gbrayhan/microservices-go
68.7
Adequate · 21 September 2026
2.8k
lines of production code
Go
primary language
4
measurements over time
What this system is
This release marks a significant architectural shift from a legacy, template-based UI to a modern REST API structure built on a clean architecture. The backend has been refactored to use a centralized dependency injection container, environment-variable configuration, and structured error handling, while the frontend has been stripped of obsolete assets and templates. New features include full CRUD and search capabilities for Medicine and User domains, alongside a robust authentication system with JWT token management. The release also introduces comprehensive integration testing and updates core Go dependencies.
Features
Add JWT service for token generation and verification
A new JWT service has been introduced in the security infrastructure, providing capabilities to generate and verify access and refresh tokens. The implementation uses the golang-jwt library, supports configurable expiration times and secret keys via environment variables, and includes comprehensive unit tests covering token generation, verification, and error handling.
src/infrastructure/security · high confidence
Added PostgreSQL repository implementation with database initialization and user seeding
The new \psql\_repository.go\ file introduces the \PSQLRepository\ struct and its methods, enabling the application to connect to a PostgreSQL database using environment variables for configuration. The implementation includes logic to load database credentials, establish a GORM connection with Zap-based logging, and perform automatic schema migrations for \User\ and \Medicine\ entities. Additionally, it provides functionality to seed an initial admin user from environment variables, hashing the password with bcrypt before creation.
src/infrastructure/repository/psql · high confidence
Added PostgreSQL repository implementations for Medicine and User entities
New repository implementations for the Medicine and User domains have been introduced, each providing full CRUD operations (Create, Read, Update, Delete) and search capabilities via the GORM ORM. These repositories map domain entities to database tables (medicines, users) and include corresponding unit tests to verify data access logic.
src/infrastructure/repository/psql/user · high confidence
Centralized dependency injection and test scaffolding for application context
The application now uses a centralized \ApplicationContext\ struct in \src/infrastructure/di\ to manage all dependencies, including controllers, use cases, repositories, and services. This change introduces a \SetupDependencies\ function to wire up the database, JWT service, and all business logic components, while also providing a \NewTestApplicationContext\ helper to inject mock repositories for testing. The addition of these files establishes a clear, single point for retrieving and configuring application services, improving testability and dependency management.
src/infrastructure/di · high confidence
Domain models and interfaces for medicine and user entities
The domain layer now includes structured models and service interfaces for both medicine and user entities. The medicine module defines the \Medicine\ struct with fields for ID, name, description, EAN code, laboratory, and timestamps, alongside a \DataMedicine\ wrapper for paginated search results. The user module similarly defines a \User\ struct with identity, contact, and status fields, plus a \SearchResultUser\ for search results. Both modules introduce corresponding service interfaces (\IMedicineService\ and \IUserService\) that specify methods for retrieval, creation, deletion, and update operations, establishing the core data contracts for these domains.
src/domain/medicine · high confidence
Implemented login and token refresh use cases
Added the AuthUseCase which implements the Login and AccessTokenByRefreshToken workflows. The Login method validates user credentials against the database, verifies the password hash, and generates access and refresh JWTs. The AccessTokenByRefreshToken method validates the refresh token and issues a new access token. Both methods include structured logging and error handling.
src/application/usecases/auth · high confidence
Introduce new Medicine REST controller with full CRUD and validation
A new REST controller for the Medicine domain has been added, exposing endpoints for creating, retrieving, updating, and deleting medicines, as well as paginated search and property-based search. The controller implements input validation for update requests and includes corresponding unit tests with a mock service.
src/infrastructure/rest/controllers/medicine · high confidence
Introduces structured application error handling with HTTP status mapping
A new error handling module has been added to the domain layer, defining specific error types such as NotFound, ValidationError, and NotAuthorized. The system now maps these application errors to corresponding HTTP status codes (e.g., 404, 400, 401, 403, 500) via a dedicated conversion function, providing consistent and structured error responses for API consumers.
src/domain/errors · high confidence
Introduction of a centralized logging infrastructure
A new logging subsystem has been added to the application, providing a unified way to handle logs across the codebase. This includes a core Logger struct wrapping the Zap library for structured JSON output, with specific adapters for the Gin web framework (capturing HTTP request metrics and standard error streams) and the GORM database ORM (capturing SQL queries and errors). This change introduces the capability to route all application logs through a single, configurable logger.
src/infrastructure/logger · high confidence
Medicine use-case layer with full CRUD and search capabilities
Added the application-layer implementation for the Medicine domain, providing a complete set of operations: GetByID, Create, Delete, Update, GetAll, SearchPaginated, and SearchByProperty. The new \MedicineUseCase\ struct delegates to the repository layer and integrates structured logging via the \zap\ logger. A corresponding test file (\medicine\_test.go\) was also added to verify the use-case logic against a mock repository.
src/application/usecases/medicine, src/application/usecases/user · high confidence
New auth controller with structured login and token refresh endpoints
The authentication layer now exposes structured login and access-token-refresh endpoints. Users can log in with email and password to receive JWT access and refresh tokens, and subsequently use the refresh token to obtain a new access token. The controller integrates with the application use cases and includes comprehensive unit tests for both success and error scenarios.
src/infrastructure/rest/controllers/auth · high confidence
New middleware infrastructure for REST API
The REST layer now includes a comprehensive set of new middleware components to handle cross-origin headers, request logging, authentication, and error handling. The \Headers\ middleware was moved and updated to include \c.Next()\. A new \Interceptor\ middleware was added to log request and response bodies for debugging. The \RequiresLogin\ middleware enforces JWT authentication, validating tokens, expiration, and token type. An \ErrorHandler\ middleware was introduced to catch domain errors and map them to appropriate HTTP status codes and JSON error responses. All new middleware files include corresponding unit tests to verify their behavior.
src/infrastructure/rest/middlewares · high confidence
New user REST controller with validation and logging
A new user controller has been introduced in the REST infrastructure layer, implementing CRUD operations (create, read, update, delete) and search capabilities. The controller integrates structured logging via the project's logger and enforces input validation using the go-playground/validator library, ensuring that user requests meet specific format and length requirements before processing.
src/infrastructure/rest/controllers/user · high confidence
New utility functions for JSON binding and pagination
The REST controllers layer now includes new helper functions for handling HTTP request bodies and pagination. A new BindTools.go file provides utilities to safely read and bind JSON from Gin context requests, along with request data structures (MessageResponse, SortByDataRequest, FieldDateRangeDataRequest). Additionally, a new Utils.go file introduces a PaginationValues helper to calculate page counts and cursor positions for paginated responses. These changes support cleaner controller logic by centralizing common binding and pagination logic.
src/infrastructure/rest/controllers · high confidence
Removals
Removal of legacy frontend assets
The static CSS and JavaScript files for the admin panel, login page, and medication management interface have been deleted. This includes styles for the admin dashboard, login form, and medication search/editing features, as well as the associated JavaScript logic for AJAX requests and UI interactions. Users will no longer have access to these specific frontend components, which appear to be replaced by a new template or microservice architecture.
public · high confidence
Behavioural changes
Migrated configuration from JSON to environment variables
The application configuration has been migrated from a JSON file (config.json.example) to environment variables, with new .env.example and .env.local files providing default values for database, server, JWT, and other settings. This change simplifies environment-specific configuration and improves security by avoiding hardcoded secrets in configuration files.
(repo-wide) · high confidence
Refactored REST route structure and added Medicine endpoints
The REST route definitions have been reorganized into separate files (medicine.go, user.go, auth.go) to improve code structure. The previous ApplicationV1.go file was renamed to auth.go and updated to use dependency injection for the AuthController. New endpoints for the Medicine domain have been added, including GET/POST/PUT/DELETE for all medicines and specific CRUD operations, as well as search endpoints. The application router now explicitly wires up the Medicine routes alongside existing User and Auth routes.
src/infrastructure/rest/routes · high confidence
Removal of PDF generation and MD5 utility functions
The 'tools' package has been refactored by removing the 'CreatePDF.go' and 'Tools.go' files. This eliminates the ability to generate PDFs using the 'go-wkhtmltopdf' library and removes the 'GetMD5Hash' utility function, indicating a shift away from these specific capabilities in the application.
tools · high confidence
Removal of legacy login middleware
The \RequiresLogin\ middleware has been removed from the application. This change eliminates the previous login-checking logic, likely as part of a broader architectural shift or refactoring of authentication handling within the project.
middlewares · high confidence
Removed ExampleAction controller
The ExampleAction controller has been removed from the application. This eliminates the associated request handling and validation logic for that endpoint.
controllers · medium confidence
Removed empty .docker directory placeholder
The empty .gitkeep file within the .docker directory has been removed. This cleanup eliminates an empty directory that previously served only as a placeholder for version control.
.docker · high confidence
Removed legacy database connection and response handling models
The legacy database connection implementation (DataBaseSQL.go), the ExampleElement model, and the ResponseBase response handler have been removed from the models package. This change eliminates the previous manual SQL connection management and custom response formatting, likely as part of a broader migration to a new ORM or database abstraction layer.
models · high confidence
Removed legacy view templates and layout files
The following view templates have been removed from the application: the generic modal layout, the admin dashboard template, the login page template, the medication management template, and the main menu template. These deletions indicate a shift away from the previous template-based UI structure.
views · high confidence
Removed obsolete archive placeholders and documentation
The archives directory has been cleaned up by removing placeholder files (.gitkeep) in the layouts and tmp folders, as well as the README.md file in the upload/cargaS3 folder. These files were likely remnants of an earlier project structure or template and are no longer needed.
archives · high confidence
Test coverage
Added integration test runner script; Added integration test suite for API endpoints; Added integration tests for authentication, medicine, and user management APIs.
Dependencies
Updated Go dependencies and tooling
The project's Go module dependencies have been updated, including the Go version to 1.24.2 and various libraries such as gin, gorm, and crypto. This ensures the application uses the latest stable versions of its core dependencies.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 70 → 69 (-1.4)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 91 → 93 (+1.9)
- Architecture 100 → 74 (-25.9)
- Maturity 69 → 72 (+2.9)
- Readiness 68 → 64 (-4.8)
- Security 64 → 68 (+4.0)
- Domain Modelling 100 → 100 (+0.0)
Resolved (26)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (src/infrastructure/di/application_context.go)
- Duplicated block (10 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (10 lines × 2) (src/infrastructure/rest/controllers/medicine/Medicines.go)
- Duplicated block (13 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (15 lines × 2) (src/infrastructure/logger/logger.go)
- Duplicated block (15 lines × 2) (src/infrastructure/rest/controllers/medicine/Medicines.go)
- Duplicated block (16 lines × 2) (src/infrastructure/rest/controllers/auth/Auth.go)
- Duplicated block (16 lines × 2) (src/infrastructure/rest/controllers/medicine/Validation.go)
- Duplicated block (17 lines × 2) (src/infrastructure/rest/controllers/medicine/Medicines.go)
- Duplicated block (18 lines × 2) (src/infrastructure/rest/controllers/medicine/Medicines.go)
- Duplicated block (20 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2025-3749 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- …and 6 more
New (60)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Duplicated block (10 lines × 2) (src/infrastructure/di/application_context.go)
- Duplicated block (11 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (11 lines × 2) (src/infrastructure/rest/controllers/medicine/Medicines.go)
- Duplicated block (12 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (12 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (12 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (12 lines × 2) (src/infrastructure/rest/controllers/medicine/Medicines.go)
- Duplicated block (13 lines × 2) (src/infrastructure/rest/controllers/medicine/Validation.go)
- Duplicated block (17 lines × 2) (src/infrastructure/rest/controllers/medicine/Medicines.go)
- Duplicated block (18 lines × 2) (src/infrastructure/logger/logger.go)
- Duplicated block (19 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (19 lines × 2) (src/infrastructure/rest/controllers/medicine/Validation.go)
- Duplicated block (20 lines × 2) (src/infrastructure/rest/controllers/auth/Auth.go)
- Duplicated block (33 lines × 2) (src/infrastructure/rest/controllers/medicine/Medicines.go)
- Duplicated block (5 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (6 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (6 lines × 2) (src/infrastructure/repository/psql/medicine/medicine.go)
- Duplicated block (6 lines × 2) (src/infrastructure/rest/controllers/auth/Auth.go)
- …and 40 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
gbrayhan/microservices-go was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b63ba3de1132c6461359ac70ebbbec64e99bf128 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.