranceNumber ||
null,
// Insurance details
LastCompanyDocumentNumber:
newResponse.lastCompanyInsuranceNumber ||
newResponse.LastCompanyDocumentNumber ||
newResponse.insuranceNumber,
newResponse.insuranceNumber ||
null,
// Technical details
MtrNum: newResponse.MtrNum || newResponse.mtrnum,

View File

@@ -1,6 +1,7 @@
import { HttpModule } from "@nestjs/axios";
import { Module } from "@nestjs/common";
import { ConfigModule } from "@nestjs/config";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
import { KavenegarService } from "./kavenegar.service";
import { KavenegarSmsGateway } from "./kavenegar-sms.gateway";
@@ -8,7 +9,14 @@ import { ParsianSmsGateway } from "./parsian-sms.gateway";
import { SmsGatewayService } from "./sms-gateway.service";
@Module({
imports: [HttpModule, ConfigModule],
imports: [
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
ConfigModule,
],
providers: [
KavenegarService,
KavenegarSmsGateway,

View File

@@ -6,10 +6,16 @@ import { SmsGatewayModule } from "./provider/sms-gateway.module";
import { OtpGeneratorService } from "./otp-generator.service";
import { SmsOrchestrationService } from "./sms-orchestration.service";
import { HttpModule } from "@nestjs/axios";
import { ConfigModule, ConfigService } from "@nestjs/config";
import { createHttpModuleOptions } from "src/core/config/http-proxy.factory";
@Module({
imports: [
HttpModule,
HttpModule.registerAsync({
imports: [ConfigModule],
inject: [ConfigService],
useFactory: createHttpModuleOptions,
}),
SmsGatewayModule,
MongooseModule.forFeature([{ name: SmsText.name, schema: SmsTextSchema }]),
],

View File

@@ -37,20 +37,25 @@ export class SmsOrchestrationService implements OnModuleInit {
);
}
buildInviteLink(frontendRoute: string, requestId: string): string {
return `${process.env.URL}/${process.env.USER_BASE_PATH}/${frontendRoute}?token=${requestId}`;
buildInviteLink(
frontendRoute: string,
requestId: string,
versionPrefix: string,
): string {
return `${process.env.URL}/${versionPrefix}/${frontendRoute}?token=${requestId}`;
}
buildBlamePartyLink(
requestId: string,
partyRole: "FIRST" | "SECOND",
versionPrefix: string,
): string {
const route = partyRole === "SECOND" ? "user2" : "user";
return `${process.env.URL}/${process.env.USER_BASE_PATH}/${route}?token=${requestId}`;
return `${process.env.URL}/${versionPrefix}/${route}?token=${requestId}`;
}
buildClaimLink(claimRequestId: string): string {
return `${process.env.URL}/${process.env.USER_BASE_PATH}/caseClaim?token=${claimRequestId}`;
buildClaimLink(claimRequestId: string, versionPrefix: string): string {
return `${process.env.URL}/${versionPrefix}/caseClaim?token=${claimRequestId}`;
}
async sendInviteLink(

View File

@@ -74,3 +74,37 @@ export class CreateRegistrarAdminDto {
@IsNotEmpty()
clientId: string;
}
export class CreateCallCenterAgentDto {
@ApiProperty({ example: "agent@insurer.ir" })
@IsEmail()
email: string;
@ApiProperty({ example: "CallCenter@724" })
@IsString()
@IsNotEmpty()
password: string;
@ApiProperty({ example: "Sara" })
@IsString()
@IsNotEmpty()
firstName: string;
@ApiProperty({ example: "Hosseini" })
@IsString()
@IsNotEmpty()
lastName: string;
@ApiProperty({
example: "664a1b2c3d4e5f6789012345",
description: "Mongo ObjectId of the insurer client this agent belongs to.",
})
@IsString()
@IsNotEmpty()
clientId: string;
@ApiPropertyOptional({ example: "09121234567" })
@IsOptional()
@IsString()
mobile?: string;
}

View File

@@ -1,24 +1,32 @@
import {
BadRequestException,
Body,
Controller,
Get,
Param,
Patch,
Post,
Put,
Query,
UseGuards,
} from "@nestjs/common";
import {
ApiBearerAuth,
ApiBody,
ApiOperation,
ApiParam,
ApiQuery,
ApiResponse,
ApiTags,
} from "@nestjs/swagger";
import { Types } from "mongoose";
import { SuperAdminGuard } from "./guards/super-admin.guard";
import { SuperAdminService } from "./super-admin.service";
import {
CreateSuperAdminDto,
CreateFieldExpertAdminDto,
CreateRegistrarAdminDto,
CreateCallCenterAgentDto,
} from "./dto/super-admin.dto";
import { ClientDto } from "src/client/dto/create-client.dto";
import {
@@ -32,6 +40,20 @@ import {
UpdateSystemSettingsDto,
} from "src/system-settings/dto/system-settings.dto";
import { SetExternalInquiriesLiveDto } from "src/client/dto/external-inquiries-live.dto";
import { ExpertInsurerService } from "src/expert-insurer/expert-insurer.service";
import { ListQueryV2Dto } from "src/common/dto/list-query-v2.dto";
import {
UnifiedFileStatusReportDto,
UnifiedFileStatusReportQueryDto,
} from "src/common/dto/unified-file-status-report.dto";
import { CreateBranchDto } from "src/client/dto/create-branch.dto";
import { FileRating } from "src/request-management/entities/schema/request-management.schema";
import {
CreateBlameExpertByInsurerDto,
CreateClaimExpertByInsurerDto,
CreateFileMakerByInsurerDto,
CreateFileReviewerByInsurerDto,
} from "src/expert-insurer/dto/create-insurer-expert.dto";
@ApiTags("super-admin")
@ApiBearerAuth()
@@ -41,6 +63,7 @@ export class SuperAdminController {
constructor(
private readonly superAdminService: SuperAdminService,
private readonly systemSettingsService: SystemSettingsService,
private readonly expertInsurerService: ExpertInsurerService,
) {}
// ── Super-admin account management ───────────────────────────────────────
@@ -129,6 +152,13 @@ export class SuperAdminController {
return this.superAdminService.createRegistrar(body);
}
@Post("create-call-center-agent")
@ApiOperation({ summary: "Create a call-center agent for a given client" })
@ApiBody({ type: CreateCallCenterAgentDto })
createCallCenterAgent(@Body() body: CreateCallCenterAgentDto) {
return this.superAdminService.createCallCenterAgent(body);
}
// ── System settings ──────────────────────────────────────────────────────
@Get("system-settings")
@@ -159,4 +189,313 @@ export class SuperAdminController {
externalApis: { sandHubUseLiveApi: body?.enabled === true },
});
}
// ── Insurer panel (super-admin proxy) ────────────────────────────────────
@Get("insurer/branches")
@ApiOperation({ summary: "List branches for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
@ApiQuery({ name: "search", required: false, type: String })
@ApiQuery({ name: "from", required: false, description: "Optional start datetime (ISO string)" })
@ApiQuery({ name: "to", required: false, description: "Optional end datetime (ISO string)" })
@ApiQuery({ name: "isActive", required: false, description: "Filter active state (true/false)" })
getInsuranceBranches(
@Query("clientId") clientId: string,
@Query("search") search?: string,
@Query("from") from?: string,
@Query("to") to?: string,
@Query("isActive") isActive?: string,
) {
return this.expertInsurerService.retrieveInsuranceBranches(
clientId,
{ search, from, to, isActive },
);
}
@Post("insurer/branches")
@ApiOperation({ summary: "Add a branch for a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateBranchDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addBranch(
@Body("clientId") clientId: string,
@Body() createBranchDto: CreateBranchDto,
) {
return this.expertInsurerService.addBranch(clientId, createBranchDto);
}
@Put("insurer/branches/:branchId/status")
@ApiOperation({ summary: "Set branch active/inactive for a given client" })
@ApiParam({ name: "branchId" })
@ApiBody({
schema: {
type: "object",
properties: {
clientId: { type: "string", description: "Client ObjectId" },
isActive: { type: "boolean" },
},
required: ["clientId", "isActive"],
},
})
setBranchStatus(
@Param("branchId") branchId: string,
@Body("clientId") clientId: string,
@Body("isActive") isActive: unknown,
) {
let active: boolean;
if (typeof isActive === "boolean") {
active = isActive;
} else {
const normalized = String(isActive ?? "").trim().toLowerCase();
if (!["true", "false", "1", "0", "yes", "no"].includes(normalized)) {
throw new BadRequestException("isActive must be a boolean");
}
active = ["true", "1", "yes"].includes(normalized);
}
return this.expertInsurerService.setBranchActive(clientId, branchId, active);
}
@Post("insurer/experts/blame")
@ApiOperation({ summary: "Create a blame expert under a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateBlameExpertByInsurerDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addBlameExpert(
@Body("clientId") clientId: string,
@Body() body: CreateBlameExpertByInsurerDto,
) {
return this.expertInsurerService.addBlameExpert(clientId, body);
}
@Post("insurer/experts/claim")
@ApiOperation({ summary: "Create a claim expert under a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateClaimExpertByInsurerDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addClaimExpert(
@Body("clientId") clientId: string,
@Body() body: CreateClaimExpertByInsurerDto,
) {
return this.expertInsurerService.addClaimExpert(clientId, body);
}
@Post("insurer/experts/file-maker")
@ApiOperation({ summary: "Create a FileMaker account under a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateFileMakerByInsurerDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addFileMaker(
@Body("clientId") clientId: string,
@Body() body: CreateFileMakerByInsurerDto,
) {
return this.expertInsurerService.addFileMaker(clientId, body);
}
@Post("insurer/experts/file-reviewer")
@ApiOperation({ summary: "Create a FileReviewer account under a given client" })
@ApiBody({
schema: {
allOf: [
{ $ref: "#/components/schemas/CreateFileReviewerByInsurerDto" },
{
type: "object",
required: ["clientId"],
properties: { clientId: { type: "string", description: "Client ObjectId" } },
},
],
},
})
addFileReviewer(
@Body("clientId") clientId: string,
@Body() body: CreateFileReviewerByInsurerDto,
) {
return this.expertInsurerService.addFileReviewer(clientId, body);
}
@Get("insurer/experts/list")
@ApiOperation({ summary: "List all experts of a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
@ApiQuery({ name: "page", type: Number })
@ApiQuery({ name: "response_count", type: Number })
getAllExperts(
@Query("clientId") clientId: string,
@Query("page") page: number,
@Query("response_count") count: number,
) {
return this.expertInsurerService.retrieveAllExpertsOfClient(
{ clientKey: clientId },
page,
count,
);
}
@Get("insurer/experts/top")
@ApiOperation({ summary: "Top blame vs claim experts for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
getTopExperts(@Query("clientId") clientId: string) {
return this.expertInsurerService.getTopExpertsForClient({ clientKey: clientId });
}
@Get("insurer/files")
@ApiOperation({ summary: "List files (blame + claim merged) for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
getAllFiles(
@Query("clientId") clientId: string,
@Query() query: ListQueryV2Dto,
) {
return this.expertInsurerService.retrieveAllFilesOfClient(clientId, query);
}
@Get("insurer/report/unified-file-statuses")
@ApiOperation({ summary: "Unified file status catalog + counts for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
@ApiResponse({ status: 200, type: UnifiedFileStatusReportDto })
getUnifiedFileStatusReport(
@Query("clientId") clientId: string,
@Query() query: UnifiedFileStatusReportQueryDto,
): Promise<UnifiedFileStatusReportDto> {
return this.expertInsurerService.getInsurerUnifiedFileStatusReport(
{ clientKey: clientId },
query,
);
}
@Get("insurer/report/status-counts")
@ApiOperation({
summary: "Legacy status counts for a given client",
deprecated: true,
description: "Prefer GET insurer/report/unified-file-statuses.",
})
@ApiQuery({ name: "clientId", required: true, type: String })
@ApiQuery({ name: "from", required: false, description: "Optional start datetime (ISO string)" })
@ApiQuery({ name: "to", required: false, description: "Optional end datetime (ISO string)" })
getInsurerStatusReport(
@Query("clientId") clientId: string,
@Query("from") from?: string,
@Query("to") to?: string,
) {
return this.expertInsurerService.getInsurerFileStatusCounts(
{ clientKey: clientId },
from,
to,
);
}
@Get("insurer/files/:publicId/timeline")
@ApiOperation({ summary: "Activity timeline for a case of a given client" })
@ApiParam({ name: "publicId" })
@ApiQuery({ name: "clientId", required: true, type: String })
getFileTimeline(
@Query("clientId") clientId: string,
@Param("publicId") publicId: string,
) {
return this.expertInsurerService.getFileTimeline(clientId, publicId);
}
@Get("insurer/files/:publicId")
@ApiOperation({ summary: "File details by publicId for a given client" })
@ApiParam({ name: "publicId" })
@ApiQuery({ name: "clientId", required: true, type: String })
getFileDetailsByPublicId(
@Query("clientId") clientId: string,
@Param("publicId") publicId: string,
) {
return this.expertInsurerService.retrieveFileDetailsByPublicId(clientId, publicId);
}
// @Put("insurer/files/:publicId/rating")
// @ApiOperation({ summary: "Rate experts by publicId for a given client" })
// @ApiParam({ name: "publicId" })
// @ApiBody({
// schema: {
// type: "object",
// required: [
// "clientId",
// "collisionMethodAccuracy",
// "evaluationTimeliness",
// "accidentCauseAccuracy",
// "guiltyVehicleIdentification",
// "botRating",
// ],
// properties: {
// clientId: { type: "string", description: "Client ObjectId" },
// collisionMethodAccuracy: { type: "number", minimum: 0, maximum: 5 },
// evaluationTimeliness: { type: "number", minimum: 0, maximum: 5 },
// accidentCauseAccuracy: { type: "number", minimum: 0, maximum: 5 },
// guiltyVehicleIdentification: { type: "number", minimum: 0, maximum: 5 },
// botRating: { type: "number", minimum: 0, maximum: 5 },
// },
// },
// })
// rateExpertsByPublicId(
// @Param("publicId") publicId: string,
// @Body() body: FileRating & { clientId: string },
// ) {
// const { clientId, ...rating } = body;
// return this.expertInsurerService.rateExpertByPublicId(publicId, rating as FileRating, clientId);
// }
@Get("insurer/top-files")
@ApiOperation({ summary: "Top-rated files for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
getTopFiles(@Query("clientId") clientId: string) {
return this.expertInsurerService.getTopFilesForClient(clientId);
}
@Get("insurer/statistics")
@ApiOperation({ summary: "Expert statistics report for a given client" })
@ApiQuery({ name: "clientId", required: true, type: String })
getExpertStatistics(@Query("clientId") clientId: string) {
return this.expertInsurerService.getExpertStatisticsReport({ clientKey: clientId });
}
@Get("insurer/:expertId")
@ApiOperation({ summary: "Files handled by one roster expert for a given client" })
@ApiParam({ name: "expertId" })
@ApiQuery({ name: "clientId", required: true, type: String })
getExpertFiles(
@Query("clientId") clientId: string,
@Param("expertId") expertId: string,
) {
if (!Types.ObjectId.isValid(expertId)) {
throw new BadRequestException("Invalid expert ID");
}
return this.expertInsurerService.getAllFilesForInsurerExpert(expertId, clientId);
}
}

View File

@@ -3,6 +3,7 @@ import { ClientModule } from "src/client/client.module";
import { SystemSettingsModule } from "src/system-settings/system-settings.module";
import { HashModule } from "src/utils/hash/hash.module";
import { UsersModule } from "src/users/users.module";
import { ExpertInsurerModule } from "src/expert-insurer/expert-insurer.module";
import { SuperAdminController } from "./super-admin.controller";
import { SuperAdminService } from "./super-admin.service";
import { SuperAdminGuard } from "./guards/super-admin.guard";
@@ -26,6 +27,7 @@ import { SuperAdminGuard } from "./guards/super-admin.guard";
SystemSettingsModule,
HashModule,
UsersModule,
ExpertInsurerModule,
],
controllers: [SuperAdminController],
providers: [SuperAdminService, SuperAdminGuard],

View File

@@ -19,10 +19,12 @@ import {
CreateSuperAdminDto,
CreateFieldExpertAdminDto,
CreateRegistrarAdminDto,
CreateCallCenterAgentDto,
} from "./dto/super-admin.dto";
import { RoleEnum } from "src/Types&Enums/role.enum";
import { FieldExpertDbService } from "src/users/entities/db-service/field-expert.db.service";
import { RegistrarDbService } from "src/users/entities/db-service/registrar.db.service";
import { CallCenterAgentDbService } from "src/users/entities/db-service/call-center-agent.db.service";
@Injectable()
export class SuperAdminService {
@@ -33,6 +35,7 @@ export class SuperAdminService {
private readonly actorAuthService: ActorAuthService,
private readonly fieldExpertDbService: FieldExpertDbService,
private readonly registrarDbService: RegistrarDbService,
private readonly callCenterAgentDbService: CallCenterAgentDbService,
) {}
/** List all super-admin accounts (sans password). */
@@ -99,4 +102,28 @@ export class SuperAdminService {
async createRegistrar(body: CreateRegistrarAdminDto) {
return this.actorAuthService.createRegistrarMock(body);
}
async createCallCenterAgent(body: CreateCallCenterAgentDto) {
const email = body.email.toLowerCase().trim();
const existing = await this.callCenterAgentDbService.findOne({ email });
if (existing) {
throw new ConflictException(
"A call-center agent with this email already exists.",
);
}
const password = await this.hashService.hash(body.password);
const created = await this.callCenterAgentDbService.create({
email,
password,
firstName: body.firstName,
lastName: body.lastName,
clientKey: new Types.ObjectId(body.clientId),
mobile: body.mobile,
role: RoleEnum.CALL_CENTER,
});
const { password: _pw, ...rest } = (created as any).toObject
? (created as any).toObject()
: (created as any);
return rest;
}
}

View File

@@ -0,0 +1,50 @@
import { Injectable } from "@nestjs/common";
import { InjectModel } from "@nestjs/mongoose";
import { FilterQuery, Model, Types } from "mongoose";
import { CallCenterAgentModel } from "../schema/call-center-agent.schema";
@Injectable()
export class CallCenterAgentDbService {
constructor(
@InjectModel(CallCenterAgentModel.name)
private readonly model: Model<CallCenterAgentModel>,
) {}
async create(
data: Partial<CallCenterAgentModel> & { password: string },
): Promise<CallCenterAgentModel> {
return this.model.create(data);
}
async findOne(
filter: FilterQuery<CallCenterAgentModel>,
): Promise<CallCenterAgentModel | null> {
return this.model.findOne(filter);
}
async findById(id: string): Promise<CallCenterAgentModel | null> {
return this.model.findOne({ _id: new Types.ObjectId(id) });
}
async findByLoginIdentifier(
identifier: string,
): Promise<CallCenterAgentModel | null> {
const id = identifier.trim();
const or: FilterQuery<CallCenterAgentModel>[] = [
{ email: id },
{ username: id },
];
if (/^\d{10}$/.test(id)) {
or.push({ nationalCode: id });
}
return this.model.findOne({ $or: or });
}
async findAll(
filter: FilterQuery<CallCenterAgentModel>,
): Promise<(CallCenterAgentModel & { _id: Types.ObjectId })[]> {
return this.model.find(filter).lean() as Promise<
(CallCenterAgentModel & { _id: Types.ObjectId })[]
>;
}
}

View File

@@ -0,0 +1,61 @@
import { Prop, Schema, SchemaFactory } from "@nestjs/mongoose";
import { Types } from "mongoose";
import { RoleEnum } from "src/Types&Enums/role.enum";
/**
* Call-center agent actor. Works under an insurance company (clientKey) and
* can start V6 LINK blame files on behalf of callers.
*/
@Schema({
collection: "call-center-agents",
versionKey: false,
timestamps: true,
})
export class CallCenterAgentModel {
_id?: Types.ObjectId;
@Prop({ required: true })
firstName: string;
@Prop({ required: true })
lastName: string;
@Prop({ type: String, unique: true, sparse: true, required: false })
email?: string;
@Prop({ type: String })
username?: string;
@Prop({ type: String, index: true, sparse: true })
nationalCode?: string;
@Prop({ type: Types.ObjectId, index: true })
clientKey?: Types.ObjectId;
@Prop({ required: true })
password: string;
@Prop({ required: false })
mobile?: string;
@Prop({ required: false })
phone?: string;
@Prop({ default: RoleEnum.CALL_CENTER })
role: RoleEnum;
@Prop({ type: "string", default: "" })
otp: string;
createdAt: Date;
}
export const CallCenterAgentDbSchema =
SchemaFactory.createForClass(CallCenterAgentModel);
CallCenterAgentDbSchema.pre("save", function (next) {
if (!this.username) {
this.username = (this as any).email || (this as any).nationalCode;
}
next();
});

View File

@@ -11,6 +11,7 @@ import { UserDbService } from "./entities/db-service/user.db.service";
import { ExpertFileActivityDbService } from "./entities/db-service/expert-file-activity.db.service";
import { FileMakerDbService } from "./entities/db-service/file-maker.db.service";
import { FileReviewerDbService } from "./entities/db-service/file-reviewer.db.service";
import { CallCenterAgentDbService } from "./entities/db-service/call-center-agent.db.service";
import {
DamageExpertDbSchema,
DamageExpertModel,
@@ -41,6 +42,10 @@ import {
FileReviewerDbSchema,
FileReviewerModel,
} from "./entities/schema/file-reviewer.schema";
import {
CallCenterAgentDbSchema,
CallCenterAgentModel,
} from "./entities/schema/call-center-agent.schema";
@Module({
imports: [
@@ -54,6 +59,7 @@ import {
{ name: ExpertFileActivity.name, schema: ExpertFileActivitySchema },
{ name: FileMakerModel.name, schema: FileMakerDbSchema },
{ name: FileReviewerModel.name, schema: FileReviewerDbSchema },
{ name: CallCenterAgentModel.name, schema: CallCenterAgentDbSchema },
]),
HashModule,
],
@@ -68,6 +74,7 @@ import {
ExpertFileActivityDbService,
FileMakerDbService,
FileReviewerDbService,
CallCenterAgentDbService,
],
exports: [
UserDbService,
@@ -79,6 +86,7 @@ import {
ExpertFileActivityDbService,
FileMakerDbService,
FileReviewerDbService,
CallCenterAgentDbService,
],
})
export class UsersModule {}