Skip to content
CAI
Software that uses CAICheck a score

bush1D3v/tsbank_api

55.5

Adequate · 21 September 2026

2.6k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a backend service for managing user accounts and financial transactions. It provides APIs for user registration, authentication, and profile management, alongside endpoints for processing various financial operations such as deposits, withdrawals, PIX transfers, and card payments. The architecture is structured around distinct layers for routing, validation, business logic, and data access, all secured with JWT-based authentication.

Features

Add HTTP status error handling utilities

Introduces a new error handling module in src/error. It adds a custom HttpStatusError class that carries an HTTP status code, and a handleError function that uses it to format JSON error responses for Express, falling back to a generic 500 error for unhandled cases. The index file exports these components for easy import.

src/error · high confidence

Add authentication middleware for user verification

A new authentication middleware has been introduced in the \src/middlewares/auth\ directory. This middleware extracts the token from the request, retrieves the corresponding user, and verifies the user's existence. If the user is not found or an error occurs, a 401 Unauthorized response is returned; otherwise, the request proceeds to the next handler.

src/middlewares/auth · high confidence

Added database connection configuration

A new file, src/data/connection.ts, has been added to configure the database connection using the Knex library. The connection is established via environment variables (DB\_CLIENT, DB\_HOST, DB\_USER, DB\_PASS, DB\_DATA), allowing users to connect to their database by setting these environment variables.

src/data · medium confidence

Added new utility functions for authentication and data formatting

New utility functions have been introduced to handle authentication and data processing tasks. Specifically, createToken generates JWTs and returns user data without exposing passwords, while getToken extracts and validates user IDs from incoming request headers. Password security is enhanced with encryptPassword for hashing and validatePassword for verification, both leveraging the bcrypt library. Additionally, a dateFormatter utility is provided to format dates using dayjs. All new utilities are exported via the utils index for easy access.

src/utils · high confidence

Adds transaction repository implementations for financial operations

The src/repositories/transaction directory now contains a comprehensive set of repository functions for managing financial data. This includes creating and deleting transactions (createNewTransaction, dropTransaction, dropTransactions), retrieving transaction details and lists (getTransaction, getTransactions, getTypedTransactions), and handling specific financial flows such as card payments (cardPay), deposits (createNewDeposit), and PIX transfers (createNewPix). The module also provides utility functions for calculating transaction values by type (getTypeValue) and fetching user or card balances (getBalancePerId). All new repository files are exported via the index.ts barrel file.

src/repositories/transaction · high confidence

Centralized export of all middleware validators

The src/middlewares/index.ts file has been created to serve as a central entry point that re-exports all middleware validation functions. This includes user-related validators (such as verifyUserBody, verifyLoginUserBody, verifyUpdateEmailUserBody, verifyUpdateUserBody, verifyUpdatePasswordUserBody, verifyPassword, verifyUpdateCardPassword, and verifyUpdatePhoneUserBody), card-related validators (verifyCardBody and verifyCardPay), transaction validators (verifyTransactionBody, verifyType, verifyTypeofParams, verifyOutputTransaction, verifyDepositTransaction, verifyCardTransaction, and verifyPixValue), and the auth middleware. This change simplifies imports for consumers of the middlewares module.

src/middlewares · high confidence

Centralized export of all schema types

The src/schemas/index.ts file has been created to provide a single entry point for all schema definitions. This change allows consumers to import UserSchema, LoginUserSchema, TransactionSchema, and other related schemas directly from the schemas package rather than importing from individual files like ./user or ./transaction.

src/schemas · high confidence

Centralized export of model types

A new \src/models/index.ts\ file has been introduced to serve as a central entry point for all model and parameter types. This change allows consumers to import \UpdateUserParams\, \LoginUserParams\, \TransactionParams\, \PixParams\, and other related types from a single location rather than importing them individually from their respective \user\ or \transaction\ modules.

src/models · high confidence

Centralized provider exports via new index module

A new \src/providers/index.ts\ file has been introduced to consolidate and re-export all provider-related functions. This creates a single entry point for accessing utilities related to user verification (e.g., \verifyEmailExists\, \validateCard\), transaction validation (e.g., \validateTransaction\, \verifyTransactionId\), and other validation helpers. Users can now import these functions from the providers index rather than importing from individual module files.

src/providers · high confidence

Initial Express server setup with CORS and route mounting

The application now initializes an Express server that enables CORS, parses JSON, and mounts routes for Swagger documentation, user management, transactions, automatic rendering requests, and a render auto-request handler. The server listens on port 3001 (or the value of the PORT environment variable).

src · high confidence

Initial SQL schema for users, transactions, and cards

The project now includes a new SQL dump file that defines the initial database schema. This introduces tables for user accounts, financial transactions, and both credit and debit cards, establishing the foundational data structure for the application.

src/sql · high confidence

Initial release of user and transaction API endpoints

The application now exposes a comprehensive set of API routes for managing user accounts and financial transactions. Users can register, log in, and update their profile, email, password, and phone number. The system also supports card management (creation, password updates, and details) and a wide range of transaction types, including deposits, withdrawals, card payments, PIX transfers, and transaction history. Additionally, the API documentation is accessible via Swagger, and a simple ping endpoint is available for health checks.

src/routes · high confidence

Introduces TypeScript interfaces for transaction and payment operations

The \src/models/transaction\ directory now provides a comprehensive set of TypeScript interfaces that define the structure for various financial operations. This includes request and response models for deposits, withdrawals, card payments, card transactions, and PIX transfers, as well as specific types for card types and database records. These interfaces standardize the data shapes for transactional endpoints, ensuring type safety across the application's core business logic.

src/models/transaction · high confidence

Introduces new transaction management services

Adds a new set of backend services for managing user transactions, including creating, retrieving, and deleting transactions. The update introduces specific handlers for card transactions, deposits, PIX transfers, card payments, withdrawals, and transaction summaries. It also provides a centralized index to export these new transaction-related services, enabling the application to process and track various financial operations.

src/services/transaction · high confidence

Introduces user and card repository operations

Adds a new set of repository functions for managing user and card data. Users can now create new accounts, retrieve user profiles by ID, email, phone, or CPF, and delete accounts. It also introduces operations to update user email, password, and phone number, as well as create, retrieve (single or multiple), and update credit/debit card details. The index file exports all these new repository functions.

src/repositories/user · high confidence

Introduces user management services for account lifecycle

The user service layer is now fully implemented, providing endpoints for the complete account lifecycle. Users can now register (insertUserAndReturn), authenticate (loginUserAndReturn), and retrieve their profile details (getUserDetailsAndReturn). The update capabilities have been expanded to include changing the email, phone, and password, as well as updating general user information. Additionally, the system now supports managing credit/debit cards (insertCardAndReturn, detailCardsAndReturn, updateCardPasswordAndConfirm) and permanently deleting user accounts (deleteUserAndConfirm). All operations are exported via the user service index for consistent access.

src/services/user · high confidence

Introduces validation schemas for user and card data

Adds new validation schemas for user and card data, including general schemas for users and cards, as well as specific schemas for login, password updates, email updates, phone updates, and card password updates. The index file exports all related user schemas.

src/schemas/user · high confidence

New transaction management endpoints

The application now exposes a comprehensive set of transaction-related controllers, enabling users to create, view, and delete transactions. Specifically, the system now supports inserting various transaction types (general, card, PIX, deposits, withdrawals, and card payments) as well as retrieving transaction history, individual transaction details, and account summaries. Additionally, users can now delete their transactions.

src/controllers/transaction · high confidence

New transaction validation and verification providers

A new set of transaction-related providers has been introduced to the application, centralizing validation logic for transaction operations. The update includes \validateTransaction\ to verify transaction ownership, \verifyTransactionId\ to check for the existence of a specific transaction, \verifyAccountTransactions\ to ensure an account has registered transactions, \validateOutput\ to check for sufficient balance, and \validatePix\ to prevent self-directed PIX transfers. These providers are now exported via a new \index.ts\ file in the \src/providers/transaction\ directory, making these validation capabilities available for use in the transaction workflow.

src/providers/transaction · high confidence

New transaction validation schemas for various payment methods

The application now enforces structured validation for multiple transaction types, each derived from a shared base schema. A new GeneralTransactionSchema defines common fields (type, description, value, password, email, cpf) with specific constraints, such as a minimum value of 0.01. Specialized schemas are then created by omitting irrelevant fields: CardPaySchema and TransactionWithdrawSchema exclude description, type, email, and cpf; DepositSchema omits type, description, and cpf; PixSchema excludes email, description, and type; TransactionSchema removes password, email, and cpf; and CardTransactionSchema is derived from a user-related schema, omitting sensitive card details. These are all exported via a new index file, enabling consistent validation across different transaction flows.

src/schemas/transaction · high confidence

New user and card management models introduced

The user model layer has been expanded with a comprehensive set of TypeScript interfaces to support user and card operations. New models include \UserParams\ for user registration, \LoginUserParams\ for authentication, and \UpdateUserParams\ for modifying user details. The update is extended to cover card management, introducing \CardParams\ and \InsertCardParams\ for adding new cards, alongside \ValidateCardParams\ and \RefreshCardParams\ for card verification and updates. Additionally, database-specific models (\DatabaseUserParams\, \DatabaseCardParams\) and return types (\ReturnedDatabaseUserParams\) are provided, with all interfaces exported via \src/models/user/index.ts\.

src/models/user · high confidence

New user management and card control endpoints

The application now exposes a comprehensive set of user and card management capabilities. Users can register, log in, and retrieve their profile or card details. Existing users can update their email, phone, password, and general profile information. Additionally, users can add new cards, update card passwords, and permanently delete their accounts. All new endpoints are exported via the user controller index for routing.

src/controllers/user · high confidence

New user request validation middleware

The \src/middlewares/user\ directory now contains a comprehensive set of new middleware functions that validate request bodies for various user-related routes. Specifically, the system now enforces schema validation for user registration (\verifyUserBody\), login (\verifyLoginUserBody\), and updates to user profile, email, phone, password, and card details. Each middleware validates the incoming JSON payload against its respective schema (e.g., \UserSchema\, \LoginUserSchema\, \UpdateEmailSchema\) and returns a 400 error on failure, ensuring that all user-facing update and authentication endpoints have consistent, strict input verification.

src/middlewares/transaction, src/middlewares/user · high confidence

New user validation providers for email, CPF, phone, and card

The user provider module now exports new validation and verification functions. Users can now check for duplicate email, CPF, and phone numbers, as well as validate card types and check for existing cards. Additionally, new providers verify if a user or email is undefined, throwing appropriate HTTP errors for each case.

src/providers/user · high confidence

Behavioural changes

Added JWT password configuration

A new file, jwtPassword.ts, has been added to the src/jwt directory. This file exports the value of the JWT\_PASS environment variable, providing a centralized way to access the JWT secret key for password-related operations.

src/jwt · low confidence

Centralized export of all controller functions

A new barrel file at src/controllers/index.ts now re-exports all user, transaction, and card-related controller functions (such as insertUser, loginUser, insertTransaction, and getHistory) from their respective modules, allowing consumers to import these handlers from a single entry point.

src/controllers · high confidence

Centralized export of all repository functions

The src/repositories/index.ts file has been introduced to serve as a central entry point that re-exports all user and transaction repository functions. This change consolidates the public API for data access, allowing consumers to import from a single location rather than navigating multiple internal modules.

src/repositories · high confidence

Centralized service exports

A new barrel file at src/services/index.ts now re-exports all user and transaction service functions, allowing consumers to import them from a single entry point rather than importing from individual module files.

src/services · high confidence

Test coverage

Added comprehensive test coverage for transaction-related endpoints; Added comprehensive test coverage for user and card management endpoints; Added test cleanup for database and server; Added test data models for user, login, and card scenarios; Added test fixtures for deposit and withdraw transactions; Added test helper functions for user and card operations; Added test helpers for deposit and withdraw transactions; Centralized export of test model utilities; Centralized test function exports.

Dependencies

Initial project setup with core dependencies

The project is initialized with a new package.json defining the application's dependencies and scripts. This includes runtime libraries such as Express, Knex, and JWT for API and database interactions, alongside development tools like TypeScript, Jest, and ESLint. The configuration also establishes scripts for running the application in development mode, executing tests, and managing Docker containers.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 58 → 56 (-2.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 93 (-1.3)
  • Architecture 100 → 82 (-17.6)
  • Maturity 59 → 59 (+0.0)
  • Readiness 33 → 35 (+2.5)
  • Security 99 → 99 (+0.2)

Resolved (8)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • no production source files with tracked history to analyse
  • single-maintainer — knowledge-concentration (bus factor) risk

New (7)

  • Coverage not measured — JavaScript/TypeScript suite
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Scattered collaborators

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bush1D3v/tsbank_api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 3e307c1790cd99bfcb3dd09d9a7638fbcfe8eb07 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.