CARULY / TECHNICAL REPORT
Caruly — Ten Core Modules
Ten logical areas of the current application and their responsibilities.
Forms · Photos · Listings
Routing · Validation · Ownership
SQLite ↔ Private image files
Simplified request flow, not a complete dependency graph. Tech serves curated files through a separate read-only route.
1. Overview
Back to contents ↑These are logical responsibilities, not ten independent services or source files.
2. 1. Vehicle Entry
Back to contents ↑index.html accepts plate/state and matches the two demo plates to a fixed Toyota record. No external vehicle-data provider is connected.
3. 2. Seller Details
Back to contents ↑Basic Info, condition, phone-gated contact fields, and completion validation collect the draft. server.js/storage.js persist whitelisted details. Client validation is more detailed than the initial draft API validation.
4. 3. Estimate
Back to contents ↑A static $4,375 estimate and sales copy lead to Continue to Listing. This module does not calculate a market price or submit an offer.
5. 4. Demo Session
Back to contents ↑The verification modal and verify-demo endpoint accept the fixed demo code. verified_drafts enables same-browser return. The bearer cookie owns data; it does not prove a telephone identity.
6. 5. Vehicle Photo Collection
Back to contents ↑Twelve categories, including four tires; uploads, previews, removal, and completion counters. Backend files use UUID names and owner-scoped reads. Browser image decoding supplements backend signature checks.
7. 6. Damage Report
Back to contents ↑Eight categories, independent Yes/No answers, required photo per Yes, optional additional damage photo, all-No confirmation, and saved state. Completion is checked on the server.
8. 7. Self-Inspection
Back to contents ↑Twelve question groups, exclusive no-issues choices, condition, modifications, frame history, ownership and tires. Electrical and Transmission require descriptions. Modified vehicles require photos. Uneven tire condition exposes four individual selections. Notes are limited to 1,000 characters.
9. 8. Listing Progress
Back to contents ↑My Vehicles presents current details and two implemented completion groups out of four. Continue Listing resumes photos, damage, inspection, or the pending Documents step. The Documents and minimum-price groups are not yet completeable workflows.
10. 9. Storage And Operations
Back to contents ↑SQLite WAL, disk quota, raw file persistence, seven-day daily database backup retention, eight-day deleted-photo retention, health checks and Render deployment. Backups share the service disk; an independent recovery copy is still needed.
11. 10. Tech Library
Back to contents ↑A top-menu Tech link opens a curated manifest-based document collection. Text/Markdown, PDFs, common images and sandboxed HTML can be previewed. Other formats can be downloaded. Files must be explicitly registered by a maintainer; arbitrary server paths and seller photos are not exposed.
12. Common Contract
Back to contents ↑UI navigation does not itself authorize access. JSON APIs use the owning cookie, origin checks and per-operation validation. Changes to conditional inspection fields should be reflected in inspection.js, frontend gating, persistence tests and browser verification.
13. Sources And Maintenance
Back to contents ↑Prepared from the Caruly source tree and recorded development work on September 13, 2026. Reference report structure supplied by the owner. Update this snapshot when routes, schema, security, or deployment behavior changes. Do not copy unrelated project findings into this report.