lezhnev74/ema
51.2
Adequate · 20 September 2026
2.6k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a PHP-based note-taking application built on a Domain-Driven Design architecture, utilizing the Prooph Service Bus for command, event, and query handling. It provides a RESTful HTTP API secured by JWT authentication and Google OAuth, allowing users to create, search, and manage their own notes. The backend employs event sourcing principles with Doctrine DBAL for persistent storage, supporting both SQL databases and in-memory implementations for testing.
Features
Added Doctrine DBAL connection and migration configuration factory
The application now includes a factory class for creating Doctrine DBAL connections and configuring database migrations. This change introduces the ability to establish database connections using configuration parameters and sets up the migration system with a specific table name, directory, and namespace, enabling structured database schema management.
src/Infrastructure/Factory · high confidence
Added Doctrine and In-Memory implementations for account persistence and retrieval
The application now supports two concrete strategies for managing account data: a Doctrine DBAL-based implementation for SQL databases and an in-memory implementation for testing or lightweight scenarios. The Doctrine classes (\DoctrineAccountCollection\ and \DoctrineAccountFinder\) handle saving accounts (inserting or updating social provider details) and querying accounts by social ID or retrieving all records directly from the database. The In-Memory classes (\InMemoryAccountFinder\) provide the same interface but operate on an in-memory collection, mapping account objects to arrays for lookup. This change enables the system to switch between persistent storage and ephemeral storage for account operations.
src/Infrastructure/Account · high confidence
Added Doctrine and In-Memory implementations for note retrieval
The application now includes concrete implementations for the NoteFinder interface, enabling users to retrieve notes via a database-backed Doctrine adapter or an in-memory collection. These implementations support listing all notes, searching by text content, and fetching the most recently modified notes, providing the underlying data access layer for note queries.
src/Infrastructure/Note/Finder · high confidence
Added bin symlinks for DDD generator, Doctrine, Interop Config, and PHPUnit
The project now exposes command-line tools directly in the bin directory via symlinks to their respective vendor packages. Users can now run the DDD generator (dddtool), Doctrine DBAL and Migrations utilities, Interop Config, and PHPUnit directly from the bin folder, simplifying access to these development and database management tools without needing to reference the full vendor paths.
bin · high confidence
Added public entry point for the Slim application
A new public/index.php file has been added to serve as the entry point for the application. It bootstraps the environment via autoload.php, retrieves the Slim App instance from the container, and runs the application.
public · high confidence
Added query handlers for listing, searching, and retrieving recent notes
This change introduces the application-layer query infrastructure for the Note module, enabling users to retrieve their notes in three distinct ways. It adds command objects, authorizers, and handlers for fetching all notes owned by a user, searching notes by query text, and retrieving a specific count of recent notes. The implementation enforces ownership checks for the 'all' and 'search' operations, ensuring users can only access their own data, while the 'recent' query is publicly accessible. These components rely on a new \NoteFinder\ interface to abstract the underlying data retrieval logic.
src/App/Note · high confidence
Initial HTTP API scaffolding with authentication and logging
This change introduces the core application factory and infrastructure for the HTTP API. It establishes a Slim application with CORS headers, a trailing-slash fix, and a structured error handler that returns specific JSON error codes (ACCESS\_DENIED, BAD\_TOKEN, INVALID\_DATA, SERVER\_ERROR) and logs exceptions. It adds a LogFactory to configure Monolog for file-based logging and a LogCommands plugin to record command bus activity. The HTTP layer includes an authentication middleware using JWT, a Google OAuth integration that exchanges auth codes for app access tokens, and route definitions for account management and note operations (recent, search, all, create, modify, delete).
src/App/Factory · high confidence
Initial application bootstrap and service bus integration
This change introduces the core bootstrap files (\autoload.php\ and \helpers.php\) that initialize the application environment. It sets up the dependency injection container using PHP-DI, configures environment variable loading via Dotenv, and registers the Prooph Service Bus components (CommandBus, EventBus, QueryBus) as accessible global helpers. Additionally, it includes utility functions for configuration access, logging, and retrieving the current authenticated user identity, laying the foundation for the application's command and event handling architecture.
bootstrap · high confidence
Initial application configuration and dependency injection setup
This change introduces the foundational configuration files for the application, establishing the environment settings, database connections (specifically SQLite for production and testing), and the core dependency injection container wiring. It configures the Prooph Service Bus with command, event, and query buses, integrates Doctrine DBAL for database abstraction and migrations, sets up Monolog for logging, and defines social provider credentials, effectively bootstrapping the application's infrastructure layer.
config · high confidence
Initial implementation of social account linking via Google
This change introduces the core domain logic for linking user accounts to social providers, specifically Google. It adds the necessary Command and Query structures (AddAccount, FindAccount) along with their handlers and authorizers to manage the lifecycle of an account link. The Account model enforces that only 'google' is a supported provider and stores the provider name and ID. An in-memory collection implementation is provided to store and retrieve these accounts by social key, laying the groundwork for the authentication flow.
src/App/Account · high confidence
Initial release of domain foundation and command handling components
This change introduces the core domain foundation classes, including the \AggregateRoot\ abstract class for managing domain events and identities, and the \Command\ interface to standardize command structures. It also adds the \Authorizer\ abstract class for handling command authorization logic and an \AuthenticatedUserNotFound\ exception to handle specific authentication errors. These components establish the foundational architecture for command-driven interactions within the application.
src/Domain/Foundation/Command · high confidence
Initial release of the DDD code generator with stub templates and configuration
This change introduces the initial version of the \ddd-gen\ tool, providing a configuration file (\ddd-gen-config.php\) and a set of PHP stub templates for generating Domain-Driven Design components. The generator is configured to produce code across three layers (App, Domain, Infrastructure) and includes specific stubs for Commands, including the command class, handler, and authorizer, along with corresponding test stubs. Users can now utilize these templates to scaffold basic command structures within their project.
ddd-gen · high confidence
Initial release of the Note domain model
This change introduces the core domain entities for the Note feature, including the Note aggregate root, the NoteText value object, and the NoteCollection interface with an in-memory implementation. Users can now create, modify, and delete notes, with the system automatically tracking when a note was posted and when it was last modified.
src/Domain/Note/Model · high confidence
Initial support for creating new notes
Users can now create new notes through the application. This change introduces the command handler for the 'PostNewNote' operation, which validates that the note text is not empty and persists the new note to the collection. Additionally, the handler is configured to dispatch domain events associated with the newly created note.
src/Domain/Note/Commands/PostNewNote · high confidence
Introduce structured domain exception hierarchy with problem codes
Added a new exception hierarchy in the domain foundation layer to standardize error handling. The \DomainProblem\ base class and \ModelNotFound\ specific exception now utilize the \KnownProblem\ trait, which equips exceptions with a structured \problem\_code\ and \payload\ for better logging and debugging. This allows the application to attach specific identifiers and additional context to domain errors, moving away from plain exception messages.
src/Domain/Foundation/Exception · high confidence
Introduction of Doctrine DBAL Migrations for database schema management
The application now uses Doctrine DBAL Migrations to manage database schema changes, replacing manual SQL execution with version-controlled migration scripts. This change introduces initial migration files that create the \notes\ table (containing id, owner\_id, note\_text, posted\_at, and modified\_at fields) and the \accounts\ table (containing id, social\_provider\_id, and social\_provider\_name fields). A new console configuration file (\migrations/doctrine.php\) has been added to register Doctrine migration commands (such as \migrate\, \diff\, and \execute\) within the Symfony console application, enabling developers to apply, rollback, and generate database schema updates programmatically.
migrations · high confidence
Introduction of Value Object for UUID-based Identity
A new Identity value object has been added to the domain foundation, providing a dedicated wrapper for UUIDs. This component automatically generates a version 4 UUID when instantiated without an argument and ensures type safety by validating and storing the identifier as a Ramsey Uuid object. It exposes methods to retrieve the identifier as a string and to compare identities for equality, establishing a consistent pattern for unique entity identification within the domain layer.
src/Domain/Foundation/VO · high confidence
Introduction of versioned domain event infrastructure
The domain layer now includes a base event structure that tracks the version of each event alongside its aggregate ID, payload, and timestamp. This foundation supports event sourcing by ensuring every event carries a version number, starting at 1, which allows consumers to handle event evolution and compatibility. Specific note-related events (NoteDeleted, NoteModified, NotePosted) have been added to represent key lifecycle changes.
src/Domain/Foundation/Event, src/Domain/Note/Events · high confidence
JWT-based HTTP authentication middleware
The application now supports HTTP authentication using JSON Web Tokens (JWT). A new middleware inspects the Authorization header for Bearer tokens, validates them using the Lcobucci JWT library (checking signature, issuer, audience, and expiration), and sets the authenticated user identity in the container if valid. Invalid or missing tokens result in a 403 Forbidden response. This change introduces the core authentication logic for securing HTTP endpoints.
src/App/Http · high confidence
New authorization service with implicit authorizer support
A new AuthorizationService has been introduced in the src/App/Authorization directory to manage command authorization. It implements the Prooph authorization interface and defaults to denying access unless an explicit check passes. The service supports an 'implicit authorizer' strategy: for fully qualified command class names, it automatically looks for a corresponding Authorizer class (by appending 'Authorizer' to the message name) within the dependency container. If such an authorizer exists and does not deny the request for the current authenticated user identity, access is granted; otherwise, access is denied.
src/App/Authorization · high confidence
Behavioural changes
Note deletion and modification commands with ownership authorization
This change introduces the command handlers and authorizers for deleting and modifying notes. The DeleteNote and ModifyNote commands now enforce that only the note's owner can perform these actions, preventing unauthorized users from altering or removing notes they do not own. Additionally, both operations now dispatch domain events upon completion, ensuring that other parts of the system are notified of these state changes.
src/Domain/Note/Commands/DeleteNote · high confidence
Persistent note storage via Doctrine DBAL
The application now supports saving, retrieving, updating, and deleting notes in a relational database using Doctrine DBAL. This implementation ensures that the modified date is updated whenever a note is changed, providing accurate tracking of the last modification time for each note.
src/Infrastructure/Note/Collection · high confidence
Test coverage
Added BaseTest class with HTTP and migration helpers; Added infrastructure tests for note command handlers; Added integration tests for Doctrine-based note queries; Added test utilities for service authorization and message bus event logging; Added tests for JWT token handling and authentication middleware; Added tests for Note query handlers and authorizers; Added tests for account management, note CRUD, and service bus authorization; Added tests for note command handlers and authorizers; Added unit tests for Note model and NoteText value object.
Dependencies
Initial project dependency setup
The application introduces its core dependency graph via composer.json and composer.lock, establishing the runtime environment on PHP 7.1+. Key libraries include the Slim framework for HTTP handling, Prooph Service Bus for event-driven architecture, Doctrine DBAL and Migrations for database management, and lcobucci/jwt for authentication. Development tooling is also configured with PHPUnit, Faker, and Symfony Var Dumper.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 55 → 51 (-3.5)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 96 (-4.0)
- Architecture 100 → 88 (-12.2)
- Maturity 39 → 39 (+0.0)
- Readiness 41 → 35 (-5.9)
- Security 100 → 91 (-8.7)
- Domain Modelling 87 → 89 (+2.2)
Resolved (5)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- No exposed public API
- Test reliability not included
- single-maintainer — knowledge-concentration (bus factor) risk
New (21)
- Abandoned package: doctrine/cache
- Critical CVE: [GHSA redacted] (composer.lock)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (18 lines × 2) (src/Domain/Note/Commands/DeleteNote/DeleteNoteAuthorizer.php)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- Low CVE: [GHSA redacted] (composer.lock)
- Medium CVE: [GHSA redacted] (composer.lock)
- Medium CVE: [GHSA redacted] (composer.lock)
- Medium CVE: [GHSA redacted] (composer.lock)
- No ADRs found
- No dependency advisory monitoring
- Outdated: google/apiclient
- Outdated: prooph/service-bus
- Outdated: sandrokeil/interop-config
- TodoComment (src/App/Authorization/AuthorizationService.php)
- TodoComment (src/Domain/Foundation/Exception/KnownProblem.php)
- …and 1 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
lezhnev74/ema was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 1ab022600a3b675da0a428871bb001f090eb23a6 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.