Skip to content
CAI
Software that uses CAICheck a score

jordifierro/abidria-api

52.5

Adequate · 22 September 2026

1.7k

lines of production code

Python

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Abidria is a Python-based API service that manages user accounts, experiences, and scenes. It supports user registration, authentication, and email verification, while allowing users to create and modify experiences and their associated scenes. The system also enables users to save and filter their own or saved experiences.

Features

Add local development setup scripts

New shell scripts have been added to the abidria/setup directory to streamline local development. envvars.sh defines environment variables for database credentials, secret keys, and email configuration. postgres.sh initializes the local PostgreSQL database and user. startup.sh activates the Python virtual environment, sources the environment variables, starts the PostgreSQL server, and launches the Django development server.

abidria/setup · high confidence

Initial project structure and API routing

The abidria application is initialized with a new project structure, including a generic ViewWrapper for handling HTTP methods and exception serialization, and URL routing for experiences, scenes, and people endpoints.

abidria · high confidence

Initial release of the Abidria API

The API now supports creating, listing, and updating experiences, including saving favorites and uploading pictures. Users can filter experience lists by 'mine' or 'saved' status. The backend is configured for Heroku deployment using Python 3.6.1 and Gunicorn.

(repo-wide) · high confidence

Introduce Scenes for Experiences

Users can now create, update, and upload pictures for scenes associated with an experience. This new feature allows users to add multiple scenes to a single experience, each with a title, description, geographic coordinates (latitude/longitude), and an optional picture. The system enforces validation on scene titles, descriptions, and coordinates, and requires appropriate permissions to modify scenes or their associated experiences.

scenes · high confidence

Introduce experiences module with save/unsave and filtering capabilities

The new 'experiences' module adds support for creating, modifying, and uploading pictures for experiences, as well as saving and unsaving them. Users can now filter the /experiences list by 'mine' (created by the current user) or 'saved' (marked by the current user). The experience entity now includes 'is\_mine' and 'is\_saved' flags, and the save functionality prevents users from saving their own experiences.

experiences · high confidence

Introduce user registration, authentication, and email confirmation

Added the core infrastructure for user accounts, including database models for people, auth tokens, and confirmation tokens. Implemented the full flow for guest account creation, username and email registration, and email verification via a new mailer service. This enables users to sign up, receive a confirmation email, and authenticate using access and refresh tokens.

people · high confidence

Test coverage

Added comprehensive test suite for the People module; Added test coverage for the Scenes module; Added tests for experience management features; Added unit tests for exception serialization.

Dependencies

Initial Python dependency manifest for the application

Added requirements.txt defining the project's Python dependencies, including Django 1.11.2, boto3, and various supporting libraries like gunicorn and psycopg2.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 52 → 53 (+0.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.2)
  • Architecture 100 → 88 (-11.7)
  • Maturity 45 → 45 (-0.0)
  • Readiness 32 → 35 (+3.3)
  • Security 86 → 92 (+5.4)

Resolved (11)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (requirements.txt)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (requirements.txt)
  • Medium CVE: [GHSA redacted] (requirements.txt)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • The README states the API is consumed by abidria-android but does not document how to set up the backend for local development or run tests. (README.md)
  • dormant codebase — no living knowledge left to concentrate

New (22)

  • Critical CVE: [GHSA redacted] (requirements.txt)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (5 lines × 4) (experiences/views.py)
  • High CVE: [GHSA redacted] (requirements.txt)
  • Hotspot: scenes/validators.py (scenes/validators.py)
  • Leaked secret: high-entropy-secret (abidria/setup/envvars.sh)
  • Leaked secret: signing-key (abidria/setup/envvars.sh)
  • Medium CVE: [GHSA redacted] (requirements.txt)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No ADRs found
  • Outdated: boto3
  • Outdated: dj-database-url
  • Outdated: django
  • Outdated: django-stdimage
  • Outdated: django-storages
  • Outdated: gunicorn
  • Outdated: mock
  • Outdated: psycopg2
  • …and 2 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jordifierro/abidria-api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d7689783bf23fbe43c395b07572a1380654652cd — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.