juicycleff/ultimate-backend
50.0
Adequate · 21 September 2026
36.4k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
Ultimate Backend is an enterprise-grade, multi-tenant SaaS platform built on a microservices architecture using NestJS, gRPC, and GraphQL. It provides core domain capabilities for user account management, role-based access control, tenant administration, and Stripe-based billing, all coordinated through a CQRS and event-driven infrastructure. The system supports complex operational needs via webhook management, asynchronous email notifications, and robust CI/CD pipelines for Kubernetes deployment.
How it got here
2019 — Ultimate Backend rebrand and microservice expansion
56 changes.
The project was rebranded to Ultimate Backend and expanded into an enterprise-scale, multi-tenant SaaS architecture with new microservices for billing, tenants, and notifications. This period involved migrating the repository layer from TypeORM to MongoDB, adopting CQRS and code-first GraphQL, and establishing comprehensive CI/CD and infrastructure-as-code pipelines.
2020 — Microservices architecture and CQRS adoption
32 changes.
This period focused on establishing a comprehensive microservices architecture by introducing core services for accounts, access, billing, tenants, roles, and projects. The team implemented a consistent CQRS pattern with gRPC communication across these services, supported by a new core library handling multi-tenancy, configuration, and shared infrastructure. Initial integrations with Stripe for billing and Kubernetes for deployment automation were also completed.
Features
Account management CQRS command handlers
The service-account module now includes CQRS command handlers for core account operations: login (supporting password, Google, GitHub, and Facebook services), user registration (handling both local password and social sign-ups with automatic role and billing setup), email verification and resend, password reset, password update, and general user profile updates. These handlers wire the account service to the CQRS pattern, publishing domain events for each action.
apps/service-account/src/accounts/cqrs/commands/handlers/account · high confidence
Added ArangoDB support to the repository ORM
The repository ORM now supports ArangoDB alongside MongoDB. This change introduces a complete ArangoDB integration, including the \ArangoModule\ for dependency injection, an \ArangoDatabaseClient\ for connection management, and a \BaseArangoRepository\ for data access. It also provides \ArangoEntity\ and \ArangoEntityRepository\ decorators for defining entities, along with utilities for AQL query formatting and connection constants.
libs/repo-orm · high confidence
Added CQRS query handlers for retrieving single and multiple projects
New query handlers have been introduced to support fetching project data via the CQRS pattern. The \GetProjectHandler\ allows retrieving a single project based on a parsed filter, while the \GetProjectsHandler\ supports listing multiple projects with optional pagination (limit and skip). Both handlers utilize the \@juicycleff/repo-orm\ utilities to parse GraphQL-style filters into MongoDB queries and expose these capabilities through the \ProjectQueryHandlers\ export.
apps/service-project/src/projects/cqrs/query/handlers/project · high confidence
Added CQRS query handlers for tenant retrieval and availability checks
This change introduces the CQRS query handler implementations for tenant-related queries within the service-tenant application. Specifically, it adds handlers for fetching a single tenant (GetTenantHandler), fetching a list of tenants (GetTenantsHandler), and checking if a tenant is available (TenantAvailableHandler). These handlers utilize the TenantRepository and integrate with the @juicycleff/repo-orm for MongoDB query parsing, enforcing user-based filtering via member relationships where applicable. The handlers are exported via an index file to be registered as part of the application's query handler collection.
apps/service-tenant/src/tenants/cqrs/query/handlers/tenant · high confidence
Added Docker support and updated TypeScript configuration for service-project
The service-project now includes a Dockerfile that builds the application using Node 12 Alpine, exposes port 500193, and runs the compiled main.js entry point. A config.example file has been added to document required settings for MongoDB, EventStore, and Redis connections. Additionally, the TypeScript configuration (tsconfig.app.json) has been updated to include 'definitions/type.d.ts' in the compilation scope.
apps/service-project · high confidence
Added Kubernetes deployment update and rollback scripts
New shell scripts have been added to the scripts/kubernetes directory to manage Kubernetes deployments. The update-deployment.sh script iterates through NestJS application projects defined in nest-cli.json, sorts them by version, and performs a rolling update of their container images in a specified namespace (defaulting to production) using the IMAGE\_TAG variable. The rollback-deployment.sh script similarly identifies these services and executes kubectl rollout undo commands to revert deployments in the development namespace.
scripts/kubernetes · high confidence
Added core health-check infrastructure for microservices and MongoDB
The \libs/core/src/heath-indicators\ module now provides a foundational health-check system using \@nestjs/terminus\. It introduces a \BaseHealthService\ that configures a \/health\ endpoint, dynamically checking TCP connectivity for configured microservices and verifying MongoDB availability via a new \MongoHealthIndicator\. The module also includes stubs for EventStore and Redis health checks, a dedicated \IndicatorsModule\ for dependency injection, and shared interfaces for service status.
libs/core/src/heath-indicators · high confidence
Added core metadata storage and reflection utilities
The \libs/core/src/metadata\ module now includes a \MetadataStorage\ class and supporting utilities to manage reflection data for classes, fields, permissions, and resources. This introduces the underlying infrastructure for storing and retrieving type metadata (via \find-type.ts\ and \get-storage.ts\), which enables features like RBAC and resource definition that rely on runtime type information.
libs/core/src/metadata · high confidence
Added core module infrastructure with service registry and subscription support
The \libs/core/src/modules\ area now introduces several new foundational modules: \BaseModule\ handles automatic scanning and persistence of resource permissions via an RPC client; \CoreModule\ provides global exports for HTTP, CQRS, validation, logging, and cookie serialization; \ServiceRegistryModule\ integrates NestCloud components (Consul, Config, Service, Loadbalance, Schedule) along with Event Store and health checks; and \SubscriptionBaseClass\/\SubscriptionBaseProvider\ enable GraphQL subscriptions over both MQTT and NATS. These changes establish the core wiring for service discovery, configuration, event sourcing, and real-time subscriptions within the core library.
libs/core/src/modules · high confidence
Added email notification service with SendGrid integration
The email notification subsystem has been introduced to handle user-facing communications. It leverages SendGrid for delivery and defines specific templates for account activation, welcome messages, password resets, and verification codes. The service is wired into the application via an EventStore subscription to react to user lifecycle events (such as registration and login) and utilizes a Bull queue for asynchronous processing of these notifications.
apps/service-notification/src/email · high confidence
Added event handlers for Stripe billing and plan lifecycle events
The system now includes dedicated CQRS event handlers to process Stripe user lifecycle events (created, deleted, updated) and plan lifecycle events (created, deleted, updated). These new handlers, located in the billing and plan modules, currently log incoming events, establishing the infrastructure for future business logic integration.
libs/core/src/cqrs/events/handlers/billing, libs/core/src/cqrs/events/handlers/plan · high confidence
Added gRPC context propagation helpers
New helper functions have been added to the core library to facilitate passing authentication and tenant context through gRPC services. The \setRpcContext\ function serializes user, tenant, and header information from the GraphQL context into gRPC metadata, while \getIdentityFromCtx\ reconstructs these entities from incoming metadata, enabling consistent identity resolution across service boundaries.
libs/core/src/helpers · high confidence
Added saga handlers for authentication-related email notifications
The email notification service now includes an \AuthSagas\ module that listens for specific user events (such as registration, login, password reset, and email verification) and automatically queues corresponding email jobs. This ensures that users receive verification codes, reset links, and welcome emails triggered by these authentication actions without manual intervention.
apps/service-notification/src/email/sagas · high confidence
Added subscription query handlers with caching
The billing service now includes CQRS query handlers for retrieving subscription data. The new GetSubscriptionHandler fetches a single subscription by ID, while GetSubscriptionsHandler retrieves all subscriptions for a specific customer and tenant. Both handlers integrate with Stripe to fetch data and implement a caching layer (via CacheManager) to reduce redundant API calls, with TTLs set to 50 and 200 seconds respectively. The handlers are exported together in an index file for easy registration.
apps/service-billing/src/billings/cqrs/query/handlers/subscription · high confidence
Added user lifecycle event handlers
The system now includes dedicated event handlers for user creation, deletion, and updates within the CQRS event handling layer. These handlers (UserCreatedHandler, UserDeletedHandler, UserUpdatedHandler) are registered in the user event handler module and currently log incoming events, providing the foundational structure for processing user state changes.
libs/core/src/cqrs/events/handlers/user · high confidence
Added user retrieval query handler
Introduced a new CQRS query handler for retrieving user accounts. The \GetUserHandler\ processes \GetUserQuery\ requests by parsing GraphQL-style filter inputs into MongoDB queries using the \@juicycleff/repo-orm\ utility and executing the lookup via the \UserRepository\. The handler is registered in the module's export list via \AccountQueryHandlers\.
apps/service-account/src/accounts/cqrs/query/handlers/user · high confidence
Billing service introduces gRPC interface and CQRS architecture
The billing service now exposes its capabilities via a gRPC interface defined by the BillingService contract, handling operations for customers, plans, subscriptions, and invoices. Internally, the implementation has shifted to a Command Query Responsibility Segregation (CQRS) pattern, routing requests through Command and Query buses to dedicated handlers. The module also integrates EventStore for the '$ce-billing' stream to support event-driven billing logic.
apps/service-billing/src/billings · high confidence
Dockerization and configuration for service-access and service-account apps
Added Dockerfiles and example configuration files for the service-access and service-account applications, enabling containerized builds and runs. The service-access Dockerfile exposes port 50089, while service-account exposes port 50054. Additionally, TypeScript configuration files were updated to reflect the new app names, and linting configurations were moved to the respective app directories.
apps/service-access, apps/service-account · high confidence
Exposes CQRS event definitions
The CQRS module now exports its event definitions via a new index file, making the events available for consumption by other parts of the application.
libs/core/src/cqrs · high confidence
Implemented member invitation, update, and removal command handlers
Added CQRS command handlers for managing tenant membership, including accepting invitations, inviting new members, updating member roles, and removing members. The AcceptInvitationHandler validates JWT tokens and updates member status from PENDING to ACCEPTED while assigning roles. The InviteMemberHandler checks tenant existence, prevents duplicate invitations, generates invitation tokens, and publishes a MemberInvited event. The UpdateMemberHandler validates input fields and user permissions before updating member roles and publishing a MemberUpdated event. The RemoveMemberHandler enforces authorization rules (preventing removal of the tenant creator/owner) and removes members from both the tenant and their assigned roles, publishing a MemberRemoved event. All handlers are exported via a centralized index file for dependency injection.
apps/service-tenant/src/members/cqrs/command/handlers/member · high confidence
Implemented tenant lifecycle command handlers
Added CQRS command handlers for creating, updating, and removing tenants within the tenant service. The create handler now enforces unique tenant slugs, validates user authentication, checks for existing free-plan tenants, initializes billing subscriptions via the billing service, assigns the owner role, and publishes a TenantCreated event. The update handler allows modifying tenant names and settings while verifying member membership, and the remove handler deletes the tenant record and publishes a TenantRemoved event.
apps/service-tenant/src/tenants/cqrs/command/handlers/tenant · high confidence
Initial CQRS command/query handlers and event infrastructure for access tokens and billing
This change introduces the foundational CQRS command and query handlers for the \service-access\ and \service-billing\ applications, alongside core event handlers in \libs/core\. In \service-access\, new handlers implement the creation and deletion of access tokens (which now enforce permissions via \NestCasbinService\) and provide read/find capabilities with caching. In \service-billing\, the skeleton for plan management is added, including Stripe client wiring and data mappers, though the command handlers currently throw 'Not implemented' errors. Additionally, \libs/core\ now includes event handlers for access token lifecycle events and various account/member events, as well as GraphQL scalars for cursor, date-time, JSON, and MAC addresses.
(repo-wide) · high confidence
Initial CQRS event definitions and handlers for core domain entities
This change introduces the foundational structure for the application's event-driven architecture within the core library. It adds event definitions (impl) and corresponding handlers for key domain entities including Users, Tenants, Projects, Members, Plans, Billing (Stripe), Cards, Access Tokens, Subscriptions, and Webhooks. This provides the necessary hooks for reacting to lifecycle events such as user registration, tenant creation, project updates, and subscription changes, enabling future business logic to be decoupled via the CQRS pattern.
libs/core/src/cqrs/events · high confidence
Initial Docker and configuration setup for the billing service
The billing service now includes a Dockerfile based on Node 12 Alpine, exposing port 50067 and building the NestJS application. A configuration example file has been added defining settings for the billing port (9900), Stripe API key, MongoDB, EventStore, and Redis connections. Additionally, the TypeScript application configuration has been renamed from the service-user context to service-billing, updating the output directory accordingly.
apps/service-billing · high confidence
Initial Terraform infrastructure for AWS EKS cluster
Added Terraform configuration files to provision an Amazon EKS cluster on AWS. The setup includes a VPC with public and private subnets, an EKS cluster module using the official Terraform AWS modules, and worker groups configured with specific instance types (t2.small and t2.medium). It also defines necessary outputs for cluster access and variables for region, AWS profile, and IAM authentication mappings.
iac · high confidence
Initial billing microservice scaffolding with Stripe and MongoDB integration
The billing service is now available as a standalone NestJS microservice, bootstrapped with Fastify and configured for service discovery via Consul and configuration via environment variables. It integrates MongoDB for persistence and Stripe for payment processing, exposing core billing capabilities through dedicated modules for cards, billings, and plans. The service is wired to gRPC definitions in proto/billing.proto and includes environment-specific bootstrap configurations for development and production.
apps/service-billing/src · high confidence
Initial billing plan seeding and Stripe integration service
The service-billing module now includes a PlansService that manages the synchronization of subscription plans with Stripe. This service provides functionality to seed default plans (Basic, Starter, Medium, Large) into both the local database and Stripe, creating corresponding products and monthly/annual pricing tiers. It also exposes RPC methods to read and list Stripe plans with caching support, ensuring that billing configuration is initialized and accessible for users.
apps/service-billing/src/plans · high confidence
Initial implementation of the API Admin service with multi-tenant GraphQL resolvers and authentication
This change introduces the \api-admin\ application, a NestJS-based service that exposes a GraphQL API for managing platform resources. It includes resolvers and modules for access tokens, user accounts (with social login strategies for Facebook, Google, and GitHub), billing (subscriptions and invoices), and payment cards. The service is configured for multi-tenancy, using RPC clients to communicate with backend services, and includes environment-specific bootstrap configurations for development and production.
apps/api-admin/src · high confidence
Initial implementation of the Account service with gRPC and CQRS
The service-account application now provides a complete account management layer, exposing gRPC endpoints for user registration, login, logout, profile updates, password management, and email verification. Internally, the service utilizes a CQRS pattern to handle commands and queries, and integrates with an event store to process domain events such as user login and Stripe subscription creation via sagas. The service is configured for both development and production environments using bootstrap YAML files and connects to MongoDB, NATS, and Redis.
apps/service-account/src · high confidence
Initial implementation of the service-access microservice
The service-access application is introduced, providing a gRPC-based Access Service for managing access tokens and permissions. It implements the AccessService interface with gRPC methods for creating, reading, deleting, and checking rights for access tokens, utilizing a CQRS pattern with dedicated command and query handlers. The service integrates Casbin for role-based access control (RBAC) using a MongoDB adapter and a custom ACL model, and is configured for service discovery and configuration via Consul and NATS.
apps/service-access/src · high confidence
Initial implementation of the service-role microservice with gRPC-based RBAC
This change introduces the new service-role application, providing a role-based access control (RBAC) microservice built on NestJS and gRPC. The service exposes gRPC methods for checking user permissions (hasRights), reading user roles, and managing role assignments (addUserToRole, removeUserFromRole, addPolicy). It integrates Casbin for policy enforcement, configured to use MongoDB via a custom adapter, and includes a default resource builder for initial policy population. The service is containerized with a Dockerfile, supports environment-specific configuration via Consul, and includes unit and end-to-end tests.
apps/service-role · high confidence
Initial release of core API schema definitions
This change introduces the foundational protocol buffer schemas and their TypeScript implementations for the platform's core services. It defines the data models and service contracts for Access control, Account management (including user profiles, sessions, and authentication), Billing (covering plans, subscriptions, and payments), Projects, Roles, Tenants, and Webhooks. These files establish the interface definitions that other services will use to communicate via gRPC.
libs/proto-schema · high confidence
Initial release of notification and tenant services with Docker support
This change introduces the new service-notification and service-tenant applications to the platform. Each service is now accompanied by a Dockerfile (based on node:12-alpine), a TypeScript configuration (tsconfig.app.json), and an example configuration file (config.example) defining settings for MongoDB, Redis, and other dependencies. The notification service exposes port 50044, while the tenant service exposes port 50053. Additionally, linting configuration files (tslint.json) have been reorganized and moved into the respective service directories to support the new structure.
apps/service-tenant · high confidence
Initial release of the tenant service
The tenant service is now available as a standalone NestJS application. It provides core tenant and member management capabilities via the TenantsModule and MembersModule, integrated with MongoDB for persistence and Consul for service discovery. The service uses Fastify as its HTTP adapter and exposes gRPC endpoints defined in proto/tenant.proto, with environment-specific bootstrap configurations for development and production environments.
apps/service-tenant/src · high confidence
Initial service notification implementation with email queue support
The service-notification application has been initialized with a NestJS-based architecture, replacing the previous gateway-admin module structure. This change introduces core infrastructure for handling asynchronous notifications via a BullMQ queue, specifically processing authentication-related events such as user registration, email verification, password resets, login alerts, and tenant invitations. The service is configured to integrate with SendGrid for email delivery and utilizes environment variables for connecting to infrastructure services like Consul, NATS, and Redis, ensuring it can operate within the microservice mesh.
apps/service-notification/src · high confidence
Initial support for card payment method events and entity model
The system now includes infrastructure to handle card-related payment events and defines the underlying data model. A new \CardEntity\ has been added to the repository layer to represent card details, including identifiers, brand, last four digits, expiration, and billing address. On the core side, event handlers for \PaymentMethodAdded\, \PaymentMethodDeleted\, and \PaymentMethodUpdated\ events have been introduced; these currently log the incoming events, establishing the foundation for future business logic processing.
libs/core/src/cqrs/events/handlers/card, libs/repository/src/entities/types · high confidence
Initial tenant management service with CQRS and gRPC
This change introduces the core tenant management capabilities within the service-tenant application. It implements a CQRS architecture, defining specific commands for creating, updating, and removing tenants, and queries for retrieving tenant details, listing tenants, and checking availability. These commands and queries are exposed via a gRPC controller (TenantService) that processes requests using a CommandBus and QueryBus. The module also integrates with an event store (subscribing to $ce-tenant and $ce-point streams) and registers sagas to handle side effects, such as logging, upon tenant creation events.
apps/service-tenant/src/tenants · high confidence
Introduce CQRS-based project management service
The projects module now implements a Command Query Responsibility Segregation (CQRS) architecture for managing projects. This change introduces specific command handlers for creating, updating, and deleting projects, alongside query handlers for retrieving single or multiple projects. The gRPC controller delegates these operations to the respective command and query buses, while the module registers the necessary handlers and configures an EventStore subscription for the '$ce-project' stream to handle project-related events.
apps/service-project/src/projects · high confidence
Introduce multi-tenancy support with flexible tenant resolution and MongoDB isolation strategies
This change adds a new multi-tenancy module to the core library, enabling applications to resolve tenant context from various sources including domain names, HTTP headers, query parameters, cookies, and URL path parameters. It includes a global middleware to attach tenant information to requests and a request-scoped service that dynamically configures MongoDB connections. The service supports three database isolation strategies—Data Isolation, Database Isolation, and Both—allowing developers to choose whether tenants share a database with separate schemas or use entirely separate databases, with optional support for custom tenant-specific database hosts.
libs/core/src/mutiltenancy · high confidence
Introduce webhook service with CQRS and gRPC support
The new \service-webhook\ application provides a gRPC-based service for managing webhooks, implementing full CRUD operations (create, read, update, delete) via a CQRS architecture. The service exposes a \WebhookService\ interface, handling commands and queries through dedicated handlers and a MongoDB-backed repository. It is configured to integrate with an Event Store for stream processing and supports NATS for messaging, with environment-specific bootstrap configurations for development and production.
apps/service-webhook · high confidence
New CQRS-based member management API for tenant services
The tenant service now exposes a complete set of gRPC endpoints for managing tenant members, including inviting, accepting invitations, removing, and updating members, as well as reading single or filtered lists of members. This is implemented using a CQRS pattern with dedicated command and query handlers that delegate to the tenant repository, allowing members to be managed via role and status filters.
apps/service-tenant/src/members, apps/service-tenant/src/members/cqrs/query/handlers/member · high confidence
New GraphQL authentication guard with role-based access control
A new GqlAuthGuard has been introduced in the core library to enforce authentication and authorization for GraphQL resolvers. This guard supports both WebSocket (subscription) and HTTP contexts, validating user sessions and tenant access. It implements role-based access control by checking user rights against specific resources and actions via an RPC service, and also supports token-based authorization for tenants. The guard is exported from the core guards module and includes its associated test suite.
libs/core/src/guards · high confidence
New automation scripts for Docker, service registration, and NestJS builds
Three new shell scripts have been added to the scripts directory to streamline development workflows. The dockerize.sh script automates Docker image building and pushing using docker-compose. The register.sh script iterates through NestJS application projects defined in nest-cli.json, extracts service names, and registers their configurations into Consul's key-value store. The setup.sh script automates the building of all NestJS services and libraries listed in the configuration file.
scripts · high confidence
New core decorators and service infrastructure
This update introduces foundational building blocks for the core library, including decorators for role-based access control (Roles, Permission, Resource), identity extraction across HTTP, GraphQL, and RPC contexts (CurrentIdentity, HttpCurrentIdentity, RpcCurrentIdentity), and field filtering (Filterable). It also adds an instance collector decorator and exposes a suite of configuration and utility services such as AppLogger, AWS S3, Config, Mongo, EventStore, Cache, JWT, and MQTT clients, providing the necessary infrastructure for authentication, authorization, and external service integration.
libs/core/src/decorators, libs/core/src/services · high confidence
New core interfaces for RBAC, billing, and MQTT device management
This change introduces a new set of TypeScript interfaces in the core library to support role-based access control (RBAC), Stripe-based billing, and MQTT device command handling. Specifically, it adds \IPermission\ and \IResource\ (with defined \InAppRole\ types like admin, owner, member, etc.) to define access control structures, a \Customer\ class implementing Stripe's customer interface for billing integration, and \MqttCommandConfig\ types for device commands such as Wi-Fi updates, OTA updates, and reboots. Additionally, it defines the GraphQL context (\GqlContext\) to expose RPC client services for accounts, tenants, access tokens, roles, billing, and webhooks, and exports these via a new \index.ts\ barrel file.
libs/core/src/interfaces · high confidence
New gRPC client services for core domain modules
Added NestJS gRPC client services for Accounts, Access Tokens, Billings, Projects, Roles, Tenants, and Webhooks, each exposing a typed service client (e.g., AccountServiceClient, BillingServiceClient) via @nestcloud decorators and re-exported from the grpc-clients index. A global client service was moved from libs/common to this location and renamed to GlobalClientService. Basic unit tests were added for each new service to verify they can be instantiated within a NestJS testing module.
libs/core/src/services/grpc-clients · high confidence
New helper utilities for GraphQL gateway and query conditions
This change introduces new helper modules in the common library to support GraphQL federation and query building. A new \HeadersDatasource\ class extends \RemoteGraphQLDataSource\ to automatically forward safe HTTP headers from incoming requests to downstream services and handle \set-cookie\ responses by writing them to the client context. Additionally, new TypeScript definitions (\FindConditions\ type and \FindOperator\ class) are added to support complex query condition logic, and these are re-exported via the helpers index.
libs/common/src/helpers · high confidence
New service configuration constants for core library
The core library now exposes centralized constants for service discovery and access control. A new \SERVICE\_LIST\ object defines metadata (package names, Consul service names, and proto paths) for internal services including role, access, webhook, billing, tenant, account, project, and admin. Additionally, string constants for service access identifiers (e.g., \TENANT\_SERVICE\_ACCESS\, \AUTH\_SERVICE\_ACCESS\) are provided to standardize how other parts of the application reference these services.
libs/core/src/constants · high confidence
New shared interfaces for request context, class typing, and Consul service configuration
The common library now exports three new interface modules to support shared type definitions across services. The \request.interface\ module defines an \IRequest\ type extending Express's Request to include optional user, vhost, and tenant information, facilitating context propagation. The \class-type.interface\ module provides utility types like \ClassType\ and \DecoratorTypeOptions\ for generic class instantiation and decorator configuration. Additionally, the \consul-service-config.interface\ module introduces structured interfaces for Consul service configurations, covering application ports, database connections (MongoDB, EventStore, Redis), and their specific connection parameters. These changes standardize how request context and service configuration are typed within the application.
libs/common/src/interfaces · high confidence
New utility modules for caching, CORS, crypto, and data cleaning
The \libs/common/src/utils\ library has been expanded with several new utility modules to support authentication and data handling. A new \CachingUtils\ class provides deterministic cache key generation using stable JSON stringification and a custom hash function. CORS configuration is now centralized in \cors-config.util.ts\, offering specific options for Apollo with a whitelist and credentials enabled. Cryptographic operations are supported by \crypto.utils.ts\ for JWT-based token encryption and decryption, while \encryption.util.ts\ has been updated to use \bcryptjs\ and added Base64 cursor encoding/decoding helpers. Additional utilities include \magic-code.generator.ts\ and \verification-code-generator.ts\ for generating random codes, \mime-type.util.ts\ for a comprehensive list of MIME types, and \metadata.utils.ts\ to ensure Reflect metadata availability. A new \cleanEmptyProperties\ function allows recursive removal of empty values from objects, and \reduceByPercent\ provides percentage reduction calculations.
libs/common/src/utils · high confidence
Stripe billing integration for customers, subscriptions, and cards
The billing service now implements core Stripe operations via CQRS handlers and a dedicated card service. Users can create, update, and delete Stripe customers, as well as create, cancel, and change subscriptions, with events published for state changes. Invoice retrieval is supported with caching, and a new CardsModule provides services to add, read, set as default, and delete payment cards for customers.
(repo-wide) · high confidence
Webhook management and GraphQL query complexity enforcement
This change introduces the backend command and query handlers for creating, reading, updating, and deleting webhooks within the \service-webhook\ application, including validation of endpoint connectivity and support for Basic, Token, API Key, and OAuth 2 authentication methods. It also adds a GraphQL plugin that enforces a maximum query complexity of 20 to prevent expensive operations, alongside a new field-level roles guard for future access control.
(repo-wide) · high confidence
Removals
Removal of GraphQL Federation support
The GraphQL gateway no longer supports Apollo Federation. The \GraphqlDistributedModule\ and \GraphqlDistributedGatewayModule\ classes, along with the \ResolveReference\ decorator and \ReferencesExplorerService\, have been removed. This eliminates the ability to aggregate and resolve references across multiple GraphQL subgraphs.
libs/graphql-gateway · high confidence
Removal of GraphQL-specific authentication guard
The \GqlAuthGuard\ class, which previously handled authentication for GraphQL contexts by checking \ctx.isAuthenticated()\, has been removed from the \libs/common/src/guards\ library. This change also updates the guards module's index file to stop exporting the removed guard, effectively eliminating this specific authentication mechanism from the shared codebase.
libs/common/src/guards · high confidence
Removal of NestJS Casbin library and TypeORM adapter
The \libs/nest-casbin\ module has been removed from the application. This eliminates the previous implementation that used TypeORM to persist Casbin policies, along with the associated \NestCasbinModule\ and \NestCasbinService\ classes. Users relying on this specific library for role-based access control via a TypeORM-backed policy store will no longer have access to these components.
libs/nest-casbin · high confidence
Removal of custom exception classes
The custom \AppError\ and \ValidationError\ classes, which previously extended NestJS's \HttpException\ to provide standardized error handling with metadata support, have been removed from the common library. This change eliminates the centralized exception definitions and their re-exports from the \index.ts\ barrel file, meaning consumers of this library can no longer import these specific error types.
libs/common/src/exceptions · high confidence
Removal of gateway-admin application entry point
The main entry point file for the gateway-admin application has been deleted, removing the code responsible for bootstrapping the NestJS application and listening on port 3000.
apps/gateway-admin/src · high confidence
Removal of the NestJS Event Store library
The \libs/nestjs-event-store\ library has been completely removed from the codebase. This eliminates the previous integration with EventStore.org, including the \EventStore\ class for publishing and subscribing to domain events, the \NestjsEventStoreModule\ for dependency injection, and all associated configuration interfaces and constants. Applications relying on this library for event sourcing capabilities will no longer have access to these components.
libs/nestjs-event-store · high confidence
Removed Facebook OAuth integration and legacy auth components
The Facebook social login feature has been removed from the authentication service. This change deletes the \AuthController\ handling Facebook redirects, the \FacebookStrategy\ for passport integration, and the associated \AuthService\, \AuthResolver\, and \AuthModule\ files that supported this legacy authentication flow.
apps/service-auth/src/auth · high confidence
Removed legacy GraphQL resolver and module for Project service
The ProjectModule and ProjectResolver files have been deleted from the project service. This removes the previous GraphQL-based implementation for querying and mutating project data, including the project resolver that handled queries for single and paginated projects, mutations for creation, and property resolution for project owners.
apps/service-project/src/project · high confidence
Behavioural changes
Centralized configuration services for Redis, MongoDB, JWT, EventStore, and MQTT
The configuration logic for core infrastructure services has been reorganized into dedicated factory services within the core library. New services now handle options for Redis caching (via \cache-store-config.service.ts\), MongoDB connections (\mongo-config.service.ts\), JWT authentication (\jwt-config.service.ts\), EventStore (\eventstore-config.service.ts\), and MQTT messaging (\mqtt-client-config.service.ts\), all reading settings from Etcd or Consul. The legacy \ConfigService\ has been moved to this location and stripped of its TypeORM and EventSource configuration methods, which are no longer managed by this central class.
libs/core/src/services/configs · high confidence
Core library restructured with new service exports and removed legacy modules
The core library has been significantly reorganized: the legacy CoreModule and CoreService have been removed, and the public API now exports a broader set of modules including CQRS, guards, decorators, health indicators, scalers, and interceptors. Additionally, the BootstrapService has been moved from the user service application into the core library's services/bootstrap directory, and its associated test suite has been updated to reflect this new location and class name.
libs/core/src · high confidence
Migrate project service to CQRS and microservice architecture
The project service has been refactored from a GraphQL-based module to a Command-Query Responsibility Segregation (CQRS) architecture using NestJS CQRS. This change introduces dedicated command handlers for creating, updating, and deleting projects, which now publish domain events (e.g., ProjectCreatedEvent) via an event bus. The application bootstrap has been updated to use NestCloud with a Fastify adapter and a microservice setup, replacing the previous direct NestJS factory creation. Additionally, the service now relies on a multi-tenant MongoDB configuration via \MongoMultiTenantConfigService\ and includes new environment-specific bootstrap configuration files for development and production.
apps/service-project/src · high confidence
Migrated repository entities from TypeORM to a code-first ORM with new domain models
The repository layer has been refactored to replace the previous TypeORM-based entity definitions with a new code-first ORM approach (imported from @juicycleff/repo-orm). This change introduces several new domain entities for the platform's core features: AccessToken, Offer, Plan, Tenant, and Webhook, while removing the legacy Auth entity and its associated repository providers. Existing entities like User, Project, and BaseEntity have been significantly restructured to align with the new ORM, including changes to the base class structure (e.g., ID handling) and the User entity's authentication model (shifting from a direct OneToOne Auth relation to embedded social/local auth services).
libs/repository/src/entities · high confidence
Migrated repository layer from TypeORM to MongoDB with @juicycleff/repo-orm
The repository implementation has been switched from a relational TypeORM-based architecture to a document-based MongoDB architecture using the @juicycleff/repo-orm library. This change replaces the previous \BaseRepository\ and \EntityRepository\ classes with \BaseMongoRepository\ and \MongoEntityRepository\ decorators across all data access objects, including User, Tenant, Project, Plan, Offer, Webhook, and AccessToken. The migration introduces automatic caching via NestJS \CacheModule\ and enforces multi-tenancy through \InjectCurrentTenant\ in the Webhook repository. Existing TypeORM-specific methods (such as \createQueryBuilder\, \getAll\ with pagination, and \getByEmail\) have been removed in favor of the new ORM's built-in query capabilities, and the \AuthRepository\ has been deleted entirely as authentication logic is no longer handled at this layer.
libs/repository/src/repositories · high confidence
Migrated to code-first GraphQL schema definitions
The \libs/contracts\ library has been restructured to support a code-first GraphQL approach, replacing previous schema definitions with TypeScript classes and decorators. This change introduces a comprehensive set of shared GraphQL types, including base entities like \Node\ with standard \id\, \createdAt\, and \updatedAt\ fields, as well as specialized types for billing (\Address\, \Price\), features (\Feature\, \KeyValuePair\), and signals (\SignalData\). It also defines new input types for pagination (\PaginationInput\, \ConnectionPaginationInput\) and filtering (\BooleanComparisonFilter\, \StringComparisonFilter\, etc.), alongside enums for authentication services, billing intervals, subscription statuses, and webhook configurations. Additionally, helper utilities such as \FilterMongo\ and \ExtendConnectionType\ are provided to automatically generate GraphQL filter and connection structures based on these type definitions.
libs/contracts · high confidence
Migration of gateway-admin to api-admin with new Docker and configuration scaffolding
The application previously known as gateway-admin has been renamed to api-admin, reflected in the relocation of configuration files (tsconfig.app.json, tslint.json) and the update of the build output directory. A new Dockerfile has been introduced to containerize the service using Node 12 Alpine, exposing port 50020 and running the compiled NestJS application. Additionally, a config.example file has been added to document required settings for application ports, caching, authentication strategies (Facebook, GitHub, Google), and database connections (MongoDB, EventStore, Redis).
apps/api-admin · high confidence
Migration to code-first GraphQL and removal of legacy entry points
The user service has migrated from a schema-first GraphQL approach to a code-first implementation. As part of this architectural shift, the previous \main.ts\ bootstrap file and the \user.graphql\ schema definition file have been removed, indicating that the service's entry point and type definitions are now managed through the new code-first structure.
apps/service-user/src · high confidence
New request timeout interceptor and standardized error handling
The application now includes a new TimeoutInterceptor that automatically rejects HTTP requests taking longer than 5 seconds, improving responsiveness for slow operations. Additionally, the ExitInterceptor has been updated to wrap unhandled exceptions in ApolloError instances instead of generic HttpException objects, ensuring consistent error formatting for GraphQL clients. The common library also exports this new timeout interceptor and cleans up minor formatting in the context and cookie serializer providers.
libs/common/src/interceptors, libs/common/src/providers · high confidence
Notification service configuration and core library restructuring
The service-notification app now includes dedicated configuration services for Bull (Redis-based job queues) and SendGrid (email notifications), allowing these integrations to be bootstrapped via Consul and Etcd configuration stores. In the core library, the AWS S3 service implementation has been temporarily disabled (commented out) and moved to the 'others' directory, while the UUID generation utility has been updated to use the modern 'uuid' package API (importing 'v1' directly) to resolve linting and compatibility issues. Additionally, a placeholder AppLogger service has been added to the core library, and other utility services (Generator, Validator) have been relocated to the core 'others' directory.
apps/service-notification/src/configs, libs/core/src/services/others · high confidence
Order enum values changed from strings to integers and filename corrected
The Order enum in the repository library now uses integer values (0 for ASC, 1 for DESC) instead of string values ('ASC', 'DESC'). This change, along with the correction of the source filename from order.edum.ts to order.enum.ts, may break existing code that relies on the previous string-based enum values.
libs/repository/src/enums · high confidence
Project rebrand to Ultimate Backend with expanded microservice architecture and CI/CD infrastructure
The project has been rebranded from 'GraphQL CQRS Microservice Boilerplate' to 'Ultimate Backend', reflecting a shift toward an enterprise-scale, multi-tenant SaaS architecture. This change introduces a broader set of microservices (including billing, tenant, and webhook services) alongside existing ones, wired together via Consul for service discovery and NATS for messaging. To support this expanded scope, the repository now includes comprehensive CI/CD pipelines for GitLab and Azure DevOps, Docker Compose configurations for local development and production, and Infrastructure as Code (Terraform) for Kubernetes deployment. Additionally, security is enhanced with Snyk integration to patch known vulnerabilities in dependencies like lodash, and the internal library paths have been updated to reflect the new 'ultimatebackend' namespace.
(repo-wide) · high confidence
Refactor authentication decorators and introduce tenant context
The common decorators library has been updated to support multi-protocol contexts and multi-tenancy. The existing CurrentUser decorator now explicitly handles GraphQL execution contexts via GqlExecutionContext, ensuring robust user extraction in GraphQL resolvers. A new GrpcCurrentUser decorator has been added to extract the current user from gRPC arguments. Additionally, a new CurrentTenant decorator has been introduced to expose the tenant ID from the request context. The legacy Permission and Resource decorators, which relied on reflect-metadata for class-level definitions, have been removed from the exports.
libs/common/src/decorators · high confidence
Refactored authentication entity models and added tenant/payment data structures
The repository's embedded entity definitions have been restructured to support new tenant, payment, and social authentication capabilities. Social authentication models were simplified: the previous TypeORM-based FacebookAuth and GoogleAuth classes were replaced by a unified SocialAuth class, and LocalAuth was streamlined to store only a hashed password. New entity classes were introduced to support billing and tenant management, including PriceEmbed and KeyValuePair for payment plans, FeatureEmbed and ActionStatusType for plan features, TenantAccessEmbed for API keys, and TenantMemberEmbed along with BillingSettingEmbed and TenantSettingsEmbed for tenant configuration and membership.
libs/repository/src/entities/embeded · high confidence
Refactored common library module structure and exports
The common library has been restructured by removing the previous global CommonModule and CommonService, which previously bundled JWT configuration, HTTP module imports, and various utility services (Config, Validator, AwsS3, Generator) into a single global module. This change eliminates the global scope of these services, requiring consumers to explicitly import necessary modules. Additionally, the library's public API surface has been updated in index.ts to remove exports for the deleted module and service, while adding new exports for helpers, interfaces, and constants to support the refactored architecture.
libs/common/src · high confidence
Relaxed DTO validation and updated MongoDB ID type
The repository DTOs now skip runtime validation for search, pagination, and response fields (class-validator decorators are commented out), meaning fields like query strings, page numbers, and user/project names are no longer enforced as non-empty or strictly typed at the DTO layer. Additionally, the base DTO's ID field now accepts both string and MongoDB ObjectID types, and the Order enum in pagination options is passed as an array of values to Swagger for better API documentation compatibility.
libs/repository/src/dtos · high confidence
Removal of GraphQL User Module and Resolver
The user module and its associated GraphQL resolver have been removed from the service. This eliminates the previous GraphQL-based user data access layer, aligning with the project's migration to a code-first GraphQL approach or a different architectural pattern for user interactions.
apps/service-user/src/user · high confidence
Removal of QueryFailedFilter exception handler
The \QueryFailedFilter\ class, which previously caught \QueryFailedError\ exceptions from TypeORM and returned specific HTTP status codes (Conflict for unique constraint violations, Internal Server Error otherwise) with localized error messages, has been removed from the \libs/common/src/filters\ module. This change means that database query failures will no longer be handled by this specific filter, potentially altering how these errors are reported to API consumers. The \index.ts\ barrel file has also been updated to stop exporting the deleted filter.
libs/common/src/filters · high confidence
Removal of custom snake-case database naming strategy
The custom \SnakeNamingStrategy\ implementation for TypeORM has been removed from the common library. This means that database table and column names will no longer be automatically converted to snake\_case by this specific strategy; applications relying on this behavior must now either configure TypeORM's global naming strategy or implement the conversion logic elsewhere.
libs/common/src/strategies · high confidence
Removal of repository interface contracts
The explicit interface definitions for authentication, project, and user repositories have been removed from the codebase. This change eliminates the IAuthRepo, ITenantRepo, and IUserRepo contracts that previously defined method signatures for operations such as retrieving entities by local credentials, path, or ID, as well as storing user and project data.
libs/repository/src/repositories/contracts · high confidence
Removed legacy GraphQL schema and bootstrap configuration
The file-based GraphQL schema definition (auth.graphql) and the legacy application bootstrap entry point (main.ts) have been removed from the service-auth module. This eliminates the previous code-first GraphQL setup, including the GraphqlDistributedModule configuration, Swagger API documentation setup, and the specific port binding logic, indicating a shift away from the previous schema definition and initialization approach.
apps/service-auth/src · high confidence
Session management now uses Redis and external configuration
The authentication setup in libs/common/src/setup has been significantly enhanced to support production-grade session storage and flexible configuration. Sessions are no longer stored in-memory but are now persisted using a Redis store, initialized via NestCloud configuration. Session parameters such as the secret, cookie domain, max age, and security settings are now read from the application's auth configuration rather than being hardcoded. Additionally, the setup function now accepts an optional boolean flag to conditionally include Passport.js middleware, allowing for lighter-weight setups when authentication is not required, and includes user-agent parsing and cookie parsing middleware.
libs/common/src/setup · high confidence
Standardized error handling for GraphQL and gRPC services
The common error library has been refactored to provide structured, typed error classes for both GraphQL (Apollo) and gRPC (NestJS Microservices) communication layers. This change introduces dedicated error classes such as NotFoundError, BadRequestError, and UnauthorizedError for GraphQL, alongside corresponding RpcException classes for gRPC, replacing the previous single NotFoundError and generic GraphqlErrors utility. This allows consumers of the library to throw and catch specific, standardized errors that map directly to HTTP/gRPC status codes, improving error clarity and consistency across the application.
libs/common/src/errors · high confidence
Fixes
Added TypeScript definitions for MongoDB environment variables
A new type definition file (definitions/type.d.ts) has been added to extend the NodeJS Global interface. This change allows TypeScript to recognize the \_\_MONGO\URI\\_ and \_\_MONGO\_DB\NAME\\_ global variables, improving type safety and IntelliSense support for MongoDB connection configuration.
definitions · high confidence
Test coverage
Added and reorganized end-to-end test suites for admin and service apps; Added e2e test configuration and relocated test spec; Added e2e test infrastructure for service-notification.
Dependencies
Major dependency upgrade and project rebranding to Ultimate Backend
The project has been renamed to 'ultimate-backend' (version 2.0.0-beta.4) and underwent a significant dependency overhaul. Core NestJS libraries were upgraded from v6 to v7, and GraphQL packages were updated to support Apollo Federation v0.17 and GraphQL v15. New integrations were added for gRPC, NATS, MongoDB, Redis, Memcached, and Stripe, while older dependencies like ArangoDB and Influx were introduced or updated. Build scripts were modified to use npx for Nest CLI commands, and security protections via Snyk were integrated into the preparation phase.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 43 → 50 (+7.5)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 70 → 70 (+0.6)
- Architecture 43 → 57 (+13.7)
- Maturity 66 → 69 (+3.0)
- Readiness 32 → 42 (+9.7)
- Security 45 → 47 (+2.2)
- Domain Modelling 100 → 100 (+0.0)
Resolved (57)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- …and 37 more
New (345)
- ClassTooLong: BaseArangoRepository (libs/repo-orm/src/database/arango/repository/base-arango.repository.ts)
- ClassTooLong: BaseMongoRepository (libs/repo-orm/src/database/mongo/repository/base-mongo.repository.ts)
- ClassTooLong: Invoice (libs/proto-schema/src/billing.ts)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- …and 325 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
juicycleff/ultimate-backend was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0ae62a4b894c0e46baf75228ec88fae98f6abe06 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.