Skip to content
CAI
Software that uses CAICheck a score

dzungtran/echo-rest-api

69.4

Adequate · 21 September 2026

4.4k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add OPA-based authorization and user/org policy enforcement

The \pkg/authz\ package introduces an Open Policy Agent (OPA) integration to enforce access control policies. This includes new \data.json\ and \routes.json\ files that map API endpoints to required permissions and define role-based access for org and user resources. The \opa.go\ file initializes the OPA engine with embedded Rego policies (\rego/main.rego\, \rego/deny.rego\, etc.) that evaluate user roles and resource permissions to allow or deny requests. Additionally, middleware functions (\CheckPolicies\, \CheckPoliciesWithOrg\, \CheckPoliciesWithProject\) are added to the \pkg/middlewares\ package to integrate this authorization check into the request lifecycle. Tests for org and user policies are also included to verify the new access control logic.

pkg · high confidence

Add modgen CLI tool for generating modular code templates

Introduces a new CLI tool, \modgen\, located in \tools/mod\, which generates modular application code from templates. The tool reads a \.modgen.yaml\ configuration file and Go templates to scaffold components including domain models, DTOs, handlers, repositories, and use cases, with support for pluralization and case conversion. It also includes a version command and a root command structure using Cobra.

tools/mod · high confidence

Added automated route generation utility

A new Go utility at tools/routes/main.go has been added to automatically generate a JSON file (routes.json) that maps HTTP methods to route names. This tool iterates over all registered Echo routes, filters out internal framework routes, and writes the resulting map to the project's authz package, enabling other parts of the system to access a structured list of available API endpoints.

tools/routes · medium confidence

Added initial database migration scripts

The application now includes the initial database schema for PostgreSQL, defining tables for organizations, users, and their relationships. This migration, managed by the golang-migrate library, establishes the foundational data structures required for the system to function.

migrations · high confidence

Added pre-commit hook to enforce code formatting and tests

A new pre-commit hook has been introduced in the tools/scripts directory. This hook automatically runs gofmt to format Go code and executes the test suite for the pkg/authz package before each commit, failing the commit if the tests do not pass.

tools/scripts · high confidence

Introduce core user and organization management capabilities

The application now supports creating, updating, and deleting organizations and users. Users can authenticate via Firebase, view their own profile, and manage organization details. The system enforces role-based access control for organization resources and provides endpoints to list, create, update, and delete organizations, as well as manage user accounts and their roles within organizations.

modules/core · high confidence

Introduce modular project management capabilities

Users can now create, read, update, and delete projects via the /admin/projects endpoints. This change introduces a modular structure for the projects module, including domain models, DTOs, handlers, use cases, and repositories, enabling full CRUD operations for project resources.

modules/projects · high confidence

Behavioural changes

Add SQL database client wrappers for master and slave instances

The infrastructure layer now includes new Go files (sql.go) that define MasterDbInstance and SlaveDbInstance wrappers around sqlx.DB, providing factory functions to initialize PostgreSQL database connections with specific connection pool settings. A commented-out Redis client implementation (redis.go) is also added, indicating a shift away from Redis in favor of SQL-based data storage.

infrastructure · medium confidence

Centralized application configuration and logging setup

The application now uses a centralized configuration system in the config package. The new app.go file defines an AppConfig struct that loads environment variables for settings such as the server port, database URL, and third-party integrations including Firebase, Kratos, and CORS. It also initializes a custom validator for request validation. Additionally, echo.go provides a dedicated function to configure Echo framework logging with RFC3339 time formatting.

config · medium confidence

Introduces modular, dependency-injection-based API structure

The API entry point (cmd/api/main.go) and a new dependency injection container (cmd/api/di/di.go) have been added to the codebase. This change shifts the application from a flat structure to a modular architecture where modules (such as 'core' and 'projects') are registered via a DI container. This enables better organization of handlers, use cases, and repositories, and integrates Swagger documentation generation into the startup process.

cmd · high confidence

Dependencies

Updated Go dependencies to latest versions

The project's Go dependencies have been updated to their latest versions. This includes upgrades to key libraries such as the Echo web framework (v4.15.1), the Open Policy Agent (v1.15.1), and gRPC (v1.79.3), alongside numerous indirect dependencies. These updates ensure the application uses the most recent, stable releases of its Go modules.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 69 → 69 (+0.9)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 97 (-0.1)
  • Architecture 100 → 87 (-12.7)
  • Maturity 75 → 75 (+0.0)
  • Readiness 74 → 66 (-8.0)
  • Security 72 → 84 (+12.8)
  • Domain Modelling 60 → 64 (+4.1)

Resolved (30)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (pkg/middlewares/middleware.go)
  • Duplicated block (12 lines × 2) (pkg/utils/strings.go)
  • Duplicated block (13 lines × 2) (modules/core/repositories/org.go)
  • Duplicated block (13 lines × 2) (modules/core/repositories/user_org.go)
  • Duplicated block (14 lines × 4) (modules/core/repositories/org.go)
  • Duplicated block (15 lines × 2) (modules/core/repositories/org.go)
  • Duplicated block (15 lines × 2) (modules/core/repositories/user.go)
  • Duplicated block (15 lines × 3) (modules/core/repositories/org.go)
  • Duplicated block (8 lines × 2) (pkg/middlewares/middleware.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High vulnerability: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 10 more

New (61)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (pkg/middlewares/middleware.go)
  • Duplicated block (11 lines × 2) (pkg/authz/opa.go)
  • Duplicated block (11 lines × 2) (pkg/utils/strings.go)
  • Duplicated block (11 lines × 4) (modules/core/repositories/org.go)
  • Duplicated block (12 lines × 2) (modules/core/repositories/org.go)
  • Duplicated block (12 lines × 2) (modules/core/repositories/user_org.go)
  • Duplicated block (13 lines × 3) (modules/core/repositories/org.go)
  • Duplicated block (15 lines × 2) (modules/core/usecases/user.go)
  • Duplicated block (15–16 lines × 2) (modules/core/repositories/user.go)
  • Duplicated block (18 lines × 2) (modules/core/repositories/org.go)
  • Duplicated block (18 lines × 3) (modules/core/repositories/org.go)
  • Duplicated block (6 lines × 3) (modules/core/repositories/user.go)
  • Duplicated block (7 lines × 2) (modules/core/handlers/org.go)
  • Duplicated block (8 lines × 2) (pkg/middlewares/functions.go)
  • Duplicated block (9 lines × 3) (modules/core/usecases/org.go)
  • High CVE: [GHSA redacted] (go.mod)
  • …and 41 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

dzungtran/echo-rest-api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 495accb4c102d2f3017c71fdf03783b6e6a214cb — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.