CocaineCong/todolist-ddd
43.6
Weak · 21 September 2026
1.5k
lines of production code
Go
primary language
4
measurements over time
What this system is
This is a Go-based web application that manages tasks and user accounts. It provides public endpoints for user registration and login, while offering protected CRUD and search operations for tasks. The system handles authentication via JWT tokens and persists data using MySQL, with configuration managed through YAML files.
Features
Add password encryption service using bcrypt
The infrastructure/encrypt package now includes a new PwdEncryptService that implements password encryption and verification using the bcrypt algorithm. The service provides Encrypt to hash passwords and Check to verify them against stored hashes, supporting the user domain's authentication requirements.
infrastructure/encrypt · high confidence
Add user context and logging infrastructure
The application now includes new infrastructure components for managing user information within the request context and for structured logging. A new 'user\_info.go' file introduces a 'UserInfo' struct and helper functions to store and retrieve user details (ID and name) in the context. Additionally, a new 'logger.go' file initializes a Logrus-based logger that writes timestamped, text-formatted logs to daily files in a 'logs' directory. These changes provide the foundational tools for tracking user identity and application events.
infrastructure/common · high confidence
Added task and user API endpoints with authentication and CORS middleware
The application now exposes HTTP endpoints for user registration and login, as well as full CRUD and search operations for tasks. The router in \interfaces/adapter/initialize/routes.go\ registers these handlers under \/api/v1/\. User endpoints (\/user/register\, \/user/login\) are public, while task endpoints (\/task/create\, \/task/list\, \/task/detail\, \/task/update\, \/task/delete\, \/task/search\) are protected by a JWT authentication middleware. Additionally, a CORS middleware is applied globally to handle cross-origin requests.
interfaces · high confidence
Implemented persistence layer for user and task entities
Added new files in the persistence infrastructure to handle database interactions for users and tasks. This includes database initialization and connection pooling setup, automatic schema migration for the User and Task models, and repository implementations that map domain entities to database models. The changes introduce a structured approach to data access, ensuring that user and task data is correctly persisted and retrieved from the database.
infrastructure/persistence · high confidence
Initialize domain and application service wiring in container
A new \init.go\ file in the \infrastructure/container\ package introduces the \LoadingDomain\ function, which wires up the application and domain layers for both user and task modules. This initialization step sets up repositories, JWT services, and password encryption services, then registers the user and task domain implementations with their respective application service singletons.
infrastructure/container · low confidence
Introduce YAML-based configuration for service, MySQL, and Redis
Added Go structs and initialization logic in conf/config.go to load application settings from a YAML file, supporting configuration for the server (port, version, JWT secret, metrics), MySQL (driver, host, port, database, credentials, charset), and Redis (host, port, password, DB name). A default config.yaml and an example config.yaml.example are also added to define these settings.
conf · high confidence
Introduce new application entry point and infrastructure initialization
A new main.go file has been added to the cmd directory, serving as the application's entry point. This file initializes the configuration, logging, database connections, and domain containers, then starts the HTTP server on the configured port.
cmd · high confidence
Introduce task domain with entity, repository, and service layers
The task domain is now structured with a clear separation of concerns: the entity layer defines the Task struct and its business rules (such as title validation and status updates), the repository layer declares the interface for data access operations like creating, updating, and searching tasks, and the service layer implements the TaskDomain interface to orchestrate these repository calls. This change establishes the core domain logic for managing tasks, including creation, retrieval, and modification.
domain/task · high confidence
User application layer implementation for registration and login
The application/user package now contains the concrete implementation of the user service, including the Register and Login use cases. The Register flow validates that the username is not already in use, while the Login flow verifies the password and generates an authentication token. A new converter handles mapping domain entities to response types.
application/user · high confidence
User domain model and service layer implementation
The user domain is now fully implemented with a new entity, repository interfaces, and a service layer. The User entity includes fields for ID, username, password, and timestamps, along with validation and password-setting logic. A new password encryption interface (PwdEncrypt) is introduced to handle password hashing and verification. The UserDomain service layer integrates these components, providing methods to create users (with encrypted passwords), find users by name or ID, and verify passwords. This establishes the core user management functionality within the domain layer.
domain/user · high confidence
Behavioural changes
Added task application service and converter
The application layer for tasks now includes a new service implementation that handles Create, List, Detail, Update, Search, and Delete operations. A converter is also introduced to map request objects to domain entities. This provides the core business logic and orchestration for task management within the application package.
application/task · high confidence
Centralized error codes and messages for user and task domains
The application now uses a centralized constants package to define error codes, status messages, and task states. Users will see specific, localized messages for common scenarios such as authentication failures (e.g., 'Token expired'), user validation errors (e.g., 'User not found'), and database issues. Additionally, task status messages (e.g., 'Not completed', 'Completed') are now explicitly defined, ensuring consistent feedback across the application.
consts · high confidence
Implement JWT-based token generation and validation
The authentication infrastructure now includes a new token management component that generates and parses JSON Web Tokens (JWT) for user sessions. This change introduces a \TokenService\ interface and a \JWTTokenService\ implementation that handles token creation with a 24-hour expiration and signature verification using HS256, replacing previous token handling mechanisms.
infrastructure/auth · medium confidence
Dependencies
Initial Go module and dependency configuration
The project's Go module file (go.mod) and its corresponding checksum file (go.sum) have been added, establishing the project's dependencies. This includes the core framework (Gin), database drivers (GORM, MySQL), logging (Logrus), and configuration (Viper) libraries, along with their indirect dependencies.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 40 → 44 (+3.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (-0.2)
- Architecture 69 → 69 (+0.0)
- Maturity 54 → 54 (+0.0)
- Readiness 12 → 18 (+6.2)
- Security 83 → 89 (+5.3)
- Domain Modelling 70 → 74 (+3.5)
Resolved (14)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2025-3749 (go.mod)
- Medium CVE: GO-2026-4503 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- No exposed public API
- early-stage repository — too little history to judge knowledge freshness
- git history depth insufficient
- git history depth insufficient
- single-maintainer — knowledge-concentration (bus factor) risk
New (19)
- Critical CVE: [GHSA redacted] (go.mod)
- Documentation: no contributor guidance (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (8 lines × 2) (interfaces/controller/user.go)
- High CVE: [GHSA redacted] (go.mod)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2025-3749 (go.mod)
- Medium CVE: GO-2026-4503 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- No ADRs found
- Outdated: github.com/gin-gonic/gin
- Outdated: github.com/sirupsen/logrus
- Outdated: github.com/spf13/viper
- Outdated: golang.org/x/crypto
- Outdated: gorm.io/gorm
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
CocaineCong/todolist-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 38facc30bb1cae64f7c69166c2455f6c12f55de6 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.