Skip to content
CAI
Software that uses CAICheck a score

jzwo/CleanAdmin

54.8

Adequate · 21 September 2026

13.2k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

CleanAdmin is a .NET 10-based administrative system that manages users, roles, and menu structures with granular permission controls. It provides a RESTful API with JWT and API key authentication, supporting AI-driven chat features and distributed caching. The architecture has been refactored from a legacy Blazor WebAssembly client to a modern web application with a centralized API service, ensuring consistent database schema management and secure access control.

How it got here

2025 — CleanAdmin migration and cleanup

18 changes.

The project was renamed to CleanAdmin and upgraded to .NET 10, while the legacy Blazor WebAssembly client and Web App scaffolding were removed. This period focused on stripping out obsolete domain models, API controllers, and test infrastructure to simplify the architecture.

2026 — CleanAdmin rebranding and feature expansion

14 changes.

This period focused on renaming the project to CleanAdmin and flattening the solution structure, while introducing a comprehensive permission and role-based access control system. The work also established a modern development environment using .NET Aspire and expanded the API with AI chat capabilities and menu management features.

Features

Add Redis-backed data protection and default admin/menu seed data

The application now supports distributed data protection by persisting encryption keys to a StackExchange.Redis instance, ensuring key consistency across multiple instances. Additionally, the system now automatically seeds a default super-administrator account and a set of initial menu structures (Home, System Manage, AI Chat, and associated user/role/menu management items) upon first run, establishing the baseline navigation and administrative access.

src/CleanAdmin.ApiService/Extensions · high confidence

Added menu and role management commands and queries

The application layer now includes commands for creating, updating, deleting, hiding, showing, and reordering menus, as well as creating, updating, and deleting roles and their permissions. Corresponding validators and handlers implement the business logic for these operations. Additionally, queries and domain event handlers were added to support menu validation (e.g., checking for circular references, duplicate names, or route path conflicts) and to synchronize user permissions when role permissions change.

src/CleanAdmin.ApiService/Application · high confidence

Auto-generated Kiota SDK for CleanAdmin API integration

The client now includes an auto-generated Kiota SDK (version 1.0.0) that provides strongly-typed request builders for the CleanAdmin API. This adds typed access to endpoints for authentication (login, create, refresh token), menu management (current user, hide/show/sort), and AI chat, enabling the application to interact with the backend via a structured, type-safe client library.

src/CleanAdmin.Web.Client · high confidence

Centralized permission definitions for system resources

A new PermissionRegistrar class has been added to CleanAdmin.Shared to centralize the definition of permissions for System resources, including Users, Roles, and Menus. This change introduces structured permission groups for List, Create, Update, and Delete actions, along with specific permissions like ManagePermissions and SetVisibility, establishing the foundation for enforcing permission checks on endpoints and seeding menu actions.

src/CleanAdmin.Shared · high confidence

Introduce Aspire-based app host and migration service for local development

The solution now includes a new \CleanAdmin.AppHost\ project that uses .NET Aspire to orchestrate local infrastructure, including Redis, RabbitMQ, and PostgreSQL, and defines the \CleanAdmin\_MigrationService\ background service that automatically applies Entity Framework Core database migrations on startup. Additionally, the \CleanAdmin.MigrationService\ project has been added to handle database initialization and schema updates, ensuring the database schema is kept in sync with the application's data models.

(repo-wide) · high confidence

Introduce authentication, permissions, and AI infrastructure in the API service

The CleanAdmin.ApiService entry point (Program.cs) and configuration files have been added, establishing the application's startup logic. This includes configuring JWT and API key authentication schemes, registering services for user permissions and claims transformation, and setting up the database context with PostgreSQL. Additionally, the service integrates AI capabilities via the Microsoft.Agents.AI.DevUI package and configures OpenAI settings in appsettings.json, while also enabling health checks, Prometheus metrics, and SignalR support.

src/CleanAdmin.ApiService · high confidence

Introduces API key authentication and user permission management endpoints

The API now supports authentication via an API key header (x-api-key) for programmatic access, alongside existing JWT-based flows. A new middleware extracts current user claims and permissions into a scoped ICurrentUser service, enabling endpoints to identify the caller and their permission codes. New endpoints allow users to view and update their profile and password, while menu and role management endpoints enforce granular permission checks using the new permission system. Additionally, an AI chat endpoint is exposed for streaming responses.

src/CleanAdmin.ApiService/Endpoints · high confidence

Introduces domain models for menus, roles, and users with permission management

The domain layer now includes new aggregate roots for Menu, Role, and User, enabling the system to manage menu structures, role-based access control, and user profiles. The User aggregate implements logic to build and synchronize user permissions based on role-permission mappings, while the Menu aggregate supports tree structures and visibility control. Additionally, the Order aggregate was migrated to the new CleanAdmin namespace.

src/CleanAdmin.Domain · high confidence

Removals

Removed demo, order, and user API controllers

The application's demo, order, and user API endpoints have been removed. Specifically, the DemoController, OrderController, and UserController files have been deleted from the Controllers directory. This eliminates the associated HTTP routes for JSON handling, order management, and user authentication (login/auth) from the web layer.

src/NcpAdminBlazor.Web/Controllers · high confidence

Removed obsolete Blazor client project files

The NcpAdminBlazor.Client solution file, Program.cs, and Routes.razor have been removed. This cleanup eliminates the legacy Blazor WebAssembly client project structure, indicating a shift away from the previous client-side application architecture.

src/NcpAdminBlazor.Client · high confidence

Removed obsolete authentication and utility pages

The obsolete authentication pages (Forgot, Login, Register, Reset) and utility pages (FAQ, WasmLoading) have been removed from the client application. This cleanup eliminates unused Razor components that were no longer part of the active user flow, streamlining the navigation structure and reducing the client-side bundle size.

src/NcpAdminBlazor.Client/Pages/Pages · high confidence

Removed obsolete personal pages

The Account, Dashboard, Form, and Test pages in the Personal section have been removed from the application. This eliminates the user-facing interfaces for account management, dashboard metrics, registration forms, and internal testing endpoints, likely as part of a broader authentication and layout refactoring.

src/NcpAdminBlazor.Client/Pages/Personal · high confidence

Behavioural changes

Add custom scrollbar styles and apply to ChromeStyleReuseTabs content

A new CSS file (app.css) introduces custom scrollbar styling for the application, including a \.scrollbar-custom\ class that defines a 6px wide, rounded scrollbar with a semi-transparent black thumb. This style is applied to the \ChromeStyleReuseTabs\ component to provide a consistent, modern scrolling experience across Chrome-based browsers.

src/CleanAdmin.Web/wwwroot · high confidence

Migrate solution to CleanAdmin and flatten web project paths

The solution has been renamed from NcpAdminBlazor to CleanAdmin, with all project paths flattened to remove the previous nested structure. This includes renaming the infrastructure namespace from NcpAdminBlazor.Infrastructure to CleanAdmin.Infrastructure, updating entity type configurations for Order, DeliverRecord, Menu, Role, and User, and adjusting database table names (e.g., 'deliverrecord' to 'deliver\_record'). Additionally, the primary key generation strategy for Order and DeliverRecord entities has been changed from SnowFlake to GuidVersion7, and the application context now includes User, Role, and Menu entities.

src/CleanAdmin.Infrastructure · medium confidence

Migrate to CleanAdmin and centralize API service configuration

The web project has been renamed to CleanAdmin and reorganized, including renaming the solution and flattening web project paths. Configuration for the API service address is now centralized in appsettings.json and appsettings.Demo.json, with the default address set to 'https+http://apiservice'. The application now supports both server-side and WebAssembly rendering modes, and integrates YARP for HTTP forwarding and service discovery. Additionally, unused dependencies like @ant-design/pro-layout have been removed, and a .gitignore file has been added to exclude build artifacts.

src/CleanAdmin.Web · medium confidence

Project renamed to CleanAdmin and upgraded to .NET 10

The solution has been renamed from NcpAdminBlazor to CleanAdmin, with all project references, build properties, and solution files updated to reflect the new name. The project has also been upgraded to .NET 10, as indicated by the SDK version bump in global.json and the updated Directory.Build.props. This change affects the entire solution structure, including the solution file, build configuration, and documentation files.

(repo-wide) · high confidence

Removal of legacy Blazor Web App scaffolding and configuration

The NcpAdminBlazor.Web project has removed the original Blazor Web App template files, including the main Program.cs, Dockerfile, and associated query and extension classes. This change strips out the default Blazor server-side rendering and hot-assembly-reloading infrastructure, indicating a shift away from the initial Blazor project structure towards a different architectural approach for the web layer.

src/NcpAdminBlazor.Web · high confidence

Removal of legacy Blazor WebAssembly app shell and imports

The legacy Blazor WebAssembly application shell (App.razor) and its associated global imports (\_Imports.razor) have been removed. This eliminates the previous rendering mode configuration and global namespace imports for MudBlazor and the client project, indicating a structural shift away from the old Blazor WebAssembly project setup.

src/NcpAdminBlazor.Web/Components · high confidence

Removal of obsolete client-side model classes

The following model classes have been removed from the client application: ChatMessage, ChatUser, LoginModel, LoginResult, RegisterModel, RegisterResult, Response, Student, UpdateModel, UserDetails, UserModel, and WeatherForecast. This cleanup eliminates unused or deprecated data structures from the NcpAdminBlazor.Client.Models namespace.

src/NcpAdminBlazor.Client/Models · high confidence

Removed chat and email application pages

The chat and email application pages have been removed from the application. This includes the main layout and component files for the Chat feature (Chat, ChatChannels, ChatUsers, User, UserMessage) and the Email feature (Email, EmailNavList, Inbox). Users will no longer have access to these specific UI components within the Applications section.

src/NcpAdminBlazor.Client/Pages/Applications · high confidence

Removed default template pages

The default Blazor template pages—Counter, Home, and Weather—have been removed from the application. Users will no longer see the standard counter, home, and weather forecast pages that are typically included in new Blazor projects.

src/NcpAdminBlazor.Client/Pages · high confidence

Removed legacy layout components and string extension

Removed the legacy layout components (MainLayout, LoginLayout, NavMenu, PersonCard) and the StringExtension utility class from the client application. This change eliminates the previous implementation of the application's primary layout structure and navigation menu, likely as part of a broader refactoring to simplify the UI architecture.

src/NcpAdminBlazor.Client/Layout · high confidence

Removed obsolete database repository and design-time factory files

The codebase has removed the \DesignTimeApplicationDbContextFactory\ and the \DeliverRecordRepository\ and \OrderRepository\ files from the \NcpAdminBlazor.Infrastructure\ project. These files previously contained MySQL-specific configuration and repository implementations that are no longer present, indicating a shift away from the previous database setup and repository structure in this layer.

src/NcpAdminBlazor.Infrastructure · medium confidence

Removed obsolete domain models and events

The domain layer has been cleaned up by removing the \DeliverRecord\ aggregate and the \OrderPaidDomainEvent\. These files are no longer part of the current domain model, indicating a simplification of the domain logic and event structure.

src/NcpAdminBlazor.Domain · high confidence

Removed placeholder and hardcoded login endpoint

The placeholder authentication endpoint at /api/user/auth and the hardcoded login endpoint at /api/user/login have been removed. Users will no longer be able to access these specific legacy authentication routes, which previously returned a static success response or generated a JWT token without validating user credentials.

src/NcpAdminBlazor.Web/Endpoints · high confidence

Removed token-based authentication state provider

The \TokenAuthenticationStateProvider\ class, which previously managed authentication state by storing and retrieving JWT tokens from local storage, has been removed from the client application. This change eliminates the client-side mechanism for maintaining and propagating token-based authentication state.

src/NcpAdminBlazor.Client/Providers · high confidence

Removed unused MudBlazor theme file

The unused theme file 'MudBlazorAdminDashboard.cs' has been removed from the client application. This cleanup eliminates dead code and reduces the size of the Blazor client bundle, ensuring that only active theme configurations are maintained.

src/NcpAdminBlazor.Client/Theme · high confidence

Rename to CleanAdmin and update app shell with favicon and theme support

The application shell (App.razor) now includes an SVG favicon, a title of 'CleanAdmin', and logic to apply dark/light theme CSS. The project has been renamed to CleanAdmin, with all components and imports updated to reflect the new namespace and path structure.

src/CleanAdmin.Web/Components · high confidence

Test coverage

Added and updated domain tests for User, Order, and global usings; Added integration tests for user, role, and menu management endpoints; Removed obsolete test suite and test infrastructure.

Dependencies

Upgrade to .NET 10 and migrate from NcpAdminBlazor to CleanAdmin

The project has been upgraded to .NET 10.0, with all .csproj files and the central Directory.Packages.props updated to target net10.0. The solution has been renamed from NcpAdminBlazor to CleanAdmin, involving the renaming of all projects, test projects, and directories (e.g., CleanAdmin.Domain, CleanAdmin.Infrastructure). Additionally, the solution now includes a new CleanAdmin.Template.csproj for dotnet new templates, and the NcpAdminBlazor.Client and NcpAdminBlazor.Web projects have been removed in favor of the new CleanAdmin.Web and CleanAdmin.Web.Client structure.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 55 (-6.1)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 84 (-12.2)
  • Architecture 80 → 80 (-0.4)
  • Maturity 68 → 65 (-3.4)
  • Readiness 50 → 50 (+0.0)
  • Security 66 → 65 (-0.6)
  • Domain Modelling 100 → 98 (-1.9)
  • Accessibility 71 → 48 (-23.1)

Resolved (28)

  • Bounded contexts not declared
  • Build status unknown
  • Dependency Hygiene not included (time budget)
  • High CVE: [GHSA redacted] (src/CleanAdmin.Web/package-lock.json)
  • High CVE: [GHSA redacted] (src/CleanAdmin.Web/package-lock.json)
  • High CVE: [GHSA redacted] (src/CleanAdmin.Web/package-lock.json)
  • High vulnerability: [GHSA redacted] (src/CleanAdmin.Web/package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 8 more

New (58)

  • CommentedOutCode (src/CleanAdmin.ServiceDefaults/Extensions.cs)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (src/CleanAdmin.ApiService/Application/Commands/Users/CreateUserCommand.cs)
  • Duplicated block (11–12 lines × 2) (src/CleanAdmin.ApiService/Application/Commands/Users/CreateUserCommand.cs)
  • Duplicated block (11–15 lines × 4) (src/CleanAdmin.ApiService/Application/Commands/Menus/CreateMenuCommand.cs)
  • Duplicated block (12 lines × 6) (src/CleanAdmin.ApiService/Application/Commands/Users/CreateUserCommand.cs)
  • Duplicated block (13 lines × 2) (src/CleanAdmin.Infrastructure/EntityConfigurations/MenuEntityTypeConfiguration.cs)
  • Duplicated block (13 lines × 4) (src/CleanAdmin.ApiService/Application/Commands/Users/UpdateCurrentUserBasicInfoCommand.cs)
  • Duplicated block (16 lines × 3) (src/CleanAdmin.Web.Client/Pages/Application/SystemManage/Menu/Menu.razor)
  • Duplicated block (16–22 lines × 2) (src/CleanAdmin.ApiService/Application/Commands/Menus/UpdateMenuCommand.cs)
  • Duplicated block (17 lines × 2) (src/CleanAdmin.ApiService/Application/Commands/Menus/CreateMenuCommand.cs)
  • Duplicated block (18 lines × 2) (src/CleanAdmin.ApiService/Application/Commands/Users/CreateUserCommand.cs)
  • Duplicated block (22–31 lines × 2) (src/CleanAdmin.ApiService/Application/Commands/Menus/CreateMenuCommand.cs)
  • Duplicated block (26 lines × 2) (src/CleanAdmin.Web.Client/Components/PDrawerForm.razor)
  • Duplicated block (5 lines × 2) (src/CleanAdmin.ApiService/Endpoints/Users/CreateUserEndpoint.cs)
  • Duplicated block (7 lines × 2) (src/CleanAdmin.ApiService/Application/Commands/Menus/UpdateMenuSortOrderCommand.cs)
  • Duplicated block (7 lines × 2) (src/CleanAdmin.ApiService/Application/Commands/Roles/UpdateRolePermissionsCommand.cs)
  • Duplicated block (7 lines × 2) (src/CleanAdmin.ApiService/Application/Queries/Roles/GetRoleListQuery.cs)
  • …and 38 more

API surface

  • Unchanged — 2 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jzwo/CleanAdmin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e03ec687b80b41e9953095dfa540c5bc8f745f61 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.