dzungtran/echo-rest-api
69.4
Adequate · 21 September 2026
4.4k
lines of production code
Go
primary language
4
measurements over time
What this system is
Features
Add OPA-based authorization and user/org policy enforcement
The \pkg/authz\ package introduces an Open Policy Agent (OPA) integration to enforce access control policies. This includes new \data.json\ and \routes.json\ files that map API endpoints to required permissions and define role-based access for org and user resources. The \opa.go\ file initializes the OPA engine with embedded Rego policies (\rego/main.rego\, \rego/deny.rego\, etc.) that evaluate user roles and resource permissions to allow or deny requests. Additionally, middleware functions (\CheckPolicies\, \CheckPoliciesWithOrg\, \CheckPoliciesWithProject\) are added to the \pkg/middlewares\ package to integrate this authorization check into the request lifecycle. Tests for org and user policies are also included to verify the new access control logic.
pkg · high confidence
Add modgen CLI tool for generating modular code templates
Introduces a new CLI tool, \modgen\, located in \tools/mod\, which generates modular application code from templates. The tool reads a \.modgen.yaml\ configuration file and Go templates to scaffold components including domain models, DTOs, handlers, repositories, and use cases, with support for pluralization and case conversion. It also includes a version command and a root command structure using Cobra.
tools/mod · high confidence
Added automated route generation utility
A new Go utility at tools/routes/main.go has been added to automatically generate a JSON file (routes.json) that maps HTTP methods to route names. This tool iterates over all registered Echo routes, filters out internal framework routes, and writes the resulting map to the project's authz package, enabling other parts of the system to access a structured list of available API endpoints.
tools/routes · medium confidence
Added initial database migration scripts
The application now includes the initial database schema for PostgreSQL, defining tables for organizations, users, and their relationships. This migration, managed by the golang-migrate library, establishes the foundational data structures required for the system to function.
migrations · high confidence
Added pre-commit hook to enforce code formatting and tests
A new pre-commit hook has been introduced in the tools/scripts directory. This hook automatically runs gofmt to format Go code and executes the test suite for the pkg/authz package before each commit, failing the commit if the tests do not pass.
tools/scripts · high confidence
Introduce core user and organization management capabilities
The application now supports creating, updating, and deleting organizations and users. Users can authenticate via Firebase, view their own profile, and manage organization details. The system enforces role-based access control for organization resources and provides endpoints to list, create, update, and delete organizations, as well as manage user accounts and their roles within organizations.
modules/core · high confidence
Introduce modular project management capabilities
Users can now create, read, update, and delete projects via the /admin/projects endpoints. This change introduces a modular structure for the projects module, including domain models, DTOs, handlers, use cases, and repositories, enabling full CRUD operations for project resources.
modules/projects · high confidence
Behavioural changes
Add SQL database client wrappers for master and slave instances
The infrastructure layer now includes new Go files (sql.go) that define MasterDbInstance and SlaveDbInstance wrappers around sqlx.DB, providing factory functions to initialize PostgreSQL database connections with specific connection pool settings. A commented-out Redis client implementation (redis.go) is also added, indicating a shift away from Redis in favor of SQL-based data storage.
infrastructure · medium confidence
Centralized application configuration and logging setup
The application now uses a centralized configuration system in the config package. The new app.go file defines an AppConfig struct that loads environment variables for settings such as the server port, database URL, and third-party integrations including Firebase, Kratos, and CORS. It also initializes a custom validator for request validation. Additionally, echo.go provides a dedicated function to configure Echo framework logging with RFC3339 time formatting.
config · medium confidence
Introduces modular, dependency-injection-based API structure
The API entry point (cmd/api/main.go) and a new dependency injection container (cmd/api/di/di.go) have been added to the codebase. This change shifts the application from a flat structure to a modular architecture where modules (such as 'core' and 'projects') are registered via a DI container. This enables better organization of handlers, use cases, and repositories, and integrates Swagger documentation generation into the startup process.
cmd · high confidence
Dependencies
Updated Go dependencies to latest versions
The project's Go dependencies have been updated to their latest versions. This includes upgrades to key libraries such as the Echo web framework (v4.15.1), the Open Policy Agent (v1.15.1), and gRPC (v1.79.3), alongside numerous indirect dependencies. These updates ensure the application uses the most recent, stable releases of its Go modules.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 69 → 69 (+0.9)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 97 → 97 (-0.1)
- Architecture 100 → 87 (-12.7)
- Maturity 75 → 75 (+0.0)
- Readiness 74 → 66 (-8.0)
- Security 72 → 84 (+12.8)
- Domain Modelling 60 → 64 (+4.1)
Resolved (30)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (pkg/middlewares/middleware.go)
- Duplicated block (12 lines × 2) (pkg/utils/strings.go)
- Duplicated block (13 lines × 2) (modules/core/repositories/org.go)
- Duplicated block (13 lines × 2) (modules/core/repositories/user_org.go)
- Duplicated block (14 lines × 4) (modules/core/repositories/org.go)
- Duplicated block (15 lines × 2) (modules/core/repositories/org.go)
- Duplicated block (15 lines × 2) (modules/core/repositories/user.go)
- Duplicated block (15 lines × 3) (modules/core/repositories/org.go)
- Duplicated block (8 lines × 2) (pkg/middlewares/middleware.go)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High vulnerability: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 10 more
New (61)
- Critical CVE: [GHSA redacted] (go.mod)
- Documentation: no architecture or design documentation (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (pkg/middlewares/middleware.go)
- Duplicated block (11 lines × 2) (pkg/authz/opa.go)
- Duplicated block (11 lines × 2) (pkg/utils/strings.go)
- Duplicated block (11 lines × 4) (modules/core/repositories/org.go)
- Duplicated block (12 lines × 2) (modules/core/repositories/org.go)
- Duplicated block (12 lines × 2) (modules/core/repositories/user_org.go)
- Duplicated block (13 lines × 3) (modules/core/repositories/org.go)
- Duplicated block (15 lines × 2) (modules/core/usecases/user.go)
- Duplicated block (15–16 lines × 2) (modules/core/repositories/user.go)
- Duplicated block (18 lines × 2) (modules/core/repositories/org.go)
- Duplicated block (18 lines × 3) (modules/core/repositories/org.go)
- Duplicated block (6 lines × 3) (modules/core/repositories/user.go)
- Duplicated block (7 lines × 2) (modules/core/handlers/org.go)
- Duplicated block (8 lines × 2) (pkg/middlewares/functions.go)
- Duplicated block (9 lines × 3) (modules/core/usecases/org.go)
- High CVE: [GHSA redacted] (go.mod)
- …and 41 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
dzungtran/echo-rest-api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 495accb4c102d2f3017c71fdf03783b6e6a214cb — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.