Skip to content
CAI
Software that uses CAICheck a score

antoinechalifour/remix-hexagonal-architecture

56.9

Adequate · 4 August 2026

6.9k

lines of production code

TypeScript

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a collaborative task management application that allows users to create, organize, and share todo lists with others. It provides full authentication flows, including registration, verification, and password recovery, while supporting real-time updates via Server-Sent Events. The backend is built on a dual-framework architecture using NestJS for business logic and Remix for the frontend, with Prisma managing a PostgreSQL database that tracks permissions, events, and list ordering.

Features

Add Remix request parameter decorators and error mapping utilities

New decorators are introduced to simplify handling of request data in Remix data functions. The Body, Params, and Query decorators allow methods to automatically parse and validate request payloads, parameters, and query strings using class-validator and class-transformer, returning structured error responses when validation fails. Additionally, MapErrorThrowing and MapErrorReturning decorators provide a way to map specific error types to custom JSON responses with defined HTTP status codes, improving error handling consistency across the application.

src/web/remix/decorators · high confidence

Add SSE endpoint for real-time todo list updates

A new Server-Sent Events (SSE) endpoint is now available at /events/l/:todoListId, allowing clients to subscribe to real-time updates for a specific todo list. The implementation includes a 30-second heartbeat to prevent connection timeouts and filters events to ensure clients only receive updates relevant to their subscribed list.

src/web/controllers · high confidence

Add todo list route with drag-and-drop and state management

A new route at /$todoListId renders the TodoList component, providing the page structure for managing a specific todo list. The implementation integrates Recoil for state management and react-dnd (with HTML5Backend) to enable drag-and-drop functionality within the list. The page also defines a loader to fetch todo list details and an action to add new todos.

app/routes/l · high confidence

Added Cypress end-to-end test suite for the todo list feature

The project now includes a new Cypress-based end-to-end test suite. This adds automated tests for the 'managing a todo list' user flow, including creating lists, adding and completing todos, and logging in. The test setup includes a fixture for mock data, custom Cypress commands for login and interaction, and a plugin configuration file, enabling reliable E2E testing for the application's core functionality.

cypress · high confidence

Added array utility for reordering items

A new shared library module was introduced to provide array manipulation capabilities. Specifically, the codebase now includes an \array.ts\ file exporting a \moveArrayItem\ function that allows users to reorder items within an array by specifying the current and new indices. This utility is now available for import via the \src/shared/lib\ entry point.

src/shared/lib · high confidence

Added authentication and account management routes

Users can now access dedicated pages for logging in, registering, resetting passwords, verifying accounts, and a welcome page. Each route exposes the necessary loader and action hooks to the application context, enabling the corresponding authentication flows.

app/routes · high confidence

Domain model and event system for todo lists

The domain layer now includes full domain models for Todo and TodoList, including logic for reordering, title updates, and tag management (with a 3-tag limit). A new Contributor model and TodoListPermission system enforce access control, allowing owners and contributors to perform actions like archiving, editing, and sharing. Additionally, a comprehensive set of domain events (e.g., TodoReordered, TodoListAccessGranted) is introduced to track state changes.

src/todo-list-manager/domain · high confidence

Email notifications for account verification, password reset, and password changes

The application now sends automated emails to users for key authentication events. A welcome email with an account verification link is sent upon registration, a password reset email is sent when a user requests a password reset, and a notification email is sent when a user's password is successfully changed. These changes are implemented via the new \AuthenticationEventsConsumer\ which listens to domain events and triggers the appropriate email templates.

src/authentication/application · high confidence

Implemented core authentication infrastructure and password reset capabilities

Added the AccountDatabaseRepository to handle account persistence, including support for verified and unverified account states, password reset tokens, and case-insensitive email lookups. Introduced BCryptPasswordHasher for secure password hashing and verification. Added FetchAuthenticationStatusSessionQuery to expose the current authentication status to the user.

src/authentication/infrastructure · high confidence

Initial app shell and error handling

The app now includes a complete root layout with a favicon, accessibility-friendly route change announcements, and dedicated error pages for 404 and unexpected errors. The entry points for client and server rendering have been established, and a date formatting utility has been added.

app · high confidence

Initial project scaffolding and configuration

The repository was initialized with essential configuration files to support a dual-framework (Remix and Nest.js) architecture. This includes environment variables for database and session secrets, ESLint rules for code quality, TypeScript and Jest configurations for the test suite, and Tailwind CSS settings for styling. Additionally, Docker and Heroku deployment files (Dockerfile, Procfile, docker-compose.yml) were added to streamline local development and production deployment.

(repo-wide) · high confidence

Introduce ApplicationModule to centralize web-layer dependency injection

A new ApplicationModule has been added to src/web to serve as the central configuration point for the web tier. It registers controllers, providers, and infrastructure services (such as the mailer, session configuration, and Remix handlers) within a single NestJS module, effectively wiring together authentication, todo-list management, and Remix-specific components.

src/web · high confidence

Introduce Remix-based web layer with authentication and session management

Added a new Remix application layer in src/web/remix that bridges NestJS to the frontend via Actions and Loaders. This introduces session-based authentication (Authenticated decorator, SessionManager) and exposes endpoints for login, registration, password reset, account verification, and todo list management. The controller routes all requests through the Remix handler, making the web interface functional for user flows.

src/web/remix · high confidence

Introduce dedicated components for todo list management and sharing

The application now features a dedicated Sharing area with new components for managing collaborators, including a ContributorPin for displaying user avatars and a ManageContributors list that shows each collaborator's email and role, with the ability to revoke access. A ShareButton and ShareTodoListForm allow owners to invite new contributors via email. Additionally, the TodoList area now includes components for adding new todos, filtering by tags, displaying the list completion progress, and rendering the todo list header with title editing and contributor pins.

app/todolist/Sharing · high confidence

Introduce email sending infrastructure with SendGrid integration

The application now includes a new mail subsystem in src/shared/mail that defines a Mailer interface and a concrete SendGridMailer implementation. Users will be able to receive password-change notifications via email, as the system is configured to send emails using SendGrid templates. A FakeMailer is also provided for testing or non-production environments.

src/shared/mail · high confidence

Introduce shared ID generation abstraction

A new shared module for ID generation has been added to the codebase. It defines a GenerateId interface and provides two implementations: GenerateUUID, which produces standard UUIDs using the uuid library, and GenerateTestId, which generates sequential test IDs with a configurable prefix. The module is exported via an index file to centralize access to these generators.

src/shared/id · high confidence

Introduce shared client DTOs for todo lists, home page, and authentication

Added new TypeScript data-transfer objects in src/shared/client to define the structure of API responses. This includes TodoListDetailsDto, TodoListContributorDto, and TodoListPageDto for list and contributor details; HomePageDto for the home page summary; TodoDto with DoneTodos and DoingTodoDto variants; and AuthenticationErrorDto. These types enable the client to correctly parse and display todo lists, user permissions, completion status, and authentication errors.

src/shared/client · high confidence

Introduce time abstraction for clock operations

A new time abstraction has been added to the shared utilities, defining a Clock interface with a now() method. This includes a RealClock implementation that returns the current system time and a FixedClock implementation that returns a static, configurable date, enabling more predictable behavior in time-dependent code.

src/shared/time · high confidence

Introduced Prisma database integration with NestJS dependency injection

Added new files to the shared database module to integrate Prisma with the application's dependency injection system. The \Prisma\ class now extends \PrismaClient\ and implements \OnModuleInit\ to handle connection lifecycle, while \PrismaRepository\ provides an abstract base class for repository implementations, including a helper to detect unique constraint failures. These components are re-exported via the \src/shared/database/index.ts\ barrel file.

src/shared/database · high confidence

Introduced new authentication use cases for login, registration, password reset, and account verification

The src/authentication/usecase directory now contains five new use-case classes: LoginFlow for authenticating users, RegisterFlow for creating new accounts, ForgotPassword and ResetPassword for managing password recovery, and VerifyAccount for confirming new registrations. Each class encapsulates the specific business logic and domain interactions required for that part of the authentication flow.

src/authentication/usecase · high confidence

Introduces database persistence and query layers for todo lists, todos, and permissions

The application now stores and retrieves todo list data, individual todos, and access permissions via a new set of database repositories and a dedicated query class. This enables saving and loading todo lists and their associated todos (including tags and completion status), persisting and querying permission records for list owners and contributors, and executing complex database queries to fetch list details, summaries, and sorted todo items. This change shifts the system from in-memory or external storage to a structured database-backed architecture for core todo list management.

src/todo-list-manager/infrastructure · high confidence

New UI component library and layout structure

The app's user interface has been refactored into a new set of reusable React components, including Button, CheckboxOption, Dialog, EditableContent, FloatingLabelInput, Popover, and Tooltip, many of which are built on top of the Radix UI library. A new RootLayout component introduces a sticky header with a logo and logout link, while a SkipToContent link is added for accessibility. These changes provide a consistent visual style and improved interactivity across the application.

app/ui · high confidence

New authentication form components and templates

The authentication area now includes dedicated React components for each step of the user journey: a login form with error handling and spinner states, a registration form with password confirmation logic, a forgot-password form, a reset-password form with hidden token/email fields, and an info-page template used for welcome, account verification success, and verification error states. These components introduce a consistent card-based UI with floating-label inputs, notification banners, and client-side password matching, providing a unified and mobile-friendly authentication experience.

app/authentication · high confidence

New validation DTOs for Remix endpoints

The \src/web/remix/dtos\ directory now contains a set of new TypeScript classes that define input validation rules for various application endpoints. These include data transfer objects for user authentication (Login, Register, ForgotPassword, ResetPassword, VerifyAccount), todo list management (CreateTodoList, UpdateTodoListTitle, ArchiveTodoList), and individual todo operations (AddTodo, UpdateTodoTitle, MarkTodo, ReorderTodo, DeleteTodoFromTodoList). Each DTO enforces constraints such as email format, string length limits, and required fields, ensuring that incoming requests are validated before processing.

src/web/remix/dtos · high confidence

Refactored TodoItem into modular components with drag-and-drop reordering

The TodoItem component has been refactored into a set of smaller, focused components (EditTodoTitle, TodoTags, TodoPopoverMenu, etc.) to improve code organization. Additionally, a new ReorderableTodoItem wrapper was introduced, enabling users to drag and drop todo items to reorder them within the list.

app/todolist/TodoItem · high confidence

Todo list management with collaboration and event tracking

Users can now create, edit, and manage todo lists and individual todos, including adding/removing tags, reordering items, marking tasks as done, and updating titles. The system enforces strict permission checks, allowing only owners or authorized contributors to modify lists. Collaboration features allow owners to grant or revoke access for other users, with role-based permissions controlling actions like archiving or sharing. Each action triggers specific domain events (e.g., TodoListCreated, TodoUpdated, TagAddedToTodo), enabling external systems to react to changes. The home page displays both owned and contributed lists, showing completion percentages and allowing users to leave or archive lists based on their role.

src/todo-list-manager/usecase · high confidence

Behavioural changes

Account verification status handling updated

The system now supports registering unverified accounts. The database schema was updated to include a 'verificationToken' and a 'verified' boolean column on the Account table. Subsequently, the default value for the 'verified' column was removed, allowing accounts to be created in an unverified state rather than defaulting to verified.

_prisma/migrations/20220521090745\_add\_account\_verification, prisma/migrations/20220521090857\_remove\_default\_verification\status · high confidence

Authentication module restructured with explicit public API exports

The authentication module now exposes a consolidated public API via index.ts, re-exporting core components such as the AuthenticationApplicationService, Authenticator, FetchAuthenticationStatus, and various error types. This change organizes the module's public interface, making it easier for other parts of the application to import and use authentication-related services and domain objects.

src/authentication · high confidence

Consolidate todo and todo-list operations into dedicated application services

The application layer now uses separate \TodoApplicationService\ and \TodoListApplicationService\ classes to handle their respective domains. \TodoApplicationService\ manages individual todo operations such as adding, deleting, marking as complete, updating titles, and managing tags. \TodoListApplicationService\ handles todo-list level operations including creation, archiving, title updates, reordering, and access management (granting/revoking contributor access). Both services coordinate database transactions and event publishing through shared infrastructure components.

src/todo-list-manager/application · high confidence

Database schema expanded to support task ordering, permissions, and activity logging

The Prisma schema and database migrations have been updated to support new product capabilities. The 'Todo' model now includes 'tags' (JSONB) and a 'doneAt' timestamp for completion tracking. 'TodoList' gains a 'todosOrder' field to persist UI drag-and-drop reordering. A new 'TodoListPermission' table replaces the previous 'ownerId' columns on 'Todo' and 'TodoList' with a dedicated permissions model, adding a 'contributorsIds' field to support collaborator roles. Additionally, a 'TodoListEvent' table is introduced to log published events for each list, and the 'Account' model is extended with 'verified', 'verificationToken', 'passwordResetToken', and 'passwordResetExpiration' fields to support registration and password reset flows.

prisma · high confidence

Enable Fast Refresh in Recoil for SSR warning reduction

The project now applies a patch to the Recoil library (version 0.7.3) that enables Fast Refresh support. This change modifies the \isFastRefreshEnabled\ function across multiple build targets (CommonJS, ES, Native, UMD) to return \true\ instead of \false\, which helps suppress related server-side rendering warnings.

patches · medium confidence

Expose Todo List Manager Public API

The src/todo-list-manager/index.ts file has been added to serve as the public entry point for the todo-list-manager module. It re-exports key application services (TodoListApplicationService, TodoApplicationService), domain error classes (TodoListNotFoundError, TodoListPermissionDeniedError, ContributorNotFoundError), and infrastructure components (TodoListDatabaseRepository, TodoDatabaseRepository, TodoListPermissionsDatabaseRepository, TodoListDatabaseQuery, ContributorsAdapter), making these internal implementations accessible to consumers of the module.

src/todo-list-manager · high confidence

Extracted route actions into dedicated files

The route handlers for the todo list and individual todo items have been refactored into separate files (e.g., archive, grant-access, reorder-todo, revoke-access, add-tag, delete, remove-tag, mark, and update). Each file now exports a specific action function that delegates to the corresponding method in the application context, improving code organization and separation of concerns.

app/routes/l/$todoListId · high confidence

Introduce configurable session management and application bootstrap

The application now initializes the NestJS server via a new \src/main.ts\ entry point, which configures session handling (including a configurable secret via \process.env.SESSION\_SECRET\) and registers the Remix handler path. Additionally, \src/keys.ts\ introduces specific symbols for dependency injection, including session configuration, authenticator, and Remix-related components, supporting the new session management architecture.

src · medium confidence

Introduce domain models and error types for account verification and password reset

The authentication domain now includes new domain models for account states (unverified, verified, and forgot-password) along with a repository interface to persist them. It also introduces specific error types for account verification, password reset token validity, and credential validation, as well as domain events for user registration, password changes, and forgotten passwords.

src/authentication/domain · medium confidence

Introduce structured event system with automatic ID and timestamp generation

The shared events module has been refactored to provide a standardized event structure. Each event now automatically generates a unique ID and records the publication timestamp. The system includes a base Event class and an Events interface, along with specific implementations for NestJS (NestEvents) and testing/collection (CollectEvents), ensuring consistent event handling across the application.

src/shared/events · high confidence

New global styles and focus ring implementation

The application now uses Tailwind CSS for utility classes and defines global styles for the Metropolis font family. Additionally, a focus-visible ring is applied to all elements to improve keyboard navigation accessibility.

styles · medium confidence

Redesign of the homepage layout and components

The homepage has been restructured into new components: a form for adding new todo lists (AddTodoListForm), a section for displaying existing lists (TodoListsSection), and individual list items (TodoListItem) that include an archive button and modification date. The page now explicitly separates owned lists from those shared with the user, each with its own header and empty state message.

app/homepage · high confidence

Removed completed todos from order lists

The database schema has been updated to automatically remove completed todos from the 'todosOrder' field in TodoList records. This migration restructures the order of items in each list to only include active (non-completed) todos, ensuring that completed items no longer appear in the ordered sequence.

_prisma/migrations/20220604185050\_remove\_complete\_todos\_from\order · medium confidence

Replaced custom state management with Recoil and added stale-list notifications

The todo list application now uses the Recoil library for state management, consolidating logic into a new \state.ts\ file that manages todos, filters, and contributors. This enables a new 'stale' state: when the list is outdated, a \TodoListOutdatedMessage\ component appears at the bottom of the page, prompting the user to click to refresh the data. Additionally, the \TodoList\ component has been restructured to use these new hooks, and a \TodoTag\ component was added for rendering tags.

app/todolist · high confidence

Test coverage

Added domain tests for authentication use cases; Added integration tests for todo-list-manager persistence layer; Added test fakes and builders for authentication domain; Added tests for todo list management use cases.

Dependencies

Initial project setup with NestJS, Remix, and Prisma

The project's \package.json\ and \yarn.lock\ files were added, establishing the initial dependency graph. This includes the core framework libraries NestJS and Remix (v1.5.1), the Prisma ORM client (v3.8.1) for PostgreSQL, and UI libraries like Radix UI and React DnD. The configuration also introduces build scripts for the front-end and back-end, test runners for Jest and Cypress, and tooling for linting and type-checking.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 28 → 57 (+28.7)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

Lenses

  • Code Health 92 (new)
  • Architecture 86 (new)
  • Maturity 13 → 46 (+32.7)
  • Readiness 15 → 61 (+45.9)
  • Security 100 → 64 (-36.5)
  • Domain Modelling 100 (new)
  • Accessibility 62 (new)

Resolved (6)

  • Dependency hygiene not measured — no supported dependency manifest was read
  • No automated tests
  • No tests found
  • bus factor not measured — no commits were sampled
  • early-stage repository — too little history to judge knowledge freshness
  • single-commit history — no usable git history window to measure hotspots

New (80)

  • Boundary-crossing change coupling: $todoListId.tsx ↔ AddTag.tsx (app/routes/l/$todoListId.tsx)
  • Boundary-crossing change coupling: AddTodoForm.tsx ↔ CheckboxOption.tsx (app/todolist/TodoList/AddTodoForm.tsx)
  • Boundary-crossing change coupling: AddTodoListForm.tsx ↔ AddTodoForm.tsx (app/homepage/AddTodoListForm.tsx)
  • Boundary-crossing change coupling: AddTodoListForm.tsx ↔ TodoItem.tsx (app/homepage/AddTodoListForm.tsx)
  • Boundary-crossing change coupling: TodoItem.tsx ↔ Button.tsx (app/todolist/TodoItem/TodoItem.tsx)
  • Boundary-crossing change coupling: TodoListItem.tsx ↔ AddTodoForm.tsx (app/homepage/TodoListItem.tsx)
  • Boundary-crossing change coupling: TodoListItem.tsx ↔ TodoItem.tsx (app/homepage/TodoListItem.tsx)
  • Change coupling: AddTag.tsx ↔ TodoItem.tsx (app/todolist/TodoItem/Popover/AddTag.tsx)
  • Change coupling: TodoItem.tsx ↔ Todos.tsx (app/todolist/TodoItem/TodoItem.tsx)
  • Change coupling: UpdateTodoListTitle.ts ↔ UpdateTodoTitle.ts (src/todo-list-manager/usecase/UpdateTodoListTitle.ts)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • …and 60 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

antoinechalifour/remix-hexagonal-architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 4 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit df94d98bcccf5b4d87aa5792ac8642e7b3816f5d — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.