Skip to content
CAI
Software that uses CAICheck a score

leal32b/webapi-nodejs

52.0

Adequate · 21 September 2026

4.7k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Node.js API built on a clean architecture, providing user identity management and asynchronous email communication services. It exposes HTTP endpoints for authentication, group creation, and user sign-up, while handling email confirmation flows via a message broker. The codebase is structured with distinct domain, application, and presentation layers, supported by comprehensive unit tests and strict linting configurations.

Features

Add user identity management and group creation capabilities

The identity module now supports user sign-up, sign-in, email confirmation, and password changes, alongside the ability to create and manage user groups. This includes domain models for users and groups, application-level use cases for authentication and group management, and presentation-layer controllers and routes to expose these features via HTTP endpoints.

src/modules/identity · high confidence

Added email confirmation functionality for new users

The communication module now includes a complete flow for sending email confirmation messages. This includes domain entities and value objects for email composition, an application use case that compiles a Handlebars template with i18n support for English and Brazilian Portuguese, and a Nodemailer-based infrastructure adapter. The system automatically triggers a confirmation email when a user is created, utilizing a message broker queue and handler to ensure asynchronous delivery.

src/modules/communication · high confidence

Initial project scaffolding and configuration

The repository was initialized with a complete development environment setup, including TypeScript and Node.js configuration files (tsconfig.json, tsconfig.build.json), ESLint rules (.eslintrc.json), and a Vitest test runner configuration (vitest.config.ts). The project also includes a Docker Compose file (docker-compose.yml) to orchestrate local infrastructure services for MongoDB, PostgreSQL, and RabbitMQ, alongside environment variable templates (.env.development) and a .gitignore file.

(repo-wide) · high confidence

Introduces a clean architecture foundation with domain, application, presentation, and infrastructure layers

Adds a complete set of base classes, interfaces, and utilities that establish a clean architecture structure. The domain layer introduces abstract base classes for aggregates, entities, value objects, and handlers, alongside a comprehensive set of domain error types and validators. The application layer defines interfaces for use cases, event handling, cryptography, and middleware. The presentation layer provides base controllers, middleware for authentication and schema validation, and error factories. Finally, the infrastructure layer implements these interfaces with concrete adapters for templating, cryptography, documentation, and event messaging.

src/common · high confidence

Behavioural changes

Husky upgraded to v8 with new commit-msg hook

The project has upgraded Husky to version 8, evidenced by the new .husky/pre-commit script that invokes npx lint-staged. Additionally, a new .husky/commit-msg hook was added to execute .git/hooks/commit-msg, and the .husky/pre-push hook was updated to run npm run test:ci and npm run jscpd.

.husky · medium confidence

Test coverage

Added unit tests for domain, application, and presentation layers

Added unit tests for domain base classes (Entity, ValueObject), error classes (EmptyError, InvalidDateError, InvalidEmailError, InvalidLocaleError, MaxLengthError, MinLengthError, NotHtmlError, NullError), utility classes (Either, Identifier, Random, Var), validators (Date, Email, Html, Locale, MaxLength, MinLength, NotEmpty, NotNull), application events, application errors (EmailTakenError, InvalidPasswordError, NameTakenError, NotFoundError, PasswordMismatchError), presentation errors (InvalidTokenError, MissingAuthError, MissingTokenError, ServerError), and presentation factories (clientError, serverError, success) and middleware (AuthMiddleware).

test, test/modules/communication, test/modules/identity · high confidence

Dependencies

Initial dependency and build configuration for the Node.js API

The project now includes a complete set of dependencies and tooling to support the application's architecture. Production dependencies include Express, MongoDB, Postgres, TypeORM, and various utility libraries. Development and testing tooling has been added, including Vitest, ESLint, Husky, and TypeScript, establishing the foundation for building and testing the API.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 63 → 52 (-10.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 93 (-1.6)
  • Architecture 87 → 80 (-6.8)
  • Maturity 59 → 59 (+0.0)
  • Readiness 57 → 36 (-20.9)
  • Security 60 → 64 (+3.9)

Resolved (57)

  • Change coupling clique: change-password.use-case.ts, sign-in.use-case.ts, sign-up.use-case.ts (src/modules/identity/1.application/use-cases/change-password.use-case.ts)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 37 more

New (96)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Documentation: written for insiders (docs/conventions/test-doubles.md)
  • End-of-life runtime: Node.js 18
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 76 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

leal32b/webapi-nodejs was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9784f344383f12f7a44405f79d829d0d7e216f1a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.