iammukeshm/CleanArchitecture.WebApi
55.2
Weak · 21 September 2026
1.9k
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is a .NET-based web API built on Clean Architecture principles, designed to manage product inventory and user accounts. It provides secure, authenticated endpoints for creating, reading, updating, and deleting products, alongside comprehensive user management features including registration, email verification, and password recovery. The architecture enforces separation of concerns through distinct layers, utilizing CQRS for command and query handling, while maintaining strict audit trails and role-based access control.
Features
Added CQRS command handlers and validators for product CRUD operations
Implemented the application layer for product management using the CQRS pattern. New command handlers handle Create, Update, and Delete operations for products, integrating with the repository layer. Validation rules enforce required fields, length limits, and unique barcodes using FluentValidation. The application service collection is extended to register AutoMapper, MediatR, and the validation pipeline behavior.
Application/Features/Products/Commands · high confidence
Added Clean Architecture WebAPI template configuration
Introduced the .template.config/template.json and template.vstemplate files that define the 'Clean Architecture WebAPI' project template. This adds the template metadata, including the identity, description, and primary output paths for the solution structure.
.template.config · high confidence
Added Metadata model class
A new Metadata class has been introduced in the WebApi/Models namespace. This change adds a placeholder model for metadata, which may be used to store or transfer metadata information in the API.
WebApi/Models · high confidence
Added Product CRUD endpoints with JWT authentication
A new ProductController has been introduced in the v1 API, exposing standard CRUD operations (Create, Read, Update, Delete) for products. The endpoints are secured with JWT authentication, requiring users to be authenticated for POST, PUT, and DELETE operations, while GET endpoints remain public. The controller integrates with a CQRS-based application layer, mapping requests to corresponding commands and queries.
WebApi/Controllers/v1 · medium confidence
Added account and email DTOs for authentication and registration
New data transfer objects were added to support account management features. This includes request and response models for authentication, registration, email verification, and password reset, as well as a model for sending emails and a base class for paginated requests. These changes enable the backend to handle user sign-up, login, and password recovery workflows.
Application/DTOs · high confidence
Added generic response and pagination wrappers
Added generic response and pagination wrapper classes to the application layer. The new \Response\<T\>\ and \PagedResponse\<T\>\ classes provide a standardized structure for API responses, including success status, messages, and data payload, while \PagedResponse\ specifically supports pagination metadata like page number and size.
Application/Wrappers · high confidence
Added initial database migration for the Products table
A new migration (20200724181511\_Updat) was added to the persistence layer, creating the 'Products' table in the database. The table includes columns for Id, Name, Barcode, Description, Rate, and audit fields (Created, CreatedBy, LastModified, LastModifiedBy). This establishes the initial schema for product data in the application's SQL Server database.
Infrastructure.Persistence/Migrations · high confidence
Added paginated product listing and single-product retrieval via CQRS queries
Users can now retrieve a paginated list of all products or fetch a specific product by its ID. The new GetAllProducts query supports pagination parameters (PageNumber, PageSize) and returns a PagedResponse containing a list of product view models (Id, Name, Barcode, Description, Rate). The GetProductById query retrieves a single product by ID, returning a standard Response with the product entity. These changes implement the read side of the product feature using the CQRS pattern with MediatR handlers.
Application/Features/Products/Queries · high confidence
Added product repository interface with unique barcode validation
A new IProductRepositoryAsync interface was added to the application layer, introducing an IsUniqueBarcodeAsync method to support unique barcode validation for products.
Application/Interfaces/Repositories · high confidence
Introduce generic repository with pagination and unique barcode validation
Added a new generic repository implementation (GenericRepositoryAsync) that provides standard CRUD operations and supports pagination via the GetAll method, which now accepts page number and size parameters. Additionally, the Product repository implements a new IsUniqueBarcodeAsync method that uses AllAsync to validate barcode uniqueness, replacing the previous AnyAsync approach.
Infrastructure.Persistence/Repositories · medium confidence
Introduces structured error handling, Serilog console logging, and Swagger UI for the WebApi
The WebApi project now includes a global error-handling middleware that catches exceptions and returns consistent JSON error responses for bad requests, validation errors, and not-found scenarios. Serilog is configured to write console logs, and the application seeds default roles and users at startup. Additionally, Swagger UI is enabled at /swagger to expose the API documentation, and an authenticated user service is registered to support identity-based operations.
WebApi · high confidence
New Identity infrastructure with custom database schema and JWT authentication
The Identity layer now uses a dedicated \IdentityContext\ with a custom 'Identity' schema, mapping tables such as 'User', 'Role', and 'UserRoles' to specific names. Authentication is handled via JWT tokens, with the \AuthenticationHelper\ and \ServiceExtensions\ configuring the bearer token validation and error handling. The system also includes seeding logic for default roles (SuperAdmin, Admin, Moderator, Basic) and initial user accounts (Basic User, Super Admin).
Infrastructure.Identity · high confidence
New account management and API infrastructure endpoints
The API now supports full account lifecycle management, including user registration, email confirmation, and password reset (forgot/reset password) via the new AccountController. A BaseApiController has been introduced to standardize API versioning and Mediator access, and a MetaController provides version and build metadata at the /info endpoint.
WebApi/Controllers · high confidence
New service and repository interfaces for account, email, and data access
The application layer introduces new interfaces to support authentication, user identity, date/time abstraction, email delivery, and generic data access. IAccountService defines methods for authentication, registration, email confirmation, and password reset. IAuthenticatedUserService exposes the current user's ID. IDateTimeService abstracts the current UTC time. IEmailService provides a method to send emails. IGenericRepositoryAsync defines standard CRUD operations and a paginated retrieval method for generic entities. These interfaces establish the contracts for these capabilities within the application layer.
Application/Interfaces · high confidence
Shared email and date-time services introduced
The shared infrastructure layer now registers and implements core services: an IEmailService that sends emails via SMTP with configurable display names and settings, and an IDateTimeService providing UTC time. These are wired up in the new ServiceRegistration class, making these capabilities available across the application.
Infrastructure.Shared · medium confidence
Behavioural changes
Added AutoMapper mappings for Product create and query operations
A new GeneralProfile class was added to the Application/Mappings directory, configuring AutoMapper mappings for the Product entity. Specifically, it defines mappings between the Product domain entity and the GetAllProductsViewModel, as well as between the CreateProductCommand and the Product entity. Additionally, it maps the GetAllProductsQuery to GetAllProductsParameter, supporting the pagination and filtering capabilities for the GetAll method.
Application/Mappings · medium confidence
Added Roles enum for default user roles
A new Roles enum has been added to the Application layer, defining SuperAdmin, Admin, Moderator, and Basic roles. This provides the foundational type for the system's default role-based access control, supporting the seeding of initial superadmin and basic user accounts.
Application/Enums · medium confidence
Automatic audit trail for entity changes
The new ApplicationDbContext now automatically tracks creation and modification metadata (timestamps and user IDs) for all entities inheriting from AuditableBaseEntity. When saving changes, the context populates Created, CreatedBy, LastModified, and LastModifiedBy fields based on the current user and time, ensuring consistent audit trails without manual intervention.
Infrastructure.Persistence/Contexts · high confidence
Configurable database persistence with in-memory and SQL Server support
The application now supports switching between an in-memory database and SQL Server for data persistence. When the 'UseInMemoryDatabase' configuration flag is enabled, the system uses an in-memory database; otherwise, it connects to SQL Server using the 'DefaultConnection' connection string. Additionally, generic and product-specific repository interfaces are registered for dependency injection.
Infrastructure.Persistence · medium confidence
Introduced base entity classes and configuration settings for domain models
The domain layer now includes abstract base classes for entities, specifically AuditableBaseEntity and BaseEntity, which provide common properties such as Id, CreatedBy, and LastModified. Additionally, configuration classes for JWT and Mail settings have been added to support authentication and email functionality within the domain.
Domain · high confidence
v1.1 Release: Security, Identity, and Architecture Updates
The v1.1 release introduces significant security and architectural changes, including securing POST/DELETE/PUT endpoints with JWT authentication, adding forgot-password/reset-password endpoints, and implementing user auditing to track entity changes. The release also includes default role and user seeding, a custom response for 401/403 errors, and refactored service extensions. Additionally, the repository now includes a CHANGELOG.md, a standard CODE\_OF\_CONDUCT.md, and a MIT LICENSE file, alongside updated solution and project structures.
(repo-wide) · high confidence
Fixes
Added validation behavior for request handling
A new ValidationBehavior class has been introduced in the Application/Behaviours directory. This class implements the IPipelineBehavior interface to automatically validate incoming requests using FluentValidation. If any validation errors are detected, a ValidationException is thrown, ensuring that invalid requests are caught early in the pipeline.
Application/Behaviours · medium confidence
Dependencies
Initial release of Clean Architecture Web API with .NET Core 3.1 and EF Core 3.1.7
The project establishes a clean architecture solution structure, upgrading the target framework to .NET Core 3.1 and utilizing Entity Framework Core 3.1.7 across the application, domain, and infrastructure layers. This release introduces key dependencies including Serilog for console and SQL Server logging, FluentValidation for request validation, and Swashbuckle for Swagger UI integration, while also configuring in-memory database support for development.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 54 → 55 (+1.1)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 67 → 65 (-1.6)
- Architecture 84 → 84 (+0.0)
- Maturity 54 → 59 (+4.8)
- Readiness 45 → 45 (+0.0)
- Security 72 → 73 (+0.9)
Resolved (8)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: Microsoft.Data.SqlClient 1.1.3
- No exposed public API
- The README is a banner with no installation, prerequisites, or configuration instructions for the Clean Architecture boilerplate. (README.md)
- dormant codebase — no living knowledge left to concentrate
- redundant comment (Infrastructure.Identity/Seeds/DefaultBasicUser.cs)
- redundant comment (WebApi/Program.cs)
New (13)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Duplicated block (18 lines × 2) (Infrastructure.Identity/Seeds/DefaultBasicUser.cs)
- End-of-life runtime: .NET netcoreapp3.1
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- WriteOnlyPrivateField (Infrastructure.Identity/Services/AccountService.cs)
- WriteOnlyPrivateField (Infrastructure.Identity/Services/AccountService.cs)
- redundant comment (Infrastructure.Identity/Services/AccountService.cs)
- redundant comment (Infrastructure.Identity/Services/AccountService.cs)
API surface
- Unchanged — 11 HTTP endpoints
Architecture
- Unchanged — 2 containers · 0 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
iammukeshm/CleanArchitecture.WebApi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a0e6abafde5be95a23835978146e26c5637d770b — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.