Skip to content
CAI
Software that uses CAICheck a score

agungsptr/node-clean

56.5

Adequate · 21 September 2026

1.9k

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Node.js application that manages users and students through both HTTP (Express) and gRPC interfaces. It provides full CRUD operations and authentication capabilities, supported by a modular architecture that separates data access, use cases, and drivers. The codebase has been refactored to use a shared base for data access and headless use-case functions, with validation and error handling centralized in utility modules.

How it got here

2022 — User authentication and architecture refactoring

19 changes.

This period focused on implementing user authentication and refactoring the codebase's architecture. Key changes include adding user models, data access layers, and use cases for login/logout, alongside a broader refactor of the student module and removal of legacy controllers and routes.

2023 — Web and gRPC driver implementation

6 changes.

This period focused on implementing the web and gRPC drivers, establishing RESTful and gRPC interfaces for user and student management. The work included setting up middleware for authentication and request handling, creating controllers and routes, and adding scripts for database seeding and service startup.

Features

Add authentication middleware for web drivers

A new authentication middleware has been introduced in the web drivers layer. This middleware validates incoming requests by extracting the authorization header, decoding the JWT token, and verifying the user's credentials against the data access layer. If the token is missing, invalid, or the user cannot be found, an unauthorized response is returned; otherwise, the authenticated user's ID and username are attached to the request object for downstream use.

drivers/web/middlewares · high confidence

Add gRPC driver for user and student management

The application now includes a new gRPC driver that exposes a service for creating, finding, updating, and removing both Users and Students. This includes the protocol buffer definition (app.proto), the server implementation (index.js, controllers), and client-side examples (client-examples) demonstrating how to interact with the gRPC endpoints.

drivers/grpc · high confidence

Added startup and database seeding scripts

New shell scripts have been added to the \scripts\ directory to manage the application's startup process. \scripts/start.dev.sh\ now handles the development workflow by waiting for the MongoDB service to become available, running the database seed script (\db/seeds/index.js\), and then starting the Node.js service via PM2. A separate \scripts/start.sh\ script provides a streamlined production startup path that waits for the database and starts the service. The \scripts/wait-for-it.sh\ utility is also included to handle TCP port availability checks for the database connection.

scripts · high confidence

Implemented login and logout authentication use cases

Added new authentication use cases for login and logout. The login flow validates credentials using Joi, verifies the password, and returns a JWT token with an expiration time. The logout flow invalidates the user's session by updating their secret UUID. These changes introduce the core user authentication capabilities.

use-cases/auth · high confidence

Introduce base data-access module with standard CRUD operations

A new \base.js\ file has been added to the \data-access\ directory, providing a reusable \baseDataAccess\ factory. This module implements standard database operations including \findAll\ (with pagination support via limit/skip), \findOne\, \findOneBy\, \create\, \update\, \remove\, and \removeAll\. It integrates with existing utility functions for query building, error handling, and serialization, establishing a consistent pattern for data access across the application.

data-access · high confidence

Introduce student model with schema validation

The student model is now structured with a dedicated schema and validation layer. The \student.schema.js\ file defines the required fields (name, age, grade, perfect, createdBy, createdAt, updatedAt) using Joi, and the \student.js\ builder enforces these rules, throwing errors for invalid data types or missing required fields. This change ensures that student data is validated before processing, improving data integrity.

models/student, models/user · high confidence

Introduce user data access layer with credential retrieval and serialization

Added a new data-access module for users, providing CRUD operations and a dedicated method to retrieve user credentials (including password and secretUuid) for authentication purposes. The implementation includes a serializer for standard user data and unit tests covering creation, retrieval, updates, and deletion of users.

data-access/users · high confidence

Introduce user management use cases

Added new use-case modules for user operations: create, findOne, findAll, update, and remove. The findAll function now supports pagination and query filtering by id or username, while the update function automatically sets the updatedAt timestamp.

use-cases/users · medium confidence

New API routes for authentication, users, and students

The web driver now exposes RESTful endpoints for authentication (login/logout), as well as full CRUD operations (create, read, update, delete) for users and students. These routes are registered in the main router and include corresponding unit tests to verify the new API behavior.

drivers/web/routes · high confidence

New web controllers for authentication, student, and user management

The web controllers for authentication (login, logout), student management (create, findAll, findOne, update, remove), and user management (create, findAll, findOne, update, remove) have been added to the codebase. These controllers handle HTTP requests by delegating to the corresponding use cases, utilizing a shared response builder and error handling utilities. The findAll endpoints for students and users now support pagination via query parameters.

drivers/web/controllers · high confidence

Web driver initialization and middleware setup

The web driver now initializes the Express application with a standard set of middleware, including CORS, Helmet, body parsing, sanitization, compression, and rate limiting in production environments.

drivers/web · high confidence

Removals

Removal of models/validator module

The validation logic previously provided by the 'models/validator' module has been removed from the codebase. This module previously exported a function that validated payloads against a schema and returned error details or true. Users relying on this specific module path will no longer have access to this validation utility.

models/validator · high confidence

Removal of student model implementation and tests

The student model implementation, including the schema definition, builder function, and associated unit tests, has been removed from the codebase.

models/students · high confidence

Removal of students controller module

The students controller file has been deleted, removing the HTTP request handlers for creating, finding, and listing students. This eliminates the direct API endpoints for student management that were previously exposed through this controller.

controllers · high confidence

Behavioural changes

Expanded configuration for runtime, security, and services

The application now supports running both HTTP and gRPC services, with the gRPC driver and port exposed via environment variables. Security and environment handling have been enhanced by making the bcrypt salt configurable via the BYCRIPT\_SALT environment variable, and by exposing the JWT secret key and expiration duration. Additionally, rate limiting parameters (minute and max) are now configurable, and the configuration object now exposes the application port, environment-specific flags, and root path.

config · medium confidence

Refactor database connection and add configuration generator

The database connection module (db/connection.js) now uses configurable host and database name from the environment rather than hardcoded values, and explicitly sets Mongoose's strictQuery mode to false. Additionally, a new dbConfigGenerator.js script was added to generate MongoDB initialization scripts for user creation.

db · high confidence

Refactor database seeding to use modular seeders

The database seeding process has been refactored to use a modular structure. A new index.js file orchestrates the seeding by dropping all collections and then running separate seeders for users and students. The users seeder was added to insert a default user, while the students seeder was updated to link student records to this user via a createdBy field, and the seeding logic was changed from individual creates to insertMany for efficiency.

db/seeds · high confidence

Refactor student data access to use a shared base implementation

The student data-access module has been refactored to use a shared base data-access implementation, replacing the previous custom CRUD functions (findAll, findOne, create, remove, etc.) with a generic base class. This change introduces a 'createdBy' field to the student model and serializer, and updates the test suite to reflect the new API, including the addition of user creation in test setup and assertions for the new 'createdBy' property.

data-access/students · high confidence

Refactor student use cases to headless functions with pagination support

The student use cases (create, findOne, findAll, update, remove) have been refactored from Express middleware-style functions (receiving req, res, next) to headless functions that accept explicit arguments (payload, id, queries, limit, page). This change removes internal error handling and response formatting from the use cases, delegating to a new pagination builder for findAll, and introduces a new remove use case alongside the existing ones.

use-cases/students · high confidence

Refactored common utilities and error handling

The \helper.js\ module was removed, with its functionality (logging, password hashing) moved to \utils.js\ and \errors.js\. Validation and utility functions in \checks.js\ were renamed to lowercase (e.g., \isEmpty\), and a new \isValidObjId\ check was added. The \constants.js\ file was expanded to include \StatusCode\ and \ResponseMessage\ maps. The \errors.js\ module was updated to use the new \responseBuilder\ utility for consistent API responses, and the \CustomError\ class was modified to store error details in a \list\ property.

commons · high confidence

Removal of legacy Express server implementation

The file \drivers/server.js\ has been deleted, removing the previous Express-based server setup that handled middleware (body parser, compression, logging) and route mounting. This eliminates the old server entry point, likely as part of a broader architectural shift to a different server configuration or framework.

drivers · high confidence

Removed legacy student route definitions

The application's routing structure has been simplified by removing the previous student route configuration. Specifically, the main router file (routes/index.js) and the dedicated student route file (routes/students.route.js) have been deleted. This removes the previous GET (findAll, findOne) and POST (create) endpoints for students, indicating a shift in how student data is accessed or managed within the application.

routes · medium confidence

User model introduces password hashing and unique identifiers

The new Users model enforces password hashing on save and includes a secret UUID, along with createdAt and updatedAt timestamps. The Students model was updated to include createdBy, createdAt, and updatedAt fields, and a typo fix changed the 'prefect' field to 'perfect'.

db/models · high confidence

Test coverage

Added load testing and test setup infrastructure

Added a new load test configuration (test/loadTest.yml) that simulates warming up, ramping up, and sustained load scenarios against the /api endpoints, including a sign-up flow that authenticates and accesses /users. Additionally, a test setup module (test/setup.js) was introduced to configure an Express application with JSON and URL-encoded body parsers and the web routes, providing a reusable foundation for running these tests.

test · high confidence

Dependencies

Updated project dependencies and configuration

The project's dependencies have been updated to newer versions, including axios (1.2.2 to 1.4.0), mongoose (6.6.2 to 7.3.4), and eslint (8.25.0 to 8.39.0). Additionally, the package.json has been updated with new scripts for gRPC and load testing, and the project name was changed from 'nodejs-clean-arch' to 'node-clean'.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 58 → 56 (-1.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 58 → 58 (+0.2)
  • Architecture 100 → 83 (-16.6)
  • Maturity 47 → 47 (+0.0)
  • Readiness 75 → 65 (-9.9)
  • Security 66 → 76 (+10.2)

Resolved (61)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • …and 41 more

New (127)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • …and 107 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

agungsptr/node-clean was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1d4ce1a4ea4c8ae1d74be03948b2ff0de212d9f4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.