Skip to content
CAI
Software that uses CAICheck a score

AdilsonFuxe/auth-microservice

48.9

Weak · 21 September 2026

1.5k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Node.js backend application built with TypeScript and Express, designed to manage user accounts and authentication. It implements a clean architecture with distinct layers for domain logic, data access, and HTTP interfaces, utilizing MongoDB for persistence and various adapters for security and email services. The system provides RESTful endpoints for user sign-up, sign-in, password management, and account retrieval, all supported by comprehensive unit and integration tests.

How it got here

2021 — TypeScript and Express infrastructure

30 changes.

This period focused on establishing the core application architecture by introducing TypeScript, Express, and Docker tooling. It involved building the foundational layers, including domain models, use-case interfaces, and repository implementations for MongoDB and email services. Additionally, comprehensive test coverage was added for validation, cryptography, and route handlers to ensure the new structure was robust.

2022 — Interface and data layer refactoring

5 changes.

The project underwent a significant architectural shift to a functional programming paradigm within the data layer, introducing new protocols and dependency injection for improved testability. This was accompanied by the creation of a new interface layer for authentication and account management, supported by comprehensive unit tests.

Features

Add TypeScript, Jest, and Docker tooling

The project now includes configuration files for TypeScript (tsconfig.json, tsconfig-build.json) and Jest (jest.config.ts, jest-integration-config.ts, jest-unit-config.ts, jest.setup.ts), along with ESLint and Prettier setup (.eslintrc.json, .prettierrc, .eslintignore). Additionally, a Dockerfile and docker-compose.yml are added to support containerized development and testing, and a .dockerignore file is created to optimize the build context.

(repo-wide) · high confidence

Add email validation via adapter

A new email validation capability is introduced through an adapter that wraps the external \validator\ library's \isEmail\ function, exposing it via the \EmailValidator\ protocol. This allows the application to validate email addresses using a standardized interface.

src/infra/validators · high confidence

Add interface layer for account management and authentication

The interface layer now includes controllers for sign-in, sign-up, sign-out, password reset, and account retrieval, along with an authentication middleware and supporting error and helper utilities. This provides the HTTP handling and validation logic for user authentication and account operations.

src/interface, test-suite/interface · high confidence

Added Express adapters for HTTP requests

New adapter files have been added to the \src/main/adapters\ directory to bridge the application's internal controllers with the Express web server. The \express-middleware-adapter.ts\ and \express-routes-adapter.ts\ files provide functions that translate incoming Express requests into the application's internal \HttpRequest\ format and map the resulting \HttpResponse\ back to Express responses. The \index.ts\ file exports the route adapter, making these integration points available for use in the application's entry point.

src/main/adapters · high confidence

Added new validation logic and protocols

Introduced new validation components including email, required field, and compare field validators, along with a validation composite to chain multiple validators. The email validator now uses an injected EmailValidator protocol to check validity, while the required field and compare field validators return specific error types (MissingParamError, InvalidParamError) when validation fails. A new EmailValidator protocol is defined to abstract email validation logic.

src/validation · high confidence

Added server entry point

A new server entry point has been added at src/main/server.ts. This file initializes the application by connecting to the MongoDB database and starting the HTTP server on the configured port, serving as the main execution entry for the application.

src/main · medium confidence

Automated pre-commit linting and pre-push testing via Husky

The project now uses Husky to automatically run linting on staged files before each commit and execute CI tests before each push. This ensures code quality and test coverage are enforced at the Git hook level, preventing unlinted or failing code from being committed or pushed.

.husky · high confidence

Centralized export of data usecases

A new barrel file at src/data/usecases/index.ts has been added to centralize the exports of all data usecases, including db-add-account, db-authentication, db-forgot-password, db-load-account-by-id, db-load-account-by-token, db-update-password, send-mail, db-load-account-by-email, and db-signout. This change simplifies imports for consumers of these usecases by providing a single entry point for the entire data layer.

src/data/usecases · high confidence

Initial Express application configuration and middleware setup

The application is now configured to use Express, with a central app entry point that registers body parsing, CORS, and content-type middlewares. Routes are mounted under the /api/v1 prefix, and authentication middleware is adapted for use within the application.

src/main/config · high confidence

Introduce Account domain model

A new AccountModel type has been added to the domain models, defining the structure for account data including fields for identity, credentials, and authentication tokens. This model is now exported from the models index for use across the application.

src/domain/models · high confidence

Introduce Mongoose-based MongoDB repository implementations

The MongoDB data access layer has been implemented using Mongoose, providing concrete repository classes for account management. This includes operations for adding accounts, loading accounts by email, ID, or access token, and updating access tokens and password reset tokens. The implementation also handles serializing Mongoose documents to plain JavaScript objects, ensuring consistent data shapes for the rest of the application.

src/infra/db · high confidence

Introduce NodeMailer adapter for sending emails

Added a new NodeMailer adapter implementation that configures an email transport using host, port, and authentication credentials, and uses it to send emails with specified subject, text, and recipient. This provides the underlying mechanism for remote email delivery within the infrastructure layer.

src/infra/remote · high confidence

Introduce cryptography adapters for password hashing, JWT, and access tokens

Added new adapter implementations for cryptographic operations: bcrypt-based password hashing and comparison, JWT encryption/decryption, and access token generation. These adapters implement the corresponding protocols to handle password hashing via bcrypt, JWT token creation and verification, and random access token generation, making these capabilities available for use in the application's authentication and security flows.

src/infra/cryptography · high confidence

Introduce dbSignout use-case for account sign-out

A new dbSignout use-case has been added to handle account sign-out operations. The implementation wraps a signoutRepository to perform the sign-out action for a given accountId, exposing a standardized interface for data-layer sign-out logic.

src/data/usecases/db-signout · medium confidence

Introduces functional use-case interfaces for account and authentication flows

The domain layer now exposes functional type definitions for core account and authentication operations, including add-account, authentication, forgot-password, load-account-by-email, load-account-by-id, load-account-by-token, send-mail, signout, and update-password. These interfaces standardize the input and output contracts for these use cases, enabling consistent integration with underlying repositories and services.

src/domain/usecases · high confidence

New account management routes

A new 'account-routes.ts' file has been added to define the API endpoints for user account management. The routes include POST /signup, POST /signin, GET /me, PATCH /forgot, PATCH /reset-password, and DELETE /signout, all wired to their respective controllers via the 'adaptRoute' adapter. This establishes the routing layer for authentication and account operations.

src/main/routes · high confidence

Architecture

Centralized factory pattern for controllers, middleware, and use cases

The application's dependency injection and object creation logic has been centralized into a new \src/main/factories\ directory. This change introduces factory functions for all primary controllers (signup, signin, forgot-password, reset-password, me, signout), the authentication middleware, and core use cases (authentication, account management, password reset, and email sending). By moving these instantiation steps into dedicated factory files, the codebase now uses a consistent, functional approach to wire up controllers and services, simplifying the entry points and making it easier to swap or mock dependencies for testing.

src/main/factories · high confidence

Behavioural changes

Centralized export of data protocol interfaces

A new index file at src/data/protocols/index.ts has been added to centralize the re-exports of cryptography, database, and remote protocol interfaces. This change consolidates the public API for data-layer protocols, allowing consumers to import all protocol types from a single entry point rather than importing from individual subdirectories.

src/data/protocols · high confidence

Centralized test mock implementations

A new file at test-suite/data/index.ts consolidates mock implementations for various repositories and services (such as AddAccountRepository, LoadAccountByEmailRepository, and RemoteSendMail) that were previously scattered or defined inline. This change provides a single, centralized location for these test utilities, making it easier for users to access and reuse these mocks across different test suites.

test-suite/data · high confidence

Introduced new database repository interfaces for account and authentication operations

Added a set of new repository interfaces in the \src/data/protocols/db\ directory to define the contracts for database operations. These include \AddAccountRepository\, \LoadAccountByEmailRepository\, \LoadAccountByIdRepository\, \LoadAccountByTokenRepository\, \SignoutRepository\, \UpdateAccessTokenRepository\, \UpdateForgotPasswordAccessTokenRepository\, and \UpdatePasswordRepository\. Each interface specifies the expected parameters and response types for their respective use cases, establishing a clear separation of concerns for data access. The \index.ts\ file was also created to export all these new repository types, making them available for dependency injection and implementation.

src/data/protocols/db · high confidence

Introduces functional programming patterns for data layer use cases and protocols

The data layer has been refactored to use functional programming paradigms, replacing previous object-oriented structures. This change introduces new functional types and protocols for cryptography (decrypt, encrypt, password hashing, access token generation), account loading (by email, ID, or token), authentication, password updates, and email sending. Each use case now relies on dependency injection via a 'Build' function that accepts a dependencies object, promoting testability and separation of concerns.

(repo-wide) · high confidence

Test coverage

Add mock validators for test suite validation; Added integration tests for main route handlers; Added mock account factory for domain tests; Added test coverage for cryptography adapters; Added test coverage for validation validators; Added test helper utilities for account and authentication mocking; Added tests for Mongoose account repositories; Added tests for NodeMailerAdapter; Added tests for body-parser, content-type, and CORS middlewares; Added tests for the email validator adapter; Added tests for validation factories; Added unit tests for data-layer use cases; Added unit tests for interface controllers and middleware.

Dependencies

Updated project dependencies and tooling configuration

The project's package.json and package-lock.json have been updated to include a comprehensive set of development and runtime dependencies. Runtime dependencies include bcrypt, express, jsonwebtoken, mongoose, nodemailer, and validator. Development dependencies have been added for testing (jest, supertest, mockdate), TypeScript compilation (typescript, ts-node, ts-jest), linting and formatting (eslint, prettier, husky, lint-staged), and type definitions. The Node.js engine requirement is set to 16.x.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 59 → 49 (-10.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (+0.3)
  • Architecture 90 → 69 (-21.7)
  • Maturity 49 → 49 (+0.0)
  • Readiness 54 → 36 (-17.4)
  • Security 68 → 65 (-3.2)

Resolved (56)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 36 more

New (107)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no licence statement (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 87 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

AdilsonFuxe/auth-microservice was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 29fa2287443736b1dac06dce7c55eb5178aedfc3 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.