Skip to content
CAI
Software that uses CAICheck a score

falberthen/EcommerceDDD

47.6

Weak · 21 September 2026

17k

lines of production code

C#

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a containerized e-commerce platform built on a microservices architecture using .NET 10 and Angular 21. It implements Domain-Driven Design with CQRS and event sourcing via Marten and Wolverine to manage core business domains such as orders, payments, inventory, and customer profiles. The platform provides a secure, authenticated frontend SPA that communicates with backend services through an API Gateway, featuring real-time order status updates via SignalR and comprehensive distributed observability.

How it got here

2020–2024 — Microservices modernization and SPA introduction

22 changes.

The project underwent a comprehensive infrastructure overhaul, migrating from .NET Core 3.1 to .NET 10 and replacing custom messaging with Wolverine and Marten for event sourcing. A new Angular Single Page Application was introduced with Cypress E2E testing, while the backend was restructured into a microservices architecture featuring an API Gateway, IdentityServer, and dedicated domain services like Customer Management.

2025–2026 — Kiota client migration and real-time features

7 changes.

The project migrated its API communication layer to a strongly-typed, Kiota-generated TypeScript SDK for both the SPA and backend service clients, enhancing type safety and resilience. Concurrently, it introduced real-time order status updates via a new SignalR hub and expanded observability with OpenTelemetry integration. The period also saw the addition of customer account management features and event history views within the frontend application.

Features

Add OpenTelemetry observability with Aspire Dashboard support

The application now includes built-in distributed tracing, metrics, and logging via OpenTelemetry, configured to export data using the OTLP protocol for integration with the Aspire Dashboard. This setup automatically instruments ASP.NET Core HTTP requests, HTTP client calls, and PostgreSQL database interactions, while also capturing spans from the Wolverine framework (specifically the outbox, broker, and handler operations) to provide end-to-end visibility across the system.

src/Core/EcommerceDDD.Core.Infrastructure/OpenTelemetry · high confidence

Add environment configuration for distributed tracing and SignalR integration

The Angular SPA now includes environment configuration files that define URLs for the API gateway, the SignalR orders hub, and the Aspire dashboard. This enables the frontend to connect to real-time order updates via SignalR and allows users to access the Aspire observability dashboard directly from the application context.

src/EcommerceDDD.Spa/src/environments · high confidence

Added HTTP interceptors for authentication and loading state management

The application now includes two new HTTP interceptors to handle common request behaviors. The auth interceptor automatically attaches the Bearer token to outgoing requests and triggers a logout when a 401 Unauthorized response is received. The loader interceptor manages a global loading state, activating it at the start of an HTTP request and deactivating it upon completion, enabling UI feedback during network activity.

src/EcommerceDDD.Spa/src/app/core/interceptors · high confidence

Angular SPA introduced with Cypress E2E testing and Docker support

The EcommerceDDD application now includes a new Angular Single Page Application (SPA) located in src/EcommerceDDD.Spa. This addition brings a complete frontend environment, including a Dockerfile for containerized deployment via Nginx, and an end-to-end (E2E) testing suite powered by Cypress that validates core user flows such as login, product selection, cart management, and checkout. The SPA is configured with Angular CLI, Jest for unit testing, and specific TypeScript path mappings for modular code organization.

src/EcommerceDDD.Spa · high confidence

Automated backend client generation and multi-database initialization scripts added

New scripts have been introduced to streamline development setup and service communication. The \db\_init.sql\ script now automatically provisions eight distinct databases (identityserver, products, inventory, customers, quotes, orders, payments, and shipments) to support the microservice architecture. Additionally, \regenerate-clients.sh\ automates the generation of C\# backend service clients for eight specific services (SignalR, IdentityServer, ProductCatalog, InventoryManagement, CustomerManagement, QuoteManagement, PaymentProcessing, and ShipmentProcessing) using Kiota, as well as a unified TypeScript API client for the frontend via the API Gateway.

scripts · high confidence

Core DDD infrastructure and security guardrails

The core library now provides the foundational building blocks for a Domain-Driven Design architecture, including CQRS interfaces (ICommand, IQuery), domain primitives (AggregateRoot, Entity, StronglyTypedId, ValueObject), and an event store repository contract (IEventStoreRepository) that integrates with Wolverine's durable outbox for transactional consistency. To address OWASP API1 (Broken Object Level Authorization), the core introduces a reflection-based ownership guard rule (OwnershipGuardRule) that detects command/query handlers accepting customer-owned resource IDs without verifying the current user's identity, alongside specific FluentResults error types (ForbiddenError, RecordNotFoundError) to standardize validation responses.

src/Core/EcommerceDDD.Core · high confidence

IdentityServer authentication and authorization infrastructure introduced

The IdentityServer service now provides user registration and login endpoints (v2 API) backed by a PostgreSQL database with Entity Framework Core migrations. It configures Duende IdentityServer with specific API scopes (read, write, delete) and clients, manages ASP.NET Identity user data, and persists data protection keys to ensure consistent token signing and encryption across deployments.

src/Crosscutting/EcommerceDDD.IdentityServer · high confidence

Introduce API Gateway with Ocelot routing and Swagger aggregation

The EcommerceDDD.ApiGateway service is introduced to centralize external access to the microservices architecture. It uses Ocelot to route upstream requests (e.g., /customerManagement, /orderProcessing) to their respective downstream services (e.g., ecommerceddd-customer-management) with consistent Bearer token authentication and Quality of Service (QoS) options like timeouts and circuit-breaker durations. The gateway aggregates Swagger documentation from individual services using Koalesce, exposing a unified API definition at /swagger/v2/apigateway.yaml for easier client consumption. It also handles SignalR proxying for real-time updates and is containerized with a Dockerfile targeting .NET 10.

src/Crosscutting/EcommerceDDD.ApiGateway · high confidence

Introduce Customer Management service with registration, profile updates, and event history

A new Customer Management service has been added to the platform, enabling customers to register accounts, update their profile information (name, shipping address, store credit), and view their event history. The service exposes public registration and internal endpoints for retrieving customer details and store credit, backed by a domain model that enforces email uniqueness and data validation. It utilizes Marten for event sourcing and projections to maintain customer details and history, and is containerized with a .NET 10 Dockerfile.

src/Services · high confidence

Introduce SignalR-based real-time order status updates

A new SignalR service has been added to provide real-time order status notifications. The service exposes an OrderStatusHub at the /api/v2/signalr endpoint, allowing authenticated customers to subscribe to updates for their own orders. It is configured with API versioning (v2), Swagger documentation, and health checks, and is containerized via a new Dockerfile for deployment.

src/Crosscutting/EcommerceDDD.SignalR · high confidence

Introduces core SPA services for API error handling, authentication, and real-time updates

The application now includes a dedicated set of core services to manage user experience and connectivity. A new error handling pipeline (ApiErrorParserService and ApiErrorHandlerService) standardizes how API failures are parsed and displayed, ensuring users see clear, deduplicated messages for validation errors, server issues, or gateway timeouts. Authentication is managed via AuthService and TokenStorageService, which handle login/logout flows and persist access tokens. Connectivity is enhanced with KiotaClientService, which configures HTTP clients for both authenticated and anonymous requests, and SignalrService, which establishes a real-time connection to the orders hub for live updates.

src/EcommerceDDD.Spa/src/app/core/services · high confidence

New API endpoint to trigger real-time order status broadcasts

A new v2 API endpoint (POST /api/v2/signalr/updateorderstatus) has been added to the SignalR cross-cutting layer, allowing authorized M2M clients to trigger real-time order status updates. The endpoint accepts a request containing the customer ID, order ID, status text, and status code, and uses the new IOrderStatusUpdater service to broadcast the update to the specific customer's SignalR group via the OrderStatusHub.

src/Crosscutting/EcommerceDDD.SignalR/API · high confidence

New SPA shell and shared UI components

The application now includes a new Angular SPA entry point with a navigation menu, routing configuration, and shared UI components. Users will see a main layout with a nav menu displaying links to Orders, Products, and Profile, along with a currency selector and logout option. The SPA also introduces a confirmation dialog modal, a loader skeleton for loading states, and a stored events viewer that displays a timeline of event history with formatted fields. These components are registered in the app configuration and routed through the new app.routes.ts file.

src/EcommerceDDD.Spa/src/app/shared · high confidence

New customer account creation and login pages with currency selection and event history

The application now includes dedicated pages for creating a new customer account and logging in, featuring form validation and account creation workflows. A currency dropdown component allows users to switch between USD, CAD, and EUR, with the selection persisted in local storage. Additionally, the cart, customer details, and orders views now support viewing stored event history for quotes, customer profiles, and orders respectively, and the orders view includes a 'Confirm Delivery' action for shipped orders.

src/EcommerceDDD.Spa/src/app/features/ecommerce · high confidence

New identity infrastructure with role-based access and customer ownership checks

The Identity layer now includes a complete set of new components to handle authentication and authorization. This introduces JWT-based authentication with support for SignalR query-string tokens, a centralized policy builder defining CanRead, CanWrite, and CanDelete scopes, and a dedicated TokenRequester that caches application tokens to reduce IdentityServer load. Crucially, it adds a CustomerOwnershipExtensions helper to enforce Broken Object Level Authorization (BOLA) protections by ensuring resources belong to the current customer, alongside interfaces and implementations for retrieving user info and tokens.

src/Core/EcommerceDDD.Core.Infrastructure/Identity · high confidence

Architecture

Comprehensive infrastructure and development environment overhaul

The repository has been restructured to support a modern, containerized development workflow. A new Docker Compose stack is introduced, defining infrastructure services (PostgreSQL 18, Kafka 7.8.0, Kafka UI, pgAdmin, and the Aspire Dashboard) and orchestrating the application's microservices (IdentityServer, API Gateway, SignalR, and domain services like Order and Payment Processing) with standardized health checks and dependency management. The solution file has been significantly refactored to reflect a new project topology, separating Core, Crosscutting, and Services layers, and adding dedicated test projects for each service. Additionally, developer tooling has been updated with a new .editorconfig for consistent C\# styling, a .nvmrc pinning Node.js to 20.20.0, and a new Docker Compose 'tools' profile that automates Kiota client regeneration using .NET SDK 10.0.

(repo-wide) · high confidence

Behavioural changes

Adopts Wolverine for messaging and introduces Newtonsoft serialization for durable messages

The infrastructure layer has replaced its previous custom CQRS and Kafka-based messaging implementation with Wolverine. This change introduces a new Newtonsoft-based message serializer (NewtonsoftMessageSerializer) specifically designed to handle the serialization of immutable domain value objects and command records for durable inbox and dead-letter scenarios, ensuring reliable message persistence and recovery within the new Wolverine transport.

src/Core/EcommerceDDD.Core.Infrastructure · high confidence

Generated Kiota-based API client for the SPA

The SPA now uses a Microsoft Kiota-generated TypeScript SDK to communicate with the backend, replacing the previous manual HTTP client implementation. This new client provides a strongly-typed, fluent API for all backend services, including customer management (registration, details, history), inventory management (stock tracking), order processing, product catalog, and quote management. The change introduces a new \ApiClient\ entry point and associated request builders that handle serialization, deserialization, and error mapping for the API v2 endpoints, ensuring type safety and consistent request construction across the application.

src/EcommerceDDD.Spa/src/app/clients · high confidence

Introduce Kiota-based backend service clients with resilience and configuration

The service client layer has been refactored to use Kiota-generated HTTP clients for all backend services (Identity, Customer Management, Inventory, Product Catalog, Quote, Payment, Shipment, and SignalR). These clients are registered via extension methods that apply Polly-based resilience policies (retry with exponential backoff and circuit breaking) and automatic Bearer token authentication. Configuration is centralized in a new ServiceClientsOptions class, mapping to the 'Services' configuration section, and the clients are explicitly registered for service location to support Wolverine's code generation requirements.

src/Crosscutting/EcommerceDDD.ServiceClients · high confidence

Introduce Marten-based event store with Wolverine outbox integration

The infrastructure layer now uses Marten as the event store, replacing previous custom CQRS/Kafka/outbox implementations. This change introduces a new \MartenRepository\ that handles event appending and fetching with optimistic concurrency, while integrating with Wolverine's outbox to ensure durable delivery of integration events alongside aggregate state changes. Configuration is managed via \MartenConfigExtension\, supporting separate read/write schemas and Newtonsoft serialization, and a new \IQuerySessionWrapper\ is provided to facilitate testing by abstracting Marten's query session.

src/Core/EcommerceDDD.Core.Infrastructure/Marten · high confidence

Introduce dedicated API service wrappers for Kiota clients

The application now uses specific Angular services (Auth, Customer, Inventory, Order, Product Catalog, and Quote) to handle API communication. These new services act as wrappers around the underlying Kiota HTTP client, centralizing error handling and providing a cleaner interface for the rest of the application to interact with backend endpoints.

src/EcommerceDDD.Spa/src/app/core/services/api · high confidence

Migrate core infrastructure to Wolverine and add OpenTelemetry observability

The core infrastructure now uses Wolverine for command, query, and event dispatch, replacing the previous custom CQRS and Kafka-based outbox implementation. This change introduces conventional handler discovery, automatic retry with cooldown on transient failures, and dead-lettering for exhausted attempts, while also integrating OpenTelemetry for distributed tracing and metrics. Additionally, standard .NET services such as memory caching, HTTP context access, JWT authentication, and Swagger are registered, alongside a new utility for retrieving enum descriptions.

src/Core/EcommerceDDD.Core.Infrastructure/Extensions · high confidence

Standardized API error responses and versioning infrastructure

The WebApi infrastructure now provides a consistent error-handling model and API versioning support. Controllers inherit from a new CustomControllerBase that automatically maps CQRS command/query results to standardized HTTP ProblemDetails responses, handling specific cases like validation errors (422), forbidden access (403), and not found (404). A GlobalExceptionHandler catches unhandled exceptions, mapping domain exceptions to 422 and others to 500, while including trace IDs in the response. API versioning is configured to default to V2, read versions from URL segments, and report available versions. Additionally, Swagger UI is configured to document the API with Bearer JWT authentication requirements, and a health check endpoint is exposed at /health.

src/Core/EcommerceDDD.Core.Infrastructure/WebApi · high confidence

Test coverage

Added global usings for test infrastructure; Added test infrastructure for HTTP mocking; Added unit tests for AggregateRoot and StronglyTypedId domain primitives; Added unit tests for CQRS command and query handlers; Added unit tests for the TokenRequester service.

Dependencies

Upgrade to .NET 10 and Angular 21 with centralized dependency management

The project has been upgraded to target .NET 10.0 (previously .NET Core 3.1) and Angular 21.1.3 (previously Angular 19.2). To streamline maintenance, the solution now uses Central Package Management via \Directory.Packages.props\, which defines versions for key libraries including Duende IdentityServer 8.0.6, WolverineFx 6.30.3, Marten 9.30.0, and Ocelot 25.0.0. This change also introduces Kiota-based HTTP client generation and consolidates the infrastructure layer to support these modernized dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 43 → 48 (+4.7)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 85 → 79 (-5.9)
  • Architecture 88 → 88 (-0.2)
  • Maturity 71 → 73 (+2.1)
  • Readiness 33 → 49 (+15.9)
  • Security 50 → 52 (+1.7)
  • Domain Modelling 74 → 74 (-0.4)
  • Event-Driven 100 → 100 (+0.0)
  • Event Sourcing 75 → 72 (-2.4)
  • Accessibility 36 → 36 (+0.0)

Resolved (82)

  • Bounded contexts not declared
  • Critical CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • Critical CVE: Marten 8.22.1
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • High CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • …and 62 more

New (234)

  • ApiErrorParserService.parseKiotaOrUnknown (cognitive 22) (src/EcommerceDDD.Spa/src/app/core/services/api-error-parser.service.ts)
  • ApiErrorParserService.parseKiotaOrUnknown (cyclomatic 23) (src/EcommerceDDD.Spa/src/app/core/services/api-error-parser.service.ts)
  • Critical CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/EcommerceDDD.Spa/package-lock.json)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • Cross-context type DomainEvent (Core → Services)
  • …and 214 more

Changes since last survey

  • 7 commits — 7 feature/other, 0 fixes

By area

  • src/Services — 6 commits
  • src/Crosscutting — 1 commit

Notable commits

  • change: chore(deps): upgrade Marten to 9, Duende IdentityServer to 8 and remaining packages (#96)
  • change: feat(identity): persistent signing key management and token lifetime reduction (#95)
  • change: refactor: enforce customer resource ownership (OWASP API1 / BOLA) (#94)
  • change: refactor: keep OrderPlaced in-process instead of round-tripping through Kafka (#99)
  • change: refactor: name event store repository methods after their effects (#98)
  • change: refactor: order-fulfillment resilience (failure semantics, gateway QoS, dead-letter recovery) (#100)
  • change: refactor: replace custom CQRS/Kafka/Outbox infrastructure with Wolverine (#97)

API surface

  • 2 added · 1 removed (a removed endpoint is potentially breaking)

Added endpoints (2)

  • POST /api/v{version}/internal/payments/{paymentId}/cancel
  • PUT /api/v{version}/internal/inventory/{productId}/increase-stock-quantity

Removed endpoints (breaking) (1)

  • DELETE /api/v{version}/internal/payments/{paymentId}

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

falberthen/EcommerceDDD was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 94ac6d54afd202f833d76223573379f52cf1b553 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.