fpindej/netrock
48.5
Weak · 21 September 2026
16.9k
lines of production code
C#
with TypeScript
4
measurements over time
What this system is
This system is a full-stack web application built with a .NET backend and a SvelteKit frontend, designed to manage user identities, administrative operations, and background tasks. It provides comprehensive authentication features including OAuth2 social logins, TOTP two-factor authentication, and secure session management, alongside a granular, permission-based authorization model for role and user administration. The platform supports user profile management with avatar uploads, transactional email notifications, and an audit trail for tracking system activity, all secured with robust infrastructure for caching, encryption, and rate limiting.
How it got here
2025 — Authentication overhaul and frontend launch
53 changes.
The project replaced its initial scaffolding with a comprehensive, permission-based authentication system featuring TOTP 2FA, OAuth integration, and hardened security controls. Simultaneously, a new SvelteKit frontend was introduced, providing a complete user interface for login, profile management, and administrative tasks, supported by a modernized backend architecture and dependency stack.
2026 — Admin panel and security infrastructure
59 changes.
This period focused on implementing a comprehensive admin panel for managing users, roles, permissions, and background jobs, supported by a new data-driven permission model and fine-grained authorization. It also established core security and infrastructure foundations, including AES-256-GCM encryption, S3 file storage, Hangfire job scheduling, and structured error handling with PII masking.
Features
Add Cloudflare Turnstile CAPTCHA verification
The application now integrates Cloudflare Turnstile for CAPTCHA verification during user registration and password recovery. This change introduces the infrastructure services required to validate Turnstile tokens, including configuration options for the secret key and verification endpoint, and a service that sends the token along with the client's remote IP address to Cloudflare. The system logs warnings for non-successful HTTP responses and debug information for specific error codes returned by the verification API, ensuring that invalid or failed challenges are handled gracefully.
src/backend/MyProject.Infrastructure/Features/Captcha · high confidence
Add OAuth provider selection and connected account management UI
The frontend now includes a dedicated OAuth component library that allows users to discover available identity providers, initiate login flows via provider buttons, and manage existing linked accounts. The new \OAuthProviderButtons\ component fetches available providers from the \/api/auth/external/providers\ endpoint and renders individual login buttons with loading states, while the \ConnectedAccountsCard\ component displays currently linked providers, offers disconnect functionality via a confirmation dialog, and provides a hint to set a password if no other disconnect options are available. Supporting components include \ProviderIcon\ for rendering logos for providers like Google, GitHub, Discord, Apple, Microsoft, LinkedIn, GitLab, Facebook, Slack, and Twitch, and \DisconnectDialog\ for handling the unlinking process with cooldown protection.
src/frontend/src/lib/components/oauth · high confidence
Add admin OAuth providers management page
Administrators can now view a list of configured OAuth providers via a new page at /admin/oauth-providers. The page loads provider data from the backend API and displays them in a grid using OAuthProviderCard components, showing an empty state if no providers are configured. Access is restricted to users with the admin oauthProviders permission, redirecting unauthorized users to the dashboard.
src/frontend/src/routes/(app)/admin/oauth-providers, src/frontend/src/routes/(app)/admin/roles · high confidence
Add email verification page with token-based validation
Users can now verify their email address via a dedicated page that accepts a token from the URL. The page loads the token, calls the /api/auth/email/verify endpoint, and displays a success message with a link to the dashboard or login, or an error message if the token is invalid or the verification fails.
src/frontend/src/routes/(public)/verify-email · high confidence
Add forgot password page with authenticated-user redirection
A new forgot-password route has been added to the public section of the frontend. The server-side load function checks if a user is already logged in; if so, it redirects them to the dashboard, ensuring that only unauthenticated users can access the password recovery flow. The page component renders a ForgotPasswordForm component and sets the appropriate meta title and description for SEO and accessibility.
src/frontend/src/routes/(public)/forgot-password · high confidence
Added cookie management service with cross-subdomain support
A new CookieService implementation has been added to the backend infrastructure to handle cookie operations, specifically configured with SameSite=None and Secure=true to support cross-subdomain deployments where the API and frontend reside on different origins. The service provides methods to set, retrieve, and delete cookies, with a dedicated SetSecureCookie method that enforces HttpOnly flags for sensitive data, and is registered in the dependency injection container via the AddCookieServices extension.
src/backend/MyProject.Infrastructure/Cookies · high confidence
Added dynamic robots.txt and sitemap.xml endpoints for SEO
The application now serves dynamic robots.txt and sitemap.xml files to improve search engine optimization. The robots.txt file explicitly allows crawling of public content while disallowing API, admin, dashboard, profile, and settings routes. The sitemap.xml file dynamically generates an XML sitemap listing public routes (currently only the home page) with specified change frequencies and priorities, excluding utility pages like login or registration.
src/frontend/src/routes/robots.txt, src/frontend/src/routes/sitemap.xml · high confidence
Added web app manifest for PWA support
A new site.webmanifest file has been added to the static assets, defining the application name, short name, theme colors, and display mode as standalone. This enables the application to be installed as a Progressive Web App (PWA) on supported devices, providing an app-like experience with custom icons and a standalone browser window.
src/frontend/static · high confidence
Admin job detail page with execution history and management actions
A new detail view for individual scheduled jobs is now available in the admin interface. Users can view job metadata, including the cron schedule, and review the execution history. Administrators with the appropriate permissions can perform management actions on the job, such as pausing or resuming it. The page enforces role-based access control, redirecting unauthorized users to the dashboard, and includes breadcrumb navigation for context.
src/frontend/src/routes/(app)/admin/jobs/\[jobId\] · high confidence
Admin user and role management infrastructure with permission escalation guards
This change introduces the backend service layer for the admin feature, registering \AdminService\ and \RoleManagementService\ via dependency injection. It implements core administrative capabilities including user listing, role assignment, and role CRUD operations, all protected by a \PermissionEscalationGuard\ that prevents privilege escalation by ensuring callers only grant permissions they hold themselves. The implementation enforces role hierarchy, prevents self-action on critical roles, and revokes sessions on destructive actions to maintain security.
src/backend/MyProject.Infrastructure/Features/Admin · high confidence
Admin user detail page with permission-gated PII masking
A new admin user detail page has been added at the /admin/users/\[id\] route, allowing administrators to view individual user profiles and their audit trails. The page enforces role-based access control, redirecting unauthorized users to the dashboard. It features permission-gated PII masking: if the current user lacks the 'Users.ViewPii' permission, sensitive email addresses are hidden behind a masked indicator. The page loads user details and available roles in parallel, gracefully handling role-list failures by rendering the UI without role assignment options, and displays dynamic breadcrumbs based on the user's display name.
src/frontend/src/routes/(app)/admin/users/\[id\] · high confidence
Aspire-based local development environment and hardened WebApi configuration
The WebApi project is now integrated with an Aspire AppHost, enabling a unified local development stack that automatically provisions and wires up PostgreSQL, MinIO, Mailpit, and the frontend via declarative service definitions. The API itself is hardened for production: it strips development and testing configuration files from Docker artifacts, enforces HTTPS redirection and HSTS outside of development, and adds an Origin header validation middleware for CSRF defense. Additionally, the API exposes new admin capabilities through DTOs and validators for managing user creation, OAuth provider configurations, job scheduling details, and role permissions, while supporting structured logging via Serilog and OpenTelemetry.
src/backend/MyProject.WebApi · high confidence
Audit trail logging and retrieval API
This change introduces the backend infrastructure and API contracts for an append-only audit trail. The infrastructure layer adds an \AuditEvent\ entity stored in the \audit\ schema (using JSONB for metadata and no foreign-key constraints to preserve history after user deletion), registers the \IAuditService\ for logging events without disrupting main operations, and provides a service to retrieve paginated audit events for a user. The WebApi layer exposes the corresponding response DTOs (\AuditEventResponse\, \ListAuditEventsResponse\) and mapping logic to serve these audit records via the API.
src/backend/MyProject.Infrastructure/Features/Audit, src/backend/MyProject.WebApi/Features/Audit · high confidence
Authentication service overhaul with TOTP 2FA, OAuth, and permission-based JWTs
The authentication infrastructure has been significantly expanded and hardened. Users can now log in with a 'remember me' option and complete TOTP two-factor authentication flows (setup, verify, recovery codes) via the new TwoFactorService. External OAuth provider management is introduced through ExternalAuthService and ProviderConfigService, allowing database-backed, encrypted configuration and connection testing. Token security is improved with a dedicated TokenSessionService that handles refresh token rotation, reuse detection, and cookie management, while JwtTokenProvider now embeds user permissions and security stamps directly into access tokens for fine-grained authorization.
src/backend/MyProject.Infrastructure/Features/Authentication/Services · high confidence
Expanded authentication DTOs with validation and new capabilities
The authentication API now supports a comprehensive set of request and response data transfer objects, enabling users to change passwords, reset forgotten passwords, verify email addresses, and set initial passwords for OAuth accounts. External OAuth2 integration is supported via challenge, callback, and unlink endpoints, while two-factor authentication (TOTP) allows users to set up, verify, and disable 2FA using authenticator apps or recovery codes. Login requests now include a 'Remember Me' option for persistent sessions, and registration requires a Cloudflare Turnstile CAPTCHA token. All new and updated DTOs are backed by FluentValidation rules to enforce field constraints, password complexity, and format requirements at runtime.
src/backend/MyProject.WebApi/Features/Authentication/Dtos · high confidence
Expanded authentication and user profile data models
The application's authentication layer now exposes a comprehensive set of data transfer objects that support dual authentication (Bearer tokens and cookies), external OAuth2 provider integration, and two-factor authentication. Users can now manage their profiles (including avatars and contact details), change or reset passwords, and handle email verification flows. The system also introduces admin-facing DTOs for configuring external OAuth providers with database-backed, encrypted credentials, and provides detailed user output including roles, permissions, and linked provider status.
src/backend/MyProject.Application/Features/Authentication/Dtos · high confidence
Expanded authentication data models for enhanced security and user profiles
The authentication infrastructure now supports a richer set of security and user features through new and updated data models. Users can now log in with persistent sessions via the new 'remember me' functionality, which is backed by the RefreshToken model. Security is strengthened with database-backed TOTP two-factor authentication (TwoFactorChallenge), OAuth2 social login with CSRF protection (ExternalAuthState), and runtime-managed provider credentials encrypted with AES-256-GCM (ExternalProviderConfig). Password-reset and email-verification links are now anonymized using hashed tokens (EmailToken) to prevent email exposure. User profiles are extended with biography and avatar support (ApplicationUser), and the role system now supports granular permissions, system role protection, and hierarchy ranking (ApplicationRole).
src/backend/MyProject.Infrastructure/Features/Authentication/Models · high confidence
Initial SvelteKit frontend with production-ready configuration
The frontend application has been introduced as a SvelteKit project using Svelte 5, TypeScript, and Tailwind CSS. This change establishes the core development and deployment infrastructure, including a multi-stage Dockerfile for production builds and a local development container, alongside configuration for the pnpm package manager, ESLint, and Prettier. It also sets up the Content Security Policy (CSP) directives in the SvelteKit config to support Cloudflare Turnstile CAPTCHA integration and defines environment variables for the API URL, Turnstile keys, and proxy origins.
src/frontend · high confidence
Introduce Hangfire-based background job scheduling with pause support
The application now uses Hangfire with PostgreSQL for background job scheduling, replacing previous static API usage with a dependency-injection-based approach. This adds a new job infrastructure that includes an admin API for managing recurring jobs (listing, triggering, pausing, and resuming) and a development-only Hangfire dashboard at /hangfire. Three hourly cleanup jobs are now active to remove expired refresh tokens, email tokens, and two-factor challenges, preventing unbounded database growth. The system also supports pausing jobs, with the pause state persisted to the database so it survives application restarts.
src/backend/MyProject.Infrastructure/Features/Jobs · high confidence
Introduce S3-compatible file storage infrastructure
The application now supports persistent file storage via an S3-compatible backend (such as MinIO or AWS S3). This change introduces the \FileStorageOptions\ configuration model and registers the \S3FileStorageService\ implementation, which handles uploading, downloading, deleting, and existence-checking of objects. The service is configured with specific endpoint, credentials, and bucket settings, and includes logic to ensure the target bucket exists upon first use, making it compatible with both local development environments and production cloud storage.
src/backend/MyProject.Infrastructure/Features/FileStorage · high confidence
Introduce SvelteKit root layout and error handling with session-aware auth
The frontend now uses a SvelteKit-based routing structure with a root layout (+layout.svelte, +layout.ts, +layout.server.ts) and a global error page (+error.svelte). The server layout loads user session data and conditionally exposes the internal API URL only in development mode, while the client layout initializes browser authentication, theme, and health monitoring. The error page provides localized, icon-rich displays for common HTTP errors (403, 404, 429, 500, 503) and includes automatic recovery logic for 503 Service Unavailable states by polling backend health and reloading when the service returns. Tests verify that the server layout correctly determines session presence before calling getUser, ensuring robust handling of cookie mutations during token refresh.
src/frontend/src/routes · high confidence
Introduce application-layer audit logging service and event definitions
The application layer now includes a new audit feature that provides a service for recording and retrieving user activity logs. This change introduces the IAuditService interface, which allows the system to log actions (such as logins, profile updates, and admin operations) without disrupting the main operation if logging fails, and to retrieve paginated lists of these events for specific users. The feature is supported by a set of constants in AuditActions that classify events (e.g., LoginSuccess, AdminCreateUser, TwoFactorEnabled) and DTOs (AuditEventOutput, AuditEventListOutput) that define the structure of the logged data, including user IDs, action types, target entities, and metadata.
src/backend/MyProject.Application/Features/Audit · high confidence
Introduce job management API for Hangfire recurring jobs
The application now exposes an API for managing Hangfire recurring jobs, allowing administrators to query job lists and details, trigger immediate executions, remove jobs, and pause or resume schedules. This change introduces the \IJobManagementService\ interface and associated DTOs (\JobExecutionOutput\, \RecurringJobOutput\, \RecurringJobDetailOutput\) within the \Features/Jobs\ layer to support these operations, including a \RestoreJobsAsync\ method to re-register definitions while preserving pause states.
src/backend/MyProject.Application/Features/Jobs · high confidence
Introduce templated email infrastructure for transactional notifications
This change adds the core application-layer components for sending transactional emails using a Liquid-based template system. It introduces the \EmailMessage\ record for message structure, interfaces for rendering templates (\IEmailTemplateRenderer\) and sending them safely (\ITemplatedEmailSender\), and a set of constants (\EmailTemplateNames\) defining specific templates such as email verification, password reset, user invitations, and admin-initiated two-factor authentication disablement. Additionally, it defines the corresponding data models (e.g., \VerifyEmailModel\, \ResetPasswordModel\) that bind context data like URLs and expiration times into these templates, enabling consistent and maintainable email content generation across the application.
src/backend/MyProject.Application/Features/Email · high confidence
Introduces AES-256-GCM encryption and SHA-256 hashing utilities
The cryptography infrastructure now includes an AES-256-GCM encryption service for securely storing sensitive configuration data, deriving keys via HKDF-SHA256, and a SHA-256 hashing helper for generating secure token hashes. These changes enable robust encryption for provider configurations and secure storage of refresh tokens.
src/backend/MyProject.Infrastructure/Cryptography · high confidence
Introduces a data-driven permission and role model with hierarchy and wildcard support
The application now uses a centralized, reflection-based system for managing authorization. New files define atomic permission claims (e.g., \users.view\, \jobs.manage\) grouped by category, and declarative role definitions (\User\, \Admin\, \Superuser\) that include hierarchy ranks and default permission sets. The \Superuser\ role is granted a wildcard permission (\\*\) for full access, while \Admin\ and \User\ roles have specific, limited permissions. This structure replaces hardcoded role/permission logic with a seeded, database-backed model that supports fine-grained authorization and role hierarchy enforcement.
src/backend/MyProject.Application/Identity/Constants · high confidence
Introduction of CAPTCHA validation service interface
A new ICaptchaService interface has been added to the application layer, defining a contract for validating CAPTCHA tokens submitted by the frontend. This interface introduces a ValidateTokenAsync method that accepts a token string and returns a boolean indicating validity, laying the groundwork for integrating CAPTCHA verification into user-facing flows such as registration and password recovery.
src/backend/MyProject.Application/Features/Captcha · high confidence
Introduction of centralized cookie name constants and service abstraction
The application layer now defines explicit constants for JWT authentication cookies (access and refresh tokens) using the \_\_Secure- prefix to enforce security attributes, and introduces an ICookieService interface to standardize how cookies are set, retrieved, and deleted across the WebApi and Infrastructure layers.
src/backend/MyProject.Application/Cookies · high confidence
Introduction of user context and service infrastructure for identity management
The application now includes a new identity infrastructure layer that registers and implements core user context services. This change adds a DI extension method to register IUserContext and IUserService, alongside a UserContext implementation that extracts user identity details (such as UserId, Email, and UserName) from HTTP context claims. It also introduces role checking and permission evaluation capabilities via IsInRole and HasPermission methods, laying the groundwork for the permission-based authorization system mentioned in the commit history.
src/backend/MyProject.Infrastructure/Identity · high confidence
New Admin API endpoints for user, role, job, and OAuth management
The WebApi layer now exposes a comprehensive set of administrative endpoints under the Admin feature, enabling administrators to manage users (list, view, assign/remove roles, lock accounts, disable 2FA), roles (create, update, set permissions, view details), background jobs (list, trigger, pause, resume, remove, restore), and OAuth provider configurations (list, update, test connection). These endpoints are protected by permission-based authorization, enforce role hierarchy and self-action protections, and include PII masking for user data based on caller permissions. Rate limiting is applied to all mutation endpoints to prevent abuse.
src/backend/MyProject.WebApi/Features/Admin · high confidence
New Admin Jobs page with restore functionality
A new admin page at /admin/jobs has been added, allowing users with the Jobs.Manage permission to view a list of jobs and trigger a restore operation. The page includes a confirmation dialog for the restore action, which calls the /api/v1/admin/jobs/restore endpoint, and implements a cooldown timer on the button to prevent rapid repeated submissions. The UI displays a loading state during the restore process and provides success or error feedback via toast notifications.
src/frontend/src/routes/(app)/admin/jobs · high confidence
New Admin Service Interfaces for User and Role Management
The application introduces two new service interfaces, IAdminService and IRoleManagementService, within the Admin feature layer to standardize administrative operations. IAdminService provides methods for managing user accounts—including listing, creating, locking, unlocking, deleting, verifying email, resetting passwords, and disabling two-factor authentication—while enforcing a strict role hierarchy where the caller must have a higher rank than the target user and cannot perform self-modifying actions like locking or deleting their own account. IRoleManagementService exposes CRUD operations for custom roles and permission assignment, explicitly protecting system roles (Superuser, Admin, User) from deletion or renaming and preventing privilege escalation by ensuring callers cannot grant permissions they do not hold.
src/backend/MyProject.Application/Features/Admin · high confidence
New UserService implementation with HybridCache and avatar upload support
The identity service layer now uses a new UserService implementation that integrates HybridCache for user data retrieval and supports avatar uploads via file storage. This change introduces caching for user profile lookups, invalidates the cache on profile updates, and adds functionality for processing and storing user avatars, replacing previous URL-based avatar handling.
src/backend/MyProject.Infrastructure/Identity/Services · high confidence
New admin API data models for user and role management
This change introduces a comprehensive set of Data Transfer Objects (DTOs) in the application layer to support the new admin capabilities for managing users and roles. For user management, the system now exposes detailed user profiles (including 2FA status, lockout details, and avatar presence) via \AdminUserOutput\, paginated lists via \AdminUserListOutput\, and inputs for creating users (\CreateUserInput\) and assigning roles (\AssignRoleInput\). For role management, administrators can now create (\CreateRoleInput\), update (\UpdateRoleInput\), and modify permissions (\SetRolePermissionsInput\) for roles. The system also exposes role details (\RoleDetailOutput\, \AdminRoleOutput\) including hierarchy ranks, system protection flags, and permission grants, along with grouped permission categories (\PermissionGroupOutput\) to facilitate the new permission-based authorization UI.
src/backend/MyProject.Application/Features/Admin/Dtos · high confidence
New admin management interfaces for users, roles, jobs, and audit trails
The admin panel now includes dedicated UI components for managing core system entities. Administrators can manage user accounts (lock/unlock, delete, send password resets, verify emails, disable 2FA) and view PII-masked details. Role management allows creating, editing, and deleting roles, with a grid view that groups and displays permissions. A new Hangfire job scheduler UI lets admins trigger, pause, resume, and delete background jobs, and view their execution history. Additionally, a full audit trail component displays a timeline of user activity with detailed event metadata.
src/frontend/src/lib/components/admin · high confidence
New admin users management page with permission-gated access and PII masking
A new admin users management interface has been added, allowing administrators to view, search, and paginate through user lists. Access to this page is restricted by role-based permissions, redirecting unauthorized users to the dashboard. The interface supports searching users and paginating results. Additionally, personally identifiable information (PII) in the user table is masked for users who do not have the specific 'ViewPii' permission, while those with 'Manage' permissions can invite new users via a dialog.
src/frontend/src/routes/(app)/admin/users · high confidence
New authentication service interfaces for login, 2FA, and OAuth
The application now exposes a comprehensive set of authentication capabilities through new service interfaces in the application layer. Users can log in with standard credentials or via external OAuth providers, with support for persistent 'remember me' cookies and dual authentication modes (stateless tokens or HTTP cookies). The system introduces TOTP-based two-factor authentication, including setup, verification, and recovery code management. Additionally, account lifecycle features such as registration, password changes, password resets, and email verification are now defined, along with administrative capabilities to manage and test OAuth provider configurations stored in the database.
src/backend/MyProject.Application/Features/Authentication · high confidence
New common UI component library
The frontend now includes a new set of reusable UI components in the common library, providing consistent patterns for displaying empty states, field validation errors, loading spinners, page headers, status indicators, and work-in-progress notices. These components standardize the visual language across the application, ensuring uniform styling for icons, alerts, and status messages while reducing duplication in individual page implementations.
src/frontend/src/lib/components/common · high confidence
New configurable options for hosting, rate limiting, and CORS
This change introduces new configuration classes in the WebApi project to allow fine-tuning of deployment and security settings. HostingOptions enables control over HTTPS enforcement and trusted reverse proxy networks for accurate client IP detection. RateLimitingOptions adds a comprehensive, config-driven rate limiting system with distinct policies for global traffic, registration, authentication, sensitive operations, and admin mutations, each supporting custom permit limits, time windows, and queue behaviors. Additionally, the existing CorsOptions class has been sealed and documented to clarify its role in managing cross-origin request policies.
src/backend/MyProject.WebApi/Options · high confidence
New dashboard page with user-specific widgets
A new dashboard page has been added that displays a personalized greeting based on the logged-in user's first name and includes four main widget components: WelcomeGuide, DeveloperGuide, QuickActions, and AccountStatus. The page also sets appropriate meta title and description for SEO purposes.
src/frontend/src/routes/(app)/dashboard · high confidence
New dashboard widget components for account status, quick actions, and guides
The dashboard now includes four new Svelte components that provide users with immediate visibility into their account state and easy access to key areas. The AccountStatus widget displays the completion status of the user profile, email verification, two-factor authentication, and assigned roles. QuickActions offers direct navigation links to the Profile, Settings, and (for administrators) the Admin panel, with the admin link conditionally shown based on user permissions. A WelcomeGuide component highlights these core areas, while a collapsible DeveloperGuide provides instructions for customizing the dashboard and adding new features. These components are exported via a new index.ts barrel file for easy integration.
src/frontend/src/lib/components/dashboard · high confidence
New dedicated page for editing individual role details and permissions
The admin interface now includes a specific route for managing a single role's configuration. This page loads the role's current data alongside the full list of available permissions, allowing administrators to edit the role name and description, toggle specific permission groups, and delete the role (if it is not a system role and has no assigned users). Access is restricted to users with the 'Manage Roles' permission, and the UI adapts to hide editing controls for system roles or when permission data fails to load.
src/frontend/src/routes/(app)/admin/roles/\[id\] · high confidence
New external OAuth/OIDC authentication providers added
The authentication infrastructure now supports logging in via Apple, Discord, Facebook, GitHub, GitLab, Google, and LinkedIn. This location introduces the specific provider implementations and the shared \ExternalUserInfo\ record, enabling users to authenticate with these services using their existing accounts.
src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders · high confidence
New frontend health check endpoint
A new health check route has been added to the frontend application at /api/health. This endpoint proxies the health status from the configured backend API. If the backend is reachable, the frontend returns its status and content type; if the backend is unreachable, the frontend returns a 503 Service Unavailable status with an 'Offline' message, allowing external monitoring tools to verify the frontend's connectivity to the backend.
src/frontend/src/routes/api/health · high confidence
New frontend state management utilities and hooks
The \src/frontend/src/lib/state\ directory now provides a suite of new reactive state modules for the Svelte frontend. This includes \health.svelte.ts\ for global API health polling with adaptive intervals, \cooldown.svelte.ts\ for rate-limit timers, \shortcuts.svelte.ts\ for keyboard shortcuts (including a command palette), \theme.svelte.ts\ for light/dark/system theme switching, \shake.svelte.ts\ for error animations, \breadcrumb.svelte.ts\ for dynamic labels, and \is-mobile.svelte.ts\ for breakpoint detection. A corresponding test file \health.test.ts\ has been added to verify the health state logic.
src/frontend/src/lib/state · high confidence
New frontend utility modules for permissions, roles, audit, and OAuth
The frontend now includes a suite of new client-side utility modules in src/frontend/src/lib/utils to support recent feature additions. The permissions module introduces a data-driven role model with wildcard support, allowing users to check specific or any permissions (e.g., users.view, users.manage) against their profile. The roles module implements a hierarchy enforcement system, ensuring that users can only manage accounts if their role rank is strictly higher than the target's. The audit module provides a full-stack audit trail UI, mapping backend actions (like login, role assignment, or 2FA changes) to localized labels and visual variants (success, warning, destructive). The OAuth module handles the login flow by initiating challenges and redirecting users to providers, while the jobs module formats Hangfire job statuses and durations for the admin UI. Additionally, a crop utility enables avatar image processing, and platform detection utilities support device-specific UI logic.
src/frontend/src/lib/utils · high confidence
New layout components with command palette, breadcrumbs, and admin RBAC
The layout area now includes a new AppSidebar that filters admin navigation items (Users, Roles, Jobs, OAuth Providers) based on user permissions, a CommandPalette for keyboard-driven navigation and actions (including theme toggling and logout), a ContentHeader that renders dynamic breadcrumbs for admin detail pages, and supporting UI components (Header, LanguageSelector, ThemeToggle, UserNav, ShortcutsHelp) that integrate with the new Paraglide i18n system and shortcut state.
src/frontend/src/lib/components/layout · high confidence
New login and registration pages with session-aware redirects and feedback
The application now includes dedicated login and registration routes. On the login page, users who are already authenticated are automatically redirected to the dashboard. The login flow also supports a 'reason' query parameter to display specific user feedback: a 'session\_expired' reason triggers an error toast, while a 'password\_changed' reason triggers a success toast, and an optional 'email' parameter pre-fills the login form. The registration page similarly redirects authenticated users to the dashboard. Both pages are implemented using SvelteKit server loads and Svelte components, with tests verifying the redirect logic and parameter handling for the login page.
src/frontend/src/routes/(public)/login · high confidence
New profile management interface with avatar upload and account details
The profile section now features a comprehensive set of components for managing user identity. Users can view their account details, including user ID and assigned roles, via the AccountDetails component. The ProfileForm allows editing of personal information (first name, last name, phone number, and bio) with real-time field-level validation errors and shake animations. A significant addition is the AvatarDialog, which enables users to upload, crop, and zoom new profile pictures from their device, supporting drag-and-drop and file selection, with cooldown protection against rate limits. The ProfileHeader displays the current avatar with cache-busting to ensure updates are reflected immediately, showing initials as a fallback.
src/frontend/src/lib/components/profile · high confidence
New profile page layout with two-column grid
A new profile page has been added that displays the user's profile form and account details side-by-side on large screens using a two-column grid layout, while stacking vertically on smaller screens. The page uses Paraglide JS for internationalized titles and descriptions.
src/frontend/src/routes/(app)/profile · high confidence
New settings components for account security and activity
The settings area now includes dedicated UI components for managing account security and visibility. Users can change or set their password via ChangePasswordForm and SetPasswordForm, enable or disable TOTP two-factor authentication through TwoFactorCard and its setup/disable dialogs, and review their login history in the new ActivityLog component. A DeleteAccountDialog is also provided for account removal.
src/frontend/src/lib/components/settings · high confidence
New shadcn/ui component library added to the frontend
The frontend now includes a comprehensive set of UI components sourced from shadcn/ui, providing a consistent design system for building interfaces. This addition introduces ready-to-use primitives for common patterns such as dialogs, alerts, avatars, badges, breadcrumbs, buttons, cards, checkboxes, command palettes, dropdown menus, and more. These components are built on top of bits-ui and Tailwind CSS, ensuring accessibility and customization while reducing the need to reinvent standard UI elements.
src/frontend/src/lib/components/ui · high confidence
New unified settings page with account management and security controls
A new settings page has been introduced at the application's settings route, consolidating account management and security features into a single interface. Users can now manage their password status (setting a new password or changing an existing one), configure two-factor authentication via TOTP, and view or manage connected OAuth accounts. The page also includes an activity log for auditing and a dedicated danger zone section that allows users to initiate account deletion through a confirmation dialog.
src/frontend/src/routes/(app)/settings · high confidence
New user profile management endpoints with avatar and account deletion
The Users API now exposes a comprehensive set of endpoints for managing authenticated user profiles. Users can retrieve their current information, update profile details, and manage avatars via upload, removal, and retrieval endpoints (with images resized to 512x512 and stored as WebP). A new account deletion endpoint allows users to permanently remove their accounts with password confirmation, revoking all tokens and clearing auth cookies. Additionally, users can view their personal audit activity log. These changes introduce new response DTOs and a mapper to translate application-layer user data into API responses.
src/backend/MyProject.WebApi/Features/Users · high confidence
New user profile update API and enriched user response model
The API now supports updating user profile details (first name, last name, phone number, and bio) via a new UpdateUserRequest DTO, which includes validation rules for phone number formatting and field lengths. Additionally, the UserResponse model has been expanded to expose comprehensive account status information, including avatar presence, assigned roles, atomic permissions, email confirmation status, two-factor authentication status, linked OAuth providers, and password existence.
src/backend/MyProject.WebApi/Features/Users/Dtos · high confidence
OpenAPI documentation and interactive API reference setup
The API now registers a comprehensive OpenAPI v1 specification using custom transformers to refine document structure, operation details, and schema definitions (including support for ProblemDetails and enums). Additionally, the Scalar interactive API reference UI is mapped to the application, configured with the 'Mars' theme, C\# HttpClient as the default client, and specific UI behaviors like alphabetical tag sorting and a 'k' search hotkey.
src/backend/MyProject.WebApi/Features/OpenApi/Extensions · high confidence
Replaces legacy AI agent guidelines with structured Claude Code orchestration and Playwright integration
The project's AI development workflow has been modernized by removing the generic \AGENTS.md\ and \docker-compose.local.yml\ files and introducing a dedicated Claude Code setup. This includes a new \CLAUDE.md\ that defines a strict delegation model with specialized agents (backend, frontend, security, etc.) and automated verification loops, alongside a \.mcp.json\ file that configures the Playwright MCP server for browser-based UI verification. The \FILEMAP.md\ provides a comprehensive change-impact reference to ensure cross-stack consistency, while standard repository governance files (Code of Conduct, Contributing, Security, License) are added to support open-source collaboration.
(repo-wide) · high confidence
Reset password page now supports admin invitation flows
The reset password page now handles both standard password resets and admin-sent invitations. It detects an invitation context via a URL parameter and adjusts the page title and meta description accordingly. The page no longer redirects authenticated users away, allowing them to complete the invitation flow even if they are already signed in.
src/frontend/src/routes/(public)/reset-password · high confidence
Standardized cache keys and secret encryption service introduced
The application now provides a centralized factory for generating standardized cache keys (e.g., for user profiles, security stamps, and provider configurations) to improve cache consistency. Additionally, a new secret encryption service interface has been added, utilizing AES-256-GCM to securely encrypt and decrypt sensitive data such as OAuth client credentials at rest.
src/backend/MyProject.Application/Caching · high confidence
Transactional email delivery with Liquid templates and background jobs
The application now sends transactional emails (password resets, email verification, account invitations, and admin notifications) using Liquid templates rendered by the Fluid engine. Delivery is configurable: when both email and job scheduling are enabled, emails are queued as Hangfire background jobs with automatic SMTP retries; otherwise, they are sent inline via SMTP or logged only in development.
src/backend/MyProject.Infrastructure/Features/Email · high confidence
User avatars can now be uploaded as files and are stored in S3
Users can upload avatar images via a file upload mechanism instead of providing a URL. The system validates the file (max 5 MB, JPEG/PNG/WebP/GIF), processes it into a normalized WebP format using SkiaSharp, and stores the result in an S3-compatible object store via the new file storage service.
(repo-wide) · high confidence
Removals
Removal of initial authentication and infrastructure scaffolding
The entire initial implementation of the application has been removed, including the authentication feature (controllers, services, DTOs, and models), the persistence layer (DbContext, UnitOfWork, and migrations), and the WebApi entry point (Program.cs, Dockerfile, and configuration files). This deletes the ability to register, log in, or manage users via cookie-based JWT authentication, removes the database context and transaction management, and eliminates the API server startup logic, rate limiting, and OpenAPI documentation setup.
(repo-wide) · high confidence
Architecture
Centralized type aliases for frontend API models
A new shared types module has been introduced in the frontend library to reduce repetition by creating explicit type aliases for common API response schemas. This file maps internal frontend types (such as User, AdminUser, AdminRole, PermissionGroup, AuditEvent, Job, JobDetail, JobExecution, and OAuthProviderConfig) directly to their corresponding OpenAPI component definitions, ensuring consistent typing across components that consume these API responses.
src/frontend/src/lib/types · high confidence
Behavioural changes
API proxy hardening with CSRF protection and header filtering
The frontend API proxy route now validates request origins to prevent cross-site request forgery on state-changing methods, forwards only a strict allowlist of request headers while stripping sensitive response headers, and buffers request bodies to ensure proper 401 error handling instead of network errors.
src/frontend/src/routes/api/\[...path\] · high confidence
Account deletion and permission-based authorization
Users can now permanently delete their own accounts via a new endpoint that requires password confirmation, with the backend revoking all tokens and clearing auth cookies upon success. Additionally, the system has shifted to a permission-based authorization model where access is determined by specific permission claims (including a wildcard for superusers) rather than role names, providing a more granular control over user capabilities.
src/backend/MyProject.Application/Identity · high confidence
Admin API request validation and data contracts
The Admin API now enforces strict validation on role assignment and user listing requests. Assigning a role requires a non-empty role name (max 50 characters), while listing users supports optional search filtering (max 200 characters) with enforced pagination constraints (page number \>= 1, page size 1-100). New DTOs define the request/response structures for these admin operations.
src/backend/MyProject.WebApi/Features/Admin/Dtos/AssignRole, src/backend/MyProject.WebApi/Features/Admin/Dtos/ListUsers · high confidence
Admin area access now requires specific permissions
Access to the admin section is now gated by a server-side layout guard that checks for specific permissions (users.view, roles.view, jobs.view, or oauth\_providers.view). Users without at least one of these permissions are automatically redirected to the dashboard, while those with wildcard permissions (Superuser) or any single admin permission retain access.
src/frontend/src/routes/(app)/admin · high confidence
Authentication API restructured into dedicated feature controllers
The authentication endpoints have been reorganized from a single monolithic controller into a set of specialized controllers under the \api/auth\ route prefix to improve clarity and maintainability. The new structure includes \AuthController\ for core login, registration, and token management; \PasswordController\ for forgot/reset/change password flows; \TwoFactorController\ for TOTP setup and verification; \ExternalAuthController\ for OAuth2 provider interactions; and \EmailVerificationController\ for email confirmation. This change also introduces dual authentication support, allowing clients to choose between Bearer tokens and HttpOnly cookies via a \useCookies\ query parameter, and enforces per-endpoint rate limiting across all authentication operations.
src/backend/MyProject.WebApi/Features/Authentication · high confidence
Automated development environment checks and safety hooks
New hooks in .claude/hooks enforce safer and more consistent development workflows: session-start.mjs verifies prerequisites (.NET SDK, pnpm, dotnet-ef, Docker) at the beginning of a session; auto-format.mjs automatically formats backend C\# files with dotnet format and frontend files with Prettier after edits; validate-bash.mjs blocks dangerous shell commands such as force pushes, destructive rm -rf, and piping remote scripts to the shell; and stop-quality-gate.mjs prevents the session from ending with uncommitted changes in src/, prompting a commit or explaining why changes are left uncommitted.
.claude/hooks · high confidence
Automatic auditing and user cache invalidation on data changes
The persistence layer now automatically tracks entity lifecycle changes and manages caching consistency without manual intervention. An AuditingInterceptor is applied to all entities inheriting from BaseEntity, automatically setting CreatedAt, CreatedBy, UpdatedAt, UpdatedBy, and soft-delete fields (DeletedAt, DeletedBy) based on the current user context and time. Additionally, a UserCacheInvalidationInterceptor detects modifications to users or their roles and automatically invalidates the corresponding user cache entries via HybridCache after the changes are saved, ensuring data consistency.
src/backend/MyProject.Infrastructure/Persistence/Interceptors · high confidence
Backend project structure reorganization and new tooling files
The backend directory has been restructured to include new configuration and tooling files: a .dockerignore file to exclude unnecessary artifacts from Docker builds, an .editorconfig enforcing C\# interface naming conventions, and a nuget.config specifying explicit package sources. A new HealthProbe tool has been added to check service health endpoints, and the solution file (MyProject.slnx) now explicitly references multiple project layers (Application, Domain, Infrastructure, Shared, WebApi, ServiceDefaults, AppHost) along with test projects. The Directory.Build.props file has been moved and simplified to define common build properties like target framework and nullable/implicit usings settings.
src/backend · high confidence
BaseEntity now tracks user audit fields and simplifies soft-delete/restore
The BaseEntity in the domain layer now includes Guid? properties for CreatedBy, UpdatedBy, and DeletedBy to record which user performed each action. The SoftDelete and Restore methods no longer accept explicit DateTime arguments; timestamps are no longer set by these methods, and Restore also clears the DeletedBy field.
src/backend/MyProject.Domain · high confidence
CSRF defense and standardized error responses
The API now includes an OriginValidationMiddleware that blocks cross-origin state-changing requests (POST, PUT, PATCH, DELETE) unless the Origin header matches the configured allowed origins, providing defense-in-depth against CSRF attacks. Additionally, the ExceptionHandlingMiddleware has been refactored to return standardized ProblemDetails responses instead of custom JSON error objects, ensuring consistent error formatting across the application while still exposing stack traces in development environments.
src/backend/MyProject.WebApi/Middlewares · high confidence
Centralized app layout with session-aware auth and backend health handling
The (app) route now uses a dedicated server-side layout to enforce authentication and handle backend availability before rendering any protected pages. If the backend is unavailable, users see a 503 error instead of being redirected to login. For unauthenticated users, the system distinguishes between fresh visitors (who are sent to a clean login page) and those with an expired session (who are redirected to /login?reason=session\_expired), preventing confusing error messages for long-expired cookies. Additionally, the layout persists sidebar state via cookies to avoid visual flashes on load, automatically re-runs server loads when backend health polling detects an outage, and displays an email verification banner for users who haven't confirmed their email address.
src/frontend/src/routes/(app) · high confidence
Centralized route configuration and server-side environment validation
The application now manages navigation paths and access control through a centralized configuration in src/frontend/src/lib/config. Route paths (such as dashboard, login, and profile) are defined as constants to prevent hardcoding, while admin routes are explicitly paired with RBAC permissions to ensure consistent access control across guards and UI components. Additionally, server-side configuration has been introduced to validate the API URL at startup and support configurable allowed origins for proxy CSRF checks, improving reliability and security for cross-origin requests.
src/frontend/src/lib/config · high confidence
Database initialization, role seeding, and PostgreSQL query hardening
The persistence layer now includes a new \ApplicationBuilderExtensions\ that handles startup database initialization, including applying migrations in development, and robustly seeding roles and users from environment variables. Role seeding has been hardened to validate hierarchy invariants, update metadata drift without overwriting operator-edited descriptions, and rotate security stamps when a role gains wildcard permissions to invalidate stale tokens. The PostgreSQL configuration now enables retry-on-failure and logs command errors as warnings, while new interceptors handle auditing and user cache invalidation. Additionally, string escaping for SQL LIKE queries has switched from bracket-based to backslash-based escaping to correctly support PostgreSQL wildcards, and pagination error messages now reference centralized error constants.
src/backend/MyProject.Infrastructure/Persistence/Extensions · high confidence
Enhanced authentication security and external provider support
This update introduces several security and capability improvements to the authentication system. Account lockout is now enforced after five failed attempts to mitigate brute-force attacks. JWT token validation has been hardened to verify the security stamp against the database (cached via HybridCache), ensuring tokens are invalidated upon password changes or role updates. The system now supports dual authentication via Bearer headers and HttpOnly cookies. Additionally, the infrastructure registers services for two-factor authentication, email verification, and external OAuth providers including Google, GitHub, Discord, Apple, Microsoft, LinkedIn, GitLab, Facebook, Slack, and Twitch, with provider configurations encrypted using AES-256-GCM.
src/backend/MyProject.Infrastructure/Features/Authentication/Extensions · high confidence
Frontend security headers and safe-area viewport support
The frontend now applies security headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy) to all page responses while skipping them for API proxy routes (/api/\*) where the backend handles them. In production, Strict-Transport-Security (HSTS) is also added. The HTML template includes viewport-fit=cover and safe-area insets to improve layout on devices with notches or dynamic islands.
src/frontend/src · high confidence
Global soft-delete filtering and standardized error handling in persistence layer
The persistence layer now automatically excludes soft-deleted entities from all database queries via a global query filter defined in BaseEntityConfiguration, removing the need for manual filtering in repository methods. To support operations like restoring deleted items, the repository explicitly ignores these filters when necessary. Additionally, the repository implementation has been refactored to use centralized error message constants instead of inline strings and relies on injected logging rather than a TimeProvider for timestamping soft-delete and restore actions.
src/backend/MyProject.Infrastructure/Persistence · high confidence
Introduction of permission-based authorization with standardized error responses
The API now supports fine-grained, permission-based access control (e.g., 'users.view') via the new RequirePermission attribute, replacing or supplementing previous role-based checks. This system dynamically resolves policies and validates permissions against user claims. Additionally, unauthorized (401) and forbidden (403) responses now return structured ProblemDetails JSON bodies, ensuring consistency with the OpenAPI specification and providing clear error messages to clients instead of empty responses.
src/backend/MyProject.WebApi/Authorization · high confidence
Logging infrastructure reorganized and documented
The logging configuration code has been moved from the root infrastructure folder into the backend-specific logging module. The logger extension methods have been updated with comprehensive XML documentation, clarifying the distinction between the minimal bootstrap logger used during early startup and the full Serilog setup, while noting that OTLP log export is handled by ServiceDefaults rather than a separate sink.
src/backend/MyProject.Infrastructure/Logging · high confidence
New CachingOptions configuration with validation and master switch
A new CachingOptions class has been introduced to manage caching behavior via the 'Caching' configuration section. It includes a master Enabled switch (defaulting to true) that allows users to disable caching entirely, registering a no-op implementation when false. The configuration also exposes a DefaultExpiration setting (defaulting to 10 minutes) which is now validated to ensure it is greater than zero, preventing invalid cache entry lifetimes.
src/backend/MyProject.Infrastructure/Caching/Options · high confidence
New account deletion request validation
The system now enforces specific validation rules for the account deletion request, requiring the user's password to be between 6 and 255 characters long. This ensures that account deletion is confirmed with a valid password that meets the application's security standards.
src/backend/MyProject.WebApi/Features/Users/Dtos/DeleteAccount · high confidence
New health checks, rate limiting, security headers, and hosting configuration
The backend now exposes dedicated health check endpoints (/health, /health/ready, /health/live) that verify PostgreSQL connectivity and optionally degrade gracefully if S3 storage is unreachable. Rate limiting is enforced via fixed-window policies partitioned by IP or authenticated user, with specific per-endpoint limits for registration and authentication, returning standard ProblemDetails on rejection. Security response headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy) are added to all API responses to mitigate common browser-side attacks. Hosting infrastructure is hardened by trusting configured reverse proxy networks for forwarded headers and optionally forcing HTTPS, while CORS configuration now explicitly rejects 'AllowAllOrigins' in non-development environments to prevent credential-leaking misconfigurations.
src/backend/MyProject.WebApi/Extensions · high confidence
New route constraints for job IDs, provider names, and role names
The API now enforces stricter validation on URL route parameters through three new route constraints. Job identifiers are restricted to alphanumeric characters, dots, hyphens, and underscores with a maximum length of 100 characters. OAuth provider names must consist solely of letters and cannot exceed 32 characters. Role names must start with a letter, followed by letters, digits, hyphens, or underscores, with a maximum length of 50 characters, aligning with existing request validators.
src/backend/MyProject.WebApi/Routing · high confidence
OAuth callback handling with error display and account linking support
The OAuth callback route now processes authentication responses from external providers, handling success by redirecting to the dashboard, managing account linking flows by redirecting to settings, and displaying user-friendly error messages for issues like provider denial, missing parameters, or backend API errors.
src/frontend/src/routes/(public)/oauth · high confidence
OpenAPI specification generation and accuracy improvements
This change introduces a suite of OpenAPI document transformers to enhance the accuracy and consistency of the generated API specification. The BearerSecurityOperationTransformer now correctly applies bearerAuth security requirements to endpoints protected by AuthorizeAttribute, including inherited attributes. The CamelCaseQueryParameterTransformer ensures query parameters are camelCase to match JSON serialization and propagates schema descriptions to parameters. The CleanupDocumentTransformer removes redundant content types and strips response bodies from HEAD operations for RFC compliance. The EnumSchemaTransformer ensures enums are represented as string enums with all members listed, while the NumericSchemaTransformer fixes numeric types that were incorrectly flagged as strings. Additionally, the ProblemDetailsSchemaTransformer documents the machine-readable error code extension, and the ProjectDocumentTransformer sets the API metadata and describes the dual authentication support (Bearer tokens and cookies).
src/backend/MyProject.WebApi/Features/OpenApi/Transformers · high confidence
Redesigned authentication UI with two-factor and CAPTCHA support
The authentication interface has been completely rebuilt using a new \AuthShell\ layout component that provides a consistent branded frame for all auth flows. This update introduces a full two-factor authentication (2FA) experience, including a dedicated step for entering TOTP codes or recovery codes, and integrates Cloudflare Turnstile CAPTCHA into the registration and forgot-password forms to prevent abuse. The login form now supports a 'remember me' option and handles 2FA challenges seamlessly, while the registration flow includes draft saving to local storage and OAuth provider buttons. Additionally, the email verification process is improved with a dismissable banner that allows users to request a new verification email with a cooldown timer.
src/frontend/src/lib/components/auth · high confidence
Redesigned visual theme and modularized frontend styling architecture
The frontend styling system has been restructured into a modular architecture (base, animations, themes, utilities) and features a completely redesigned color palette optimized for comfortable light and dark modes. The new theme uses a warm stone-neutral base with slate-blue accents, replacing previous harsh contrasts with softer tones for extended use. This update introduces new visual capabilities, including ambient glow effects for panels, interactive card hover states, and subtle dot-grid patterns, alongside specific animation utilities for authentication transitions, OTP input cursors, and status indicators. Accessibility is maintained through respect for reduced-motion preferences across all new animations and transitions.
src/frontend/src/styles · high confidence
Refined database schema and configuration for authentication entities
The authentication infrastructure's database mapping has been updated to support more granular role management, secure external provider storage, and enhanced session handling. New EF Core configurations define the structure for roles (including system flags and permission grants), email verification tokens, and OAuth external auth states. Refresh token handling has been improved by removing the unused JWT ID column, adding a 'Persistent' flag for remember-me functionality, and indexing the UserId for faster lookups. Additionally, a new configuration for encrypted external provider credentials enables database-backed OAuth setup, while two-factor challenge tokens are now explicitly tracked with expiration and usage indices.
src/backend/MyProject.Infrastructure/Features/Authentication/Configurations · high confidence
Repository interface moved to backend and updated dependencies
The IBaseEntityRepository interface has been relocated from the root src directory to the src/backend/MyProject.Application/Persistence folder. Additionally, the interface's dependencies were adjusted to remove the direct reference to the MyProject.Domain namespace in favor of MyProject.Domain.Entities and MyProject.Shared, and a reference to the backend-conventions skill documentation was added to the remarks.
src/backend/MyProject.Application/Persistence · high confidence
Standardized API error handling and backend availability monitoring
The frontend API layer now uses a unified error-handling system based on RFC 9457 ProblemDetails, replacing ad-hoc error parsing. This introduces a typed \browserClient\ (via openapi-fetch) with middleware support, a \backend-monitor\ that detects 502/503 responses to trigger a global offline state, and a \handleMutationError\ utility that standardizes user feedback for rate limits (429 with Retry-After cooldowns), validation errors (422 with field mapping), and generic failures. Machine-readable error codes are extracted for translation, and auto-generated OpenAPI types (\v1.d.ts\) ensure type safety for API responses.
src/frontend/src/lib/api · high confidence
Standardized error responses and hardened API validation
The API now provides consistent, machine-readable error codes in all ProblemDetails responses via the new ProblemFactory, ensuring clients can reliably handle errors without parsing human-readable text. Additionally, pagination request parameters are now strictly validated with range constraints (PageNumber ≥ 1, PageSize between 1 and 100), and response properties are made immutable using init-only setters to prevent accidental mutation. Shared constants for rate limiting policies and phone number validation have also been introduced to enforce stricter security controls.
src/backend/MyProject.WebApi/Shared · high confidence
Strict security permissions and automated guardrails for Claude Code
The project now enforces a deny-by-default security model for the Claude Code agent, explicitly blocking access to sensitive files (such as .env, .pem, and .key files) and dangerous operations (including force pushes, privileged Docker runs, and secret API mutations). To support safe development, the setup includes lifecycle hooks that automatically check prerequisites on startup, validate bash commands to prevent destructive actions, and auto-format code after edits. Additionally, the configuration registers official LSP plugins and vendor skill packs from Microsoft and Svelte, while providing a local settings example for users to customize permissions without modifying the core security rules.
.claude · high confidence
Structured authentication configuration with validation
The application now uses strongly-typed, sealed configuration classes (AuthenticationOptions, ExternalAuthOptions) to manage JWT, refresh token, TOTP, and OAuth settings. These options enforce strict validation rules at startup, including a minimum 64-character JWT signing key, bounded lifetimes for access and refresh tokens, and safe URI schemes for OAuth redirects. External provider credentials are now managed via the database rather than appsettings, with encryption keys protected by HKDF-SHA256.
src/backend/MyProject.Infrastructure/Features/Authentication/Options · high confidence
Structured error handling with machine-readable codes and PII masking
The shared backend layer now enforces structured error responses and data privacy. Error handling has shifted from plain text messages to a typed system using the \Error\ record (containing a stable, snake\_case \Code\ and \Message\) and the \ErrorType\ enum (mapping failures to HTTP status codes like 400, 401, 403, 404). The \Result\ type has been refactored to carry these structured errors, ensuring clients can branch on stable codes rather than parsing English text. Additionally, a new \PiiMasker\ utility is provided to mask personally identifiable information (such as email addresses and phone numbers) before it is exposed in admin views or logs, and a \PhoneNumberHelper\ normalizes phone inputs for consistent storage.
src/backend/MyProject.Shared · high confidence
Switch to HybridCache with optional master switch
The caching infrastructure now uses the new HybridCache API instead of the previous Redis-based implementation. A new configuration option allows users to disable caching entirely via a master switch; when disabled, the system uses a no-op implementation that bypasses all cache operations and calls the underlying data factories directly.
src/backend/MyProject.Infrastructure/Caching/Extensions · high confidence
Transparent session refresh and improved error handling in authentication
The frontend authentication library now automatically handles expired access tokens by refreshing them via a new middleware, allowing users to remain logged in without interruption when using idempotent requests (GET, HEAD, OPTIONS). It also introduces structured error reporting to distinguish between unauthenticated states and backend unavailability, and ensures a clean redirect to the login page upon logout even if the logout request fails.
src/frontend/src/lib/auth · high confidence
Validation rules added for role creation and update requests
The API now enforces specific validation rules for role management endpoints. When creating a role, the name is required, must start with a letter, contain only alphanumeric characters, hyphens, or underscores, and be limited to 50 characters, while the description is optional but capped at 200 characters. For updates, at least one field (name or description) must be provided; if a name is supplied, it undergoes the same format and length checks as creation, and the description remains optional with a 200-character limit.
src/backend/MyProject.WebApi/Features/Admin/Dtos/CreateRole, src/backend/MyProject.WebApi/Features/Admin/Dtos/UpdateRole · high confidence
Fixes
Server-side layout for public routes handles backend errors and provides Turnstile key
A new server-side layout loader (+layout.server.ts) has been added to the public route group. It now explicitly checks for backend availability, throwing a 503 error with an i18n-compliant message if the backend is unavailable, and passes the Cloudflare Turnstile site key to the client for CAPTCHA integration.
src/frontend/src/routes/(public) · high confidence
Test coverage
Added architecture and unit test suites for backend; Added tests for Origin validation middleware and machine-readable error codes; Added tests for PII masking in admin user endpoints; Added tests for the BFF API proxy handler; Added unit tests for application identity constants and permission evaluation; Added unit tests for shared backend utilities; Added validation tests for API request models; Added validation tests for CORS and rate-limiting options; Comprehensive backend test suite added; Comprehensive backend test suite for API controllers; New test infrastructure for API integration testing.
Dependencies
Backend dependency overhaul and frontend migration to pnpm
The backend has been restructured to use centralized package version management via Directory.Packages.props, introducing several key library updates: Hangfire (1.8.24) for job scheduling, Fluid.Core (2.31.0) for email templates, and Microsoft.Extensions.Caching.Hybrid (10.9.0) replacing previous caching implementations. Security is addressed by pinning Newtonsoft.Json to 13.0.4 to mitigate [CVE redacted] and updating MailKit to 4.17.0. The frontend has migrated from npm to pnpm (10.34.5), updating the SvelteKit ecosystem (Svelte 5.56.9, Kit 2.70.2) and adding Vitest (4.1.10) for testing.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 50 → 49 (-1.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 89 → 84 (-5.2)
- Architecture 81 → 75 (-6.7)
- Maturity 70 → 72 (+1.7)
- Readiness 35 → 33 (-2.3)
- Security 66 → 64 (-2.3)
- Accessibility 54 → 54 (+0.0)
- Performance 68 → 67 (-0.3)
Resolved (92)
- Boundary-crossing change coupling: UserManagementCard.svelte ↔ +page.svelte (src/frontend/src/lib/components/admin/UserManagementCard.svelte)
- Bounded contexts not declared
- Change coupling: AdminController.cs ↔ UsersController.cs (src/backend/MyProject.WebApi/Features/Admin/AdminController.cs)
- Change coupling: AuthController.cs ↔ UsersController.cs (src/backend/MyProject.WebApi/Features/Authentication/AuthController.cs)
- Change coupling: AvatarDialog.svelte ↔ DeleteAccountDialog.svelte (src/frontend/src/lib/components/profile/AvatarDialog.svelte)
- Change coupling: ChangePasswordForm.svelte ↔ DeleteAccountDialog.svelte (src/frontend/src/lib/components/settings/ChangePasswordForm.svelte)
- Change coupling: ForgotPasswordForm.svelte ↔ ResetPasswordForm.svelte (src/frontend/src/lib/components/auth/ForgotPasswordForm.svelte)
- Change coupling: LoginForm.svelte ↔ ProfileForm.svelte (src/frontend/src/lib/components/auth/LoginForm.svelte)
- Change coupling: ProfileForm.svelte ↔ ChangePasswordForm.svelte (src/frontend/src/lib/components/profile/ProfileForm.svelte)
- Change coupling: ProfileForm.svelte ↔ DeleteAccountDialog.svelte (src/frontend/src/lib/components/profile/ProfileForm.svelte)
- Change coupling: UsersController.cs ↔ ExceptionHandlingMiddleware.cs (src/backend/MyProject.WebApi/Features/Users/UsersController.cs)
- Critical CVE: [GHSA redacted] (src/frontend/pnpm-lock.yaml)
- Duplicated block (12 lines × 3) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
- Duplicated block (13 lines × 3) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/GitLabAuthProvider.cs)
- Duplicated block (16 lines × 9) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/AppleAuthProvider.cs)
- Duplicated block (19 lines × 7) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/AppleAuthProvider.cs)
- Duplicated block (9 lines × 2) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/AuthenticationService.cs)
- Duplicated block (9 lines × 5) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/FacebookAuthProvider.cs)
- High CVE: [GHSA redacted] (src/frontend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (src/frontend/pnpm-lock.yaml)
- …and 72 more
New (89)
- Documentation: no installation or build instructions (README.md)
- Documentation: written for insiders (docs/sessions/2026-03-14-favicons-and-seo-fundamentals.md)
- Documentation: written for insiders (docs/sessions/2026-03-14-startup-migration-retry.md)
- Duplicated block (10 lines × 5) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/FacebookAuthProvider.cs)
- Duplicated block (11 lines × 4) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/AuthenticationService.cs)
- Duplicated block (12 lines × 2) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
- Duplicated block (12 lines × 4) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
- Duplicated block (13 lines × 2) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/AuthenticationService.cs)
- Duplicated block (13 lines × 2) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalAuthService.cs)
- Duplicated block (13 lines × 3) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
- Duplicated block (14 lines × 2) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
- Duplicated block (14 lines × 3) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/GoogleAuthProvider.cs)
- Duplicated block (14 lines × 3) (src/backend/MyProject.Infrastructure/Identity/Services/UserService.cs)
- Duplicated block (15 lines × 2) (src/backend/MyProject.WebApi/Extensions/RateLimiterExtensions.cs)
- Duplicated block (15 lines × 3) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/GitLabAuthProvider.cs)
- Duplicated block (17–19 lines × 9) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/AppleAuthProvider.cs)
- Duplicated block (18–19 lines × 2) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/GitHubAuthProvider.cs)
- Duplicated block (19 lines × 2) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
- Duplicated block (20–21 lines × 9) (src/backend/MyProject.Infrastructure/Features/Authentication/Services/ExternalProviders/AppleAuthProvider.cs)
- Duplicated block (21–22 lines × 2) (src/backend/MyProject.Infrastructure/Features/Admin/Services/AdminService.cs)
- …and 69 more
Changes since last survey
- 12 commits — 8 feature/other, 4 fixes
By area
- src/backend — 5 commits
- .claude/skills — 2 commits
- src/frontend — 2 commits
- (root) — 1 commit
- .claude/README.md — 1 commit
- docs/sessions — 1 commit
Notable commits
- fix: fix(auth): harden auth flows per security audit (#532)
- fix: fix(claude): narrow docker and gh api permissions, deny secret reads (#531)
- fix: fix(frontend): buffer proxied bodies so 401 responses pass through (#525)
- fix: fix(init): make init.ps1 survive real Windows environments (#536)
- change: chore(backend): bump Aspire.AppHost.Sdk to 13.4.6 (#524)
- change: chore(claude): audit and optimize the agentic coding setup (#529)
- change: chore: update all dependencies to latest (NuGet, npm, Actions, Node 24) (#523)
- change: feat(claude): add polish-ui composite design skill
- change: feat(email): deliver transactional emails via Hangfire jobs (#527)
- change: feat: add machine-readable error codes to ProblemDetails (#526)
- change: refactor(auth): data-driven role model with wildcard permissions (#528)
- change: style(auth): premium polish for auth shell brand panel (#535)
API surface
- Unchanged — 56 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
fpindej/netrock was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit dbc6b49844d9095ef96b6492ae9ba304ea3c3c2c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.