Skip to content
CAI
Software that uses CAICheck a score

jkazama/sample-boot-jpa

55.4

Adequate · 21 September 2026

8k

lines of production code

Java

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Spring Boot-based backend application that manages financial and administrative operations, including account management, asset tracking, and user authentication. It provides domain-specific services for handling cash flows, staff roles, and system settings, supported by a modernized infrastructure using JPA, Jakarta EE, and Spring Security. The system also includes utilities for CSV report generation and audit logging.

Features

Add CSV report generation and parsing utilities

New classes CsvLayout, CsvReader, and CsvWriter have been added to the src/main/java/sample/context/report/csv package. CsvLayout defines CSV formatting options (delimiter, quoting, encoding). CsvReader provides an iterator-based approach to parse CSV data from streams or byte arrays, handling headers and escaping. CsvWriter enables exporting data to CSV files or output streams, supporting both overwrite and append modes, with automatic header writing and proper escaping of special characters.

src/main/java/sample/context/report/csv · high confidence

Expanded CSV processing capabilities in the report module

The report module now provides concrete implementations for reading and writing CSV files, including support for custom layouts and stream-based processing. The \ReportFile\ class has been refactored to support both byte arrays and \InputStream\ resources, and the \ReportHandler\ now exposes methods for CSV import/export operations.

src/main/java/sample/context/report · medium confidence

Project initialization and tooling configuration

The repository was initialized with essential configuration files to standardize the development environment. An .editorconfig was added to enforce consistent coding styles (UTF-8, LF line endings, 4-space indentation for Java, 2-space for Gradle/YAML/XML/JSON). A .env file was created to define the Docker Compose project name. The .gitignore was updated to exclude IDE-specific files (IntelliJ, Eclipse, VS Code, etc.) and build artifacts. The Gradle wrapper scripts (gradlew, gradlew.bat) were updated to the latest version, and the LICENSE file was updated with the current copyright years.

(repo-wide) · high confidence

Behavioural changes

Added initial database schema and seed data for application tables

New SQL scripts have been added to the data directory, defining the DDL for system and application tables (including account, cash\_balance, cashflow, and staff) and populating them with initial seed data such as an admin user and sample accounts.

data · high confidence

Audit logging refactored to use JPA and Spring Data

The audit logging mechanism in the \sample.context.audit\ package has been refactored to use JPA and Spring Data instead of the previous Hibernate-specific ORM. \AuditActor\ and \AuditEvent\ entities now implement \DomainEntity\ and use standard JPA annotations, with \AuditActor\ gaining a \roleType\ field to capture user roles in the audit log. The \AuditHandler\ component has been updated to use \OrmRepository\ and \TxTemplate\ for persistence, and logging is now handled via the \@Slf4j\ annotation on the class rather than static logger fields.

src/main/java/sample/context/audit · high confidence

Migrate validation annotations to Jakarta EE and add new domain constraints

All existing constraint annotations in the \sample.model.constraints\ package have been migrated from the \javax.validation\ API to \jakarta.validation\, updating imports and package references accordingly. The \Email\ and \EmailEmpty\ annotations have been renamed to \MailAddress\ and \MailAddressEmpty\ respectively. Additionally, new constraint annotations have been introduced to support ISO 8601 formats for dates, times, and date-times, as well as a new \Ratio\ constraint for validating numeric rates. The legacy \Day\ and \DayEmpty\ annotations have been removed.

src/main/java/sample/model/constraints · high confidence

Migrated ORM infrastructure from Hibernate 5 to JPA with modernized entity and query builder components

The project has been upgraded from Hibernate 5 to JPA, replacing the legacy \OrmRepository\ and \OrmCriteria\ with a new \JpqlBuilder\ for dynamic JPQL generation and a modernized \Actor\ class that now implements \UserDetails\ for Spring Security integration. This change also introduces a new \TxTemplate\ for transaction management and updates the \OrmInterceptor\ to use \LocalDateTime\ instead of \Date\ for timestamping, reflecting a broader architectural shift towards standard JPA practices.

src/main/java/sample/context/orm · high confidence

Refactor IdLockHandler to use an interface and concurrent map

The IdLockHandler class has been refactored into an interface (IdLockHandler) with a default implementation (IdLockHandlerImpl). This change improves thread safety by replacing the previous HashMap with a ConcurrentHashMap and updates exception handling to use a centralized ErrorKeys constant. Users will see a more robust locking mechanism that better handles concurrent access to ID-based locks.

src/main/java/sample/context/lock · medium confidence

Refactor admin controllers to use constructor injection and explicit HTTP methods

The admin controllers have been refactored to use constructor injection via Lombok's @RequiredArgsConstructor, replacing the previous @Autowired field injection. Additionally, the controllers now explicitly specify HTTP methods (e.g., @GetMapping, @PostMapping) instead of using the generic @RequestMapping, and return ResponseEntity\<Void\> for POST operations to provide a consistent API response structure.

src/main/java/sample/controller/admin · high confidence

Refactored account domain models to use Jakarta EE annotations and modern Java patterns

The account domain models have been refactored to use Jakarta EE (javax → jakarta) persistence annotations and implement the DomainEntity interface. The Login class was removed and its functionality was moved to the master package, while the Account class was updated to use a record for its change parameters and replaced Lombok's @AllArgsConstructor with @Builder. Additionally, the FiAccount entity was updated to use a JPQL template for loading and the AccountStatusType enum had its validation methods renamed to isValid/isInvalid.

src/main/java/sample/model/account · high confidence

Refactored application configuration and security setup

The application's configuration and security have been restructured. A new \ApplicationProperties\ class now handles application settings, including mail and CORS options. Security is now managed via a dedicated \ApplicationSecurityConfig\ that configures Spring Security with form-based login, logout, and optional CORS filtering. Database configuration has been extracted into \ApplicationDbConfig\. Additionally, the \ApplicationConfig\ has been simplified, and the \Hibernate5Module\ has been upgraded to \Hibernate6Module\.

src/main/java/sample · high confidence

Refactored application layer to use constructor injection and explicit transaction templates

The application layer has been refactored to replace the previous \ServiceSupport\ base class with explicit constructor injection via \@RequiredArgsConstructor\. Services such as \AssetService\ and \SecurityService\ now directly depend on specific handlers (e.g., \AuditHandler\, \IdLockHandler\) and use \TxTemplate\ for transaction management, removing the need for \@Transactional\ annotations and \ServiceUtils\ helper classes. Additionally, the \SecurityService\ was converted into an \AuthenticationProvider\ implementation for Spring Security integration, and new admin services (\AssetAdminService\, \MasterAdminService\, \SystemAdminService\) were introduced to handle internal administrative use cases.

src/main/java/sample/usecase · high confidence

Refactored asset domain model to use Java 8+ types and updated naming conventions

The asset domain models (Asset, CashBalance, CashInOut, Cashflow) were refactored to use modern Java 8+ types (e.g., LocalDate, LocalDateTime) instead of legacy Date/String date representations. The canWithdraw method in Asset now accepts LocalDate for valueDay, and CashBalance queries use LocalDate for baseDay. Additionally, constant values in Remarks and CashflowType were updated to PascalCase, and error keys were externalized into AssetErrorKeys.

src/main/java/sample/model/asset · medium confidence

Refactored business day handling and introduced domain error keys

The \BusinessDayHandler\ was refactored to use \java.time.LocalDate\ instead of \String\ for date handling, improving type safety and modernizing the API. A new \DomainErrorKeys\ interface was added to centralize error message keys for domain validation. Additionally, the \DataFixtures\ component, which provided test data generation, was removed from the main source tree.

src/main/java/sample/model · high confidence

Refactored controllers to use Spring MVC annotations and dependency injection

The controller layer was refactored to modernize the implementation. Controllers now use standard Spring MVC annotations (e.g., @GetMapping, @PostMapping) instead of the generic @RequestMapping, and rely on constructor injection via @RequiredArgsConstructor rather than @Autowired or inheritance from a base class. The previous base class ControllerSupport and the AOP-based LoginInterceptor were removed; their functionality was replaced by a new ControllerUtils utility class and explicit session binding in ApplicationController. Additionally, DTOs were converted to Java records, and error handling was centralized in a new RestErrorAdvice class.

src/main/java/sample/controller · high confidence

Refactored master model entities to use JPA 3.0+ annotations and modern Java types

The master model entities (Login, Holiday, SelfFiAccount, Staff, StaffAuthority) were refactored to use JPA 3.0+ annotations (e.g., \jakarta.persistence.\\ instead of \javax.persistence.\\) and modern Java types (e.g., \LocalDate\ instead of \Date\/\String\ for dates). The \Holiday\ entity now uses \LocalDate\ for the \day\ field and \LocalDateTime\ for timestamps, replacing previous string-based date handling. The \Staff\ entity now includes a \roleType\ field and uses \ActorRoleType\ for role management. The \Login\ entity was added to handle actor login information, including password encoding. The \StaffAuthority\ entity was updated to use JPA 3.0+ annotations and modern Java types. These changes improve type safety and align with current JPA standards.

src/main/java/sample/model/master · medium confidence

Refactored validation and utility classes with modern Java types

The \Validator\ class was replaced by a new \AppValidator\ that supports message arguments and field-specific errors, while \BeanValidator\ was added to wrap Jakarta Bean Validation. The \TimePoint\ model was updated to use \java.time.LocalDate\ and \LocalDateTime\ instead of \java.util.Date\ and \String\, and \ConvertUtils\ was refactored to use \Optional\ and surrogate-pair-aware string handling. Additionally, \Encryptor\ was added to provide a builder for AES encryption, and \Calculator\ was simplified to use \BigDecimal\ directly.

src/main/java/sample/util · high confidence

Refactors domain infrastructure with new interfaces and lazy loading

The domain infrastructure layer has been refactored to use interfaces for better testability and lazy loading. The \DomainHelper\ and \Timestamper\ classes are now interfaces with default methods, delegating to new implementation classes (\DomainHelperProviderImpl\, \TimestamperImpl\) that use \ObjectProvider\ for lazy initialization. The \Entity\ and \Repository\ interfaces have been renamed to \DomainEntity\ and \GenericRepository\ respectively, with updated method signatures (e.g., \load\ returning \T\ instead of \Optional\<T\>\). A new \ActionStatusType\ enum and \ValidationException\ class have been added to support business logic validation and status tracking. Additionally, the \AppSettingHandler\ and \Entity\/\Repository\ interfaces have been restructured to support these changes.

src/main/java/sample/context · medium confidence

Removal of legacy REST error handling components

The \RestErrorAdvice\ and \RestErrorController\ classes, which previously handled RESTful error responses and error mapping, have been removed from the application. This eliminates the custom exception handling logic for REST controllers and the specific error controller endpoint, indicating a shift in how the application manages and presents error states to API consumers.

src/main/java/sample/context/rest · high confidence

Updated validation and application messages to English and modernized logging configuration

The application's resource files have been updated to support English error messages and modernize infrastructure configurations. Validation error messages in messages-validation.properties have been translated to English and updated to align with Jakarta Validation constraints. Application messages in messages.properties have also been translated to English, and audit log entries have been added for asset, master, and system operations. Additionally, the logging configuration has been refactored: a new banner.txt file was added, and separate Logback XML files were created for production (logback-spring-production.xml) and development (logback-spring.xml) environments, replacing the previous single logback.xml. The ehcache.xml configuration was also updated to use the newer Ehcache 3.x schema.

src/main/resources · high confidence

Test coverage

Migrated test infrastructure from JUnit 4 to JUnit 5

Replaced the legacy \EntityTestSupport\, \UnitTestSupport\, and \WebTestSupport\ base classes with a new \DomainTester\ framework that uses JUnit 5 and the H2 in-memory database. This provides a modern, lightweight test harness for domain model validation, supported by new mock implementations for \AppSettingHandler\, \IdGenerator\, and \Timestamper\ to facilitate isolated unit testing.

src/test · high confidence

Dependencies

Updated Gradle wrapper to version 8.14.1

The Gradle wrapper configuration has been updated to use Gradle version 8.14.1, replacing the previous version 2.6. This change includes adding network timeout and distribution validation settings to the wrapper properties, ensuring a more modern and secure build environment for the project.

gradle · high confidence

Upgrade to Spring Boot 3.5 and Java 21

The project has been upgraded to Spring Boot 3.5.0, which includes a migration to Java 21 and the use of the modern Gradle plugin management syntax. Dependencies have been updated to their latest versions, including Hibernate 6, and the build configuration now uses \mavenCentral()\ instead of \jcenter()\. The project name in \settings.gradle\ has also been changed to 'sample-boot-jpa'.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 53 → 55 (+2.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 100 (+2.1)
  • Architecture 100 (new)
  • Maturity 73 → 73 (+0.0)
  • Readiness 26 → 27 (+1.3)
  • Security 100 → 93 (-6.8)
  • Domain Modelling 72 → 76 (+4.3)

Resolved (11)

  • Coverage not included — suite not readable by the collector
  • CsvReader.parseRow (cognitive 25) (src/main/java/sample/context/report/csv/CsvReader.java)
  • CsvReader.readStreamLine (cognitive 29) (src/main/java/sample/context/report/csv/CsvReader.java)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (src/main/java/sample/context/audit/AuditHandler.java)
  • Duplicated block (8 lines × 2) (src/main/java/sample/context/audit/AuditHandler.java)
  • Duplicated block (9 lines × 4) (src/main/java/sample/context/orm/JpqlBuilder.java)
  • No exposed public API
  • Test reliability not included
  • change coupling unreadable for .java — no production change history could be paired for this repository's own source
  • single-maintainer — knowledge-concentration (bus factor) risk

New (13)

  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (12 lines × 4) (src/main/java/sample/context/orm/JpqlBuilder.java)
  • Duplicated block (23 lines × 2) (src/main/java/sample/context/audit/AuditHandler.java)
  • Duplicated block (9 lines × 2) (src/main/java/sample/context/audit/AuditHandler.java)
  • Leaked secret: password-hash-credential (data/db/201-dml-app.sql)
  • Low IaC: WD-COMPOSE-0002 (.devcontainer/compose.yml)
  • Low IaC: WD-COMPOSE-0002 (.devcontainer/compose.yml)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (src/main/java/sample/context/orm/JpqlBuilder.java)
  • Rotate the exposed credentials — git history can't be un-committed
  • Secret: password-hash-credential (data/db/201-dml-app.sql)
  • Secret: password-hash-credential (data/db/201-dml-app.sql)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jkazama/sample-boot-jpa was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 8f663e8a05d781656fff1c01a13ed76392da7b6f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.