Skip to content
CAI
Software that uses CAICheck a score

alexandrebeato/bankflix

41.5

Weak · 21 September 2026

4.2k

lines of production code

C#

with Dart, TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a banking application supporting both web and mobile clients, enabling clients to manage accounts, view transaction histories, and perform deposits and transfers. It provides an administrative interface for agency staff to approve client registrations and monitor financial movements. The backend implements a CQRS architecture with MongoDB persistence and message queue integration to handle these banking operations.

Features

Add Agencia controller with login and retrieval endpoints

A new AgenciaController is introduced to handle agency-related operations. It provides a login endpoint (POST /login) that authenticates an agency using CNPJ and password, returning a JWT token and agency details. It also includes a GET endpoint to retrieve agency information, protected by an 'Autenticado' policy. The controller integrates AutoMapper for mapping and uses dependency injection for repository and mediator access.

server/src/Bankflix.API/Controllers/Agencia · high confidence

Added AutoMapper configuration for domain and view model mapping

The application now includes a new AutoMapper configuration in the server's mapper layer, defining bidirectional mappings between domain models and view models. Specifically, it maps entities for agencies, clients, and financial transactions (deposits, transfers, and general movements) to their respective view models, and conversely maps view models back to domain commands for client registration and transaction requests.

server/src/Bankflix.API/Mapper · high confidence

Added MongoDB repository layer for agency data access

The application now includes a new data access layer for agencies, implemented via MongoDB. A generic \Repository\<T\>\ base class provides standard CRUD operations (insert, update, delete, and query by ID or predicate), while a specific \AgenciaRepository\ implements agency-specific logic, including a method to retrieve agencies by CNPJ and a seeding method to insert a default agency record if none exist.

server/src/Agencia.Infra.Data · high confidence

Added Movimentações (transactions) page to the board

A new Movimentações page has been added to the board, allowing users to view their account details, current balance, and a detailed transaction history (extrato). The page displays account number, available balance, and a list of movements including type (deposit/transfer), value, date, and associated client information.

clients/angular/src/app/modules/board/components/movimentacoes · high confidence

Added client and agency authentication modules

The application now includes a new authentication module that provides login and registration interfaces for both clients and agencies. Clients can register new accounts or log in to access their personal dashboard, while agency users can log in to the administrative area. The module includes the necessary routing, components, and services to handle these authentication flows.

clients/angular/src/app/modules/autenticacao · high confidence

Added domain models for client, agency, and financial movements

New TypeScript classes and enums have been introduced to represent core banking entities. This includes models for client registration and status (Cliente, SituacaoCliente), agency details (Agencia, DadosBancarios), and financial movements such as deposits (Deposito) and transfers (Transferencia), along with their respective status and type enums. These changes provide the data structures required to support the new deposit, transfer, and client management screens.

clients/angular/src/app/models · high confidence

Added route guards for client and agency authentication

New Angular route guards (CanActivateChild) have been introduced for client and agency users, ensuring that only authenticated users can access their respective application sections. The client guard redirects unauthenticated users to the login page, while the agency guard does the same for agency users. Additionally, a general authentication guard manages the transition between client and agency contexts, clearing conflicting tokens and redirecting users to the appropriate dashboard (board for clients, agencia for agencies) to prevent simultaneous active sessions. These changes are supported by a new LocalStorageUtils utility to manage client and agency tokens and data in local storage.

clients/angular/src/app/utils · medium confidence

Added view models for agency and login functionality

Introduced new view models to support agency and login operations. AgenciaViewModel provides a structured representation of agency data including ID, social reasons, CNPJ, and associated bank details. LoginViewModel handles authentication inputs, enforcing validation rules for CNPJ and password fields, and includes a computed property to encrypt the password using MD5.

server/src/Bankflix.API/Models/Agencia · high confidence

Added view models for client registration, login, and account details

New view models have been introduced to support client-facing API interactions. CadastrarClienteViewModel and LoginViewModel handle registration and authentication data transfer, including CPF, email, and password fields with validation attributes. ClienteViewModel provides a simplified representation of client data for general queries, while ContaViewModel exposes account details such as balance and account number. These models define the structure of data exchanged with the client module.

server/src/Bankflix.API/Models/Clientes · medium confidence

Domain models for deposits, transfers, and movements are introduced

The domain layer now includes full entity definitions, validation rules, and repository interfaces for deposits, transfers, and general movements. Users can now create and validate deposits and transfers, with specific checks for account details, client information, and transaction values. The system enforces consistency through dedicated validation classes for each entity type, ensuring that required fields like account numbers, client names, CPFs, and amounts are present and correct before processing.

server/src/Movimentacoes.Domain · high confidence

Implemented CQRS command and event handling for client and account management

Added the client CQRS stack, including a command handler for registering, approving, and rejecting clients, along with corresponding domain events. Also introduced an event handler that triggers account creation upon client approval. Additionally, implemented the account CQRS stack with command handlers for creating accounts and adjusting balances.

server/src/Clientes.CommandStack · high confidence

Implemented CQRS handlers for deposits and transfers

The application layer now includes command handlers and event handlers for processing deposit and transfer requests. This change introduces the command stack logic for 'Depositos' (deposits) and 'Transferencias' (transfers), including their respective adapters, events, and handlers, enabling the system to process these financial movements via the CQRS pattern.

server/src/Movimentacoes.CommandStack · high confidence

Initial API scaffolding with dependency injection and background queue processing

The Bankflix API project has been initialized with a new architecture that includes a shared BaseController for consistent error handling and validation, along with a HostedService for continuous background queue processing. The startup configuration registers all necessary dependencies, including authentication services, AutoMapper, MediatR, and specific repositories for Agencias, Clientes, and Movimentacoes. Additionally, the application is configured to connect to MongoDB and RabbitMQ as defined in the appsettings.json file.

server/src/Bankflix.API · high confidence

Initial Angular application shell with routing and guards

The Angular client application is initialized with a root module, component, and routing configuration. The app defines three primary navigation areas—authentication, board, and agency—each protected by specific route guards (CanActivateAutenticacaoGuard, CanActivateClienteGuard, CanActivateAgenciaGuard) to control access. The app module also registers locale data for Portuguese, and includes essential Angular modules like Browser, Animation, HTTP, and a custom validators library.

clients/angular/src/app · medium confidence

Initial Angular client scaffolding and theming

The Angular client application is introduced with the foundational entry files (index.html, main.ts, polyfills.ts) and global styles. The UI is configured with a custom Material Design theme using indigo and pink palettes, alongside Bootstrap grid utilities and Roboto typography, establishing the visual identity for the BankFlix front-end.

clients/angular/src · high confidence

Initial Angular client structure and Docker support

The Angular front-end application has been initialized with a complete project structure, including configuration files (angular.json, tsconfig, tslint.json, browserslist) and an end-to-end test setup using Protractor. Additionally, the application is now Dockerized, featuring a multi-stage Dockerfile that builds the Angular app using Node.js and serves the static assets via Nginx, supported by a custom Nginx configuration file.

clients/angular · high confidence

Initial Flutter client scaffolding and core feature controllers

The Flutter client application is introduced with the standard Android and iOS platform configurations, including manifest files, build configurations, and Xcode project structures. Additionally, the diff adds the foundational state management and repository controllers for the app's core features: a login controller, a client registration controller, a dashboard controller, and a deposits controller, each implementing the business logic and state handling for their respective screens.

clients/flutter · high confidence

Initial server infrastructure and client domain implementation

The server project is initialized with a new .NET Core 3.0 architecture, including a Dockerfile for containerization and a global.json specifying SDK 3.0.100. The change introduces the client domain's data layer, implementing MongoDB repositories for clients and accounts using a generic base repository pattern. This establishes the foundational data access and infrastructure for the client and account entities within the server's domain model.

server · high confidence

Introduce client and account management endpoints

Adds new API controllers for client and account management. The ClientesController provides endpoints for client registration, login, and administrative approval/rejection of pending clients. The ContasController exposes endpoints to retrieve all accounts or the current user's account, with access restricted by user role (Agencia for admin operations, Cliente for personal account access).

server/src/Bankflix.API/Controllers/Clientes · high confidence

Introduces CQRS command classes for deposits and transfers

The server now includes new CQRS command classes for the 'Movimentacoes' (movements) context, specifically for deposits and transfers. This adds command definitions for executing and requesting deposits (EfetuarDeposito, SolicitarDeposito) and transfers (EfetuarTransferencia, SolicitarTransferencia), each containing relevant identifiers, amounts, and timestamps. These commands serve as the input layer for the application's command handlers, enabling the processing of these financial operations.

server/src/Movimentacoes.Commands · high confidence

Introduzido domínio de clientes e contas

O domínio de clientes foi iniciado com a entidade Cliente, que inclui validações de consistência e regras de negócio para CPF e e-mail únicos. Além disso, foi criada a entidade Conta, que gerencia o saldo disponível e impede a criação de múltiplas contas para o mesmo cliente, garantindo a unicidade do número da conta.

server/src/Clientes.Domain · medium confidence

Introduzido o domínio de agência com validações e repositório

O domínio de agência foi introduzido no servidor, incluindo a entidade \Agencia\ com seus atributos (RazaoSocial, NomeFantasia, Cnpj, Senha, DadosBancarios) e um método de fábrica para criar uma agência padrão. O pacote inclui a interface \IAgenciaRepository\ para persistência, a classe de especificação \DeveExistirApenasUmaAgenciaSpecification\ para garantir a unicidade da agência na base, e as classes de validação \AgenciaEstaConsistenteValidation\ e \AgenciaEstaConsistenciaParaCadastroValidation\ que verificam a consistência dos dados e a existência prévia de uma agência. Além disso, foi adicionado o valor de negócio \DadosBancarios\ para armazenar informações bancárias da agência.

server/src/Agencia.Domain · medium confidence

Introduzidos comandos CQRS para gestão de clientes e contas

A estrutura CQRS foi expandida para incluir novos comandos de domínio. Para o contexto de Clientes, foram adicionados comandos para aprovar (AprovarClienteCommand) e recusar (RecusarClienteCommand) clientes, bem como um comando para cadastrar um novo cliente (CadastrarClienteCommand) com detalhes como nome, CPF e e-mail. Para o contexto de Contas, foram introduzidos comandos para criar uma conta (CriarContaCommand) e para adicionar ou remover valores do saldo (AdicionarValorSaldoContaCommand e RemoverValorSaldoContaCommand).

server/src/Clientes.Commands · high confidence

New 'Agência' module with client management and transaction history views

A new 'Agência' module has been introduced to the Angular client, providing a dedicated interface for branch-level operations. This includes a 'Pending Clients' view where users can approve or reject client registrations, and a 'Transactions' view that allows filtering and viewing financial movements by date range. The module also includes a main navigation header and a base service for handling authenticated API requests.

clients/angular/src/app/modules/agencia · high confidence

New API endpoints for deposits, transfers, and account movements

Added new controllers for deposits, transfers, and account movements, enabling users to submit deposit and transfer requests and retrieve their transaction history. Deposits can be requested by clients and viewed by agency staff. Transfers allow clients to initiate transfers and view their sent and received transactions. Account movements support filtering by date range for agency staff and allow clients to view their own movement history.

server/src/Bankflix.API/Controllers/Movimentacoes · high confidence

New Board module with deposit and transfer functionality

The Angular client now includes a new Board module that provides a dashboard for managing financial movements. Users can view their deposit history and request new deposits, as well as initiate and track bank transfers. The module introduces the Deposits and Transfers components, along with the corresponding services (DepositosService, TransferenciasService, ContasService, MovimentacoesService) and routing configuration to support these new capabilities.

clients/angular/src/app/modules/board · high confidence

New view models for deposits, transfers, and transaction periods

Added new view models to support the UI for deposits, transfers, and transaction history. This includes \DepositoViewModel\ and \SolicitarDepositoViewModel\ for deposit operations, \TransferenciaViewModel\ and \SolicitarTransferenciaViewModel\ for transfer operations, and \PeriodoMovimentacoesViewModel\ for filtering transactions by date range. These models define the data structures required for the frontend to display and submit banking movements.

server/src/Bankflix.API/Models/Movimentacoes · high confidence

Behavioural changes

Added placeholder for Angular assets directory

A .gitkeep file was added to the clients/angular/src/assets directory, ensuring the folder is tracked by version control.

clients/angular/src/assets · high confidence

Added queue service configuration and JWT authentication setup

The application now includes a new queue service configuration that registers a background service for continuous queue processing, and implements JWT-based authentication and authorization. Users will experience secure access to the system via JWT tokens, with specific role-based policies for 'Agencia' and 'Cliente' types. The authentication mechanism uses a symmetric key for signing tokens, and the system enforces authenticated access through defined authorization policies.

server/src/Bankflix.API/Configurations · medium confidence

Added user identity and profile models

The API now includes new models to handle user authentication and profile data. AspNetUser implements IUsuario to manage authentication state, permissions, and user identification via HTTP context. UsuarioViewModel defines the structure for user profile data, including a TipoUsuario enum to distinguish between 'Agencia' (Agency) and 'Cliente' (Client) user types.

server/src/Bankflix.API/Models · high confidence

Centralized dependency registration for domain modules

The codebase now uses explicit dependency registration bootstrappers for the Agencia, Clientes, and Movimentacoes modules. Each module's infrastructure layer now contains a dedicated class (e.g., BootstrapperAgencia, BootstrapperClientes, BootstrapperMovimentacoes) that registers repository implementations and MediatR command/notification handlers with the service container. This replaces the previous implicit or scattered registration approach, making the dependency graph for each domain module more explicit and easier to maintain.

server/src/Agencia.Infra.CrossCutting, server/src/Clientes.Infra.CrossCutting, server/src/Movimentacoes.Infra.CrossCutting · high confidence

Configure API endpoint for Angular environments

Added environment configuration files for the Angular client, defining the API base URL as 'http://127.0.0.1:5002/' for both development and production builds.

clients/angular/src/environments · medium confidence

Introduces CQRS and message queue integration for domain commands

The Core.Domain layer now supports sending commands to a message queue (RabbitMQ) via a new MediatorHandler that routes commands either directly to MediatR or publishes them to a queue. A background hosted service continuously consumes messages from the queue, deserializes them, and processes them through the Mediator. The change also adds base classes for Commands and Events, a notification system for domain errors, and utility classes for validation and cryptography.

server/src/Core.Domain · medium confidence

MongoDB data access layer for core entities

The application now includes a new data access layer for the 'Movimentacoes' (transactions) context, implemented using MongoDB. This update introduces repository classes for Cliente (client), Conta (account), Deposito (deposit), Movimentacao (transaction), and Transferencia (transfer), each providing specific query methods (e.g., finding records by client ID, account number, or origin/destination). These repositories are built on generic base classes (Repository and ReadOnlyRepository) that handle standard CRUD operations and MongoDB client initialization, enabling the application to persist and retrieve these financial records from the database.

server/src/Movimentacoes.Infra.Data.Mongo · high confidence

Dependencies

Initial project scaffolding for Angular, Flutter, and .NET server

This change introduces the foundational build and dependency configurations for the application's three main components: the Angular client (package.json/lock), the Flutter mobile client (pubspec.yaml/lock, Android Gradle, iOS Podfile), and the .NET server (multiple .csproj files). These files establish the initial dependency trees and project structures required to build and run each part of the system.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 42 → 41 (-0.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 54 → 54 (-0.3)
  • Architecture 65 → 63 (-2.1)
  • Maturity 50 → 50 (+0.0)
  • Readiness 27 → 27 (+0.0)
  • Security 80 → 64 (-15.6)
  • Domain Modelling 66 → 70 (+4.1)
  • Event-Driven 100 → 100 (+0.0)
  • Accessibility 50 → 50 (+0.0)

Resolved (61)

  • Bounded contexts not declared
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • …and 41 more

New (132)

  • Coverage not measured — .NET and JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • Critical CVE: [GHSA redacted] (clients/angular/package-lock.json)
  • …and 112 more

API surface

  • Unchanged — 10 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

alexandrebeato/bankflix was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5293d90755efe52d21866db62093e7633bf91001 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.