amantinband/clean-architecture
56.9
Weak · 21 September 2026
1.8k
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is a .NET-based backend service for managing user reminders and subscriptions, structured around a Clean Architecture pattern. It provides RESTful APIs for creating, retrieving, and dismissing reminders, as well as managing user subscriptions and generating authentication tokens. The system enforces strict role-based access control and input validation, while also supporting email notifications for due reminders.
Features
Added HTTP request file for token generation endpoint
A new HTTP request file (GenerateToken.http) was added to the requests/Tokens directory, providing a ready-to-use template for the /tokens/generate endpoint. The file includes a POST request with a sample JSON payload containing user details, permissions, and roles, allowing users to easily test the token generation flow.
requests/Tokens · high confidence
Email notifications for due reminders
Users will now receive email notifications when their reminders are due. This is powered by a new background service that periodically checks for upcoming reminders and sends emails to the relevant users. The system now includes configuration for SMTP settings and email templates, as well as repository methods to fetch and manage reminders for the notification service.
src/CleanArchitecture.Infrastructure/Reminders · high confidence
Behavioural changes
Adds JWT authentication and email notification configuration
The API now supports JWT-based authentication, with configuration options for secret keys, token expiration, and issuer/audience settings. Additionally, email notification settings (SMTP server, port, credentials) have been added to the application configuration, enabling the system to send emails when reminders are due. The middleware pipeline has been updated to include exception handling, authorization, and a custom infrastructure middleware, while the ReminderResponse contract now includes an IsDismissed status field.
src/CleanArchitecture.Api · high confidence
Adds persistence converters and refactors domain event handling
New value converters for JSON serialization and list-of-IDs storage are introduced in the persistence layer, enabling more flexible data mapping in the database. Additionally, the \AppDbContext\ is moved to a \Persistence\ subdirectory, and \SaveChangesAsync\ is refactored to use \SelectMany\ for domain event extraction, while the \EventualConsistencyMiddleware\ is reorganized into a \Middleware\ folder and simplified with primary constructors.
src/CleanArchitecture.Infrastructure/Common · high confidence
Database schema updated to support users, subscriptions, and enhanced reminders
The application's database schema has been updated to include a new Users table and expand the Reminders table. The Reminders table now stores additional fields including UserId, SubscriptionId, DateTime, Text, and IsDismissed. A new Users table has been added to store user details such as Email, FirstName, LastName, and references to their Subscription and Calendar data. This change reflects the addition of user management and subscription features.
src/CleanArchitecture.Infrastructure/Migrations · high confidence
Introduces a new authorization and validation pipeline for application requests
The application now enforces access control and input validation through new MediatR pipeline behaviors. The \AuthorizationBehavior\ intercepts requests marked with the \Authorize\ attribute, checking roles, permissions, and policies against the current user. The \ValidationBehavior\ runs FluentValidation validators before handlers execute. These behaviors are registered in \DependencyInjection\, and the \CurrentUser\ model has been removed in favor of passing user context via the \IAuthorizeableRequest\ interface. This change affects how all commands and queries in the application are processed, ensuring that only authorized users can execute specific actions.
src/CleanArchitecture.Application · high confidence
New HTTP request files for subscription management
Added HTTP request files for creating, deleting, and retrieving user subscriptions, enabling developers to test the new subscription endpoints directly via HTTP clients.
requests/Subscriptions · medium confidence
Restructure API endpoints to enforce hierarchical resource scoping
API routes are reorganized to reflect nested resource relationships: reminders are now scoped under both user and subscription (e.g., /users/{userId}/subscriptions/{subscriptionId}/reminders), and subscription management endpoints are similarly nested under the user. The SubscriptionsController introduces create, delete, and get operations for subscriptions, while the TokensController provides an anonymous endpoint for generating authentication tokens. Additionally, the base ApiController now enforces global authorization, and the RemindersController adds dismiss and list capabilities alongside the existing create, get, and delete operations.
src/CleanArchitecture.Api/Controllers · high confidence
Restructure security concerns
The security-related components have been reorganized into the \CleanArchitecture.Infrastructure.Security\ namespace. This includes the introduction of an \AuthorizationService\ that enforces role, permission, and policy-based access control, alongside a \CurrentUserProvider\ that extracts user identity and claims from the HTTP context. Additionally, JWT token generation and bearer token validation configurations have been added to support secure authentication flows.
src/CleanArchitecture.Infrastructure/Security · medium confidence
Restructures infrastructure layer with new security, user, and date-time services
The CleanArchitecture.Infrastructure project has been restructured to support new security and user management capabilities. A new SystemDateTimeProvider service is introduced to abstract system time. User persistence is expanded with a new UsersRepository implementing AddAsync, GetByIdAsync, GetBySubscriptionIdAsync, RemoveAsync, and UpdateAsync methods, alongside a corresponding UserConfigurations entity mapping. Authentication and authorization are explicitly configured via AddAuthentication and AddAuthorization extension methods, registering JwtBearer options, token generators, and policy enforcers. The request pipeline middleware is renamed from AddInfrastructureMiddleware to UseInfrastructure, and background services for email notifications are conditionally registered based on configuration.
src/CleanArchitecture.Infrastructure · high confidence
Updated Reminder API endpoints to include user and subscription context
The HTTP request files for creating, retrieving, listing, deleting, and dismissing reminders have been updated to reflect a new API structure. Reminders are now accessed via nested paths that include the user and subscription identifiers (e.g., /users/{userId}/subscriptions/{subscriptionId}/reminders). Additionally, an Authorization header is now required for these requests, and the request body for creating a reminder now includes a specific date-time format.
requests/Reminders · medium confidence
Test coverage
Added integration and subcutaneous tests for reminders and subscriptions; Expanded test coverage and build configuration.
Dependencies
Centralized package version management and dependency updates
The project now uses a centralized package version management file (Directory.Packages.props) to define and share versions for all NuGet packages across the solution. This change updates several dependencies, including upgrading Microsoft.EntityFrameworkCore and related packages to version 8.0.0, updating Swashbuckle.AspNetCore to 6.5.0, and upgrading System.IdentityModel.Tokens.Jwt to 7.2.0. Additionally, new test projects (IntegrationTests, SubcutaneousTests, UnitTests) have been added with their respective dependencies, and some package names have been corrected (e.g., Ardalis.SmartEnum, ErrorOr).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 62 → 57 (-4.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 70 → 50 (-19.9)
- Architecture 77 → 79 (+2.0)
- Maturity 68 → 68 (+0.0)
- Readiness 57 → 59 (+1.3)
- Security 67 → 70 (+3.5)
- Event-Driven 100 → 100 (+0.0)
- Performance 60 → 60 (+0.0)
Resolved (21)
- Bounded contexts not declared
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- Medium IaC: CKV2_GHA_1 (.github/workflows/build.yml)
- Medium IaC: CKV2_GHA_1 (.github/workflows/publish.yml)
- Medium IaC: CKV_DOCKER_3 (Dockerfile)
- Medium IaC: CKV_SECRET_6 (src/CleanArchitecture.Api/appsettings.Development.json)
- Medium IaC: CKV_SECRET_6 (src/CleanArchitecture.Api/appsettings.Development.json)
- Medium IaC: CKV_SECRET_6 (src/CleanArchitecture.Api/bin/Debug/net8.0/appsettings.Development.json)
- Medium IaC: CKV_SECRET_6 (src/CleanArchitecture.Api/bin/Debug/net8.0/appsettings.Development.json)
- Secret: jwt (.vscode/settings.json)
- Secret: jwt (.vscode/settings.json)
- Secret: jwt (.vscode/settings.json)
- Secret: jwt (.vscode/settings.json)
- Secret: jwt (.vscode/settings.json)
- Secret: jwt (.vscode/settings.json)
- …and 1 more
New (44)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- …and 24 more
API surface
- Unchanged — 9 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
amantinband/clean-architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 582281115489ac69d048e47c7363c7832e5b425a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.