Skip to content
CAI
Software that uses CAICheck a score

amasen02/freshcart-backend

68.1

Adequate · 21 September 2026

25.4k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a backend platform for an e-commerce application, managing core business domains including catalog, inventory, basket, ordering, payment, delivery, and pricing. It implements a microservices architecture with a focus on data consistency, utilizing transactional outboxes, idempotent operations, and exactly-once projections to handle events and state changes reliably. The platform also includes dedicated services for identity management, customer support, and reporting, supported by a robust infrastructure layer that enforces security hardening and isolated data protection.

Features

Customer Support API adds secure development Swagger UI

Developers can now access the Customer Support API documentation via a self-hosted Swagger UI in the Development environment. This change introduces a custom UI implementation that serves static assets locally and enforces a strict Content Security Policy (CSP) to prevent unauthorized script execution, ensuring the API documentation interface is secure while maintaining full OpenAPI specification availability.

src/Services/CustomerSupport · high confidence

Removals

Customer SPA application code removed

The entire source code for the customer-facing Single Page Application (SPA) located in \clients/freshcart-customer\ has been deleted. This includes the Angular application entry point, routing configuration, core state management stores (auth, basket), HTTP interceptors, and all associated unit tests. This change aligns with the repository restructuring to split the customer SPA into its own separate repository.

(repo-wide) · high confidence

Security

Enforced secret injection and isolated data-protection cache

Infrastructure deployment now strictly requires explicit environment variables for all administrator passwords and the Key Vault administrator object ID, failing the build if they are missing rather than using placeholder defaults. Additionally, a dedicated Redis instance for ASP.NET Core Data Protection keys has been added to prevent session cookie signing material from being exposed through the shared application cache used by other services.

infra · high confidence

Security hardening: strict forwarded-headers validation, HSTS, and data-protection isolation

The API gateway now enforces strict security controls to prevent IP spoofing and improve transport security. It only trusts X-Forwarded-For headers from explicitly configured proxies (via ForwardedHeaders:KnownProxies/Networks), preventing attackers from bypassing rate limits by forging client IPs. HSTS is enabled with a 365-day max age and subdomain inclusion to enforce HTTPS. Additionally, the data-protection key ring is isolated into its own dedicated Redis connection ('dataprotection') rather than sharing the application cache, ensuring session cookies and anti-forgery tokens are not exposed to other services. Role claims are also corrected to use the standard ClaimTypes.Role to fix 403 errors on role-based authorization.

src/ApiGateways · high confidence

Behavioural changes

Catalog service now maps duplicate SKU creation to 409 and seeds inventory via events

The Catalog service now returns a 409 Conflict instead of a 500 Internal Server Error when a user attempts to create a product with a SKU that already exists, handling the race condition between the pre-check and the unique index constraint. Additionally, the catalog data seeder now publishes ProductCreated integration events for seed data, ensuring that downstream services like Inventory are notified and can initialize stock levels for pre-seeded products.

src/Services/Catalog · high confidence

Customer SPA repository split

The FreshCart customer storefront application has been moved from this repository into its own dedicated repository named freshcart-web. This change removes all associated source code, build configurations (Dockerfile, angular.json, eslint, karma), and deployment assets (nginx.conf) for the Angular-based customer interface from this codebase.

(repo-wide) · high confidence

Delivery service reliability: transactional outbox and atomic slot booking

The Delivery service now guarantees that integration events (DeliveryScheduled, DeliveryCompleted) are never lost if the message broker fails, by staging them in a MongoDB outbox collection within the same multi-document transaction that persists the delivery state. A background publisher drains these outbox messages to the bus. Additionally, delivery-slot booking is now atomic; concurrent schedulers racing for the last unit of capacity will no longer oversubscribe slots, with the system safely retrying when a slot fills during the booking window.

src/Services/Delivery · high confidence

Frontend split and repository rebranding

The Angular 20 customer storefront has been moved to a companion repository (amasen02/freshcart-web), and this repository has been rebranded as the backend platform (freshcart-backend). The README now directs users to clone the separate frontend repo, the Docker Compose configuration pulls the published frontend image instead of building it locally, and the CI workflow for the SPA has been removed. Additionally, the repository's default branch reference has been updated from 'main' to 'master' in the contributing guidelines.

(repo-wide) · high confidence

Identity service security hardening and reliability fixes

This update introduces several security and reliability improvements to the Identity service. Refresh token rotation is now atomic, preventing concurrent requests from successfully rotating the same token and ensuring reuse detection works correctly. CSRF protection is enforced on all state-changing mutations via cookie-conditional antiforgery validation, while safe HTTP methods are excluded. The data-protection key ring is now stored in a dedicated Redis connection, isolated from the application cache to prevent unauthorized access to session signing material. Additionally, the sign-up flow now correctly propagates user roles to the immediate session cookie, and the database initializer uses EnsureCreated to support the developer loop without EF migrations.

src/Services/Identity · high confidence

Improved outbox reliability, postal code validation, and local HTTPS connectivity

The outbox mechanism now prevents duplicate publishes across multiple publisher replicas by introducing a claim-based lease system (ClaimId, ClaimedOnUtc, and ClaimLeaseTimeout) and uses a stable, version-independent event contract name (Type.FullName) to ensure events in the outbox can be resolved even after assembly version bumps. Postal code validation has been tightened to enforce specific structural formats for GB, US, IE, DE, FR, and AU, rejecting malformed inputs while leaving unknown countries to generic validation. Additionally, local development environments now automatically accept the ASP.NET Core HTTPS development certificate for internal service-to-service calls, resolving 'UntrustedRoot' errors without requiring manual trust configuration.

src/BuildingBlocks · high confidence

Ordering service reliability and payment accuracy improvements

The Ordering service now ensures payment refunds are idempotent by sending the Payment ID as an idempotency key, preventing double-refunds on retries, and correctly interprets payment outcomes using the Payment service's status strings (e.g., "Captured", "Refunded") instead of boolean flags. To support multi-replica deployments, the outbox store uses a claim-by-update mechanism to prevent duplicate message publishing, and the gRPC channel to Inventory now accepts the ASP.NET Core development certificate in local environments to resolve SSL handshake failures.

src/Services/Ordering · high confidence

Outbox deduplication and improved startup reliability

The Basket service now prevents duplicate message publishing when multiple replicas run concurrently by implementing a claim-by-update mechanism in the Marten outbox store, ensuring each message is claimed by exactly one drainer. Additionally, the service now automatically provisions its tenant database on startup using a maintenance connection, and the Inventory service adds transient-failure retry logic to SQL connection opening to handle cold-boot contention more gracefully.

src/Services/Basket · high confidence

Payment service introduces idempotent refunds and asynchronous read-model projection

The Payment service now enforces idempotency on refund operations by requiring an Idempotency-Key header; duplicate requests are safely replayed without double-refunding the customer. Additionally, the service has shifted from synchronous read-model updates to an asynchronous, exactly-once projection model: event appends now stage markers in MongoDB, which a background worker drains to update the SQL read model, ensuring consistency without dual writes.

src/Services/Payment · high confidence

Pricing gRPC service allows anonymous access and adds integration tests

The Pricing gRPC service endpoint is now accessible without authentication (\[AllowAnonymous\]), resolving 401 errors for internal callers like the basket price calculator and message consumers that do not provide bearer tokens. To ensure reliability, integration tests have been added to verify the gRPC calculator and REST endpoints against an in-memory SQLite database, and unit tests now explicitly validate that negative discount values are rejected.

src/Services/Pricing · high confidence

Reporting warehouse becomes functional with exactly-once projections and invoice security fixes

The Reporting service is now live: a startup initializer provisions the MySQL warehouse schema (analytical fact and snapshot tables) so dashboards have data, and new projection consumers for delivery and inventory events feed these tables. All projection writes are now exactly-once, preventing double-counting on message redelivery. Invoice download endpoints are secured with a BackOfficeUser role to close a BOLA vulnerability, and path traversal is blocked by validating invoice numbers before accessing blob storage.

src/Services/Reporting · high confidence

Stabilizes local Aspire stack with persistent credentials and MongoDB replica set support

The local development environment now supports stable, persistent backing services by introducing configurable credentials for SQL Server, PostgreSQL, MySQL, and RabbitMQ, preventing authentication failures when containers are reused across runs. MongoDB is configured as a single-node replica set with a custom initialization script and direct-connection health checks, ensuring transactional consistency for Delivery and Payment services. Additionally, missing databases for Inventory, Payment Read, and Reporting are now automatically provisioned via creation scripts, and the stack can be switched to ephemeral mode for CI testing.

src/AspireAppHost/FreshCart.AppHost · high confidence

Fixes

Improved checkout validation for postal codes and shipping addresses

The checkout process now validates that postal codes match the format required by the selected country, rejecting invalid combinations with a clear error message. Additionally, the system enforces that a shipping address is provided when the basket contains physical items; this logic has been moved from the validator to the command handler to resolve a dependency injection issue where a singleton validator was incorrectly capturing a scoped repository.

src/Services/Basket/FreshCart.Basket.Api/Features/ShoppingBaskets · high confidence

Test coverage

Added tests for postal code validation and checkout command handler behavior; E2E test suite updates for HTTPS, authentication, and checkout flows.

Dependencies

Security hardening, dependency updates, and test infrastructure improvements

This release addresses several security vulnerabilities by pinning or upgrading specific packages: System.Security.Cryptography.Xml is updated to 10.0.11 to resolve multiple high-severity issues ([GHSA redacted], etc.), SSH.NET is upgraded to 2026.0.0 to fix a flagged high-severity vulnerability, and Microsoft.OpenApi is pinned to 2.9.0 to prevent a stack-overflow DoS ([GHSA redacted]). Additionally, the CustomerSupport API now includes Swashbuckle.AspNetCore.SwaggerUI for API documentation, and the Pricing service generates gRPC client stubs (GrpcServices=Both) to support integration tests. Test infrastructure is expanded with the addition of Testcontainers for PostgreSQL, MySQL, and MS SQL across various service test projects, and the Reporting API aligns its EF Core runtime with Pomelo by overriding EF packages to version 9.0.17. The customer SPA lock file and package manifest have been removed, and a Mongo replica set initialization script is now included in the AppHost.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 67 → 68 (+1.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (-0.1)
  • Architecture 83 → 83 (+0.0)
  • Maturity 84 → 84 (+0.0)
  • Readiness 63 → 64 (+1.3)
  • Security 78 → 77 (-0.7)
  • Domain Modelling 66 → 69 (+2.9)
  • Event-Driven 88 → 88 (+0.0)
  • Accessibility 69 → 69 (+0.0)
  • Performance 72 → 72 (+0.0)

Resolved (29)

  • Bounded contexts not declared
  • Coverage not measured — analyzer environment
  • Duplicated block (10 lines × 2) (src/Services/Catalog/FreshCart.Catalog.Api/Features/Products/CreateProduct/CreateProductCommandValidator.cs)
  • Duplicated block (11 lines × 2) (src/Services/Basket/FreshCart.Basket.Api/Persistence/MartenOutboxStore.cs)
  • Duplicated block (14 lines × 4) (src/Services/Catalog/FreshCart.Catalog.Api/DependencyInjection.cs)
  • Duplicated block (15 lines × 2) (src/BuildingBlocks/FreshCart.ServiceDefaults/DevelopmentCertificateValidation.cs)
  • Duplicated block (15 lines × 2) (src/Services/Catalog/FreshCart.Catalog.Api/Features/Products/CreateProduct/CreateProductCommandValidator.cs)
  • Duplicated block (15 lines × 2) (src/Services/Identity/FreshCart.Identity.Api/Configuration/AuthenticationConfiguration.cs)
  • Duplicated block (22 lines × 2) (src/Services/Basket/FreshCart.Basket.Api/Pricing/PricingGrpcChannelFactory.cs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • LLM evaluation failed
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • …and 9 more

New (303)

  • Critical CVE: Marten 8.37.0
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no project overview (docs/REQUIREMENTS.md)
  • Documentation: no usage examples (README.md)
  • Documentation: written for insiders (docs/CONVENTIONS.md)
  • Duplicated block (10 lines × 2) (src/Services/CustomerSupport/FreshCart.CustomerSupport.Api/Persistence/SupportChatGuidSerialization.cs)
  • Duplicated block (10 lines × 4) (src/Services/Reporting/FreshCart.Reporting.Infrastructure/Persistence/Warehouse/DapperSalesReadWarehouse.cs)
  • Duplicated block (12 lines × 2) (src/Services/Basket/FreshCart.Basket.Api/Persistence/MartenOutboxStore.cs)
  • Duplicated block (12 lines × 3) (src/Services/Reporting/FreshCart.Reporting.Infrastructure/Persistence/Warehouse/DapperSalesReadWarehouse.cs)
  • Duplicated block (13 lines × 2) (src/Services/Ordering/FreshCart.Ordering.Application/Orders/Dtos/OrderDetailDto.cs)
  • Duplicated block (13–21 lines × 2) (src/BuildingBlocks/FreshCart.BuildingBlocks.Messaging/MassTransit/MessageBrokerExtensions.cs)
  • Duplicated block (15 lines × 2) (src/Services/Catalog/FreshCart.Catalog.Api/Features/Products/CreateProduct/CreateProductCommandValidator.cs)
  • Duplicated block (16 lines × 2) (src/Services/Catalog/FreshCart.Catalog.Api/Features/Products/CreateProduct/CreateProductCommandValidator.cs)
  • Duplicated block (16 lines × 4) (src/Services/Basket/FreshCart.Basket.Api/DependencyInjection.cs)
  • Duplicated block (17 lines × 2) (src/BuildingBlocks/FreshCart.BuildingBlocks.Messaging/MassTransit/MessageBrokerExtensions.cs)
  • Duplicated block (18 lines × 2) (src/BuildingBlocks/FreshCart.ServiceDefaults/DevelopmentCertificateValidation.cs)
  • Duplicated block (18 lines × 3) (src/Services/Basket/FreshCart.Basket.Api/DependencyInjection.cs)
  • Duplicated block (18 lines × 3) (src/Services/Ordering/FreshCart.Ordering.Application/DependencyInjection.cs)
  • Duplicated block (20–21 lines × 2) (src/ApiGateways/FreshCart.Gateway.Yarp/Configuration/GatewayAuthenticationConfiguration.cs)
  • Duplicated block (22 lines × 2) (src/Services/CustomerSupport/FreshCart.CustomerSupport.Api/Authentication/ClaimsPrincipalExtensions.cs)
  • …and 283 more

Changes since last survey

  • 24 commits — 18 feature/other, 6 fixes

By area

  • (repo) — 6 commits
  • src/Services — 4 commits
  • (root) — 3 commits
  • .github/scripts — 2 commits
  • .github/workflows — 2 commits
  • src/AspireAppHost — 2 commits
  • tests/e2e — 2 commits
  • .github/labeler.yml — 1 commit
  • src/ApiGateways — 1 commit
  • src/BuildingBlocks — 1 commit

Notable commits

  • fix: Merge pull request #15 from amasen02/fix/readiness-2026-09-12-followup
  • fix: Merge pull request #17 from amasen02/fix/postal-code-validation-2026-09-13
  • fix: fix(delivery): tighten postal format matching
  • fix: fix(delivery): validate supported postal code formats
  • fix: fix(e2e): serve CI storefront over HTTPS
  • fix: fix(reporting): align API EF Core runtime with Pomelo
  • change: Merge pull request #12 from amasen02/feat/ci-pr-labeler-workflow-8
  • change: Merge pull request #13 from amasen02/docs/docker-compose-quickstart-7
  • change: Merge pull request #16 from amasen02/test/pricing-negative-discounts-2026-09-13
  • change: Pin two vulnerable transitive packages that were failing the audit gate
  • change: Wire up Trivy + Cosign image security gates, add SonarCloud quality gate (#1)
  • change: ci: add OpenSSF Scorecard supply-chain security workflow
  • change: ci: add pull request labeling workflow for community contributions (#8)
  • change: ci: make Mongo replica initialization production-tested
  • change: ci: retry Mongo replica set initialization
  • change: ci: run FreshCart E2E against ephemeral local stack (#14)
  • change: ci: update scorecard-action to v2.4.4 to resolve container image deprecation
  • change: docs(e2e): document HTTPS storefront setup
  • change: docs(security): add OpenSSF Scorecard and Best Practices badges, mirror SECURITY.md to .github
  • change: docs: add local development quickstart guide using Docker Compose (#7)
  • …and 4 more

API surface

  • Unchanged — 45 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

amasen02/freshcart-backend was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 518aab1ed09411f3916664674b4f69a1e1ae5ed2 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.