BenGorUser/User
55.9
Adequate · 20 September 2026
6.2k
lines of production code
PHP
primary language
4
measurements over time
What this system is
BenGorUser is a PHP library implementing a domain-driven design architecture for user management, supporting operations such as registration, authentication, role management, and account lifecycle handling. It provides a command-query separation pattern for application logic, along with domain events for side effects like email notifications and token generation. The system includes infrastructure abstractions for persistence and security, allowing for flexible implementation of user storage and password encoding.
Features
Added UserCommandBus interface for command execution
A new UserCommandBus interface has been introduced in the infrastructure layer to define the contract for executing user-related commands. This interface specifies a handle method, allowing the application to dispatch commands through a standardized abstraction within the BenGorUser package.
src/BenGorUser/User/Infrastructure/CommandBus · high confidence
Initial project scaffolding and configuration for BenGorUser v0.8.1
This change establishes the foundational configuration files for the BenGorUser library, including \.editorconfig\ for consistent code formatting, \.php\_cs\ and \.phpspec\_cs\ for PHP-CS-Fixer rules, and \.travis.yml\ to define the CI environment supporting PHP 5.5 through 7.1. It also introduces standard project documentation and metadata files such as \README.md\, \CHANGELOG.md\, \UPGRADE.md\, \LICENSE\, and \.gitignore\, setting the stage for the v0.8.1 release which includes features like invitation registration and token purging.
(repo-wide) · high confidence
Introduce UserDTODataTransformer for serializing user domain models
Added a new \UserDTODataTransformer\ class and its \UserDataTransformer\ interface in the application layer to convert \User\ domain objects into structured arrays. The transformer extracts specific user attributes including ID, email, roles, timestamps, and various tokens (confirmation, invitation, and password reset), while safely handling null values for optional fields like password and salt. This change provides a standardized mechanism for serializing user data for API responses or internal transfers.
src/BenGorUser/User/Application/DataTransformer · high confidence
New query handlers for retrieving users by ID, email, and tokens with expiration checks
The application layer now includes dedicated query handlers to retrieve user data by ID, email, invitation token, and remember-password token. These handlers use the user repository to fetch the corresponding user and transform the result for consumption. Notably, the invitation token and remember-password token queries now validate token expiration, throwing a UserTokenExpiredException if the token has expired, in addition to throwing UserDoesNotExistException if the user is not found. The underlying query objects have been refactored from domain events to simple data carriers holding the specific lookup key (ID, email, or token).
src/BenGorUser/User/Application/Query · high confidence
Removals
Removal of Doctrine user repository and password encoder implementations
The Doctrine-based user repository and the BCrypt and SHA-512 password encoder implementations have been removed from the infrastructure layer. This eliminates the existing persistence strategy for user data and the specific password hashing mechanisms, requiring users to adopt alternative implementations for these core functionalities.
Infrastructure · high confidence
Removal of empty application services and password-reset event subscriber
The application layer has removed several placeholder service classes (EditUserProfileService, LogOutUserService, RememberPasswordUserService, RemoveUserService, and ViewUserProfileService) that contained no implementation logic. Additionally, the domain event subscriber responsible for handling password-reset requests (UserRememberPasswordRequestedSubscriber) has been deleted, removing the automatic email notification capability for forgotten passwords.
Application, Domain · high confidence
Behavioural changes
Domain model refactoring: new factories and event bus interface
The domain layer in src/BenGorUser/User/Infrastructure/Domain now includes a new UserEventBus interface for publishing domain events, a UserFactorySignUp implementation for creating users via sign-up with roles, and a refactored UserFactoryInvite (renamed from SwiftMailerUserMailer) that now builds invited users with roles instead of sending emails directly.
src/BenGorUser/User/Infrastructure/Domain · high confidence
Refactored user management into a command-based application layer
The application layer for user management has been restructured from a service-oriented approach to a command-handler pattern. This change introduces dedicated command and handler classes for key operations including user sign-up (with and without confirmation, and by invitation), password changes (with and without old password, and via remember-password token), role management (granting and revoking roles), user invitations (sending and resending), account enabling, logout, user removal, and purging outdated invitation and remember-password tokens. This provides a more explicit and structured way to handle user-related actions within the system.
src/BenGorUser/User/Application/Command · high confidence
Replaced Mandrill emailer with plain URL generator
The infrastructure component previously responsible for sending emails via Mandrill has been repurposed into a simple URL generator. Instead of integrating with the Mandrill API to send messages, the class now accepts a base URL string and generates final URLs by substituting a provided token into a placeholder. This removes the external email dependency for this specific component and shifts its behavior to static string manipulation.
src/BenGorUser/User/Infrastructure/Routing · high confidence
User domain model refactored with explicit event-driven mailers and stricter role validation
The User domain model has been restructured to decouple side effects from the core entity. The User class no longer publishes events directly; instead, it records them in an aggregate root, which are then handled by new dedicated subscribers (UserInvitedMailerSubscriber, UserRegisteredMailerSubscriber, UserRememberPasswordRequestedMailerSubscriber) that trigger email notifications. Additionally, the UserRole value object now strictly enforces that roles are strings, throwing UserRoleInvalidException for non-string inputs, and the domain now includes specific exceptions for token expiration and invalid IDs.
src/BenGorUser/User/Domain · high confidence
User repositories now support optional event publishing and token-based lookups
The SQL and InMemory user repositories have been refactored to make the UserEventBus optional; if an event bus is provided, domain events are automatically published when users are persisted or removed, but the system functions correctly without it. Additionally, the repositories now support finding users by confirmation, invitation, and remember-password tokens, replacing the previous single confirmation token lookup and removing the generic query specification method. The InMemory repository has also been moved to a new namespace and simplified its internal structure.
src/BenGorUser/User/Infrastructure/Persistence · high confidence
Test coverage
Added PhpSpec tests for User domain model value objects; Added PhpSpec tests for user domain events; Added dummy password encoder for testing; Added specs for user application command handlers; Added specs for user factory classes and URL generator; Added specs for user mailer event subscribers; Added specs for user query handlers and queries; Added tests for UserDTODataTransformer; Removed obsolete PhpSpec test for User domain model.
Dependencies
Package renamed and PHP version requirements updated
The library has been renamed from 'bengor/user' to 'bengor-user/user' and its minimum PHP requirement has been raised to version 5.5 or 7.0, dropping support for PHP 5.4. The 'carlosbuenosvinos/ddd' dependency has been removed, and development tools have been updated to use 'friendsofphp/php-cs-fixer' version 2.0 along with 'phpspec' version 2.5. Additionally, the autoloading namespace has changed to 'BenGorUser\\User\\' pointing to the 'src' directory, and a branch alias for version 1.0.x-dev has been added.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 58 → 56 (-2.2)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 98 → 99 (+0.2)
- Architecture 100 → 95 (-4.6)
- Maturity 50 → 50 (+0.0)
- Readiness 39 → 36 (-3.4)
- Security 100 → 100 (+0.0)
Resolved (8)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (14–15 lines × 2) (src/BenGorUser/User/Application/Command/SignUp/SignUpUserHandler.php)
- No exposed public API
- Test reliability not included
- The README mentions a 'Gitt' contribution section but never explains how to submit patches or what review process applies. (README.md)
- The top-level 'Usage' outline lists Sign up with confirmation but no other usage docs. (docs/index.md)
- dormant codebase — no living knowledge left to concentrate
New (13)
- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicate intent: Two distinct transformer types with identical method signatures (write, read) and nearly identical names. It is unclear if UserDTODataTransformer is a legacy artifact, a specific implementation for a different DTO structure, or a redundant abstraction.
- Duplicated block (13 lines × 3) (src/BenGorUser/User/Domain/Event/UserInvitedMailerSubscriber.php)
- Duplicated block (19 lines × 2) (src/BenGorUser/User/Application/Command/SignUp/SignUpUserHandler.php)
- Duplicated block (27 lines × 3) (src/BenGorUser/User/Domain/Model/Event/UserEnabled.php)
- Duplicated block (38 lines × 2) (src/BenGorUser/User/Domain/Model/Event/UserInvitationTokenRegenerated.php)
- Duplicated block (44 lines × 2) (src/BenGorUser/User/Application/Command/SignUp/SignUpUserCommand.php)
- Duplicated block (8 lines × 2) (src/BenGorUser/User/Application/Query/UserOfEmailHandler.php)
- Duplicated block (9 lines × 2) (src/BenGorUser/User/Application/Command/PurgeOutdatedTokens/PurgeOutdatedInvitationTokensUserHandler.php)
- No dependency advisory monitoring
- bus factor 1 — one contributor carries this repository
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
BenGorUser/User was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 734900f463042194502191e4fb3e4f588cb7bf6f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.