Skip to content
CAI
Software that uses CAICheck a score

ivanpaulovich/clean-architecture-manga

37.5

Weak · 20 September 2026

6.6k

lines of production code

C#

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a multi-service wallet application built on .NET 7 that manages user accounts and financial transactions. It provides a React-based frontend and a backend API to handle account creation, deposits, withdrawals, transfers with currency conversion, and account closure. The architecture includes an IdentityServer4 service for authentication and uses SQL Server for persistent storage, all containerized via Docker for local and production deployment.

Features

Account repository implementation and fake for data access

The accounts-api now includes a concrete AccountRepository and its in-memory fake counterpart (AccountRepositoryFake) within the Infrastructure/DataAccess/Repositories layer. These classes implement the IAccountRepository interface, providing methods to add, delete, update, and retrieve accounts along with their associated credits and debits, enabling the application to persist and query account data via Entity Framework Core in production and in-memory contexts for testing.

accounts-api/src/Infrastructure/DataAccess/Repositories · high confidence

Added Bootstrap 4.4.1 front-end assets

The identity server's wwwroot now includes the Bootstrap 4.4.1 framework, providing the grid system, CSS, and JavaScript bundles. This adds responsive layout capabilities and UI components to the identity server's web interface.

identity-server/wwwroot · high confidence

Added currency exchange infrastructure with fake and real implementations

The accounts-api now includes a new CurrencyExchange infrastructure layer that provides two implementations of the ICurrencyExchange service: a fake version using hardcoded rates for testing or development, and a real version that fetches live exchange rates from the exchangeratesapi.io API. This enables the application to convert money between supported currencies (USD, EUR, CAD, GBP, SEK, BRL) using either static data or live external data depending on the configuration.

accounts-api/src/Infrastructure/CurrencyExchange · high confidence

Adds application-layer interfaces and validation infrastructure

The Application layer now includes core infrastructure for business logic execution: interfaces for currency conversion (ICurrencyExchange), unit of work (IUnitOfWork), and user context (IUserService), alongside a Notification class for collecting validation errors and a strongly-typed resource file for localized error messages.

accounts-api/src/Application · high confidence

Common API infrastructure and feature-gated capabilities

The accounts-api now includes a shared Common module that standardizes cross-cutting concerns and introduces new capabilities. Authentication is now configurable via feature flags, allowing the API to switch between IdentityServer4 (production) and a test handler (development). API documentation is now versioned and exposed via Swagger, with Swagger access itself controlled by a feature flag. The module also introduces custom API conventions for consistent controller responses, a feature-gated global exception filter, Prometheus HTTP metrics, CORS support, reverse proxy header forwarding, and data protection persistence.

accounts-api/src/WebApi/Modules/Common · high confidence

Custom error page for API v1

A new custom error handling view and controller have been added to the API v1 use cases. Users will now see a branded error page displaying a request ID when an error occurs, along with guidance on enabling the Development environment for local debugging.

accounts-api/src/WebApi/UseCases/V1/CustomError · high confidence

Initial IdentityServer4 implementation with .NET 7 and Docker support

The identity-server component has been added, providing a complete IdentityServer4 authentication and authorization service. The server is configured to run on .NET 7 (via the provided Dockerfile) and includes standard quickstart UIs for login, logout, consent, device flow, and external authentication. It is set up with in-memory data protection, CORS policies, and reverse proxy support, and defines a default client ('spa') for the Produce SPA React App with PKCE enabled.

identity-server · high confidence

Initial WebApi project scaffolding with .NET 7 and IdentityServer integration

The accounts-api WebApi project has been initialized with a new structure targeting .NET 7, including a Dockerfile based on the aspnet:7.0-alpine image and an entrypoint script for certificate handling. The application is configured to use IdentityServer 4 for authentication, with feature flags controlling access to endpoints like account management and currency exchange. The startup configuration includes SQL Server persistence, health checks, API versioning, Swagger documentation, and custom error handling, with separate appsettings files for development and production environments.

accounts-api/src/WebApi · high confidence

Initial data access infrastructure for account management

The accounts-api now includes the core Entity Framework Core infrastructure to persist account, credit, and debit data. This adds a \MangaContext\ for database operations, a \ContextFactory\ to support design-time tooling and migrations, and a \UnitOfWork\ to manage transactional saves. To support testing and development, a fake in-memory context (\MangaContextFake\) and unit of work (\UnitOfWorkFake\) are provided, along with an \EntityFactory\ for creating domain entities and \SeedData\ to populate initial test accounts and transactions.

accounts-api/src/Infrastructure/DataAccess · high confidence

Initial database schema and seed data for accounts

The application now includes the initial Entity Framework Core migration (InitialCreate) and corresponding model configurations for the Account, Credit, and Debit entities. This establishes the database schema with cascade-delete relationships between accounts and their transactions, and seeds the database with a default USD account and initial credit/debit records upon first migration.

accounts-api/src/Infrastructure/DataAccess/Configuration, accounts-api/src/Infrastructure/DataAccess/Migrations · high confidence

Initial domain model for account management

The accounts-api domain layer now includes the core entities and value objects required to manage user accounts. This introduces the Account aggregate root, which tracks credits and debits to calculate balances and enforce closing rules, alongside dedicated Credit and Debit entities. The model is supported by value objects for Money, Currency (including predefined codes like USD, EUR, GBP), and unique identifiers for accounts and transactions. Additionally, repository and factory interfaces are defined to handle account persistence and object creation, with localized error messages available for scenarios such as insufficient funds.

accounts-api/src/Domain · high confidence

Initial project scaffolding and documentation

The repository is initialized with the core project structure, including a .NET solution file defining the Clean Architecture layers (Domain, Application, Infrastructure, WebApi) and test projects. It includes configuration files for Docker, .editorconfig, and VS Code, along with comprehensive documentation such as a README, CHANGELOG, and contributor registry to support the open-source community.

(repo-wide) · high confidence

Initial project scaffolding for accounts-api

The accounts-api module has been initialized with standard .NET project configuration files. A Directory.Build.props file sets the default assembly version to 6.0.0, and a nuget.config file configures the official NuGet package source, establishing the baseline build environment for the service.

accounts-api · high confidence

Initial project scaffolding for wallet SPA and account infrastructure resources

This change introduces the foundational structure for the wallet single-page application and the account API's infrastructure layer. For the wallet SPA, it adds the standard public assets including the HTML entry point, a PWA manifest for standalone installation, and robots.txt configuration. Simultaneously, it adds strongly-typed resource files (Messages.Designer.cs and Messages.resx) to the accounts API infrastructure, providing localized string lookups for user identifiers and names.

accounts-api/src/Infrastructure, wallet-spa/public · high confidence

Initial wallet-spa configuration and Docker support

The wallet-spa location now includes the foundational configuration files required to run the React application in various environments. This adds environment-specific configuration files (.env.development, .env.docker, .env.localhost) that define authentication endpoints for IdentityServer4, API URLs, and SSL settings. It also introduces a Dockerfile based on Node 18 Alpine for containerized builds, a .dockerignore file to optimize build contexts, and standard project files like .gitignore and README.md. These changes enable the wallet-spa to be built and run locally or within Docker containers with proper identity and API integration.

wallet-spa · high confidence

Introduces structured use cases for retrieving and closing accounts

This change adds the application-layer logic for two new account operations: retrieving an account by ID and closing an account. For both operations, the system now enforces input validation (checking for empty IDs) via dedicated validation use cases that delegate to the core business logic. The close account operation specifically prevents closure if the account holds remaining funds and ensures the action is tied to the current user. Both use cases follow a consistent pattern with specific output ports to handle success, not-found, and invalid-state scenarios.

accounts-api/src/Application/UseCases/CloseAccount, accounts-api/src/Application/UseCases/GetAccount · high confidence

Introduction of external authentication user service implementations

The accounts-api now includes concrete implementations for the IUserService interface within the ExternalAuthentication infrastructure layer. The new ExternalUserService retrieves the current user's ID from the HTTP context's 'sub' claim, enabling integration with external identity providers like IdentityServer4. Additionally, a TestUserService is provided to return a default user ID during testing, facilitating local development and test scenarios without requiring live external authentication.

accounts-api/src/Infrastructure/ExternalAuthentication · high confidence

New API endpoints for opening and retrieving accounts

This change introduces two new v1 API endpoints for account management. Users can now open a new account by sending a POST request to /api/v1/Accounts/OpenAccount with amount and currency as form data, and retrieve existing account details via a GET request to /api/v1/Accounts/GetAccount/{accountId}. Both endpoints require authentication and are gated by feature flags (OpenAccount and GetAccount respectively).

accounts-api/src/WebApi/UseCases/V1/Accounts/OpenAccount · high confidence

New API response models for account details and transactions

The API now exposes structured view models for account data, introducing AccountDetailsModel, AccountModel, CreditModel, and DebitModel. These models define the shape of the response for account information, including account ID, current balance, currency, and detailed lists of credits and debits with transaction IDs, amounts, and dates, enabling clients to consume standardized account and transaction data.

accounts-api/src/WebApi/ViewModels · high confidence

New Docker Compose configuration for local development and production deployment

This change introduces a complete set of Docker Compose files to containerize the application stack, including the Wallet SPA, Accounts API, Identity Server, and SQL Server. It provides a \docker-compose.yml\ for the base services, an \override\ file for local development (using \wallet.local\ and specific ports), and a \production\ file for production environments. The configuration also includes setup scripts (\setup.sh\, \setup.ps1\, \setup.production.sh\) to generate self-signed SSL certificates for \wallet.local\, update the hosts file, and initialize the database, along with an \ssl-selfsigned.cnf\ configuration for certificate generation.

docker-compose · high confidence

New V1 API endpoint to retrieve accounts

A new controller and response model have been added to expose a GET /api/v1/accounts endpoint. This endpoint requires authentication, is gated by the GetAccounts feature flag, and returns a list of accounts formatted via AccountModel.

accounts-api/src/WebApi/UseCases/V1/Accounts/GetAccounts · high confidence

New V2 API endpoint for retrieving account details as an Excel file

A new V2 controller and request model have been added for the GetAccount use case. When authenticated users call the GET /api/v2/accounts/{AccountId} endpoint, the system now returns the account's ID and current balance in an Excel spreadsheet format, gated by the GetAccountV2 feature flag.

accounts-api/src/WebApi/UseCases/V2 · high confidence

New account lifecycle use cases: Open, Deposit, Withdraw, and Transfer

The application now supports creating new accounts and performing financial transactions. Users can open an account with an initial deposit, deposit funds into existing accounts, withdraw funds (with balance checks), and transfer money between accounts, including automatic currency conversion. Each operation includes input validation for account IDs, positive amounts, and supported currencies (Dollar, Euro, British Pound, Canadian, Real, Krona), and returns specific status outcomes such as success, not found, invalid input, or insufficient funds.

(repo-wide) · high confidence

New deposit, withdrawal, and transfer transaction endpoints

The API now exposes three new transaction operations for account management: deposit, withdrawal, and transfer. These are implemented via new controllers and response models in the V1 Transactions module, each gated by a specific feature flag (Deposit, Withdraw, Transfer) and requiring authentication. Users can now deposit funds, withdraw funds, and transfer amounts between accounts using PATCH requests, with responses returning the resulting transaction details.

accounts-api/src/WebApi/UseCases/V1/Transactions · high confidence

New use case for retrieving a user's accounts

The application now includes a new capability to fetch the list of accounts associated with the currently authenticated user. This change introduces the \GetAccountsUseCase\ within the \GetAccounts\ directory, which retrieves accounts via the \IAccountRepository\ and formats the result using a new \GetAccountPresenter\ that implements the \IOutputPort\ interface. This allows the system to return a structured list of accounts to the caller.

accounts-api/src/Application/UseCases/GetAccounts · high confidence

Nginx reverse proxy configuration for HTTPS and service routing

Added a new Nginx container configuration that enforces HTTPS by redirecting all HTTP traffic on port 80 to HTTPS on port 443. The secure server block proxies requests to specific backend services: /identity-server routes to the identity-server, /accounts-api routes to the accounts-api, and all other requests are forwarded to the wallet-spa frontend on port 3000, while passing standard proxy headers for IP and protocol information.

nginx · high confidence

Behavioural changes

Configurable module initialization with feature flags and use-case validation

The API now initializes its core modules (SQL Server persistence, currency exchange, health checks, and use cases) via dedicated extension methods that respect feature flags. When the SQL Server or Currency Exchange flags are enabled, the system registers real implementations (e.g., SQL Server DbContext, live HTTP client); otherwise, it falls back to fake implementations for local development or testing. Additionally, account-related use cases (Open, Close, Deposit, Withdraw, Transfer, Get) are now wrapped with validation decorators, ensuring that input validation is applied consistently across these operations.

accounts-api/src/WebApi/Modules · high confidence

Introduces React-based Single Page Application for Wallet Management

The wallet interface has been migrated to a React Single Page Application, replacing the previous implementation. This update introduces a Material UI-based design with a responsive layout featuring a collapsible side navigation drawer, a fixed header, and a footer. Users can now access core wallet features through a dedicated dashboard, including viewing account summaries, opening new accounts, and performing transactions such as deposits, withdrawals, and transfers. The application integrates IdentityServer4 for authentication, providing secure sign-in, sign-out, and silent token renewal capabilities, while routing is managed via React Router to handle both public and protected views.

wallet-spa/src · high confidence

Test coverage

Added component and end-to-end test infrastructure for the Accounts API; Added component tests for Accounts API endpoints; Added integration tests for account repository and currency exchange; Added unit tests for account lifecycle operations.

Dependencies

Upgrade to .NET 7 and add IdentityServer4

The accounts-api and identity-server projects have been upgraded to target .NET 7. This change includes updating core dependencies such as Entity Framework Core to version 7.0.8 and IdentityServer4 to version 4.1.2. Additionally, the identity-server project now includes Google authentication support via Microsoft.AspNetCore.Authentication.Google version 7.0.8.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 38 → 37 (-1.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 46 → 46 (+0.0)
  • Architecture 94 → 94 (+0.0)
  • Maturity 51 → 50 (-1.0)
  • Readiness 25 → 26 (+1.2)
  • Security 72 → 62 (-9.5)
  • Accessibility 41 → 40 (-1.0)

Resolved (30)

  • BarePragmaDisable (accounts-api/src/WebApi/UseCases/V1/Accounts/OpenAccount/AccountsController.cs)
  • BarePragmaDisable (accounts-api/src/WebApi/UseCases/V1/Transactions/Deposit/TransactionsController.cs)
  • BarePragmaDisable (accounts-api/src/WebApi/UseCases/V1/Transactions/Transfer/TransactionsController.cs)
  • BarePragmaDisable (accounts-api/src/WebApi/UseCases/V1/Transactions/Withdraw/TransactionsController.cs)
  • Bounded contexts not declared
  • Duplicated block (10 lines × 2) (accounts-api/src/Domain/Credits/CreditsCollection.cs)
  • Duplicated block (17 lines × 2) (accounts-api/src/Application/UseCases/Deposit/DepositValidationUseCase.cs)
  • Duplicated block (8 lines × 2) (accounts-api/src/Infrastructure/DataAccess/Migrations/InitialCreate.cs)
  • High IaC: DS-0002 (accounts-api-seed/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Low: security finding (details withheld)
  • Medium CVE: Azure.Identity 1.6.0
  • Medium CVE: Azure.Identity 1.6.0
  • Medium CVE: IdentityServer4 4.1.2
  • Medium CVE: IdentityServer4 4.1.2
  • Medium: security finding (details withheld)
  • No exposed public API
  • Outdated: IdentityServer4
  • …and 10 more

New (65)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (accounts-api/src/Application/UseCases/Deposit/DepositUseCase.cs)
  • Duplicated block (11 lines × 2) (accounts-api/src/Application/UseCases/Transfer/TransferUseCase.cs)
  • Duplicated block (11 lines × 2) (accounts-api/src/Domain/Credits/CreditsCollection.cs)
  • Duplicated block (15 lines × 2) (accounts-api/src/Application/UseCases/Transfer/TransferUseCase.cs)
  • Duplicated block (15 lines × 2) (accounts-api/src/Infrastructure/DataAccess/Configuration/CreditConfiguration.cs)
  • Duplicated block (15 lines × 2) (accounts-api/src/WebApi/Modules/Common/CustomApiConventions.cs)
  • Duplicated block (21 lines × 4) (accounts-api/src/Application/UseCases/Deposit/DepositValidationUseCase.cs)
  • Duplicated block (23 lines × 3) (accounts-api/src/Application/UseCases/Deposit/DepositValidationUseCase.cs)
  • Duplicated block (26 lines × 2) (accounts-api/src/WebApi/Modules/Common/CustomCorsExtensions.cs)
  • Duplicated block (26 lines × 2) (identity-server/Quickstart/Consent/ConsentController.cs)
  • Duplicated block (28 lines × 2) (accounts-api/src/Application/UseCases/Deposit/DepositValidationUseCase.cs)
  • Duplicated block (33 lines × 2) (identity-server/Quickstart/Consent/ConsentController.cs)
  • Duplicated block (8 lines × 2) (accounts-api/src/Infrastructure/DataAccess/Migrations/InitialCreate.cs)
  • Duplicated block (9 lines × 2) (accounts-api/src/WebApi/Modules/Common/ReverseProxyExtensions.cs)
  • End-of-life runtime: .NET net7.0
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 45 more

API surface

  • Unchanged — 11 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ivanpaulovich/clean-architecture-manga was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 68b1d5869dd9a7730c58eb0daf5051309eaf09a4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.