Skip to content
CAI
Software that uses CAICheck a score

fpindej/netrock

48.5

Weak · 21 September 2026

16.9k

lines of production code

C#

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a full-stack web application built with a .NET backend and a SvelteKit frontend, designed to manage user identities, administrative operations, and background tasks. It provides comprehensive authentication features including OAuth2 social logins, TOTP two-factor authentication, and secure session management, alongside a granular, permission-based authorization model for role and user administration. The platform supports user profile management with avatar uploads, transactional email notifications, and an audit trail for tracking system activity, all secured with robust infrastructure for caching, encryption, and rate limiting.

How it got here

2025 — Authentication overhaul and frontend launch

53 changes.

The project replaced its initial scaffolding with a comprehensive, permission-based authentication system featuring TOTP 2FA, OAuth integration, and hardened security controls. Simultaneously, a new SvelteKit frontend was introduced, providing a complete user interface for login, profile management, and administrative tasks, supported by a modernized backend architecture and dependency stack.

2026 — Admin panel and security infrastructure

59 changes.

This period focused on implementing a comprehensive admin panel for managing users, roles, permissions, and background jobs, supported by a new data-driven permission model and fine-grained authorization. It also established core security and infrastructure foundations, including AES-256-GCM encryption, S3 file storage, Hangfire job scheduling, and structured error handling with PII masking.

Features

Add Cloudflare Turnstile CAPTCHA verification

The application now integrates Cloudflare Turnstile for CAPTCHA verification during user registration and password recovery. This change introduces the infrastructure services required to validate Turnstile tokens, including configuration options for the secret key and verification endpoint, and a service that sends the token along with the client's remote IP address to Cloudflare. The system logs warnings for non-successful HTTP responses and debug information for specific error codes returned by the verification API, ensuring that invalid or failed challenges are handled gracefully.

src/backend/MyProject.Infrastructure/Features/Captcha · high confidence

Add OAuth provider selection and connected account management UI

The frontend now includes a dedicated OAuth component library that allows users to discover available identity providers, initiate login flows via provider buttons, and manage existing linked accounts. The new \OAuthProviderButtons\ component fetches available providers from the \/api/auth/external/providers\ endpoint and renders individual login buttons with loading states, while the \ConnectedAccountsCard\ component displays currently linked providers, offers disconnect functionality via a confirmation dialog, and provides a hint to set a password if no other disconnect options are available. Supporting components include \ProviderIcon\ for rendering logos for providers like Google, GitHub, Discord, Apple, Microsoft, LinkedIn, GitLab, Facebook, Slack, and Twitch, and \DisconnectDialog\ for handling the unlinking process with cooldown protection.

src/frontend/src/lib/components/oauth · high confidence

Add admin OAuth providers management page

Administrators can now view a list of configured OAuth providers via a new page at /admin/oauth-providers. The page loads provider data from the backend API and displays them in a grid using OAuthProviderCard components, showing an empty state if no providers are configured. Access is restricted to users with the admin oauthProviders permission, redirecting unauthorized users to the dashboard.

src/frontend/src/routes/(app)/admin/oauth-providers, src/frontend/src/routes/(app)/admin/roles · high confidence

Add email verification page with token-based validation

Users can now verify their email address via a dedicated page that accepts a token from the URL. The page loads the token, calls the /api/auth/email/verify endpoint, and displays a success message with a link to the dashboard or login, or an error message if the token is invalid or the verification fails.

src/frontend/src/routes/(public)/verify-email · high confidence

Add forgot password page with authenticated-user redirection

A new forgot-password route has been added to the public section of the frontend. The server-side load function checks if a user is already logged in; if so, it redirects them to the dashboard, ensuring that only unauthenticated users can access the password recovery flow. The page component renders a ForgotPasswordForm component and sets the appropriate meta title and description for SEO and accessibility.

src/frontend/src/routes/(public)/forgot-password · high confidence

A new CookieService implementation has been added to the backend infrastructure to handle cookie operations, specifically configured with SameSite=None and Secure=true to support cross-subdomain deployments where the API and frontend reside on different origins. The service provides methods to set, retrieve, and delete cookies, with a dedicated SetSecureCookie method that enforces HttpOnly flags for sensitive data, and is registered in the dependency injection container via the AddCookieServices extension.

src/backend/MyProject.Infrastructure/Cookies · high confidence

Added dynamic robots.txt and sitemap.xml endpoints for SEO

The application now serves dynamic robots.txt and sitemap.xml files to improve search engine optimization. The robots.txt file explicitly allows crawling of public content while disallowing API, admin, dashboard, profile, and settings routes. The sitemap.xml file dynamically generates an XML sitemap listing public routes (currently only the home page) with specified change frequencies and priorities, excluding utility pages like login or registration.

src/frontend/src/routes/robots.txt, src/frontend/src/routes/sitemap.xml · high confidence

Added web app manifest for PWA support

A new site.webmanifest file has been added to the static assets, defining the application name, short name, theme colors, and display mode as standalone. This enables the application to be installed as a Progressive Web App (PWA) on supported devices, providing an app-like experience with custom icons and a standalone browser window.

src/frontend/static · high confidence

Admin job detail page with execution history and management actions

A new detail view for individual scheduled jobs is now available in the admin interface. Users can view job metadata, including the cron schedule, and review the execution history. Administrators with the appropriate permissions can perform management actions on the job, such as pausing or resuming it. The page enforces role-based access control, redirecting unauthorized users to the dashboard, and includes breadcrumb navigation for context.

src/frontend/src/routes/(app)/admin/jobs/\[jobId\] · high confidence

Admin user and role management infrastructure with permission escalation guards

This change introduces the backend service layer for the admin feature, registering \AdminService\ and \RoleManagementService\ via dependency injection. It implements core administrative capabilities including user listing, role assignment, and role CRUD operations, all protected by a \PermissionEscalationGuard\ that prevents privilege escalation by ensuring callers only grant permissions they hold themselves. The implementation enforces role hierarchy, prevents self-action on critical roles, and revokes sessions on destructive actions to maintain security.

src/backend/MyProject.Infrastructure/Features/Admin · high confidence

Admin user detail page with permission-gated PII masking

A new admin user detail page has been added at the /admin/users/\[id\] route, allowing administrators to view individual user profiles and their audit trails. The page enforces role-based access control, redirecting unauthorized users to the dashboard. It features permission-gated PII masking: if the current user lacks the 'Users.ViewPii' permission, sensitive email addresses are hidden behind a masked indicator. The page loads user details and available roles in parallel, gracefully handling role-list failures by rendering the UI without role assignment options, and displays dynamic breadcrumbs based on the user's display name.

src/frontend/src/routes/(app)/admin/users/\[id\] · high confidence

Aspire-based local development environment and hardened WebApi configuration

The WebApi project is now integrated with an Aspire AppHost, enabling a unified local development stack that automatically provisions and wires up PostgreSQL, MinIO, Mailpit, and the frontend via declarative service definitions. The API itself is hardened for production: it strips development and testing configuration files from Docker artifacts, enforces HTTPS redirection and HSTS outside of development, and adds an Origin header validation middleware for CSRF defense. Additionally, the API exposes new admin capabilities through DTOs and validators for managing user creation, OAuth provider configurations, job scheduling details, and role permissions, while supporting structured logging via Serilog and OpenTelemetry.

src/backend/MyProject.WebApi · high confidence

Audit trail logging and retrieval API

This change introduces the backend infrastructure and API contracts for an append-only audit trail. The infrastructure layer adds an \AuditEvent\ entity stored in the \audit\ schema (using JSONB for metadata and no foreign-key constraints to preserve history after user deletion), registers the \IAuditService\ for logging events without disrupting main operations, and provides a service to retrieve paginated audit events for a user. The WebApi layer exposes the corresponding response DTOs (\AuditEventResponse\, \ListAuditEventsResponse\) and mapping logic to serve these audit records via the API.

src/backend/MyProject.Infrastructure/Features/Audit, src/backend/MyProject.WebApi/Features/Audit · high confidence

Authentication service overhaul with TOTP 2FA, OAuth, and permission-based JWTs

The authentication infrastructure has been significantly expanded and hardened. Users can now log in with a 'remember me' option and complete TOTP two-factor authentication flows (setup, verify, recovery codes) via the new TwoFactorService. External OAuth provider management is introduced through ExternalAuthService and ProviderConfigService, allowing database-backed, encrypted configuration and connection testing. Token security is improved with a dedicated TokenSessionService that handles refresh token rotation, reuse detection, and cookie management, while JwtTokenProvider now embeds user permissions and security stamps directly into access tokens for fine-grained authorization.

src/backend/MyProject.Infrastructure/Features/Authentication/Services · high confidence

Expanded authentication DTOs with validation and new capabilities

The authentication API now supports a comprehensive set of request and response data transfer objects, enabling users to change passwords, reset forgotten passwords, verify email addresses, and set initial passwords for OAuth accounts. External OAuth2 integration is supported via challenge, callback, and unlink endpoints, while two-factor authentication (TOTP) allows users to set up, verify, and disable 2FA using authenticator apps or recovery codes. Login requests now include a 'Remember Me' option for persistent sessions, and registration requires a Cloudflare Turnstile CAPTCHA token. All new and updated DTOs are backed by FluentValidation rules to enforce field constraints, password complexity, and format requirements at runtime.

src/backend/MyProject.WebApi/Features/Authentication/Dtos · high confidence

Expanded authentication and user profile data models

The application's authentication layer now exposes a comprehensive set of data transfer objects that support dual authentication (Bearer tokens and cookies), external OAuth2 provider integration, and two-factor authentication. Users can now manage their profiles (including avatars and contact details), change or reset passwords, and handle email verification flows. The system also introduces admin-facing DTOs for configuring external OAuth providers with database-backed, encrypted credentials, and provides detailed user output including roles, permissions, and linked provider status.

src/backend/MyProject.Application/Features/Authentication/Dtos · high confidence

Expanded authentication data models for enhanced security and user profiles

The authentication infrastructure now supports a richer set of security and user features through new and updated data models. Users can now log in with persistent sessions via the new 'remember me' functionality, which is backed by the RefreshToken model. Security is strengthened with database-backed TOTP two-factor authentication (TwoFactorChallenge), OAuth2 social login with CSRF protection (ExternalAuthState), and runtime-managed provider credentials encrypted with AES-256-GCM (ExternalProviderConfig). Password-reset and email-verification links are now anonymized using hashed tokens (EmailToken) to prevent email exposure. User profiles are extended with biography and avatar support (ApplicationUser), and the role system now supports granular permissions, system role protection, and hierarchy ranking (ApplicationRole).

src/backend/MyProject.Infrastructure/Features/Authentication/Models · high confidence

Initial SvelteKit frontend with production-ready configuration

The frontend application has been introduced as a SvelteKit project using Svelte 5, TypeScript, and Tailwind CSS. This change establishes the core development and deployment infrastructure, including a multi-stage Dockerfile for production builds and a local development container, alongside configuration for the pnpm package manager, ESLint, and Prettier. It also sets up the Content Security Policy (CSP) directives in the SvelteKit config to support Cloudflare Turnstile CAPTCHA integration and defines environment variables for the API URL, Turnstile keys, and proxy origins.

src/frontend · high confidence

Introduce Hangfire-based background job scheduling with pause support

The application now uses Hangfire with PostgreSQL for background job scheduling, replacing previous static API usage with a dependency-injection-based approach. This adds a new job infrastructure that includes an admin API for managing recurring jobs (listing, triggering, pausing, and resuming) and a development-only Hangfire dashboard at /hangfire. Three hourly cleanup jobs are now active to remove expired refresh tokens, email tokens, and two-factor challenges, preventing unbounded database growth. The system also supports pausing jobs, with the pause state persisted to the database so it survives application restarts.

src/backend/MyProject.Infrastructure/Features/Jobs · high confidence

Introduce S3-compatible file storage infrastructure

The application now supports persistent file storage via an S3-compatible backend (such as MinIO or AWS S3). This change introduces the \FileStorageOptions\ configuration model and registers the \S3FileStorageService\ implementation, which handles uploading, downloading, deleting, and existence-checking of objects. The service is configured with specific endpoint, credentials, and bucket settings, and includes logic to ensure the target bucket exists upon first use, making it compatible with both local development environments and production cloud storage.

src/backend/MyProject.Infrastructure/Features/FileStorage · high confidence

Introduce SvelteKit root layout and error handling with session-aware auth

The frontend now uses a SvelteKit-based routing structure with a root layout (+layout.svelte, +layout.ts, +layout.server.ts) and a global error page (+error.svelte). The server layout loads user session data and conditionally exposes the internal API URL only in development mode, while the client layout initializes browser authentication, theme, and health monitoring. The error page provides localized, icon-rich displays for common HTTP errors (403, 404, 429, 500, 503) and includes automatic recovery logic for 503 Service Unavailable states by polling backend health and reloading when the service returns. Tests verify that the server layout correctly determines session presence before calling getUser, ensuring robust handling of cookie mutations during token refresh.

src/frontend/src/routes · high confidence

Introduce application-layer audit logging service and event definitions

The application layer now includes a new audit feature that provides a service for recording and retrieving user activity logs. This change introduces the IAuditService interface, which allows the system to log actions (such as logins, profile updates, and admin operations) without disrupting the main operation if logging fails, and to retrieve paginated lists of these events for specific users. The feature is supported by a set of constants in AuditActions that classify events (e.g., LoginSuccess, AdminCreateUser, TwoFactorEnabled) and DTOs (AuditEventOutput, AuditEventListOutput) that define the structure of the logged data, including user IDs, action types, target entities, and metadata.

src/backend/MyProject.Application/Features/Audit · high confidence

Introduce job management API for Hangfire recurring jobs

The application now exposes an API for managing Hangfire recurring jobs, allowing administrators to query job lists and details, trigger immediate executions, remove jobs, and pause or resume schedules. This change introduces the \IJobManagementService\ interface and associated DTOs (\JobExecutionOutput\, \RecurringJobOutput\, \RecurringJobDetailOutput\) within the \Features/Jobs\ layer to support these operations, including a \RestoreJobsAsync\ method to re-register definitions while preserving pause states.

src/backend/MyProject.Application/Features/Jobs · high confidence

Introduce templated email infrastructure for transactional notifications

This change adds the core application-layer components for sending transactional emails using a Liquid-based template system. It introduces the \EmailMessage\ record for message structure, interfaces for rendering templates (\IEmailTemplateRenderer\) and sending them safely (\ITemplatedEmailSender\), and a set of constants (\EmailTemplateNames\) defining specific templates such as email verification, password reset, user invitations, and admin-initiated two-factor authentication disablement. Additionally, it defines the corresponding data models (e.g., \VerifyEmailModel\, \ResetPasswordModel\) that bind context data like URLs and expiration times into these templates, enabling consistent and maintainable email content generation across the application.

src/backend/MyProject.Application/Features/Email · high confidence

Introduces AES-256-GCM encryption and SHA-256 hashing utilities

The cryptography infrastructure now includes an AES-256-GCM encryption service for securely storing sensitive configuration data, deriving keys via HKDF-SHA256, and a SHA-256 hashing helper for generating secure token hashes. These changes enable robust encryption for provider configurations and secure storage of refresh tokens.

src/backend/MyProject.Infrastructure/Cryptography · high confidence

Introduces a data-driven permission and role model with hierarchy and wildcard support

The application now uses a centralized, reflection-based system for managing authorization. New files define atomic permission claims (e.g., \users.view\, \jobs.manage\) grouped by category, and declarative role definitions (\User\, \Admin\, \Superuser\) that include hierarchy ranks and default permission sets. The \Superuser\ role is granted a wildcard permission (\\*\) for full access, while \Admin\ and \User\ roles have specific, limited permissions. This structure replaces hardcoded role/permission logic with a seeded, database-backed model that supports fine-grained authorization and role hierarchy enforcement.

src/backend/MyProject.Application/Identity/Constants · high confidence

Introduction of CAPTCHA validation service interface

A new ICaptchaService interface has been added to the application layer, defining a contract for validating CAPTCHA tokens submitted by the frontend. This interface introduces a ValidateTokenAsync method that accepts a token string and returns a boolean indicating validity, laying the groundwork for integrating CAPTCHA verification into user-facing flows such as registration and password recovery.

src/backend/MyProject.Application/Features/Captcha · high confidence

The application layer now defines explicit constants for JWT authentication cookies (access and refresh tokens) using the \_\_Secure- prefix to enforce security attributes, and introduces an ICookieService interface to standardize how cookies are set, retrieved, and deleted across the WebApi and Infrastructure layers.

src/backend/MyProject.Application/Cookies · high confidence

Introduction of user context and service infrastructure for identity management

The application now includes a new identity infrastructure layer that registers and implements core user context services. This change adds a DI extension method to register IUserContext and IUserService, alongside a UserContext implementation that extracts user identity details (such as UserId, Email, and UserName) from HTTP context claims. It also introduces role checking and permission evaluation capabilities via IsInRole and HasPermission methods, laying the groundwork for the permission-based authorization system mentioned in the commit history.

src/backend/MyProject.Infrastructure/Identity · high confidence

New Admin API endpoints for user, role, job, and OAuth management

The WebApi layer now exposes a comprehensive set of administrative endpoints under the Admin feature, enabling administrators to manage users (list, view, assign/remove roles, lock accounts, disable 2FA), roles (create, update, set permissions, view details), background jobs (list, trigger, pause, resume, remove, restore), and OAuth provider configurations (list, update, test connection). These endpoints are protected by permission-based authorization, enforce role hierarchy and self-action protections, and include PII masking for user data based on caller permissions. Rate limiting is applied to all mutation endpoints to prevent abuse.

src/backend/MyProject.WebApi/Features/Admin · high confidence

New Admin Jobs page with restore functionality

A new admin page at /admin/jobs has been added, allowing users with the Jobs.Manage permission to view a list of jobs and trigger a restore operation. The page includes a confirmation dialog for the restore action, which calls the /api/v1/admin/jobs/restore endpoint, and implements a cooldown timer on the button to prevent rapid repeated submissions. The UI displays a loading state during the restore process and provides success or error feedback via toast notifications.

src/frontend/src/routes/(app)/admin/jobs · high confidence

New Admin Service Interfaces for User and Role Management

The application introduces two new service interfaces, IAdminService and IRoleManagementService, within the Admin feature layer to standardize administrative operations. IAdminService provides methods for managing user accounts—including listing, creating, locking, unlocking, deleting, verifying email, resetting passwords, and disabling two-factor authentication—while enforcing a strict role hierarchy where the caller must have a higher rank than the target user and cannot perform self-modifying actions like locking or deleting their own account. IRoleManagementService exposes CRUD operations for custom roles and permission assignment, explicitly protecting system roles (Superuser, Admin, User) from deletion or renaming and preventing privilege escalation by ensuring callers cannot grant permissions they do not hold.

src/backend/MyProject.Application/Features/Admin · high confidence

New UserService implementation with HybridCache and avatar upload support

The identity service layer now uses a new UserService implementation that integrates HybridCache for user data retrieval and supports avatar uploads via file storage. This change introduces caching for user profile lookups, invalidates the cache on profile updates, and adds functionality for processing and storing user avatars, replacing previous URL-based avatar handling.

src/backend/MyProject.Infrastructure/Identity/Services · high confidence

New admin API data models for user and role management

This change introduces a comprehensive set of Data Transfer Objects (DTOs) in the application layer to support the new admin capabilities for managing users and roles. For user management, the system now exposes detailed user profiles (including 2FA status, lockout details, and avatar presence) via \AdminUserOutput\, paginated lists via \AdminUserListOutput\, and inputs for creating users (\CreateUserInput\) and assigning roles (\AssignRoleInput\). For role management, administrators can now create (\CreateRoleInput\), update (\UpdateRoleInput\), and modify permissions (\SetRolePermissionsInput\) for roles. The system also exposes role details (\RoleDetailOutput\, \AdminRoleOutput\) including hierarchy ranks, system protection flags, and permission grants, along with grouped permission categories (\PermissionGroupOutput\) to facilitate the new permission-based authorization UI.

src/backend/MyProject.Application/Features/Admin/Dtos · high confidence

New admin management interfaces for users, roles, jobs, and audit trails

The admin panel now includes dedicated UI components for managing core system entities. Administrators can manage user accounts (lock/unlock, delete, send password resets, verify emails, disable 2FA) and view PII-masked details. Role management allows creating, editing, and deleting roles, with a grid view that groups and displays permissions. A new Hangfire job scheduler UI lets admins trigger, pause, resume, and delete background jobs, and view their execution history. Additionally, a full audit trail component displays a timeline of user activity with detailed event metadata.

src/frontend/src/lib/components/admin · high confidence

New admin users management page with permission-gated access and PII masking

A new admin users management interface has been added, allowing administrators to view, search, and paginate through user lists. Access to this page is restricted by role-based permissions, redirecting unauthorized users to the dashboard. The interface supports searching users and paginating results. Additionally, personally identifiable information (PII) in the user table is masked for users who do not have the specific 'ViewPii' permission, while those with 'Manage' permissions can invite new users via a dialog.

src/frontend/src/routes/(app)/admin/users · high confidence

New authentication service interfaces for login, 2FA, and OAuth

The application now exposes a comprehensive set of authentication capabilities through new service interfaces in the application layer. Users can log in with standard credentials or via external OAuth providers, with support for persistent 'remember me' cookies and dual authentication modes (stateless tokens or HTTP cookies). The system introduces TOTP-based two-factor authentication, including setup, verification, and recovery code management. Additionally, account lifecycle features such as registration, password changes, password resets, and email verification are now defined, along with administrative capabilities to manage and test OAuth provider configurations stored in the database.

src/backend/MyProject.Application/Features/Authentication · high confidence

New common UI component library

The frontend now includes a new set of reusable UI components in the common library, providing consistent patterns for displaying empty states, field validation errors, loading spinners, page headers, status indicators, and work-in-progress notices. These components standardize the visual language across the application, ensuring uniform styling for icons, alerts, and status messages while reducing duplication in individual page implementations.

src/frontend/src/lib/components/common · high confidence

New configurable options for hosting, rate limiting, and CORS

This change introduces new configuration classes in the WebApi project to allow fine-tuning of deployment and security settings. HostingOptions enables control over HTTPS enforcement and trusted reverse proxy networks for accurate client IP detection. RateLimitingOptions adds a comprehensive, config-driven rate limiting system with distinct policies for global traffic, registration, authentication, sensitive operations, and admin mutations, each supporting custom permit limits, time windows, and queue behaviors. Additionally, the existing CorsOptions class has been sealed and documented to clarify its role in managing cross-origin request policies.

src/backend/MyProject.WebApi/Options · high confidence

New dashboard page with user-specific widgets

A new dashboard page has been added that displays a personalized greeting based on the logged-in user's first name and includes four main widget components: WelcomeGuide, DeveloperGuide, QuickActions, and AccountStatus. The page also sets appropriate meta title and description for SEO purposes.

src/frontend/src/routes/(app)/dashboard · high confidence

New dashboard widget components for account status, quick actions, and guides

The dashboard now includes four new Svelte components that provide users with immediate visibility into their account state and easy access to key areas. The AccountStatus widget displays the completion status of the user profile, email verification, two-factor authentication, and assigned roles. QuickActions offers direct navigation links to the Profile, Settings, and (for administrators) the Admin panel, with the admin link conditionally shown based on user permissions. A WelcomeGuide component highlights these core areas, while a collapsible DeveloperGuide provides instructions for customizing the dashboard and adding new features. These components are exported via a new index.ts barrel file for easy integration.

src/frontend/src/lib/components/dashboard · high confidence

New dedicated page for editing individual role details and permissions

The admin interface now includes a specific route for managing a single role's configuration. This page loads the role's current data alongside the full list of available permissions, allowing administrators to edit the role name and description, toggle specific permission groups, and delete the role (if it is not a system role and has no assigned users). Access is restricted to users with the 'Manage Roles' permission, and the UI adapts to hide editing controls for system roles or when permission data fails to load.

src/frontend/src/routes/(app)/admin/roles/\[id\] · high confidence

New external OAuth/OIDC authentication providers added

The authentication infrastructure now supports logging in via Apple, Discord, Facebook, GitHub, GitLab, Google, and LinkedIn. This location introduces the specific provider implementations and the shared \ExternalUserInfo\ record, enabling users to authenticate with these services using their existing accounts.

src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders · high confidence

New frontend health check endpoint

A new health check route has been added to the frontend application at /api/health. This endpoint proxies the health status from the configured backend API. If the backend is reachable, the frontend returns its status and content type; if the backend is unreachable, the frontend returns a 503 Service Unavailable status with an 'Offline' message, allowing external monitoring tools to verify the frontend's connectivity to the backend.

src/frontend/src/routes/api/health · high confidence

New frontend state management utilities and hooks

The \src/frontend/src/lib/state\ directory now provides a suite of new reactive state modules for the Svelte frontend. This includes \health.svelte.ts\ for global API health polling with adaptive intervals, \cooldown.svelte.ts\ for rate-limit timers, \shortcuts.svelte.ts\ for keyboard shortcuts (including a command palette), \theme.svelte.ts\ for light/dark/system theme switching, \shake.svelte.ts\ for error animations, \breadcrumb.svelte.ts\ for dynamic labels, and \is-mobile.svelte.ts\ for breakpoint detection. A corresponding test file \health.test.ts\ has been added to verify the health state logic.

src/frontend/src/lib/state · high confidence

New frontend utility modules for permissions, roles, audit, and OAuth

The frontend now includes a suite of new client-side utility modules in src/frontend/src/lib/utils to support recent feature additions. The permissions module introduces a data-driven role model with wildcard support, allowing users to check specific or any permissions (e.g., users.view, users.manage) against their profile. The roles module implements a hierarchy enforcement system, ensuring that users can only manage accounts if their role rank is strictly higher than the target's. The audit module provides a full-stack audit trail UI, mapping backend actions (like login, role assignment, or 2FA changes) to localized labels and visual variants (success, warning, destructive). The OAuth module handles the login flow by initiating challenges and redirecting users to providers, while the jobs module formats Hangfire job statuses and durations for the admin UI. Additionally, a crop utility enables avatar image processing, and platform detection utilities support device-specific UI logic.

src/frontend/src/lib/utils · high confidence

New layout components with command palette, breadcrumbs, and admin RBAC

The layout area now includes a new AppSidebar that filters admin navigation items (Users, Roles, Jobs, OAuth Providers) based on user permissions, a CommandPalette for keyboard-driven navigation and actions (including theme toggling and logout), a ContentHeader that renders dynamic breadcrumbs for admin detail pages, and supporting UI components (Header, LanguageSelector, ThemeToggle, UserNav, ShortcutsHelp) that integrate with the new Paraglide i18n system and shortcut state.

src/frontend/src/lib/components/layout · high confidence

New login and registration pages with session-aware redirects and feedback

The application now includes dedicated login and registration routes. On the login page, users who are already authenticated are automatically redirected to the dashboard. The login flow also supports a 'reason' query parameter to display specific user feedback: a 'session\_expired' reason triggers an error toast, while a 'password\_changed' reason triggers a success toast, and an optional 'email' parameter pre-fills the login form. The registration page similarly redirects authenticated users to the dashboard. Both pages are implemented using SvelteKit server loads and Svelte components, with tests verifying the redirect logic and parameter handling for the login page.

src/frontend/src/routes/(public)/login · high confidence

New profile management interface with avatar upload and account details

The profile section now features a comprehensive set of components for managing user identity. Users can view their account details, including user ID and assigned roles, via the AccountDetails component. The ProfileForm allows editing of personal information (first name, last name, phone number, and bio) with real-time field-level validation errors and shake animations. A significant addition is the AvatarDialog, which enables users to upload, crop, and zoom new profile pictures from their device, supporting drag-and-drop and file selection, with cooldown protection against rate limits. The ProfileHeader displays the current avatar with cache-busting to ensure updates are reflected immediately, showing initials as a fallback.

src/frontend/src/lib/components/profile · high confidence

New profile page layout with two-column grid

A new profile page has been added that displays the user's profile form and account details side-by-side on large screens using a two-column grid layout, while stacking vertically on smaller screens. The page uses Paraglide JS for internationalized titles and descriptions.

src/frontend/src/routes/(app)/profile · high confidence

New settings components for account security and activity

The settings area now includes dedicated UI components for managing account security and visibility. Users can change or set their password via ChangePasswordForm and SetPasswordForm, enable or disable TOTP two-factor authentication through TwoFactorCard and its setup/disable dialogs, and review their login history in the new ActivityLog component. A DeleteAccountDialog is also provided for account removal.

src/frontend/src/lib/components/settings · high confidence

New shadcn/ui component library added to the frontend

The frontend now includes a comprehensive set of UI components sourced from shadcn/ui, providing a consistent design system for building interfaces. This addition introduces ready-to-use primitives for common patterns such as dialogs, alerts, avatars, badges, breadcrumbs, buttons, cards, checkboxes, command palettes, dropdown menus, and more. These components are built on top of bits-ui and Tailwind CSS, ensuring accessibility and customization while reducing the need to reinvent standard UI elements.

src/frontend/src/lib/components/ui · high confidence

New unified settings page with account management and security controls

A new settings page has been introduced at the application's settings route, consolidating account management and security features into a single interface. Users can now manage their password status (setting a new password or changing an existing one), configure two-factor authentication via TOTP, and view or manage connected OAuth accounts. The page also includes an activity log for auditing and a dedicated danger zone section that allows users to initiate account deletion through a confirmation dialog.

src/frontend/src/routes/(app)/settings · high confidence

New user profile management endpoints with avatar and account deletion

The Users API now exposes a comprehensive set of endpoints for managing authenticated user profiles. Users can retrieve their current information, update profile details, and manage avatars via upload, removal, and retrieval endpoints (with images resized to 512x512 and stored as WebP). A new account deletion endpoint allows users to permanently remove their accounts with password confirmation, revoking all tokens and clearing auth cookies. Additionally, users can view their personal audit activity log. These changes introduce new response DTOs and a mapper to translate application-layer user data into API responses.

src/backend/MyProject.WebApi/Features/Users · high confidence

New user profile update API and enriched user response model

The API now supports updating user profile details (first name, last name, phone number, and bio) via a new UpdateUserRequest DTO, which includes validation rules for phone number formatting and field lengths. Additionally, the UserResponse model has been expanded to expose comprehensive account status information, including avatar presence, assigned roles, atomic permissions, email confirmation status, two-factor authentication status, linked OAuth providers, and password existence.

src/backend/MyProject.WebApi/Features/Users/Dtos · high confidence

OpenAPI documentation and interactive API reference setup

The API now registers a comprehensive OpenAPI v1 specification using custom transformers to refine document structure, operation details, and schema definitions (including support for ProblemDetails and enums). Additionally, the Scalar interactive API reference UI is mapped to the application, configured with the 'Mars' theme, C\# HttpClient as the default client, and specific UI behaviors like alphabetical tag sorting and a 'k' search hotkey.

src/backend/MyProject.WebApi/Features/OpenApi/Extensions · high confidence

Replaces legacy AI agent guidelines with structured Claude Code orchestration and Playwright integration

The project's AI development workflow has been modernized by removing the generic \AGENTS.md\ and \docker-compose.local.yml\ files and introducing a dedicated Claude Code setup. This includes a new \CLAUDE.md\ that defines a strict delegation model with specialized agents (backend, frontend, security, etc.) and automated verification loops, alongside a \.mcp.json\ file that configures the Playwright MCP server for browser-based UI verification. The \FILEMAP.md\ provides a comprehensive change-impact reference to ensure cross-stack consistency, while standard repository governance files (Code of Conduct, Contributing, Security, License) are added to support open-source collaboration.

(repo-wide) · high confidence

Reset password page now supports admin invitation flows

The reset password page now handles both standard password resets and admin-sent invitations. It detects an invitation context via a URL parameter and adjusts the page title and meta description accordingly. The page no longer redirects authenticated users away, allowing them to complete the invitation flow even if they are already signed in.

src/frontend/src/routes/(public)/reset-password · high confidence

Standardized cache keys and secret encryption service introduced

The application now provides a centralized factory for generating standardized cache keys (e.g., for user profiles, security stamps, and provider configurations) to improve cache consistency. Additionally, a new secret encryption service interface has been added, utilizing AES-256-GCM to securely encrypt and decrypt sensitive data such as OAuth client credentials at rest.

src/backend/MyProject.Application/Caching · high confidence

Transactional email delivery with Liquid templates and background jobs

The application now sends transactional emails (password resets, email verification, account invitations, and admin notifications) using Liquid templates rendered by the Fluid engine. Delivery is configurable: when both email and job scheduling are enabled, emails are queued as Hangfire background jobs with automatic SMTP retries; otherwise, they are sent inline via SMTP or logged only in development.

src/backend/MyProject.Infrastructure/Features/Email · high confidence

User avatars can now be uploaded as files and are stored in S3

Users can upload avatar images via a file upload mechanism instead of providing a URL. The system validates the file (max 5 MB, JPEG/PNG/WebP/GIF), processes it into a normalized WebP format using SkiaSharp, and stores the result in an S3-compatible object store via the new file storage service.

(repo-wide) · high confidence

Removals

Removal of initial authentication and infrastructure scaffolding

The entire initial implementation of the application has been removed, including the authentication feature (controllers, services, DTOs, and models), the persistence layer (DbContext, UnitOfWork, and migrations), and the WebApi entry point (Program.cs, Dockerfile, and configuration files). This deletes the ability to register, log in, or manage users via cookie-based JWT authentication, removes the database context and transaction management, and eliminates the API server startup logic, rate limiting, and OpenAPI documentation setup.

(repo-wide) · high confidence

Architecture

Centralized type aliases for frontend API models

A new shared types module has been introduced in the frontend library to reduce repetition by creating explicit type aliases for common API response schemas. This file maps internal frontend types (such as User, AdminUser, AdminRole, PermissionGroup, AuditEvent, Job, JobDetail, JobExecution, and OAuthProviderConfig) directly to their corresponding OpenAPI component definitions, ensuring consistent typing across components that consume these API responses.

src/frontend/src/lib/types · high confidence

Behavioural changes

API proxy hardening with CSRF protection and header filtering

The frontend API proxy route now validates request origins to prevent cross-site request forgery on state-changing methods, forwards only a strict allowlist of request headers while stripping sensitive response headers, and buffers request bodies to ensure proper 401 error handling instead of network errors.

src/frontend/src/routes/api/\[...path\] · high confidence

Account deletion and permission-based authorization

Users can now permanently delete their own accounts via a new endpoint that requires password confirmation, with the backend revoking all tokens and clearing auth cookies upon success. Additionally, the system has shifted to a permission-based authorization model where access is determined by specific permission claims (including a wildcard for superusers) rather than role names, providing a more granular control over user capabilities.

src/backend/MyProject.Application/Identity · high confidence

Admin API request validation and data contracts

The Admin API now enforces strict validation on role assignment and user listing requests. Assigning a role requires a non-empty role name (max 50 characters), while listing users supports optional search filtering (max 200 characters) with enforced pagination constraints (page number \>= 1, page size 1-100). New DTOs define the request/response structures for these admin operations.

src/backend/MyProject.WebApi/Features/Admin/Dtos/AssignRole, src/backend/MyProject.WebApi/Features/Admin/Dtos/ListUsers · high confidence

Admin area access now requires specific permissions

Access to the admin section is now gated by a server-side layout guard that checks for specific permissions (users.view, roles.view, jobs.view, or oauth\_providers.view). Users without at least one of these permissions are automatically redirected to the dashboard, while those with wildcard permissions (Superuser) or any single admin permission retain access.

src/frontend/src/routes/(app)/admin · high confidence

Authentication API restructured into dedicated feature controllers

The authentication endpoints have been reorganized from a single monolithic controller into a set of specialized controllers under the \api/auth\ route prefix to improve clarity and maintainability. The new structure includes \AuthController\ for core login, registration, and token management; \PasswordController\ for forgot/reset/change password flows; \TwoFactorController\ for TOTP setup and verification; \ExternalAuthController\ for OAuth2 provider interactions; and \EmailVerificationController\ for email confirmation. This change also introduces dual authentication support, allowing clients to choose between Bearer tokens and HttpOnly cookies via a \useCookies\ query parameter, and enforces per-endpoint rate limiting across all authentication operations.

src/backend/MyProject.WebApi/Features/Authentication · high confidence

Automated development environment checks and safety hooks

New hooks in .claude/hooks enforce safer and more consistent development workflows: session-start.mjs verifies prerequisites (.NET SDK, pnpm, dotnet-ef, Docker) at the beginning of a session; auto-format.mjs automatically formats backend C\# files with dotnet format and frontend files with Prettier after edits; validate-bash.mjs blocks dangerous shell commands such as force pushes, destructive rm -rf, and piping remote scripts to the shell; and stop-quality-gate.mjs prevents the session from ending with uncommitted changes in src/, prompting a commit or explaining why changes are left uncommitted.

.claude/hooks · high confidence

Automatic auditing and user cache invalidation on data changes

The persistence layer now automatically tracks entity lifecycle changes and manages caching consistency without manual intervention. An AuditingInterceptor is applied to all entities inheriting from BaseEntity, automatically setting CreatedAt, CreatedBy, UpdatedAt, UpdatedBy, and soft-delete fields (DeletedAt, DeletedBy) based on the current user context and time. Additionally, a UserCacheInvalidationInterceptor detects modifications to users or their roles and automatically invalidates the corresponding user cache entries via HybridCache after the changes are saved, ensuring data consistency.

src/backend/MyProject.Infrastructure/Persistence/Interceptors · high confidence

Backend project structure reorganization and new tooling files

The backend directory has been restructured to include new configuration and tooling files: a .dockerignore file to exclude unnecessary artifacts from Docker builds, an .editorconfig enforcing C\# interface naming conventions, and a nuget.config specifying explicit package sources. A new HealthProbe tool has been added to check service health endpoints, and the solution file (MyProject.slnx) now explicitly references multiple project layers (Application, Domain, Infrastructure, Shared, WebApi, ServiceDefaults, AppHost) along with test projects. The Directory.Build.props file has been moved and simplified to define common build properties like target framework and nullable/implicit usings settings.

src/backend · high confidence

BaseEntity now tracks user audit fields and simplifies soft-delete/restore

The BaseEntity in the domain layer now includes Guid? properties for CreatedBy, UpdatedBy, and DeletedBy to record which user performed each action. The SoftDelete and Restore methods no longer accept explicit DateTime arguments; timestamps are no longer set by these methods, and Restore also clears the DeletedBy field.

src/backend/MyProject.Domain · high confidence

CSRF defense and standardized error responses

The API now includes an OriginValidationMiddleware that blocks cross-origin state-changing requests (POST, PUT, PATCH, DELETE) unless the Origin header matches the configured allowed origins, providing defense-in-depth against CSRF attacks. Additionally, the ExceptionHandlingMiddleware has been refactored to return standardized ProblemDetails responses instead of custom JSON error objects, ensuring consistent error formatting across the application while still exposing stack traces in development environments.

src/backend/MyProject.WebApi/Middlewares · high confidence

Centralized app layout with session-aware auth and backend health handling

The (app) route now uses a dedicated server-side layout to enforce authentication and handle backend availability before rendering any protected pages. If the backend is unavailable, users see a 503 error instead of being redirected to login. For unauthenticated users, the system distinguishes between fresh visitors (who are sent to a clean login page) and those with an expired session (who are redirected to /login?reason=session\_expired), preventing confusing error messages for long-expired cookies. Additionally, the layout persists sidebar state via cookies to avoid visual flashes on load, automatically re-runs server loads when backend health polling detects an outage, and displays an email verification banner for users who haven't confirmed their email address.

src/frontend/src/routes/(app) · high confidence

Centralized route configuration and server-side environment validation

The application now manages navigation paths and access control through a centralized configuration in src/frontend/src/lib/config. Route paths (such as dashboard, login, and profile) are defined as constants to prevent hardcoding, while admin routes are explicitly paired with RBAC permissions to ensure consistent access control across guards and UI components. Additionally, server-side configuration has been introduced to validate the API URL at startup and support configurable allowed origins for proxy CSRF checks, improving reliability and security for cross-origin requests.

src/frontend/src/lib/config · high confidence

Database initialization, role seeding, and PostgreSQL query hardening

The persistence layer now includes a new \ApplicationBuilderExtensions\ that handles startup database initialization, including applying migrations in development, and robustly seeding roles and users from environment variables. Role seeding has been hardened to validate hierarchy invariants, update metadata drift without overwriting operator-edited descriptions, and rotate security stamps when a role gains wildcard permissions to invalidate stale tokens. The PostgreSQL configuration now enables retry-on-failure and logs command errors as warnings, while new interceptors handle auditing and user cache invalidation. Additionally, string escaping for SQL LIKE queries has switched from bracket-based to backslash-based escaping to correctly support PostgreSQL wildcards, and pagination error messages now reference centralized error constants.

src/backend/MyProject.Infrastructure/Persistence/Extensions · high confidence

Enhanced authentication security and external provider support

This update introduces several security and capability improvements to the authentication system. Account lockout is now enforced after five failed attempts to mitigate brute-force attacks. JWT token validation has been hardened to verify the security stamp against the database (cached via HybridCache), ensuring tokens are invalidated upon password changes or role updates. The system now supports dual authentication via Bearer headers and HttpOnly cookies. Additionally, the infrastructure registers services for two-factor authentication, email verification, and external OAuth providers including Google, GitHub, Discord, Apple, Microsoft, LinkedIn, GitLab, Facebook, Slack, and Twitch, with provider configurations encrypted using AES-256-GCM.

src/backend/MyProject.Infrastructure/Features/Authentication/Extensions · high confidence

Frontend security headers and safe-area viewport support

The frontend now applies security headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy) to all page responses while skipping them for API proxy routes (/api/\*) where the backend handles them. In production, Strict-Transport-Security (HSTS) is also added. The HTML template includes viewport-fit=cover and safe-area insets to improve layout on devices with notches or dynamic islands.

src/frontend/src · high confidence

Global soft-delete filtering and standardized error handling in persistence layer

The persistence layer now automatically excludes soft-deleted entities from all database queries via a global query filter defined in BaseEntityConfiguration, removing the need for manual filtering in repository methods. To support operations like restoring deleted items, the repository explicitly ignores these filters when necessary. Additionally, the repository implementation has been refactored to use centralized error message constants instead of inline strings and relies on injected logging rather than a TimeProvider for timestamping soft-delete and restore actions.

src/backend/MyProject.Infrastructure/Persistence · high confidence

Introduction of permission-based authorization with standardized error responses

The API now supports fine-grained, permission-based access control (e.g., 'users.view') via the new RequirePermission attribute, replacing or supplementing previous role-based checks. This system dynamically resolves policies and validates permissions against user claims. Additionally, unauthorized (401) and forbidden (403) responses now return structured ProblemDetails JSON bodies, ensuring consistency with the OpenAPI specification and providing clear error messages to clients instead of empty responses.

src/backend/MyProject.WebApi/Authorization · high confidence

Logging infrastructure reorganized and documented

The logging configuration code has been moved from the root infrastructure folder into the backend-specific logging module. The logger extension methods have been updated with comprehensive XML documentation, clarifying the distinction between the minimal bootstrap logger used during early startup and the full Serilog setup, while noting that OTLP log export is handled by ServiceDefaults rather than a separate sink.

src/backend/MyProject.Infrastructure/Logging · high confidence

New CachingOptions configuration with validation and master switch

A new CachingOptions class has been introduced to manage caching behavior via the 'Caching' configuration section. It includes a master Enabled switch (defaulting to true) that allows users to disable caching entirely, registering a no-op implementation when false. The configuration also exposes a DefaultExpiration setting (defaulting to 10 minutes) which is now validated to ensure it is greater than zero, preventing invalid cache entry lifetimes.

src/backend/MyProject.Infrastructure/Caching/Options · high confidence

New account deletion request validation

The system now enforces specific validation rules for the account deletion request, requiring the user's password to be between 6 and 255 characters long. This ensures that account deletion is confirmed with a valid password that meets the application's security standards.

src/backend/MyProject.WebApi/Features/Users/Dtos/DeleteAccount · high confidence

New health checks, rate limiting, security headers, and hosting configuration

The backend now exposes dedicated health check endpoints (/health, /health/ready, /health/live) that verify PostgreSQL connectivity and optionally degrade gracefully if S3 storage is unreachable. Rate limiting is enforced via fixed-window policies partitioned by IP or authenticated user, with specific per-endpoint limits for registration and authentication, returning standard ProblemDetails on rejection. Security response headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy) are added to all API responses to mitigate common browser-side attacks. Hosting infrastructure is hardened by trusting configured reverse proxy networks for forwarded headers and optionally forcing HTTPS, while CORS configuration now explicitly rejects 'AllowAllOrigins' in non-development environments to prevent credential-leaking misconfigurations.

src/backend/MyProject.WebApi/Extensions · high confidence

New route constraints for job IDs, provider names, and role names

The API now enforces stricter validation on URL route parameters through three new route constraints. Job identifiers are restricted to alphanumeric characters, dots, hyphens, and underscores with a maximum length of 100 characters. OAuth provider names must consist solely of letters and cannot exceed 32 characters. Role names must start with a letter, followed by letters, digits, hyphens, or underscores, with a maximum length of 50 characters, aligning with existing request validators.

src/backend/MyProject.WebApi/Routing · high confidence

OAuth callback handling with error display and account linking support

The OAuth callback route now processes authentication responses from external providers, handling success by redirecting to the dashboard, managing account linking flows by redirecting to settings, and displaying user-friendly error messages for issues like provider denial, missing parameters, or backend API errors.

src/frontend/src/routes/(public)/oauth · high confidence

OpenAPI specification generation and accuracy improvements

This change introduces a suite of OpenAPI document transformers to enhance the accuracy and consistency of the generated API specification. The BearerSecurityOperationTransformer now correctly applies bearerAuth security requirements to endpoints protected by AuthorizeAttribute, including inherited attributes. The CamelCaseQueryParameterTransformer ensures query parameters are camelCase to match JSON serialization and propagates schema descriptions to parameters. The CleanupDocumentTransformer removes redundant content types and strips response bodies from HEAD operations for RFC compliance. The EnumSchemaTransformer ensures enums are represented as string enums with all members listed, while the NumericSchemaTransformer fixes numeric types that were incorrectly flagged as strings. Additionally, the ProblemDetailsSchemaTransformer documents the machine-readable error code extension, and the ProjectDocumentTransformer sets the API metadata and describes the dual authentication support (Bearer tokens and cookies).

src/backend/MyProject.WebApi/Features/OpenApi/Transformers · high confidence

Redesigned authentication UI with two-factor and CAPTCHA support

The authentication interface has been completely rebuilt using a new \AuthShell\ layout component that provides a consistent branded frame for all auth flows. This update introduces a full two-factor authentication (2FA) experience, including a dedicated step for entering TOTP codes or recovery codes, and integrates Cloudflare Turnstile CAPTCHA into the registration and forgot-password forms to prevent abuse. The login form now supports a 'remember me' option and handles 2FA challenges seamlessly, while the registration flow includes draft saving to local storage and OAuth provider buttons. Additionally, the email verification process is improved with a dismissable banner that allows users to request a new verification email with a cooldown timer.

src/frontend/src/lib/components/auth · high confidence

Redesigned visual theme and modularized frontend styling architecture

The frontend styling system has been restructured into a modular architecture (base, animations, themes, utilities) and features a completely redesigned color palette optimized for comfortable light and dark modes. The new theme uses a warm stone-neutral base with slate-blue accents, replacing previous harsh contrasts with softer tones for extended use. This update introduces new visual capabilities, including ambient glow effects for panels, interactive card hover states, and subtle dot-grid patterns, alongside specific animation utilities for authentication transitions, OTP input cursors, and status indicators. Accessibility is maintained through respect for reduced-motion preferences across all new animations and transitions.

src/frontend/src/styles · high confidence

Refined database schema and configuration for authentication entities

The authentication infrastructure's database mapping has been updated to support more granular role management, secure external provider storage, and enhanced session handling. New EF Core configurations define the structure for roles (including system flags and permission grants), email verification tokens, and OAuth external auth states. Refresh token handling has been improved by removing the unused JWT ID column, adding a 'Persistent' flag for remember-me functionality, and indexing the UserId for faster lookups. Additionally, a new configuration for encrypted external provider credentials enables database-backed OAuth setup, while two-factor challenge tokens are now explicitly tracked with expiration and usage indices.

src/backend/MyProject.Infrastructure/Features/Authentication/Configurations · high confidence

Repository interface moved to backend and updated dependencies

The IBaseEntityRepository interface has been relocated from the root src directory to the src/backend/MyProject.Application/Persistence folder. Additionally, the interface's dependencies were adjusted to remove the direct reference to the MyProject.Domain namespace in favor of MyProject.Domain.Entities and MyProject.Shared, and a reference to the backend-conventions skill documentation was added to the remarks.

src/backend/MyProject.Application/Persistence · high confidence

Standardized API error handling and backend availability monitoring

The frontend API layer now uses a unified error-handling system based on RFC 9457 ProblemDetails, replacing ad-hoc error parsing. This introduces a typed \browserClient\ (via openapi-fetch) with middleware support, a \backend-monitor\ that detects 502/503 responses to trigger a global offline state, and a \handleMutationError\ utility that standardizes user feedback for rate limits (429 with Retry-After cooldowns), validation errors (422 with field mapping), and generic failures. Machine-readable error codes are extracted for translation, and auto-generated OpenAPI types (\v1.d.ts\) ensure type safety for API responses.

src/frontend/src/lib/api · high confidence

Standardized error responses and hardened API validation

The API now provides consistent, machine-readable error codes in all ProblemDetails responses via the new ProblemFactory, ensuring clients can reliably handle errors without parsing human-readable text. Additionally, pagination request parameters are now strictly validated with range constraints (PageNumber ≥ 1, PageSize between 1 and 100), and response properties are made immutable using init-only setters to prevent accidental mutation. Shared constants for rate limiting policies and phone number validation have also been introduced to enforce stricter security controls.

src/backend/MyProject.WebApi/Shared · high confidence

Strict security permissions and automated guardrails for Claude Code

The project now enforces a deny-by-default security model for the Claude Code agent, explicitly blocking access to sensitive files (such as .env, .pem, and .key files) and dangerous operations (including force pushes, privileged Docker runs, and secret API mutations). To support safe development, the setup includes lifecycle hooks that automatically check prerequisites on startup, validate bash commands to prevent destructive actions, and auto-format code after edits. Additionally, the configuration registers official LSP plugins and vendor skill packs from Microsoft and Svelte, while providing a local settings example for users to customize permissions without modifying the core security rules.

.claude · high confidence

Structured authentication configuration with validation

The application now uses strongly-typed, sealed configuration classes (AuthenticationOptions, ExternalAuthOptions) to manage JWT, refresh token, TOTP, and OAuth settings. These options enforce strict validation rules at startup, including a minimum 64-character JWT signing key, bounded lifetimes for access and refresh tokens, and safe URI schemes for OAuth redirects. External provider credentials are now managed via the database rather than appsettings, with encryption keys protected by HKDF-SHA256.

src/backend/MyProject.Infrastructure/Features/Authentication/Options · high confidence

Structured error handling with machine-readable codes and PII masking

The shared backend layer now enforces structured error responses and data privacy. Error handling has shifted from plain text messages to a typed system using the \Error\ record (containing a stable, snake\_case \Code\ and \Message\) and the \ErrorType\ enum (mapping failures to HTTP status codes like 400, 401, 403, 404). The \Result\ type has been refactored to carry these structured errors, ensuring clients can branch on stable codes rather than parsing English text. Additionally, a new \PiiMasker\ utility is provided to mask personally identifiable information (such as email addresses and phone numbers) before it is exposed in admin views or logs, and a \PhoneNumberHelper\ normalizes phone inputs for consistent storage.

src/backend/MyProject.Shared · high confidence

Switch to HybridCache with optional master switch

The caching infrastructure now uses the new HybridCache API instead of the previous Redis-based implementation. A new configuration option allows users to disable caching entirely via a master switch; when disabled, the system uses a no-op implementation that bypasses all cache operations and calls the underlying data factories directly.

src/backend/MyProject.Infrastructure/Caching/Extensions · high confidence

Transparent session refresh and improved error handling in authentication

The frontend authentication library now automatically handles expired access tokens by refreshing them via a new middleware, allowing users to remain logged in without interruption when using idempotent requests (GET, HEAD, OPTIONS). It also introduces structured error reporting to distinguish between unauthenticated states and backend unavailability, and ensures a clean redirect to the login page upon logout even if the logout request fails.

src/frontend/src/lib/auth · high confidence

Validation rules added for role creation and update requests

The API now enforces specific validation rules for role management endpoints. When creating a role, the name is required, must start with a letter, contain only alphanumeric characters, hyphens, or underscores, and be limited to 50 characters, while the description is optional but capped at 200 characters. For updates, at least one field (name or description) must be provided; if a name is supplied, it undergoes the same format and length checks as creation, and the description remains optional with a 200-character limit.

src/backend/MyProject.WebApi/Features/Admin/Dtos/CreateRole, src/backend/MyProject.WebApi/Features/Admin/Dtos/UpdateRole · high confidence

Fixes

Server-side layout for public routes handles backend errors and provides Turnstile key

A new server-side layout loader (+layout.server.ts) has been added to the public route group. It now explicitly checks for backend availability, throwing a 503 error with an i18n-compliant message if the backend is unavailable, and passes the Cloudflare Turnstile site key to the client for CAPTCHA integration.

src/frontend/src/routes/(public) · high confidence

Test coverage

Added architecture and unit test suites for backend; Added tests for Origin validation middleware and machine-readable error codes; Added tests for PII masking in admin user endpoints; Added tests for the BFF API proxy handler; Added unit tests for application identity constants and permission evaluation; Added unit tests for shared backend utilities; Added validation tests for API request models; Added validation tests for CORS and rate-limiting options; Comprehensive backend test suite added; Comprehensive backend test suite for API controllers; New test infrastructure for API integration testing.

Dependencies

Backend dependency overhaul and frontend migration to pnpm

The backend has been restructured to use centralized package version management via Directory.Packages.props, introducing several key library updates: Hangfire (1.8.24) for job scheduling, Fluid.Core (2.31.0) for email templates, and Microsoft.Extensions.Caching.Hybrid (10.9.0) replacing previous caching implementations. Security is addressed by pinning Newtonsoft.Json to 13.0.4 to mitigate [CVE redacted] and updating MailKit to 4.17.0. The frontend has migrated from npm to pnpm (10.34.5), updating the SvelteKit ecosystem (Svelte 5.56.9, Kit 2.70.2) and adding Vitest (4.1.10) for testing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 50 → 49 (-1.5)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 89 → 84 (-5.2)
  • Architecture 81 → 75 (-6.7)
  • Maturity 70 → 72 (+1.7)
  • Readiness 35 → 33 (-2.3)
  • Security 66 → 64 (-2.3)
  • Accessibility 54 → 54 (+0.0)
  • Performance 68 → 67 (-0.3)

Resolved (92)

  • Boundary-crossing change coupling: UserManagementCard.svelte ↔ +page.svelte (src/frontend/src/lib/components/admin/UserManagementCard.svelte)
  • Bounded contexts not declared
  • Change coupling: AdminController.cs ↔ UsersController.cs (src/backend/MyProject.WebApi/Features/Admin/AdminController.cs)
  • Change coupling: AuthController.cs ↔ UsersController.cs (src/backend/MyProject.WebApi/Features/Authentication/AuthController.cs)
  • Change coupling: AvatarDialog.svelte ↔ DeleteAccountDialog.svelte (src/frontend/src/lib/components/profile/AvatarDialog.svelte)
  • Change coupling: ChangePasswordForm.svelte ↔ DeleteAccountDialog.svelte (src/frontend/src/lib/components/settings/ChangePasswordForm.svelte)
  • Change coupling: ForgotPasswordForm.svelte ↔ ResetPasswordForm.svelte (src/frontend/src/lib/components/auth/ForgotPasswordForm.svelte)
  • Change coupling: LoginForm.svelte ↔ ProfileForm.svelte (src/frontend/src/lib/components/auth/LoginForm.svelte)
  • Change coupling: ProfileForm.svelte ↔ ChangePasswordForm.svelte (src/frontend/src/lib/components/profile/ProfileForm.svelte)
  • Change coupling: ProfileForm.svelte ↔ DeleteAccountDialog.svelte (src/frontend/src/lib/components/profile/ProfileForm.svelte)
  • Change coupling: UsersController.cs ↔ ExceptionHandlingMiddleware.cs (src/backend/MyProject.WebApi/Features/Users/UsersController.cs)
  • Critical CVE: [GHSA redacted] (src/frontend/pnpm-lock.yaml)
  • Duplicated block (12 lines × 3) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
  • Duplicated block (13 lines × 3) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/GitLabAuthProvider.cs)
  • Duplicated block (16 lines × 9) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/AppleAuthProvider.cs)
  • Duplicated block (19 lines × 7) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/AppleAuthProvider.cs)
  • Duplicated block (9 lines × 2) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/AuthenticationService.cs)
  • Duplicated block (9 lines × 5) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/FacebookAuthProvider.cs)
  • High CVE: [GHSA redacted] (src/frontend/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (src/frontend/pnpm-lock.yaml)
  • …and 72 more

New (89)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: written for insiders (docs/sessions/2026-03-14-favicons-and-seo-fundamentals.md)
  • Documentation: written for insiders (docs/sessions/2026-03-14-startup-migration-retry.md)
  • Duplicated block (10 lines × 5) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/FacebookAuthProvider.cs)
  • Duplicated block (11 lines × 4) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/AuthenticationService.cs)
  • Duplicated block (12 lines × 2) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
  • Duplicated block (12 lines × 4) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
  • Duplicated block (13 lines × 2) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/AuthenticationService.cs)
  • Duplicated block (13 lines × 2) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalAuthService.cs)
  • Duplicated block (13 lines × 3) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
  • Duplicated block (14 lines × 2) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
  • Duplicated block (14 lines × 3) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/GoogleAuthProvider.cs)
  • Duplicated block (14 lines × 3) (src/backend/MyProject.Infrastructure/Identity/Services/UserService.cs)
  • Duplicated block (15 lines × 2) (src/backend/MyProject.WebApi/Extensions/RateLimiterExtensions.cs)
  • Duplicated block (15 lines × 3) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/GitLabAuthProvider.cs)
  • Duplicated block (17–19 lines × 9) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/AppleAuthProvider.cs)
  • Duplicated block (18–19 lines × 2) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/GitHubAuthProvider.cs)
  • Duplicated block (19 lines × 2) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
  • Duplicated block (20–21 lines × 9) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/AppleAuthProvider.cs)
  • Duplicated block (21–22 lines × 2) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
  • …and 69 more

Changes since last survey

  • 12 commits — 8 feature/other, 4 fixes

By area

  • src/backend — 5 commits
  • .claude/skills — 2 commits
  • src/frontend — 2 commits
  • (root) — 1 commit
  • .claude/README.md — 1 commit
  • docs/sessions — 1 commit

Notable commits

  • fix: fix(auth): harden auth flows per security audit (#532)
  • fix: fix(claude): narrow docker and gh api permissions, deny secret reads (#531)
  • fix: fix(frontend): buffer proxied bodies so 401 responses pass through (#525)
  • fix: fix(init): make init.ps1 survive real Windows environments (#536)
  • change: chore(backend): bump Aspire.AppHost.Sdk to 13.4.6 (#524)
  • change: chore(claude): audit and optimize the agentic coding setup (#529)
  • change: chore: update all dependencies to latest (NuGet, npm, Actions, Node 24) (#523)
  • change: feat(claude): add polish-ui composite design skill
  • change: feat(email): deliver transactional emails via Hangfire jobs (#527)
  • change: feat: add machine-readable error codes to ProblemDetails (#526)
  • change: refactor(auth): data-driven role model with wildcard permissions (#528)
  • change: style(auth): premium polish for auth shell brand panel (#535)

API surface

  • Unchanged — 56 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

fpindej/netrock was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit dbc6b49844d9095ef96b6492ae9ba304ea3c3c2c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.