Skip to content
CAI
Software that uses CAICheck a score

Atharva-System/blazor-ecommerce

42.4

Weak · 21 September 2026

5k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a .NET-based e-commerce platform built on a clean architecture, providing a Blazor client and a RESTful API server. It manages core commerce operations including product and category management, shopping cart handling, and order processing. The application integrates with Stripe for payment processing and uses JWT-based authentication to support both standard user and administrative roles.

Features

Add and retrieve user address details

The application now supports managing user addresses. Users can add or update their address information, and the system will automatically populate the first and last name fields from the user's profile if they are missing. This includes a new command handler for saving address data and a query handler that fetches existing address details, ensuring that user profile information is used to complete address records.

src/BlazorEcommerce.Application/Features/Address · high confidence

Added Automapper profiles for core domain entities

New mapping configurations have been introduced for Address, Cart, Category, Order, Product, and ProductType entities. These profiles define bidirectional mappings between domain models and their corresponding DTOs (e.g., Address to AddressDto, Product to ProductDto), enabling automatic object-to-object conversion for these specific areas of the application.

src/BlazorEcommerce.Application/MappingProfıles · high confidence

Blazor client application with authentication, admin tools, and error handling

The Blazor client application is introduced, featuring a custom authentication state provider that manages JWT tokens in local storage and automatically attaches them to HTTP headers. The app includes a comprehensive set of pages: an index page with error boundaries, login and registration forms, a shopping cart, order history, and product details. An admin section provides interfaces for managing categories, product types, and products, as well as editing product details. The application also implements custom error pages for 404, 500, and unauthorized states, along with an HTTP interceptor service to handle API calls and exceptions.

src/Presentation/Client · high confidence

Implemented ProductType command and query handlers

Added new command handlers for creating and updating product types, along with a query handler to retrieve all product types. These handlers utilize AutoMapper for mapping between DTOs and domain entities, and interact with the command/query unit of work to persist changes or fetch data.

src/BlazorEcommerce.Application/Features/ProductType · high confidence

Initial database persistence layer and data seeding

The application now includes a complete persistence layer built on Entity Framework Core with SQL Server. This introduces the \PersistenceDataContext\ to manage database state for entities like Products, Categories, and Orders, along with an initial migration script to create the schema. The system also registers command and query repositories for all aggregate roots, enabling data access for the domain. Additionally, seed data is provided to populate initial categories, product types, and sample products, ensuring the database is ready for use upon first run.

src/BlazorEcommerce.Persistence · high confidence

Initial identity and authentication setup

The identity module has been implemented with a new database context, entity configurations, and a database initializer that applies the initial migration. This includes seeding default roles (User, Admin) and an initial admin user account. The system now supports user registration, login, and JWT-based authentication with refresh tokens.

src/BlazorEcommerce.Identity · high confidence

Initial project structure and documentation

The BlazorEcommerce solution is initialized with a clean architecture, defining projects for the Server, Client, and Shared layers in the Presentation folder, alongside Application, Domain, Infrastructure, Identity, and Persistence layers. The solution file also includes unit test projects for Domain and Application, and organizes source code under a 'src' directory with a 'Presentation' folder containing the Blazor components. A comprehensive README.md is added, detailing the app's features, technologies, and clean architecture diagrams.

(repo-wide) · high confidence

Introduce PaymentService for Stripe integration

A new PaymentService has been added to handle Stripe payment processing. The service manages the creation of checkout sessions for cart items and processes incoming Stripe webhooks to fulfill orders. Configuration for Stripe API keys and the client URL is now read from appSettings.json via IOptions, allowing these values to be externalized from the code.

src/BlazorEcommerce.Infrastructure/Service · high confidence

Introduce product and cart management capabilities

Users can now create, update, and delete products, as well as manage their shopping cart. The update operation now supports modifying product details, images, and variants, while deletion is handled via a soft-delete flag. For the cart, users can add, remove, and update item quantities, as well as place orders that clear the cart upon successful checkout. Administrators can retrieve product lists and search for products using text-based queries with pagination support.

src/BlazorEcommerce.Application/Features/Product · high confidence

Introduce server-side API controllers for Blazor Ecommerce

The server presentation layer now exposes a comprehensive set of RESTful API endpoints to support the Blazor client. New controllers have been added to handle authentication (AuthController), user identity and password management (UserController), and standard e-commerce operations including product browsing and search (ProductController), category management (CategoryController), shopping cart operations (CartController), order retrieval (OrderController), and payment processing via Stripe (PaymentController). Additionally, a CurrentUser service is provided to expose the authenticated user's identity and role claims to the application, and the application startup is configured to initialize the database and register all necessary services.

src/Presentation/Server · high confidence

Introduces domain entities and base classes for the ecommerce model

The BlazorEcommerce.Domain layer now includes foundational domain classes and entities. A new BaseAuditableEntity provides common audit fields (IsActive, IsDeleted, CreatedUtc, etc.) and a BaseEvent class implementing MediatR's INotification. New entity classes are added for Address, CartItem, Category, Image, Order, OrderItem, Product, ProductType, and ProductVariant, establishing the core data model for the application.

BlazorEcommerce.Domain · medium confidence

Introduces shared DTOs and response models for the presentation layer

The presentation layer now includes a comprehensive set of data transfer objects and response wrappers to standardize data exchange. This includes models for user authentication (AuthResponseDto, RefreshTokenRequest, UserLogin, UserRegister, UserDto), order management (OrderDto, OrderItemDto, OrderDetailsResponse), cart items, product details, and a generic ApiResponse\<T\> alongside a typed DataResponse\<T\> for consistent API responses.

src/Presentation/Shared · high confidence

New repository and unit-of-work interfaces for command and query operations

The application layer now exposes a comprehensive set of repository interfaces to support a clean architecture separation between commands (write operations) and queries (read operations). This includes base interfaces for both command and query repositories, along with specific interfaces for entities such as Address, CartItem, Category, Image, Order, OrderItem, Product, ProductType, and ProductVariant. Additionally, command and query unit-of-work interfaces are introduced to manage transactional boundaries and repository access across the application.

src/BlazorEcommerce.Application/Repositories · high confidence

Behavioural changes

Added application-layer pipeline behaviors for logging, validation, and exception handling

The application now includes three new MediatR pipeline behaviors in the Common layer: LoggingBehaviour for tracking request details, ValidationBehavior for enforcing FluentValidation rules, and UnhandledExceptionBehaviour for centralized error logging. These behaviors wrap all incoming commands and queries, ensuring consistent logging, input validation, and exception handling across the application.

src/BlazorEcommerce.Application/Common · high confidence

Added identity and payment service contracts

Introduced new interface contracts for identity and payment services. The identity layer now includes IAuthService for registration, login, and refresh token operations, alongside ICurrentUser for user context and IIdentityService for user management and password changes. Additionally, the payment domain now exposes IPaymentService for creating checkout sessions and fulfilling orders.

src/BlazorEcommerce.Application/Contracts · high confidence

Added validation for category creation

A new validation rule has been introduced for the 'Add Category' operation, ensuring that the category name is not empty and contains between 2 and 50 characters.

src/BlazorEcommerce.Application/Validations · high confidence

Application layer configured with MediatR and validation pipelines

The BlazorEcommerce.Application module now registers application services using a dependency injection setup that includes AutoMapper, FluentValidation, and MediatR. This configuration adds global using statements for shared response types, repository interfaces, and unit of work, while registering pipeline behaviors for unhandled exceptions and validation.

src/BlazorEcommerce.Application · medium confidence

Category commands and queries migrated to Mediator pattern

The application's category management logic has been refactored from a service-based approach to a Mediator pattern using C\# records and handlers. New command handlers (Add, Delete, Update) and a query handler (GetAll) have been introduced for the Category feature, each implementing the IRequestHandler interface. This change standardizes how category operations are executed, ensuring consistent API responses and leveraging the unit of work pattern for data persistence.

src/BlazorEcommerce.Application/Features/Category · medium confidence

Domain model infrastructure and role enumeration added

The domain layer now includes a generic base entity class that manages domain events, a value object base class for value-type equality, and a Role enumeration defining Manager, Admin, and Standard roles. These changes establish the foundational building blocks for the domain model, enabling consistent entity behavior and role-based identification within the application.

src/BlazorEcommerce.Domain · medium confidence

Infrastructure services and configuration bindings added

The infrastructure layer now registers key services and configuration bindings. Specifically, it configures Stripe settings and general app configuration from appSettings.json, and registers the payment service implementation.

src/BlazorEcommerce.Infrastructure · high confidence

Introduced configuration models for application settings

Added new strongly-typed configuration classes—AppConfig, JwtSettings, and StripeConfig—to the application's model layer. These classes define the structure for client URLs, JWT authentication parameters (key, issuer, audience, duration), and Stripe payment integration secrets, enabling externalized configuration via appSettings.json.

src/BlazorEcommerce.Application/Model · high confidence

Dependencies

Upgrade to .NET 7 and add new project dependencies

The application has been upgraded to .NET 7.0 across all projects, including the new BlazorEcommerce.Identity, Infrastructure, Persistence, and Domain layers. New dependencies have been added, including MediatR, FluentValidation, AutoMapper, Swashbuckle for API documentation, Stripe.net for payments, and Blazored.LocalStorage for client-side storage. The server project now references the Identity and Infrastructure projects, and the client project includes MudBlazor and HttpClientInterceptor packages.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 43 → 42 (-0.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 87 → 86 (-1.2)
  • Architecture 88 → 88 (+0.0)
  • Maturity 57 → 56 (-0.0)
  • Readiness 32 → 32 (-0.3)
  • Security 58 → 63 (+5.1)
  • Accessibility 38 → 36 (-1.6)

Resolved (18)

  • Bounded contexts not declared
  • Duplicated block (13 lines × 2) (src/Presentation/Client/Services/CategoryService/CategoryService.cs)
  • Duplicated block (20 lines × 2) (src/BlazorEcommerce.Persistence/Repositories/Queries/Base/QueryRepository.cs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent use of the letter 'i' in the word 'Profiles' within the namespace 'BlazorEcommerce.Application.MappingProfıles'. The namespace uses a Cyrillic 'і' (U+0456) instead of the Latin 'i' (U+0069). This is a critical inconsistency as it breaks the namespace path and likely causes compilation errors or reflection issues.
  • Medium CVE: Azure.Identity 1.6.0
  • Medium CVE: Azure.Identity 1.6.0
  • No exposed public API
  • Secret: generic-api-key (src/Presentation/Server/appsettings.json)
  • Secret: generic-api-key (src/Server/Services/PaymentService/PaymentService.cs)
  • Secret: generic-api-key (src/Server/Services/PaymentService/PaymentService.cs)
  • Secret: stripe-access-token (src/Presentation/Server/appsettings.json)
  • Secret: stripe-access-token (src/Server/Services/PaymentService/PaymentService.cs)
  • Secret: stripe-access-token (src/Server/Services/PaymentService/PaymentService.cs)
  • Test reliability not measured — no test run produced results
  • Typo in the query handler name: 'GetOrderDeatils' (missing 'a' in Details) compared to the repository method 'GetOrderDetails'. The handler name contains a typo.
  • single-maintainer — knowledge-concentration (bus factor) risk

New (33)

  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (src/BlazorEcommerce.Identity/Contexts/UserIdentityDbContextInitialiser.cs)
  • Duplicated block (12 lines × 2) (src/Presentation/Server/Controllers/CategoryController.cs)
  • Duplicated block (13 lines × 2) (src/Presentation/Client/Services/CategoryService/CategoryService.cs)
  • Duplicated block (16 lines × 2) (src/BlazorEcommerce.Identity/Service/AuthService.cs)
  • Duplicated block (26 lines × 2) (src/BlazorEcommerce.Persistence/Repositories/Queries/Base/QueryRepository.cs)
  • Duplicated block (36 lines × 2) (src/BlazorEcommerce.Application/Features/Cart/Query/GetCartProducts/GetCartProductsQueryHandler.cs)
  • Duplicated block (6 lines × 2) (src/BlazorEcommerce.Application/Features/Product/Query/GetProductSearchSuggestions/GetProductSearchSuggestionsQueryHandler.cs)
  • Duplicated block (7 lines × 2) (src/BlazorEcommerce.Domain/Entities/Address.cs)
  • Duplicated block (7 lines × 2) (src/Presentation/Shared/User/UserChangePassword.cs)
  • End-of-life runtime: .NET net7.0
  • High secret: WD-SECRET-0002 (src/Presentation/Server/appsettings.json)
  • High secret: WD-SECRET-0002 (src/Presentation/Server/appsettings.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/BlazorEcommerce.Persistence/Repositories/Queries/Base/QueryRepository.cs (src/BlazorEcommerce.Persistence/Repositories/Queries/Base/QueryRepository.cs)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 13 more

API surface

  • Unchanged — 35 HTTP endpoints

Architecture

  • Unchanged — 2 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Atharva-System/blazor-ecommerce was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9765f3fb8170cbb75eeb662bfe5086aff777c81b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.