eldimious/nodejs-api-showcase
52.8
Adequate · 21 September 2026
1.9k
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
This is a Node.js backend system that manages user accounts and blog-style posts through a structured, layered architecture. It provides HTTP and WebSocket APIs for authentication, user management, and post creation, backed by a MongoDB data layer with Redis-based rate limiting. The codebase emphasizes security, logging, and test coverage for its core domain logic.
How it got here
2017–2019 — API and domain layer implementation
7 changes.
This period focused on establishing the core architecture of a Node.js API, organizing the codebase into distinct layers for data, domain, and infrastructure. Key features included implementing MongoDB schemas, authentication services, and centralized logging, while also introducing Swagger documentation and utility functions for process management.
2020–2022 — Core domain and presentation layer implementation
5 changes.
The project established the foundational data access layer by implementing repositories for authentication, users, and posts, alongside a centralized constants module. This was followed by the creation of an HTTP and WebSocket presentation layer to expose these capabilities, supported by comprehensive test coverage for the new endpoints and service logic.
Features
Add Swagger API documentation and error handling utilities
The API now includes a complete Swagger 2.0 specification that documents the Auth, Posts, and Users endpoints, along with shared response schemas for errors (400, 401, 404, 500) and data models for User, Post, and Token. Additionally, a new \src/common/errors\ module exports HTTP error helpers, and a \src/signals\ module provides a process exit handler, supporting the overall API structure.
src/common/errors, src/signals, src/swagger · high confidence
Added MongoDB database layer with Post and User schemas
The data infrastructure now includes a new database connection module that initializes a MongoDB connection using Mongoose, exposing methods to connect, retrieve the connection, close it, and access defined schemas. New schema definitions for Post and User models have been added, including field definitions, indexes, pagination support for posts, and pre-save hooks for timestamps and password hashing. The schemas are exported via an index file, enabling the application to interact with the database through this structured data access layer.
src/data/infrastructure · high confidence
Added utility functions and worker process management
Added a new helper utility that provides a function to calculate retry-after seconds from milliseconds, and introduced a new module to manage worker processes using Node.js cluster module to spawn and monitor worker processes based on available CPU cores.
src/common/utils · high confidence
Initial HTTP and WebSocket presentation layer for user and post management
The application now exposes HTTP and WebSocket endpoints for user and post operations. The HTTP layer is built on Express, featuring JWT-based authentication, input validation for user and post bodies, and error handling. Key endpoints include user registration and login, retrieving user profiles with their posts, and creating or fetching posts. A WebSocket handler is also introduced to broadcast custom events. Response models are structured to exclude sensitive data like passwords.
src/presentation · high confidence
Introduces centralized logging with Winston and Express-Winston
Adds a new logging module at src/common/logging/index.js that configures Winston for application logs and Express-Winston for HTTP request/error logging. The module exports request and error loggers, plus convenience methods (info, warn, error, etc.) that respect environment-based log levels, providing a unified logging interface for the application.
src/common/logging · high confidence
Introduces domain layer models and services for authentication, posts, tokens, and users
The application now includes a structured domain layer with new model and service files. Authentication is handled via a new auth service that manages login and registration logic, including rate limiting for failed attempts. A new posts domain provides services to list, create, and retrieve user posts. Token management is supported by a new Token model and service. User data is encapsulated in a User model and a corresponding service that fetches user details along with their posts. These changes establish the core business logic and data structures for these key features.
src/domain · high confidence
New data repository implementations for authentication, users, posts, and rate limiting
The application now includes four new repository modules that abstract data access for core domain models. The authentication repository handles password hashing and JWT token generation/verification. The users repository manages user creation and retrieval. The posts repository provides methods for listing, creating, and fetching individual posts with pagination support. Additionally, a resource limiter repository has been added to track consecutive failed login attempts using Redis, supporting security measures against brute-force attacks.
src/data/repositories · high confidence
Behavioural changes
Application startup and configuration logic moved to src
The application's entry point and configuration have been reorganized into the src directory. A new src/server.js file now handles the initialization of services, repositories, and the HTTP/WebSocket servers, including cluster mode support and graceful shutdown. Configuration is now explicitly managed via src/configuration/index.js, which loads environment variables for database, HTTP, JWT, and Redis. Additionally, a data mapper utility has been added at src/data/mapper/index.js to handle database-to-domain and domain-to-database transformations.
src · high confidence
Centralized application constants and configuration
A new constants module has been introduced to centralize key application settings. This includes configuration for user token expiration, user roles, and password complexity requirements (minimum length, character types). It also defines limits for failed login attempts, environment names, logging levels, and default pagination settings.
src/common/constants · high confidence
Test coverage
Added tests for post repository and service logic; Added tests for user post retrieval endpoint.
Dependencies
Initial project dependencies established
The project now includes a comprehensive set of dependencies for building a Node.js API, including Express, Mongoose, and Socket.io for real-time features, alongside testing and linting tools like Mocha, ESLint, and Nodemon.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 54 → 53 (-0.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 67 → 70 (+2.5)
- Architecture 100 → 85 (-14.7)
- Maturity 57 → 57 (+0.0)
- Readiness 37 → 36 (-1.5)
- Security 79 → 80 (+1.1)
- Domain Modelling 100 → 100 (+0.0)
Resolved (56)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 36 more
New (98)
- Coverage not measured — JavaScript/TypeScript suite
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 78 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
eldimious/nodejs-api-showcase was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6a35edb0b0a14cf3e951ff87c110b89022102d8a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.