cnodejs/nodeclub
36.1
Weak · 2 October 2026
41.5k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a Node.js-based community platform, specifically NodeClub, designed for managing user-generated content such as topics, replies, and messages. It provides a RESTful API and a responsive web interface that supports GitHub OAuth authentication, Markdown editing with syntax highlighting, and real-time notification handling. The architecture separates concerns into controllers, middleware, and a dedicated data access layer, backed by MongoDB and Redis for persistence and caching.
How it got here
2012 — Initial project scaffolding and core features
15 changes.
This period established the foundational structure of the NodeClub application, introducing the Express-based backend, Mongoose data models, and core controllers for user authentication and content management. It also implemented the initial responsive frontend using Bootstrap, including views for topics, replies, user profiles, and a GitHub OAuth integration, alongside essential static documentation and API endpoints.
2013–2016 — Architecture modernization and API development
20 changes.
This period focused on restructuring the application with a dedicated proxy layer for data access and a comprehensive middleware suite for authentication and rate limiting. It introduced a robust v1 REST API, replaced the markdown editor with CodeMirror, and established a solid foundation of integration and unit tests across controllers, models, and utilities.
Features
Add GitHub OAuth login and account linking views
The sign-in and sign-up pages now include a link to authenticate via GitHub. After successful GitHub authentication, users are presented with a new view allowing them to either enter the site directly or associate their GitHub identity with an existing local account by providing a username and password. Additionally, a dedicated error page is shown if the GitHub account lacks a public email or if the email is already registered.
views/sign · high confidence
Added Font Awesome 4.2.0 icon library assets
The public/libs/font-awesome directory now includes the Font Awesome 4.2.0 CSS styles and font files (EOT, WOFF, TTF, SVG). This adds the complete set of icon classes and font definitions to the application, enabling the use of Font Awesome icons in the UI.
public/libs/font-awesome · high confidence
Added WebUploader library for image uploads
The public/libs/webuploader directory now includes the WebUploader library (version 0.1.5) and its associated CSS styles. This addition provides the underlying component for the new image upload editor, enabling users to upload images through the application interface.
public/libs/webuploader · high confidence
Added one-time data migration and utility scripts
New scripts have been added to the bin directory to handle legacy data fixes and user operations. The \fix\_at\_problem.js\ script corrects rendering issues caused by duplicate @mentions in post content, while \fix\_topic\_collect\_count.js\ recalculates and syncs the collection counts for both users and topics. Additionally, \generate\_accesstoken.js\ creates access tokens for existing users who lack them, and \get\_user\_topics.js\ serves as a utility to retrieve a specific user's topics.
bin · high confidence
Added responsive sidebar and back-to-top functionality
Users now have a dedicated back-to-top button that appears when scrolling down and fixes the footer to the bottom on short pages. Additionally, a new responsive sidebar is available on touch devices, allowing users to open and close the sidebar via a toggle button or by swiping from the screen edges.
public/javascripts · high confidence
Added syntax highlighting support for 15 programming languages
The code-prettify library now includes language definition files for Apollo, Clojure, CSS, Go, Haskell, Lisp, Lua, ML/F\#, Nemerle, Protocol Buffers, Scala, SQL, TeX/LaTeX, Visual Basic, VHDL, Wiki markup, XQuery, and YAML. This allows code snippets in these languages to be automatically highlighted with appropriate syntax coloring in the application's UI.
public/libs/code-prettify · high confidence
Initial CSS styling and responsive layout support
This change introduces the foundational CSS styles for the application, including base typography, form elements, and code block formatting in common.css, along with the visual design for the @-mention autocomplete dropdown in jquery.atwho.css. It also adds responsive layout rules in responsive.css to adapt the navigation, content width, and sidebar behavior for smaller screens, and establishes the primary visual theme and layout structure in style.less.
public/stylesheets · high confidence
Initial project scaffolding and configuration
This change introduces the foundational structure for the Nodeclub application, including the main Express application entry point (app.js) and separate routers for web pages (web\_router.js) and the v1 API (api\_router\_v1.js). It establishes the default configuration (config.default.js) for MongoDB, Redis, and GitHub OAuth, and sets up the build and test infrastructure via Makefile and .travis.yml. Additionally, it adds essential development tooling such as JSHint rules (.jshintrc), a Snyk security policy file (.snyk) to patch known vulnerabilities in dependencies, and a .gitignore file to exclude generated artifacts and sensitive data.
(repo-wide) · high confidence
Initial release of core application controllers
This change introduces the complete set of backend controllers for the application, establishing the primary user-facing logic for authentication (sign up, login, GitHub OAuth integration), content management (creating, editing, and deleting topics and replies), user profile management, and site features like RSS feeds, sitemaps, and search. It also implements behavioral rules such as score updates upon posting, reply locking, and admin capabilities for account activation.
controllers · high confidence
Initial release of the GitHub Card widget
The public area now includes a standalone GitHub Card widget (public/github-card.html) that renders user or repository profiles directly in the browser. The widget fetches data from the GitHub API, caches results in localStorage, and communicates its rendered height to the parent window via postMessage for proper embedding.
public · high confidence
New Markdown Editor with Image Upload and Icon Support
The editor component in public/libs/editor has been replaced with a new implementation based on CodeMirror 3.15 and markdown-it, providing a richer editing experience. This update introduces a dedicated toolbar with custom SVG icons (icomoon) for formatting actions such as bold, italic, lists, links, and code. It also adds a new image upload feature, allowing users to insert images directly into their content via a modal interface that integrates with WebUploader. The switch to markdown-it ensures consistent Markdown parsing and rendering.
public/libs/editor · high confidence
New message center UI with read/unread separation
The message center now displays notifications in two distinct sections: 'New Messages' for unread items and 'Past Messages' for those already viewed. Each notification card dynamically renders context-specific content based on the message type (reply, reply to reply, follow, or @ mention), including direct links to the author's profile, the topic, and the specific reply if applicable. Unread messages are visually distinguished from read ones, and empty states are handled gracefully with a 'No messages' placeholder.
views/message · high confidence
New middleware suite for authentication, rate limiting, and request logging
This change introduces a new set of middleware modules in the \middlewares/\ directory to handle core application concerns. Authentication is now managed via \auth.js\, which provides guards for admin and user access, implements a user blocking feature (returning 403 for blocked users except on sign-out), and handles session generation and user lookup. Rate limiting is handled by \limit.js\, offering per-user and per-IP daily limits with distinct responses for API (JSON) and frontend (HTML) requests. Request visibility is improved through \request\_log.js\ and \mongoose\_log.js\, which log HTTP request start/finish times and Mongoose query performance respectively. Additional utilities include \proxy.js\ for safely proxying avatar and analytics requests, \error\_page.js\ for standardized error rendering, and \render.js\ for logging view rendering durations.
middlewares · high confidence
New responsive layout and sidebar components for the CNode community site
The views directory now includes a complete set of layout and partial templates that establish a responsive, mobile-friendly interface for the CNode Node.js community. The new \layout.html\ serves as the base template, integrating Bootstrap for styling and jQuery-ujs for handling CSRF-protected requests, while also supporting configurable Google Analytics and CNZZ tracking. A dedicated \sidebar.html\ component provides a collapsible navigation area featuring user profile cards, topic creation buttons, ad placements, leaderboards, and links to partner communities. Supporting partials like \index.html\ (topic listing), \editor\_sidebar.html\ (Markdown syntax help), and \\_sponsors.html\ (sponsor credits) complete the structural overhaul, enabling the site to adapt to various screen sizes and improve the overall user experience for browsing and posting topics.
views · high confidence
New static documentation pages for About, FAQ, API, and Getting Started
The site now includes dedicated static pages for key informational sections. The About page details the community's mission, maintenance, and mobile client information (including the 'noder' client and a Java-based alternative). The FAQ page addresses the relationship between CNode and Node Club. The API page provides comprehensive documentation for the v1 API, covering topics, collections, replies, users, and messages, including specific parameters like \is\_uped\ for comment likes. The Get Started page offers a curated list of Node.js learning resources, tutorials, and server recommendations.
views/static · high confidence
New user profile, settings, and social interaction views
The user-facing interface has been expanded with dedicated views for profile management, social features, and administrative controls. Users can now view and edit their personal settings (including signature, location, and access tokens with QR codes), browse their created topics, replies, and collections, and see their followers and followings. The profile page displays user scores, GitHub/Weibo links, and registration date. Additionally, new views support community features like a 'Top 100' leaderboard, a list of 'Star' (expert) users, and a notification page. Admin-specific actions such as blocking users, setting star status, and activating accounts are now exposed in the user profile view.
views/user · high confidence
New v1 API endpoints for topics, replies, messages, and user collections
This change introduces a new set of REST API endpoints under the v1 namespace, providing structured access to core application features. Users can now retrieve and manage topics (including listing, creating, viewing details with reply upvote status, and collecting/un-collecting), create and upvote replies, manage message notifications (listing read/unread, marking all or single messages as read), and view user profiles with recent activity. The API also includes authentication middleware that supports both strict login checks and optional authentication, while enforcing security measures like blocking disabled accounts and validating input to prevent MongoDB injection.
api · high confidence
Reply views now include an editor sidebar and support editing replies
The reply view templates have been updated to include a new \edit.html\ page that allows users to edit replies using a Markdown editor, and the \reply.html\ template now displays reply content with author information, upvote counts, and edit/delete buttons for admins or the original author. Additionally, the reply view now supports replying to a specific reply via a dedicated reply form embedded within each reply item.
views/reply · high confidence
Architecture
Introduction of a dedicated proxy layer for data access
A new \proxy\ directory has been added to the application, introducing a dedicated data-access layer that sits between the controllers and the Mongoose models. This layer encapsulates database operations for core entities—User, Topic, Reply, Message, and TopicCollect—handling tasks such as fetching related data (e.g., authors and last replies for topics), managing read statuses for messages, and enforcing business rules like soft-deletion checks. This change separates raw database queries from controller logic, centralizing data retrieval and manipulation for these specific modules.
proxy · high confidence
Behavioural changes
Log directory structure updated
The project's README file has been moved into the logs directory and renamed to .gitkeep to ensure the directory is tracked by version control.
logs · low confidence
New data models and base model infrastructure
The application introduces a new \BaseModel\ that provides \create\_at\_ago\ and \update\_at\_ago\ helper methods to all models via Mongoose plugins. New schema definitions are added for \User\, \Topic\, \Reply\, \Message\, and \TopicCollect\, including specific fields like \is\_star\ and \isAdvanced\ for users, \top\ and \good\ for topics, and \deleted\ flags for soft deletion. The \User\ model now uses \loginname\ as a unique identifier alongside \email\ and \githubId\, and automatically updates the \update\_at\ timestamp on save. Database indexes are configured for performance on key fields such as \master\_id\ and \has\_read\ in messages, and \user\_id\/\topic\_id\ uniqueness in topic collections.
models · high confidence
Refactor common utilities and introduce new modules for logging, caching, and user mentions
The common directory has been restructured with several new modules and behavioral updates. A new \common/at.js\ module handles extracting and linking @mentions in text, ensuring mentions inside code blocks or URLs are ignored. Logging is now centralized via \common/logger.js\ using log4js, writing to files and respecting debug/test environment settings. Caching operations are abstracted in \common/cache.js\ with Redis integration and duration logging. Password handling now uses the \bcryptjs\ library via \common/tools.js\. Email sending (\common/mail.js\) includes retry logic. Markdown rendering (\common/render\_helper.js\) switches to markdown-it with XSS filtering. Redis connection (\common/redis.js\) now exits on error. File storage is abstracted via \common/store.js\ supporting local or Qiniu backends.
common · high confidence
Topic views restructured with mandatory section selection and enhanced metadata display
The topic views have been reorganized into new template files (\_top\_good.html, abstract.html, edit.html, index.html, list.html, small.html) to improve layout and functionality. The topic creation and editing interface now enforces mandatory selection of a section (tab) before submission, providing specific guidance for 'job' and 'ask' categories. Topic listings and detail pages now prominently display section origin, author information, and visual indicators for pinned or featured topics. Additionally, the topic detail view includes user-specific management controls for locking, editing, and deleting topics, as well as a collection feature for users.
views/topic · high confidence
Upgraded to Bootstrap 2.3.1
The project's frontend library has been updated to Bootstrap version 2.3.1, replacing the previous version. This upgrade includes the new responsive CSS files (bootstrap-responsive.css) which enable device-specific layouts for phones, tablets, and desktops, as well as updated JavaScript components (alerts, buttons, carousel, collapse, dropdowns) that support CSS3 transitions and improved interaction handling.
public/libs/bootstrap · high confidence
Fixes
Added editor view include template
A new include file for the editor view has been added, which loads the necessary JavaScript assets for the editor functionality, including the main editor script, webuploader, and extension scripts.
views/includes · high confidence
Test coverage
Added API v1 integration tests for core endpoints; Added controller integration tests; Added empty test stubs for proxy modules; Added initial test suite and environment setup; Added test support utilities for creating test users, topics, and replies; Added tests for configuration, rate limiting, and proxy middlewares; Added tests for user model avatar URL generation; Added unit tests for common utilities.
Dependencies
Initial dependency manifest for NodeClub v2.1.1
This change introduces the \package.json\ file for the NodeClub project, establishing the baseline dependency tree for version 2.1.1. It specifies production dependencies including Express 4.16.0, Mongoose 5.3.9, and ioredis 2.0.0, alongside development tools like Mocha 2.4.5 and Nock 7.5.0. The manifest also integrates Snyk for vulnerability management, enabling automated security protection via the \snyk-protect\ script.
(dependencies) · high confidence
Updated frontend libraries and added new client-side utilities
Upgraded jQuery to version 2.1.0 and replaced the previous markdown parser with markdown-it (v3.0.3). Added jquery-ujs to support Rails-style RESTful hyperlinks and remote form submissions, and introduced jquery.atwho and jquery.caret to enable 'at' mention functionality in input fields. Also added lodash.compat (v2.4.1) for utility functions and updated qrcode.js to generate clearer QR codes.
public/libs · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 39 → 36 (-2.6)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 43 → 41 (-2.4)
- Architecture 89 → 83 (-6.5)
- Maturity 37 → 37 (+0.0)
- Readiness 43 → 43 (-0.4)
- Security 88 → 61 (-27.7)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 29 → 27 (-2.0)
Resolved (1)
- create (cognitive 22) (controllers/github.js)
New (41)
- FileTooLong: js/bootstrap.js (public/libs/bootstrap/js/bootstrap.js)
- FileTooLong: libs/jquery-2.1.0.js (public/libs/jquery-2.1.0.js)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Projects may be oversized for their cohesion
- editor.CodeMirror.defineMode("markdown","xml") (cognitive 167) (public/libs/editor/editor.js)
- editor.CodeMirror.defineMode("markdown","xml") (cyclomatic 132) (public/libs/editor/editor.js)
- editor.CodeMirror.defineMode("xml") (cognitive 141) (public/libs/editor/editor.js)
- editor.CodeMirror.defineMode("xml") (cyclomatic 99) (public/libs/editor/editor.js)
- editor.Editor.createToolbar (cognitive 19) (public/libs/editor/editor.js)
- github.create (cognitive 22) (controllers/github.js)
- jquery-2.1.0.Animation (cognitive 18) (public/libs/jquery-2.1.0.js)
- jquery-2.1.0.Animation (cyclomatic 16) (public/libs/jquery-2.1.0.js)
- jquery-2.1.0.ajaxConvert (cognitive 73) (public/libs/jquery-2.1.0.js)
- jquery-2.1.0.ajaxConvert (cyclomatic 25) (public/libs/jquery-2.1.0.js)
- jquery-2.1.0.ajaxHandleResponses (cognitive 26) (public/libs/jquery-2.1.0.js)
- jquery-2.1.0.ajaxHandleResponses (cyclomatic 16) (public/libs/jquery-2.1.0.js)
- jquery-2.1.0.augmentWidthOrHeight (cognitive 18) (public/libs/jquery-2.1.0.js)
- jquery-2.1.0.defaultPrefilter (cognitive 54) (public/libs/jquery-2.1.0.js)
- …and 21 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
cnodejs/nodeclub was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 91a3286f2c759653524765775b44bff2ab232b32 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.