Skip to content
CAI
Software that uses CAICheck a score

aalmada/BookStore

58.3

Adequate · 21 September 2026

20k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

BookStore is a multi-tenant e-commerce platform built on .NET that manages the full lifecycle of books, authors, and sales. It provides a comprehensive API for administrative operations, user authentication, and order processing, supported by a Blazor web interface with real-time updates and localization. The system enforces strict data integrity through optimistic concurrency, tenant isolation, and automated cache invalidation.

How it got here

2025 — Initial project scaffolding and core feature implementation

16 changes.

This period marks the initial setup and structural foundation of the BookStore project, establishing the .NET 10-based architecture, CI/CD configurations, and core domain models. It introduces the primary API endpoints for order, tenant, and user management, alongside the frontend shell with multi-tenancy and role-based access controls. The work also includes the integration of external services like Azure Storage and Redis, and the enforcement of architectural patterns through custom Roslyn analyzers.

2026 — multi-tenancy and sales feature expansion

29 changes.

This period focused on implementing multi-tenancy security, sale scheduling, and shared domain models across the application. It also introduced client-side components for localization and theme selection, alongside extensive integration and unit test coverage for these new features.

Features

Add parallel API orchestrator scripts

Added two new Python scripts, \parallel\_api\_calls.py\ and \parallel\_api\_orchestrator.py\, which demonstrate concurrent HTTP request handling using \asyncio\ and \aiohttp\. The first script provides a semaphore-bounded parallel execution model, while the second offers a simpler concurrent fetch pattern with detailed result printing and timing metrics.

python · high confidence

Add shared UI components for language, currency, and theme selection

Users can now select their preferred language, currency, and visual theme directly from the application header. The new AllLanguageSelector, CurrencySelector, and ThemeSwitcher components provide interactive controls for localization, pricing display, and light/dark mode, each with tooltips and accessibility labels to improve usability.

src/BookStore.Web/Components/Shared · high confidence

Added domain event notification types for real-time updates

A new file, DomainEventNotifications.cs, introduces a comprehensive set of domain event notification records (e.g., BookCreated, AuthorUpdated, TenantCreated) that support real-time event streaming. These notifications enable clients to receive live updates for various entities, including books, authors, categories, publishers, users, and tenants.

src/BookStore.Shared/Notifications · high confidence

Added email notification handling and book sale badge component

Users can now receive email verification notifications via a new EmailHandlers class in the API service, which processes verification commands and sends emails using a template service. Additionally, the web application now displays a sale badge on book items, showing the discount percentage in a red chip component within the catalog view.

src/BookStore.ApiService/Handlers/Notifications, src/BookStore.Web/Components/Catalog · high confidence

Enforce architectural patterns with new Roslyn analyzers

The BookStore.ApiService.Analyzers project now includes a suite of Roslyn analyzers that enforce architectural and best-practice rules across the codebase. These analyzers validate that events and commands are immutable records in their respective namespaces, ensure aggregate Apply methods follow Marten conventions, enforce CQRS handler naming and static patterns for Wolverine, and promote modern C\# features like generic math and time-ordered GUIDs.

src/BookStore.ApiService.Analyzers · high confidence

Introduce Refit-based BookStore API client with automatic DI registration

The client library now uses Refit to generate strongly-typed HTTP clients for all API endpoints, replacing the previous manual HttpClient wrappers. The \BookStoreClientExtensions\ class provides \AddBookStoreClient\ to register all client interfaces (Books, Authors, Orders, Passkeys, etc.) with the DI container, along with a \BookStoreEventsService\ for Server-Sent Events. The setup includes a custom \BookStoreHeaderHandler\ for managing headers like Accept-Language and tenant context, an \ETagHelper\ for optimistic concurrency, and a dedicated error handler. DTOs are defined in \Contracts.cs\.

src/BookStore.Client · high confidence

Introduce configurable application settings and sale scheduling logic

The API service now supports configurable options for currencies, localization, and pagination, allowing administrators to define supported currencies, default and supported languages, and page size limits. Additionally, the system introduces a new sale scheduling capability, enabling users to schedule, manage, and cancel book discounts with automatic application and removal.

BookStore.ApiService · high confidence

Introduce reactive query management and domain event-driven cache invalidation

Added a new \ReactiveQuery\ service that manages data fetching, caching, and automatic invalidation based on server-sent domain events, similar to React's useQuery. This is paired with a \QueryInvalidationService\ that maps specific domain events (e.g., \BookUpdated\, \AuthorDeleted\) to cache keys, ensuring the UI stays in sync with backend changes. The implementation includes logging for query failures and cancellations, and integrates with the existing event system to trigger state updates.

src/BookStore.Web/Services · high confidence

Introduce shared models and DTOs for the bookstore domain

The application now includes a comprehensive set of shared models and Data Transfer Objects (DTOs) to support the bookstore's core features. This includes administrative DTOs for managing books, authors, categories, and publishers, as well as request and response models for user authentication, shopping cart operations, and order placement. The update also introduces pagination and sorting request models, error code definitions, and configuration DTOs for localization and currency settings, enabling the API and UI to interact with the backend using a consistent, strongly-typed contract.

src/BookStore.Shared/Models · high confidence

Introduce shared models and constants for multi-tenancy and sales

Adds new shared components to the \BookStore.Shared\ library to support multi-tenancy and sales management. Introduces \MultiTenancyConstants\ to centralize tenant ID handling with a default tenant alias, and adds \SaleDto\ as a record type for sales data transfer. These changes provide the necessary data structures and constants for the backend and frontend to maintain type safety and consistency.

src/BookStore.Shared · high confidence

Introduces new API endpoints for order management, tenant administration, and passkey authentication

The BookStore.ApiService now exposes endpoints for placing and retrieving orders, managing tenant configurations, and handling passkey-based authentication flows. Users can now place orders as an anonymous shopper or authenticated user, view their order history, and manage passkey credentials. Administrators gain access to endpoints for promoting/demoting users to admin roles, creating and updating tenant entities, and viewing scheduled sales. The API also provides configuration endpoints for localization and currency settings, and a real-time notification stream via Server-Sent Events (SSE).

src/BookStore.ApiService · high confidence

Introduces new authentication, account management, and order tracking pages

The application now includes dedicated pages for user authentication and account management: a Login page supporting both standard and Passkey-based sign-in, a Register page for new account creation, and a VerifyEmail page for email confirmation. Users can manage their security credentials via a new ManagePassword page (to set, change, or remove passwords) and a ManagePasskeys page (to register or delete passkeys). Additionally, a new Orders page allows authenticated users to view their purchase history, while the existing Counter and Weather demo pages have been removed.

src/BookStore.Web/Components/Pages · high confidence

New admin management interfaces for books, authors, categories, publishers, and sales

The admin panel now includes dedicated management pages and dialogs for books, authors, categories, publishers, and sales. Users can create, edit, and delete these entities through new UI components, with real-time updates via server-sent events and improved multi-language support for descriptions and names.

src/BookStore.Web/Components/Pages/Admin · high confidence

New client-side modules for cart, auth sync, browser info, cookies, and passkeys

Added five new JavaScript modules to the web root: anonymous-cart.js for managing an anonymous shopping cart in localStorage; auth-broadcast.js to synchronize authentication state across browser tabs using BroadcastChannel; browser-info.js to collect browser metadata; cookie-storage.js for secure cookie read/write operations; and passkeys.js to handle WebAuthn registration and login flows. These changes introduce new client-side capabilities for cart management, cross-tab auth synchronization, and passkey-based authentication.

src/BookStore.Web/wwwroot/js · high confidence

New data models for book sales, error handling, and partial dates

The BookStore.Shared layer introduces three new domain models: BookSale, which represents scheduled book sales with percentage discounts and time ranges; Error, a structured record for handling and categorizing errors with specific types like validation, not found, and conflict; and PartialDate, a flexible date representation that supports year-only, year-month, or full date formats, including JSON serialization and comparison logic.

BookStore.Shared · high confidence

Redesigned layout and navigation with multi-tenancy and role-based access

The application's layout has been completely overhauled to support multi-tenancy and role-based access control. The main layout now includes a header with tenant switching capabilities and a sidebar navigation menu that dynamically adjusts based on user roles. Specifically, the navigation menu now displays admin links for authors, publishers, categories, sales, books, users, and tenants, while also showing 'My Orders' for authenticated users and a shopping cart link that reflects the current user's state (server vs. anonymous). The login display component has been added to the header, providing user account management options for logged-in users and login/registration links for guests.

src/BookStore.Web/Components/Layout · high confidence

Repository initialization and structural setup for BookStore

The repository is initialized with the core project structure, including the solution file (BookStore.slnx) and a new .NET 10-based directory layout. Key configuration files are added: \.editorconfig\ enforces code style and analyzer rules (e.g., suppressing IDE0051 for Marten reflection), \Directory.Build.props\ sets global build properties, and \aspire.config.json\ configures the Aspire host. Additionally, agent guidance is introduced via \AGENTS.md\ and \DebugRefit.cs\ for client debugging, while \.copilotignore\ and \.gitignore\ are configured to manage indexing and version control exclusions.

(repo-wide) · high confidence

Behavioural changes

Add multi-tenancy security attribute and partial date JSON serialization

The application now supports multi-tenancy security by introducing the AllowAnonymousTenantAttribute, which allows public endpoints to bypass tenant restrictions. Additionally, the system adds support for serializing and deserializing PartialDate objects via a new JSON converter, enabling proper handling of nullable year, month, and day components in API payloads.

src/BookStore.Shared/Infrastructure · high confidence

AppHost expands orchestration to include Azure Storage, Redis, and configurable environment variables

The AppHost now provisions Azure Blob Storage (with a local Azurite emulator) and a Redis cache, which are referenced by the API service alongside the existing PostgreSQL database. The configuration has been updated to use a central ResourceNames class for all resource identifiers, and the host now reads environment variables (RateLimit\_\Disabled, Seeding\\Enabled, Email\\_DeliveryMethod) to conditionally apply settings to the API service. Additionally, the health check endpoint is now explicitly named and configured with display text and URL suffixes for both HTTP and HTTPS endpoints.

src/BookStore.AppHost · medium confidence

Enhanced author management with multi-language support and optimistic concurrency

The author handlers now support multi-language biographies, requiring validation of language codes and ensuring a default translation is present. The Create and Update operations now return detailed validation errors for invalid or missing translations. Additionally, the Update and SoftDelete operations now enforce optimistic concurrency control using ETags, preventing concurrent modifications. The Create operation also invalidates the author list cache upon success.

src/BookStore.ApiService/Handlers/Authors · high confidence

Enhanced book management with multi-language, multi-currency, and optimistic concurrency

The book handling logic has been significantly expanded to support multi-lingual descriptions, multi-currency pricing, and optimistic concurrency control via ETags. New handlers for book covers and pricing have been added, while existing handlers now enforce strict validation for language codes, translation completeness, and supported currencies. All book-related handlers now integrate with a hybrid cache for immediate invalidation upon updates, and cover uploads are tenant-isolated.

src/BookStore.ApiService/Handlers/Books · medium confidence

Enhanced validation, logging, and cache invalidation for category and publisher handlers

The Category and Publisher handlers now enforce stricter validation rules, including checking for invalid language codes and enforcing name length limits. Additionally, structured logging has been added to track key lifecycle events, and the handlers now automatically invalidate the relevant cache tags upon successful updates or deletions, ensuring data consistency.

src/BookStore.ApiService/Handlers/Categories · high confidence

Introduce MudBlazor theming and tenant-aware UI components

The application shell (App.razor) now loads the MudBlazor CSS/JS and includes scripts for authentication, passkeys, anonymous cart, and browser info. The Routes.razor component has been expanded to manage theme state, applying a dark/light mode that dynamically adapts to system preferences and tenant-specific primary colors. New imports in \_Imports.razor expose MudBlazor, shared models, and services to the component tree.

src/BookStore.Web/Components · high confidence

Introduce multi-tenancy, security hardening, and structured error handling in the web infrastructure

The web application now supports multi-tenancy, automatically injecting the current tenant ID into outgoing API requests via a new \TenantHeaderHandler\. To prevent circular dependencies, a \DefaultTenantAuthHandler\ ensures the system admin uses the default tenant's token. Security is strengthened by hardening forwarded header trust and using a shared constant for the SystemAdmin policy. Additionally, the application now enriches logs with browser and tenant context, and implements a robust \ProblemDetails\ parser to convert API exceptions into structured \Result\ types for better error handling.

src/BookStore.Web/Infrastructure · high confidence

Modernize web app startup and error handling

The BookStore.Web project has been updated to use C\# 12 features, including collection expressions and expression-bodied members, for improved code conciseness. Additionally, the application now supports dynamic localization and error handling via a new \ErrorLocalizationService\ and resource files, allowing users to see contextualized error messages. The startup configuration has been refactored to centralize HTTP header management and resilience policies, improving reliability and security for API calls.

src/BookStore.Web · high confidence

Refactor service defaults to use discard assignments

The service defaults configuration in \Extensions.cs\ has been refactored to use discard assignments (\\_ =\) for method calls that return values but whose results are not used, such as \ConfigureOpenTelemetry\, \AddDefaultHealthChecks\, and \AddServiceDiscovery\. This change improves code clarity by explicitly indicating that return values are intentionally ignored, while also adding a new \ResourceNames\ class to centralize resource and endpoint path constants.

src/BookStore.ServiceDefaults · high confidence

Shared validation logic for email, password, and tenant ID

The application now enforces stricter password requirements, requiring a minimum length of 12 characters along with uppercase, lowercase, digit, and special character constraints. Additionally, new shared validators have been introduced for email addresses and tenant IDs, ensuring consistent validation rules across the frontend and backend.

src/BookStore.Shared/Validation · high confidence

Visual updates to book cards and admin UI

The wwwroot/app.css stylesheet was updated to improve the visual presentation of the BookStore application. Book cards now feature a hover effect that lifts the card and adds a deeper shadow, while deleted books are visually marked with grayscale and reduced opacity. An optimistic update animation (pulse) was added for newly created items, and shared utility classes for font weights were introduced to support the admin management components.

src/BookStore.Web/wwwroot · high confidence

Test coverage

Add integration tests for the BlobStorageService; Add unit tests for domain projections; Added integration tests for anonymous cart merging; Added unit tests for API service command handlers; Added unit tests for BookSale, PartialDate, and PasswordValidator; Added unit tests for JWT and rate-limiting infrastructure; Added unit tests for JWT token generation and claims handling; Added unit tests for Roslyn analyzers and service handlers; Added unit tests for key UI components and services; Added unit tests for notification and passkey endpoint security configurations; Added unit tests for tenant isolation in MartenUserStore; Added unit tests for web application services; Added unit tests for web infrastructure components; Expanded integration test coverage for BookStore AppHost; New unit tests for API service aggregates and validation; Removed obsolete unit tests for book handlers.

Dependencies

Adopts central package management and updates Aspire dependencies

The project now uses a central package management file (Directory.Packages.props) to define versions for all NuGet packages, removing version numbers from individual .csproj files. Aspire dependencies are updated to version 13.2.4, and OpenTelemetry packages are upgraded to version 1.15.3/1.15.1. Additionally, the project structure is reorganized with new analyzers and test projects, and performance settings for garbage collection are configured for the API service.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 58 (-1.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 84 → 79 (-4.5)
  • Architecture 78 → 79 (+0.7)
  • Maturity 66 → 68 (+1.5)
  • Readiness 58 → 64 (+6.0)
  • Security 66 → 75 (+9.0)
  • Domain Modelling 53 (new)
  • Event-Driven 100 (new)
  • Accessibility 55 → 56 (+0.3)
  • Performance 71 → 71 (+0.0)

Resolved (41)

  • Bounded contexts not declared
  • Change coupling clique: AuthorAggregate.cs, BookAggregate.cs, CategoryAggregate.cs, PublisherAggregate.cs (src/BookStore.ApiService/Aggregates/AuthorAggregate.cs)
  • Change coupling clique: AuthorEndpoints.cs, BookEndpoints.cs, CategoryEndpoints.cs (src/BookStore.ApiService/Endpoints/AuthorEndpoints.cs)
  • Change coupling clique: AuthorHandlers.cs, CategoryHandlers.cs, PublisherHandlers.cs (src/BookStore.ApiService/Handlers/Authors/AuthorHandlers.cs)
  • Change coupling: AdminAuthorEndpoints.cs ↔ AdminPublisherEndpoints.cs (src/BookStore.ApiService/Endpoints/Admin/AdminAuthorEndpoints.cs)
  • Change coupling: AdminBookEndpoints.cs ↔ AdminPublisherEndpoints.cs (src/BookStore.ApiService/Endpoints/Admin/AdminBookEndpoints.cs)
  • Change coupling: AdminCategoryEndpoints.cs ↔ AdminPublisherEndpoints.cs (src/BookStore.ApiService/Endpoints/Admin/AdminCategoryEndpoints.cs)
  • Duplicated block (11 lines × 3) (src/BookStore.ApiService.Analyzers/Analyzers/AggregateRulesAnalyzer.cs)
  • Duplicated block (12 lines × 2) (src/BookStore.ApiService/Aggregates/BookAggregate.cs)
  • Duplicated block (12 lines × 3) (src/BookStore.ApiService/Projections/AuthorStatisticsProjection.cs)
  • Duplicated block (13 lines × 2) (src/BookStore.Web/Components/Pages/Register.razor)
  • Duplicated block (14 lines × 2) (src/BookStore.ApiService/Infrastructure/Notifications/NotificationService.cs)
  • Duplicated block (15 lines × 2) (src/BookStore.Web/Components/Pages/Register.razor)
  • Duplicated block (16 lines × 2) (src/BookStore.ApiService/Infrastructure/ETagHelper.cs)
  • Duplicated block (16 lines × 2) (src/BookStore.Web/Services/TenantService.cs)
  • Duplicated block (18 lines × 2) (src/BookStore.ApiService/Infrastructure/LocalizationHelper.cs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 21 more

New (137)

  • Change coupling clique: AuthorHandlers.cs, BookHandlers.cs, CategoryHandlers.cs, PublisherHandlers.cs (src/BookStore.ApiService/Handlers/Authors/AuthorHandlers.cs)
  • Change coupling: AdminBookEndpoints.cs ↔ Program.cs (src/BookStore.ApiService/Endpoints/Admin/AdminBookEndpoints.cs)
  • Change coupling: AuthorProjection.cs ↔ CategoryProjection.cs (src/BookStore.ApiService/Projections/AuthorProjection.cs)
  • Change coupling: BookAggregate.cs ↔ AdminBookEndpoints.cs (src/BookStore.ApiService/Aggregates/BookAggregate.cs)
  • Change coupling: BookEndpoints.cs ↔ CategoryEndpoints.cs (src/BookStore.ApiService/Endpoints/BookEndpoints.cs)
  • Change coupling: BookSearchProjection.cs ↔ CategoryProjection.cs (src/BookStore.ApiService/Projections/BookSearchProjection.cs)
  • Change coupling: DatabaseSeeder.cs ↔ Program.cs (src/BookStore.ApiService/Infrastructure/DatabaseSeeder.cs)
  • Change coupling: PasskeyEndpoints.cs ↔ MartenUserStore.cs (src/BookStore.ApiService/Endpoints/PasskeyEndpoints.cs)
  • Change-coupling hub: AuthorEndpoints.cs → BookEndpoints.cs, CategoryEndpoints.cs, PublisherEndpoints.cs, Program.cs (src/BookStore.ApiService/Endpoints/AuthorEndpoints.cs)
  • Change-coupling hub: PublisherEndpoints.cs → BookEndpoints.cs, CategoryEndpoints.cs, Program.cs (src/BookStore.ApiService/Endpoints/PublisherEndpoints.cs)
  • CommentedOutCode (src/BookStore.ServiceDefaults/Extensions.cs)
  • Documentation: no installation or build instructions (docs/index.md)
  • Documentation: no usage examples (docs/index.md)
  • Documentation: written for insiders (docs/guides/passkey-guide.md)
  • Documentation: written for insiders (docs/guides/performance-guide.md)
  • Documentation: written for insiders (docs/guides/production-scaling-guide.md)
  • Duplicated block (10 lines × 2) (src/BookStore.Web/Components/Pages/Admin/CreateAuthorDialog.razor)
  • Duplicated block (10 lines × 2) (src/BookStore.Web/Components/Pages/Admin/CreateCategoryDialog.razor)
  • Duplicated block (10–12 lines × 2) (src/BookStore.ApiService/Handlers/Books/BookPriceHandlers.cs)
  • Duplicated block (12 lines × 2) (src/BookStore.ApiService/Handlers/Books/BookPriceHandlers.cs)
  • …and 117 more

API surface

  • Unchanged — 15 HTTP endpoints

Architecture

  • Unchanged — 6 containers · 3 contexts · 1 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

aalmada/BookStore was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 79aabad177f47a179f0eaa3ae08738ec51c591f1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.