Skip to content
CAI
Software that uses CAICheck a score

marlonajgayle/dotnet-web-api-template

52.9

Weak · 21 September 2026

3.3k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a .NET 8-based Web API template that implements a clean architecture with distinct layers for domain, application, infrastructure, and API. It provides a complete backend scaffolding featuring user authentication, product and FAQ management, and email notifications, all orchestrated through a MediatR-based application layer. The template includes SQL Server persistence via Entity Framework Core and Dapper, alongside background job processing and centralized exception handling.

Features

Add application-layer infrastructure for health checks, MediatR pipelines, and shared utilities

The application layer now includes a new health check implementation that reports the API's build version, alongside a set of MediatR pipeline behaviors for logging, performance monitoring, validation, and exception handling. The dependency injection setup registers FluentValidation, Hashids, and the MediatR pipeline behaviors. Additionally, the change introduces shared interfaces (e.g., ICacheProvider, IEmailSender, IOutboxService, IUnitOfWork) and models (e.g., PaginatedList, HealthCheckResponse) that support cross-cutting concerns such as caching, email notifications, outbox messaging, and pagination.

src/content/src/NetWebApiTemplate.Application · high confidence

Added Frontier CLI templates for generating domain and application components

The .frontier directory now includes templates for generating entities, commands, queries, configurations, and API endpoints. These templates allow users to scaffold new domain entities, command handlers with validation, query handlers, database configurations, and controller endpoints, each with placeholder names and properties that are replaced during generation.

src/content/.frontier · high confidence

Added application features for email notifications, FAQs, and product management

The application layer now includes new features for sending email notifications, retrieving FAQs, and managing products. For email notifications, a new \EmailMessage\ class and \EmailTemplates\ enum are introduced to define message structure and template types. For FAQs, a repository interface and a query handler are added to retrieve a paginated, searchable list of frequently asked questions. For products, the update includes commands and validators for creating, updating, and deleting products, as well as a query handler to retrieve a paginated list of all products.

src/content/src/NetWebApiTemplate.Application/Features/EmailNotification, src/content/src/NetWebApiTemplate.Application/Features/Faqs, src/content/src/NetWebApiTemplate.Application/Features/Products · high confidence

Adds SQL persistence layer with EF Core and Dapper repositories

The template now includes a full persistence implementation for SQL Server. This introduces Entity Framework Core configuration classes for Faq, OutboxMessage, ProductCategory, Product, RefreshToken, and OutboxMessage entities, alongside a DbInitializer for applying database migrations. Dependency injection is wired up to register the NetWebApiTemplateDbContext and Dapper-based repositories for Faq and Product, enabling database access via both EF Core and raw SQL queries.

src/content/src/NetWebApiTemplate.Persistence · high confidence

Adds authentication commands, queries, and models to the application layer

Introduces a new set of MediatR commands and queries for the authentication feature, including login, register, refresh token, and role/claim management. The register user command now integrates with an outbox service to persist domain events, and a corresponding event handler is added to send welcome emails. The change also includes supporting models (AppUser, AuthenticationResult, Result, TokenResult) and service interfaces (IAuthenticationService, IJwtTokenService) required for these operations.

src/content/src/NetWebApiTemplate.Application/Features/Authentication · high confidence

Adds authentication, email, caching, and background job infrastructure

The infrastructure layer now includes a complete authentication stack using ASP.NET Identity and JWT, featuring an AuthenticationService for user/role management, a JwtTokenService for generating access and refresh tokens, and an ApplicationUser entity. It also introduces an email sending capability via FluentEmail with Razor templates, an in-memory cache provider, an encryption manager, and a Quartz-based background job (ProcessOutboxMessagesJob) that processes outbox messages from the database.

src/content/src/NetWebApiTemplate.Infrastructure · high confidence

Behavioural changes

API exception handling and Swagger security schema updates

The API now uses a new ApiExceptionFilterAttribute to centrally handle common exceptions (BadRequest, Forbidden, NotFound, Unauthorized, Validation) by returning standardized ProblemDetails responses and capturing each exception in Sentry with appropriate severity levels. Additionally, the Swagger/OpenAPI generation now automatically adds 401 and 403 response descriptions and applies a Bearer token security scheme to endpoints marked with \[Authorize\].

src/content/src/NetWebApiTemplate.Api/Filters · medium confidence

Add authentication, FAQ, and product management endpoints

The API now exposes new endpoints for user authentication (login, register, refresh token, role management), FAQ retrieval, and full CRUD operations for products (create, update, delete, and list). These controllers rely on the MediatR library to dispatch commands and queries to the application layer, introducing a behavioral change in how these specific API routes are handled.

src/content/src/NetWebApiTemplate.Api/Endpoints · medium confidence

Added .nuspec file to fix missing nuspec error

A .nuspec file was added to the src directory, resolving an error caused by a missing nuspec file. The file defines the package metadata, including the ID 'Net.WebApi.Template', and specifies the readme file path as 'content\\README.md'.

src · medium confidence

Added domain entities and base classes for the application

The domain layer now includes new entity classes for managing FAQs, products with their categories, refresh tokens for authentication, and an outbox message structure for event sourcing. Additionally, a base AuditableEntity class for tracking creation and modification metadata and an IDomainEvent interface for MediatR notifications have been introduced.

src/content/src/NetWebApiTemplate.Domain · medium confidence

Adds service and Swagger configuration classes

The API project introduces new infrastructure to support runtime user context and health check reporting. A new CurrentUserService class provides access to the authenticated user's ID, email, and IP address. Additionally, a HealthCheckResponseWriter class is added to serialize health check reports into JSON. The Swagger configuration is also updated with new options classes (SwaggerDocOptions and SwaggerOptions) to manage API documentation metadata and routing.

src/content/src/NetWebApiTemplate.Api/Services, src/content/src/NetWebApiTemplate.Api/Swagger · medium confidence

Updated .NET 8 Dockerfile and restructured API configuration files

The Dockerfile for the API project has been updated to use the .NET 8 SDK and runtime images, with globalization invariant mode explicitly disabled. Configuration files (appsettings.json and environment-specific variants) have been restructured to support the new Docker setup, including updated SQL Server connection strings for development and test environments, adjusted Serilog logging levels, and conditional Sentry integration. The API startup (Program.cs) has been updated to reflect these changes, ensuring proper service registration and configuration loading.

src/content/src/NetWebApiTemplate.Api · medium confidence

Updated .NET SDK requirement to version 8.0.401

The project now requires .NET SDK 8.0.401 or later, as specified in the new global.json file. This ensures developers use a compatible SDK version for building and running the template, aligning with the broader update to .NET 8 in the documentation and Docker instructions.

(repo-wide) · high confidence

Updated .NET SDK version to 8.0.401

The template now targets .NET 8, with the global.json file updated to require SDK version 8.0.401. This ensures the project uses the latest .NET 8 features and improvements.

src/content · high confidence

Dependencies

Upgrade to .NET 8 and update key dependencies

The template now targets .NET 8.0, bringing compatibility with the latest .NET runtime features and security updates. Additionally, MediatR has been upgraded to version 12.4.1, and the Quartz scheduling library has been added to the infrastructure layer, enabling background job processing capabilities within the template.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 55 → 53 (-1.7)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 89 → 77 (-12.2)
  • Architecture 73 → 73 (+0.0)
  • Maturity 52 → 54 (+2.1)
  • Readiness 49 → 45 (-4.3)
  • Security 55 → 55 (+0.3)
  • Event-Driven 100 → 100 (+0.0)
  • Performance 67 → 67 (+0.0)

Resolved (12)

  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent spelling of 'Category' as 'Catergory' in the entity class name and property, while the DbContext property and configuration class use the correct spelling 'Category'.
  • The Getting Started instructions install .NET Core 7.0 instead of the latest SDK version (which is 8.0 in the README). (docs/Getting-Started.md)
  • dormant codebase — no living knowledge left to concentrate
  • redundant comment (src/content/src/NetWebApiTemplate.Api/Program.cs)
  • redundant comment (src/content/src/NetWebApiTemplate.Infrastructure/Auth/AuthenticationService.cs)

New (23)

  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: WD-COMPOSE-0002 (src/content/docker-compose.yml)
  • Medium IaC: WD-DOCKER-0003 (src/content/src/NetWebApiTemplate.Api/Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (src/content/src/NetWebApiTemplate.Api/Dockerfile)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 3 more

API surface

  • Unchanged — 4 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

marlonajgayle/dotnet-web-api-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d2fc4d3c80f9f74d5a9322e057c7a22f95ca0daa — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.