iunary/fastapi-template
56.1
Adequate · 20 September 2026
413
lines of production code
Python
primary language
4
measurements over time
What this system is
This system is a Python-based backend service that provides user management and authentication capabilities. It exposes a structured REST API for handling user registration, login, and profile access, secured via JWT tokens. The architecture follows a layered design with distinct repositories and services, backed by a SQLAlchemy database with Alembic migration support.
Features
API v1 routes are now registered
The application now includes API v1 endpoints. The main application module imports the routers from the api.endpoints module and registers them under the /api/v1 prefix, making these endpoints accessible to users.
app · high confidence
Add user and common request schemas
New Pydantic models have been introduced to define request and response structures for user management and common query parameters. The \schemas/user.py\ module adds \CreateUserRequest\ with password validation logic, \CreateUserResponse\, and \UserProfileResponse\ for data serialization. Additionally, \schemas/common.py\ provides a \CommonParams\ base model for standard pagination and search queries.
schemas · high confidence
Added CLI commands for database migrations and user creation
The \manage.py\ CLI now supports running database migrations via the \migrate\ command (which executes \alembic upgrade head\) and generating migration scripts via the new \makemigrations\ command. Additionally, the \createuser\ command is available for setting up initial users. These changes are supported by a new Dockerfile for containerized execution and a \.dockerignore\ file to optimize build contexts.
(repo-wide) · high confidence
Initial API endpoint structure for authentication, health, and user profiles
The API now exposes a structured set of endpoints including a health check at /health, authentication routes at /auth (login, register, password reset/update), and user profile access at /users/me. The login endpoint validates credentials and issues JWT tokens, while the profile endpoint retrieves the current user's details. Note that register, password reset, and password update endpoints are currently stubs.
api · high confidence
Initial core authentication and database configuration
This change introduces the foundational authentication middleware and JWT verification logic for the core service, including a new \AuthBearer\ class that validates tokens, checks user existence, and enforces account activation status. It also adds a \RegisterRequest\ schema for user registration payloads, updates the SQLAlchemy engine configuration to remove the deprecated \future=False\ parameter, and hardcodes default database connection and authentication endpoint settings in the configuration file.
core · high confidence
Initial user model and database migration setup
This change introduces the foundational user management infrastructure. A new database migration creates the 'users' table with fields for ID, email, password, active status, and timestamps, including a unique index on the email address. The application's database migration environment is configured to automatically detect model changes by linking to the SQLAlchemy Base metadata and using the configured database URL. The User model itself is defined with an email field, a password field that supports hashing and verification, and an active status flag that defaults to inactive. Additionally, the password verification logic is corrected to check against the stored hashed password rather than re-hashing the input, ensuring authentication works as intended.
migrations, models · high confidence
Introduction of user repository and service layers
New repository and service components have been added to structure user data access. The UserRespository class in the repositories layer provides a method to retrieve users by email using SQLAlchemy, while the UserService in the services layer exposes an asynchronous get\_user\_by\_email method that delegates to the repository, establishing a clear separation of concerns for user-related operations.
repositories, services · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 53 → 56 (+2.9)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 75 → 75 (+0.0)
- Readiness 26 → 33 (+6.9)
- Security 100 → 96 (-4.4)
Resolved (7)
- Dependency hygiene not measured — no supported dependency manifest was read
- No exposed public API
- Test reliability not included
- early-stage repository — too little history to judge knowledge freshness
- git history depth insufficient
- git history depth insufficient
- single-maintainer — knowledge-concentration (bus factor) risk
New (20)
- Critical CVE: [GHSA redacted] (requirements-dev.txt)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (requirements-dev.txt)
- Medium CVE: [GHSA redacted] (requirements-dev.txt)
- Medium CVE: [GHSA redacted] (requirements-dev.txt)
- Medium CVE: PYSEC-2024-38 (requirements-dev.txt)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Outdated: alembic
- Outdated: email-validator
- Outdated: fastapi
- Outdated: psycopg2-binary
- Outdated: pydantic
- Outdated: python-jose
- Outdated: python-multipart
- Outdated: typer
- Outdated: types-passlib
- Outdated: types-python-jose
- Outdated: uvicorn
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
iunary/fastapi-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b41a88ddab55a4ab5141706307fecbc31e4649d7 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.