Skip to content
CAI
Software that uses CAICheck a score

falsandtru/clientchannel

57.4

Adequate · 21 September 2026

2.8k

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

ClientChannel is a TypeScript library that provides a unified, layered API for cross-tab communication and persistent data synchronization in the browser. It abstracts the complexities of IndexedDB, Web Storage, and BroadcastChannel into consistent interfaces for storage, ownership, and messaging. The system manages state transitions, data validation, and resource lifecycle, enabling reliable multi-tab data sharing and local persistence.

How it got here

2016 — Storage channel implementation

14 changes.

This period focused on implementing the core storage channel architecture, introducing public APIs for IndexedDB, Web Storage, and in-memory storage. The work established a consistent interface layer and application wrappers to manage state, validation, and event streams for cross-tab synchronization.

2017–2022 — IndexedDB and event-sourced data layer

11 changes.

This period focused on implementing a comprehensive storage and data management system, introducing new classes for IndexedDB channels, web storage, and event-sourced records. The work established mechanisms for data persistence, expiration, and ownership, supported by extensive unit and integration tests to ensure reliability.

Features

Add IndexedDB channel store with capacity and expiry controls

A new \ChannelStore\ implementation is introduced for the IndexedDB layer, providing a memory-backed cache over IndexedDB with configurable \capacity\ (size limit) and \age\ (expiry) options. The store exposes methods to add, delete, and retrieve records, while automatically evicting the least recently used items when the capacity is exceeded. The \recent()\ method returns keys sorted by recent access, and the \expire()\ method allows setting custom TTLs per key. The implementation includes a test suite covering resource management, recent access tracking, cleanup, and size-limiting behavior.

src/layer/domain/indexeddb/model · high confidence

Add StoreChannel with keepalive, capacity, and migration support

The StoreChannel class is introduced to manage IndexedDB-backed storage channels. It adds support for automatic resource cleanup via a keepalive timer, enforces a data capacity limit, and allows for data migration during loading. The implementation also includes unit tests for link, sync, load, send, recv, keepalive, and migrate behaviors.

src/layer/domain/indexeddb/service · high confidence

Add storage availability detection

The environment layer now includes a new module to detect whether browser storage (specifically sessionStorage) is accessible. This is achieved by attempting to write and read a test key; if the operation fails or returns an unexpected value, the system marks storage as unavailable. This change provides a reliable way for the application to check storage capabilities, which is particularly relevant for handling errors in private browsing modes where storage may be restricted.

src/layer/infrastructure/environment · high confidence

Add storage event stream for local and session storage

A new \event.ts\ file introduces a \storageEventStream\ that listens for browser storage events. It captures changes to both \localStorage\ and \sessionStorage\, emitting events to an observer pattern implementation (\spica/observer\). This allows consumers to react to storage updates in a reactive manner.

src/layer/infrastructure/webstorage/model · high confidence

Add validation and binary detection for database values

Introduced new utility functions to validate property names and values for database storage, ensuring that only safe, serializable data is accepted. The \isValidPropertyName\ and \isValidPropertyValue\ functions enforce naming conventions and type restrictions, while the \hasBinary\ helper detects the presence of binary data types (such as \ArrayBuffer\ or \Blob\) within objects. These utilities support the database layer's ability to handle and process binary data correctly.

src/layer/data/database · high confidence

Initial site content for ClientChannel

The gh-pages directory now contains the initial static site content for the ClientChannel project, including a Jekyll configuration (\_config.yml), a .gitignore file, and an index.html page that demonstrates the library's capabilities through interactive canvas and storage examples.

gh-pages · high confidence

Introduce DAO builder for creating sealed, validated object proxies

Added a new DAO builder module that creates sealed object proxies with synchronized property access and validation. The \build\ function wraps target objects, syncing property reads/writes to a source object while enforcing value constraints (e.g., rejecting circular references or invalid types). It also exposes metadata symbols (meta, id, key, date, event) for internal tracking. Tests confirm that the builder correctly initializes properties, prevents modification of sealed properties, and validates input values.

src/layer/domain/dao · high confidence

Introduce Ownership class with take, extend, and release methods

A new Ownership class has been added to manage distributed resource ownership via a channel. It provides methods to acquire (take), extend, and release ownership of keys, utilizing a priority-based system where the first commit wins for active owners, while foreign or expired claims are handled by updating or accepting new ownership. The take method now supports an optional wait parameter to return a Promise\<boolean\> for asynchronous acquisition, and the class includes automatic cleanup on unload and channel closure.

src/layer/domain/ownership · high confidence

Introduce StorageChannel for managing web storage state

A new StorageChannel class has been added to manage state in browser storage (localStorage/sessionStorage). It provides a link/unlink pattern for accessing and modifying stored data, automatically syncing changes to the storage medium and emitting events for send/recv operations. The implementation includes a migration function support for data transformation, a cache to prevent duplicate channel instances, and a destroy method that cleans up resources and storage items.

src/layer/domain/webstorage/service · high confidence

Introduce Web Storage API and Event Stream Exports

The Web Storage infrastructure layer now exposes a public API that re-exports the browser's native localStorage and sessionStorage objects, alongside the storage event stream utilities (both the Observable and the raw event stream). This provides a consistent, centralized interface for accessing browser storage and listening to storage changes.

src/layer/infrastructure/webstorage · medium confidence

Introduce application-layer wrappers for storage, broadcast, and ownership channels

A new api.ts file in the application layer now provides concrete wrapper classes (StoreChannel, StorageChannel, Ownership) that bridge domain interfaces to underlying implementations (IndexedDB, Web Storage, BroadcastChannel). This exposes the capabilities of these channels to consumers of the application layer, allowing them to interact with storage, local/session storage, and cross-tab messaging through a consistent API.

src/layer/application · medium confidence

Introduce event-sourced data layer with typed event records

A new event-sourced data layer has been added to the \src/layer/data/es\ directory, introducing a typed event record system that supports Put, Delete, and Snapshot event types. This includes the \EventRecord\ class hierarchy (\UnstoredEventRecord\, \StoredEventRecord\, \LoadedEventRecord\, \SavedEventRecord\) and an \EventStore\ implementation that manages state transitions and memory reflection. The change also adds an \EventId\ identifier type and corresponding unit tests to ensure the new data structures function correctly.

src/layer/data/es · high confidence

Introduce in-memory storage implementation for domain layer

A new file, src/layer/domain/webstorage/model/storage.ts, has been added to the codebase. This file defines a StorageLike interface and a concrete Storage class that implements it using an internal Map. This provides an in-memory storage solution, exposed as a singleton instance named fakeStorage, which supports standard key-value operations like getItem, setItem, removeItem, and clear.

src/layer/domain/webstorage/model · medium confidence

Introduce public API for WebStorage domain

The WebStorage domain now exposes a public API via the new 'src/layer/domain/webstorage/api.ts' file. This file re-exports the 'StorageChannel' class, the 'localStorage' and 'sessionStorage' instances, and the 'fakeStorage' mock, making these components available for use by other parts of the application.

src/layer/domain/webstorage · medium confidence

Introduces a new IndexedDB storage channel API

A new API entry point is added for the IndexedDB domain layer, exposing the \StoreChannel\ class. This change provides a public interface for interacting with the underlying storage channel service, effectively exposing the storage channel functionality to the rest of the application.

src/layer/domain/indexeddb · high confidence

New Channel class for domain-level broadcast messaging

A new Channel class has been added to the domain layer to handle broadcast messaging. It provides a typed message system with versioning, listener management, and lifecycle control (open, post, close). This introduces a new mechanism for domain objects to communicate via broadcast channels, with built-in duplicate channel name validation and message parsing.

src/layer/domain/broadcast · high confidence

New IndexedDB channel storage and expiry management

The channel model now includes dedicated stores for access tracking, data events, and expiry management. The new AccessStore manages recent access keys with a configurable capacity limit, automatically pruning older entries when the store exceeds the defined capacity. The ExpiryStore handles time-based expiration, automatically deleting or cleaning up records that have passed their expiry timestamp. The DataStore provides a generic event storage mechanism for channel data. These components work together to manage the lifecycle and storage of channel data within IndexedDB, with automatic cleanup and expiration handling.

src/layer/domain/indexeddb/model/channel · high confidence

Project renamed to ClientChannel with dual licensing

The project has been renamed to ClientChannel and is now dual-licensed under the Mozilla Public License 2.0 and the Apache License 2.0, replacing the previous MIT license. The repository now includes a CHANGELOG, NOTICE, and updated README that reflect the new name and features, such as persisting and syncing objects between tabs via IndexedDB or LocalStorage. The build system has been updated to use webpack, and the TypeScript configuration now targets ES2021.

(repo-wide) · high confidence

Behavioural changes

Add global storage wrappers with availability checks

The webstorage module now exposes global wrappers for localStorage and sessionStorage that safely return undefined if the browser environment does not support them, preventing errors when accessing these APIs in restricted contexts like Firefox's private mode.

src/layer/infrastructure/webstorage/module · high confidence

Introduces an API re-export in the interface layer

A new file, src/layer/interface/api.ts, was added to the project. This file acts as a re-export for the API module located in the application layer, effectively exposing the API functionality through the interface layer.

src/layer/interface · high confidence

Refactored IndexedDB access model with explicit state management

The IndexedDB infrastructure layer has been refactored to use a new state-machine-based access model. This introduces explicit state management for database connections, handling transitions between initial, blocked, upgraded, successful, error, and destroyed states. The change includes a new event stream for IndexedDB events, a request queue for managing concurrent operations, and improved error handling for database access failures. The public API exports functions for opening, listening to, closing, and destroying database connections, along with configuration types and event types.

src/layer/infrastructure/indexeddb/model · medium confidence

Test coverage

Add unit tests for the Key-Value Store implementation; Added integration and interface tests for the package; Added unit tests for global IndexedDB wrappers.

Dependencies

Updated project dependencies and tooling configuration

The project's dependency manifests have been updated. The Node.js \package.json\ now specifies \typescript\ 5.2.2 and \webpack\ 5.89.0, alongside updated testing and linting tools. The Ruby \Gemfile\ has been added, introducing \github-pages\, \webrick\, and \wdm\ as dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 55 → 57 (+2.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 91 → 93 (+1.8)
  • Architecture 83 → 70 (-13.6)
  • Maturity 49 → 49 (+0.0)
  • Readiness 48 → 56 (+7.2)
  • Security 55 → 72 (+17.1)

Resolved (15)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • single-maintainer — knowledge-concentration (bus factor) risk

New (39)

  • Change coupling: store.ts ↔ store.ts (src/layer/data/es/store.ts)
  • Documentation: no installation or build instructions (README.md)
  • EventRecord.constructor (cognitive 16) (src/layer/data/es/event.ts)
  • EventRecord.constructor (cyclomatic 19) (src/layer/data/es/event.ts)
  • EventStore.clean (cognitive 24) (src/layer/data/es/store.ts)
  • EventStore.clean (cyclomatic 18) (src/layer/data/es/store.ts)
  • EventStore.snapshot (cognitive 19) (src/layer/data/es/store.ts)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 19 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

falsandtru/clientchannel was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a8578b0e3f54e72a341c39ec3ef5150fa7fac3a6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.