babaktaremi/Clean-Architecture-Template
54.0
Adequate · 21 September 2026
4.7k
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is a .NET-based web API that provides user authentication, order management, and administrative controls. It implements a clean architecture with a CQRS pattern, exposing REST and gRPC endpoints for handling user registration, login, and order lifecycle operations. The framework standardizes API responses, manages identity and permissions via ASP.NET Core Identity, and includes infrastructure for logging, monitoring, and database persistence.
Features
Added Order management endpoints
The OrderController now exposes HTTP endpoints for creating, retrieving, updating, and deleting user orders. Users can create new orders, fetch their order history, update existing orders, and perform bulk deletion of all their orders through the API.
src/API/CleanArc.Web.Api/Controllers/V1/Order · high confidence
Added gRPC endpoints for user authentication and order retrieval
The GrpcPluginStartup class now registers and maps gRPC services for user authentication (TokenRequest, GetUserToken) and order retrieval (GetUserOrders). These new endpoints allow clients to authenticate users and fetch order data via gRPC, with the service implementations delegating to existing application features.
src/API/Plugins/CleanArc.Web.Plugins.Grpc · high confidence
Added health check and metrics configuration for monitoring
The monitoring infrastructure now includes explicit configuration for ASP.NET Core Health Checks, OpenTelemetry metrics, and Prometheus metrics. This introduces a new health check endpoint at /HealthCheck that verifies the SQL Server connection and forwards to Prometheus, while also enabling runtime, ASP.NET Core, and Kestrel metrics via OpenTelemetry and Prometheus exporters.
src/Infrastructure/CleanArc.Infrastructure.Monitoring · high confidence
Added shared kernel extension methods and validation infrastructure
Added a suite of extension methods in the shared kernel to support application logic and data access, including assembly and collection utilities, enum and string helpers (such as currency formatting and Persian character normalization), reflection helpers, and regex matching for API versions. Additionally, introduced a validation base class and a service registration extension that automatically discovers and registers FluentValidation validators via dependency injection, enabling automatic model validation for application models.
src/Shared · high confidence
Added user authentication and management commands and queries
The application now includes new features for user and admin authentication workflows. For users, this includes commands to create accounts, request phone verification codes, and refresh access tokens, as well as queries to generate tokens via phone number or password. For administrators, a new command allows adding new admins, and a query retrieves authentication tokens. These changes introduce new endpoints for user registration, password-based login, phone-based login, and admin account creation.
src/Core/CleanArc.Application/Features/Users · high confidence
CleanArcTemplate template package updated to version 10.1.3 with Docker and solution structure updates
The CleanArcTemplate NuGet package (version 10.1.3) has been updated to include Dockerfile and docker-compose.yml configurations for containerized development, alongside a revised solution structure that organizes projects into src/ and Tests/ folders. The template now supports .NET 10, includes a new monitoring project, and provides updated build and deployment configurations for easier local and containerized setup.
(repo-wide) · high confidence
Implemented user management operations via AppUserManagerImplementation
The application now exposes a comprehensive set of user management capabilities through the new AppUserManagerImplementation class. This includes creating users with or without passwords, verifying user existence by phone or username, generating and verifying OTP codes for password-less login, updating user details, managing user lockouts, and retrieving user roles. This enables core identity operations such as registration, authentication, and administrative user management.
src/Infrastructure/CleanArc.Infrastructure.Identity/UserManager · high confidence
Initial setup of CleanArc Web API with .NET 8 Minimal API and Fluent Validation
The CleanArc.Web.Api project has been initialized with a .NET 8 Minimal API structure, establishing the core application startup and configuration. This includes the addition of appsettings files for development and production environments, configuring Serilog for logging, and setting up Swagger for API exploration. The entry point (Program.cs) registers key services including health checks, OpenTelemetry, identity services, persistence, and Mapster. A significant behavioral change is the integration of Fluent Validation for request model validation, with validators configured via the DI container and a dedicated exception handler added to manage validation errors. Additionally, gRPC plugin services are configured, and the application applies database migrations and seeds default users on startup.
src/API/CleanArc.Web.Api · high confidence
Introduce BaseController for unified API response handling
Added a new BaseController class that provides helper properties to access current user identity details (name, ID, email, role, and custom data) and a generic OperationResult method to standardize success, not-found, and error responses across API controllers.
src/API/CleanArc.WebFramework/BaseController · high confidence
Introduces custom identity infrastructure and dynamic permission management
The identity layer now includes a full suite of custom ASP.NET Core Identity components, including \AppUserManager\, \AppRoleManager\, and \AppSignInManager\, alongside custom stores and validators. A new dynamic permission system has been added, featuring a \DynamicPermissionHandler\ that evaluates access based on route data and claims, supported by a \RoleManagerService\ for managing role-based permissions. Additionally, the codebase introduces custom data protection mechanisms (\LookupProtector\, \PersonalDataProtector\) and a \SeedDataBase\ service to initialize default admin roles and users.
src/Infrastructure/CleanArc.Infrastructure.Identity/Identity · medium confidence
Introduces structured API response models and application-layer behaviors
The application now includes a structured API result model (ApiResult) with status codes and request IDs, alongside an OperationResult for command handling. New pipeline behaviors have been added to the application layer: LoggingBehavior for error tracking, MetricsBehavior for request duration monitoring, and ValidateCommandBehavior for automatic FluentValidation integration. Additionally, domain entities for User, Role, and Order have been defined with corresponding repository interfaces and DTOs to support these features.
src/Core · high confidence
JWT authentication and identity services registered
The application now registers JWT-based authentication and identity services. A new JwtService implements token generation, validation, and refresh logic, while ServiceCollectionExtension wires up Identity, authorization policies, and JWT bearer authentication with specific security parameters (e.g., clock skew, audience/issuer validation).
src/Infrastructure/CleanArc.Infrastructure.Identity/ServiceConfiguration · high confidence
New Admin API endpoints for user, role, and order management
The admin API surface has been expanded with four new controllers: AdminManagerController (providing login and new admin creation), OrderManagementController (listing all orders), RoleManagerController (managing roles and their permissions), and UserManagementController (listing all users). These endpoints are versioned under /api/v1/Admin and expose the underlying CQRS commands and queries for administrative tasks.
src/API/CleanArc.Web.Api/Controllers/V1/Admin · high confidence
New User Management API Controller with Authentication Endpoints
A new User controller has been added to the V1 API, exposing endpoints for user registration, token generation, login confirmation, token refresh, logout, and password-based authentication. Each endpoint delegates to corresponding Mediator commands and queries, providing a unified interface for user management and authentication flows.
src/API/CleanArc.Web.Api/Controllers/V1/UserManagement · high confidence
Behavioural changes
Added order and role management commands and queries
Users can now create, update, and delete orders, as well as manage roles and permissions. The update and delete endpoints for orders have been added, allowing users to modify or remove their orders. Additionally, new commands and queries for role management have been introduced, enabling users to add, update, and retrieve roles and their associated permissions. These changes enhance the application's functionality by providing more control over order and role management.
src/Core/CleanArc.Application/Features/Order · high confidence
Added soft-delete support and repository methods for Orders
The persistence layer now supports soft deletion of orders. A new database migration adds an 'IsDeleted' boolean column to the 'Orders' table, and the 'OrderConfig' applies a global query filter to exclude deleted records by default. Additionally, the 'BaseAsyncRepository' now includes 'UpdateAsync' and 'DeleteAsync' methods that accept expressions, and the 'OrderRepository' implements 'UpdateAsync' and 'DeleteAsync' to expose these capabilities.
src/Infrastructure/CleanArc.Infrastructure.Persistence · high confidence
Centralized logging configuration with separate database for logs
The application now uses a dedicated database for storing logs, configured via the 'logDb' connection string. The logging setup enriches log entries with application name, environment, span context, and exception details. In non-development environments, logs are written to an MSSQL 'LogEvents' table in the 'log' schema, while development environments log to the console and a local JSON file. The configuration also includes a commented-out section for potential Elasticsearch integration.
src/Infrastructure/CleanArc.Infrastructure.CrossCutting · medium confidence
Custom exception handling via IExceptionHandler
The application now uses a custom exception handler implementing Microsoft's IExceptionHandler interface to manage error responses. For validation errors, it returns a 422 status with structured error details; for unhandled exceptions, it returns a 500 status with a generic error message. This replaces the previous middleware-based approach with a more modern, framework-integrated strategy.
src/API/CleanArc.WebFramework/Middlewares · high confidence
Standardized API response formatting and automated Swagger documentation
The framework now enforces a consistent JSON structure for all API responses, wrapping success and error states in a unified \ApiResult\ model. This is achieved through new endpoint filters (\BadRequestResultEndpointFilter\, \NotFoundResultEndpointFilter\, \OkResultEndpointFilter\) that intercept HTTP status codes and transform the output. Additionally, the Swagger/OpenAPI documentation is now automatically generated and configured with custom processors: summaries are auto-generated based on controller and action names, security requirements are applied via a \RequireTokenWithoutAuthorization\ attribute, and versioning is handled through an \ApiVersionDocumentProcessor\ that filters operations by version.
src/API/CleanArc.WebFramework/Swagger · high confidence
Standardized API response formatting via dedicated result filters
The framework now uses dedicated ASP.NET Core result filters (ApiResultFilterAttribute, BadRequestResultFilterAttribute, ContentResultFilterAttribute, NotFoundResultAttribute, OkResultAttribute, ServerErrorResult) to automatically wrap controller and action results into a consistent JSON structure. This replaces the previous approach where validation errors and other HTTP status codes were handled differently or via the removed MicroElements.FluentValidation package. Users will see a uniform API response format for success, bad request, not found, and server error states.
src/API/CleanArc.WebFramework/Filters · high confidence
Test coverage
Added unit tests for user identity and authentication flows
New unit tests have been added for the identity infrastructure, specifically covering user manager operations such as duplicate username validation, phone number confirmation, OTP code generation and verification, and access token generation. The test suite also includes setup classes for the application database context and identity services, enabling isolated testing of authentication and user management features.
src/Tests · high confidence
Dependencies
Upgrade to .NET 10 and centralize package versions
The project has been upgraded to target .NET 10, updating the \TargetFramework\ in all \.csproj\ files. Additionally, a central \Directory.Packages.props\ file has been introduced to manage package versions, including specific versions for libraries such as FluentValidation, Mapster, and various Microsoft and OpenTelemetry packages.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 56 → 54 (-2.4)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 61 → 61 (-0.4)
- Architecture 83 → 83 (+0.0)
- Maturity 59 → 56 (-3.7)
- Readiness 53 → 50 (-3.5)
- Security 55 → 54 (-0.8)
- Performance 64 → 64 (+0.0)
Resolved (39)
- Bounded contexts not declared
- Duplicated block (10 lines × 2) (src/API/CleanArc.WebFramework/Swagger/ApplySummariesOperationFilter.cs)
- Duplicated block (14 lines × 2) (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/DataProtection/LookupProtector.cs)
- Duplicated block (9 lines × 2) (src/API/CleanArc.WebFramework/Swagger/ApplySummariesOperationFilter.cs)
- High CVE: Scriban 6.2.0
- High CVE: Scriban 6.2.0
- High CVE: Scriban 6.2.0
- High CVE: Scriban 6.2.0
- High CVE: Scriban 6.2.0
- High CVE: Scriban 6.2.0
- High CVE: Scriban 6.2.0
- High CVE: Scriban 6.2.0
- High CVE: Scriban 6.2.0
- High CVE: System.Security.Cryptography.Xml 9.0.0
- High CVE: System.Security.Cryptography.Xml 9.0.0
- High CVE: System.Security.Cryptography.Xml 9.0.0
- High CVE: System.Security.Cryptography.Xml 9.0.0
- High CVE: System.Security.Cryptography.Xml 9.0.0
- High CVE: System.Security.Cryptography.Xml 9.0.0
- High CVE: System.Security.Cryptography.Xml 9.0.0
- …and 19 more
New (78)
- Ambiguous naming for user identity properties. ActionDescriptionDto uses ActionName for what is likely a user identifier or action label, while BaseController and GetUsersQueryResponse use UserName. If ActionName refers to a user, it should be UserName for consistency. If it refers to an action, the naming is consistent with its type but potentially confusing if it represents a user in other contexts.
- CRAP 30: ReflectionHelper.GetBaseTypesAndInterfaces (src/Shared/CleanArc.SharedKernel/Extensions/ReflectionExtensions.cs)
- CRAP 30: RoleManagerService.GetPermissionActionsAsync (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/PermissionManager/RoleManagerService.cs)
- CRAP 42: LookupProtector.ByteArraysEqual (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/DataProtection/LookupProtector.cs)
- CRAP 42: PersonalDataProtector.ByteArraysEqual (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/DataProtection/PersonalDataProtector.cs)
- CRAP 42: ServiceCollectionExtension.RegisterIdentityServices (src/Infrastructure/CleanArc.Infrastructure.Identity/ServiceConfiguration/ServiceCollectionExtension.cs)
- CRAP 56: ValidatorExtensions.RegisterValidatorsAsServices (src/Shared/CleanArc.SharedKernel/Extensions/ValidatorExtensions.cs)
- CRAP 72: RoleManagerService.ChangeRolePermissionsAsync (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/PermissionManager/RoleManagerService.cs)
- CommentedOutCode (src/Infrastructure/CleanArc.Infrastructure.CrossCutting/Logging/LoggingConfiguration.cs)
- Dead code: GetAllOrdersQueryResultMapping (src/Core/CleanArc.Application/Features/Order/Queries/GetAllOrders/GetAllOrdersQueryResult.cs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (src/API/CleanArc.WebFramework/Swagger/ApplySummariesOperationFilter.cs)
- Duplicated block (18 lines × 2) (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/DataProtection/LookupProtector.cs)
- Duplicated block (32–35 lines × 2) (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/DataProtection/LookupProtector.cs)
- Duplicated block (41 lines × 2) (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/DataProtection/LookupProtector.cs)
- Duplicated block (6 lines × 2) (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/DataProtection/LookupProtector.cs)
- Duplicated block (7 lines × 2) (src/Infrastructure/CleanArc.Infrastructure.Identity/Identity/DataProtection/LookupProtector.cs)
- Duplicated block (9 lines × 2) (src/API/CleanArc.WebFramework/Filters/BadRequestResultFilterAttribute.cs)
- Duplicated block (9 lines × 2) (src/API/CleanArc.WebFramework/Swagger/ApplySummariesOperationFilter.cs)
- …and 58 more
API surface
- Unchanged — 20 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
babaktaremi/Clean-Architecture-Template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 450c680b3c0b80ca545c1ccdbaeb79bd476ea2e8 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.