Skip to content
CAI
Software that uses CAICheck a score

eric-sfwe/Mini_Ecommerce_Clean

34.3

Weak · 21 September 2026

6.3k

lines of production code

Go

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a full-stack e-commerce platform built with a Go backend and a React frontend, designed to manage the complete lifecycle of online shopping. It provides core capabilities for user authentication, product catalog management with image storage, and shopping cart operations. The application facilitates order processing, including status tracking and email notifications, while enforcing role-based access control for administrative functions.

Features

Add Minio file upload and deletion service

Introduces a new Minio-based storage service in the \pkgs/minio\ package, providing an \IUploadService\ interface and a concrete \MinioClient\ implementation. This allows users to upload files to a specified bucket (defaulting to an 'avatars' folder) and delete them by URL, with the client automatically creating the bucket if it does not exist.

pkgs/minio · high confidence

Add Twilio SMS provider interface and implementation

Introduces a new \twilio\ package that provides an abstraction for sending SMS messages via Twilio. The package defines a \Provider\ interface with methods for sending SMS by phone number and by messaging service, along with a concrete \TwilioClient\ implementation that utilizes the \twilio-go\ SDK to handle the actual API calls.

pkgs/twilio · high confidence

Add utility functions for code generation, password hashing, and data mapping

New utility functions have been added to support core application features: GenerateCode creates alphanumeric identifiers with date prefixes, HashAndSalt provides password hashing via bcrypt, MapStruct enables struct-to-struct copying via JSON serialization, and ToOrderStatus validates order status strings. Additionally, ExtractConstraintName parses database error messages to identify unique constraint violations.

utils · high confidence

Added RBAC authorization and email sending capabilities

This change introduces two new packages to the codebase. The \pkgs/casbin\ package implements Role-Based Access Control (RBAC) using the Casbin library, initializing an enforcer with a GORM adapter and setting default policies for admin and customer roles on users and products resources. Additionally, the \pkgs/mail\ package provides an email sending service, defining an \IMailer\ interface and a concrete \Mailer\ implementation that uses the \gomail\ library to send text or HTML emails via SMTP.

pkgs/casbin · high confidence

Added RBAC authorization model configuration

The system now includes a Role-Based Access Control (RBAC) model configuration file that defines the structure for requests, policies, effects, and matchers. This establishes the foundational rules for how users (subjects), resources (objects), and actions are evaluated to determine access permissions, enabling granular authorization checks based on role assignments.

policy · high confidence

Added Redis client package with interface and implementation

A new \pkgs/redis\ package has been introduced, providing a \IRedis\ interface and its concrete implementation backed by the \github.com/redis/go-redis/v9\ library. This component allows the application to connect to a Redis instance using configurable address, password, and database settings, and exposes methods for standard cache operations including getting, setting (with or without expiration), removing keys, querying keys by pattern, and removing keys matching a pattern. The implementation handles JSON serialization for stored values and includes connection verification via ping.

pkgs/redis · high confidence

Added order repository implementation

Introduced the order repository layer in the order module, providing data access methods for creating orders (with transactional support for order lines), retrieving orders by ID with optional preloading, listing user orders with filtering and pagination, and updating existing orders.

internals/order/repository · high confidence

Added pagination utility for calculating page metadata

A new \Pagination\ struct and \NewPagination\ constructor have been added to the \pkgs/paging\ package to help calculate pagination metadata. This utility automatically determines total pages, skip counts, and previous/next page availability based on the current page, page size, and total item count, with a default page size of 20 and a maximum allowed size of 1000.

pkgs/paging · high confidence

Added product data transfer objects for listing, creation, and updates

New DTOs have been introduced in the product controller layer to handle product-related API interactions. This includes a \ListProductRequest\ and \ListProductResponse\ for paginated product queries with search and sorting capabilities, a \Product\ struct defining the core product data model, and \CreateProductRequest\ and \UpdateProductRequest\ structs that define validation rules and input fields for creating and modifying products, including support for image uploads.

internals/product/controller/dto · high confidence

Added user repository with database persistence layer

Introduced the user repository implementation in the internal package, providing the data access layer for user management. This component defines the IUserRepository interface and its UserRepository struct, enabling core operations such as listing users with pagination and search, retrieving users by ID or email, and performing create, update, and delete actions. The implementation integrates with the existing database abstraction and configuration settings to handle context timeouts and query execution.

internals/user/repository · high confidence

Centralized configuration management for infrastructure services

The application now uses a centralized configuration system (via Viper) to manage settings for HTTP/GRPC ports, database connections, Minio storage, Redis caching, email sending, and Twilio messaging. This change introduces support for environment-specific configurations (production/development) and enforces required environment variables, such as DATABASE\_URI, at startup.

configs · high confidence

Initial HTTP server setup with integrated services and routing

The application now exposes an HTTP server built on Gin, which wires together core domain controllers (user, product, cart, order) and integrates essential infrastructure services including mail, Twilio, MinIO, Redis, and RBAC authorization via Casbin. This entry also enables Prometheus metrics collection at /metrics, Swagger documentation at /swagger, and CORS middleware, establishing the foundational request handling layer for the ecommerce platform.

internals/server · high confidence

Initial HTTP user and authentication endpoints

This change introduces the HTTP layer for user management and authentication. It adds a new \handler.go\ file implementing \AuthHandler\ with endpoints for user sign-up, sign-in, sign-out, and token refresh, along with a user listing endpoint. The \routes.go\ file wires these handlers to the Gin router under \/auth\ and \/users\ paths, integrating middleware for token validation and RBAC authorization policies (e.g., \users:read\, \users:delete\).

internals/user/controller/http · high confidence

Initial Nginx reverse proxy configuration for the application

Added a new Nginx configuration file that sets up a reverse proxy to forward traffic from the public server (app.lvh.me:80) to the internal application service (ecommerce.app:8080). The configuration includes standard proxy headers for client identification and specifically enables WebSocket support by mapping the Upgrade header to handle connection upgrades, ensuring compatibility with real-time features.

nginx · high confidence

Initial application entry point and service wiring

The application now starts via a new main entry point in cmd/app/main.go that initializes core infrastructure services including database connectivity, Casbin RBAC authorization, MinIO storage, email mailing, Twilio SMS, Redis caching, and JWT token generation before launching the HTTP server. A service container file (cmd/app/service/service.go) is also added, though it currently contains only commented-out scaffolding for service composition.

cmd · high confidence

Initial database layer with PostgreSQL support and schema

The application now includes a new database package that initializes a PostgreSQL connection using GORM, complete with connection pooling and a 5-second operation timeout. This change introduces the core data models for the system, including Users, Products, Orders, OrderLines, Carts, and CartLines, along with their associated SQL schema and foreign key constraints. It also provides a Go interface for database operations such as creating, updating, deleting, and finding records, supporting features like batch creation, transactions, and query options for filtering, ordering, and preloading.

db · high confidence

Initial database schema for users, products, orders, and carts

Added migration files to establish the core database tables required for the application. This includes the users table (with role and authentication fields), products table, orders and order\_lines tables for transaction history, and carts and cart\_lines tables for shopping functionality. All tables use text-based IDs and include standard audit timestamps.

migrations · high confidence

Initial frontend release for ecommerce application

The frontend application is now available, providing a complete ecommerce experience built with React, Vite, and Tailwind CSS. Users can browse products, manage a shopping cart, and complete orders. The interface includes a responsive layout with a top navigation bar, product search, and a footer with site links. Authentication is supported via Sign In and Sign Up pages, with user profiles and logout functionality. Admin users have access to a dedicated user management page and can create, update, and delete products through modal dialogs. The application also features order history tracking with status updates (New, Progress, Done, Canceled) and pagination for product and order lists.

frontend · high confidence

Initial implementation of the User Use Case layer

This change introduces the core business logic for user management within the \internals/user/usecase\ package. It defines the \UserUseCase\ struct and its interface, implementing operations for user registration (including avatar upload to MinIO and welcome email via the mailer), sign-in with JWT token generation, sign-out with token blacklisting in Redis, token refresh, and user listing/deletion. The implementation integrates with existing infrastructure services for validation, repository access, caching, and authentication.

internals/user/usecase · high confidence

Initial product management capabilities with image handling

This change introduces the core product use-case logic and its repository layer, enabling users to list, retrieve, create, update, and delete products. The implementation supports paginated product listings with search and sorting, and integrates MinIO for product image uploads, ensuring that images are properly stored during creation and updated or deleted during product modifications.

internals/product/usecase · high confidence

Initial project scaffolding and infrastructure setup

The repository has been initialized with a complete project structure, including a Go backend using Clean Architecture, a React frontend, and a Docker Compose environment for local development. This setup introduces essential infrastructure services such as PostgreSQL, Redis, MinIO, Nginx, Prometheus, and Grafana, along with configuration files for environment variables, build processes (Makefile, Dockerfile), and development tooling (.air.toml).

(repo-wide) · high confidence

Introduce Order and OrderLine domain entities

Added the core data models for the order module, defining the Order entity with fields for ID, code, user association, line items, total price, and status, along with an OrderLine entity to represent individual items within an order. These entities include GORM tags for database mapping and hooks to automatically generate unique IDs and default statuses upon creation, establishing the foundational structure for order management.

internals/order/entity · high confidence

Introduce Product entity with automatic ID and code generation

A new Product entity has been added to the domain model, defining fields for product identification (ID, Code, Name), details (Image, Description, Price), and status (Active, timestamps, soft delete). The entity integrates with GORM for database mapping and automatically generates a unique UUID for the ID and a prefixed code (using the 'P' prefix) upon creation, ensuring consistent data initialization for new products.

internals/product/entity · high confidence

Introduce order management data structures

Added new Data Transfer Objects (DTOs) to define the request and response schemas for the order module. This includes structures for listing orders with pagination support, placing new orders with line-item validation, and representing order details including product information and line items.

internals/order/controller/dto · high confidence

Introduces structured validation with custom error translations

The \pkgs/validation\ package now provides a new validation capability, allowing users to validate structs with customizable error messages. It leverages the \go-playground/validator/v10\ library and includes built-in translations for English, along with specific custom validation rules for \password\ (requiring at least 6 characters) and \countryCode\ (requiring a '+' prefix and minimum 2 characters). Users can configure the validator and translators via functional options.

pkgs/validation · high confidence

Introduces user management DTOs for authentication and listing

This change adds the data transfer objects (DTOs) that define the request and response structures for the user module. Specifically, it introduces DTOs for user sign-up and sign-in (including access and refresh tokens), a DTO for refreshing authentication tokens, a DTO for listing users with pagination and search capabilities, and a core User struct representing the user entity's fields.

internals/user/controller/dto · high confidence

Introduction of structured logging package

A new logging package has been added to the codebase, providing a unified interface for structured logging across the application. It is built on top of the Uber Zap library and supports standard log levels (Debug, Info, Warn, Error, Fatal, Panic) with formatted and key-value variants. The package includes an initialization function that configures the logger based on the environment (production vs. development), setting appropriate log levels, output destinations (stderr), and encoding formats.

pkgs/logger · high confidence

JWT-based authentication token generation and validation

The pkgs/token package now provides core authentication capabilities by introducing JWT (JSON Web Token) support. This includes the ability to generate and validate both short-lived access tokens (5 hours) and long-lived refresh tokens (30 days) using HS256 signing. The implementation defines an AuthPayload structure containing user identity details (ID, email, role) and a Jit (JWT ID), and exposes an IMarker interface for token lifecycle management, allowing the application to secure API endpoints with standard bearer token authentication.

pkgs/token · high confidence

New HTTP endpoints for order management

The order module now exposes HTTP handlers for creating, listing, retrieving, and updating orders. Users can place new orders, filter their order history by code, status, and pagination, view specific order details, and update an order's status via authenticated API calls protected by the existing token middleware.

internals/order/controller/http · high confidence

New middleware suite for authentication, authorization, CORS, and metrics

The application now includes a comprehensive set of HTTP middlewares in the \pkgs/middlewares\ package. Authentication is handled by \AuthMiddleware\, which validates access and refresh tokens against a token service and checks a Redis blacklist before setting user context variables. Access control is enforced via \AuthorizePolicy\, which integrates with Casbin to check role-based permissions against specific objects and actions. Cross-Origin Resource Sharing is managed by \CorsMiddleware\, configured to allow all origins and standard HTTP methods with credentials. Additionally, \PrometheusMiddleware\ is introduced to automatically track HTTP request counts and response latencies for monitoring purposes.

pkgs/middlewares · high confidence

New response helper package for standardized API formatting

Added a new \pkgs/response\ package providing helper functions to standardize API responses. The \JSON\ function simplifies successful responses by wrapping data in a consistent structure, while the \Error\ function handles error responses by including a user-facing message and, in non-production environments, additional debug details from the error object.

pkgs/response · high confidence

New shopping cart service with CRUD operations

This change introduces a new cart domain within the ecommerce application, enabling users to manage their shopping carts via HTTP endpoints. The implementation includes a complete clean-architecture layer: entities for carts and line items, a repository for database persistence, a use case layer for business logic (including price calculation and validation), and an HTTP handler exposing routes to retrieve, add, update, and remove products from a user's cart. The service is secured with authentication middleware and integrates with the existing product repository to fetch product details.

internals/cart · high confidence

Order use case implementation with validation, product lookup, and email notification

The order module now includes a concrete use-case implementation that handles placing, listing, retrieving, and updating orders. When placing an order, the system validates the request, fetches product details to calculate line prices, persists the order, and sends a confirmation email. Users can also list their own orders with pagination, retrieve specific orders by ID, and update order status, with permission checks ensuring users can only modify their own orders and status updates are validated against allowed transitions.

internals/order/usecase · high confidence

Product management API with caching and RBAC

The HTTP controller for the product module now exposes endpoints to list, retrieve, create, and update products. The implementation integrates Redis caching to improve read performance for product listings and details, and enforces role-based access control (RBAC) via middleware policies for write and delete operations.

internals/product/controller/http · high confidence

User entity with automatic cart creation

A new User entity is introduced in the user domain, defining fields for identity, authentication, and role-based access control (defaulting to 'customer'). On creation, the system automatically generates a unique ID, hashes the password, and provisions an empty Cart for the new user, ensuring every account starts with a shopping container.

internals/user/entity · high confidence

Behavioural changes

2 commits (0 fixes) modifying pkgs

A change to existing behaviour in pkgs — 2 commits, 1 file.

pkgs · medium confidence · unverified

Centralized initialization for core infrastructure services

The application now provides a unified set of initialization functions in the \internals/initial\ package to set up critical dependencies at startup. This includes database migration setup via GORM, configuration for the MinIO object storage client, Redis connection management, email sending via the mailer package, and a placeholder initialization for the Twilio SMS provider. This change centralizes the wiring of these services, ensuring they are properly configured and connected before the application logic begins.

dist, internals, internals/initial · high confidence

Dependencies

Initial frontend and backend dependency manifests added

The project now includes the initial dependency configurations for both the frontend and backend services. The frontend (located in \frontend/package.json\) is set up with React 19, Vite 6, Tailwind CSS 4, Redux Toolkit, and related tooling. The backend (located in \go.mod\) initializes the Go module with Gin, GORM, Redis, MinIO, JWT, and various other libraries required for the application's core functionality.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 36 → 34 (-1.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 85 → 94 (+8.8)
  • Architecture 100 → 90 (-9.6)
  • Maturity 54 → 54 (-0.5)
  • Readiness 12 → 14 (+2.1)
  • Security 58 → 67 (+8.7)
  • Domain Modelling 100 → 50 (-49.7)
  • Accessibility 44 → 43 (-1.1)

Resolved (45)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (frontend/package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 3) (internals/order/repository/order.go)
  • Duplicated block (12 lines × 2) (internals/order/controller/http/handler.go)
  • Duplicated block (12 lines × 2) (internals/order/controller/http/handler.go)
  • Duplicated block (12 lines × 2) (internals/product/repository/product.go)
  • Duplicated block (12 lines × 2) (internals/user/usecase/user.go)
  • Duplicated block (16 lines × 2) (internals/product/repository/product.go)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • …and 25 more

New (201)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (frontend/package-lock.json)
  • Dependency pinned to a stale untagged commit: gopkg.in/gomail.v2
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 3) (internals/order/repository/order.go)
  • Duplicated block (11 lines × 2) (internals/order/controller/http/handler.go)
  • Duplicated block (12 lines × 2) (internals/product/repository/product.go)
  • Duplicated block (12 lines × 2) (internals/user/usecase/user.go)
  • Duplicated block (18 lines × 2) (internals/product/repository/product.go)
  • Duplicated block (7 lines × 2) (internals/product/repository/product.go)
  • Duplicated block (7 lines × 2) (internals/product/usecase/product.go)
  • Duplicated block (9 lines × 2) (internals/order/controller/http/handler.go)
  • FunctionTooLong: Cart.Cart (frontend/src/pages/cart/Cart.tsx)
  • FunctionTooLong: SignUp.SignUp (frontend/src/pages/auth/SignUp.tsx)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • …and 181 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

eric-sfwe/Mini_Ecommerce_Clean was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fef42731436533b9db0c730e9f4d01779ded88a4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.