jeangatto/ASP.NET-Core-Vertical-Slice-Architecture
52.1
Adequate · 20 September 2026
876
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is a .NET 10-based REST API for managing a blog, built using Vertical Slice Architecture and CQRS principles. It provides core functionality for user registration, email/password authentication via JWT, and the creation and retrieval of blog posts with associated authors and tags. The application utilizes Entity Framework Core with SQLite for data persistence and enforces strict validation and referential integrity constraints.
Features
Added Author and Tag domain entities to the Post aggregate
The Post aggregate now includes dedicated Author and Tag domain entities. Users can now associate specific authors (identified by user ID and name) and tags (identified by title) with blog posts, enabling richer metadata and relationship management within the post content model.
src/Blog.PublicAPI/Domain/PostAggregate · high confidence
Initial project scaffolding with .NET 10 and Vertical Slice Architecture
The repository has been initialized with a sample ASP.NET Core 10 blog API built using Vertical Slice Architecture, CQRS, and REST principles. The project requires the .NET 10 SDK (version 10.0.204) and includes a new solution file (Blog.slnx), global configuration, and a comprehensive .editorconfig that enforces coding standards via Roslynator analyzers and .NET diagnostic rules. The API exposes endpoints for authentication, user management, and blog posts, utilizing technologies such as Entity Framework Core 10, SQLite, MediatR, and Scalar for API documentation.
(repo-wide) · high confidence
Initial release of the Blog Public API
This change introduces the Blog Public API, an ASP.NET Core application that exposes the blog's data through versioned REST endpoints. The API includes JWT-based authentication, automatic database initialization, and API versioning support. For developer experience, it integrates Scalar for API documentation in development environments and configures JSON serialization with camelCase naming and null-value suppression.
src/Blog.PublicAPI · high confidence
Introduces core API infrastructure for authentication, data access, and feature composition
This change adds the foundational service configuration for the Blog Public API. It introduces JWT Bearer authentication with strict token validation (zero clock skew) and a dedicated configuration model, registers an in-memory SQLite database context for data persistence, and sets up a feature-scanning system using MediatR, FluentValidation, and AutoMapper. Additionally, it provides a utility for converting titles into URL-friendly slugs.
src/Blog.PublicAPI/Extensions · high confidence
Introduction of EF Core database context for blog data access
A new BlogDbContext class has been added to the Data layer, establishing the Entity Framework Core configuration for the application. This context defines the primary entities (Posts and Users) and configures global conventions, such as disabling Unicode and setting a maximum length of 250 characters for string properties. It also explicitly disables lazy loading and applies entity configurations from the assembly while removing the default cascade delete convention to manage referential integrity.
src/Blog.PublicAPI/Data · high confidence
Introduction of Post and User domain aggregates
The domain layer now includes the core entity models for the blog system. The Post aggregate defines the structure for blog entries, including title, content, authorship, and associated tags, while the User aggregate establishes the foundation for user accounts with identity, authentication credentials, and account state.
Blog.PublicAPI.Domain · high confidence
Introduction of core domain interfaces
The domain layer now includes foundational interfaces for entity modeling: IAggregateRoot serves as a marker interface for aggregate roots, while IEntity\<TKey\> defines a generic contract requiring a non-null Id property, establishing the basis for identifying domain entities.
src/Blog.PublicAPI/Domain · high confidence
New Posts API endpoints for creating and retrieving blog posts
The Public API now exposes a Posts controller with two new endpoints: a POST /api/posts route to create a new blog post (requiring JWT authentication) and a GET /api/posts/{id} route to retrieve a post by its unique identifier (publicly accessible). The creation flow validates input using FluentValidation, enforces title uniqueness, and persists the post via MediatR handlers, while retrieval fetches the post from the database and maps it to a response object containing the title, content, creation date, and formatted tags.
src/Blog.PublicAPI/Features/Posts · high confidence
New email/password authentication endpoint
The API now exposes a POST /api/auth endpoint that accepts an email and password, validates the input, and returns a JWT access token upon successful authentication. The implementation uses MediatR to handle the request, verifies credentials against the database using BCrypt, and generates a signed JWT token with configurable expiration.
src/Blog.PublicAPI/Features/Authentication · high confidence
New user registration endpoint
The API now exposes a POST /api/users endpoint that allows anonymous users to register. The implementation validates input (name, email, password) using FluentValidation, checks for duplicate emails, hashes the password using BCrypt with SHA512, and persists both the User and associated Author entities to the database via MediatR and Entity Framework Core.
src/Blog.PublicAPI/Features/Users · high confidence
Behavioural changes
Adds Entity Framework Core configurations and restricts cascade deletes
This change introduces explicit Entity Framework Core mapping configurations for the Author, Post, Tag, and User entities, defining primary keys, required properties, string length limits, and unique indexes (such as on User email and the composite Tag PostId/Title). It also adds a ModelBuilder extension that globally overrides the default cascade delete behavior for foreign keys, changing it from Cascade to Restrict to prevent accidental deletion of referenced records.
src/Blog.PublicAPI/Data/Configurations · high confidence
Introduction of IFeatureMarker interface for feature registration
A new IFeatureMarker interface has been added to the Features/Abstractions namespace. This interface serves as a marker to facilitate the registration of features via assembly scanning, allowing the system to identify and register feature implementations based on their assembly rather than explicit individual registrations.
src/Blog.PublicAPI/Features/Abstractions · medium confidence
UserState enum defined with byte underlying type
The UserState enum, representing Active and Inactive states for users, has been introduced in the UserAggregate domain. It is explicitly defined with a byte underlying type, which may impact serialization or storage size for user state data.
src/Blog.PublicAPI/Domain/UserAggregate · high confidence
Test coverage
Added integration tests for the Users API controller; Added integration tests for the authentication controller; Added unit tests for StringExtensions and xUnit runner configuration.
Dependencies
Initial project setup targeting .NET 10 with wildcard dependency versions
The project introduces two new project files: the main API project (Blog.PublicAPI) and its corresponding test project (Blog.PublicAPI.Tests), both targeting .NET 10.0. The API project configures a stack including ASP.NET Core, Entity Framework Core with SQLite, JWT authentication, and Scalar for API documentation, while the test project sets up xUnit, FluentAssertions, and coverage tools. All NuGet package references utilize wildcard version notation (e.g., 10.\, 12.\) to allow flexible minor/patch updates.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 50 → 52 (+2.2)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 70 → 70 (-0.4)
- Architecture 69 → 69 (+0.0)
- Maturity 65 → 65 (+0.0)
- Readiness 37 → 45 (+8.4)
- Security 59 → 61 (+3.0)
- Domain Modelling 60 → 51 (-8.9)
Resolved (14)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- IL efficiency: 1 authored method(s) exceed the IL budget (src/Blog.PublicAPI/Data/Configurations/PostConfiguration.cs)
- No exposed public API
- redundant comment (src/Blog.PublicAPI/Data/Extensions/ModelBuilderExtensions.cs)
- single-maintainer — knowledge-concentration (bus factor) risk
New (23)
- CoverageExclusion (src/Blog.PublicAPI/Extensions/ServiceCollectionExtensions.cs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No dependency advisory monitoring
- Outdated: Roslynator.Analyzers
- Outdated: Roslynator.CodeAnalysis.Analyzers
- Outdated: Roslynator.CodeFixes
- Outdated: Roslynator.Formatting.Analyzers
- Outdated: xunit.analyzers
- …and 3 more
API surface
- Unchanged — 4 HTTP endpoints
Architecture
- Unchanged — 2 containers · 1 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
jeangatto/ASP.NET-Core-Vertical-Slice-Architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a79c79116633f73b204b66c59bad7c1467fa59c9 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.