foxminchan/BookWorm
57.5
Adequate · 21 September 2026
43.9k
lines of production code
TypeScript
with C#
2
measurements over time
What this system is
BookWorm is a distributed e-commerce platform for books, structured as a .NET 10 and Bun monorepo that manages catalog browsing, shopping baskets, order processing, and user ratings. It employs a domain-driven design with vertical slice architecture, leveraging WolverineFx for event-driven messaging and .NET Aspire for orchestrating microservices, AI agents, and infrastructure. The system provides a Next.js storefront with AI-assisted shopping and a Backoffice admin portal, all secured by Keycloak and supported by comprehensive observability and performance testing.
How it got here
2025 — Platform modernization and service rebuild
191 changes.
The project underwent a comprehensive modernization, upgrading to .NET 10 and Aspire 13 while migrating the messaging infrastructure from MassTransit to Wolverine. Core services such as Catalog, Ordering, and Basket were rebuilt from the ground up using a vertical slice architecture, the Mediator library, and standardized chassis components. This period also established robust architectural guardrails, including automated testing, strict API versioning, and consistent observability across the distributed system.
2026 — Storefront launch and AI integration
63 changes.
This period focused on building the BookWorm storefront from scratch, establishing a comprehensive Next.js application with catalog browsing, basket management, and user account features. It also introduced CopilotKit AI integration for personalized recommendations and basket actions, alongside the development of an admin backoffice for content management. The work was supported by extensive unit and end-to-end testing, as well as infrastructure updates including a migration to WolverineFx for event handling and the addition of PII detection capabilities.
Features
ACID transactional pipeline with configurable isolation level
The CQRS infrastructure now supports automatic ACID transaction wrapping for commands. By decorating a command handler with the new TransactionalAttribute, the system automatically begins a database transaction before execution and commits it on success or rolls back on failure. The attribute allows configuring the transaction's isolation level, defaulting to ReadCommitted to prevent dirty reads, providing a declarative way to ensure data consistency for write operations.
src/BuildingBlocks/BookWorm.Chassis/CQRS · high confidence
Add AI chat client middleware for content guardrails and PII redaction
Users can now protect their AI chat pipelines with two new middleware components. The GuardrailMiddleware filters input and output messages to replace forbidden keywords (such as 'harmful', 'violence', or 'hate') with a redaction marker, helping to enforce content safety policies. The PIIMiddleware integrates with the Presidio service to automatically detect and anonymize Personally Identifiable Information in chat messages before they are processed, enhancing data privacy. Both are registered via fluent extension methods on the ChatClientBuilder.
src/BuildingBlocks/BookWorm.Chassis/AI/Middlewares · high confidence
Add ESLint, TypeScript, and Turborepo configuration for the validations package
The validations package now includes standard configuration files to integrate with the workspace tooling. An ESLint config extends the shared base configuration, a TypeScript config sets up ESNext module resolution and restricts output to the src directory, and a Turborepo config tags the package as a 'domain' dependency. These changes establish the build and linting foundation for the package within the monorepo.
src/Clients/packages/validations · high confidence
Add Keycloakify login theme for BookWorm
This change introduces the Keycloakify login theme for BookWorm, establishing the necessary build configuration and tooling to generate a custom Keycloak theme. The addition includes a Vite configuration that defines the theme metadata (name, version, group/artifact IDs) and output path, along with a Bun lockfile specifying dependencies such as keycloakify, React, Tailwind CSS, and Storybook. Supporting configuration files for TypeScript, ESLint, Prettier, and PostCSS are also added to standardize the development environment for the theme.
src/Aspire/BookWorm.AppHost/Container/keycloak/keycloakify · high confidence
Add NotificationException base class
A new NotificationException class has been introduced in the notification service's domain layer to serve as a standard exception type for notification-related errors, providing constructors for both simple messages and messages with inner exceptions.
src/Services/Notification/BookWorm.Notification/Domain/Exceptions · high confidence
Add Presidio PII detection and anonymization container integrations
Users can now add Microsoft Presidio Analyzer and Anonymizer containers to their distributed applications via new \AddPresidioAnalyzer\ and \AddPresidioAnonymizer\ extension methods. These integrations pull the \presidio-analyzer\ and \presidio-anonymizer\ images from \mcr.microsoft.com\ (tagged \latest\), expose them on HTTP port 3000 by default, and provide connection strings for programmatic access.
src/Integrations · high confidence
Add command and query handler metrics instrumentation
The CQRS infrastructure now includes built-in telemetry for command and query handlers. New \CommandHandlerMetrics\ and \QueryHandlerMetrics\ classes have been added to track the total number of commands and queries sent, the number of currently active handlers, and the duration of each handling operation using OpenTelemetry counters and histograms.
src/BuildingBlocks/BookWorm.Chassis/CQRS/Command, src/BuildingBlocks/BookWorm.Chassis/CQRS/Query · high confidence
Add configurable CORS support with environment-aware defaults
The BookWorm ServiceDefaults library now includes a dedicated CORS module that registers and applies Cross-Origin Resource Sharing policies based on the runtime environment. In development, services automatically allow all requests from localhost; in production and other environments, CORS behavior is driven by strongly-typed configuration under the "Cors" section, allowing administrators to specify allowed origins, headers, HTTP methods, preflight max age, and credential requirements via the new CorsSettings class.
src/Aspire/BookWorm.ServiceDefaults/Cors · high confidence
Add helper classes for UTC time and UUID v7 generation
New helper classes have been added to the shared kernel to support consistent time and identifier handling. DateTimeHelper provides a UtcNow method and a SQL snippet for UTC timestamps, while UniqueIdentifierHelper exposes a constant for the uuidv7() function, aligning with the project's move to UUID v7 for entity IDs.
src/BuildingBlocks/BookWorm.SharedKernel/Helpers · high confidence
Add hybrid search capability for text snippets
The application now supports hybrid search, combining vector similarity and keyword matching to retrieve text snippets. This is implemented via a new \HybridSearch\ class that uses an embedding generator to create vectors for the input text and queries a vector store collection (\TextSnippet\) using cosine similarity. The search functionality is registered in the dependency injection container via the \AddHybridSearch\ extension method, allowing services to inject \ISearch\ for performing these enhanced lookups.
src/BuildingBlocks/BookWorm.Chassis/AI/Search · high confidence
Add paginated list endpoint for book feedbacks
The Rating service now exposes a new GET endpoint to retrieve feedback for a specific book, supporting pagination, filtering, and sorting. Users can request feedback by book ID and control the results via page index, page size, and ordering criteria (defaulting to rating in ascending order). The response includes pagination metadata, and the endpoint is versioned as V1.
src/Services/Rating/BookWorm.Rating/Features/List · high confidence
Add storefront basket and content pages with loading states
This change introduces the initial implementation of the storefront's basket and content pages. The basket section now includes a dedicated layout with header, footer, and mobile navigation, a main page that manages item quantities, removals, and checkout initiation via API hooks, and a loading skeleton to display while the basket data is being fetched. Additionally, new pages have been added for the About, Returns, and Shipping content sections, each composed of specific feature components (such as hero, mission, policy, and FAQ sections) and wrapped in a consistent layout structure.
src/Clients/apps/storefront/app/(basket), src/Clients/apps/storefront/app/(content) · high confidence
Added API routes for authentication and CopilotKit AI integration
The storefront now exposes two new API endpoints to support user authentication and AI-assisted interactions. The \/api/auth/\[...all\]\ route proxies authentication requests using Better-Auth, enabling secure user sessions. Additionally, the \/api/copilotkit\ route integrates CopilotKit with a backend AI agent, forwarding user authentication context (headers and cookies) to the agent to enable personalized, context-aware AI features such as basket actions and user-specific assistance.
src/Clients/apps/storefront/app/api · high confidence
Added Keycloakify login theme for BookWorm
The BookWorm application now includes a custom login theme powered by Keycloakify. This change introduces the necessary React source files (including the entry point and auto-generated context types) and a .gitignore configuration to support the new UI, allowing users to authenticate via a branded login interface.
src/Aspire/BookWorm.AppHost/Container/keycloak/keycloakify/src · high confidence
Added Outbox Repository for Reliable Message Delivery
The notification service now includes an OutboxRepository to persist and manage outbox messages, supporting the introduction of a Scheduler Service for reliable asynchronous communication. This repository provides methods to add new outbox entries, list them based on specifications, and perform bulk deletions, ensuring that notification events are reliably stored before processing.
src/Services/Notification/BookWorm.Notification/Infrastructure/Repositories · high confidence
Added Redis-backed distributed locking for Fusion Cache
The ordering service now registers a distributed lock implementation using Redis via the ZiggyCreatures.Caching.Fusion.Locking.Distributed.Redis library. This change enables distributed caching mechanisms to coordinate access across service instances, ensuring cache consistency in a distributed environment.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/DistributedLock · high confidence
Added handlers for basket deletion completion and failure events
The ordering service now includes specific integration event handlers to process basket deletion outcomes. When a basket deletion completes, the system logs the order ID and total amount for tracking. If the deletion fails, the system retrieves the associated order and marks it as deleted, ensuring the order state is updated consistently even when the basket removal process encounters issues.
src/Services/Ordering/BookWorm.Ordering/IntegrationEvents/EventHandlers · high confidence
Added idempotency enforcement for POST and PATCH requests
The Ordering service now includes an IdempotencyEndpointFilter that prevents duplicate operations on non-idempotent HTTP methods. Clients must provide a unique Request-Id header for POST and PATCH requests; the system checks this key against existing records and returns a 409 Conflict if the operation has already been processed, ensuring that retries do not create duplicate orders.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/Filters · high confidence
Added storefront public assets and MSW service worker
The storefront application now includes essential public assets, specifically a brand logo and a book placeholder image, which will be served to users. Additionally, a Mock Service Worker (MSW) script has been added to the public directory to enable network request mocking during development, allowing the UI to function with simulated data before backend integration is complete.
src/Clients/apps/storefront/public · high confidence
Added validation schemas for catalog, ordering, and rating domains
The validation package now includes Zod schemas for managing catalog entities (books, authors, categories, publishers), ordering operations (buyers, orders, basket items), and user feedback (ratings). These schemas enforce input constraints such as required fields, ID formats, and value ranges, ensuring that client requests for creating, updating, and listing resources in these domains are validated before processing.
src/Clients/packages/validations/src · high confidence
Adds distributed tracing and user context propagation to the Event Store
The Event Store now automatically propagates OpenTelemetry activity context (trace and span IDs) into document session headers, enabling end-to-end distributed tracing across service boundaries. Additionally, the current user's identity (NameIdentifier claim) is injected into the session headers, allowing downstream consumers to associate events with the originating user. These changes improve observability and auditability of ordering events without requiring manual header management in application code.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/EventStore/Diagnostic · high confidence
Adds structured logging enrichment and compliance-based data redaction
The logging infrastructure now automatically enriches log events with the machine name and the authenticated user's ID via a new ApplicationEnricher. Additionally, it introduces a compliance redaction system that masks sensitive data with asterisks and applies deterministic HMAC-based redaction to PII fields, configured via the HMAC:Key setting to ensure sensitive information is not stored in plain text in logs.
src/BuildingBlocks/BookWorm.Chassis/Logging · high confidence
Admin portal tables for customers, orders, and reviews
The backoffice now includes interactive data tables for managing customers, orders, and reviews. The Customers table lists buyers and allows deletion via a confirmation dialog. The Orders table displays order details (ID, date, total, status) and supports completing, canceling, or deleting orders based on status, with a status filter to narrow the list. The Reviews table shows customer feedback for a selected book, including ratings and comments, and allows deletion of individual reviews.
src/Clients/apps/backoffice/features/customers, src/Clients/apps/backoffice/features/orders, src/Clients/apps/backoffice/features/reviews · high confidence
Admin-only feedback deletion endpoint with rate limiting
The Rating service now exposes a DELETE endpoint for removing feedback records. This new capability is restricted to administrators and includes per-user rate limiting to prevent abuse. The underlying implementation uses a transactional pipeline to ensure data consistency when deleting the feedback entity.
src/Services/Rating/BookWorm.Rating/Features/Delete · high confidence
Basket persistence implementation using Redis
The basket service now persists customer shopping carts in Redis. A new repository class handles storing, retrieving, and deleting basket data by serializing the basket content to JSON, using a specific key format based on the user ID.
src/Services/Basket/BookWorm.Basket/Infrastructure · high confidence
Basket service adds gRPC client for book catalog lookups
The Basket service now includes a new gRPC client implementation (BookService) and its interface (IBookService) to communicate with the Catalog service. This allows the Basket service to retrieve individual books or lists of books by ID via gRPC calls, with a 10-second deadline set for each request.
src/Services/Basket/BookWorm.Basket/Grpc/Services/Book · high confidence
BookWorm Chat service introduces multi-agent orchestration with specialized AI agents
The Chat service now features a multi-agent architecture where a RouterAgent directs user requests to specialized agents: a BookAgent for catalog searches and recommendations, a QAAgent for store policies, a LanguageAgent for translation, a SentimentAgent for emotional analysis, and a SummarizeAgent for long messages. This orchestration is supported by input validation (including prompt injection detection), response formatting, and context compaction pipelines to manage conversation history. The service also includes unit tests for these orchestration conditions and executors to ensure reliability.
src/Services/Chat · high confidence
Category repository interface and seed data implementation
The catalog service now includes a dedicated repository interface for categories, defining methods to add, list, retrieve by ID, and delete category entities. Additionally, a new CategoryData class has been introduced to provide a predefined set of default categories (such as Fiction, Science Fiction, and Mystery) for seeding purposes, ensuring the catalog starts with a standard set of options.
src/Services/Catalog/BookWorm.Catalog/Domain/AggregatesModel/CategoryAggregate · high confidence
Centralized core constants and API versioning support
The core constants library now includes dedicated static classes for API versioning (V1–V3), authorization roles and policies, HTTP endpoint paths, data schema lengths, and pagination defaults. This centralizes shared configuration values, ensuring consistent API versioning and standardizing common constants across the application.
src/BuildingBlocks/BookWorm.Constants/Core · high confidence
Comprehensive k6 performance testing suite for the BookWorm catalog API
The k6 load testing configuration in the AppHost container has been replaced with a structured, TypeScript-based test suite that covers five distinct scenarios: browsing the catalog, searching and filtering, comprehensive API endpoint validation, stress testing, and spike testing. The new setup uses a seeded random number generator to ensure reproducible test runs and includes realistic user behavior simulations, such as variable sleep times and retry logic for transient failures. It validates the /catalog/api/v1 endpoints (books, categories, authors, publishers) against specific performance thresholds (e.g., 95th percentile response times) and checks for correct handling of edge cases like malformed parameters and invalid IDs. Test results are now exported as HTML reports, JSON summaries, and console output for easier analysis.
src/Aspire/BookWorm.AppHost/Container/k6/src · high confidence
Copilot integration for basket actions and user context
The Storefront now integrates Copilot to manage shopping basket interactions and user context. New hooks expose basket state to the AI agent, allowing it to understand the current cart contents and user authentication status. Users can now interact with the AI to search for books, view their basket, and add items to the cart through a human-in-the-loop confirmation flow. The integration includes UI components for displaying search results, basket summaries, and confirmation dialogs, as well as utilities for handling offline message queuing and rate limiting during AI interactions.
src/Clients/apps/storefront/hooks · high confidence
Domain models and events for Catalog, Ordering, Basket, Notification, and Rating services
This change introduces the core domain aggregates, value objects, and domain events for the Catalog, Ordering, Basket, Notification, and Rating services. In the Catalog service, new aggregates include Book, Author, Category, Publisher, and Price, supporting operations like updating book metadata, managing author associations, and handling pricing with discounts. The Ordering service now features Buyer, Address, Order, and OrderItem aggregates, enabling order creation, status transitions (new, completed, cancelled), and total price calculation. The Basket service introduces the CustomerBasket aggregate for managing basket items. The Notification service adds Order and Outbox models to support notification workflows and outbox patterns. Finally, the Rating service includes the Feedback aggregate with rating validation and deletion capabilities. All aggregates follow domain-driven design principles with proper validation, event registration, and method chaining for updates.
Services · high confidence
Finance service initialization with structured logging and Kestrel hardening
The BookWorm.Finance service has been established with a new project structure, including global usings for the Chassis, EventBus, and EF infrastructure layers. The service now enforces security best practices by disabling the Kestrel server header and enabling HSTS in non-development environments. Additionally, it introduces granular logging capabilities, featuring request-scoped buffering, random probabilistic sampling to reduce noise, and specific debug-level logging for saga operations, alongside configuration for the Order State Machine's retry logic.
src/Services/Finance/BookWorm.Finance · high confidence
Implement gRPC client services for Basket and Book with FusionCache integration
The Ordering service now exposes dedicated gRPC client implementations for Basket and Book operations. The new BasketService handles basket retrieval with a 10-second deadline, while the BookService provides methods to fetch individual or multiple books, integrating FusionCache to cache book data by ID. These services replace previous direct gRPC client usage with a structured service layer, improving maintainability and enabling caching for book-related queries.
src/Services/Ordering/BookWorm.Ordering/Grpc/Services · high confidence
Initial implementation of Storefront library utilities and configuration
This change introduces the foundational library code for the new BookWorm storefront application. It adds authentication integration using Better Auth with Keycloak OAuth support, configures TanStack Query for optimized server-side rendering and client-side state management, and implements structured data generation (JSON-LD) for SEO across product, organization, and website pages. Additionally, it provides utility functions for navigation state, sorting logic, order status styling, and initializes MSW for local development mocking.
src/Clients/apps/storefront/lib · high confidence
Initial storefront application scaffolding and configuration
The Storefront application is introduced as a new Next.js client, establishing the foundational project structure and configuration. This includes setting up environment variable validation via \env.mjs\, configuring the UI component library (shadcn/ui) and Tailwind CSS, and defining TypeScript and ESLint rules. The entry also integrates state management for the shopping basket using Jotai and TanStack Query, implements a middleware-based proxy for handling authentication redirects on protected routes, and configures the testing infrastructure with Vitest for unit tests and Playwright for end-to-end BDD tests, complete with Allure reporting.
src/Clients/apps/storefront · high confidence
Initial storefront shell with SEO, PWA, and layout structure
The storefront application now includes its core Next.js App Router structure, providing a consistent page layout with a header, footer, and mobile navigation. To improve discoverability, the site generates dynamic sitemaps for books and categories, configures robots.txt to block AI crawlers and sensitive routes, and serves custom Open Graph images for social sharing. The app is also configured as a Progressive Web App (PWA) via a web manifest, and includes a styled 404 page for missing routes.
src/Clients/apps/storefront/app · high confidence
Introduce A2A agent client and discovery infrastructure
The AI agents module now includes a new client library for connecting to remote agents via the Agent-to-Agent (A2A) protocol. This adds an \A2AAgentClient\ that handles service discovery, HTTP communication, and automatic token exchange for authenticated agent interactions, along with an \A2AClientFactory\ for simplified instantiation. Additionally, an \AgentDiscoveryClient\ is provided to query remote services for available agents, complete with DI registration extensions to configure the underlying HTTP client.
src/BuildingBlocks/BookWorm.Chassis/AI/Agents · high confidence
Introduce Agent Governance Toolkit for policy enforcement
This change adds a new governance layer to the AI chassis, allowing applications to enforce security policies on agent tool invocations. It introduces configuration options (via \AgentGovernanceOptions\) to enable features like ring-based isolation, prompt injection detection, and circuit breakers. The toolkit registers a shared \GovernanceKernel\ that loads policy files (including a provided \default.yaml\ which blocks dangerous tools, prevents data exfiltration, and limits rate usage) and provides an extension method (\WithBookWormGovernance\) to wrap agents with function-call middleware for real-time policy enforcement.
src/BuildingBlocks/BookWorm.Chassis/AI/Governance · high confidence
Introduce Aspire-based application host with unified service orchestration
The application host has been migrated to .NET Aspire, establishing a centralized orchestration layer that defines the entire distributed system topology. This change introduces declarative provisioning for Azure infrastructure (Container Apps, PostgreSQL Flexible Server, Managed Redis, Qdrant, and Azure Storage) alongside local container fallbacks for development. It wires up all backend services (Catalog, Basket, Ordering, Chat, Rating, Notification, Finance, Scheduler) and frontend applications (Storefront, Backoffice) with explicit dependency graphs, health checks, and Keycloak authentication. The host also integrates AI capabilities via Azure Foundry (GPT-4o, Text Embedding Ada-002), PII redaction via Presidio, and messaging via Kafka, while providing build targets for K6 load testing and Keycloakify theme compilation.
src/Aspire/BookWorm.AppHost · high confidence
Introduce BookWorm MCP Tools service for catalog and review operations
A new BookWorm MCP Tools service has been added to expose catalog and review capabilities to external LLM clients via the Model Context Protocol. The service provides tools to search the book catalog, retrieve book details, list categories and authors, and fetch customer reviews. It also includes prompts for generating book recommendations, analyzing book quality, and summarizing review sentiment. To ensure safe usage, the service integrates an Agent Governance Toolkit that enforces policies to block dangerous tool invocations, detect tool poisoning, and rate-limit requests. The service is secured with Keycloak authentication and CORS support, and exposes its capabilities through a stateless HTTP transport.
src/Services/McpTools/BookWorm.McpTools · high confidence
Introduce BookWorm Scheduler service with Quartz-based job orchestration
A new Scheduler service has been added to the platform, leveraging Quartz for job scheduling and Wolverine for event publishing. The service defines three scheduled jobs: a HeartbeatJob that logs activity every 30 seconds for observability, a CleanUpSentEmailJob that runs hourly to publish cleanup events, and a ResendErrorEmailJob that runs hourly to retry failed email deliveries. Configuration is managed via a jobs.xml file, with persistent storage enabled and a dashboard exposed for monitoring. The service also includes a JobTelemetryListener to track job execution times and status, and integrates with the existing event bus for inter-service communication.
src/Services/Scheduler/BookWorm.Scheduler · high confidence
Introduce PagedResult type for pagination metadata
A new PagedResult generic class has been added to the shared kernel, providing a structured way to handle paginated data. This type extends a list of items and includes metadata such as page index, page size, total items, and total pages, along with convenience properties to check for previous and next pages. This enables API consumers to easily determine pagination state and navigate through results.
src/BuildingBlocks/BookWorm.SharedKernel/Results · high confidence
Introduce Presidio PII detection and anonymization service
This change adds a new building block for handling Personally Identifiable Information (PII) by integrating Microsoft Presidio. It introduces the \IPresidioService\ interface and a concrete implementation that communicates with external Presidio Analyzer and Anonymizer HTTP endpoints. The service is registered in the dependency injection container via \AddPresidio()\, which configures typed HTTP clients for both the analyzer and anonymizer services using connection strings from configuration. Users can now inject \IPresidioService\ to automatically detect and redact PII entities from text inputs before they are processed further.
src/BuildingBlocks/BookWorm.Chassis/AI/Presidio · high confidence
Introduce React Query hooks for storefront domain data
This change adds a new \api-hooks\ package that provides React Query-based hooks for the storefront's core domains. It introduces standardized hooks for fetching and mutating data related to baskets, catalog entities (books, authors, categories, publishers), ordering (orders, buyers), and ratings (feedbacks). By wrapping the existing API clients, these hooks handle query caching, invalidation, and mutation logic, enabling components to easily manage server state for these areas.
src/Clients/packages/api-hooks · high confidence
Introduce Redis-backed idempotency request tracking
The ordering service now includes a new idempotency infrastructure layer that prevents duplicate request processing. A new \ClientRequest\ model captures request identifiers, names, and timestamps, while an \IRequestManager\ interface and its \RequestManager\ implementation store these records in Redis with a one-hour expiration. This ensures that subsequent requests with the same idempotency key are detected and handled appropriately, improving reliability for order operations.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/Idempotency · high confidence
Introduce Spec Kit extensions for Git workflow and coding agent context management
The Specify CLI now supports a pluggable extension system, adding two bundled extensions: a Git workflow extension that automates repository initialization, feature branch creation (with sequential or timestamp numbering), branch validation, and configurable auto-committing at various specification phases, and an agent-context extension that manages coding agent instruction files (such as CLAUDE.md or copilot-instructions.md) by automatically refreshing a delimited section with the current plan path. These extensions are registered in the local extension registry, configured via YAML files, and integrated into the specification lifecycle through hooks that trigger Git operations and context updates before and after key steps like specifying, planning, and implementing.
.specify · high confidence
Introduce TypeScript build tooling for k6 performance tests
The k6 performance test container now supports TypeScript source files by adding a Webpack build pipeline, TypeScript configuration, and ESLint rules. This change enables developers to write load tests in TypeScript with strict type checking, path aliases (e.g., @config, @scenarios), and automated bundling into a single CommonJS module for execution, replacing the previous uncompiled script approach.
src/Aspire/BookWorm.AppHost/Container/k6 · high confidence
Introduce buyer management endpoints with PII redaction
The Ordering service now exposes a full set of REST endpoints for managing buyers, including creating a buyer, retrieving the current user's profile, listing all buyers with pagination, updating an address, and deleting a buyer. These endpoints are versioned as V1, require authorization (with admin-only access for listing and deleting), and enforce per-user rate limiting. The response data is returned via a new BuyerDto that marks Name and Address fields with \[PIIData\], ensuring sensitive information is handled according to the platform's privacy and redaction policies.
src/Services/Ordering/BookWorm.Ordering/Features/Buyers · high confidence
Introduce centralized Aspire service defaults for observability and resilience
A new \BookWorm.ServiceDefaults\ library has been added to standardize cross-cutting concerns across all services. It provides a single \AddServiceDefaults()\ extension that configures OpenTelemetry (tracing, metrics, and logging with OTLP export), baseline health checks (readiness and liveness), service discovery, and default HTTP client resilience. The library also sets up structured logging with request-scoped buffering and probabilistic sampling, and configures Kestrel HTTP/2 limits, ensuring consistent observability and reliability behavior for every service that references this project.
src/Aspire/BookWorm.ServiceDefaults · high confidence
Introduce outbox pattern infrastructure for reliable notification delivery
The notification service now includes domain models and repository interfaces to support an outbox pattern, ensuring reliable message delivery. This change adds an \IOutboxRepository\ for managing outbox records, along with specific query specifications (\OutboxFilterSpec\ and \UnsentOutboxSpec\) to efficiently retrieve unsent notifications. A new \Status\ enum defines the lifecycle states (New, Completed, Canceled) for these records, providing a structured way to track and process pending notifications.
src/Services/Notification/BookWorm.Notification/Domain/Models · high confidence
Introduce shared TypeScript type definitions for the storefront
This change adds a new \@workspace/types\ package that centralizes TypeScript interfaces for the storefront application. It defines core domain models including \Book\, \Author\, \Category\, and \Publisher\ for the catalog, \Basket\ and \BasketItem\ for shopping cart functionality, \Order\ and \Buyer\ for the ordering system, and \Feedback\ for ratings. Additionally, it provides a generic \PagedResult\ type for paginated responses and configures the package with standard ESLint and TypeScript settings to ensure type safety across the frontend.
src/Clients/packages/types · high confidence
Introduce shared frontend utility package
A new \@workspace/utils\ package has been added to provide shared utilities for frontend applications. It includes formatting helpers for prices (USD) and dates, text truncation, and discount calculation. The package also exports functions for building HTTP Link headers for pagination, generating W3C Trace Context-compliant trace IDs, and formatting Zod validation errors into a FluentValidation-compatible structure. Configuration files for TypeScript, ESLint, and Turborepo are included to integrate this package into the workspace.
src/Clients/packages/utils · high confidence
Introduce structured API client with retry logic and domain-specific service wrappers
The api-client package now provides a centralized Axios-based client that automatically attaches Bearer tokens via a configurable provider and implements exponential backoff retry logic for network errors, timeouts, and rate-limiting (429). This core client is wrapped by new domain-specific service classes for baskets, catalog entities (books, authors, categories, publishers), ordering (buyers, orders), and rating feedbacks. These services expose typed methods for CRUD operations, with the books service handling multipart form data for image uploads and the ordering service injecting unique request IDs for idempotency. Configuration is environment-aware, defaulting to a gateway URL with a 30-second timeout in production and a 10-second timeout in tests.
src/Clients/packages/api-client/src · high confidence
Introduce telemetry-aware event store extensions and DI registration
The ordering service now includes new extension methods for Marten's IDocumentSession that wrap event persistence (starting streams and writing to aggregates) with OpenTelemetry activity tracking, ensuring distributed tracing context is propagated for all event store operations. Additionally, a dedicated service registration method configures the Marten event store with Npgsql, enables the async daemon for event processing, and sets up OpenTelemetry metrics and tracing along with a health check for the async daemon status.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/EventStore/Extensions · high confidence
Introduces OrderingDomainException for domain error handling
A new OrderingDomainException class has been added to the domain layer to provide a specific exception type for ordering-related errors, allowing for more precise error handling and identification of domain issues within the application.
src/Services/Ordering/BookWorm.Ordering/Domain/Exceptions · high confidence
Introduces book catalog seeding data and repository interfaces
The catalog service now includes initial seed data for books and authors via new \BookData\ and \AuthorData\ classes, providing a predefined set of titles and authors for testing or initialization. Additionally, explicit repository interfaces (\IBookRepository\ and \IAuthorRepository\) are defined to standardize data access patterns, and a \Status\ enum is introduced to track inventory availability (In Stock/Out of Stock).
src/Services/Catalog/BookWorm.Catalog/Domain/AggregatesModel/BookAggregate · high confidence
Introduces constants for agent types, workflows, and seeding configuration
New constant classes have been added to centralize configuration values for the application's agent orchestration and data seeding. The Agents class defines identifiers for specific agent roles including QA, Book, Rating, Router, Language, Summarize, and Sentiment agents. The Workflows class provides constants for the chat and rating-summarizer workflows. Additionally, Seeder constants define default values for seeding operations, and LoggingConstant establishes standard keys for machine name and user ID in logs.
src/BuildingBlocks/BookWorm.Constants/Other · high confidence
Introduces foundational domain model base classes
The BuildingBlocks library now provides core base classes for the domain model: Entity and its generic variant, which establish identity management; AuditableEntity, which adds automatic creation and modification timestamps along with row versioning for concurrency control; and DomainEvent, which implements INotification from the Mediator library to support event-driven domain logic.
BuildingBlocks · high confidence
Introduces generic mapper and repository abstractions with DI registration
The application now provides a built-in chassis for data mapping and persistence. A generic \IMapper\<TSource, TDestination\>\ interface allows for type-safe object mapping, with an extension method to automatically register all mapper implementations via dependency injection. Similarly, a generic \IRepository\<T\>\ interface (constrained to aggregate roots) and an \IUnitOfWork\ interface for transactional persistence are introduced, along with an extension method to auto-register repository implementations. This standardizes how data is transformed and persisted across the application.
src/BuildingBlocks/BookWorm.Chassis/Mapper, src/BuildingBlocks/BookWorm.Chassis/Repository · high confidence
Introduction of DecimalValue type for precise price handling
A new DecimalValue domain value type has been added to the Catalog service to handle monetary amounts with higher precision. This type stores prices as a combination of units and nanoseconds, providing implicit conversion operators to and from the standard decimal type, which ensures accurate price calculations within the catalog domain.
src/Services/Catalog/BookWorm.Catalog/Domain/Values · high confidence
Introduction of EventMapper for domain-to-integration event translation
A new EventMapper service has been added to the Ordering infrastructure to handle the conversion of internal domain events (such as OrderPlaced, OrderCancelled, and OrderCompleted) into specific integration events. This component extracts user identity details (email and full name) from the current claims principal and maps them to corresponding integration events like UserCheckedOutIntegrationEvent and OrderStatusChangedToCancelIntegrationEvent, ensuring that downstream systems receive enriched context when order state changes occur.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/Services · high confidence
Introduction of IdentityOptions configuration class
A new IdentityOptions class has been added to the Security/Settings module to manage identity configuration settings. This class exposes properties for Realm, ClientId, ClientSecret, Scopes, and TokenExchangeTargets, providing a structured way to bind and compare identity-related configuration values via the 'Identity' configuration section.
src/BuildingBlocks/BookWorm.Chassis/Security/Settings · high confidence
New ACID-transactional feedback creation endpoint
Users can now submit book ratings and comments via a new Create Feedback endpoint. This change introduces a dedicated command handler that ensures data integrity by wrapping the operation in an ACID transaction, guaranteeing that the feedback record is persisted atomically. The endpoint validates input constraints, including mandatory book and author identifiers, a comment length limit, and a rating scale between 0 and 5.
src/Services/Rating/BookWorm.Rating/Features/Create · high confidence
New AI infrastructure extensions and ingestion interface
This change introduces new extension methods and interfaces to support the AI chassis. ActorFrameworkWebApplicationExtensions adds a discovery endpoint that exposes registered AI agents via a standardized route. McpClientExtensions registers Model Context Protocol (MCP) clients using StreamableHttp transport with automatic authentication. ModelExtensions provides AddAIServices to configure OpenAI-compatible chat and embedding clients based on Foundry connection strings, and WithAITelemetry to enable OpenTelemetry tracing and metrics for AI components. Additionally, a new IIngestionSource interface is added to define a standard contract for asynchronous data ingestion.
src/BuildingBlocks/BookWorm.Chassis/AI/Extensions · high confidence
New API endpoint to summarize book feedback
A new GET endpoint at /{id:guid}/summarize has been added to the Rating service, allowing authenticated users to retrieve a summary of ratings for a specific book. The endpoint accepts a book ID, invokes the ISummarizer infrastructure to generate the overview, and returns the result as a SummarizeResult, with a 404 response if no ratings are found for the specified book.
src/Services/Rating/BookWorm.Rating/Features/Summarize · high confidence
New AppHost network extensions for CORS, email, proxy, and URL management
The AppHost now includes a new set of extension methods in the Network folder to simplify configuration of cross-origin requests, email delivery, API gateway routing, and UI URLs. Developers can add configurable Storefront and Backoffice CORS origins via AddCorsOriginParameters and apply them to services with WithCorsOrigins. Email support automatically uses Mailpit in development or configures SendGrid parameters in production via WithEmailProvider. A new YARP-based API gateway can be built with AddApiGatewayProxy, allowing services to be registered with custom routes, protobuf forwarding, and header transforms. Finally, WithFriendlyUrls provides a consistent, user-friendly URL display in the Aspire dashboard for project resources.
src/Aspire/BookWorm.AppHost/Extensions/Network · high confidence
New Aspire security extensions for Keycloak integration and secret management
The AppHost now includes a new set of security extension methods in the \BookWorm.AppHost.Extensions.Security\ namespace to streamline identity and configuration. \KeycloakExtensions\ provides \AddLocalKeycloak\ and \AddHostedKeycloak\ to configure local or external Keycloak instances, and \WithKeycloak\ to automatically wire up client credentials, realms, and scopes for Project, Container, and Turborepo resources. Additionally, \SecretExtensions\ introduces \WithSecret\ for generating secure environment variables and \WithGeneratedDefault\ to handle parameter generation and state initialization, simplifying the setup of secrets and Keycloak client configurations in the distributed application host.
src/Aspire/BookWorm.AppHost/Extensions/Security · high confidence
New Azure infrastructure provisioning and Scalar API reference extensions
This change introduces new extension methods in the AppHost infrastructure layer to streamline Azure resource configuration and API documentation. For Azure services, dedicated extensions now allow provisioning Container Apps with Consumption workload profiles, Postgres Flexible Servers with zone-redundant high availability and specific storage/backup settings, Managed Redis instances, and Storage Accounts with configurable CORS rules and access tiers, all defaulting to the Southeast Asia region. Additionally, a new Scalar API reference extension is added, supporting local Keycloak authentication and automatic OAuth2 authorization code flow configuration with PKCE for API projects.
src/Aspire/BookWorm.AppHost/Extensions/Infrastructure · high confidence
New CQRS pipeline behaviors for validation, transactions, logging, and telemetry
The CQRS pipeline layer now includes four new internal behaviors that automatically wrap command and query handling. ValidationBehavior uses FluentValidation to reject invalid requests before they reach handlers. TransactionBehavior automatically wraps commands in database transactions with configurable isolation levels, rolling back on failure. LoggingBehavior records request/response details and warns on slow operations, while redacting properties marked with DataClassificationAttribute to prevent PII exposure. ActivityBehavior integrates OpenTelemetry tracing and metrics for both commands and queries, respecting IgnoreOTelOnHandlerAttribute to skip instrumentation when needed.
src/BuildingBlocks/BookWorm.Chassis/CQRS/Pipelines · high confidence
New EF Core infrastructure with automatic migrations, domain event dispatching, and query performance logging
The EF Core chassis now provides a unified registration pipeline for PostgreSQL contexts that automatically applies snake\_case naming, sets a global NoTracking query behavior, and wires up two new interceptors: a QueryPerformanceInterceptor that logs slow queries exceeding 100ms, and an EventDispatchInterceptor that automatically dispatches and clears domain events after save changes. Additionally, a new migration subsystem registers a hosted service to apply database migrations and run seeders at startup, with OpenTelemetry tracing integrated into the migration process.
src/BuildingBlocks/BookWorm.Chassis/EF · high confidence
New FeedbackRepository implementation using Chassis specifications
The Rating service now includes a new FeedbackRepository in the infrastructure layer that implements the IFeedbackRepository interface. This repository leverages the BookWorm.Chassis.Specification framework for query composition, enabling consistent filtering and counting of feedback entities through specification evaluators rather than raw LINQ queries.
src/Services/Rating/BookWorm.Rating/Infrastructure/Repositories · high confidence
New HTTP URL builder and service discovery utilities
Added HttpUtilities and ServiceDiscoveryUtilities to the BookWorm.Chassis package. HttpUtilities provides a UrlBuilder class for constructing URLs with support for base URLs, schemes, hosts, ports, paths, query parameters, and fragments, while ServiceDiscoveryUtilities offers methods to retrieve service endpoints from environment variables using a structured naming convention (e.g., services\\{serviceName}\\{endpointName}\\{index}).
src/BuildingBlocks/BookWorm.Chassis/Utilities · high confidence
New Keycloak security middleware and claims transformation
This change introduces a new Keycloak integration layer within the BookWorm Chassis security module. It adds a token introspection middleware that validates bearer tokens against the Keycloak introspection endpoint before allowing access to protected endpoints, returning a 401 Unauthorized response for invalid or inactive tokens. Additionally, it provides a claims transformation service that maps Keycloak realm and resource roles into standard ASP.NET Core role claims, and includes helper classes for Keycloak endpoint URLs and claim type constants.
src/BuildingBlocks/BookWorm.Chassis/Security/Keycloak · high confidence
New MJML-based email templates for order notifications
The notification service now uses MJML templates to render order-related emails. A new layout file (\_Layout.mjml) provides a consistent structure with the BookWorm branding, Roboto font, and a standard header/footer, while a specific template (OrderEmail.mjml) defines the content for order notifications, displaying the customer's name, order ID, status, total amount, and creation date.
src/Services/Notification/BookWorm.Notification/Templates · high confidence
New OpenAPI transformers for security, deprecation, and versioning
The ServiceDefaults library now includes four new OpenAPI document and operation transformers that automatically enhance the generated API specification. AuthorizationChecksTransformer adds 401/404 responses and OAuth2 security requirements to endpoints marked with IAuthorizeData. DeprecatedStatusTransformer marks operations as deprecated if they carry the ObsoleteAttribute. OpenApiInfoDefinitionsTransformer injects API versioning information from Asp.Versioning into the document info. SecuritySchemeDefinitionsTransformer configures the OAuth2 security scheme definition with Keycloak authorization and token endpoints.
src/Aspire/BookWorm.ServiceDefaults/ApiSpecification/OpenApi/Transformers · high confidence
New OpenTelemetry tracing client package
A new \otel\ client package has been added to the project, providing a ready-to-use OpenTelemetry setup for Node.js applications. The package exports an \initializeOpenTelemetry\ function that configures an OTLP trace exporter, automatically reading the collector endpoint from the \OTEL\_EXPORTER\_OTLP\_ENDPOINT\ environment variable and supporting custom headers via \OTEL\_EXPORTER\_OTLP\_HEADERS\. This allows developers to easily integrate distributed tracing into their services without manual SDK configuration.
src/Clients/packages/otel · high confidence
New REST API endpoints for managing orders
The Ordering service now exposes a complete set of REST endpoints for order lifecycle management, including creating, retrieving, listing, canceling, completing, and deleting orders. Users can create orders from their basket with distributed locking to prevent race conditions, retrieve individual order details with item names, and list orders with pagination and filtering by status or buyer. Admins have additional capabilities to delete any order and view other users' order data, while regular users are restricted to their own orders. All endpoints support idempotency keys and per-user rate limiting.
src/Services/Ordering/BookWorm.Ordering/Features/Orders · high confidence
New ReviewTool for fetching book reviews via AI agents
A new ReviewTool has been added to the Rating service, enabling AI agents to retrieve customer reviews and ratings for a specific book. The tool exposes a GetCustomerReviews method that accepts a book ID, queries the system for associated feedback, and returns the results as a JSON string containing review IDs, ratings, and comments. It integrates with the Microsoft Agent Framework by implementing AsAITools to expose the functionality as an AI tool.
src/Services/Rating/BookWorm.Rating/Tools · high confidence
New Specification pattern for composable EF Core queries
The \BookWorm.Chassis.Specification\ module introduces a fluent Specification pattern for building Entity Framework Core queries. It provides a builder API to compose filters (Where), full-text search (Search), navigation includes (Include/ThenInclude), sorting (OrderBy/ThenBy), and pagination (Skip/Take). The implementation also supports EF Core query hints such as AsNoTracking, AsTracking, AsSplitQuery, and IgnoreQueryFilters, allowing developers to construct complex, reusable query definitions that are evaluated by a centralized SpecificationEvaluator.
src/BuildingBlocks/BookWorm.Chassis/Specification · high confidence
New UI component library added
The UI package now includes a comprehensive set of new React components, including Accordion, AlertDialog, Alert, Badge, Breadcrumb, Button, Card, Checkbox, Collapsible, Command, Dialog, DropdownMenu, Empty, Field, Form, Input, InputGroup, and Label. These components provide a consistent design system for building user interfaces.
src/Clients/packages/ui/src · high confidence
New account management UI components for the storefront
This change introduces the core UI components for the user account section in the storefront application. It adds a navigation menu linking to order history, a profile section displaying the buyer's name, a logout button with loading state handling, and a delivery address section that allows users to view and edit their city and province via a form backed by Zod validation and React Hook Form.
src/Clients/apps/storefront/features/account · high confidence
New basket and order management UI components for the storefront
This change introduces the frontend components for the shopping basket and order history features in the storefront application. In the basket area, new components (header, item, list, and summary) enable users to view items, adjust quantities, save changes, clear the basket, and proceed to checkout with a visible order summary. In the ordering area, new components provide an order confirmation page, an order history list with status filtering, and detailed order views showing items, totals, and shipping information.
src/Clients/apps/storefront/features/basket, src/Clients/apps/storefront/features/ordering · high confidence
New book management interface in the backoffice
The backoffice now includes a complete set of UI components for managing books. Users can create and edit book details (title, description, price, sale price) via a form that integrates with author, category, and publisher data. The interface supports uploading and previewing book cover images. A dedicated filtering panel allows searching by title or author, filtering by category, publisher, and price range, with debounced inputs for performance. A data table displays book listings with columns for title, authors, category, publisher, price, stock status, and rating, and provides inline actions to edit or delete individual books.
src/Clients/apps/backoffice/features/books · high confidence
New event mapping service for rating domain events
A new EventMapper class has been added to the Rating service's infrastructure layer to handle the conversion of internal domain events (FeedbackCreatedEvent, FeedbackDeletedEvent) into integration events. This change introduces a specific mapping logic that translates book ID, rating, and feedback ID from the domain model to the integration contract, enabling the service to publish these events to external systems.
src/Services/Rating/BookWorm.Rating/Infrastructure/Services · high confidence
New gRPC service for retrieving book details and lists
A new BookService implementation has been added to the Catalog gRPC layer, exposing endpoints to fetch a single book by ID or retrieve a list of books by their IDs. This service integrates with the existing book repository and specification system to map domain models into gRPC responses, including handling book status (InStock/OutOfStock) and price information.
src/Services/Catalog/BookWorm.Catalog/Grpc/Services · high confidence
New guard utilities and JSON converters in BookWorm.Chassis
This change introduces new utility components within the BookWorm.Chassis building block. It adds a set of System.Text.Json converters for handling DateOnly (ISO 8601 format), decimal (rounded to 2 places), and string (trimmed) types during serialization and deserialization. Additionally, it provides a new Guard utility class with extension methods to enforce preconditions, specifically validating that a user ID is present (throwing UnauthorizedAccessException if missing) and that entity values are not null (throwing NotFoundException if missing).
src/BuildingBlocks/BookWorm.Chassis/Utilities/Guards · high confidence
New mapper for converting order commands to domain models
A new internal mapper class has been added to the notification service's integration events layer to transform incoming order commands (PlaceOrder, CompleteOrder, CancelOrder) into the corresponding Order domain models. This ensures that order status updates are correctly mapped to the internal notification system's data structures.
src/Services/Notification/BookWorm.Notification/IntegrationEvents · high confidence
New mock service layer for frontend development
The \src/Clients/packages/mocks\ package now provides a complete in-browser mock service using MSW, intercepting API calls for the basket, catalog (books, authors, categories, publishers), and other domain entities. This allows frontend clients to develop and test against realistic, persistent mock data without requiring a live backend. The package also introduces a shared, modular ESLint configuration (\@workspace/eslint-config\) with specific presets for Next.js and React, standardizing linting rules across the client applications.
src/Clients/packages/mocks · high confidence
New order summary projection for optimized read views
A new \OrderSummaryViewProjection\ has been added to the event store infrastructure to maintain a denormalized view of order summaries. This projection aggregates \OrderPlaced\, \OrderCancelled\, and \OrderCompleted\ events to track order status and total price, enabling faster read access to summary data. It is configured with a cache limit of 1000 entries per tenant and a batch size of 5000 to optimize performance and rebuild times for the event store.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/EventStore/Projections · high confidence
New overview dashboard components for the backoffice
The backoffice overview feature now includes four new UI components: a KPI cards section displaying total revenue, orders, active customers, and catalog size; a pie chart visualizing book distribution by category; a line chart showing daily orders and revenue trends over the last week; and a table listing the five most recent orders with details on ID, amount, status, and date. These components provide a consolidated view of key business metrics and recent activity for administrators.
src/Clients/apps/backoffice/features/overview · high confidence
New rating summarization capability
The rating service now includes a new summarization feature that generates concise summaries of book ratings. This is implemented via the ISummarizer interface and the RatingSummarizer class, which leverages the Microsoft Agent Framework to execute a 'summarize\_rating' prompt through an MCP client, returning a SummarizeResult containing the generated text.
src/Services/Rating/BookWorm.Rating/Infrastructure/Summarizer · high confidence
New service defaults for authentication forwarding, rate limiting, and health checks
The BookWorm.ServiceDefaults library now includes Kestrel-specific extensions to standardize how downstream service calls and API endpoints are handled. Developers can now automatically forward user access tokens to outgoing HTTP requests via the new HttpClientAuthorizationDelegatingHandler, apply configurable per-user and global rate limiting with standardized 429 responses, and register typed gRPC and HTTP service references that include built-in resilience policies and health checks.
src/Aspire/BookWorm.ServiceDefaults/Kestrel · high confidence
New storefront UI components and Copilot integration
The Storefront application now includes a comprehensive set of new UI components, including a Back-to-Top button, Book Card with discount and rating display, and structured Filter Sections with search capabilities. The Header and Footer have been implemented with account menus, search functionality, and policy dialogs. Additionally, a ChatBot component has been added, integrating Copilot for AI-assisted interactions and basket actions.
src/Clients/apps/storefront/components · high confidence
New storefront catalog browsing and product detail pages
The storefront now includes a complete catalog browsing experience, featuring a shop page with sidebar filters for price, category, publisher, and author, alongside a dedicated product detail page. Users can view book information, manage basket quantities, and submit customer reviews with sorting and pagination. The catalog also introduces new browsing sections for genres and publishers, allowing users to explore books by these classifications.
src/Clients/apps/storefront/features/catalog · high confidence
New storefront home page with AI recommendations and dynamic content sections
The storefront home page now features a structured layout including a hero banner, a featured books section that dynamically loads and displays up to four book titles with skeleton loading states, a categories section that browses up to six categories with similar loading handling, and a new AI recommendations section that promotes an interactive chatbot assistant. The page content component orchestrates these sections and integrates the chatbot interface, enabling personalized book discovery through a conversational UI.
src/Clients/apps/storefront/features/home · high confidence
New storefront pages for catalog browsing and order management
The BookWorm storefront now includes dedicated pages for browsing the catalog and managing orders. Users can explore books via the Shop page (with search, filtering, and pagination), browse by Category or Publisher, and view individual Book Details with rich SEO metadata and dynamic Open Graph images. The ordering flow is completed with an Account page for profile and address management, an Orders list with status filtering and pagination, individual Order Details, and a Checkout Confirmation page that displays order status and actions.
src/Clients/apps/storefront/app/(catalog) · high confidence
New token exchange service and HTTP handler for Keycloak integration
The application now includes a dedicated token exchange mechanism within the security chassis. This change introduces an \ITokenExchange\ service that converts a user's current access token into a new token for a specific target audience using Keycloak's token-exchange grant. To simplify usage, a new \AddAuthTokenExchange\ extension method registers this service along with an \HttpClientAuthorizationDelegatingHandler\. This handler automatically intercepts outgoing HTTP requests, performs the token exchange using the current user's context, and attaches the new access token to the request authorization header, allowing downstream services to be called with the correct credentials without manual token management.
src/BuildingBlocks/BookWorm.Chassis/Security/TokenExchange · high confidence
Publisher management now supports deletion and includes seed data
The Publisher aggregate now exposes a Delete method via the repository interface, enabling users to remove publishers from the catalog. Additionally, the system initializes with a predefined set of major publishing houses (such as Penguin Random House and HarperCollins) to provide immediate seed data for the application.
src/Services/Catalog/BookWorm.Catalog/Domain/AggregatesModel/PublisherAggregate · high confidence
Rating service scaffolding and configuration
The BookWorm.Rating service has been initialized with a new project structure, including a Program.cs entry point that configures ASP.NET Core with Keycloak token introspection, rate limiting, and API versioning (V1). The service exposes feedback endpoints under the 'feedbacks' route and integrates with the Agent Governance Toolkit for policy enforcement. A new FeedbackDto record and DomainToDtoMapper are added to handle feedback data transformation, while appsettings.json configures logging with request-scoped buffering and probabilistic sampling.
src/Services/Rating/BookWorm.Rating · high confidence
Storefront adds Copilot integration with custom styling
The Storefront client now includes a Copilot integration, evidenced by the addition of \@copilotkit/react-core\ and \@copilotkit/runtime\ dependencies in the lockfile and a new \copilot.css\ stylesheet that styles the CopilotKit sidebar, messages, and input components. This change is accompanied by the introduction of a standardized monorepo structure for the Clients area, including new \turbo.json\ build tasks, ESLint configurations, and TypeScript settings for the \api-client\ and \ui\ packages.
src/Clients · high confidence
Removals
Removal of AI embedding and blob storage infrastructure
The AI service for generating text embeddings and the Azurite blob storage service have been removed from the catalog infrastructure. This eliminates the ability to generate vector embeddings for books and store associated images in local storage, and also removes the EF Core compiled model files that defined the database schema for these entities.
src/BookWorm.Catalog/Infrastructure · high confidence
Removal of AppHost infrastructure and shared libraries
The AppHost project has been completely removed, along with shared infrastructure code for database migrations and activity tracing. This eliminates the local development orchestration of services (such as PostgreSQL, MongoDB, Redis, and various APIs) and the automatic database migration/seeding logic previously provided by the deleted shared extensions.
src/BookWorm.AppHost · high confidence
Removal of BookWorm.Basket application entry point
The Program.cs file for the BookWorm.Basket service has been deleted, removing the application's startup configuration, dependency injection setup (including MediatR, FluentValidation, and service defaults), and endpoint mapping. This indicates the service is no longer bootstrapped as a standalone web application within this project structure.
src/BookWorm.Basket · high confidence
Removal of BookWorm.Shared infrastructure components
The BookWorm.Shared library has removed its internal infrastructure implementations, including the ActivityScope for distributed tracing, the MassTransit/RabbitMQ event bus extension, the custom endpoint mapping and API versioning extensions, the global exception handlers, and the MediatR pipeline behaviors for logging, metrics, and validation. This change eliminates the shared library's role in wiring up these cross-cutting concerns, requiring consumers to configure these capabilities directly within their respective service boundaries.
src/BookWorm.Shared · high confidence
Removal of Catalog API endpoints for Books, Authors, and Categories
The catalog service no longer exposes HTTP endpoints for managing books, authors, or categories. All command and query handlers, API endpoints, validators, and DTO mapping logic for these resources have been removed from the \src/BookWorm.Catalog/Features\ directory, effectively disabling the ability to create, read, update, delete, or list these items via the API.
src/BookWorm.Catalog/Features/Books · high confidence
Removal of Catalog Domain entities and specifications
The domain layer for the BookWorm Catalog service has been stripped of its core data models and query logic. Specifically, the Author, Book, BookAuthor, Price, Category, and Publisher entities, along with the Status enum and the BookFilterSpec specification, have been deleted from the src/BookWorm.Catalog/Domain directory. This removes the foundational structures used to represent books, their metadata, and filtering criteria from this specific project location.
src/BookWorm.Catalog/Domain · high confidence
Removal of file upload validation filter
The FileValidationFilter component, which previously enforced constraints on uploaded files (such as maximum size and allowed content types like JPEG and PNG), has been removed from the Catalog service. Users can no longer rely on this specific server-side validation logic for file uploads within this module.
src/BookWorm.Catalog/Filters · high confidence
Removal of gRPC BookService implementation
The gRPC service implementation for retrieving book details and status (BookService.cs) has been removed from the Catalog service. This eliminates the server-side handlers that previously allowed clients to fetch individual book information and check book status via the gRPC interface.
src/BookWorm.Catalog/Grpc · high confidence
Removal of gRPC service and API contract definitions
The gRPC service implementation and its associated protocol buffer definitions have been removed from the Catalog service. This eliminates the \GetBook\ and \GetBookStatus\ RPC endpoints, along with the \BookService\ gRPC registration and related infrastructure (such as the \Book.proto\ file), effectively deprecating the gRPC-based communication channel for this component.
src/BookWorm.Catalog · high confidence
Removal of legacy Basket domain models
The legacy \Basket\ and \BasketItem\ domain classes have been removed from the \BookWorm.Basket\ domain layer. This deletion eliminates the previous implementation for managing basket contents, including adding, removing, and adjusting item quantities, indicating a structural shift in how basket data is handled within the application.
src/BookWorm.Basket/Domain · high confidence
Architecture
Introduction of marker interfaces for Chassis and Constants layers
New marker interfaces, IChassisMarker and IConstantsMarker, have been added to the BookWorm.Chassis and BookWorm.Constants building blocks respectively. These empty interfaces serve as architectural markers to identify and enforce dependencies for these specific layers, likely supporting the architectural tests mentioned in the commit history.
src/BuildingBlocks/BookWorm.Chassis, src/BuildingBlocks/BookWorm.Constants · high confidence
Behavioural changes
Adopt Protobuf edition 2023 syntax for gRPC services
The gRPC protocol definitions for the Basket and Catalog services have been updated to use the Protobuf edition 2023 syntax. This change modernizes the interface contracts by replacing the legacy \syntax = "proto3"\ declaration with the explicit \edition = "2023"\ directive, ensuring consistent language behavior and future-proofing the API definitions for both services.
src/Services/Basket/BookWorm.Basket/Grpc/Protos, src/Services/Catalog/BookWorm.Catalog/Grpc/Protos · high confidence
Auth pages now redirect to Keycloak for login and registration
The login and registration pages in the storefront have been updated to automatically redirect users to Keycloak for authentication. Instead of displaying static forms, these pages now show a loading spinner and a message indicating the redirect is in progress, leveraging the Keycloak social provider via the auth client. A new layout ensures these pages are centered on the screen with a consistent background.
src/Clients/apps/storefront/app/(auth) · high confidence
Authors feature refactored to use Mediator and new API structure
The Authors feature in the Catalog service has been restructured to use the Mediator library instead of the previous MediatR implementation, updating command and query handlers to implement ICommandHandler and IQueryHandler interfaces. The REST endpoints for creating, reading, listing, updating, and deleting authors have been rewritten to use the new IEndpoint interface, integrating with the Asp.Versioning.OpenApi system for API versioning and applying consistent authorization and per-user rate limiting policies. Validation logic has been consolidated into internal validators, and domain-to-DTO mapping has been standardized, ensuring that author management operations are now handled through a more modern, consistent architectural pattern within the catalog service.
src/Services/Catalog/BookWorm.Catalog/Features/Authors · high confidence
Automated code formatting and build verification on commit
The repository now automatically runs code formatting, style checks, analyzer verification, and a build step before every commit. This is achieved by introducing a Husky pre-commit hook that executes the .NET Husky runner, which is configured via task-runner.json to invoke CSharpier for formatting and checking, run Roslyn analyzers on the solution, and perform a Release build to ensure the code compiles cleanly.
.husky · high confidence
Basket creation now uses a vertical slice architecture with Mediator
The basket creation flow has been restructured into a vertical slice pattern, replacing the previous implementation with new command, endpoint, and validator classes. This change migrates the service from MediatR to the Mediator library, updates the endpoint to use empty base paths with specific resource names for routing, and enforces per-user rate limiting on the create basket API. Users will see no functional change to the basket creation capability itself, but the underlying structure is now aligned with the project's modernized architecture.
src/Services/Basket/BookWorm.Basket/Features/Create · high confidence
Basket integration events now include customer and order totals
The basket service's integration events have been updated to carry additional context for downstream consumers. The PlaceOrderCommand now includes the customer's FullName and the order's TotalMoney. Similarly, the new BasketDeletedCompleteIntegrationEvent and BasketDeletedFailedIntegrationEvent events expose the TotalMoney, with the failed event also including the customer's Email. These changes ensure that related services receive complete financial and user details when processing basket operations.
src/Services/Basket/BookWorm.Basket/IntegrationEvents/Events · high confidence
Basket retrieval now enriches items with current book details
The Get Basket endpoint has been restructured into a vertical slice using the Mediator library, introducing a post-processor that fetches and injects the latest name, sale price, and regular price for each item in the user's basket. This ensures that the returned basket data reflects the most up-to-date product information from the catalog service rather than relying on stale cached values.
src/Services/Basket/BookWorm.Basket/Features/Get · high confidence
Basket service adopts Wolverine for event handling
The Basket service has migrated its integration event handling infrastructure from MassTransit to Wolverine. This change is evidenced by the introduction of a new \PlaceOrderCommandHandler\ that utilizes Wolverine's \IMessageBus\ and attribute-based routing conventions, replacing the previous MassTransit-based implementation. Users of the Basket service will experience this as an internal architectural shift in how order placement events are processed and published, ensuring consistency with the broader platform's move to WolverineFx.
src/Services/Basket/BookWorm.Basket/IntegrationEvents/EventHandlers · high confidence
Basket service initializes with unified identity, authorization, and infrastructure wiring
The Basket service now explicitly registers its application services, establishing a standardized security and operational baseline. Authentication is configured via Keycloak with specific role and scope requirements for read/write access, and identity is exposed through new extension methods for both HTTP and gRPC contexts. The service integrates with Redis for state, uses a scoped Mediator pipeline for command/query handling, and configures an event bus with Kafka partitioning based on OrderId to preserve saga ordering. Additional capabilities include rate limiting, OpenAPI documentation, gRPC support, and global exception handling.
src/Services/Basket/BookWorm.Basket/Extensions · high confidence
Basket service now exposes a versioned gRPC API with Keycloak authentication and per-user rate limiting
The Basket service has been restructured to expose its primary interface via gRPC (BasketService) rather than traditional HTTP endpoints. This gRPC service is protected by Keycloak token introspection middleware and enforces per-user rate limiting (configured via fixed window and token bucket policies in appsettings.json). The API is versioned (V1) and accessible under the 'baskets' route prefix. Additionally, the service now includes health checks, CORS support, and structured logging with probabilistic sampling and request-scoped buffering to reduce noise.
src/Services/Basket/BookWorm.Basket · high confidence
Basket service now registers gRPC services with detailed error handling and health checks
The Basket service's gRPC configuration has been updated to enable detailed error messages in development environments and register a global exception interceptor for improved error handling. Additionally, gRPC health checks are now enabled, and the service explicitly registers a reference to the Catalog's Book gRPC service alongside the local BookService implementation.
src/Services/Basket/BookWorm.Basket/Grpc · high confidence
Basket update and delete operations now use Mediator and enforce per-user rate limiting
The Basket service has been refactored to use the Mediator library for command handling, replacing the previous implementation. The Update and Delete endpoints now explicitly require per-user rate limiting and authorization, ensuring that users can update or delete their baskets within defined limits. The update command validates basket items and persists changes, while the delete command removes the basket entirely, both returning a NoContent status upon success.
src/Services/Basket/BookWorm.Basket/Features/Update · high confidence
Blob storage operations now use URNs and support secure SAS token access
The catalog service's blob storage implementation has been refactored to use Uniform Resource Names (URNs) for identifying files instead of raw URLs, and now includes the ability to generate time-limited Shared Access Signature (SAS) URLs for secure, temporary file access. This change introduces a new BlobService that validates URN formats against the expected account and container names, replaces the previous IAzuriteService interface with a broader IBlobService contract, and registers the service via Azure Blob Container Client integration.
src/Services/Catalog/BookWorm.Catalog/Infrastructure/Blob · high confidence
Books API restructured with vertical slices, FusionCache, and blob storage integration
The Books feature in the Catalog service has been reorganized into vertical slices (Create, Get, List, Update, Delete), replacing the previous flat structure. The API now supports creating and updating books with image uploads via a BlobService, which generates SAS URLs for secure access. Reading book details uses FusionCache for improved performance, and listing books supports advanced filtering, sorting, and pagination with semantic search integration. The BookDto has been enriched to include nested Category, Publisher, and Author objects instead of simple strings, and all endpoints are versioned to V1 with admin authorization and per-user rate limiting.
src/Services/Catalog/BookWorm.Catalog/Features/Books · high confidence
Catalog database schema updates and migration scaffolding
The Catalog service's database migrations have been updated to support several structural changes: the 'image' column in the 'books' table has been widened from 100 to 255 characters to accommodate longer URNs, and the 'created\_at' and 'last\_modified\_at' timestamps now use dynamic SQL defaults ('NOW() AT TIME ZONE UTC') instead of static values. Additionally, the migration scaffolding now includes the initial schema definition and a new table for MassTransit inbox/outbox patterns to support reliable messaging.
src/Services/Catalog/BookWorm.Catalog/Infrastructure/Migrations · high confidence
Catalog entities now use UUID v7 identifiers and explicit EF Core configurations
The Catalog service's database schema for Author, Book, BookAuthor, Category, and Publisher entities has been updated to generate IDs using UUID v7 instead of the previous identifier strategy. This change is implemented via new Entity Framework Core configuration classes that also enforce required fields, set maximum string lengths, define relationship constraints (such as restricting deletion on author links and cascading on book links), and apply soft-delete filters. Users will see these changes reflected in database migrations and potentially in how IDs are generated and stored, which may improve sortability and distributed-system compatibility.
src/Services/Catalog/BookWorm.Catalog/Infrastructure/EntityConfigurations · high confidence
Catalog service adopts WolverineFx for event persistence and adds structured API tracing
The Catalog service now uses WolverineFx to persist integration events to PostgreSQL and applies per-book/partition ordering on Kafka, replacing the previous event bus implementation. Additionally, a new structured logging helper (BookApiTrace) was added to emit debug-level trace messages for book creation and update events, improving observability for these domain actions.
src/Services/Catalog/BookWorm.Catalog/Extensions · high confidence
Catalog service infrastructure modernized with AI seeding and vector search
The Catalog service's infrastructure layer has been restructured to support AI-driven data seeding and hybrid search capabilities. The new CatalogDbContext integrates Wolverine for envelope storage and uses a dedicated seeder that leverages an AI chat client to automatically generate compelling book descriptions during database initialization, falling back to static text if generation fails. Additionally, the service now ingests book data into a Qdrant vector store via a new BookDataIngestor, enabling vector-based search, while Redis caching and Azure Blob Storage configurations have been consolidated into the service extension methods.
src/Services/Catalog/BookWorm.Catalog/Infrastructure · high confidence
Catalog service restructured with new hosting, security, and performance configurations
The BookWorm.Catalog service has been reorganized into a new project structure, introducing a centralized Program.cs that enforces security and performance standards. Key changes include the integration of Keycloak token introspection for authentication, the application of per-user rate limiting to control traffic, and the explicit mapping of API versions for both REST and gRPC endpoints. The service now utilizes a shared chassis for infrastructure concerns (EF, Repository, EventBus) and configures Kestrel to hide server headers and support HTTP/1 and HTTP/2. Additionally, logging is enhanced with request-scoped buffering and probabilistic sampling to reduce noise, while caching expiration and Redis connection settings are explicitly defined in the configuration.
src/Services/Catalog/BookWorm.Catalog · high confidence
Categories API refactored to use Mediator and new endpoint structure
The Categories feature in the Catalog service has been restructured to use the Mediator library instead of the previous MediatR implementation. This change introduces new command and query handlers for Create, Read, List, Update, and Delete (CRUD) operations, along with corresponding endpoints that enforce admin authorization and per-user rate limiting. The delete operation now includes validation to prevent deletion of categories that still contain books. Additionally, the project structure has been updated, moving files to a new namespace under \src/Services/Catalog/BookWorm.Catalog/Features/Categories\ and updating imports to reflect the new library dependencies.
src/Services/Catalog/BookWorm.Catalog/Features/Categories · high confidence
Centralized Aspire service and component constants
The application now uses a dedicated constants library to define identifiers for Aspire-managed services (such as Catalog, Ordering, and Scheduler), infrastructure components (like Redis and Keycloak), and client applications (Storefront and Backoffice). This change also introduces structured descriptions for configuration parameters, including detailed guidance for Keycloak authentication, SendGrid email settings, and CORS origins, providing clearer context for developers configuring the environment.
src/BuildingBlocks/BookWorm.Constants/Aspire · high confidence
Centralized JWT authentication and authorization helpers
The application now provides a unified entry point for security configuration via the new \AuthenticationExtensions.AddDefaultAuthentication\ method, which registers JWT Bearer authentication backed by Keycloak. This setup automatically adjusts its behavior based on the environment: in development, it uses HTTP and relaxes issuer/audience validation, while production enforces HTTPS and strict validation. A key behavioral change is that the access token is now saved in the authentication properties, making it available for downstream service calls. Additionally, the \ClaimsPrincipalExtensions\ class offers convenient methods to retrieve roles, claim values, and parse JSON claims, while \PolicyBuilderExtensions\ introduces a \RequireScope\ helper to enforce Keycloak scope-based authorization policies.
src/BuildingBlocks/BookWorm.Chassis/Security/Extensions · high confidence
Centralized OpenAPI metadata and configuration for Basket and Catalog services
The Basket and Catalog services now define their OpenAPI documentation details (title, summary, description, contact, and license) via dedicated configuration classes (BasketAppSettings and CatalogAppSettings). This change centralizes API metadata management, ensuring consistent documentation generation for these services. Additionally, the Catalog service configuration now includes a specific setting for SAS token expiry hours, allowing for configurable storage access security parameters.
src/Services/Basket/BookWorm.Basket/Configurations, src/Services/Catalog/BookWorm.Catalog/Configurations · high confidence
Configurable mail sending resilience with circuit breaking, retry, and timeout
The notification service now includes a resilience pipeline for email sending that can be tuned via configuration. This pipeline applies circuit breaking, exponential backoff with jitter for retries, and a 30-second timeout to mail operations, allowing the system to handle transient failures more gracefully without manual intervention.
src/Services/Notification/BookWorm.Notification/Infrastructure/Senders · high confidence
Configures gRPC services with detailed error handling and inter-service references
The ordering service now registers its gRPC infrastructure via a new extension method, enabling detailed error messages in development environments and adding a global exception interceptor for improved error reporting. It also establishes typed gRPC client references to the Catalog and Basket services, wiring them into the dependency injection container with degraded health status handling, and registers the corresponding application-layer service interfaces (IBookService, IBasketService) to facilitate communication with these downstream dependencies.
src/Services/Ordering/BookWorm.Ordering/Grpc · high confidence
Domain events now drive projections via Marten subscriptions
The ordering service now uses a new Marten-based event subscription to process domain events. This change replaces the previous mechanism with a dedicated publisher that dispatches events to the event dispatcher, ensuring that user context is correctly propagated and that database changes are persisted within the same scope as event handling.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/EventStore/Subscriptions · high confidence
Email delivery now uses an outbox pattern for reliability
The notification service now wraps email sending in an outbox mechanism to ensure messages are persisted before transmission. When an email is sent, it is first saved to the database via the outbox repository, then dispatched using the actual sender (MailKit in development, SendGrid in production), and finally marked as sent only after successful delivery. This change improves reliability by preventing message loss if the sending process fails midway.
src/Services/Notification/BookWorm.Notification/Infrastructure/Senders/Outbox · high confidence
Enforce strict data validation and modernize ID generation for ordering entities
The ordering service now applies stricter database constraints and uses UUID v7 for primary keys. Buyer, Order, and OrderItem configurations enforce required fields (such as buyer name, address details, order status, and item quantities/prices) and set default timestamps for creation and modification. This ensures data integrity at the database level and aligns entity IDs with the new UUID v7 standard.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/EntityConfigurations · high confidence
Event dispatcher now propagates user ID through message headers
The event dispatching mechanism has been updated to explicitly support user identity propagation. The new EventDispatcher implementation accepts an optional userId parameter and attaches it to the outbound message headers (both 'UserId' and 'userid') when publishing integration events. This ensures that the originating user identifier is preserved across asynchronous boundaries, such as when events are processed by background daemons or Marten projections, allowing downstream components to identify the user context even when the original HTTP request context is no longer available.
src/BuildingBlocks/BookWorm.Chassis/EventBus/Dispatcher · high confidence
Event handlers now use FusionCache and AI ingestion via the Mediator library
The catalog service's event handling logic has been updated to integrate with the new caching and AI infrastructure. When a book is changed, the new BookChangedEventHandler automatically invalidates the corresponding cache entry using FusionCache. Additionally, new BookUpsertEmbeddingHandler instances now listen for book creation and update events to trigger AI data ingestion, ensuring that search embeddings stay synchronized with catalog changes. These handlers are implemented using the new Mediator library instead of the previous MediatR implementation.
src/Services/Catalog/BookWorm.Catalog/Domain/EventHandlers · high confidence
Event store configuration and setup logic introduced
The ordering service now includes explicit configuration classes for the Marten event store. A new \MartenConfigs\ class defines settings such as schema names, metadata usage, and daemon mode. The \StoreConfigs\ class provides a method to build \StoreOptions\, configuring serialization, projection error handling, metadata tracking (causation/correlation IDs), performance optimizations like quick append mode and identity maps, PostgreSQL stream partitioning, and OpenTelemetry tracing.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/EventStore/Configs · high confidence
Finance service now uses Wolverine for event persistence and saga management
The Finance service has been updated to integrate Wolverine as its messaging backbone. This change introduces automatic persistence of integration events to PostgreSQL and configures saga state machines, ensuring reliable event handling and order-based partitioning for saga consistency.
src/Services/Finance/BookWorm.Finance/Extensions · high confidence
Introduce custom Keycloakify login theme for BookWorm
The BookWorm application now uses a new, custom login theme built with Keycloakify (React) instead of the default Keycloak interface. This change brings a redesigned user experience featuring the 'Geist' font family, a branded gradient button style, and a background image. The new login page supports social identity providers (such as Google, Microsoft, and GitHub) and includes Storybook stories to visualize various states like invalid credentials, registration options, and WebAuthn errors.
src/Aspire/BookWorm.AppHost/Container/keycloak/keycloakify/src/login · high confidence
Introduce structured OpenTelemetry activity scoping via DI abstractions
The OpenTelemetry internals in the Chassis building block are now hidden behind a dedicated abstraction layer. A new \ActivityScope\ component provides an \IActivityScope\ interface and an \ActivitySourceProvider\ singleton, allowing the application to create and manage distributed tracing activities with consistent naming (prefixed by 'BookWorm') and W3C trace context propagation. This change standardizes how telemetry spans are started, run, and error-handled across the system, replacing previous ad-hoc instrumentation with a reusable, dependency-injection-friendly pattern.
src/BuildingBlocks/BookWorm.Chassis/OpenTelemetry/ActivityScope · high confidence
Introduces Entity Framework Core configuration for the Outbox entity with UUID v7 IDs
The Notification service now uses Entity Framework Core to manage the Outbox entity, replacing previous persistence mechanisms. This change configures the Outbox table to use UUID v7 for primary keys, ensuring globally unique and time-sortable identifiers. It also defines specific column constraints for recipient details and message content, including maximum lengths and required fields, and adds an index on the IsSent flag to optimize query performance for sent status checks.
src/Services/Notification/BookWorm.Notification/Infrastructure/EntityConfigurations · high confidence
Introduces repository interfaces and specification-based filtering for Buyer and Order aggregates
The domain layer now exposes explicit repository interfaces (IBuyerRepository, IOrderRepository) that rely on a specification pattern for data retrieval. New specification classes (BuyerFilterSpec, OrderFilterSpec) and helper extensions (OrderSpecExpression) allow queries to be built with explicit tracking controls (AsNoTracking/AsTracking), pagination, and filtering by status or buyer ID. This shifts data access from ad-hoc queries to composable, predictable specifications, improving query performance and consistency for order and buyer lookups.
src/Services/Ordering/BookWorm.Ordering/Domain/AggregatesModel · high confidence
Introduces structured request and DTO models for basket items
The basket feature now uses dedicated request and data-transfer objects to handle item additions and responses. A new \BasketItemRequest\ record defines the input contract with a GUID-based item ID and quantity, while \CustomerBasketDto\ and \BasketItemDto\ structure the outgoing basket data, including optional sale prices. Validation rules ensure that item lists are not empty, individual IDs are present, and quantities are positive. Mappers convert incoming requests into domain entities and domain models into DTOs, centralizing this transformation logic within the basket feature.
src/Services/Basket/BookWorm.Basket/Features · high confidence
Introduction of CatalogDomainException for domain error handling
The catalog service now utilizes a dedicated CatalogDomainException class for handling domain-specific errors. This change centralizes exception handling within the domain layer, ensuring that domain violations are reported consistently.
src/Services/Catalog/BookWorm.Catalog/Domain/Exceptions · high confidence
MJML-based email template rendering engine
The notification service now uses an MJML template engine to generate HTML emails. A new renderer loads embedded MJML templates, injects a layout, substitutes model properties (including formatted values), and compiles the result to HTML, replacing the previous rendering approach.
src/Services/Notification/BookWorm.Notification/Infrastructure/Render · high confidence
Migrate Catalog integration events to Wolverine
The Catalog service has replaced its previous messaging infrastructure with Wolverine. This change introduces new integration event records (FeedbackCreated, FeedbackDeleted, and a new BookUpdatedRatingFailed event) and corresponding handlers that process feedback to update book ratings. The handlers now utilize Wolverine's message bus for publishing failure events and rely on the repository for data persistence, aligning the service with the broader platform migration from MassTransit to WolverineFx.
src/Services/Catalog/BookWorm.Catalog/IntegrationEvents · high confidence
Migrate caching infrastructure to FusionCache with Redis backplane
The application's caching layer has been replaced with FusionCache, providing a hybrid L1 (in-memory) and L2 (distributed) caching strategy. This change introduces a new CachingOptions configuration class to manage expiration settings and updates the service registration to wire FusionCache with a System.Text.Json serializer. The distributed cache layer utilizes Redis via StackExchange.Redis, reusing the existing connection multiplexer for both the cache store and the backplane. Additionally, OpenTelemetry instrumentation for metrics and traces is now automatically registered for FusionCache operations.
src/BuildingBlocks/BookWorm.Chassis/Caching · high confidence
Migrate event bus from MassTransit to WolverineFx
The event bus implementation in the Chassis building block has been replaced with WolverineFx, introducing a new set of components for message handling and transport. This includes a CloudEvents-compatible Kafka mapper for serializing and deserializing messages, middleware to propagate user IDs and source URNs via envelope headers, and a topic router for kebab-case naming. The migration also enables durable outbox/inbox patterns with PostgreSQL, automatic schema setup, and native Kafka dead-letter queues, while maintaining compatibility with existing integration events through assembly scanning.
src/BuildingBlocks/BookWorm.Chassis/EventBus/Wolverine · high confidence
Migrate event bus infrastructure to WolverineFx
The event bus implementation has been replaced with WolverineFx, shifting the underlying messaging framework from the previous solution. This change introduces a new registration API (AddEventBus) that configures the Wolverine event framework, registers a scoped EventDispatcher service, and defines core primitives like IntegrationEvent and EventBusHeaders. Users relying on the previous event bus infrastructure will need to update their dependency injection setup to use the new Wolverine-based extensions.
src/BuildingBlocks/BookWorm.Chassis/EventBus · high confidence
Migrate integration events to WolverineFx
The integration event definitions and handlers in the Rating service have been updated to use WolverineFx, replacing the previous MassTransit implementation. This change introduces Wolverine-specific attributes (such as \[MessageIdentity\]) to the event records and updates the handler signatures to align with Wolverine's message handling model, ensuring consistent event processing within the new messaging framework.
src/Services/Rating/BookWorm.Rating/IntegrationEvents · high confidence
Migrate notification service to WolverineFx and EF Core
The notification service now uses WolverineFx for event handling and persistence instead of the previous MassTransit implementation, enabling message persistence via PostgreSQL Entity Framework Core transactions. Service registration has been updated to configure the Wolverine event bus with specific partitioning for OrderId-based saga ordering, and the email rendering infrastructure now defaults to MJML template rendering via MjmlTemplateRenderer.
src/Services/Notification/BookWorm.Notification/Extensions · high confidence
Migrate ordering infrastructure to Wolverine and modernize persistence setup
The ordering service's infrastructure layer has been refactored to support the migration from MassTransit to Wolverine. The new \Extensions.cs\ centralizes service registration, configuring Azure PostgreSQL for the \OrderingDbContext\, setting up the Event Store with live stream aggregation for \OrderSummary\, and integrating Redis for caching. The \OrderingDbContext\ now implements \IUnitOfWork\ and explicitly maps Wolverine envelope storage, ensuring that message handling and database transactions are managed cohesively within the new Wolverine-based architecture.
src/Services/Ordering/BookWorm.Ordering/Infrastructure · high confidence
New OpenTelemetry infrastructure in BookWorm.Chassis
The OpenTelemetry capabilities have been consolidated into the new BookWorm.Chassis module, moving the IgnoreOTelOnHandlerAttribute from BookWorm.Shared. This location now provides the core wiring and processing logic: an ActivityScope service for dependency injection, a FixHttpRouteProcessor that normalizes HTTP route tags and display names in traces (handling API version patterns), a TelemetryPropagator for context injection/extraction, and a TelemetryTags class defining standard tags for commands, queries, and events.
src/BuildingBlocks/BookWorm.Chassis/OpenTelemetry · high confidence
New configuration utilities and settings management infrastructure
This change introduces a new configuration subsystem within the Chassis building block. It adds an \AppSettings\ base class to hold OpenAPI metadata, and provides extension methods for \IConfiguration\ and \IHostApplicationBuilder\ to simplify binding, validating, and registering settings as singletons. Additionally, it adds helpers to detect HTTPS launch profiles and determine the URL scheme, replacing previous HTTP scheme handling.
src/BuildingBlocks/BookWorm.Chassis/Utilities/Configurations · high confidence
New entity configuration for Feedback with UUID v7 IDs and unique constraints
The Rating service now includes a specific Entity Framework Core configuration for the Feedback entity. This configuration enforces that Feedback records use UUID v7 identifiers, requires the Rating, FirstName, and LastName fields, applies length limits to name and comment fields, and establishes a unique composite index on the combination of BookId, FirstName, and LastName to prevent duplicate feedback entries.
src/Services/Rating/BookWorm.Rating/Infrastructure/EntityConfigurations · high confidence
New handlers for order lifecycle notifications and email outbox management
The notification service now includes dedicated command handlers for PlaceOrder, CompleteOrder, and CancelOrder events, which render order-specific HTML emails and dispatch them to customers. Additionally, new integration event handlers manage the email outbox: one handles resending failed or unsent emails by iterating through the repository and marking successes, while another performs bulk cleanup of successfully sent emails to keep storage lean.
src/Services/Notification/BookWorm.Notification/IntegrationEvents/EventHandlers · high confidence
Notification Service database schema updated for Wolverine message storage
The Notification Service's database schema has been migrated to support the Wolverine message broker. This change replaces the previous MassTransit inbox/outbox tables with Wolverine-specific envelope storage tables (\wolverine\_incoming\_envelopes\ and \wolverine\_outgoing\_envelopes\) and updates the \outboxes\ table to use \uuidv7()\ for ID generation. Users relying on the notification service's internal message persistence will see these structural changes applied via the new EF Core migrations.
src/Services/Notification/BookWorm.Notification/Infrastructure, src/Services/Notification/BookWorm.Notification/Infrastructure/Migrations · high confidence
Notification formatting now uses en-US culture
The notification service now consistently applies the en-US culture for string formatting operations. This change ensures that formatted output (such as dates and numbers) remains stable and predictable regardless of the server's regional settings, preventing potential localization issues in user-facing notifications.
src/Services/Notification/BookWorm.Notification/Domain/Attributes · high confidence
Notification service restructured with new integration events and resilient email configuration
The Notification service has been reorganized into a new project structure, introducing specific integration events for order lifecycle actions (PlaceOrder, CompleteOrder, CancelOrder) and email handling (ResendErrorEmail, CleanUpSentEmail). The service now configures resilient email sending via Polly policies (retry, circuit breaker, timeout) and implements advanced logging features including request-scoped buffering and random probabilistic sampling to reduce log noise. Additionally, the service is wired up as a standalone application using Service Defaults and includes a marker interface for API identification.
src/Services/Notification/BookWorm.Notification · high confidence
OpenAPI metadata configuration for Ordering and Rating services
The Ordering and Rating services now include dedicated configuration classes (OrderingAppSettings and RatingAppSettings) that define their OpenAPI documentation metadata. This ensures that the generated API documentation for these services displays specific titles, summaries, descriptions, and contact information, improving clarity for API consumers.
src/Services/Ordering/BookWorm.Ordering/Configurations, src/Services/Rating/BookWorm.Rating/Configurations · high confidence
Order event handlers now propagate user identity and use Version-7 GUIDs
The new OrderEventHandler, which processes OrderPlaced, OrderCompleted, and OrderCancelled events, now explicitly propagates the current user ID to the document session via the PropagateUserId extension method, ensuring user context is preserved in downstream operations. Additionally, all OrderSummary records created or updated by this handler now use Version-7 GUIDs for their identifiers, replacing the previous identifier generation strategy.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/EventStore/Handlers · high confidence
Order saga now includes automatic timeout and retry logic
The Order saga in the Finance service now handles order placement failures by scheduling a recurring timeout. If the initial order placement does not succeed, the saga automatically retries the operation up to a configurable number of attempts (MaxAttempts) with a specified delay (MaxRetryTimeout). If the maximum retry limit is exceeded, the order is automatically cancelled and a cancellation command is sent. This ensures that orders are not left in an indefinite pending state due to transient failures.
src/Services/Finance/BookWorm.Finance/Saga · high confidence
Order saga persistence migrates to Wolverine with timeout and concurrency support
The Finance service's order saga storage has been updated to use Wolverine's built-in inbox/outbox and saga persistence, replacing the previous MassTransit-based implementation. This change introduces a new \OrderSaga\ entity (migrating from \OrderState\) and configures the \FinanceDbContext\ to map Wolverine envelope storage. To support reliable order processing, the saga schema now includes a \RowVersion\ (xmin) column for optimistic concurrency control, as well as \PlaceOrderTimeoutTokenId\ and \TimeoutRetryCount\ columns to enable timeout handling and retry logic for pending orders.
src/Services/Finance/BookWorm.Finance/Infrastructure · high confidence
Ordering integration events enriched with customer details and migrated to Wolverine
Integration events in the ordering service now include additional customer context fields (FullName, Email, TotalMoney) to provide richer information to downstream consumers. Additionally, these event definitions have been updated to use Wolverine-specific attributes (MessageIdentity), reflecting the migration of the messaging infrastructure from MassTransit to Wolverine.
src/Services/Ordering/BookWorm.Ordering/IntegrationEvents/Events · high confidence
Ordering service database schema updated for PostgreSQL 18 and Wolverine migration
The ordering service's database schema has been updated to support PostgreSQL 18 and the migration from MassTransit to Wolverine. Entity IDs for Orders, OrderItems, and Buyers now use UUIDv7 generation, and concurrency control for Orders has switched from a UUID-based version column to a PostgreSQL xid row version column. The previous MassTransit inbox and outbox tables have been removed to accommodate Wolverine's message handling infrastructure.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/Migrations · high confidence
Ordering service infrastructure and security configuration
The Ordering service now registers its core infrastructure, including a Mediator-based CQRS pipeline with validation and transaction behaviors, and configures authentication via Keycloak with specific Admin, Reporter, and User authorization policies. It also sets up the WolverineFx event bus with PostgreSQL persistence and Kafka partitioning, adds distributed locking via Redis, and implements structured logging for order lifecycle events.
src/Services/Ordering/BookWorm.Ordering/Extensions · high confidence
Project modernization: .NET 10, Aspire 13, and Bun tooling
The project has been upgraded to .NET 10 and .NET Aspire 13.5, with the solution structure reorganized into a new \BookWorm.slnx\ file and centralized version management in \Versions.props\. The frontend toolchain has switched from pnpm to Bun (version 1.4.2), and the build system now uses \mise\ as the task runner. Additionally, the solution now enforces treating warnings as errors and includes updated SonarQube analysis configurations.
(repo-wide) · high confidence
Publisher management endpoints migrated to Mediator and vertical slice architecture
The Publisher feature in the Catalog service has been restructured into a vertical slice architecture, replacing the previous MediatR implementation with the Mediator library. This change introduces new command and query handlers for creating, updating, listing, and deleting publishers, along with corresponding minimal API endpoints. The delete operation now includes validation to prevent deletion of publishers that still have associated books, and all endpoints are secured with admin authorization and per-user rate limiting.
src/Services/Catalog/BookWorm.Catalog/Features/Publishers · high confidence
Rating agent now enforces security policies and formats responses
The Rating agent now includes a multi-layered security and formatting workflow. Input is validated against prompt injection patterns and processed by the Agent Governance Toolkit, while output is sanitized to prevent system prompt leaks and ensure consistent formatting. Policy-related queries are routed through a dedicated condition check, and the agent uses a compaction pipeline to manage context efficiently.
src/Services/Rating/BookWorm.Rating/Infrastructure/Agents · high confidence
Rating service adopts PostgreSQL and WolverineFx for persistence and messaging
The Rating service infrastructure now uses a new RatingDbContext based on Entity Framework Core with PostgreSQL, replacing the previous Cosmos DB implementation. This context integrates WolverineFx for message handling by mapping envelope storage and implementing the IUnitOfWork interface, enabling reliable inbox/outbox patterns for the service's feedback data.
src/Services/Rating/BookWorm.Rating/Infrastructure · high confidence
Rating service database schema updated for PostgreSQL 18 and Wolverine messaging
The Rating service's database migrations have been updated to support PostgreSQL 18 and the WolverineFx messaging framework. The schema now uses UUID v7 for entity IDs, replaces the previous MassTransit inbox/outbox tables with Wolverine's incoming and outgoing envelope tables, and adds a unique index on book, first name, and last name to prevent duplicate feedback entries.
src/Services/Rating/BookWorm.Rating/Infrastructure/Migrations · high confidence
Rating service domain refactored to use Mediator and Chassis patterns
The Rating service's domain layer has been restructured to replace the previous MediatR implementation with the Mediator library, introducing an IEventDispatcher for handling events like FeedbackCreated and FeedbackDeleted. Additionally, the domain now utilizes the BookWorm Chassis pattern, featuring a new IFeedbackRepository interface and specification-based filtering (FeedbackFilterSpec) for querying feedback, alongside a dedicated RatingDomainException class.
src/Services/Rating/BookWorm.Rating/Domain · high confidence
Rating service initializes with WolverineFx, PostgreSQL, and Keycloak authentication
The Rating service now registers its application services using a new extension method that configures WolverineFx as the event bus (with PostgreSQL persistence and message partitioning by BookId/FeedbackId), switches the database context to PostgreSQL (replacing previous storage), and integrates Keycloak for authentication and authorization. It also sets up scoped Mediator pipelines for CQRS commands, adds rate limiting, registers OpenAPI versioning, and includes agent orchestration and summarization capabilities.
src/Services/Rating/BookWorm.Rating/Extensions · high confidence
Rebuilt Ordering service with modernized infrastructure and security defaults
The BookWorm.Ordering service has been restructured into a new project layout, introducing a standardized Program.cs that enforces HTTPS (HSTS) in non-development environments, disables the Kestrel server header, and integrates Keycloak token introspection and per-user rate limiting. Configuration has been updated to include specific Redis connection retry settings, request-scoped log buffering, and probabilistic sampling to reduce log noise, while development settings have been cleaned of redundant identity and OpenApi metadata.
src/Services/Ordering/BookWorm.Ordering · high confidence
Redesigned .devcontainer with .NET 10, mise, and enhanced tooling
The development container configuration has been updated to use the .NET 10 SDK image and replace the custom Dockerfile with a post-create script that installs tools via mise, Aspire, and the Buf CLI. The setup now includes additional VS Code extensions (such as Copilot, SonarLint, and Bicep), enforces higher host resource requirements (8 CPUs, 32GB RAM), and adds a post-start command to trust HTTPS development certificates.
.devcontainer · high confidence
Refactor domain primitives and move shared kernel to building blocks
Core domain primitives have been relocated from the BookWorm.Core project to the BookWorm.SharedKernel building block, including the renaming of HasDomainEventsBase to HasDomainEvents and the addition of an IHasDomainEvents interface. The domain event system now uses a specific DomainEvent type instead of the generic EventBase, with serialization attributes added to prevent JSON leakage. The ISoftDelete interface has been extended with a Delete method, and the ValueObject base class has been rewritten to use static equality operators and a new hashing strategy, while also exposing a GetCopy method for cloning.
src/BuildingBlocks/BookWorm.SharedKernel/SeedWork · high confidence
Refactored MailKit email sending infrastructure with centralized client management
The MailKit email sender implementation has been restructured to improve reliability and observability. A new \MailKitClientFactory\ now centrally manages the creation, connection, and disposal of SMTP clients, ensuring proper resource cleanup even when authentication or connection attempts fail. The \MailKitSender\ now leverages a resilience pipeline for sending operations, providing automatic retry capabilities for transient failures. Configuration is streamlined through \MailKitSettings\, which supports parsing connection strings to extract endpoints and credentials, and includes validation to ensure required fields like the 'From' address are present. Additionally, the service now integrates with the platform's health check system to verify SMTP connectivity and supports OpenTelemetry tracing and metrics for monitoring email delivery performance.
src/Services/Notification/BookWorm.Notification/Infrastructure/Senders/MailKit · high confidence
Refactored basket domain model and repository interface
The basket domain layer has been reorganized to improve code structure and type safety. The domain now includes specific exception classes (BasketCreatedException, BasketDomainException) for clearer error handling. The BasketItem entity has been updated to implement IValidatableObject, ensuring that quantity is strictly validated as greater than zero. Additionally, the IBasketRepository interface has been refined to use specific method names (CreateOrUpdateBasketAsync) and explicit string syntax attributes for GUID parameters, standardizing how basket data is persisted and retrieved.
src/Services/Basket/BookWorm.Basket/Domain · high confidence
Refactored book filtering specifications with optimized query execution
The catalog's book filtering logic has been restructured to improve query performance and maintainability. A new BookFilterSpec class now centralizes filtering by category, publisher, author, price, and ID, while explicitly enabling EF Core's AsNoTracking to reduce memory overhead during read operations. Existing specifications like BookAuthorFilterSpec have been migrated to use the new internal chassis pattern, and helper methods for ordering and paging have been adjusted to align with the updated specification builder interface.
src/Services/Catalog/BookWorm.Catalog/Domain/AggregatesModel/BookAggregate/Specifications · high confidence
Removal of BookWorm.Rating service configuration and entry point
The BookWorm.Rating service's standalone configuration files, including Program.cs, launch settings, and appsettings, have been deleted. This indicates the service is no longer running as an independent web application with its own HTTP endpoints and development server configuration, likely as part of a broader architectural shift or consolidation.
src/BookWorm.Rating · high confidence
Removal of Identity Service database scaffolding and configuration files
The Identity service has removed its static configuration and database scaffolding files, including \AppSettings.cs\, \Config.cs\ (which defined IdentityServer resources, APIs, scopes, and clients), and the entire \Data/CompliedModels\ directory containing the auto-generated Entity Framework Core runtime model for the \ApplicationDbContext\. This change eliminates the hardcoded definitions for Swagger UI clients and the BFF client, as well as the compiled database schema metadata for Identity tables, indicating a shift away from this specific static configuration and scaffolding approach in the Identity service.
src/BookWorm.Identity · high confidence
Removal of centralized authentication, health check, and Swagger configuration defaults
The \BookWorm.ServiceDefaults\ library has removed its core infrastructure extensions, meaning services no longer automatically configure JWT authentication, OpenTelemetry observability, default health check endpoints, or Swagger UI generation through this shared package. Specifically, the \AddDefaultAuthentication\ method for configuring JWT Bearer tokens, the \AddServiceDefaults\ method for setting up metrics/tracing and service discovery, the \AddOpenApi\/\UseOpenApi\ methods for Swagger generation, and the \MapDefaultEndpoints\ method for exposing health routes have all been deleted. Consumers of this library must now implement these configurations directly within their respective service projects.
src/BookWorm.ServiceDefaults · high confidence
Removal of legacy core abstractions and Aspire hosting extensions
This change removes several foundational components from the BookWorm application. In the core library, the \EntityBase\ class and \EventBase\ class (used for domain events) have been deleted, along with the \ICommand\, \ICommandHandler\, \IQuery\, \IQueryHandler\, \IReadRepository\, \IRepository\, and \ITxRequest\ interfaces that supported the previous CQRS and repository patterns. Additionally, the custom Aspire hosting extensions for Health Checks UI (\HealthChecksUiExtensions\, \HealthChecksUiResource\, and the associated lifecycle hook) and MailDev (\MailDevResource\ and \MailDevResourceBuilderExtensions\) have been removed from their respective hosting projects, eliminating the custom resource builders and lifecycle hooks that previously managed these containerized services.
src/BookWorm.Core, src/BookWorm.HealthCheck.Hosting, src/BookWorm.MailDev.Hosting · high confidence
Removed Next.js project scaffolding files
The default Next.js starter template files have been removed from the BackOffice application. This includes the root layout (\layout.tsx\), the home page (\page.tsx\), global styles (\globals.css\), Tailwind configuration (\tailwind.config.ts\), and the associated Next.js and Vercel logo assets. This change clears the initial boilerplate, preparing the directory for custom application code.
src/BookWorm.BackOffice · high confidence
Removed default Blazor application scaffolding from the StoreFront
The default Blazor application scaffolding has been removed from the BookWorm.StoreFront project. This includes the deletion of the client-side entry point, the server-side host configuration, and all default UI components such as the Counter, Weather, and Home pages, along with their associated layouts, styles, and configuration files. The application no longer includes these out-of-the-box demo features.
src/BookWorm.StoreFront, src/BookWorm.Web.Bff · high confidence
Replace MediatR with Mediator for domain event dispatching
The domain event dispatching mechanism in the shared kernel has been migrated from MediatR to the Mediator library. This change introduces a new IDomainEventDispatcher interface and a MediatorDomainEventDispatcher implementation that leverages the Mediator IPublisher to handle domain events, along with a DI extension method to register the dispatcher as a scoped service.
src/BuildingBlocks/BookWorm.SharedKernel · high confidence
Repository implementations refactored to use primary constructors and internal visibility
The repository classes in the catalog infrastructure layer (Author, Book, Category, and Publisher) have been rewritten to use C\# primary constructors for dependency injection of the DbContext and are now marked as internal sealed classes. This change aligns the implementation with the new chassis pattern and vertical slice architecture, ensuring these infrastructure components are hidden from external scanning while maintaining their data access capabilities.
src/Services/Catalog/BookWorm.Catalog/Infrastructure/Repositories · high confidence
Repository implementations refactored to use primary constructors and specification evaluators
The BuyerRepository and OrderRepository in the ordering service infrastructure have been rewritten to use C\# primary constructors for dependency injection and to leverage the SpecificationEvaluator for query composition. This change standardizes how data access logic is structured, moving away from previous implementation patterns to a more concise and consistent approach that integrates with the Chassis specification framework.
src/Services/Ordering/BookWorm.Ordering/Infrastructure/Repositories · high confidence
SendGrid email delivery now uses a dedicated client with resilience and staging sandboxing
The notification service's SendGrid integration has been refactored to use a new \InjectableSendGridClient\ and \SendGridSender\ that rely on \ISendGridClient\ and \SendGridSettings\ for configuration. This change introduces resilience pipelines for email sending, ensuring retries or fallbacks are handled via \ResiliencePipelineProvider\. Additionally, emails sent in the staging environment are automatically routed through SendGrid's SandBox mode for safe testing. The sender now validates API keys and email formats at startup and logs failures with specific status codes, improving observability and reliability of email notifications.
src/Services/Notification/BookWorm.Notification/Infrastructure/Senders/SendGrid · high confidence
Standardized API versioning, pagination headers, and endpoint registration
The application now uses Asp.Versioning.OpenApi for API versioning, reading versions from URL segments and the 'api-version' header, with a default of v1. Paginated responses automatically include RFC 5988 Link headers (first, self, previous, next, last) and a Pagination-Count header. Endpoint discovery is centralized via assembly scanning for IEndpoint implementations, which are mapped into versioned route groups (e.g., /api/v{version}/{resourceName}).
src/BuildingBlocks/BookWorm.Chassis/Endpoints · high confidence
Standardized OpenAPI configuration with automatic deprecation and security metadata
Services using the BookWorm.ServiceDefaults now register a consistent OpenAPI setup via the new \AddDefaultOpenApi\ extension. This configuration automatically applies transformers to mark deprecated endpoints, enforce authorization checks in the documentation, and define security schemes, while \UseDefaultOpenApi\ exposes the OpenAPI JSON only in development environments.
src/Aspire/BookWorm.ServiceDefaults/ApiSpecification/OpenApi · high confidence
Standardized exception handling for HTTP and gRPC services
The application now uses a unified exception handling strategy that converts unhandled errors into standardized, user-friendly responses. For HTTP requests, validation failures from FluentValidation are returned as structured validation problem details, not-found errors return a 404 with a clear message, and other unexpected errors return a generic 500 response that includes a trace ID for debugging. For gRPC services, unhandled exceptions are caught and converted into standard RpcExceptions with an 'Internal' status code, ensuring consistent error reporting across both communication protocols.
src/BuildingBlocks/BookWorm.Chassis/Exceptions · high confidence
Test coverage
Add contract tests for basket order placement and event publishing; Added FeedbackFaker for unit test data generation; Added K6 load testing extension for AppHost; Added architectural guardrail tests for domain and service boundaries; Added contract test for failed book rating feedback event publishing; Added contract tests for basket deletion command handlers; Added contract tests for catalog and rating service event consumers; Added contract tests for integration event publishers; Added contract tests for notification consumer handlers; Added property-based fuzz tests for storefront utility and validation functions; Added snapshot tests for email rendering and SendGrid message composition; Added test coverage for Backoffice Admin Portal features; Added test coverage for storefront account UI components; Added test coverage for storefront hooks; Added test data fakers for catalog domain entities; Added test data fakers for ordering domain aggregates; Added test helper for gRPC server call context; Added unit tests and test infrastructure for the Storefront Hero Section; Added unit tests for Author CRUD operations; Added unit tests for Backoffice Orders and Reviews features; Added unit tests for Backoffice UI components and hooks; Added unit tests for Basket Get and Delete features; Added unit tests for BasketItem and CustomerBasket domain models; Added unit tests for BasketService gRPC operations; Added unit tests for Buyer CRUD operations and address management; Added unit tests for Catalog domain aggregates and specifications; Added unit tests for McpTools service components; Added unit tests for Notification domain models and specifications; Added unit tests for Publisher CRUD operations; Added unit tests for Storefront utility libraries; Added unit tests for backoffice book filter components; Added unit tests for backoffice books feature components; Added unit tests for catalog event handlers; Added unit tests for integration event handlers across Basket, Catalog, and Ordering services; Added unit tests for notification command and integration event handlers; Added unit tests for notification infrastructure components; Added unit tests for order lifecycle commands and endpoints; Added unit tests for ordering domain aggregates and projections; Added unit tests for scheduler email cleanup and resend jobs; Added unit tests for storefront UI components; Added unit tests for storefront atom state management; Added unit tests for storefront catalog and basket UI components; Added unit tests for the BookUpdatedRatingFailedIntegrationEventHandler; Added unit tests for the Books feature vertical slice; Added unit tests for the Create Basket feature; Added unit tests for the Create Feedback feature; Added unit tests for the Finance Order Saga and CloudEvent header policy; Added unit tests for the Rating service domain logic; Added unit tests for the ReviewTool; Added unit tests for the Summarize feature endpoints and handlers; Added unit tests for the gRPC BookService; Added unit tests for the list feedbacks feature; Contract tests for the Finance Order Saga now verify CloudEvents output; Contract tests now initialize Verify.Wolverine and OpenTelemetry listeners; Initial E2E test suite for the Storefront application.
Dependencies
Initial dependency manifests for BookWorm infrastructure and clients
This change introduces the initial package.json and .csproj dependency manifests for the BookWorm application's infrastructure and client layers. It defines the Node.js dependencies for the Docusaurus and EventCatalog documentation sites, the k6 load testing container, and the Keycloakify authentication theme, all targeting Node 24. It also establishes the .NET Aspire 13.5.4 AppHost project, the ServiceDefaults shared project, and the Chassis building block, which collectively wire up the hosting, telemetry, and AI agent frameworks (including Foundry, Qdrant, and Kafka) for the microservices.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 57.
Lenses
- Code Health 79
- Architecture 79
- Maturity 84
- Readiness 71
- Security 54
- Domain Modelling 58
- Event-Driven 100
- Accessibility 55
- Performance 62
Changes since last survey
- 300 commits — 258 feature/other, 42 fixes
By area
- src/Services — 67 commits
- src/Clients — 54 commits
- .github/workflows — 50 commits
- src/Aspire — 31 commits
- (root) — 19 commits
- src/BuildingBlocks — 12 commits
- docs/docusaurus — 11 commits
- .github/skills — 8 commits
- docs/eventcatalog — 8 commits
- .github/actions — 7 commits
- .github/hooks — 5 commits
- .agents/skills — 4 commits
- .github/agents — 4 commits
- assets/BookWorm.png — 4 commits
- src/Integrations — 4 commits
- .devcontainer/devcontainer.json — 1 commit
- .github/CONTRIBUTING.md — 1 commit
- .github/DISCUSSION_TEMPLATE — 1 commit
- .github/ISSUE_TEMPLATE — 1 commit
- .github/dependency-review-config.yml — 1 commit
Notable commits
- fix: Fix Book Agent failure when IPresidioService is not registered (#976)
- fix: chore: update docs & fix AuthZ confusion
- fix: fix(devcontainer): correct mise feature path in devcontainer.json
- fix: fix(eventbus): route Kafka messages through CloudEvents envelope
- fix: fix(husky): update betterleaks scan command to include pre-commit and staged options
- fix: fix: CORS policy and improve API response handling (#490)
- fix: fix: JWT authentication by saving access token (#1005)
- fix: fix: Mediator pipeline not working
- fix: fix: Migrate to MTP mode of dotnet test
- fix: fix: PII/sensitive data exposure across auth, logging, exception handling, and UI layers (#682)
- fix: fix: Qdrant references to catalog
- fix: fix: Standard token exchange and enhance performance (#1010)
- fix: fix: Update FormatProvider to use en-US culture for consistency
- fix: fix: Upgrade package and fix bugs (#481)
- fix: fix: add hooks for dashboard stats, user context, and access token (#518)
- fix: fix: add ref and sha parameters to scorecard and trivy jobs; remove unused SonarLint configuration files
- fix: fix: ci failling and sonar warming
- fix: fix: decimal convert issue
- fix: fix: disable ESLint rule for img elements in opengraph-image and twitter-image files
- fix: fix: exclude AI.Evaluation from CI test discovery and build (#645)
- …and 280 more
API surface
- 31 HTTP endpoints (baseline)
Architecture
- 29 containers · 2 bounded contexts · 1 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
foxminchan/BookWorm was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 103ae46d58a90e7440a19ae93e6fd7db6edd828a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.