Skip to content
CAI
Software that uses CAICheck a score

iammukeshm/CleanArchitecture.WebApi

55.2

Weak · 21 September 2026

1.9k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a .NET-based web API built on Clean Architecture principles, designed to manage product inventory and user accounts. It provides secure, authenticated endpoints for creating, reading, updating, and deleting products, alongside comprehensive user management features including registration, email verification, and password recovery. The architecture enforces separation of concerns through distinct layers, utilizing CQRS for command and query handling, while maintaining strict audit trails and role-based access control.

Features

Added CQRS command handlers and validators for product CRUD operations

Implemented the application layer for product management using the CQRS pattern. New command handlers handle Create, Update, and Delete operations for products, integrating with the repository layer. Validation rules enforce required fields, length limits, and unique barcodes using FluentValidation. The application service collection is extended to register AutoMapper, MediatR, and the validation pipeline behavior.

Application/Features/Products/Commands · high confidence

Added Clean Architecture WebAPI template configuration

Introduced the .template.config/template.json and template.vstemplate files that define the 'Clean Architecture WebAPI' project template. This adds the template metadata, including the identity, description, and primary output paths for the solution structure.

.template.config · high confidence

Added Metadata model class

A new Metadata class has been introduced in the WebApi/Models namespace. This change adds a placeholder model for metadata, which may be used to store or transfer metadata information in the API.

WebApi/Models · high confidence

Added Product CRUD endpoints with JWT authentication

A new ProductController has been introduced in the v1 API, exposing standard CRUD operations (Create, Read, Update, Delete) for products. The endpoints are secured with JWT authentication, requiring users to be authenticated for POST, PUT, and DELETE operations, while GET endpoints remain public. The controller integrates with a CQRS-based application layer, mapping requests to corresponding commands and queries.

WebApi/Controllers/v1 · medium confidence

Added account and email DTOs for authentication and registration

New data transfer objects were added to support account management features. This includes request and response models for authentication, registration, email verification, and password reset, as well as a model for sending emails and a base class for paginated requests. These changes enable the backend to handle user sign-up, login, and password recovery workflows.

Application/DTOs · high confidence

Added generic response and pagination wrappers

Added generic response and pagination wrapper classes to the application layer. The new \Response\<T\>\ and \PagedResponse\<T\>\ classes provide a standardized structure for API responses, including success status, messages, and data payload, while \PagedResponse\ specifically supports pagination metadata like page number and size.

Application/Wrappers · high confidence

Added initial database migration for the Products table

A new migration (20200724181511\_Updat) was added to the persistence layer, creating the 'Products' table in the database. The table includes columns for Id, Name, Barcode, Description, Rate, and audit fields (Created, CreatedBy, LastModified, LastModifiedBy). This establishes the initial schema for product data in the application's SQL Server database.

Infrastructure.Persistence/Migrations · high confidence

Added paginated product listing and single-product retrieval via CQRS queries

Users can now retrieve a paginated list of all products or fetch a specific product by its ID. The new GetAllProducts query supports pagination parameters (PageNumber, PageSize) and returns a PagedResponse containing a list of product view models (Id, Name, Barcode, Description, Rate). The GetProductById query retrieves a single product by ID, returning a standard Response with the product entity. These changes implement the read side of the product feature using the CQRS pattern with MediatR handlers.

Application/Features/Products/Queries · high confidence

Added product repository interface with unique barcode validation

A new IProductRepositoryAsync interface was added to the application layer, introducing an IsUniqueBarcodeAsync method to support unique barcode validation for products.

Application/Interfaces/Repositories · high confidence

Introduce generic repository with pagination and unique barcode validation

Added a new generic repository implementation (GenericRepositoryAsync) that provides standard CRUD operations and supports pagination via the GetAll method, which now accepts page number and size parameters. Additionally, the Product repository implements a new IsUniqueBarcodeAsync method that uses AllAsync to validate barcode uniqueness, replacing the previous AnyAsync approach.

Infrastructure.Persistence/Repositories · medium confidence

Introduces structured error handling, Serilog console logging, and Swagger UI for the WebApi

The WebApi project now includes a global error-handling middleware that catches exceptions and returns consistent JSON error responses for bad requests, validation errors, and not-found scenarios. Serilog is configured to write console logs, and the application seeds default roles and users at startup. Additionally, Swagger UI is enabled at /swagger to expose the API documentation, and an authenticated user service is registered to support identity-based operations.

WebApi · high confidence

New Identity infrastructure with custom database schema and JWT authentication

The Identity layer now uses a dedicated \IdentityContext\ with a custom 'Identity' schema, mapping tables such as 'User', 'Role', and 'UserRoles' to specific names. Authentication is handled via JWT tokens, with the \AuthenticationHelper\ and \ServiceExtensions\ configuring the bearer token validation and error handling. The system also includes seeding logic for default roles (SuperAdmin, Admin, Moderator, Basic) and initial user accounts (Basic User, Super Admin).

Infrastructure.Identity · high confidence

New account management and API infrastructure endpoints

The API now supports full account lifecycle management, including user registration, email confirmation, and password reset (forgot/reset password) via the new AccountController. A BaseApiController has been introduced to standardize API versioning and Mediator access, and a MetaController provides version and build metadata at the /info endpoint.

WebApi/Controllers · high confidence

New service and repository interfaces for account, email, and data access

The application layer introduces new interfaces to support authentication, user identity, date/time abstraction, email delivery, and generic data access. IAccountService defines methods for authentication, registration, email confirmation, and password reset. IAuthenticatedUserService exposes the current user's ID. IDateTimeService abstracts the current UTC time. IEmailService provides a method to send emails. IGenericRepositoryAsync defines standard CRUD operations and a paginated retrieval method for generic entities. These interfaces establish the contracts for these capabilities within the application layer.

Application/Interfaces · high confidence

Shared email and date-time services introduced

The shared infrastructure layer now registers and implements core services: an IEmailService that sends emails via SMTP with configurable display names and settings, and an IDateTimeService providing UTC time. These are wired up in the new ServiceRegistration class, making these capabilities available across the application.

Infrastructure.Shared · medium confidence

Behavioural changes

Added AutoMapper mappings for Product create and query operations

A new GeneralProfile class was added to the Application/Mappings directory, configuring AutoMapper mappings for the Product entity. Specifically, it defines mappings between the Product domain entity and the GetAllProductsViewModel, as well as between the CreateProductCommand and the Product entity. Additionally, it maps the GetAllProductsQuery to GetAllProductsParameter, supporting the pagination and filtering capabilities for the GetAll method.

Application/Mappings · medium confidence

Added Roles enum for default user roles

A new Roles enum has been added to the Application layer, defining SuperAdmin, Admin, Moderator, and Basic roles. This provides the foundational type for the system's default role-based access control, supporting the seeding of initial superadmin and basic user accounts.

Application/Enums · medium confidence

Automatic audit trail for entity changes

The new ApplicationDbContext now automatically tracks creation and modification metadata (timestamps and user IDs) for all entities inheriting from AuditableBaseEntity. When saving changes, the context populates Created, CreatedBy, LastModified, and LastModifiedBy fields based on the current user and time, ensuring consistent audit trails without manual intervention.

Infrastructure.Persistence/Contexts · high confidence

Configurable database persistence with in-memory and SQL Server support

The application now supports switching between an in-memory database and SQL Server for data persistence. When the 'UseInMemoryDatabase' configuration flag is enabled, the system uses an in-memory database; otherwise, it connects to SQL Server using the 'DefaultConnection' connection string. Additionally, generic and product-specific repository interfaces are registered for dependency injection.

Infrastructure.Persistence · medium confidence

Introduced base entity classes and configuration settings for domain models

The domain layer now includes abstract base classes for entities, specifically AuditableBaseEntity and BaseEntity, which provide common properties such as Id, CreatedBy, and LastModified. Additionally, configuration classes for JWT and Mail settings have been added to support authentication and email functionality within the domain.

Domain · high confidence

v1.1 Release: Security, Identity, and Architecture Updates

The v1.1 release introduces significant security and architectural changes, including securing POST/DELETE/PUT endpoints with JWT authentication, adding forgot-password/reset-password endpoints, and implementing user auditing to track entity changes. The release also includes default role and user seeding, a custom response for 401/403 errors, and refactored service extensions. Additionally, the repository now includes a CHANGELOG.md, a standard CODE\_OF\_CONDUCT.md, and a MIT LICENSE file, alongside updated solution and project structures.

(repo-wide) · high confidence

Fixes

Added validation behavior for request handling

A new ValidationBehavior class has been introduced in the Application/Behaviours directory. This class implements the IPipelineBehavior interface to automatically validate incoming requests using FluentValidation. If any validation errors are detected, a ValidationException is thrown, ensuring that invalid requests are caught early in the pipeline.

Application/Behaviours · medium confidence

Dependencies

Initial release of Clean Architecture Web API with .NET Core 3.1 and EF Core 3.1.7

The project establishes a clean architecture solution structure, upgrading the target framework to .NET Core 3.1 and utilizing Entity Framework Core 3.1.7 across the application, domain, and infrastructure layers. This release introduces key dependencies including Serilog for console and SQL Server logging, FluentValidation for request validation, and Swashbuckle for Swagger UI integration, while also configuring in-memory database support for development.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 54 → 55 (+1.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 67 → 65 (-1.6)
  • Architecture 84 → 84 (+0.0)
  • Maturity 54 → 59 (+4.8)
  • Readiness 45 → 45 (+0.0)
  • Security 72 → 73 (+0.9)

Resolved (8)

  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: Microsoft.Data.SqlClient 1.1.3
  • No exposed public API
  • The README is a banner with no installation, prerequisites, or configuration instructions for the Clean Architecture boilerplate. (README.md)
  • dormant codebase — no living knowledge left to concentrate
  • redundant comment (Infrastructure.Identity/Seeds/DefaultBasicUser.cs)
  • redundant comment (WebApi/Program.cs)

New (13)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Duplicated block (18 lines × 2) (Infrastructure.Identity/Seeds/DefaultBasicUser.cs)
  • End-of-life runtime: .NET netcoreapp3.1
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • WriteOnlyPrivateField (Infrastructure.Identity/Services/AccountService.cs)
  • WriteOnlyPrivateField (Infrastructure.Identity/Services/AccountService.cs)
  • redundant comment (Infrastructure.Identity/Services/AccountService.cs)
  • redundant comment (Infrastructure.Identity/Services/AccountService.cs)

API surface

  • Unchanged — 11 HTTP endpoints

Architecture

  • Unchanged — 2 containers · 0 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

iammukeshm/CleanArchitecture.WebApi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a0e6abafde5be95a23835978146e26c5637d770b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.