Skip to content
CAI
Software that uses CAICheck a score

amitshekhariitbhu/go-backend-clean-architecture

54.4

Adequate · 20 September 2026

1.1k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based backend service that manages user authentication and task tracking using a MongoDB database. It implements a layered architecture with distinct domain, use case, and repository components to handle JWT-based login, profile management, and CRUD operations for tasks. The application exposes these capabilities through a Gin HTTP API, enforcing security via middleware and decoupling business logic from data persistence.

Features

Added usecase layer for authentication, profile, and task management

This change introduces the usecase layer, implementing business logic for user authentication (login, signup, refresh tokens), profile retrieval, and task management. The new files define specific usecases (Login, Profile, RefreshToken, Signup, Task) that orchestrate interactions with domain repositories and token utilities, enforcing context timeouts for all operations. Additionally, unit tests were added for the Task usecase to verify successful fetches and error handling.

usecase · high confidence

Initial application bootstrap and MongoDB connection setup

The application now initializes its environment configuration and establishes a connection to MongoDB at startup. The bootstrap package loads settings from a .env file using Viper, constructs a MongoDB URI (supporting both authenticated and unauthenticated connections based on the presence of credentials), and connects to the database with a 10-second timeout and ping verification. It also provides a method to cleanly close the database connection when the application shuts down.

bootstrap · high confidence

Initial domain layer definitions and test mocks

The domain layer now defines core entities and interfaces for user authentication, profile management, and task handling. This includes request/response structures for login, signup, and refresh-token flows, along with domain models for User, Profile, and Task (stored in MongoDB collections). It also introduces use-case interfaces (LoginUsecase, SignupUsecase, RefreshTokenUsecase, ProfileUsecase, TaskUsecase) and repository interfaces (UserRepository, TaskRepository) to decouple business logic from infrastructure. Additionally, autogenerated mocks for these interfaces are provided to support unit testing.

domain · high confidence

Initial repository layer for user and task persistence

This change introduces the repository layer, adding \task\_repository.go\ and \user\_repository.go\ to handle data access for tasks and users via MongoDB. The task repository provides methods to create tasks and fetch them by user ID, while the user repository supports creating users, fetching all users (excluding passwords), and retrieving users by email or ID. A test file (\user\_repository\_test.go\) is also added to verify the user repository's create functionality using mocked database interfaces.

repository · high confidence

Introduce JWT-based authentication and new API endpoints

The API now supports user registration, login, and profile retrieval through new controllers and route definitions. Authentication is enforced via a JWT middleware that validates access tokens and injects the user ID into the request context for protected routes like profile and task management. Users can now sign up, log in to receive access and refresh tokens, and manage their tasks and profile data securely.

api · high confidence

MongoDB integration layer and test mocks added

This change introduces the core MongoDB database abstraction for the application. The \mongo/mongo.go\ file defines interfaces for \Client\, \Database\, \Collection\, \Cursor\, and \SingleResult\, along with concrete implementations that wrap the official \go.mongodb.org/mongo-driver\. It also includes a \nullawareDecoder\ to handle BSON null values gracefully during decoding. Additionally, autogenerated mock implementations for these interfaces are provided in \mongo/mocks/\ to support unit testing of components that depend on the database layer.

mongo · high confidence

Behavioural changes

Added internal JWT token generation and validation utilities

The internal package now includes a new \tokenutil\ module that provides functions to create access and refresh tokens using JWT (HS256), as well as methods to validate token authorization and extract user IDs from tokens. This change introduces the underlying cryptographic logic for JWT handling but does not yet expose a user-facing authentication flow or middleware integration in this location.

internal · high confidence

Introduce new application entry point and routing setup

The application now uses a new main entry point in cmd/main.go that initializes the environment, connects to the MongoDB database, and sets up the Gin HTTP server. This entry point delegates route configuration to the route.Setup function, replacing the previous routeV1 implementation.

cmd · high confidence

Dependencies

Initial dependency setup for Go backend

The project initializes its Go module dependencies, adding the Gin web framework (v1.8.2) for HTTP routing, the JWT library (v4.4.3) for authentication, the MongoDB driver (v1.11.1) for database access, and Viper (v1.14.0) for configuration management. The diff also includes the testify library (v1.8.1) for testing and a set of indirect dependencies required by these core packages.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 55 → 54 (-1.0)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 100 (+0.8)
  • Architecture 100 → 69 (-31.0)
  • Maturity 76 → 79 (+2.5)
  • Readiness 17 → 27 (+9.2)
  • Security 99 → 91 (-7.3)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (9)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (8–9 lines × 2) (internal/tokenutil/tokenutil.go)
  • No exposed public API
  • Test reliability not included
  • The README is a sincere personal reflection of the author's process and motivations but never actually describes the API endpoints or the full clean-architecture layering (e.g., how each package maps to the domain). (README.md)
  • complexity unreadable for .go — churn × complexity hotspots could not be measured
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness

New (24)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Deprecated module: go.mongodb.org/mongo-driver
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (5 lines × 2) (usecase/login_usecase.go)
  • Duplicated block (6 lines × 2) (internal/tokenutil/tokenutil.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2023-2041 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yaml)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0010 (Dockerfile)
  • No ADRs found
  • Outdated: github.com/gin-gonic/gin
  • …and 4 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

amitshekhariitbhu/go-backend-clean-architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 8a8bf00d4936b325baed89ceb631faae3122d1b5 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.