Skip to content
CAI
Software that uses CAICheck a score

GSabadini/golang-clean-architecture

58.4

Adequate · 21 September 2026

2.6k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based financial service built on Clean Architecture, designed to manage user accounts and process monetary transfers. It exposes an HTTP API for creating users and initiating transfers, while enforcing strict domain validation through immutable value objects for amounts, currencies, and identifiers. The backend persists data in MongoDB and coordinates external authorizations and notifications via RabbitMQ, incorporating resilience patterns like circuit breakers and retries for external service calls.

Features

Add HTTP server entry point with user and transfer endpoints

The application now exposes an HTTP server that listens on the port defined by the APP\_PORT environment variable. This server provides a health check endpoint at /health, user management endpoints (POST /users, GET /users/{user\_id}), and a transfer endpoint (POST /transfers). The server initializes dependencies for MongoDB, logging, routing, and RabbitMQ, and wires up the necessary use cases and handlers for these operations.

infrastructure · high confidence

Add RabbitMQ queue handler implementation

Introduces a new RabbitMQ handler in the queue infrastructure package, providing a concrete implementation for connecting to RabbitMQ via the RABBITMQ\_URI environment variable, declaring a 'notify' queue, and exposing the connection, channel, and queue objects for use by other components.

infrastructure/queue · high confidence

Added MongoDB integration and refactored in-memory repository

This change introduces a new MongoDB client handler (\infrastructure/database/mongodb.go\) for connecting to a MongoDB database, alongside a refactored in-memory repository (\infrastructure/database/in\_memory.go\) that was moved from the adapter layer. The in-memory implementation now exposes \Create\ instead of \Save\, returns the created entity, and uses value objects (e.g., \user.ID()\, \user.Wallet()\) instead of direct field access. Additionally, a new \TransferInMen\ in-memory store is added, and logger infrastructure files (\dummy.go\, \logrus.go\) are introduced to support structured logging.

infrastructure/logger · high confidence

Added presenter adapters for user and transfer operations

New presenter implementations have been added to the adapter layer to map domain entities to use-case output structures. This includes \createTransferPresenter\ for formatting transfer creation responses, \createUserPresenter\ for handling both common and merchant user creation outputs (including document, wallet, and role details), and \findUserByIDPresenter\ for retrieving user details by ID. Corresponding unit tests verify that these presenters correctly transform entity data into the expected output formats.

adapter/presenter · high confidence

Domain value objects now enforce validation and immutability

The \domain/vo\ package has been refactored to replace simple string aliases with structured Value Objects that enforce domain rules at creation time. Key changes include: \Amount\ now rejects negative values; \Uuid\, \Email\, \CPF\, and \CNPJ\ validate formats via regex and return errors on invalid input; \Currency\ is restricted to 'BRL' and 'USD'; \Document\ delegates validation to specific CPF/CNPJ logic; and \Money\ now encapsulates both \Amount\ and \Currency\ with arithmetic operations (\Add\, \Sub\). Additionally, \interface.go\ was renamed to \value.go\ and simplified to remove the \fmt.Stringer\ requirement, while \name.go\ was removed in favor of \full\_name.go\.

domain/vo · high confidence

Implemented HTTP-based transfer authorization and notification adapters

The HTTP adapter now includes functional implementations for transfer authorization and notification. The new \authorizer\_transfer.go\ component validates transfers by calling an external service defined by the \AUTHORIZER\_URI\ environment variable, returning an authorization error if the service does not respond with 'Autorizado'. The \notifier\_transfer.go\ component handles post-transfer notifications by calling a service defined by \NOTIFY\_URI\; if this call fails or returns an unexpected response, the system falls back to publishing an error message to a message queue via the new \queue.Producer\ implementation. Stub implementations for HTTP and logging have been added to support unit testing of these new components.

adapter/http · high confidence

Initial HTTP API handlers and middleware for user and transfer operations

This change introduces the HTTP adapter layer for the application, adding handlers for creating users, creating transfers, and finding users by ID. It includes a correlation ID middleware to propagate request identifiers, standardized JSON response structures for both success and error cases, and comprehensive unit tests for all new handlers and middleware to ensure correct input validation and error handling.

adapter/api · high confidence

Initial project structure and Dockerized deployment setup

The repository has been initialized with a Go Clean Architecture codebase, including the core application logic, domain entities, and HTTP server infrastructure. To facilitate local development and testing, the project now includes a Dockerfile (upgraded to Go 1.21), a docker-compose.yml file that orchestrates the application with a MongoDB replica set (primary, secondary, arbiter) and a RabbitMQ service, and a Makefile with commands for building, testing, and running the stack. An .env.example file provides the necessary configuration for external services like the authorizer and notifier.

(repo-wide) · high confidence

Initial setup of HTTP router and infrastructure scripts

This change introduces the core HTTP routing infrastructure and supporting initialization scripts. It adds a new router package (infrastructure/router) defining a Router interface and a Mux implementation based on gorilla/mux, which includes a correlation ID middleware and configurable read/write timeouts. Additionally, it provides MongoDB initialization scripts to create the 'challenge' database with unique indexes on user document types and emails, and a RabbitMQ configuration file that enables guest user access from non-loopback interfaces. A reflex configuration file is also moved into the \_scripts directory.

_\scripts, infrastructure/router · high confidence

Introduce HTTP client with circuit breaker and retry support

Added a new HTTP infrastructure layer that provides a configurable HTTP client. This includes a circuit breaker to prevent cascading failures and a retry mechanism with exponential backoff to handle transient errors. Users can now configure request timeouts, specify retry attempts, and define which HTTP status codes should trigger a retry.

infrastructure/http · high confidence

MongoDB repository adapters for user and transfer operations

The adapter/repository layer now provides concrete implementations for persisting and retrieving user and transfer data using MongoDB. New files implement the repository interfaces for creating users and transfers, finding users by ID, and updating user wallets. These adapters handle BSON serialization, map domain entities to database structures, and manage database interactions via the MongoHandler, including support for transactions in transfer operations.

adapter/repository · high confidence

Removals

Removal of in-memory database implementation

The in-memory database implementation has been removed from the infrastructure layer, eliminating the \InMemory\ struct that was previously available for database interactions.

infrastructure/db · high confidence

Removal of incomplete database repository implementations

The adapter/db layer has removed the stubbed repository implementations for Transfer, TransferInMen, and User. These files previously contained placeholder logic (such as panic calls or in-memory storage) that did not provide functional database access, effectively cleaning up the codebase by eliminating these non-functional components.

adapter/db · high confidence

Architecture

Refactor User and Transfer entities to use Value Objects and explicit repository interfaces

The User and Transfer domain entities have been refactored to encapsulate internal state using private fields with public accessor methods, replacing the previous public struct fields. The User entity now distinguishes between Common and Merchant types via a Roles struct that controls transfer permissions, and its wallet is managed through a dedicated Value Object rather than a raw Money type. Repository contracts have been split into specific interfaces (Creator, Finder, Updater) to define granular operations, and the import path has been updated to reflect the project's canonical module name.

domain/entity · high confidence

Refactored use cases to use structured input/output and presenter ports

The use case interactors (create user, create transfer, find user by ID) have been refactored to adopt a cleaner port-and-adapter pattern. Instead of passing raw domain entities or primitive arguments, they now accept structured input structs (e.g., CreateTransferInput, CreateUserInput) and return structured output structs (e.g., CreateTransferOutput, CreateUserOutput) via dedicated presenter interfaces. This change decouples the business logic from direct domain entity manipulation, standardizes the API surface for each use case, and improves testability by allowing easy stubbing of presenters and repositories in the new test files.

usecase · high confidence

Dependencies

Upgrade Go version and update dependencies

The project has upgraded its Go version from 1.13 to 1.21 and updated its module path. Several dependencies have been added or updated, including the MongoDB driver (v1.13.0), RabbitMQ client (v1.1.0), and various standard library extensions like crypto and sync.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 59 → 58 (-0.5)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 100 (+0.2)
  • Architecture 100 → 77 (-23.4)
  • Maturity 65 → 65 (+0.0)
  • Readiness 33 → 40 (+6.6)
  • Security 97 → 91 (-6.6)

Resolved (9)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (13 lines × 2) (adapter/api/handler/create_transfer.go)
  • Duplicated block (6 lines × 2) (adapter/presenter/create_transfer.go)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness

New (28)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Deprecated module: github.com/streadway/amqp
  • Deprecated module: go.mongodb.org/mongo-driver
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (adapter/api/handler/create_transfer.go)
  • Duplicated block (30 lines × 2) (adapter/api/handler/create_transfer.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2024-3105 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • …and 8 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

GSabadini/golang-clean-architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ac81adf1a7c67df10aefe4b0e1495368903e1550 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.