Skip to content
CAI
Software that uses CAICheck a score

Gramli/AuthApi

57.1

Adequate · 21 September 2026

1.4k

lines of production code

C#

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an authentication and user management service built with .NET 10 and Angular 21. It provides backend APIs for user registration, login, and role-based access control using JWT and Basic authentication, backed by an in-memory database. The application includes an Angular frontend that allows users to manage their profiles and enables administrators to oversee user accounts and permissions.

How it got here

2023 — Authentication API scaffolding

7 changes.

The project established the foundational structure for an authentication service by introducing the Auth.Api, Auth.Core, and Auth.Infrastructure modules. This work implemented core features including JWT and Basic authentication, user management endpoints, and in-memory data storage, while initializing the .NET 10 and Angular 21 dependency stack.

2024–2025 — Initial project scaffolding and core features

5 changes.

This period established the foundational architecture of the authentication system, including the solution structure and core domain models. It introduced essential backend capabilities for user registration, login, role management, and basic authentication. An Angular frontend was also developed to provide a user interface for authentication and administrative tasks.

Features

Add Basic Authentication support

The API now supports HTTP Basic Authentication. This change introduces a new authentication scheme named "Basic" that validates credentials provided in the Authorization header against configured username and password options. Upon successful authentication, the user is assigned the Administrator role.

src/Auth.Api/BasicAuthentication · high confidence

Added service information endpoint

Users can now retrieve basic information about the Auth Service via a new query handler. This change introduces a ServiceInfoDto containing the service name and description, exposed through the GetServiceInfoQueryHandler which returns a static response identifying the application.

src/Auth.Core/UseCases/Service, src/Auth.Domain/UseCases/Service · high confidence

Core authentication service interfaces and validation wiring

The Auth.Core module now exposes the foundational abstractions and dependency-injection configuration for the authentication system. New interfaces define the contract for account operations (login, registration), user management (finding users, changing roles), token generation, and data retrieval for users and roles. To support these operations, the module registers the corresponding command and query handlers (Login, Register, ChangeRole, GetUsers, GetUserInfo, GetServiceInfo) in the service container and integrates Validot for input validation on registration, login, and role-change commands. Additionally, localized error messages for common authentication failures (invalid credentials, registration, role changes) are provided to ensure users receive clear feedback.

src/Auth.Core · high confidence

Initial Angular frontend for authentication and administration

The Auth.Frontend application has been introduced, providing a complete Angular-based user interface for the authentication system. Users can now log in, register, and manage their profile information through dedicated views. Administrators and developers gain access to a dashboard where they can view user details, list all users, and change user roles. The application utilizes PrimeNG for its UI components and implements role-based access control via route guards to restrict sensitive administrative features.

src/Auth.Frontend · high confidence

Initial authentication API scaffolding with middleware and configuration

The Auth.Api service is introduced with a new ASP.NET Core application structure. It configures JWT Bearer and Basic authentication schemes, defining token expiration, signing keys, valid audiences, and issuers in appsettings.json. The application pipeline includes CORS, Swagger UI (in development), exception logging, and a new ClaimsMiddleware that appends custom user data claims to authenticated requests. Endpoint builders for authentication, users, and services are wired up, along with default role and user initialization.

src/Auth.Api · high confidence

Initial user authentication and role management capabilities

This change introduces the core user management features for the application, including user registration, login, and role assignment. Users can now register with a username, password, and email, and log in to receive an authentication token. Administrators can change user roles, with validation ensuring that administrators cannot be reassigned to other roles or have their role changed by other administrators. The system also provides endpoints to retrieve information about the currently authorized user and a list of all users. These capabilities are supported by new domain models, command/query handlers, validation specifications, and infrastructure repositories for persisting user and role data.

src/Auth.Core/UseCases/User, src/Auth.Domain/UseCases/User, src/Auth.Infrastructure/UseCases/User · high confidence

Introduces authentication infrastructure with JWT and user management

The Auth.Infrastructure module now provides the backend implementation for user authentication and management. It introduces a new in-memory database schema for Users and Roles, along with repository interfaces for CRUD operations. User registration and login are handled via AccountService, which uses a custom PBKDF2-SHA256 password hasher for secure credential storage. Authentication is enforced through JWT tokens, with token generation, issuer, audience, and expiration configured via the application's configuration section. The infrastructure also includes a mechanism to seed default roles and an initial admin user upon startup.

src/Auth.Infrastructure · high confidence

New API endpoint builders for authentication, service info, and user management

This change introduces three new endpoint builder classes in the Auth.Api project that define the application's HTTP routes using the SmallApiToolkit. The AuthEndpointBuilder exposes login, register, and user info endpoints under the 'auth' group. The ServiceEndpointBuilder provides service info endpoints ('/info' and '/info-basic') with hourly response caching and specific authorization policies. The UserEndpointBuilder handles user management, including changing user roles, retrieving available roles, and listing user information, each secured with distinct authorization requirements (Administrator, Developer).

src/Auth.Api/EndpointBuilders · high confidence

New authentication, authorization, and API configuration infrastructure

This change introduces the core configuration classes for the Auth.Api service, establishing the foundation for security and API documentation. Authentication is configured to support both JWT Bearer tokens (validated via a symmetric key) and Basic Authentication (using configured username/password). Authorization policies are defined to restrict access to specific roles (User, Developer, Administrator) for JWT and require authentication for Basic auth. Additionally, the API now includes Swagger/OpenAPI documentation that exposes both security schemes, a response caching mechanism for endpoints, and dependency injection setup for the HTTP context accessor.

src/Auth.Api/Configuration · high confidence

Architecture

Introduction of .slnx solution file

A new .slnx solution file has been added to the src directory, defining the project structure for the Auth solution. This file explicitly lists the four core projects (Auth.Api, Auth.Core, Auth.Domain, and Auth.Infrastructure) and organizes test files within specific folder structures (Tests/Debug, Tests/SystemTests, Tests/UnitTests), establishing the foundational layout for the project's build and organization.

src · high confidence

Test coverage

Added HTTP debug file for API testing

A new HTTP debug file has been added to the test suite, providing pre-configured requests for key API endpoints including user registration, login, role management, and service information retrieval, facilitating easier manual and automated testing of the authentication and user management flows.

src/Tests · high confidence

Dependencies

Initial dependency setup for .NET 10 and Angular 21

The project initializes its dependency manifests, targeting .NET 10.0 for the backend services (Auth.Api, Auth.Core, Auth.Domain, Auth.Infrastructure) and Angular 21.2 for the frontend (Auth.Frontend). The backend adopts Central Package Management via Directory.Packages.props, pinning key libraries such as SmallApiToolkit 10.0.0, Mapster 10.0.12, and EF Core InMemory 10.0.12. The frontend locks in PrimeNG 21.1.9, PrimeFlex 4.0.0, and Vitest 4.1.8 for testing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 57 (-1.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 92 → 93 (+0.6)
  • Architecture 83 → 83 (+0.0)
  • Maturity 64 → 58 (-5.5)
  • Readiness 49 → 53 (+3.4)
  • Security 63 → 56 (-7.6)
  • Accessibility 64 → 63 (-1.2)

Resolved (37)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High: security finding (details withheld)
  • …and 17 more

New (62)

  • Coverage not measured — .NET and JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (9 lines × 2) (src/Auth.Infrastructure/Services/UserService.cs)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • High CVE: [GHSA redacted] (src/Auth.Frontend/package-lock.json)
  • …and 42 more

Changes since last survey

  • 2 commits — 2 feature/other, 0 fixes

By area

  • src/Directory.Packages.props — 2 commits

Notable commits

  • change: Bump the all-minor-patch group with 6 updates (#110)
  • change: Bump the all-minor-patch group with 8 updates (#109)

Architecture

  • Unchanged — 2 containers · 0 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Gramli/AuthApi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6a43a4a6e968e32bcd8f9e849e082923bfea7733 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.