Skip to content
CAI
Software that uses CAICheck a score

inklabs/kommerce-core

63.8

Adequate · 22 September 2026

30.8k

lines of production code

PHP

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a PHP-based e-commerce backend that manages the full lifecycle of online retail operations, including product catalogs, shopping carts, orders, and inventory. It implements a CQRS architecture with dedicated command and query handlers to process business logic for entities like products, users, and shipments. The system supports complex commerce features such as cart price rules, catalog promotions, tax calculations, and shipping label generation via external gateways.

How it got here

2014–2015 — CQRS and domain modeling

38 changes.

The codebase underwent a significant architectural shift towards a Command Query Responsibility Separation (CQRS) pattern, introducing a Command Bus, Query Bus, and Event Dispatcher to decouple operations. This period also established a comprehensive domain model with extensive Data Transfer Objects (DTOs) and service layers for cart, order, and inventory management, all supported by rigorous test coverage.

2016 — CQRS and authorization enforcement

38 changes.

The codebase underwent a comprehensive migration to a Command/Query (CQRS) architecture, introducing dedicated command and query classes for nearly all business domains including products, carts, coupons, and inventory. This structural shift was accompanied by the implementation of strict, handler-level authorization checks, ensuring that administrative actions are properly secured across the application.

2017–2018 — Structured response and authorization layer

21 changes.

This period focused on standardizing the application's architecture by introducing a consistent set of response classes that wrap data transfer objects for various domain entities. Concurrently, the codebase implemented a robust, session-based authorization context to enforce strict access control for users, carts, and orders. The work also extended these patterns to new features like warehouse management and configuration handling.

Features

Add CRUD operations for Cart Price Rules

Introduces new action handlers that enable creating, reading, updating, and deleting cart price rules and their associated items (discounts, products, and tags). Each handler enforces admin-only authorization, ensuring that only administrators can manage these pricing configurations.

src/ActionHandler/CartPriceRule · high confidence

Add CSV import services for users, orders, order items, and payments

New services in the Import namespace (ImportUserService, ImportOrderService, ImportOrderItemService, ImportPaymentService) along with their interfaces and an ImportResult helper class enable bulk importing of users, orders, order items, and payments from CSV files. Each service iterates over an iterator of rows, maps CSV columns to entity fields, and persists them via the respective repositories, while tracking success/failure counts and error messages in the ImportResult object.

src/Service/Import · high confidence

Add EasyPost shipping rate and label purchasing support

Users can now retrieve and purchase shipping labels via the EasyPost gateway. The new \EasyPostGateway\ implementation provides \getRates\ and \getTrimmedRates\ to fetch available shipping options, with rates sorted from lowest to highest cost. The \buy\ method allows users to purchase a shipping label and receive a \ShipmentTracker\ for tracking. This introduces a new \ShipmentGatewayInterface\ contract for shipping providers.

src/Lib/ShipmentGateway · high confidence

Add command handlers for full CRUD operations on Options

The system now supports creating, reading, updating, and deleting Options, OptionValues, and OptionProducts through dedicated command and query handlers. Each handler enforces admin-level authorization, ensuring that only administrators can perform these management actions on the Option entity and its related products and values.

src/ActionHandler/Option · high confidence

Add custom Doctrine DQL functions for distance calculation and random sorting

New custom Doctrine DQL functions have been introduced to support geospatial queries and random ordering. For MySQL, a 'DISTANCE' function implements the Haversine formula to calculate distances between latitude/longitude coordinates, while a 'RAND' function enables random sorting. For SQLite, a 'DISTANCE' function uses a Manhattan distance approximation, and a 'RAND' function leverages SQLite's RANDOM() for randomization. These additions allow the application to perform location-based filtering and random product selection directly within Doctrine queries.

src/Doctrine/Functions · high confidence

Add example Doctrine CLI configuration files for MySQL and SQLite

Added example configuration files for the Doctrine ORM CLI tool, supporting both MySQL and SQLite database setups. The new files, cli-config.php.example and cli-config.php.example-sqlite, provide ready-to-use templates for setting up the Doctrine EntityManager with specific database drivers (pdo\_mysql and pdo\_sqlite) and include a workaround for mapping MySQL enum types to strings.

config · high confidence

Add full CRUD and query handlers for Attributes, AttributeValues, and ProductAttributes

The system now supports creating, updating, and deleting attributes, attribute values, and product attributes, alongside queries to list attributes, retrieve specific attribute or attribute value details, and fetch product attributes by attribute value. All attribute actions require admin authorization, while the product attribute query allows public access. This introduces the core backend logic for managing product attributes and their values.

src/ActionHandler/Attribute · high confidence

Add handlers for creating, updating, deleting, and listing tax rates

The system now supports full management of tax rates through new command and query handlers. Users can create state-based, ZIP code, and ZIP range tax rates, as well as update or delete existing ones. A list endpoint has also been added to retrieve all configured tax rates. All operations require admin authorization.

src/ActionHandler/TaxRate · high confidence

Add response classes for warehouse, inventory location, and product stock queries

New response classes have been added to the warehouse module to support querying and listing operations. Users can now retrieve a single warehouse or inventory location, list all warehouses, list inventory transactions filtered by location, and list product stock for a specific location. Each response class implements the standard ResponseInterface and provides methods to build corresponding DTOs, including support for pagination and related data (e.g., product details in inventory transactions).

src/ActionResponse/Warehouse · high confidence

Added AdjustInventoryCommand for inventory adjustments

A new command class, AdjustInventoryCommand, has been introduced to handle inventory adjustment actions. It accepts product ID, quantity, inventory location ID, and transaction type ID as parameters, converting the UUIDs from strings to a UuidInterface for internal use.

src/Action/Inventory · high confidence

Added Doctrine extensions for table prefixing and UUID handling

Introduced two new Doctrine extensions: a TablePrefix class that automatically applies a configurable prefix to entity table names and join tables, and a UuidBinaryType class that handles the conversion of UUIDs between database binary storage and PHP Uuid objects, replacing the default Ramsey UUID type with a custom implementation.

src/Doctrine/Extensions · medium confidence

Added TextOptionValueDTO for product option values

A new data transfer object, TextOptionValueDTO, has been introduced to represent text-based product option values. This DTO encapsulates a text option ID and its corresponding value, providing a structured way to handle product customization inputs within the application.

src/InputDTO · high confidence

Added catalog promotion command and query objects

Introduced new command and query objects for managing catalog promotions, including CreateCatalogPromotionCommand, UpdateCatalogPromotionCommand, DeleteCatalogPromotionCommand, GetCatalogPromotionQuery, and ListCatalogPromotionsQuery, along with an abstract base class to standardize their structure.

src/Action/CatalogPromotion · high confidence

Added catalog promotion management handlers

The system now includes dedicated command and query handlers for creating, updating, deleting, retrieving, and listing catalog promotions. Each handler enforces admin-level authorization via verifyIsAdmin(), ensuring that only administrators can perform these catalog promotion operations.

src/ActionHandler/CatalogPromotion · high confidence

Added command and query objects for Cart Price Rule management

The codebase now includes the command and query objects required to create, update, and delete cart price rules and their associated discounts and items. This includes the abstract base command, specific commands for creating and deleting rules and their items (discounts, products, tags), and queries for retrieving or listing rules. These changes support the underlying CRUD operations for cart price rules.

src/Action/CartPriceRule · high confidence

Added command and query objects for managing product and value options

The codebase now includes new command and query classes for handling option operations, specifically for products and values. This includes commands to create, update, and delete options, option products, and option values, as well as queries to retrieve or list options. These changes support the internal logic for managing product-specific option configurations.

src/Action/Option · high confidence

Added handlers for warehouse and inventory location management

The system now supports creating, updating, deleting, and retrieving warehouses and inventory locations, as well as listing warehouses, inventory transactions by location, and product stock levels. These new action handlers enable administrators to manage warehouse data and inventory locations through the API.

src/ActionHandler/Warehouse · high confidence

Added product management commands and queries

Introduced a new set of command and query objects for product operations, including CreateProductCommand, UpdateProductCommand, DeleteProductCommand, and CreateProductQuantityDiscountCommand. The update also adds query objects for retrieving products by ID, by tag, randomly, or related to other products, as well as commands for managing product tags and images (adding/removing tags, setting/removing default images).

src/Action/Product · high confidence

Comprehensive set of Entity DTOs for the domain model

A complete set of Data Transfer Objects (DTOs) has been introduced to represent the core domain entities, including Cart, Order, Product, User, Shipment, and various type definitions (e.g., OrderStatusType, PromotionType). These DTOs standardize the data structure used across the application, featuring common traits for IDs and timestamps, and establishing clear relationships between different entities.

src/EntityDTO · high confidence

Introduce CommandBus for centralized command execution and event dispatching

A new CommandBus implementation has been added to the Lib/Command directory, providing a centralized way to execute commands. The CommandBus accepts an AuthorizationContext, a Mapper, and an EventDispatcher, and is responsible for verifying authorization, invoking the appropriate handler, and dispatching any resulting events. This change introduces the CommandBusInterface, CommandInterface, and CommandHandlerInterface to support this new flow, replacing previous static or ad-hoc command handling mechanisms.

src/Lib/Command · high confidence

Introduce ad-hoc shipment capabilities and new shipment action handlers

The system now supports ad-hoc shipments, adding the ability to buy labels for non-ordered items via the new BuyAdHocShipmentLabelHandler. Additionally, the shipment module has been expanded with new handlers for listing ad-hoc shipments (ListAdHocShipmentsHandler) and retrieving the lowest shipment rates by delivery method (GetLowestShipmentRatesByDeliveryMethodHandler). All new handlers implement the standard command/query interface and enforce admin-level authorization checks.

src/ActionHandler/Shipment · high confidence

Introduced ListTaxRatesResponse for tax rate listing

Added a new ListTaxRatesResponse class that implements the ResponseInterface, allowing users to retrieve a list of tax rates via the getTaxRateDTOs method.

src/ActionResponse/TaxRate · medium confidence

Introduced new command and query objects for coupon management

Added new command and query classes for coupon operations: CreateCouponCommand, UpdateCouponCommand, DeleteCouponCommand, GetCouponQuery, and ListCouponsQuery. These classes define the data structures used to create, update, delete, retrieve, and list coupons within the system, establishing the interface for these specific actions.

src/Action/Coupon · high confidence

Introduced response classes for retrieving and listing cart price rules

Added new response classes, GetCartPriceRuleResponse and ListCartPriceRulesResponse, which implement the ResponseInterface to handle the conversion of cart price rule data into DTOs. GetCartPriceRuleResponse provides methods to retrieve a single cart price rule DTO, while ListCartPriceRulesResponse aggregates multiple cart price rule DTOs and pagination information, enabling the application to structure query results for cart price rules in a consistent, typed manner.

src/ActionResponse/CartPriceRule · high confidence

Introduces CQRS command and query objects for order management

The order action layer now uses dedicated CQRS command and query classes to handle order operations. New commands include CreateOrderFromCart, SetOrderStatus, and CSV import commands for orders, order items, and payments. New queries allow retrieving a single order, order items, all orders for a user, and listing orders with pagination. This structure supports the underlying domain logic and enables consistent, typed interfaces for these operations.

src/Action/Order · high confidence

Introduces a new Query Bus for handling read operations

A new Query Bus architecture has been added to the library, introducing a central dispatcher for query handlers. The implementation includes a QueryBus class that accepts an AuthorizationContext and a Mapper to route and execute queries. This change shifts the query execution flow to verify authorization before handling, ensuring that all query operations are properly secured and routed through the new interface-based structure.

src/Lib/Query · high confidence

Introduces custom QueryBuilder with domain-specific query methods

Adds a new \src/Doctrine/ORM/QueryBuilder.php\ that extends Doctrine's QueryBuilder to provide reusable, domain-specific query constraints and parameter handling. This includes methods for filtering active/visible products and tags, checking product availability, calculating geographic distance, and handling binary ID/UUID parameters, which simplifies repository implementations by centralizing common query logic.

src/Doctrine/ORM · high confidence

Introduces new entity and DTO classes for cart, promotions, and product attributes

The system now supports more complex cart structures with support for cart price rules, coupons, and product options. New entities such as Cart, CartItem, CartPriceRule, and their associated discount and item types enable the application to calculate totals, apply discounts, and manage product attributes. Additionally, new DTOs like ProductStockDTO are introduced to handle stock information. These changes allow users to create and manage shopping carts with multiple items, apply various types of promotions and coupons, and handle product variations and attributes.

src/Entity · high confidence

New Lib utilities and interfaces for cart, pricing, and file management

The \src/Lib\ directory now contains a suite of new classes and interfaces that introduce core business logic and infrastructure support. This includes a \CartCalculator\ and \Pricing\ engine to compute totals, discounts, and taxes for shopping carts. A \FileManager\ interface and \LocalFileManager\ implementation provide a standardized way to handle file uploads and storage. Additionally, the codebase adds a \Mapper\ for dependency injection and handler resolution, a \Slug\ generator, a \UserPasswordValidator\ for security, a \Uuid\ wrapper, and an \XMLSerializer\ for data serialization.

src/Lib · high confidence

New attachment management commands and handlers

Added new command handlers for managing attachments, including creating attachments for order items and user products, as well as locking, unlocking, making visible, and making invisible attachments. All handlers enforce admin-level authorization via verifyIsAdmin().

src/ActionHandler/Attachment · high confidence

New attachment management commands for orders and products

The system now supports managing file attachments for order items and user products, as well as controlling the visibility and lock status of attachments. New command classes have been added to handle creating attachments for order items and user products, deleting attachments, and marking attachments as visible or not visible, locked or unlocked.

src/Action/Attachment · high confidence

New attribute query response classes

Added new response classes for attribute queries: GetAttributeResponse, GetAttributeValueResponse, GetProductAttributesByAttributeValueResponse, and ListAttributesResponse. These classes implement the ResponseInterface and provide methods to retrieve attribute data, including support for pagination and pricing integration.

src/ActionResponse/Attribute · medium confidence

New cart command and query classes for item and cart management

The cart module now includes a comprehensive set of new command and query classes to support cart operations. These include commands for adding, deleting, and updating cart items, as well as managing coupons, shipment rates, tax rates, and user/session associations. Additionally, new query classes allow retrieving cart details by cart ID, user ID, or session ID. This expands the available cart actions and data retrieval options for users.

src/Action/Cart · high confidence

New cart management actions and handlers

The system now supports a comprehensive set of cart operations, including creating, copying, and deleting carts; adding, removing, and updating cart items and coupons; and setting cart user, session ID, tax rate, and shipment rates. Each operation is implemented via a dedicated command handler in the \src/ActionHandler/Cart\ directory, enforcing authorization checks before execution.

src/ActionHandler/Cart, src/ActionHandler/Tag · high confidence

New cart response classes implementing ResponseInterface

Three new response classes—GetCartBySessionIdResponse, GetCartByUserIdResponse, and GetCartResponse—have been added to the cart action response layer. Each class implements the ResponseInterface and utilizes a CartDTOBuilder to construct CartDTO objects. GetCartResponse additionally integrates a CartCalculator to support retrieving cart data with all associated information.

src/ActionResponse/Cart · high confidence

New commands and queries for managing product attributes and values

The system now supports creating, updating, and deleting attributes, attribute values, and product attributes. New commands (CreateAttributeCommand, UpdateAttributeCommand, DeleteAttributeCommand, etc.) and queries (GetAttributeQuery, ListAttributesQuery, GetProductAttributesByAttributeValueQuery, etc.) are introduced to handle these operations, enabling users to manage attribute definitions and their associated values within the commerce core.

src/Action/Attribute · medium confidence

New commands for managing tax rates

Added new command classes in the TaxRate action namespace to support creating, updating, and deleting tax rates. Specifically, the diff introduces commands for state-based tax rates (CreateStateTaxRateCommand, UpdateStateTaxRateCommand), zip code tax rates (CreateZip5TaxRateCommand, UpdateZip5TaxRateCommand), and zip range tax rates (CreateZip5RangeTaxRateCommand, UpdateZip5RangeTaxRateCommand). Additionally, a DeleteTaxRateCommand and a ListTaxRatesQuery are added, enabling users to manage tax rate configurations via these specific command and query interfaces.

src/Action/TaxRate · high confidence

New configuration query and command classes

Added two new classes to manage configuration data: GetConfigurationsByKeysQuery, which retrieves configuration values by a list of keys, and UpdateConfigurationCommand, which handles updating a specific configuration key-value pair. These classes implement the respective query and command interfaces, providing a structured way to interact with system configuration settings.

src/Action/Configuration · high confidence

New domain events and event-raising infrastructure

The system now exposes specific domain events to track user and order lifecycle changes. New event classes have been added: ImportedUsersFromCSVEvent (tracking import success/failure counts), OrderCreatedFromCartEvent (exposing the order ID), OrderShippedEvent (exposing order and shipment IDs), PasswordChangedEvent (exposing user ID, email, and full name), and ResetPasswordEvent (exposing user ID, email, full name, and token). To support these, a RaiseEventTrait and ReleaseEventsInterface have been introduced, allowing classes to queue and release pending events.

src/Event · high confidence

New event dispatching infrastructure

The application now includes a new event dispatching system, introducing an EventDispatcher interface and a concrete implementation that supports both callable listeners and EventSubscriber objects. A LoggingEventDispatcher decorator has been added to track dispatched events, and an abstract EventDispatcherDecorator is provided for wrapping the dispatcher. This enables a more structured approach to handling and logging events within the system.

src/Lib/Event · high confidence

New product management and retrieval actions

The system now supports a comprehensive set of product operations, including creating, updating, and deleting products, as well as managing product tags and images. Specific handlers have been added for actions such as adding or removing tags, setting or unsetting default images, and creating quantity discounts. Additionally, new query handlers allow retrieving individual or multiple products by ID, by tag, or randomly, as well as listing all products or related items. All write operations require admin authorization, while read operations are accessible to general users.

src/ActionHandler/Product · high confidence

New service layer for cart, order, inventory, and user management

The service layer has been restructured to introduce dedicated services for managing carts, orders, inventory, and users. The new \CartService\ handles cart operations such as adding items, managing coupons, and calculating totals. \OrderService\ manages order creation from carts, shipment tracking, and status updates. \InventoryService\ provides methods for reserving, shipping, and adjusting product stock. \UserService\ handles user authentication and login logic. These services are wired together via a \ServiceFactory\ that provides access to all service instances, promoting a cleaner separation of concerns and improved testability.

src/Service · high confidence

New shipment actions and queries for tracking, rates, and ad-hoc shipments

The system now supports adding shipment tracking codes, buying shipping labels (both for existing orders and ad-hoc shipments), and retrieving shipment rates. Users can now add tracking codes to orders, purchase labels for standard and ad-hoc shipments, and query for the lowest shipment rates by delivery method. Additionally, users can list ad-hoc shipments and retrieve shipment tracker information.

src/Action/Shipment · high confidence

New user management commands and queries

Added new command and query objects for user management, including ChangePasswordCommand, CreateUserCommand, GetUserByEmailQuery, GetUserQuery, ImportUsersFromCSVCommand, ListUsersQuery, LoginCommand, LoginWithTokenCommand, and ResetPasswordCommand. These classes define the input data structures for user-related actions such as creating accounts, logging in with credentials or tokens, changing or resetting passwords, and importing users from CSV files.

src/Action/User · high confidence

New warehouse and inventory location commands and queries

Added a set of command and query objects to support warehouse and inventory location operations. This includes commands for creating, updating, and deleting warehouses and inventory locations, as well as queries for retrieving, listing, and filtering warehouses, inventory locations, inventory transactions, and product stock.

src/Action/Warehouse · high confidence

Security

Admin authorization enforced for image upload actions

The CreateImageForProductHandler and CreateImageForTagHandler now require admin-level authorization before processing image uploads. This ensures that only administrators can upload images for products and tags, adding a security layer to these specific actions.

src/ActionHandler/Image · high confidence

Behavioural changes

Added GetConfigurationsByKeysResponse class

A new response class, GetConfigurationsByKeysResponse, has been introduced to handle the result set for retrieving configurations by keys. This class implements the ResponseInterface and manages an array of ConfigurationDTO objects, providing methods to add individual DTOs and retrieve the complete list.

src/ActionResponse/Configuration · high confidence

Added handlers for retrieving and updating system configurations

New action handlers have been introduced for the Configuration module: GetConfigurationsByKeysHandler processes queries to retrieve multiple configurations by their keys, while UpdateConfigurationHandler processes commands to update individual configuration values. Both handlers enforce administrative access control by verifying the user is an admin before executing their respective logic.

src/ActionHandler/Configuration · high confidence

Coupon management now uses dedicated command and query handlers

The Coupon module has been refactored to use dedicated handler classes for each operation: CreateCouponHandler, UpdateCouponHandler, DeleteCouponHandler, GetCouponHandler, and ListCouponsHandler. Each handler implements the appropriate interface (CommandHandlerInterface or QueryHandlerInterface) and includes explicit authorization verification (e.g., verifyIsAdmin or verifyCanMakeRequests). A shared trait, UpdateCouponFromCommandTrait, centralizes the logic for updating a Coupon entity from a command object. This replaces the previous monolithic or service-based approach, providing a clearer separation of concerns and consistent authorization checks for all coupon actions.

src/ActionHandler/Coupon · medium confidence

Introduce structured exception hierarchy for domain-specific errors

The codebase now uses a dedicated exception hierarchy under the \inklabs\\kommerce\\Exception\ namespace, replacing generic or ad-hoc error handling with specific, typed exceptions. This includes a base \KommerceException\ (defaulting to HTTP 500) and a \Kommerce400Exception\ (defaulting to HTTP 400), from which domain-specific exceptions like \UserLoginException\, \EntityValidatorException\, and \FileManagerException\ inherit. Each exception class encapsulates specific error conditions (e.g., \UserLoginException\ handles invalid passwords, expired tokens, or inactive users), providing developers with precise error context and standardized HTTP status codes for API responses.

src/Exception · high confidence

Introduce structured response classes for order queries

The codebase now uses dedicated, final classes (GetOrderItemResponse, GetOrderResponse, GetOrdersByUserResponse, ListOrdersResponse) that implement the ResponseInterface. Each class encapsulates the logic for building specific OrderDTOs or PaginationDTOs, providing explicit methods like getOrderDTO(), getOrderDTOWithAllData(), and getPaginationDTO(). This change replaces previous, likely ad-hoc or less structured approaches to handling order query responses, ensuring consistent data transfer object (DTO) construction across the Order action responses.

src/ActionResponse/Order · high confidence

Introduce typed response classes for shipment queries

The \src/ActionResponse/Shipment\ directory now contains new, strongly-typed response classes (\GetLowestShipmentRatesByDeliveryMethodResponse\, \GetShipmentRatesResponse\, \GetShipmentTrackerResponse\, and \ListAdHocShipmentsResponse\) that implement \ResponseInterface\. These classes encapsulate the results of shipment-related queries, providing structured access to shipment rate data, tracking information, and paginated lists of ad-hoc shipments, replacing previous, less structured return types.

src/ActionResponse/Shipment · high confidence

Introduced command objects for image creation

Added new command classes, CreateImageForProductCommand and CreateImageForTagCommand, which encapsulate the data required to create an image for a product or a tag respectively. These classes implement CommandInterface and hold references to UploadFileDTO and the respective entity ID (product or tag) as a UuidInterface.

src/Action/Image · high confidence

Introduced new response classes for user queries

Added three new PHP classes—GetUserByEmailResponse, GetUserResponse, and ListUsersResponse—each implementing the ResponseInterface. These classes encapsulate the logic for building UserDTO and PaginationDTO objects, providing methods to retrieve single user data (with optional roles and tokens) or lists of users with pagination details.

src/ActionResponse/Coupon, src/ActionResponse/User · medium confidence

Introduces structured payment gateway abstraction with validation

The payment gateway layer now uses dedicated DTOs (ChargeRequest, ChargeResponse) that implement validation constraints (e.g., amount ranges, card last-4 digits, brand). A new PaymentGatewayInterface defines the contract, with a Stripe implementation that maps request fields to the Stripe API and a FakePaymentGateway for testing.

src/Lib/PaymentGateway · high confidence

Inventory adjustment actions now require admin authorization

The AdjustInventoryHandler has been updated to enforce administrative privileges before processing inventory adjustments. The handler now accepts an AuthorizationContext and explicitly verifies that the user is an admin, ensuring that only authorized personnel can modify inventory levels.

src/ActionHandler/Inventory · medium confidence

Major rewrite of the EntityDTO builder system

The EntityDTO module has been completely rewritten to use a new builder pattern architecture. This introduces a factory-based system (DTOBuilderFactory) that creates specialized builders for each entity type (e.g., Cart, Order, User). The change standardizes how entities are converted to Data Transfer Objects (DTOs), ensuring consistent data exposure and simplifying the serialization of complex object graphs like carts, promotions, and user profiles.

src/EntityDTO/Builder · high confidence

Migrated order actions to CQRS handlers with authorization checks

Order actions (Create, Get, List, SetStatus, Import) are now implemented as dedicated CQRS handlers in the \src/ActionHandler/Order\ directory. Each handler includes an explicit \verifyAuthorization\ method to enforce access control: admin roles are required for list, status, and import operations, while standard users can manage their own carts and view their own orders. This refactoring replaces the previous monolithic or loosely structured handlers with a clear command/query separation and integrated security checks.

src/ActionHandler/Order · high confidence

New Product Response classes implement ResponseInterface

Added new response classes for product queries (GetProduct, GetProductsByIds, GetProductsByTag, GetRandomProducts, GetRelatedProducts, and ListProducts) that implement the ResponseInterface. These classes handle the transformation of ProductDTOs, with most integrating pricing information via the Pricing/PricingInterface, while the ListProducts response also supports pagination data.

src/ActionResponse/Product · high confidence

New response classes for catalog promotion queries

Added GetCatalogPromotionResponse and ListCatalogPromotionsResponse classes in the CatalogPromotion action response namespace. Both implement the ResponseInterface and provide methods to retrieve CatalogPromotionDTO objects, with ListCatalogPromotionsResponse also supporting pagination data retrieval.

src/ActionResponse/CatalogPromotion · high confidence

New response classes for retrieving and listing options

The codebase now includes new response classes, GetOptionResponse and ListOptionsResponse, which implement the ResponseInterface. These classes handle the construction of OptionDTO and PaginationDTO objects, allowing the application to retrieve a single option or a paginated list of options with their associated pricing and builder data.

src/ActionResponse/Option · medium confidence

New tag response classes implementing ResponseInterface

Added three new PHP classes—GetTagResponse, GetTagsByIdsResponse, and ListTagsResponse—each implementing the ResponseInterface. These classes encapsulate the logic for building TagDTO and PaginationDTO objects, with GetTagResponse handling single tag retrieval, GetTagsByIdsResponse managing multiple tags by IDs, and ListTagsResponse supporting paginated tag lists.

src/ActionResponse/Tag · medium confidence

Refactored reference number generation with new interfaces and generator

The system now uses a new HashSegmentReferenceNumberGenerator that creates reference numbers composed of three random numeric segments (3, 7, and 7 digits) separated by hyphens. This generator enforces a lookup limit to prevent infinite loops when checking for existing reference numbers. The change introduces new interfaces (ReferenceNumberGeneratorInterface, ReferenceNumberRepositoryInterface, ReferenceNumberEntityInterface) to support this refactored generation logic.

src/Lib/ReferenceNumber · medium confidence

Session-based authorization context for cart, user, and order access control

Added a new authorization layer that enforces access control for carts, users, and orders based on session and user identity. The new \SessionAuthorizationContext\ class implements \AuthorizationContextInterface\ to verify that the current session or user ID matches the resource owner, or that the user is an admin. This prevents unauthorized access to other users' carts, user profiles, and orders, throwing specific exceptions when access is denied.

src/Lib/Authorization · high confidence

Standardizes repository layer with a shared AbstractRepository and consistent find behavior

The repository layer has been refactored to use a new \AbstractRepository\ base class that provides common CRUD operations (create, update, delete, persist, flush) and a \getQueryBuilder()\ helper. A key behavioral change is that all repository \find\ operations now throw an \EntityNotFoundException\ when a record is not found, rather than returning null or throwing a generic exception. This ensures consistent error handling across all entity repositories, including specific implementations for Cart, Product, Order, and others, which now rely on the shared \returnOrThrowNotFoundException\ logic.

src/EntityRepository · high confidence

Tag management commands and queries migrated to the new Command Bus

The Tag CRUD operations have been refactored to use the new Command Bus architecture. This introduces a set of new command and query classes in the \src/Action/Tag\ directory, including \CreateTagCommand\, \UpdateTagCommand\, \DeleteTagCommand\, \GetTagQuery\, \GetTagsByIdsQuery\, \ListTagsQuery\, and several specific action commands like \AddOptionToTagCommand\ and \SetDefaultImageForTagCommand\. These changes enable the system to handle tag-related requests through the new dispatcher, replacing the previous implementation.

src/Action/Tag · high confidence

User management actions now enforce authorization checks

All user-related action handlers (ChangePassword, CreateUser, GetUserByEmail, GetUser, ImportUsersFromCSV, ListUsers, Login, LoginWithToken, and ResetPassword) now include explicit authorization verification steps. Each handler implements a verifyAuthorization method that checks user permissions (e.g., admin status, ability to manage users, or making requests) before executing the action. This ensures that user management operations require proper authorization context, improving security by validating access rights before processing commands or queries.

src/ActionHandler/User · high confidence

Test coverage

Added CountSQLLogger test helper; Added FakeShipmentGateway test helper; Added comprehensive service layer tests; Added comprehensive test coverage for Entity classes; Added comprehensive test coverage for EntityDTO builders; Added test coverage for the AdjustInventoryHandler; Added test helper classes for Action and Query components; Added test helper classes for Lib components; Added test helper classes for entity and DTO construction; Added test helper classes for event handling; Added test helper classes for reference number checks; Added test helper classes for unit testing; Added test helper for authorization context; Added tests for Attribute, AttributeValue, and ProductAttribute handlers; Added tests for EventDispatcher and LoggingEventDispatcher; Added tests for HashSegmentReferenceNumberGenerator; Added tests for MySQL RAND function; Added tests for ShipmentGateway interface; Added tests for attachment action handlers; Added tests for import services; Added tests for warehouse and inventory location management; Added unit tests for Catalog Promotion handlers; Added unit tests for PaymentGateway components; Added unit tests for Tag action handlers; Added unit tests for core Lib modules; Added unit tests for entity repository layer; Added unit tests for image creation handlers; Added unit tests for the Doctrine ORM QueryBuilder; Updated test configuration and added project metadata files.

Dependencies

Upgrade PHP and add major dependencies

The project now requires PHP 7.1 and adds several new dependencies including Doctrine DBAL and ORM, Ramsey UUID, Symfony Validator, Stripe, and EasyPost, while updating PHPUnit to version 5.7.20.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 60 → 64 (+4.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 95 (+0.8)
  • Architecture 99 → 99 (-0.6)
  • Maturity 58 → 58 (+0.0)
  • Readiness 40 → 49 (+8.8)
  • Security 97 → 97 (-0.2)

Resolved (30)

  • Change coupling: ImportOrderItemService.php ↔ ImportUserService.php (src/Service/Import/ImportOrderItemService.php)
  • Change coupling: ImportOrderService.php ↔ ImportUserService.php (src/Service/Import/ImportOrderService.php)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (src/Doctrine/Functions/Mysql/Rand.php)
  • Duplicated block (10 lines × 2) (src/Lib/Mapper.php)
  • Duplicated block (11 lines × 2) (src/Doctrine/Functions/Mysql/Distance.php)
  • Duplicated block (11 lines × 2) (src/Entity/Configuration.php)
  • Duplicated block (14 lines × 2) (src/Lib/PaymentGateway/ChargeRequest.php)
  • Duplicated block (15 lines × 2) (src/Entity/CreditCard.php)
  • Duplicated block (15 lines × 2) (src/Entity/Product.php)
  • Duplicated block (15 lines × 3) (src/Entity/Image.php)
  • Duplicated block (15 lines × 3) (src/Entity/Option.php)
  • Duplicated block (16 lines × 2) (src/Entity/Address.php)
  • Duplicated block (17 lines × 2) (src/Entity/ShipmentLabel.php)
  • Duplicated block (19 lines × 2) (src/Service/InventoryService.php)
  • Duplicated block (6 lines × 2) (src/ActionHandler/CartPriceRule/CreateCartPriceRuleHandler.php)
  • Duplicated block (6 lines × 2) (src/ActionHandler/Option/CreateOptionHandler.php)
  • Duplicated block (7 lines × 2) (src/ActionHandler/CatalogPromotion/CreateCatalogPromotionHandler.php)
  • Duplicated block (7 lines × 2) (src/EntityDTO/Builder/OptionDTOBuilder.php)
  • …and 10 more

New (182)

  • Boundary-crossing change coupling: UserRepository.php ↔ UserService.php (src/EntityRepository/UserRepository.php)
  • Change coupling clique: ImportOrderItemService.php, ImportOrderService.php, ImportUserService.php (src/Service/Import/ImportOrderItemService.php)
  • Change coupling: CreditPayment.php ↔ Order.php (src/Entity/CreditPayment.php)
  • Change coupling: UserLogin.php ↔ UserRole.php (src/Entity/UserLogin.php)
  • Change coupling: UserRole.php ↔ UserToken.php (src/Entity/UserRole.php)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (src/Doctrine/Functions/Mysql/Rand.php)
  • Duplicated block (10 lines × 2) (src/Entity/Attribute.php)
  • Duplicated block (10 lines × 2) (src/EntityDTO/Builder/CartItemOptionProductDTOBuilder.php)
  • Duplicated block (10 lines × 2) (src/Lib/Mapper.php)
  • Duplicated block (11 lines × 2) (src/Entity/Product.php)
  • Duplicated block (11 lines × 4) (src/Entity/Address.php)
  • Duplicated block (11 lines × 9) (src/ActionHandler/Attribute/GetAttributeHandler.php)
  • Duplicated block (12 lines × 2) (src/Action/Product/AddTagToProductCommand.php)
  • Duplicated block (12 lines × 2) (src/Action/Product/RemoveImageFromProductCommand.php)
  • Duplicated block (12 lines × 2) (src/Action/Tag/AddOptionToTagCommand.php)
  • Duplicated block (12 lines × 2) (src/Action/Tag/RemoveImageFromTagCommand.php)
  • Duplicated block (13 lines × 2) (src/ActionHandler/Product/GetProductsByIdsHandler.php)
  • Duplicated block (13 lines × 2) (src/ActionResponse/Shipment/GetLowestShipmentRatesByDeliveryMethodResponse.php)
  • …and 162 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

inklabs/kommerce-core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e1b2df17635ccc81504cfa0ff165e75751bc2e10 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.