ahaodev/shadmin
58.4
Adequate · 7 October 2026
14k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is an administrative platform, Shadmin, designed for managing users, roles, departments, and system configurations through a web interface and a read-only CLI tool. It supports secure authentication via local credentials, OAuth 2.0 device authorization, and third-party providers like Google and GitHub, backed by a unified caching layer and strict authorization controls. The platform provides comprehensive CRUD capabilities for organizational entities and system resources, while explicitly excluding features such as user registration, password recovery, and write operations in the CLI.
Features
Added device activation flow and reorganized frontend directory structure
Users can now activate devices via a new Device Activate page that accepts an 8-character authorization code, validates the input format, and submits it to the backend via a React Query mutation, providing success or error feedback through toast notifications. This feature is implemented in the new \frontend/src/features/auth/device-activate\ directory, which includes the main layout, the activation form component, and the associated data hook. Additionally, several existing authentication and error-handling components (such as the OTP form and various error pages) have been moved from the \web/src\ directory to \frontend/src\, reflecting a structural reorganization of the frontend codebase.
(repo-wide) · high confidence
Added sliding puzzle CAPTCHA verification
The application now includes a sliding puzzle CAPTCHA for login security. This change introduces a new \SlideManager\ component that generates slide challenges using the \go-captcha\ library and persists challenge state (coordinates, expiration, attempt count) via the unified \cacher\ interface, allowing the system to validate user input against stored server-side state.
internal/captcha · high confidence
Expanded API capabilities with device auth, social login, and department management
The API surface has been significantly extended to support new authentication flows and administrative features. Users can now authenticate devices via a dedicated device authorization flow (requesting and polling for tokens) and log in using third-party identity providers (Google/GitHub) through new OAuth endpoints. A new department management module has been added to the system administration routes, allowing for the creation, retrieval, and modification of organizational units. Additionally, a public health check endpoint is now available, and the application now enforces user state checks via middleware on protected routes. The maximum memory limit for multipart form uploads has also been increased to 1 GB.
api/route · high confidence
Expanded user model and new authorization schemas
The data model for user management has been significantly expanded to support third-party authentication and organizational structure. The User entity now tracks the authentication source (local, GitHub, or Google), allowing email uniqueness per source rather than globally, and includes fields for nickname, avatar, bio, and department association. New schemas have been introduced to support these capabilities: Department for hierarchical team structures, UserIdentity for linking third-party provider accounts, UserInvitation for secure one-time invite tokens, DeviceAuthSession for OAuth 2.0 device authorization flows, and AuthzState for tracking authorization data projections. Additionally, the Role entity now distinguishes system-built-in roles, and login logs have been refactored to record the login source and use email instead of username.
shadmin · high confidence
Introduce Shadmin CLI with device-auth login and read-only resource commands
The CLI tool is now available in the \cli/cmd\ package, providing a \login\ command that authenticates via the OAuth 2.0 device authorization flow (polling for a device code and user code) and stores the resulting tokens. It includes \logout\ to clear local credentials and \whoami\ to display the current user profile. Additionally, it introduces read-only resource management commands for \users\, \roles\, and \menus\, supporting pagination and keyword filtering where applicable, with output formatted as JSON by default or human-readable tables via the \--pretty\ flag.
cli/cmd · high confidence
Introduce shadmin-cli with OAuth device auth and secure config management
The CLI tool now supports OAuth 2.0 device authorization flow, allowing users to authenticate via a verification URI and user code. It includes a robust HTTP client that automatically handles token refresh on 401 errors and persists credentials securely in a local .env file with 0600 permissions. Configuration can be overridden via the SHADMIN\_SERVER environment variable or the --server flag without permanently overwriting the disk file, and the output supports both JSON and pretty-printed formats.
cli/internal · high confidence
Introduce shadmin-cli, a read-only Go CLI for Shadmin
A new standalone Go CLI (\shadmin-cli\) is added in the \cli/\ directory, providing a read-only interface to the Shadmin REST API designed for both human operators and external AI agents. It supports OAuth device authorization for login, caches JWTs in a secure local config file, and exposes commands to list and retrieve users, roles, menus, and API resources. The tool defaults to JSON output for machine consumption (with a \--pretty\ flag for human-readable tables) and enforces the same RBAC permissions as the web frontend, ensuring no write operations are possible in this initial release.
cli · high confidence
New OAuth callback page handles identity code exchange and session setup
A new OAuth callback component has been added to handle the completion of third-party logins. When a user is redirected back with an authorization code, this page exchanges it for access and refresh tokens via the backend, updates the local authentication store, fetches the user profile, and reloads the application menu data before navigating to the home page. It also includes logic to deduplicate concurrent exchange requests and handles errors by redirecting back to the sign-in page.
frontend/src/features/auth/oauth-callback · high confidence
New authentication security and caching infrastructure
This change introduces several new internal components to the auth module: a JWT blacklist for revoking tokens, a login security manager that tracks and locks failed login attempts using a shared cache, a store for OAuth identity codes, and a user status cache to handle disabled accounts. These additions shift authentication logic from in-memory or self-managed state to a shared caching layer, improving security and consistency.
internal/auth · high confidence
New authentication, department, and device APIs with refactored controller layer
The API controller layer introduces several new capabilities and refactors existing ones. New endpoints include a slide captcha challenge for login security, a full department management API (list, tree, CRUD), and a device authorization flow for CLI login (request code, poll token, activate). OAuth identity login is now supported via a new controller handling provider redirects, callbacks, and code exchange. Existing controllers have been refactored to use a unified \BindQueryParams\ helper for pagination and a \MustBindJSON\ helper for body binding, and the \search\ query parameter has been renamed to \keyword\ across dict, menu, and user endpoints. The login controller has been simplified to delegate security logic (locking, captcha, logging) to the use case layer, and the resource controller now delegates to a use case instead of manually collecting permissions from repositories. Additionally, the login log filter has changed from \username\ to \email\, and several controllers have updated their dependency injection to use \conf.Env\ instead of \bootstrap.Env\.
api/controller · high confidence
New department and user management interfaces with unified CRUD infrastructure
The frontend now includes dedicated management pages for departments and users, featuring hierarchical department trees with expandable rows, user lists with role assignment, and full create/edit/delete workflows. These features are powered by a new generic \useCrudMutation\ hook that standardizes API calls, query invalidation, and toast notifications across the application. Additionally, a Go backend handler (\frontend.go\) has been added to serve the static frontend build and implement Single Page Application (SPA) routing fallbacks, while a \pnpm-workspace.yaml\ file configures build allowances for specific dependencies like Tailwind CSS and React Hook Form.
frontend · high confidence
New department management, device authentication, and third-party identity use cases; refactored login and resource access
The usecase layer now includes new capabilities for managing organizational departments (create, update, delete with circular-reference and active-child checks), device-based authentication (OAuth 2.0 Device Authorization flow with code generation, polling, and token issuance), and third-party identity login (OIDC/callback handling that resolves or creates isolated users and issues JWTs). Existing login behavior has changed to require slide-captcha verification, enforce account-status checks, block password login for third-party accounts, and use a shared security manager for lockout tracking; token refresh now rotates and blacklists old refresh tokens, and logout revokes tokens. Resource access now filters menus and button permissions by user roles with batched lookups. Several use cases (dict, menu, role, user) removed direct ent.Client dependencies in favor of domain repositories, standardized status constants, protected system roles from deletion/renaming, and added admin-edit protections for user profiles.
usecase · high confidence
New hooks for identity providers and slide captcha
The sign-in flow now uses dedicated React Query and state hooks to manage authentication prerequisites. The new useIdentityProviders hook fetches the list of available identity providers via the auth API, caching the result for five minutes. The new useSlideCaptcha hook manages the lifecycle of a slide-based CAPTCHA, including fetching challenges, handling expiration timers, and exposing methods to reset or refresh the verification state.
frontend/src/features/auth/sign-in/hooks · high confidence
New unified caching abstraction with Redis and memory backends
The internal/cacher package introduces a new Cacher interface that provides a unified key-value cache with namespace support, allowing the application to switch between a Redis backend and an in-memory backend at runtime. This abstraction includes atomic increment operations (Incr) for use cases like login failure counting, ensuring accurate counters in concurrent scenarios, and atomic get-and-delete (GetAndDelete) for one-time token semantics. The Redis implementation leverages Lua scripts for atomic increments with TTL refresh and uses GETDEL for atomic retrieval and deletion, while the memory implementation uses mutexes to guarantee atomicity for these operations within a single process.
internal/cacher · high confidence
New user management interface with role-based access and department assignment
The system introduces a comprehensive user management interface in the frontend, replacing the previous web-specific implementation. Administrators can now invite new users via email with specific role assignments, and add or edit existing users with the ability to assign them to specific departments using a hierarchical department tree. The interface enforces role-based access control, hiding add, edit, and delete actions based on user permissions, and prevents modification of admin accounts. Bulk operations are supported, including multi-select deletion with confirmation and a placeholder for future bulk invites. The user table displays detailed information including username, nickname, email, source, phone, roles, department, and status, with filtering and sorting capabilities.
frontend/src/features/system/users/components · high confidence
User invitation acceptance flow and email delivery
Users can now accept an invitation to join the platform by setting a username and password via a new frontend page at /accept-invitation, which validates the input and calls the backend API. To support this, the system now sends invitation emails using the Resend service, including an HTML template with the acceptance link and any optional invitation message, with proper HTML escaping for safety.
frontend/src/features/auth/accept-invitation, internal/mailer · high confidence
Removals
Removal of legacy authentication store
The legacy \auth-store.ts\ file has been deleted from the application. This store previously managed user sessions, JWT token handling, profile fetching, and permission checks using Zustand. Its removal indicates a migration to a new authentication mechanism or state management structure elsewhere in the codebase.
web/src/stores · high confidence
Removal of legacy custom React hooks
The custom hooks use-dialog-state, use-mobile, use-sidebar-data, and usePermission have been removed from the web application. This eliminates the local implementations for managing confirm dialog state, detecting mobile viewport breakpoints, loading and caching dynamic sidebar navigation data based on user identity, and handling role/permission checks with wildcard support. Users will no longer interact with these specific hook-based logic paths, which are presumably replaced by updated components or services elsewhere in the application.
web/src/hooks · high confidence
Removal of legacy frontend service layer and permission components
The application has removed the legacy frontend service layer and associated permission components. This includes the deletion of the \web/src/services\ directory, which contained API client wrappers for authentication, menus, roles, users, dictionaries, and other system resources, as well as the \PermissionButton\ and \PermissionGuard\ components used for UI-level access control. Users will no longer have access to the previous manual API integration and permission-checking UI patterns, as these have been replaced by the current architecture.
web/src/services · high confidence
Removal of legacy schema, security manager, and web assets
This change removes several components from the codebase: the \CasbinRule\ entity schema definition in \ent/schema\, the \LoginSecurityManager\ (including login attempt tracking and locking logic) in \internal/login\_security.go\, and a set of brand icon components (Medium, Notion, Skype, Slack, Trello, Zoom) along with the core web styling files (\index.css\ and \theme.css\) in the \web/src\ directory.
(repo-wide) · high confidence
Removal of legacy utility and adapter modules
Deleted several files from the \web/src/lib\ directory, including \backend-menu-adapter.ts\, \cookies.ts\, \error.ts\, \menu-utils.ts\, \time.ts\, and \utils.ts\. This removes the previous implementations for backend menu transformation, manual cookie management, error message extraction, menu hierarchy building, date/time formatting, and UI utility functions (such as class merging and pagination logic), indicating these capabilities have been replaced or refactored elsewhere in the application.
web/src/lib · high confidence
Removal of the Apps integration demo page
The Apps integration demo page, located at the /\_authenticated/apps/ route, has been removed from the application. This change deletes the \Apps\ component and its associated data source (\apps.tsx\), eliminating the user-facing interface that previously displayed a list of integrations (such as Telegram, Notion, and Slack) with capabilities to search, filter by connection status, and sort the available services.
web/src/features/apps, web/src/features/apps/data · high confidence
Removal of the legacy Users management feature
The entire Users management feature located in web/src/features/system/users has been removed. This includes the deletion of all associated components (such as the data table, user action dialogs for add/edit/delete/invite, and the multi-delete dialog), the React Query hooks for user operations (create, update, delete, invite, bulk status), the Zod schemas and mock data, and the main route entry point. This change eliminates the legacy user management UI and its underlying data-fetching logic from the application.
web/src/features/system/users · high confidence
Removal of unused permission identifier service
The \internal/permission/identifier\_service.go\ file has been deleted. This service previously managed permission identifiers (such as menu, button, module, and project permissions) stored in Casbin for frontend control, including methods to retrieve, check, and clear these identifiers for roles and users. Its removal indicates this specific capability is no longer used or has been replaced by another mechanism.
internal/permission · high confidence
Removed demo tasks and chats features
The demo Tasks feature (including the data table, bulk actions, import dialog, and mutation drawers) and the demo Chats feature (including the chat list, new chat dialog, and sample conversation data) have been removed from the application.
web/src/features/tasks · high confidence
Removed web frontend build configuration and Go embedding layer
The web frontend build configuration (Vite, TypeScript, and environment examples) and the Go module responsible for embedding and serving the static assets have been removed from this location. This eliminates the local build tooling and the Go-based static file server that previously handled SPA routing and asset embedding.
web · high confidence
Roles feature module removed
The entire Roles management feature located in web/src/features/system/roles has been deleted. This includes the main page component, the context provider for dialog state, the custom hooks for form handling and menu selection, the dialog components, and the associated menu configuration data. Users will no longer have access to the role management interface.
web/src/features/system/roles · high confidence
Behavioural changes
Bootstrap initialization refactored with unified caching, OAuth login, and stricter startup behavior
The application bootstrap has been restructured to introduce a unified caching layer (supporting both in-memory and Redis backends) that is now shared across user status caching, JWT blacklist, and captcha management. A new social login feature has been added, allowing Google and GitHub OAuth providers to be configured via environment variables. Additionally, the startup process now strictly terminates if Casbin permission initialization fails, rather than continuing with a degraded state. The default admin initialization logic has also been updated to use the 'IsAdmin' flag for detection and to assign the 'admin' role as a system role.
bootstrap · high confidence
Casbin permission engine upgraded to v3 with pluggable storage adapters
The internal permission engine has been upgraded from Casbin v2 to v3, replacing the legacy \casbin.Enforcer\ with the thread-safe \SyncedEnforcer\ to prevent race conditions during concurrent policy updates. The adapter layer has been refactored to support pluggable storage backends: it now defaults to an \ent\-based SQL adapter but can switch to a Redis adapter when a Redis configuration is provided. Additionally, the previous global singleton manager pattern has been removed in favor of explicit manager instantiation, and a new incremental sync service has been added to efficiently synchronize policy changes based on entity timestamps.
internal/casbin · high confidence
Casbin sync scheduler reliability and incremental updates
The Casbin sync scheduler now supports idempotent and concurrent Stop calls without panicking, and allows restarting after being stopped. It has switched from full database synchronization to incremental updates based on the last sync time, improving efficiency. Additionally, the scheduler's log output format has been standardized, and the interval update mechanism now applies to the next Start rather than requiring a restart.
internal/scheduler · high confidence
Cleanup and shadmin-dev skills moved to .pi directory
The cleanup-specialist and shadmin-dev agent skills are now accessible via symlinks in the .pi/skills directory, pointing to their original locations in .agent/skills. This change reorganizes how these specific skills are referenced within the .pi configuration structure without altering the underlying skill implementations.
.pi · high confidence
Cleanup specialist and shadmin-dev agents converted to skills
The cleanup-specialist and shadmin-dev agents have been restructured as skills. This change introduces symbolic links in the .claude/skills directory that point to the corresponding skill definitions located in the .agent/skills directory, effectively migrating these capabilities from their previous agent format to the skills framework.
.claude · high confidence
Domain model refactoring and new capability interfaces
The domain layer has been significantly restructured to support new features and improve consistency. New domain interfaces and types have been added for Department management, Device Authentication (OAuth 2.0 Device Flow), Slide Captcha security validation, and Third-party User Identity (social login). The User model now includes fields for Nickname, Source, and Department, and login support has been expanded to accept any identifier (username, phone, or email) instead of just a username. The LoginRequest now requires Captcha parameters, and the LoginUsecase interface has been updated to include Logout and identifier-based lookup. Additionally, the old Casbin-specific permission request structures and constants have been removed, and the Menu and Role models have been updated to use shared constants and support keyword-based filtering. The RefreshToken interface has been simplified, and the PagedResult helper now ensures empty lists are never null.
domain · high confidence
Enhanced authentication, authorization, and logging in API middleware
The JWT authentication middleware now supports token revocation via a blacklist keyed by the JWT ID (jti), rejecting tokens without a jti or those found in the blacklist. The Casbin authorization middleware has replaced console logging with structured logrus entries for permission checks. The request logging middleware now captures full request and response bodies without truncation, handles WriteString outputs, and formats logs with color-coded status icons for development visibility. Additionally, a new User State middleware validates account status, blocking disabled or inactive users.
api/middleware · high confidence
Forgot password form now displays a temporary unavailability message
The forgot-password form in the frontend auth feature no longer simulates sending an email or navigating to an OTP page. Instead, upon submission, it immediately shows a toast notification stating that the password recovery feature is not yet open and instructs users to contact an administrator to reset their password, removing the previous mock delay and navigation logic.
frontend/src/features/auth/forgot-password · high confidence
Login logs now display email and source instead of username
The login logs table has been updated to show the user's email address and login source (e.g., local vs. other) rather than the username. The main column now renders the email, with a fallback to 'Unknown' if missing, and a new column displays the login source as a badge. Consequently, the global search and per-column filtering now target the email field, and the search placeholder has been updated to reflect this change. Additionally, the permission check for clearing logs was corrected to use the proper constant path.
frontend/src/features/system/login-logs/components · high confidence
Menu management UI refactored with unified dialog state and centralized query keys
The menu management interface has been reorganized to improve code structure and data consistency. The dialog state management was simplified by replacing individual boolean flags (showCreateDialog, showEditDialog, showDeleteDialog) with a single unified 'open' state in the menus provider, which now controls the create, edit, and delete dialogs. TanStack Query cache keys for menus and parent menus have been centralized in a new constants file to prevent string drift. The form state for API resource selection was optimized to use form.watch instead of local state, ensuring better synchronization with the form. Additionally, the layout was updated to use a simplified PageHeader, and several components were renamed or moved to align with the new directory structure.
frontend/src/features/system/menus · high confidence
Refactor dictionary management UI and state logic
The dictionary management feature has been refactored to improve code structure and state management. The \DictsProvider\ now uses a unified \typeOpen\ and \itemOpen\ state to control dialog visibility, replacing multiple boolean flags. Query keys are centralized in \dict-query-keys.ts\ for consistent cache invalidation. The main page layout has been simplified by removing inline header components (search, theme switch, profile) in favor of a shared \PageHeader\, and the search parameter is now consistently named \keyword\. Additionally, bulk actions and mutations now use a shared \useCrudMutation\ hook, and the table layout has been adjusted for better responsiveness.
frontend/src/features/system/dicts · high confidence
Refactored API Resources page layout and component structure
The API Resources feature has been reorganized under the new frontend directory structure. Visually, the page layout has been updated to use a new PageHeader component instead of the previous Header, Search, ThemeSwitch, and ProfileDropdown components. The main content area now employs a flex-column layout with improved spacing, and the API resources table data source has been adjusted to use the 'list' property from the API response instead of 'data'.
frontend/src/features/system/api-resources · high confidence
Refactored context utility helpers and added client IP extraction
The internal context utility has been updated to remove several user-info helper functions (GetUserName, GetUserEmail, GetIsAdmin, and GetCurrentUser) that previously retrieved data from the Gin context, while introducing a new BearerToken function to safely parse Authorization headers and a GetClientIP function to extract the real client IP from X-Forwarded-For, X-Real-IP, or RemoteAddr. This change simplifies the contextutil package by consolidating authentication token parsing and IP resolution logic, removing the previous bulk user-info retrieval pattern.
internal/contextutil · high confidence
Removal of legacy TanStack Router file-based route definitions
The file-based route configuration files in the \web/src/routes\ directory have been deleted. This includes the root layout (\\_\_root.tsx\), the authenticated layout wrapper (\\_authenticated/route.tsx\), and all specific page routes for features such as Apps, Chats, Tasks, and System administration (Users, Roles, Menus, Dicts, API Resources, Login Logs). Consequently, the application no longer uses this specific file-based routing structure for these areas.
web/src/routes · high confidence
Removal of legacy TypeScript type definitions
The legacy TypeScript type definitions located in the \web/src/types\ directory have been removed. This includes the deletion of files defining core domain models and API structures such as \api.ts\, \user.ts\, \role.ts\, \profile.ts\, \menu.ts\, \dict.ts\, and \constants.ts\. These types covered HTTP response wrappers, pagination results, user and role management interfaces, menu structures, dictionary items, and authentication constants. Their removal indicates a shift in how the frontend handles type safety or data structures, likely replacing these explicit definitions with a different approach (such as auto-generated types or a different schema library), which may require updates to any components that previously imported from these modules.
web/src/types · high confidence
Removal of pre-commit hook for Go and frontend checks
The pre-commit hook that automatically ran Go formatting, vetting, and tests, as well as frontend linting and formatting checks via npm, has been removed. Developers will no longer have these checks enforced automatically before committing code.
.githooks · high confidence
Repository layer refactoring and new domain support
This change introduces new repository implementations for Department and Device Auth, and refactors existing repositories (User, Menu, Dict, LoginLog, Role, Profile) to use a shared, generic tree-building helper and unified sorting/pagination logic. Key user-facing impacts include: Department management is now supported via a new repository; Device Auth sessions are persisted and managed; User profiles now display Nickname and Bio, and login logs track Email and Source instead of just Username; Menu and Role lookups are optimized with batch fetching and shared helpers; and free-text filtering across multiple entities (Users, Menus, Dicts, Departments) is unified under a 'keyword' parameter.
repository · high confidence
Roles feature refactored with centralized dialog state and TanStack Query keys
The roles management UI has been restructured to use a centralized \RolesProvider\ for managing dialog state (add, edit, delete) instead of individual boolean flags, and all TanStack Query cache keys are now imported from a shared constants file to prevent drift. A new \RolesDeleteDialog\ component was added to handle role deletion with confirmation, and the \RolesTable\ and \RolesCreateDialog\ were updated to use these new patterns. Additionally, the \MenuTreeSection\ component was updated to use a specific \RoleMenuOption\ type, and the layout was adjusted to ensure proper spacing with the pagination component.
frontend/src/features/system/roles · high confidence
Settings UI refactored and profile form functionalized
The settings interface has been reorganized under the new frontend directory structure, with the main layout replacing the previous header components (Search, ThemeSwitch, ConfigDrawer, ProfileDropdown) with a simplified PageHeader. In the profile settings, the form now supports actual data persistence: users can update their bio, which is saved via the updateProfile service and reflected in the store, accompanied by success/error toasts. Additionally, the profile form now displays the user's avatar and username initial, providing visual feedback on the current profile state.
frontend/src/features/settings · high confidence
Sign-in form now requires slide captcha verification and supports third-party identity providers
The sign-in experience has been updated to include a slide captcha challenge before submitting credentials, preventing automated login attempts and reducing layout jitter during verification. Additionally, the form now dynamically renders buttons for enabled third-party identity providers (such as GitHub and Google) via a new \IdentityLoginButtons\ component, allowing users to authenticate via OAuth. The underlying authentication flow has also been refactored to use a unified \identifier\ field for username, phone, or email, and JWT parsing has been moved to a dedicated utility.
frontend/src/features/auth/sign-in/components · high confidence
Sign-up form now displays a notification instead of simulating a delay
The sign-up form component has been moved to the frontend directory and updated to provide immediate user feedback. When a user submits the form, the previous behavior of logging data and simulating a 3-second loading delay has been replaced with an immediate info toast notification stating that the registration feature is not yet open and advising the user to contact an administrator to create an account.
frontend/src/features/auth/sign-up · high confidence
Standardized logging implementation in API setup
The API module now uses the centralized logging utility from the 'pkg' package instead of the standard Go 'log' package. This change ensures consistent log formatting and behavior across the application by routing API setup errors through the shared logging infrastructure.
api · high confidence
Standardized user status constants and added HTTP header definitions
The application now defines explicit constants for user lifecycle states (active, inactive, invited, suspended) and user sources (local, GitHub, Google) to ensure consistent status handling across entities. Additionally, standard HTTP header constants for Authorization and User Subject have been added to support unified request context propagation.
internal/constants · high confidence
Startup aborts on Casbin initialization failure
The application now terminates immediately if Casbin initialization fails, rather than continuing to start. This ensures that the system does not run without proper authorization controls, improving security posture by preventing operation in an inconsistent state.
cmd · high confidence
Structured log fields now appended to console and file outputs
The logging system in the \pkg\ package has been updated to include structured key-value pairs in all log entries. A new \formatFields\ helper sorts and formats log fields, which are now appended to the end of log messages in both the console and file formatters. This change ensures that additional context provided via log fields is consistently visible in the output. Additionally, the \TimePointer\ function in \pkg/time.go\ was simplified to use \new(TimeStamp())\ for creating a time pointer.
pkg · high confidence
Token expiry unit change and new cache/social login configuration options
The application's token expiry settings have shifted from hours to minutes, with default access and refresh tokens now set to 180 and 1800 minutes respectively. Additionally, the configuration schema now supports Redis-based caching (with connection details) and social login providers (Google and GitHub), requiring new environment variables for client IDs, secrets, and session management.
internal/conf · high confidence
Token parsing hardened and expiry unit changed to minutes
The token utility now enforces stricter validation: access tokens must include the 'shadmin' issuer claim, and only the HS256 signing algorithm is accepted, rejecting other HMAC variants and alg=none attacks. Additionally, token expiry is now specified in minutes rather than hours, and both access and refresh tokens now include a unique JTI (JWT ID) to support logout blacklisting. The previous helper functions for extracting individual claims (ID, email, admin status) have been removed in favor of dedicated parsers that return full claim structs.
internal/tokenutil · high confidence
Token service refactors extraction methods into comprehensive claim parsing
The token service API has been updated to replace granular extraction methods (such as ExtractIDFromToken, ExtractEmailFromToken, and ExtractIsAdminFromToken) with broader parsing functions (ParseAccessClaims, ParseRefreshClaims) that return full JWT claims, and a new method (ExtractJTIAndExpiry) to support server-side logout blacklisting. Additionally, a new CreateAccessTokenWithIdentity method was added to support access tokens carrying third-party identity information.
internal/tokenservice · high confidence
Dependencies
Frontend package manager migration and CLI initialization
The frontend build system has migrated from npm to pnpm, replacing the deleted \web/package.json\ and \web/package-lock.json\ with a new \frontend/package.json\ and \frontend/pnpm-lock.yaml\ that enforces pnpm v11 and Node.js v22. Additionally, a new Go CLI module (\cli/go.mod\) has been introduced, initializing the \shadmin-cli\ project with Go 1.27.1 and the Cobra framework v1.10.2.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 58 → 58 (-0.0)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 100 → 89 (-11.3)
- Architecture 86 → 82 (-4.0)
- Maturity 78 → 78 (-0.2)
- Readiness 42 → 42 (-0.5)
- Security 67 → 68 (+1.8)
- Domain Modelling 100 (new)
- Accessibility 71 → 71 (+0.0)
- Performance 76 (new)
New (57)
- Client.doWithRetry (cognitive 29) (cli/internal/client/client.go)
- Client.doWithRetry (cyclomatic 27) (cli/internal/client/client.go)
- Duplicated block (10 lines × 2) (pkg/logger.go)
- Duplicated block (10 lines × 2) (repository/role_repository.go)
- Duplicated block (11 lines × 2) (api/controller/dict_controller.go)
- Duplicated block (11 lines × 2) (api/middleware/casbin_middleware.go)
- Duplicated block (11 lines × 2) (repository/menu_repository.go)
- Duplicated block (12 lines × 2) (repository/dict_repository.go)
- Duplicated block (13 lines × 2) (api/controller/dict_controller.go)
- Duplicated block (13 lines × 3) (cli/cmd/resources.go)
- Duplicated block (14 lines × 2) (ent/schema/dict_item.go)
- Duplicated block (5 lines × 2) (usecase/login_usecase.go)
- Duplicated block (6 lines × 2) (domain/file.go)
- Duplicated block (7 lines × 2) (bootstrap/api_resources_init.go)
- Duplicated block (7 lines × 2) (usecase/resource_usecase.go)
- Duplicated block (8 lines × 2) (api/controller/dict_controller.go)
- Duplicated block (8 lines × 2) (usecase/login_usecase.go)
- Duplicated block (8 lines × 4) (ent/schema/dict_item.go)
- Duplicated block (9 lines × 2) (api/controller/dict_controller.go)
- Duplicated block (9 lines × 2) (api/controller/menu_controller.go)
- …and 37 more
Changes since last survey
- 21 commits — 18 feature/other, 3 fixes
By area
- frontend/src — 5 commits
- api/controller — 4 commits
- (root) — 2 commits
- bootstrap/admin_init_test.go — 2 commits
- internal/casbin — 2 commits
- api/middleware — 1 commit
- docs/getting-started — 1 commit
- domain/menu.go — 1 commit
- domain/role.go — 1 commit
- ent/schema — 1 commit
- internal/captcha — 1 commit
Notable commits
- fix: fix(api): propagate request contexts through use cases
- fix: fix: enforce authorization-update contract and remove dead code from review
- fix: fix: tighten repository contracts and identity usernames
- change: chore: trim verbose Go comments
- change: delete cas adapter
- change: docs
- change: docs
- change: feat: add test
- change: feat: add test
- change: feat: auth state
- change: feat: oauth user role
- change: feat: user invitation
- change: format
- change: refactor(api): move device auth throttling to middleware
- change: refactor(domain): define shared status values in domain
- change: refactor(frontend): separate API and menu types from UI
- change: refactor: casbin auth
- change: refactor: clean up department management
- change: refactor: simplify dictionary safeguards
- change: refactor: user identity
- …and 1 more
Architecture
- 0 containers · 1 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ahaodev/shadmin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 7 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c35806d1e1f32b821e0e21217e179e8ed5ad7402 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-8d8088103122.