Skip to content
CAI
Software that uses CAICheck a score

CollatzConjecture/nestjs-clean-architecture-postgres

47.3

Weak · 21 September 2026

4.3k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Node.js backend service that manages user authentication and profile data, supporting both traditional and mobile OAuth logins. It enforces a standardized JSON response format across all API endpoints and implements soft deletion for user records. The architecture decouples domain logic from data persistence, ensuring clean separation of concerns and consistent data handling.

Features

Add mobile and Apple OAuth authentication support

Users can now sign in using Google or Apple accounts on mobile platforms. This change introduces new services for validating Google and Apple ID tokens via JWKS, along with command handlers to process authentication requests. A new response service and interceptor standardize API responses, while a request ID middleware improves observability. Additionally, a new exception filter ensures consistent error formatting across the application.

src/application · high confidence

Added health check endpoint and centralized response handling

A new /health endpoint is now available for monitoring, exposing a health check via the Terminus module. Additionally, the application now enforces a standardized JSON response format across all API routes through a new ResponseInterceptor and ResponseService, ensuring consistent payload structures for clients.

src · high confidence

Introduces standardized API response structures and mobile authentication DTOs

The API now uses a unified response format with SuccessResponseDto, ErrorResponseDto, and PaginatedResponseDto, providing consistent message, data, and pagination metadata across endpoints. Additionally, new DTOs support mobile authentication via Google (ID token and PKCE flows) and Apple (ID token flow), while the register endpoint makes lastname and age optional. A dedicated DTO for changing passwords and a refresh-token DTO are also added.

src/api/dto · medium confidence

Behavioural changes

Domain services decoupled from repositories

The AuthDomainService and ProfileDomainService no longer depend on repository interfaces (IAuthRepository, IProfileRepository). Instead, they accept data from the application layer as parameters and return entities directly, removing the async database calls from the domain layer. This shifts the responsibility of data retrieval and persistence to the application layer, making the domain services purely functional and easier to test.

src/domain/services · high confidence

Extended user and profile entities with soft-delete and OAuth support

The AuthUser and Profile domain entities now include soft-deletion support via a 'deletedAt' field, along with additional tracking fields such as 'createdAt', 'updatedAt', and 'lastLoginAt' for AuthUser. AuthUser also gains an 'appleId' field to support Apple OAuth, while Profile fields 'lastname' and 'age' are made optional. The Auth repository interface is updated to support finding users by Apple ID and includes a password inclusion option in 'findById'.

src/domain/entities · medium confidence

Implement soft deletion for auth and profile records

The repository layer now uses soft deletion instead of hard deletion for both Auth and Profile entities. The \delete\ methods in \auth.repository.ts\ and \profile.repository.ts\ have been changed to call \softDelete\ rather than \delete\. Additionally, \deletedAt\ fields are now included in the response types and entity mappings, and update/delete criteria are explicitly filtered to exclude soft-deleted records using \deletedAt: IsNull()\. The encryption utility was also reformatted for consistency.

src/infrastructure/repository · high confidence

Migrate from TSLint to ESLint and Node 18 to 20

The project replaces the deprecated TSLint tool with ESLint (via eslint.config.mjs) and upgrades the Node.js runtime from version 18 to 20. This is accompanied by a switch from npm to pnpm for package management, updating the Dockerfile and Docker Compose configurations to use pnpm and the newer Node base image.

(repo-wide) · high confidence

Removes financial account and transaction entities, adds soft deletion support

The financial account and transaction entity files have been removed from the codebase, and the database module has been updated to exclude them from the TypeORM configuration. Additionally, the Auth and Profile entities now extend a new SoftDeletableEntity base class, introducing a 'deleted\_at' column to support soft deletion for these records.

src/infrastructure/entities · medium confidence

Standardized API response format across controllers

Controllers in src/api/controllers now use a centralized ResponseService to return consistent, structured JSON responses (e.g., { success, data, message }) instead of returning raw domain objects or strings. This change applies to auth, hello, and profile endpoints, ensuring all API responses follow a uniform schema for better client-side handling.

src/api/controllers · high confidence

Test coverage

Added and updated tests for profile domain and service logic; Added unit tests for the ProfileRepository; Updated e2e tests to use PostgreSQL and API versioning.

Dependencies

Migrate from npm to pnpm and replace TSLint with ESLint

The project has switched its package manager from npm to pnpm, evidenced by the addition of pnpm-lock.yaml and the removal of package-lock.json. Additionally, the build scripts have been updated to use pnpm, and the linting tool has been changed from tslint to eslint, with corresponding updates to the package.json scripts and devDependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 45 → 47 (+2.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 87 → 91 (+3.3)
  • Architecture 51 → 58 (+6.8)
  • Maturity 69 → 69 (+0.0)
  • Readiness 22 → 26 (+3.6)
  • Security 79 → 79 (-0.4)

Resolved (42)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 22 more

New (81)

  • ApiExceptionFilter.catch (cognitive 18) (src/application/filters/api-exception.filter.ts)
  • ApiExceptionFilter.catch (cyclomatic 16) (src/application/filters/api-exception.filter.ts)
  • AppleTokenValidationService.validateIdToken (cognitive 29) (src/application/services/apple-token-validation.service.ts)
  • AppleTokenValidationService.validateIdToken (cyclomatic 19) (src/application/services/apple-token-validation.service.ts)
  • ClassTooLong: AuthService (src/application/services/auth.service.ts)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 61 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

CollatzConjecture/nestjs-clean-architecture-postgres was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ab8d3fa2c2001643041f722a0f4cd08e63fab0e1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.