Skip to content
CAI
Software that uses CAICheck a score

labasubagia/realworld-backend

59.7

Adequate · 21 September 2026

4.9k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based backend application that exposes both RESTful and gRPC interfaces for managing users, articles, and comments. It supports pluggable database backends (PostgreSQL or MongoDB) and authentication via JWT tokens. The architecture separates core domain logic and services from adapters, allowing flexible configuration of logging, server types, and data persistence.

Features

Add gRPC API for user and article management

A new gRPC adapter is introduced in \internal/adapter/handler/grpc\, providing a complete set of RPC handlers for user and article operations. This includes user authentication (register, login, update, get profile, follow/unfollow) and article management (list, feed, get, create, update, delete, favorite/unfavorite, comments, and tags). The implementation includes the server setup, request serialization, error handling, and authorization middleware, exposing these capabilities via the \pb.RealWorld\ service interface.

internal/adapter/handler/grpc · high confidence

Added MongoDB repository implementation for articles and users

The application now supports a MongoDB-based persistence layer for articles, users, and their associated data (comments, favorites, tags, and follows). This change introduces new repository implementations in the \internal/adapter/repository/mongo\ package, including database connection management, schema migrations (unique indexes), and CRUD operations for domain entities. Users will see their data stored and retrieved via MongoDB rather than any previous or alternative storage mechanism.

internal/adapter/repository/mongo · high confidence

Added core utility functions for configuration, password hashing, and validation

New utility functions have been introduced to support application configuration loading, secure password hashing and verification, and input validation. The config loader now reads environment variables and .env files to populate settings like database sources, server ports, and environment modes. Passwords are hashed using bcrypt, and a test confirms correct hashing and verification behavior. Additionally, validators are provided for strings, usernames, passwords, emails, IDs, and URLs, ensuring data integrity before processing.

internal/core/util · high confidence

Centralized repository factory for database backends

The repository adapter now uses a centralized factory pattern to instantiate database repositories. This allows the application to dynamically select between Postgres and MongoDB backends based on configuration, with Postgres set as the default. Users can now switch database providers by changing the DBType configuration, and the system will automatically initialize the correct repository implementation.

internal/adapter/repository · high confidence

Defined core domain ports for articles, users, and services

The codebase now exposes a set of interfaces in the internal/core/port package that define the contracts for the application's core logic. This includes the ArticleService and UserService interfaces, which specify operations for creating, updating, and deleting articles, managing favorites and comments, and handling user registration, login, profile retrieval, and following/unfollowing. Additionally, the ArticleRepository and UserRepository interfaces define the data access contracts for articles and users, while the Repository interface provides a transactional wrapper. The Logger interface and its associated context key facilitate structured logging with sub-loggers, and a basic Server interface is introduced to manage the application's entry point.

internal/core/port · high confidence

Initial RESTful API implementation for user, article, and comment management

The \internal/adapter/handler/restful\ package now provides the complete HTTP/REST interface for the application. This includes handlers for user registration, login, profile management, and following/unfollowing users. It also implements endpoints for creating, reading, updating, and deleting articles, as well as listing and managing comments. The implementation includes a centralized error handling strategy (\errorHandler\) that maps internal exceptions to appropriate HTTP status codes, and a logging middleware that captures request details such as client IP, user agent, and duration.

internal/adapter/handler/restful · high confidence

Initial project structure and configuration for Go backend

The repository is initialized with a complete Go application structure, including a main entry point, Dockerfile, and docker-compose configuration supporting multiple service profiles (RESTful, gRPC, MongoDB, Postgres). Environment variables are standardized via .env.example and .env.docker files, and the Makefile provides commands for database migrations, testing, and gRPC code generation. The project also includes a Code of Conduct, MIT License, and updated .gitignore rules.

(repo-wide) · high confidence

Introduce JWT-based authentication token generation and verification

Added a new JWT maker implementation that creates and verifies JSON Web Tokens for user authentication. The new token package includes a Maker interface and a Payload struct containing the user ID, issue time, and expiration time. The implementation validates token signatures, checks expiration status, and returns specific error types for invalid or expired tokens.

internal/core/util/token · high confidence

Introduce core services for user and article management

Added new service implementations for user and article domains, including user registration, login, profile retrieval, and follow/unfollow capabilities, as well as article creation, updating, deletion, and favorite management. These services coordinate with the repository layer to handle business logic, token generation, and data validation, supported by comprehensive unit tests covering success and failure scenarios.

internal/core/service · high confidence

Introduce pluggable logging adapters (Zap and ZeroLog)

The application now supports configurable logging backends. A new factory in internal/adapter/logger allows selecting between Zap and ZeroLog implementations via the LogType configuration. This enables users to switch logging libraries without changing application code, with ZeroLog as the default.

internal/adapter/logger · high confidence

Introduce root command and server subcommand for the CLI

The application now exposes a Cobra-based CLI entry point. The root command initializes configuration from a .env file, and the new 'server' subcommand allows users to start the application with configurable options for server type, port, database backend, and logging mechanism. This change establishes the command-line interface structure for the backend application.

cmd · high confidence

Introduce structured exception handling for API errors

Added a new \exception\ package that defines a structured \Exception\ type for managing API errors. This includes predefined error types (e.g., \ErrValidation\, \ErrNotFound\) and helper functions like \New\ and \Into\ to wrap and propagate errors with context. This enables more granular error handling and validation in the core utility layer.

internal/core/util/exception · high confidence

Introduces domain models for articles, comments, and users with ULID-based identifiers

The application now defines core domain entities—Article, Comment, and User—along with their associated types (Tag, ArticleFavorite, UserFollow). Each entity uses a custom ID type backed by ULIDs, ensuring globally unique identifiers. The User model includes validation for email, username, and image URL, while Article and Comment models support creation and random generation. This establishes the internal representation for managing content and user interactions.

internal/core/domain · high confidence

SQL repository layer for articles, users, and tags

The SQL adapter now implements the repository interfaces for articles, users, and tags using the Bun ORM. This includes data models for articles, tags, comments, favorites, and user follows, along with the SQL error mapping for PostgreSQL. The repository entry point wires together the user and article repositories, providing a unified access point for the database.

internal/adapter/repository/sql · high confidence

Behavioural changes

Centralized server factory for RESTful and gRPC adapters

The handler package now provides a unified entry point for creating server instances, supporting both RESTful and gRPC implementations. Users can configure the server type via the application configuration, and the system will instantiate the appropriate server (RESTful or gRPC) based on the provided configuration, defaulting to RESTful if no type is specified.

internal/adapter/handler · medium confidence

Initial database schema for users, articles, and social features

The application's SQL database is initialized with two migration scripts that establish the core data model. The first migration creates the 'users' table (including a 'user\_follows' table for social connections) and the second migration adds 'articles', 'comments', 'tags', 'article\_tags', and 'article\_favorites' tables. These changes provide the necessary backend storage for user profiles, content creation, and interaction features.

internal/adapter/repository/sql/db/migration · high confidence

SQL query logging and migration initialization

The SQL database adapter now initializes database connections and runs migrations upon startup. A new logging hook has been added to the Bun ORM, which captures SQL query details (duration, query text, operation type) and logs them via the application logger, with verbose mode enabled in non-production environments.

internal/adapter/repository/sql/db · high confidence

Test coverage

Added Postman collection and test runner for the Conduit API

Added a new Postman collection (Conduit.postman\_collection.json) and a shell script (run-api-tests.sh) to run API tests locally. The test runner executes the collection against a specified API URL (defaulting to https://api.realworld.io/api) and includes the --insecure flag for the Newman test runner.

tests · high confidence

Dependencies

Initialize Go module and dependencies

The project is initialized as a Go module (github.com/labasubagia/realworld-backend) with Go 1.21.0. The diff introduces a comprehensive set of dependencies including the Gin web framework, gRPC, MongoDB and PostgreSQL drivers, logging libraries (Zap, Zerolog), and various utility packages.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 60 → 60 (+0.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 92 → 95 (+3.0)
  • Architecture 100 → 64 (-36.4)
  • Maturity 63 → 63 (+0.0)
  • Readiness 46 → 51 (+4.8)
  • Security 75 → 74 (-1.3)
  • Domain Modelling 73 → 75 (+2.4)

Resolved (40)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (internal/adapter/handler/grpc/api/article.go)
  • Duplicated block (10 lines × 2) (internal/adapter/repository/mongo/article.go)
  • Duplicated block (10 lines × 3) (internal/core/service/article.go)
  • Duplicated block (11 lines × 2) (internal/adapter/handler/grpc/api/article.go)
  • Duplicated block (11 lines × 2) (internal/adapter/handler/grpc/api/authorization.go)
  • Duplicated block (12 lines × 2) (internal/core/service/article.go)
  • Duplicated block (13 lines × 2) (internal/adapter/handler/restful/article.go)
  • Duplicated block (13 lines × 2) (internal/core/service/article.go)
  • Duplicated block (14 lines × 2) (internal/adapter/handler/restful/article.go)
  • Duplicated block (6 lines × 2) (internal/adapter/repository/mongo/article.go)
  • Duplicated block (6 lines × 2) (internal/core/service/article.go)
  • Duplicated block (6 lines × 2) (internal/core/service/article.go)
  • Duplicated block (7 lines × 2) (internal/core/service/user.go)
  • Duplicated block (8 lines × 2) (internal/adapter/repository/mongo/article.go)
  • …and 20 more

New (80)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Deprecated module: go.mongodb.org/mongo-driver
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (internal/core/service/user.go)
  • Duplicated block (11 lines × 2) (internal/core/service/user.go)
  • Duplicated block (11–12 lines × 2) (internal/adapter/repository/mongo/user.go)
  • Duplicated block (12 lines × 2) (internal/adapter/handler/restful/article.go)
  • Duplicated block (12 lines × 2) (internal/adapter/repository/mongo/article.go)
  • Duplicated block (12 lines × 2) (internal/adapter/repository/mongo/article.go)
  • Duplicated block (12 lines × 2) (internal/adapter/repository/mongo/model/user.go)
  • Duplicated block (12 lines × 2) (internal/adapter/repository/mongo/model/user.go)
  • Duplicated block (12 lines × 2) (internal/core/service/article.go)
  • Duplicated block (13 lines × 2) (internal/core/service/article.go)
  • Duplicated block (14 lines × 2) (internal/adapter/handler/grpc/api/article.go)
  • Duplicated block (14–15 lines × 2) (internal/adapter/handler/grpc/api/article.go)
  • Duplicated block (15 lines × 2) (internal/adapter/handler/restful/article.go)
  • …and 60 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

labasubagia/realworld-backend was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2c8b9bcddc4ab3a9e458f2914b89a0a6c33e909e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.