Skip to content
CAI
Software that uses CAICheck a score

jasontaylordev/CleanArchitecture

54.3

Adequate · 22 September 2026

1.9k

lines of production code

C#

with JavaScript, TypeScript

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a modern .NET 10 Clean Architecture solution template designed to scaffold full-stack applications with optional Angular or React frontends. It provides a robust backend infrastructure featuring MediatR-based command/query handling, EF Core data persistence with automatic audit tracking, and ASP.NET Core Identity for user management. The template includes comprehensive tooling for local development via .NET Aspire, along with integrated unit, functional, and Playwright-based end-to-end testing.

How it got here

2019 — .NET 10 and Aspire integration

16 changes.

The project upgraded its solution template to target .NET 10 and integrated .NET Aspire as the default orchestration layer, while simultaneously modernizing frontend dependencies to Angular 21 and React 19. This period established a robust clean architecture foundation by implementing core domain models, identity services, and application layer scaffolding with MediatR pipeline behaviors. It also introduced standardized patterns for auditing, validation, and error handling to support the template's multi-frontend capabilities.

2020–2023 — Clean Architecture modernization and testing

21 changes.

The project implemented a comprehensive Clean Architecture structure, introducing MediatR pipeline behaviors for cross-cutting concerns and EF Core interceptors for audit tracking and domain events. The web layer was modernized with Minimal APIs, .NET Aspire orchestration, and native OpenAPI support, while both Angular and React frontends were restructured with updated tooling and authentication. Extensive test coverage was added across unit, functional, and acceptance layers using Playwright and Aspire to ensure end-to-end reliability.

2024–2026 — Modernization and tooling overhaul

4 changes.

The project underwent a significant modernization of its development tooling, migrating the build system from Cake to PowerShell and introducing .NET Aspire for local environment orchestration. The React frontend was rebuilt using Vite and Pico CSS with dark mode support, while the application layer gained event logging for better observability.

Features

Add PriorityLevel enum to domain model

A new PriorityLevel enum has been added to the domain layer, defining four distinct levels: None, Low, Medium, and High. This provides a structured way to categorize priority within the application's domain logic.

src/Domain/Enums · high confidence

Added common model classes for lookups and operation results

The application now includes two new shared model classes in the Common.Models namespace. LookupDto provides a standardized structure for list-based selections (such as todo lists or items) and includes an embedded AutoMapper profile to map from domain entities. Result serves as a generic wrapper for operation outcomes, exposing success status and error details via immutable properties and static factory methods.

src/Application/Common/Models · high confidence

Application layer scaffolding with MediatR pipeline behaviors

The Application layer is initialized with dependency injection configuration that registers AutoMapper, FluentValidation, and MediatR. MediatR is configured with a set of open behaviors including Logging, UnhandledException handling, Authorization, Validation, and Performance monitoring, alongside a Logging pre-processor. A new AuthorizeAttribute is introduced to mark classes requiring authorization via roles or policies, and global usings are added to streamline references to core libraries like Ardalis.GuardClauses and EF Core.

src/Application · high confidence

Introduce .NET Aspire AppHost for local development orchestration

The solution now includes a .NET Aspire AppHost that orchestrates local development environments. This AppHost provisions the Web API and an optional JavaScript frontend, managing their dependencies and service discovery. It supports configurable database backends—PostgreSQL, SQL Server, or SQLite (default)—and automatically configures OpenTelemetry, resilience, and health checks for the services. The frontend is conditionally included based on the UseApiOnly template option, ensuring API-only projects remain lightweight.

src/AppHost · high confidence

Introduce Weather Forecasts query and DTO

Added a new GetWeatherForecasts query and its corresponding WeatherForecast DTO to the Application layer. This introduces a new capability to retrieve a list of simulated weather forecasts, including date, temperature in Celsius and Fahrenheit, and a summary description, via a MediatR handler.

src/Application/WeatherForecasts · high confidence

Introduce auditable entities, domain events, and colour value objects

The domain model now includes a BaseAuditableEntity that automatically tracks creation and modification timestamps and user IDs, which TodoItem and TodoList inherit. A new domain event system (BaseEvent implementing INotification) allows entities to raise events, such as TodoItemCompletedEvent when a todo item is marked as done. Additionally, a Colour value object provides a type-safe way to handle colour codes with validation, used by TodoList for theming.

Domain · high confidence

Introduces application-layer pipeline behaviors for validation, authorization, logging, performance, and exception handling

The application now intercepts all MediatR requests through a set of new pipeline behaviors. ValidationBehavior automatically runs FluentValidation validators and throws a ValidationException on failure. AuthorizationBehavior enforces \[Authorize\] attributes, checking user identity, role membership, and policy-based permissions via IIdentityService. LoggingBehavior logs incoming request details (name, user ID, username, and payload) for every request. PerformanceBehavior monitors request duration and logs a warning for any request taking longer than 500ms. UnhandledExceptionBehavior catches any exceptions thrown during request handling, logs them with full context, and re-throws them to ensure they are not silently swallowed.

src/Application/Common/Behaviours · high confidence

Introduction of CurrentUser service for identity resolution

A new CurrentUser service has been added to the Web layer to implement the IUser interface. This service resolves the current user's ID and roles by extracting the NameIdentifier and Role claims from the active HTTP context, providing a centralized mechanism for accessing authenticated user details within the application.

src/Web/Services · high confidence

Introduction of base domain classes for entities and value objects

The domain layer now includes abstract base classes for entities and value objects to standardize common behaviors. BaseEntity provides a simple integer Id property and a collection for managing domain events, allowing entities to track and expose events for processing. ValueObject introduces value-based equality semantics, implementing Equals, GetHashCode, and comparison operators (==, !=) based on the equality components of the object, ensuring consistent identity checks for immutable value types.

src/Domain/Common · high confidence

New Identity Service Implementation

The src/Infrastructure/Identity location now provides the core identity management capabilities for the application. This includes a new ApplicationUser entity extending IdentityUser, an extension method to map IdentityResult to the application's Result model, and the IdentityService implementation of IIdentityService. This service enables user creation, deletion, role checking, and authorization policy enforcement, effectively establishing the backend identity infrastructure.

src/Infrastructure/Identity · high confidence

Todo list query now returns colour theming data alongside priority levels

The GetTodos query handler has been updated to include a new Colours collection in its response, providing colour codes and names (e.g., Grey, Purple, Blue) for todo list theming. This change accompanies the existing PriorityLevels data and the list of todo items, enabling the client to apply visual themes to the todo lists.

src/Application/TodoLists/Queries · high confidence

Behavioural changes

Add custom exception classes for validation and authorization errors

The application now includes dedicated exception classes for handling validation failures and authorization denials. A new \ValidationException\ captures specific property-level error messages from FluentValidation, allowing clients to receive detailed feedback on which fields failed validation. Additionally, a \ForbiddenAccessException\ is introduced to explicitly represent 403 Forbidden responses, improving the clarity of authorization error handling.

src/Application/Common/Exceptions · high confidence

Added UnsupportedColourException for invalid colour codes

The domain now includes a specific exception class, UnsupportedColourException, which is thrown when an unsupported colour code is encountered. This provides clearer error messaging to users and developers by explicitly stating that the provided colour code is not valid, rather than relying on generic exception handling.

src/Domain/Exceptions · high confidence

Added logging for completed todo items

A new event handler, LogTodoItemCompleted, has been introduced to the Application layer. When a todo item is marked as completed, this handler logs the domain event using the application's logging infrastructure, providing visibility into completion actions without altering the core business logic.

src/Application/TodoItems/EventHandlers · high confidence

Angular client app restructured with new configuration and tooling

The client application in src/Web/ClientApp has been restructured to support a modern Angular setup (referenced as version 21 in documentation). This change introduces standard Angular configuration files (angular.json, tsconfig.json) and updates the TypeScript target to ES2022. It also adds an .editorconfig for consistent coding styles, a .gitignore for build artifacts, and a proxy configuration (proxy.conf.js) that routes API, OpenAPI, and Scalar requests to backend services defined via environment variables. Additionally, the nswag.json configuration remains to generate TypeScript clients from the OpenAPI spec, ensuring the frontend can interact with the backend API.

src/Web/ClientApp · high confidence

Automated audit tracking and domain event dispatching via EF Core interceptors

The application now automatically manages audit fields (Created, CreatedBy, LastModified, LastModifiedBy) for all auditable entities and dispatches pending domain events whenever changes are saved to the database. This is achieved through two new Entity Framework Core interceptors: AuditableEntityInterceptor, which updates timestamps and user IDs using a TimeProvider, and DispatchDomainEventsInterceptor, which publishes domain events via MediatR before the transaction commits.

src/Infrastructure/Data/Interceptors · high confidence

Build system migrated from Cake to PowerShell scripts

The build infrastructure has been replaced with a set of PowerShell scripts (build.ps1, repack.ps1, test.ps1), removing the previous Cake-based build process. This change introduces a new build workflow that handles solution compilation, client application builds (Angular/React), and template repacking. Additionally, a comprehensive test script is now available to validate the generated template across multiple client framework and database combinations, ensuring consistent behavior for new projects created from the template.

build · high confidence

Centralize role constants into the Domain layer

The application now defines role constants in a centralized location within the Domain layer. Specifically, a new \Roles\ class has been added to \src/Domain/Constants\, exposing the 'Administrator' role as a constant string. This change moves role definitions out of scattered locations into a single source of truth for the domain model.

src/Domain/Constants · high confidence

Client app restructured with built-in authentication and Pico CSS theming

The Angular client application has been restructured to include a built-in authentication system (login, registration, and logout) and a new visual style. A new \api-authorization\ module provides an \AuthService\ and \AuthGuard\ to protect routes like Weather and Tasks, while the \AuthorizeInterceptor\ automatically handles 401 responses by redirecting to the login page. The UI has been modernized by replacing Bootstrap with Pico CSS, introducing a dark mode toggle via a \ThemeService\ and \ThemeToggleComponent\, and updating the navigation menu to reflect the new auth state and styling.

src/Web/ClientApp/src · high confidence

Configurable database provider and identity service registration

The Infrastructure layer now registers the application's database context and identity services via a new DependencyInjection module. Users can select the database provider (PostgreSQL, SQL Server, or SQLite) through conditional compilation flags, with the context configured to use the appropriate EF Core provider and Aspire enrichment. Identity is registered using ASP.NET Core Identity API endpoints, with an option to include cookie-based sign-in management depending on the build configuration.

src/Infrastructure · high confidence

Introduction of core application interfaces for data, identity, and user context

This change introduces three new interfaces in the application layer to define contracts for data access, identity management, and current user context. IApplicationDbContext provides a standardized interface for accessing TodoList and TodoItem entities and saving changes. IIdentityService defines methods for user authentication and authorization, including retrieving user names, checking roles, authorizing against policies, and creating or deleting users. IUser replaces the previous ICurrentUserService, simplifying the naming of the interface that exposes the current user's ID and roles.

src/Application/Common/Interfaces · high confidence

Migrate React frontend from Create React App to Vite

The React client application has been rebuilt using Vite instead of Create React App, resulting in significantly faster development server startup and build times. This change introduces a new project structure with Vite-specific configuration files (vite.config.ts, tsconfig.json) and updates the development workflow to use standard npm scripts. The frontend now supports TypeScript JSX (tsx) out of the box and integrates with ASP.NET Core HTTPS certificates for secure local development. Additionally, the migration includes support for dark mode via Pico CSS and configures environment variables using Vite's VITE\_ prefix convention.

src/Web/ClientApp-React · high confidence

Modernized Minimal API endpoints with typed results and route groups

The Web API endpoints for TodoItems, TodoLists, WeatherForecasts, and Users have been refactored to use ASP.NET Core's typed results (e.g., TypedResults.Created, TypedResults.Ok) and are now organized into IEndpointGroup implementations mapped via RouteGroupBuilder. This change standardizes HTTP response handling, improves API documentation through EndpointSummary/Description attributes, and simplifies endpoint registration. The TodoItems endpoint now supports a dedicated PATCH operation for updating item details, while the Users endpoint integrates ASP.NET Core Identity API for authentication flows.

src/Web/Endpoints · high confidence

Modernized Minimal API infrastructure with native OpenAPI and structured error handling

The web layer's infrastructure has been refactored to use ASP.NET Core's native OpenAPI features and Minimal API conventions. Endpoint registration now relies on the new IEndpointGroup interface and WebApplicationExtensions.MapEndpoints, which automatically discovers endpoint groups, applies route prefixes, and assigns OpenAPI tags. To ensure generated clients and documentation are accurate, the system now uses ApiExceptionOperationTransformer to automatically document standard error responses (400, 401, 403) and BearerSecuritySchemeTransformer to configure JWT authentication in the OpenAPI spec. Additionally, IdentityApiOperationTransformer provides human-readable summaries for framework-generated Identity endpoints, while ProblemDetailsExceptionHandler converts application exceptions into RFC 9110-compliant ProblemDetails responses for consistent error reporting.

src/Web/Infrastructure · high confidence

Modernized Web API infrastructure with .NET Aspire and Scalar

The Web project has been refactored to use .NET Aspire for service orchestration and defaults to SQLite as the database provider. OpenAPI documentation is now generated using the built-in ASP.NET Core OpenAPI stack and displayed via Scalar, replacing the previous NSwag setup. The application now supports Azure Key Vault for secret management, includes dedicated configuration files for PostgreSQL and SQL Server, and provides updated HTTP client files for testing both API and Identity-based authentication flows.

src/Web · high confidence

New database initialization and configuration logic in Infrastructure/Data

The src/Infrastructure/Data location now contains the core EF Core setup for the application. ApplicationDbContext.cs defines the DbContext with DbSet properties for TodoList and TodoItem, and configures model building by applying configurations from the executing assembly. New configuration classes (TodoItemConfiguration.cs, TodoListConfiguration.cs) enforce specific constraints, such as a 200-character max length for titles and value object ownership for colors. Additionally, ApplicationDbContextInitialiser.cs introduces a new database initialization strategy that ensures the database is deleted and recreated on startup, then seeds default administrator roles, users, and sample todo data.

src/Infrastructure/Data · high confidence

React frontend rebuilt with Vite, Pico CSS, and dark mode support

The React client application has been modernized by migrating from Create React App to Vite, which enables faster development with hot module replacement and more efficient production builds. The UI styling has switched from Bootstrap to Pico CSS (configured with a violet theme and Inter/Outfit/JetBrains Mono fonts), and a new dark mode feature has been added, allowing users to toggle between light, dark, and auto themes via a theme toggle in the navigation menu. The application structure now uses React Router v6 for navigation, and the authentication flow has been updated to work with the new ASP.NET Core Identity API, featuring dedicated login, registration, and protected route components.

src/Web/ClientApp-React/src · high confidence

Refactored TodoItem commands to use guard clauses and simplified logic

The TodoItem command handlers (Create, Delete, Update, and UpdateDetail) have been refactored to use guard clauses for validation, such as checking for entity existence before modification. This change simplifies the control flow and improves code readability within the application layer's command structure.

src/Application/TodoItems/Commands · high confidence

Todo list commands now support color theming and async validation

The Create and Update TodoList commands now accept a Colour property, allowing users to assign colors to their todo lists (defaulting to Grey if omitted). Validation for list titles has been updated to use asynchronous checks (AnyAsync) to ensure uniqueness, and the Update command now correctly excludes the current list from uniqueness checks to prevent self-conflicts.

src/Application/TodoLists/Commands · high confidence

Updated command and query templates to support optional return types

The command and query use-case templates in the Clean Architecture project have been updated to conditionally include return types based on the 'hasReturnType' flag. This change ensures that generated commands and queries correctly implement IRequest\<TReturnType\> or IRequest depending on whether a return value is expected, and aligns the corresponding handlers and validators with this structure. This resolves issues with incorrect namespace directives and default return types in generated code.

templates/ca-use-case/FeatureName · high confidence

Upgrade to .NET 10 and Aspire integration

The solution template now targets .NET 10.0 (SDK 10.0.401) and integrates .NET Aspire as the default orchestration layer, requiring the AppHost project to run the application. The template supports Angular 21, React 19, or Web API-only configurations, with SQLite as the default database provider. It also introduces a new \ca-usecase\ scaffolding command for generating commands and queries, and enforces strict coding standards via a comprehensive .editorconfig and TreatWarningsAsErrors.

(repo-wide) · high confidence

Test coverage

Added Playwright acceptance tests for core web pages; Added Playwright-based acceptance tests for core web pages; Added acceptance test infrastructure using Aspire and Playwright; Added functional tests for TodoList and TodoItem commands and queries; Added global usings for NUnit in integration tests; Added unit tests for AutoMapper configuration and mapping validity; Added unit tests for ValidationException behavior; Added unit tests for the Colour value object; Added unit tests for the request logging behavior.

Dependencies

Upgrade to .NET 10 and Angular 21 with Central Package Management

The template now targets .NET 10.0, upgrading core libraries such as Entity Framework Core, ASP.NET Core, and MediatR to their .NET 10-compatible versions. The Angular frontend has been upgraded to version 21, while the React frontend now uses React 19 and Vite 8. To simplify dependency maintenance, the solution introduces central package management via Directory.Packages.props, and the AppHost infrastructure is updated to use .NET Aspire 13.5.4.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 55 → 54 (-0.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 75 → 75 (+0.2)
  • Architecture 75 → 76 (+0.2)
  • Maturity 69 → 67 (-2.7)
  • Readiness 47 → 48 (+0.6)
  • Security 70 → 73 (+3.3)
  • Event-Driven 100 → 100 (+0.0)
  • Accessibility 48 → 47 (-0.9)

Resolved (109)

  • Bounded contexts not declared
  • Change coupling: CreateTodoItem.cs ↔ DeleteTodoItem.cs (src/Application/TodoItems/Commands/CreateTodoItem/CreateTodoItem.cs)
  • Change coupling: DeleteTodoItem.cs ↔ UpdateTodoItem.cs (src/Application/TodoItems/Commands/DeleteTodoItem/DeleteTodoItem.cs)
  • Change coupling: DeleteTodoItem.cs ↔ UpdateTodoItemDetail.cs (src/Application/TodoItems/Commands/DeleteTodoItem/DeleteTodoItem.cs)
  • Change coupling: Program.cs ↔ DependencyInjection.cs (src/AppHost/Program.cs)
  • Change coupling: TodoItems.cs ↔ TodoLists.cs (src/Web/Endpoints/TodoItems.cs)
  • Change coupling: UpdateTodoItem.cs ↔ UpdateTodoItemDetail.cs (src/Application/TodoItems/Commands/UpdateTodoItem/UpdateTodoItem.cs)
  • Change coupling: proxy.conf.js ↔ Program.cs (src/Web/ClientApp/proxy.conf.js)
  • Coverage not measured
  • Critical CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp-React/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp-React/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • …and 89 more

New (94)

  • CommentedOutCode (src/ServiceDefaults/Extensions.cs)
  • Critical CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • Critical CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (src/Application/TodoLists/Commands/CreateTodoList/CreateTodoListCommandValidator.cs)
  • FunctionTooLong: Todo.Tasks (src/Web/ClientApp-React/src/components/Todo.jsx)
  • High CVE: [GHSA redacted] (src/Web/ClientApp-React/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp-React/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp-React/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp-React/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • High CVE: [GHSA redacted] (src/Web/ClientApp/package-lock.json)
  • …and 74 more

Changes since last survey

  • 19 commits — 19 feature/other, 0 fixes

By area

  • src/Web — 12 commits
  • (root) — 6 commits
  • .github/workflows — 1 commit

Notable commits

  • change: chore(deps): update .net dependencies (#1609)
  • change: chore(deps): update .net dependencies (#1636)
  • change: chore(deps): update .net dependencies (#1640)
  • change: chore(deps): update .net dependencies (#1641)
  • change: chore(deps): update .net dependencies (#1647)
  • change: chore(deps): update .net dependencies (#1649)
  • change: chore(deps): update all non-major dependencies (#1612)
  • change: chore(deps): update all non-major dependencies (#1643)
  • change: chore(deps): update all non-major dependencies (#1645)
  • change: chore(deps): update all non-major dependencies (#1648)
  • change: chore(deps): update all non-major dependencies (#1650)
  • change: chore(deps): update angular to v21.2.21 (#1610)
  • change: chore(deps): update angular to v21.2.22 (#1639)
  • change: chore(deps): update angular to v21.2.23 (#1646)
  • change: chore(deps): update dependency karma-jasmine-html-reporter to ~2.3.0 (#1644)
  • change: chore(deps): update github actions (#1619)
  • change: chore(deps): update react (#1611)
  • change: chore(deps): update react (#1642)
  • change: chore(deps): update testing (#1615)

Architecture

  • Unchanged — 3 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jasontaylordev/CleanArchitecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1d71eefc5ccf9a5e9b2db86e4cf08070148c7bb4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.