Skip to content
CAI
Software that uses CAICheck a score

CS151512/STREMO

51.8

Adequate · 21 September 2026

7k

lines of production code

Rust

with TypeScript, Go

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a backend infrastructure for a live streaming platform, orchestrating video ingestion, transcoding, and distribution alongside user-facing features like chat, profiles, and video-on-demand. It comprises a suite of microservices handling authentication, stream metadata, analytics, and content moderation, communicating via gRPC and Kafka. The architecture supports real-time interactions through WebSockets and Server-Sent Events, backed by persistent storage in PostgreSQL and ClickHouse, with caching via Redis.

Features

Add PostgreSQL persistence and Redis PubSub messaging to chat service

The chat service now supports durable message storage via PostgreSQL and real-time delivery via Redis PubSub. A new repository module introduces a PostgresBatcher that buffers chat messages and flushes them to a PostgreSQL database in batches every 500ms, enabling reliable history retrieval by channel. Additionally, a RedisPubSub component handles real-time communication by publishing messages to Redis channels (formatted as 'chat:{channel\_id}') and subscribing to those channels to stream updates to local subscribers.

backend/service/chat-service/src/repository · high confidence

Add Prometheus metrics infrastructure to ingest service

The ingest service now exposes a Prometheus-compatible metrics endpoint. This change introduces a global registry and an 'ingested\_bytes' counter to track total ingested data volume, along with a handler that returns the metrics in Prometheus text format for scraping.

backend/service/ingest-service/src/infrastructure/metrics · high confidence

Add STREMO Next.js frontend application

The \frontend\ directory has been converted from a Git submodule to a regular folder, containing the full source code for the STREMO streaming platform. This includes a Next.js application with Tailwind CSS, ESLint configuration, and React components for the home, browse, following, stream, search, and dashboard views, along with layout, header, footer, and cookie banner components.

(repo-wide) · high confidence

Add VOD domain and payload models

The VOD manager service now includes core data structures for handling video-on-demand content. The new \VOD\ model defines the schema for stored video assets, including identifiers, channel association, title, duration, and storage location. Additionally, \ClipRequest\ and \ClipEvent\ models have been introduced to handle the input parameters for creating video clips and the resulting event data, respectively.

backend/service/vod-manager-service/internal/models · high confidence

Added HTML template for user welcome emails

The SMTP service now includes a new HTML template (welcome.html) used for sending account verification emails to new users. This template provides a branded, styled email experience that includes a personalized greeting, instructions to confirm the account, and a prominent call-to-action button for email verification.

backend/service/smtp-service/templates · high confidence

Added JWT authentication and IP-based rate limiting middleware

The BFF service now includes middleware for securing API access and managing traffic. JWT authentication validates bearer tokens against a secret, checks for token revocation in Redis, and extracts user claims. Additionally, a rate limiter enforces a sliding window policy (100 requests per minute) per IP address using Redis, returning a 400 error if the limit is exceeded.

_backend/service/bff\service/src/middleware · high confidence

Added build script to generate gRPC client for moderation service

The chat service now includes a build script that automatically generates Rust code from the \moderation.proto\ file during compilation. This enables the service to communicate with the moderation gRPC service as a client, while explicitly disabling server-side code generation.

backend/service/chat-service · high confidence

Added gRPC client for internal moderation communication

The chat service now includes a new infrastructure module that implements a gRPC client for communicating with the internal moderation service. This client allows the chat service to check messages for spam by sending text, user ID, and channel ID to the moderation service, with a fallback behavior that allows messages if the moderation service is unreachable.

backend/service/chat-service/src/infrastructure · high confidence

Added placeholder crypto utility for stream key hashing

A new \crypto\ module has been added to the ingest service's utilities, exposing a \hash\_stream\key\ function. Currently, this function serves as a stub implementation that prefixes the input key with 'hashed\' rather than performing actual cryptographic hashing, indicating that the real implementation is pending.

backend/service/ingest-service/src/utils · high confidence

BFF service now uses Docker for containerization and protobuf code generation

The BFF service now supports containerized deployment via a new Dockerfile based on a slim Rust builder and distroless runtime, exposing port 8000. Additionally, the service build process has been updated to automatically generate Rust client code from protobuf definitions (auth, stream\_meta, errors) using tonic\_build during compilation.

_backend/service/bff\service · high confidence

Chat service application entrypoint and dependency wiring

The chat service now initializes its core components, including the Redis PubSub client, Postgres batcher, and Moderation gRPC client, and exposes HTTP and WebSocket routes on port 8080. This change establishes the service's entry point, configuring environment-based URLs for Redis, the database, and the moderation service, while applying CORS and tracing layers to the Axum router.

backend/service/chat-service/src · high confidence

ClickHouse repository for CCV metrics ingestion

The ingest service now includes a ClickHouse repository implementation that initializes a client connected to the 'stremo\_analytics' database and provides a method to batch-insert CCV (content view) metrics. This enables the service to persist stream IDs, view counts, and timestamps into the ClickHouse analytics store.

backend/service/ingest-service/src/repository/clickhouse · high confidence

Ingest service adds HTTP health/metrics endpoints and TCP RTMP stream handling

The ingest service now exposes an HTTP interface with a /healthz endpoint returning 'OK :)' and a /metrics endpoint for Prometheus metrics, alongside a TCP server that accepts connections, validates stream keys via the StreamManager, and handles incoming stream data by incrementing ingested byte counters.

backend/service/ingest-service/src/api · high confidence

Initial API layer for authentication and live stream access

The backend service's API module now exposes HTTP endpoints for user authentication and live stream discovery. Users can register and log in via POST requests to /register and /login, which delegate to gRPC services and return tokens or confirmation messages. Additionally, a GET endpoint at /live allows clients to retrieve a paginated catalog of live streams, supporting limit and cursor parameters for navigation.

_backend/service/bff\service/src/api · high confidence

Initial Docker build environment and gRPC build script for analytics service

The analytics service now includes the necessary infrastructure to build and containerize the application. A Dockerfile defines a multi-stage build process using Rust 1.77, installing dependencies like protobuf-compiler and clang, and exposing ports 8080 and 50051 for production use. A .dockerignore file optimizes the build context by excluding unnecessary artifacts. Additionally, a build.rs script ensures that the gRPC server code is generated from the analytics.proto file during the build process.

backend/service/analytics-service · high confidence

Initial HTTP and WebSocket API endpoints for chat history and real-time messaging

The chat service now exposes an HTTP API and WebSocket interface for interacting with chat channels. The HTTP layer provides a health check endpoint and a GET route at /api/v1/chat/:channel\_id/history to retrieve paginated chat history, supporting limit and offset query parameters. The WebSocket layer allows clients to connect to a specific channel by providing a JWT token in the query string; upon successful authentication, the connection enables real-time bidirectional communication, where the server pushes incoming messages to the client and the client can send new messages to be processed by the chat manager.

backend/service/chat-service/src/api · high confidence

Initial Kafka integration for the ingest service

The ingest service now includes a new Kafka infrastructure module containing a producer and a consumer. The producer allows sending events to Kafka topics with specified keys and payloads, while the consumer listens to the 'ingest-commands' topic to process administrative actions such as disconnecting or banning streams. This change introduces the underlying messaging capability for the service, although the consumer currently logs commands without fully executing them against the stream manager.

backend/service/ingest-service/src/infrastructure/kafka · high confidence

Initial VOD management API with CORS support

The VOD manager service now exposes an HTTP API for managing video-on-demand content. Users can retrieve VOD lists via a public GET endpoint at /api/v1/vods, filtering by channel ID with optional pagination. Additionally, authenticated users can request clip creation through a POST endpoint at /api/v1/clips, which requires a valid JWT token. The router is configured with permissive CORS settings (allowing all origins and credentials) to facilitate cross-origin requests from client applications.

backend/service/vod-manager-service/internal/routers · high confidence

Initial analytics service layer for processing and aggregating stream metrics

This change introduces the core service components for the analytics system within the backend. The AnalyticsAggregator handles incoming ping events, buffering them for periodic bulk insertion into ClickHouse while tracking current concurrent viewers (CCV) in Redis. The AnalyticsManager orchestrates this aggregation, validates stream IDs, and provides a summary endpoint that combines real-time Redis data with historical ClickHouse metrics (peak CCV, total unique views). Additionally, a stubbed CCV broadcaster is wired to the WebSocket hub to prepare for real-time updates, and a skeleton for retention logic is added.

backend/service/analytics-service/src/service · high confidence

Initial database schema and seed data for streaming platform services

This change introduces the foundational database structure for the streaming platform, establishing baseline tables and ENUM types across authentication, billing, chat, moderation, notifications, stream metadata, and VOD services. It defines core entities such as users, profiles, wallets, chat messages, and stream records, including distributed table configurations for Citus. Additionally, it provides seed scripts to populate reference dictionaries (categories, badges) and mock data for testing and baseline operations.

db · high confidence

Initial entry point for the User Profile Service

The User Profile Service now has a concrete application entry point that initializes and starts the server. This main function wires together the database (PostgreSQL), caching layer (Redis), and object storage (MinIO) using configuration values, sets up the profile service with its respective repositories, and exposes the HTTP API via the configured router and port.

backend/service/user-profile-service/cmd · high confidence

Initial gRPC API schemas for authentication and stream metadata

This change introduces the initial protobuf definitions for the backend's gRPC services. It adds the AuthService contract, enabling client-side login and registration flows via defined request and response messages. It also defines the StreamMetaService to support retrieving live stream metadata, including pagination via cursors. Additionally, a shared errors.proto is added to standardize error reporting across services with structured error details and request IDs.

backend/proto · high confidence

Initial gRPC client modules for authentication and stream metadata

The BFF service now includes dedicated gRPC client implementations for the authentication and stream metadata services. The new \auth\_client\ module provides methods to connect to the auth service and perform login and registration operations, while the \stream\_meta\_client\ module enables fetching live stream data. These clients are exposed via the \grpc\_clients\ module, which also includes the generated protobuf definitions for \stremo.auth.v1\ and \stremo.stream\_meta.v1\.

_backend/service/bff\_service/src/grpc\clients · high confidence

Initial implementation of stream ingestion service logic and management

This change introduces the core service layer for the ingest service, adding modules for stream validation, business logic, and lifecycle management. The StreamValidator enforces strict stream key formats (requiring a 'live\_' prefix, minimum length, and alphanumeric characters). The StreamLogic module handles state checks to prevent concurrent broadcasting or restarting finished sessions, and provides utilities for HLS output path generation and duration calculation. The StreamManager orchestrates the start and stop of streams, integrating with Redis for rate limiting, gRPC for authentication, Postgres for state persistence, FFmpeg for transcoding, and Kafka for event publishing.

backend/service/ingest-service/src/service · high confidence

Initial implementation of the Moderation Service with gRPC API and event publishing

The moderation-service is now available to handle content moderation tasks. It exposes a gRPC interface allowing clients to check messages for spam (returning confidence scores and reasons) and to ban users. When a user is banned, the service persists the action to a PostgreSQL audit log and publishes events to Kafka and Redis to notify other systems. The spam detection logic relies on an external ML service configured via the ML\_SERVICE\_URL environment variable.

backend/service/moderation-service · high confidence

Initial implementation of the ingest service entry point and configuration

The ingest service now includes a main entry point that initializes logging, Prometheus metrics, and loads configuration from environment variables (TCP port, gRPC URL, Kafka brokers, HLS output directory, and FFmpeg path). The service sets up connections to an Auth gRPC service, Kafka, PostgreSQL, and Redis, and starts HTTP and TCP/RTMP servers. A minor fix in main.rs corrects a function call argument.

backend/service/ingest-service/src · high confidence

Initial release of ingest-service domain models, DTOs, and event structures

The ingest service now exposes a structured models module containing core domain entities, data transfer objects, and event definitions. Users interacting with the service's internal logic will find a Stream domain model with status tracking (Pending, Active, Finished), DTOs for stream key validation requests and responses, and a typed IngestEvent enum to distinguish between StreamStarted and StreamEnded occurrences.

backend/service/ingest-service/src/models · high confidence

Initial release of the Analytics Service with gRPC and HTTP entry points

The analytics service is now available, providing a unified entry point that runs both gRPC and HTTP servers concurrently. The service loads configuration from environment variables (with sensible defaults for ports and database URLs) and initializes connections to ClickHouse, Redis, and PostgreSQL. It exposes analytics aggregation logic via a gRPC interface and an HTTP API, while also supporting WebSocket communication through a hub. If PostgreSQL is unavailable, the service starts with a warning but continues operating using ClickHouse and Redis.

backend/service/analytics-service/src · high confidence

Initial release of the BFF Service entry point and configuration

The backend service at backend/service/bff\_service/src now includes its main entry point and configuration module. The service initializes an Axum HTTP server that connects to Redis and gRPC backends (Auth and Stream Meta services) using environment variables for configuration. It exposes API routes under /v1/auth and /v1/stream, applies rate limiting and tracing middleware, and handles graceful shutdown via SIGINT/SIGTERM signals.

_backend/service/bff\service/src · high confidence

Initial repository layer for analytics data storage

The analytics service now includes a new repository module that provides data access implementations for ClickHouse, PostgreSQL, and Redis. ClickHouse support enables bulk insertion of ping events and queries for unique view counts and peak concurrent viewers. PostgreSQL integration allows fetching stream metadata by stream ID. Redis support tracks current concurrent viewers with automatic expiration.

backend/service/analytics-service/src/repository · high confidence

Initial repository module structure with StreamRepository trait

The ingest service now exposes a repository module that defines the \StreamRepository\ trait for retrieving stream data by ID. This module initializes the repository layer structure, declaring sub-modules for ClickHouse, PostgreSQL, and Redis, though only the generic database trait definition is currently implemented in this change.

backend/service/ingest-service/src/repository · high confidence

Initial scaffolding of the auth-service C++ backend

This change introduces the foundational structure for the new auth-service, including the CMake build configuration, a Dockerfile for containerization, and the initial source code skeleton. The service is built as a C++ application linking against a core library, exposing port 8080, and includes placeholder implementations for gRPC handlers, Kafka messaging, PostgreSQL and Redis repositories, and utility functions for JWT and password hashing.

backend/service/auth-service · high confidence

Initial server entrypoint for Stream Meta Service

The Stream Meta Service now includes a main entrypoint that initializes the application server. This entrypoint loads configuration, establishes connections to PostgreSQL and Redis, and wires up the dependency injection chain (repositories, service layer, and handlers) before starting the HTTP router.

backend/service/stream-meta-service/cmd · high confidence

Introduce C++ notification service with Kafka ingestion and SSE streaming

The backend now includes a new C++ notification service that consumes messages from a Kafka topic (default 'stream.alerts') and broadcasts them to connected clients via a Server-Sent Events (SSE) endpoint at /api/v1/notifications/stream. The service is configured via environment variables (PORT, KAFKA\_BROKERS, KAFKA\_TOPIC), listens on port 8087 by default, and is containerized with a multi-stage Dockerfile using CMake 3.15 and C++20. Dependencies include nlohmann\_json, cpp-httplib, and librdkafka.

backend/service/notification-service · high confidence

Introduce ML-based spam classification service

A new ML spam filter service is added to the backend, exposing a REST API at /v1/predict to classify messages as spam, toxic, or advertisement using a Hugging Face zero-shot classification model (valhalla/distilbart-mnli-12-1). Users can send a POST request with text, user\_id, and optional channel\_id; the response includes a boolean is\_spam flag, confidence score, reason, and inference time. The service runs on port 8000 via FastAPI, loads the model at startup, and is containerized with a Dockerfile. Configuration (model name, spam threshold, port) is loaded from environment variables or a .env file, with a default spam threshold of 0.6.

backend/service/ml-spam-filter · high confidence

Introduce asynchronous email sending service with Redis queuing

A new internal SMTP service has been added to handle email delivery asynchronously. Users can submit email tasks via a POST request to /internal/v1/mail, which enqueues the request into a Redis queue. A background worker then processes these tasks, rendering HTML templates and sending the emails via SMTP using configurable credentials (host, port, user, password) and a default sender address.

backend/service/smtp-service/internal · high confidence

Introduce chat message and history query models

The chat service now defines the core data structures for handling chat interactions. A ChatMessage domain entity is available to represent individual messages with identifiers, user details, and timestamps. Additionally, DTOs for chat history queries (supporting limit and offset) and responses (containing a list of messages) have been added to facilitate data transfer between the service and its consumers.

backend/service/chat-service/src/models · high confidence

Introduce stream metadata service with live directory and authenticated updates

The backend now includes a new stream metadata service that exposes a live directory endpoint (GET /api/v1/streams/live) returning live streams with viewer counts fetched from Redis, and an authenticated update endpoint (PUT /api/v1/streams/meta/:channel\_id) protected by JWT authentication and owner verification. It also provides an internal key verification endpoint (POST /internal/v1/verify-key) to validate stream keys. Metadata is persisted in PostgreSQL and cached in Redis, with configuration loaded via environment variables for the database, Redis, and JWT secret.

backend/service/stream-meta-service/internal · high confidence

Introduces ChatManager for message orchestration and moderation

The chat service now includes a ChatManager component that centralizes core business logic for handling incoming messages. This manager performs spam detection via a moderation client before processing, persists messages through a database batcher, and publishes them to Redis for real-time distribution. It also provides functionality to retrieve message history and manage local channel subscriptions for efficient in-process message broadcasting.

backend/service/chat-service/src/service · high confidence

Introduces analytics data models for domain, DTOs, and events

The analytics service now includes structured data models to support its core functionality. A new \domain\ module defines the \PingRow\ struct for storing clickhouse metrics, while the \dto\ module provides \AnalyticsSummaryDto\ and \GetSummaryQuery\ for handling API responses and queries. Additionally, an \events\ module introduces the \WsEvent\ enum to manage WebSocket message types like \ccv\_update\ and \summary\_update\. These models are exposed via a new public \models\ module.

backend/service/analytics-service/src/models · high confidence

Introduction of request and response data models for the BFF service

The BFF service now defines explicit data structures for handling API interactions. Request models include LoginRequest, RegisterRequest, and GetStreamsQuery, enabling structured input validation for authentication and stream retrieval. Response models define the shape of API outputs, including LoginResponse (with access\_token, refresh\_token, and expires\_in), RegisterResponse, and StreamCatalogResponse (containing a list of StreamCatalogItems with stream details and pagination via next\_cursor). These models standardize the contract between the service and its clients.

_backend/service/bff\service/src/models · high confidence

Introduction of standardized error codes for Rust services

The Rust core library now exposes a centralized \ErrorCode\ enum that defines specific error types across authentication, billing, streaming, and system domains. This change provides a consistent, machine-readable error structure for all services built on this core, replacing ad-hoc error handling with a unified set of codes such as \InvalidCredentials\, \InsufficientFunds\, and \RateLimitExceeded\.

backend/libs/rust-core · high confidence

Introduction of user profile domain models

The user profile service now includes domain models for representing user profiles and handling profile updates. The new \Profile\ struct defines the structure for user data including ID, username, display name, bio, avatar URL, follower count, and timestamps, while the \UpdateProfileRequest\ struct defines the fields allowed when modifying a user's display name or bio.

backend/service/user-profile-service/internal/models · high confidence

JWT authentication and ownership verification middleware added

The user-profile-service now includes middleware to enforce JWT-based authentication and resource ownership. The new \RequireAuth\ handler validates Bearer tokens using HMAC signing, extracts user claims (user ID and username), and stores the user ID in the request context. The \RequireOwner\ handler checks that the authenticated user's ID matches the resource ID parameter, returning a 403 Forbidden error if the user attempts to modify a profile that does not belong to them.

backend/service/user-profile-service/internal/middleware · high confidence

JWT authentication middleware added to VOD manager service

A new JWT authentication middleware has been introduced in the VOD manager service to protect API endpoints. This middleware validates Bearer tokens using HMAC signing, extracts user identity claims (subject and username), and stores the user ID in the request context for downstream use. Requests without a valid Authorization header or with invalid/expired tokens are rejected with a 401 Unauthorized response.

backend/service/vod-manager-service/internal/middleware · high confidence

Kafka producer for VOD lifecycle events

The VOD manager service now includes a Kafka producer component that publishes clip events to a specified topic. This new capability allows the service to emit lifecycle events, such as clip processing updates, to downstream consumers via Kafka, enabling asynchronous event-driven workflows.

backend/service/vod-manager-service/internal/kafka · high confidence

New analytics API endpoints and WebSocket support

The analytics service now exposes HTTP routes for retrieving stream summaries and checking health, alongside a WebSocket endpoint for live stream updates. A new gRPC server implementation provides \report\_ping\ and \get\_summary\ methods to ingest client data and retrieve aggregated metrics. Additionally, a WebSocket hub manages real-time event broadcasting to connected clients per stream.

backend/service/analytics-service/src/api · high confidence

New infrastructure modules for logging, FFmpeg transcoding, and gRPC authentication

The ingest service now includes a new \infrastructure\ module exposing three key capabilities: a logger initializer that configures \tracing\ with environment-based filtering, an FFmpeg runner that manages HLS transcoding processes (start/stop) for incoming streams, and a gRPC client for validating stream keys against the auth service. These components are registered as public modules in \mod.rs\, providing the foundational infrastructure for stream ingestion and authentication verification.

backend/service/ingest-service/src/infrastructure · high confidence

New transcoder service for adaptive bitrate streaming

A new transcoder service has been introduced to handle adaptive bitrate (ABR) video transcoding. It accepts a stream ID and output directory via command-line arguments, pipes input data to FFmpeg to generate HLS segments at 1080p and 720p resolutions, and notifies the VOD manager service via a webhook upon completion.

backend/service/transcoder-service · high confidence

PostgreSQL repository implementation for stream retrieval

The ingest service now includes a new PostgreSQL repository module that manages database connections via a connection pool and provides a method to retrieve stream details by ID. This implementation executes a SQL query to fetch stream records and maps the database status strings ('active', 'finished', or default 'pending') to the internal domain model, allowing the service to persist and retrieve stream state from a Postgres database.

backend/service/ingest-service/src/repository/postgres · high confidence

PostgreSQL storage implementation for VOD metadata

The VOD manager service now includes a new repository implementation that stores video-on-demand metadata in PostgreSQL. This change adds the \postgres.go\ file, which defines a \PostgresRepo\ struct using the \pgx\ driver to handle database connections. Users benefit from persistent storage capabilities for VOD records, including saving new VOD entries, retrieving specific VODs by ID, and listing VODs associated with a specific channel with pagination support.

backend/service/vod-manager-service/internal/repository · high confidence

Redis-based rate limiting for ingest service

The ingest service now includes a Redis cache module that provides rate limiting functionality. This new component initializes a Redis client and exposes an asynchronous method to check if a specific IP address has exceeded a defined request limit within a given time window, using Redis INCR and EXPIRE commands to track and enforce these limits.

backend/service/ingest-service/src/repository/redis · high confidence

User profile service adds local configuration loader with development defaults

The user profile service now includes a configuration loader that reads settings from environment variables, falling back to hardcoded defaults for local development. This allows the service to start without explicit environment setup by using default values for the port (8082), database connection (PostgreSQL on localhost), Redis, MinIO storage, and JWT secret, while logging warnings when environment variables are missing.

backend/service/user-profile-service/internal/config · high confidence

User profile service exposes HTTP endpoints for viewing, updating, and uploading avatars

The user-profile-service now provides a REST API under /api/v1/profiles to manage user profiles. Users can retrieve their profile via GET, update profile details via PUT, and upload a new avatar image via POST. The update and avatar upload endpoints are protected, requiring valid authentication and ownership verification, while the service is configured with CORS settings to allow cross-origin requests from all origins.

backend/service/user-profile-service/internal/handlers, backend/service/user-profile-service/internal/routers · high confidence

User profile service implementation with caching and avatar support

The user-profile-service now includes the core business logic for managing user profiles. Users can retrieve their profile data, which is cached in Redis for performance, update their display name and bio, and upload profile avatars stored in Minio. The service ensures data consistency by invalidating the cache after updates or avatar uploads.

backend/service/user-profile-service/internal/service · high confidence

User profile service now supports avatar uploads, persistent storage, and caching

The user-profile-service repository layer has been implemented to handle user profile data across three storage backends. It now supports uploading user avatars to MinIO, storing and updating profile details (username, display name, bio, avatar URL) in PostgreSQL, and caching profile data in Redis with configurable TTL and invalidation support.

backend/service/user-profile-service/internal/repository · high confidence

VOD Manager Service introduces environment-based configuration loading

The VOD Manager Service now loads its runtime settings (port, database URL, Kafka brokers, and JWT secret) from environment variables, falling back to hardcoded defaults if they are not provided. This allows users to configure the service's connection details and security credentials without modifying the source code, supporting deployment in environments where secrets are managed externally.

backend/service/vod-manager-service/internal/config · high confidence

VOD Manager Service server entrypoint and dependency injection setup

The VOD Manager Service now includes a main entrypoint that initializes the application server. This entrypoint loads configuration, establishes a connection to the PostgreSQL database using pgx, creates a Kafka producer for the 'stream.clips.requested' topic, and wires together the repository, service, and handler layers. The router is configured with the VOD handler and a JWT secret, and the server starts listening on the configured port.

backend/service/smtp-service/cmd, backend/service/vod-manager-service/cmd · high confidence

VOD service layer for retrieving videos and creating clips

The VOD manager service now includes a core service layer that handles video-on-demand operations. Users can retrieve VODs associated with a specific channel using pagination (limit and offset). Additionally, the service supports creating video clips by validating time ranges against the source VOD duration and publishing a clip event to Kafka for downstream processing.

backend/service/vod-manager-service/internal/service · high confidence

Behavioural changes

Introduces structured error handling and centralized application state for the BFF service

The BFF service now includes a dedicated utilities module that standardizes how errors are reported and how shared dependencies are managed. A new \AppError\ enum maps internal failures (including gRPC upstream errors) to consistent JSON responses with specific HTTP status codes and error codes, ensuring clients receive predictable error formats. Additionally, a centralized \AppState\ struct is introduced to hold shared resources such as configuration, the Redis connection pool, and gRPC clients, providing a single source of truth for service dependencies.

_backend/service/bff\service/src/utils · high confidence

Introduces structured error handling for the ingest service

The ingest service now defines a dedicated \IngestError\ enum to replace generic error handling. This new type provides specific variants for stream validation failures, authentication issues, and infrastructure errors, allowing callers to distinguish between these distinct failure modes and handle them appropriately.

backend/service/ingest-service/src/errors · high confidence

Test coverage

Added unit tests for BFF service configuration, error handling, and data models

New test files have been added to the BFF service to verify core functionality in the CI pipeline. These tests cover configuration loading from environment variables (including defaults and custom values), HTTP status code mapping for application errors (such as invalid credentials and gRPC failures), JWT token encoding/decoding and expiration validation, and JSON serialization/deserialization for login requests, stream queries, and catalog responses.

_backend/service/bff\service/src/tests · high confidence

Dependencies

Initialize backend service dependency manifests for Rust, Go, and Python

The backend directory now includes dependency manifests for multiple services, establishing the build environment for the backend. This adds a Cargo workspace and lockfile for Rust services (bff\_service, analytics-service, chat-service, ingest-service, moderation-service, transcoder-service) using libraries such as axum 0.7, tokio, sqlx 0.8, and redis. It also initializes Go modules for the smtp-service, stream-meta-service, user-profile-service, and vod-manager-service, pinning dependencies like gin 1.12.0, pgx/v5 5.9.1, and go-redis/v9 9.18.0. Additionally, a Python poetry configuration is added for the ml-spam-filter service, specifying fastapi 0.111.0 and torch 2.3.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 50 → 52 (+1.4)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 75 → 82 (+6.6)
  • Architecture 100 → 90 (-10.3)
  • Maturity 64 → 63 (-0.5)
  • Readiness 47 → 49 (+2.3)
  • Security 45 → 53 (+8.1)
  • Domain Modelling 100 → 100 (+0.0)
  • Event Sourcing 100 → 100 (+0.0)
  • Accessibility 45 → 44 (-1.2)

Resolved (45)

  • Build action pinned to a mutable branch
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (backend/service/smtp-service/go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High vulnerability: [GHSA redacted] (frontend/package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 25 more

New (250)

  • Critical CVE: [GHSA redacted] (backend/service/smtp-service/go.mod)
  • Critical vulnerability: [GHSA redacted] (frontend/package-lock.json)
  • Dependency advisory scan runs only on code events
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no project overview (README.md)
  • Duplicate functionality across different services and repositories. Both analytics and ingest services have Postgres repositories with methods to fetch stream data by ID, but with different names ('get_stream_meta' vs 'get_stream') and potentially different return types.
  • Duplicated block (10 lines × 2) (backend/service/ingest-service/src/service/manager.rs)
  • Duplicated block (7 lines × 2) (backend/service/ingest-service/src/infrastructure/kafka/producer.rs)
  • FunctionTooLong: DashboardView.DashboardView (frontend/src/components/features/dashboard/DashboardView.tsx)
  • FunctionTooLong: Footer.Footer (frontend/src/components/layout/Footer.tsx)
  • FunctionTooLong: Header.Header (frontend/src/components/layout/Header.tsx)
  • FunctionTooLong: HeroBanner.HeroBanner (frontend/src/components/features/home/HeroBanner.tsx)
  • FunctionTooLong: SearchOverlay.SearchOverlay (frontend/src/components/layout/SearchOverlay.tsx)
  • FunctionTooLong: SearchView.SearchView (frontend/src/components/features/search/SearchView.tsx)
  • FunctionTooLong: StreamView.StreamView (frontend/src/components/features/stream/StreamView.tsx)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • …and 230 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

CS151512/STREMO was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a92e599bca0999403195bd78ff69563358079a39 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.