Skip to content
CAI
Software that uses CAICheck a score

mbc-net/mbc-cqrs-serverless

51.8

Adequate · 21 September 2026

29.9k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive serverless framework for building multi-tenant CQRS applications on AWS, providing a complete development ecosystem from infrastructure-as-code templates to runtime core libraries. It offers a CLI for scaffolding NestJS applications, generating boilerplate code, and managing local development environments with mocked AWS services. The framework includes built-in modules for tenant management, data synchronization, and notification transport, alongside an MCP server to integrate AI coding assistants directly into the development workflow.

How it got here

2023 — core framework and CLI expansion

32 changes.

This period focused on expanding the MBC CQRS Serverless framework with comprehensive core modules, including authentication, authorization, and multi-transport notification systems. The CLI was significantly enhanced with new templates for local development, Prisma integration, and application scaffolding. Additionally, new features such as sequence generation and task management were introduced alongside extensive test coverage.

2024 — Multi-tenant and local testing infrastructure

22 changes.

This period focused on establishing a robust local development and testing environment, introducing scripts and mock services for AWS resources like DynamoDB, S3, and AppSync. Simultaneously, the codebase expanded to support multi-tenant capabilities through a new tenant management module and enhanced the UI settings functionality with new DTOs, entities, and helper utilities.

2025–2026 — multi-tenant and AI tooling expansion

22 changes.

This period focused on expanding the framework's core capabilities by introducing comprehensive multi-tenant management features, including new controllers, services, and DTOs for tenant and directory operations. Simultaneously, the project integrated an MCP server to enable AI assistant interactions and added robust integration tests to validate AWS SDK behaviors and tenant isolation.

Features

Add AppSync Events client example with bilingual UI and unified subscription interface

A new example application in the \examples/appsync-event-client\ directory provides a Next.js-based client for testing real-time notifications via the AWS AppSync Events API. The app features a bilingual (English and Japanese) interactive dashboard that allows users to connect, disconnect, and modify subscription dimensions such as tenant code, action, and ID. It implements a unified \subscribe()\ function that abstracts the transport layer, allowing the underlying client to be swapped seamlessly. The example includes all necessary configuration files (\.gitignore\, \next.config.ts\, \tsconfig.json\, etc.) and a \subscribe-events.ts\ library that handles channel resolution and message decoding.

examples/appsync-event-client · high confidence

Add CDK-based infrastructure template with GraphQL schema and diagram generation

A new infrastructure template is now available in the CLI, providing a complete AWS CDK project structure for managing cloud resources. This includes a GraphQL schema defining message types and operations, a CDK entry point that provisions a pipeline stack, and configuration for generating infrastructure diagrams. The template also includes standard development tooling such as TypeScript configuration, Jest testing setup, and code formatting rules, enabling users to generate and visualize their infrastructure as code.

packages/cli/templates/infra · medium confidence

Add CLI commands for generating, starting, and managing skills and UI components

The CLI package introduces several new commands to support project scaffolding and component management. The \new\ command generates a new CQRS application, supporting both latest and specific package versions. The \generate\ command creates MBC-CQRS-Serverless elements via schematics. The \install-skills\ command installs and manages Claude Code skills, including version tracking and caching. The \ui\ command installs common UI components from a remote repository, handling authentication and path configuration. Additionally, the \start\ command is added to initiate the application with the serverless framework. Each command is backed by corresponding action files and comprehensive unit tests.

packages/cli/src · high confidence

Add CLI schematics for generating controllers, DTOs, entities, and modules

The CLI now includes new schematics that generate boilerplate code for controllers, DTOs, entities, and modules. Users can generate these components via the CLI, which will create the necessary files and templates for each type, including unit tests for the generated code.

packages/cli/schematics · high confidence

Add CLI template scaffolding for serverless applications

The CLI now provides a new template for generating serverless applications, including an event factory, a main module configuration, and a handler entry point. It also adds a script to generate Swagger documentation and an interactive REPL for development, with configurable Prisma logging levels that default to 'error' in non-local environments.

packages/cli/templates/src · medium confidence

Add CQRS implementation and migration guide prompts

The MCP server now exposes a set of AI-assisted prompts for implementing CQRS patterns using the MBC CQRS Serverless framework. Users can request guidance on implementing modules, entities, and commands, debug command-related errors, and receive migration instructions between framework versions. The new files, cqrs-guide.ts and index.ts, define the prompt schemas and message generation logic for these features.

packages/mcp-server/src/prompts · high confidence

Add Prisma integration templates and Cognito local patch

The CLI templates now include a complete Prisma integration for NestJS applications, providing a configurable \PrismaModule\ with support for global registration, async factory options, explicit connection pooling, and query logging middleware. Additionally, a patch for \cognito-local\ version 3.23.2 is added to the local infrastructure templates, introducing a \UserDisableException\ to properly handle disabled user scenarios during authentication.

packages/cli/templates/infra-local/cognito-local/patches, packages/cli/templates/src/prisma · medium confidence

Add Prisma template with DynamoDB provisioning script

Introduced a new Prisma template located in the CLI templates directory, including a \schema.prisma\ file defining a \Sample\ model for MySQL, and a new \ddbs.ts\ script that provisions DynamoDB tables, enables Time-to-Live (TTL) and Point-in-Time Recovery (PITR) for non-local environments, and manages table creation with environment-specific configurations.

packages/cli/templates/prisma · high confidence

Add infrastructure configuration templates for dev, staging, and production environments

The CLI now includes a new \infra/config\ template that provides environment-specific configuration files for dev, staging, and production deployments. These templates define the structure for infrastructure settings, including domain endpoints, VPC and RDS connection details, logging levels, and new support for AppSync Events API integration and flexible notification transport selection.

packages/cli/templates/infra/config · high confidence

Add local AppSync simulator template for CLI

The CLI now includes a new template for a local AppSync simulator, enabling local development and testing of GraphQL APIs. This addition provides a Dockerized Node.js environment that runs the \@aws-amplify/amplify-appsync-simulator\ library, configured with a sample schema, resolvers, and VTL mapping templates to simulate an AppSync backend locally.

packages/cli/templates/infra-local/appsync-simulator · high confidence

Add local development scripts for S3, DynamoDB, and Step Functions

Added new shell (\.sh\) and PowerShell (\.ps1\) scripts to the \infra-local\ template to bootstrap local infrastructure resources. The \resources\ scripts ensure required S3 buckets and DynamoDB tables are created or verified, while the \trigger\_ddb\_stream\ scripts handle waiting for service health checks (DynamoDB, HTTP, Step Functions Local) and pre-register Step Functions state machines before triggering data streams. These scripts support configurable local ports via environment variables (e.g., \LOCAL\_S3\_PORT\, \LOCAL\_DYNAMODB\_PORT\) and include robust error handling and timeout management for local development workflows.

packages/cli/templates/infra-local/scripts · high confidence

Add master example with NestJS and Cognito integration

Introduces a new 'master' example application built with NestJS, featuring a REST API for managing master data via Cognito authentication and DynamoDB storage. The example includes a full module structure (controller, service, DTOs, entities) and configuration files (.env, tsconfig, nest-cli) to demonstrate the framework's capabilities.

examples/master · high confidence

Add new example projects and CLI templates with updated dependencies

Added new example projects for AppSync event client, master, and sequence modules, each with their own package.json and package-lock.json files. The CLI package was updated to version 0.1.74-beta.0 and includes new schematics and templates. The templates directory now includes a new infra template with AWS CDK dependencies. Additionally, the appsync-simulator and cognito-local templates were added with their respective dependencies. These changes provide developers with ready-to-use examples and templates for building serverless applications using the MBC CQRS framework.

(dependencies) · high confidence

Add project configuration and documentation scaffolding

Introduce configuration and documentation files to the project root, including \.aider.conf.yml\ for AI assistant context, \.cursorrules\ for Cursor IDE guidelines, and standard open-source documentation files (\AGENTS.md\, \CHANGELOG.md\, \CONTRIBUTING.md\, \FAQ.md\, \LICENSE.txt\, \README.md\, \SECURITY.md\, \TROUBLEshOOTING.md\, \TYPOS-REPORT.md\). These files establish the development workflow, coding conventions, and user-facing documentation for the MBC CQRS Serverless framework.

(repo-wide) · high confidence

Add sample template with CQRS and RDS sync

The CLI template now includes a complete sample implementation featuring a NestJS controller, service, and module, along with DTOs and entities for a 'sample' domain. It demonstrates a CQRS pattern where commands are published via a command service and data is synced to an RDS database using a custom data sync handler. The sample includes search, list, and detail retrieval endpoints, providing a reference for building similar features.

packages/cli/templates/src/sample · medium confidence

Add seq example with master module and configuration

Added a new 'seq' example application that demonstrates the CQRS serverless module. The example includes a 'master' module with controllers, services, and entities for managing master data, along with a sequence generation service. Configuration is provided via a .env file with local development endpoints for DynamoDB, S3, Step Functions, SNS, Cognito, AppSync, and SES, as well as a Prisma database URL. The example also includes NestJS CLI configuration, TypeScript build settings, and a REPL entry point for interactive development.

examples/seq · high confidence

Add session management and comprehensive unit tests for data-store services

The data-store module now includes a new SessionService that manages read-your-write session state in DynamoDB, with configurable TTL and a 1000-entry limit per user. The DynamoDbService gains a deleteItem method, supports consistent reads, and uses a structured S3 key path (ddb/table/pk/sk/ulid.json) for attribute storage. The S3Service now returns the Bucket and Key on putItem and uses a private bucket variable. Comprehensive unit tests were added for DynamoDbService, S3Service, and SessionService, covering success paths, error handling, and edge cases.

packages/core/src/data-store · high confidence

Add survey template and answer management capabilities

Introduced a new survey template module that enables creating, updating, and searching for survey templates and their associated answers. The change adds controllers and services for both survey templates and survey answers, along with the corresponding DTOs, entities, and RDS sync handlers. Users can now create and manage survey templates with additional properties, and submit or retrieve survey answers.

packages/survey-template/src · high confidence

Add tenant management DTOs for API validation

New Data Transfer Objects are introduced in the tenant package to define and validate API payloads for creating and updating tenants and tenant groups. The changes add CommonTenantCreateDto, TenantCreateDto, TenantGroupAddDto, TenantGroupUpdateDto, and TenantUpdateDto, each with specific validation decorators (e.g., IsString, IsObject, IsArray) to ensure incoming requests meet expected structures and types.

packages/tenant/src/dto · high confidence

Add tenant management controller and unit tests

Introduced the TenantController in packages/tenant/src/controllers, exposing REST endpoints for retrieving, creating, updating, and deleting tenants, as well as managing tenant groups and settings. The controller delegates to TenantService and is accompanied by comprehensive unit tests in tenant.controller.spec.ts that verify successful operations and error handling for all endpoints.

packages/tenant/src/controllers · high confidence

Added S3 event handling support

The event processing layer now supports S3 events. A new \handleS3Event\ method was added to \EventService\ and exposed via the \EventController\ at the \s3\ POST endpoint. The \DefaultEventFactory\ includes a \transformS3\ implementation to map S3 records to internal events. Additionally, the \DefaultEventFactory\ was updated to filter out DynamoDB stream records with \syncMode.SYNC\, and the \EventBus\ logging was corrected from 'binded' to 'bound'.

packages/core/src/events · high confidence

Added SQS support and refactored SNS client management

The queue module now supports Amazon SQS in addition to existing SNS capabilities. New services (SqsService, SnsService) and their corresponding client factories (SqsClientFactory, SnsClientFactory) have been added to the core package, with the SQS service providing methods for sending, receiving, and deleting messages. The SNS service has been refactored to use the new SnsClientFactory, which manages the AWS SDK client instance. The QueueModule has been updated to register and export these new services.

packages/core/src/queue · high confidence

Added configurable local service ports and environment configuration to the CLI template

The CLI template now includes a \.env.local\ file that defines configurable local service ports for components such as Serverless Offline, Lambda, DynamoDB, Cognito, and others, allowing users to resolve port conflicts during local development. Additionally, the template now provides standard configuration files (\.dockerignore\, \Dockerfile\, \.envrc\, \.eslintrc.js\, \.prettierrc\, \jest.config.json\, \nest-cli.json\, \tsconfig.json\) and a \gitignore\ file to standardize the development environment and tooling setup.

packages/cli/templates · high confidence

Added helper functions for generating and parsing setting keys

A new helper module at packages/ui-setting/src/helpers/index.ts introduces utility functions for constructing and parsing partition and sort keys for settings. It defines prefixes (MASTER, MASTER\_SETTING) and exports functions to generate primary keys (generateSettingPk), generate sort keys (generateSettingSk, generateDataSettingSk), and parse them back into structured objects (parseDataSettingSk, parsePk).

packages/ui-setting/src/helpers · medium confidence

Added infrastructure-as-code templates and build utilities for the CLI

Added new files in packages/cli/templates/infra/libs to support the CLI's infrastructure generation. This includes a build-app utility that handles local and CI build steps for the NestJS application, a DistributedMap helper for AWS Step Functions, and CDK stacks (InfraStack, PipelineInfraStage, PipelineStack) that define the AWS resources (Cognito, SNS, SQS, API Gateway, AppSync) and the CI/CD pipeline structure. These changes provide the foundational templates for generating and deploying infrastructure.

packages/cli/templates/infra/libs · high confidence

A new constants module was introduced in the tenant package, defining key identifiers such as the 'TENANT' system prefix, the 'tenant' table name, the 'SETTING' prefix for tenant settings, and the 'MASTER' tenant key. These constants provide a centralized source of truth for tenant-related string literals used across the application.

packages/tenant/src/constants · high confidence

Introduce @mbc-cqrs-serverless/mcp-server for AI tool integration

Adds a new MCP (Model Context Protocol) server package that enables AI tools like Claude Code and Cursor to interact with the MBC CQRS Serverless framework. The package provides resources for accessing framework documentation, tools for generating CQRS modules and analyzing projects, and prompts for debugging and migration guidance. It includes a CLI entry point, TypeScript configuration, and a test script to verify server functionality.

packages/mcp-server · high confidence

Introduce AppSync Events transport and enhance email service capabilities

The notification module now supports a new AppSync Events transport alongside the existing AppSync GraphQL transport, allowing notifications to be published to AWS AppSync Events channels using IAM SigV4 authentication. The EmailService has been enhanced to support email attachments via raw MIME content and supports inline templates with local fallback logic for offline development. Additionally, the email service now supports reply-to addresses and email tags for all email types.

packages/core/src/notifications · high confidence

Introduce ITenantService interface for tenant code management

A new ITenantService interface has been added to define the contract for managing tenant codes. This interface includes methods for creating, updating, and deleting tenant codes, as well as adding groups and customizing setting groups. The interface relies on specific DTOs (CommonTenantCreateDto, TenantCreateDto, etc.) and command/data models, establishing the API for the multi-tenant code management feature.

packages/tenant/src/interfaces · high confidence

Introduce MCP server for AI tool integration

A new MCP (Model Context Protocol) server package has been added to the MBC CQRS Serverless framework. This server exposes resources, tools, and prompts to AI assistants, allowing them to access framework documentation, generate code, and receive debugging help via the standard MCP interface.

packages/mcp-server/src · high confidence

Introduce RolesGuard for flexible role and tenant validation

A new \RolesGuard\ has been added to \packages/core/src/guard\ to enforce role-based access control and tenant validation. The guard validates JWT tokens and checks user roles against required roles. It enforces tenant code validation, allowing system admins to override tenant access via headers while restricting regular users to their assigned tenants. The implementation includes tests for tenant and role validation, ensuring that users without a custom tenant claim cannot use header overrides, while common tenants and cross-tenant roles are handled appropriately.

packages/core/src/guard · high confidence

Introduce TenantService for multi-tenant management

Added a new TenantService in the tenant package to handle the creation, update, and deletion of tenants and tenant groups. The service implements methods for creating common and individual tenants, updating tenant attributes, soft-deleting tenants, and managing tenant groups. A comprehensive test suite (tenant.service.spec.ts) validates the service's behavior, including scenarios for re-creating tenants after soft delete and handling common tenant creation.

packages/tenant/src/services · high confidence

Introduce core domain interfaces and DTOs for command processing and data synchronization

The core package now exposes a comprehensive set of interfaces and DTOs that define the contract for the command service, data sync handlers, and event processing. This includes the \ICommandService\ interface with \publishSync\, \publishAsync\, and \publishPartialUpdateSync\ methods, alongside \CommandModel\ and \CommandInputModel\ interfaces that support optimistic locking, tenant isolation, and soft deletes. Additionally, the \IDataSyncHandler\ interface and \CommandModuleOptions\ are defined to manage data synchronization between the command (write) and data (read) tables, while \IEventFactory\ and \IEvent\ interfaces standardize the transformation of AWS events (SQS, SNS, DynamoDB Streams, S3) into domain events. These changes provide the foundational types and validation rules required for the new command processing and data sync architecture.

packages/core/src/interfaces · high confidence

Introduce directory management package with file upload and view capabilities

A new \directory\ package has been added to manage directory structures and file operations. The package provides a NestJS module (\DirectoryStorageModule\) that registers controllers for creating, updating, copying, moving, renaming, and deleting directories, as well as generating presigned URLs for uploading and viewing files via S3. It includes DTOs for all directory and file operations, services for handling business logic and S3 interactions, and entity models for data representation. The module supports configurable table names and dynamic registration, allowing integration with existing core services like Prisma and DynamoDB.

packages/directory/src · high confidence

Introduce sequence generation service with formatted output and rotation support

Added a new sequence generation module in the \packages/sequence/src\ directory, providing a \SequencesService\ that generates formatted sequence numbers with support for daily, monthly, yearly, and fiscal-yearly rotation. The feature includes DTOs for input parameters (tenant code, type code, rotation criteria, prefixes/postfixes, and format strings), a controller exposing REST endpoints, and a data access layer that interacts with DynamoDB. The service also handles fiscal year calculations and master data lookups to determine sequence formatting.

packages/sequence/src · high confidence

Introduce structured import processing with CSV, ZIP, and publish modes

The import module now supports distinct processing modes (DIRECT and STEP\_FUNCTION) and publish modes (SYNC and ASYNC) to control how import jobs are executed and how results are reported. New DTOs (CreateCsvImportDto, CreateZipImportDto) and entities (ImportEntity with row counters) define the data contracts for CSV and ZIP imports. The system now routes single and batched import events to dedicated processors (CsvBatchProcessor, SingleImportProcessor) and handlers (CsvImportQueueEventHandler, CsvImportSfnEventHandler, ImportStatusHandler) that manage Step Functions execution, SQS batching, and status updates. This change adds the structural foundation for handling CSV and ZIP imports with configurable processing and publishing behavior.

packages/import/src · high confidence

Introduce task management and processing via event handlers and state machine integration

Adds a new task management capability, including entity models (TaskEntity, SubTaskEntity, TaskListEntity) and data transfer objects for creating tasks. Introduces event handlers for task queues and Step Functions, enabling task processing workflows and sub-task status updates. The change also adds enums for task status and types, a controller for task operations, and comprehensive unit and integration tests for the new functionality.

packages/task/src · high confidence

Introduce ui-setting module with configurable table name and event handler alias management

Added the ui-setting package, which provides a configurable NestJS module for managing UI settings. The module allows specifying a custom DynamoDB table name (defaulting to 'master') and supports asynchronous configuration. It includes controllers and services for settings and data, and manages event handler aliases to prevent conflicts with the MasterModule. The implementation includes comprehensive tests verifying table name forwarding, async registration, and alias collision handling.

packages/ui-setting/src · high confidence

Introduced data-setting DTOs and entities for the ui-setting package

The ui-setting package now includes data-setting related DTOs and entities. New DTOs include DataSettingCommandDto, CreateDataSettingDto, DataSettingSearchDto, and UpdateDataSettingDto, each defining validation rules for data setting operations. Additionally, new entity classes (DataSettingCommandEntity, DataSettingDataEntity, DataSettingDataListEntity) are added to the entities layer, supporting the data-setting functionality within the ui-setting package.

packages/ui-setting/src/dto, packages/ui-setting/src/entities · medium confidence

New MCP server tools for code analysis, validation, and generation

The MCP server now provides a suite of new tools for developers: code analysis (project structure, error catalog lookup, anti-pattern detection, health checks, and code explanation), CQRS pattern validation, and scaffolding for new modules, controllers, services, entities, and DTOs. These tools enable AI assistants to inspect, validate, and generate MBC CQRS Serverless framework code directly within the IDE.

packages/mcp-server/src/tools · high confidence

New authentication, role-based access control, and context decorators

The core package introduces new decorators to support authentication and authorization: an \@Auth\ decorator that combines role-based access control with Swagger documentation, a \@Roles\ decorator for specifying required roles, and a \@HeaderTenant\ decorator for tenant code headers. Additionally, a \@GroupRoleResolver\ decorator marks classes as group role resolvers, and a \@NotificationTransport\ decorator registers notification transports. A new \@INVOKE\_CONTEXT\ param decorator extracts the current invocation context. These changes expand the framework's capabilities for securing endpoints and managing application context.

packages/core/src/decorators · high confidence

New helper utilities for sorting and ID parsing

The CLI templates now include new helper functions for data handling. The get-order module provides utilities to convert string-based sort orders (including descending prefixes) into Prisma-compatible sort objects. The id module introduces a parser for composite primary keys, splitting them into type and tenant code components using a defined key separator. These helpers are exported via the templates' index file, making them available for use within generated code.

packages/cli/templates/src/helpers · medium confidence

New integration test utilities for AWS SDK error handling and mocking

Added new utility modules in packages/core/src/integration/utilities to support integration tests. The aws-error-factory provides factory functions to create standardized AWS SDK v3 errors (DynamoDB, S3, SQS, SNS, Step Functions, SES) with consistent metadata and retryable flags. The aws-mock-manager offers a centralized way to set up and tear down mocked AWS clients (DynamoDB, S3, SQS, SNS, Step Functions, SES) for tests. The test-assertions module exports reusable assertion helpers to validate error types (retriable, throttling, network, timeout) and error metadata. The test-data-builders module provides factory functions to generate test data for DynamoDB items, keys, and batch operations. These utilities are exported via the index.ts barrel file and tested in utilities.spec.ts.

packages/core/src/integration/utilities · high confidence

New master data and settings management endpoints

The master package now exposes a new set of controllers and DTOs for managing master data and settings. This includes a unified bulk upsert endpoint at /api/master-bulk that routes items to either the master data or master setting services based on the presence of a settingCode. Additionally, dedicated controllers are introduced for master data (CRUD and bulk operations), master settings (CRUD, bulk, and copy operations), and custom task management (querying SFN task parents and children). These changes add new API routes and validation logic for tenant code verification and data integrity.

packages/master/src · high confidence

New serialization, transformation, and utility helpers in the core package

The core package introduces several new helper modules to support data mapping and object manipulation. A new serializer module provides functions to convert between internal DynamoDB-style structures and external flat formats, with corresponding tests. A transform module adds a function to map CommandModel objects to DataModel objects, handling field mapping and timestamp preservation. Additionally, new utility functions have been added for deep object merging, byte calculation, and key generation/parsing, alongside datetime formatting helpers. The previous object-byte helper was removed and replaced with the new object utilities.

packages/core/src/helpers · high confidence

New tenant management module with configurable controllers and data sync

A new tenant management module has been introduced, providing a configurable NestJS module that integrates with existing CQRS and queue infrastructure. The module allows enabling a tenant controller and injecting optional data sync handlers, while also updating a Prisma DynamoDB schema file to include a new table name. This enables multi-tenant capabilities with flexible controller and data synchronization options.

packages/tenant/src · medium confidence

Behavioural changes

Add Step Function task token resume capability and execution name validation

The StepFunctionService now supports resuming Step Functions tasks via a new resumeExecution method that wraps the output in the required Payload array structure and handles errors gracefully by logging at the debug level. Additionally, the startExecution method now accepts an optional name parameter and validates that the execution name does not exceed 80 characters, silently falling back to an auto-generated name if the limit is exceeded.

packages/core/src/step-func · high confidence

Added pre-commit hook for lint-staged

A new pre-commit hook has been added to the .husky directory, which runs lint-staged on staged files before each commit. This ensures that code quality checks are automatically enforced at commit time.

.husky · high confidence

Added tenant setting entity models

Introduced new entity classes for managing tenant settings. The diff adds a base SettingEntity with id and settingValue properties, and a SettingListEntity that wraps an array of these settings, enabling structured data transfer for tenant configuration.

packages/tenant/src/entities · high confidence

Configurable tenant and role constants via environment variables

The core constants module now supports environment variable configuration for tenant and role settings. \DEFAULT\_COMMON\_TENANT\_CODES\ and \DEFAULT\_CROSS\_TENANT\_ROLES\ can be customized via \COMMON\_TENANT\_CODES\ and \CROSS\_TENANT\_ROLES\ respectively, allowing flexible multi-tenant and cross-tenant role configurations. The legacy \TENANT\_COMMON\ constant is deprecated in favor of the new array-based constants. Additionally, version constants \VERSION\_LATEST\ and \VERSION\_FIRST\ are added to the key constants, and the \Role\ enum is replaced by a \ROLE\_SYSTEM\_ADMIN\ constant.

packages/core/src/constants · high confidence

Core package refactors and adds unit tests

The core package introduces a new group-based authorization system with a \GroupRoleResolverRegistry\ and \AuthzBootstrapService\ to manage role resolution at startup. The bootstrap process now supports a configurable request body size limit and validates environment variables for multiple notification transports (AppSync GraphQL and Events). The Lambda handler signature is updated to be compatible with Node.js 24 by removing the callback parameter. Additionally, the \env.validation\ module is refactored to support custom environment classes and includes a migration for deprecated environment variables, while comprehensive unit tests are added for the bootstrap, environment validation, and authorization modules.

packages/core/src · high confidence

Improved reliability and observability for DynamoDB-to-Step Functions sync

The data-sync event handler now generates unique, traceable execution names for Step Functions, enabling better debugging and monitoring. Additionally, the handler now gracefully handles missing state machines in local development (serverless-offline) while ensuring that missing state machines in production environments are treated as critical errors rather than being silently swallowed. The \DataSyncCommandSfnEvent\ class also gained a \getFullCommandRecord\ method to support retrieving full command records from S3, and a new \SET\_TTL\_COMMAND\ step was added to the state machine name enum.

packages/core/src/command-events · high confidence

Introduce notification transport abstraction

Added new enums and interfaces to support flexible notification transport mechanisms. Specifically, the \NotificationTransports\ enum defines \APPSYNC\_GRAPHQL\ and \APPSYNC\_EVENT\ as supported transport types. Additionally, the \INotificationTransport\ interface and \NotificationTransportMap\ type are introduced to allow for pluggable transport implementations, enabling the system to send notifications via different underlying protocols.

packages/core/src/notifications/enums, packages/core/src/notifications/interfaces · medium confidence

Local development environment now supports configurable service ports

The local infrastructure template has been updated to allow all local service ports to be configured via environment variables (e.g., \LOCAL\_COGNITO\_PORT\, \LOCAL\_SFN\_PORT\, \LOCAL\_DYNAMODB\_PORT\). This change ensures that the Cognito local issuer URL matches the actual container port, fixing JWT validation issues with the serverless-offline authorizer. Additionally, the \docker-compose.yml\ and \serverless.yml\ configurations have been updated to support running the project in a Windows environment and to include new services such as a queue, Step Functions, and alarms.

packages/cli/templates/infra-local · medium confidence

Notification system refactored to support multiple transport backends

The notification event handler has been refactored to support multiple notification transports instead of a single AppSync service. The handler now discovers and initializes all registered transport implementations (decorated with @NotificationTransport) and broadcasts notifications to every active transport. The active transports are configured via the NOTIFICATION\_TRANSPORTS environment variable, allowing users to enable or disable specific notification backends. The implementation includes a new test suite for the event handler, covering transport discovery, configuration, and broadcasting behavior.

packages/core/src/notifications/event · high confidence

Refactor user context extraction and tenant code normalization

The user context extraction logic in packages/core/src/context has been refactored to normalize tenant codes to lowercase for case-insensitive matching, ensuring consistent API responses and seamless migration from legacy uppercase tenant codes. The new implementation in user.ts and invoke.ts introduces a more robust UserContext structure that includes tenantRoles and tenantGroupIds, and handles malformed JWT tokens gracefully. Backward compatibility is maintained through new tests in backward-compatibility.spec.ts, which verify that legacy uppercase tenant codes and mixed-case roles are correctly normalized and matched.

packages/core/src/context · medium confidence

Fixes

Configurable port and JWT issuer alignment for local Cognito

The local Cognito template now supports a configurable port via the \LOCAL\_COGNITO\_PORT\ environment variable, defaulting to 9229. The startup script dynamically updates the JWT \iss\ claim to match the actual listening port, ensuring the issuer URL remains consistent with the serverless authorizer's configuration.

packages/cli/templates/infra-local/cognito-local · medium confidence

Test coverage

Add tests for SettingTypeEnum values; Add unit tests for DataSetting and Setting services; Added DynamoDB test infrastructure scripts; Added comprehensive unit tests for the core command handling system; Added end-to-end tests for publish and health check functionality; Added hermetic snapshot and assertion tests for the infra template; Added integration tests for AWS SDK and third-party libraries; Added integration tests for MCP SDK and Zod schema validation; Added integration tests for tenant isolation and API snapshots; Added local AppSync simulator infrastructure for testing; Added local Cognito test infrastructure and DDB stream trigger script; Added local test infrastructure and test controller for command publishing; Added snapshot tests for the CDK infrastructure template; Added template files for CLI test configuration and API testing; Added test infrastructure scripts for local DynamoDB and service startup/teardown; Added tests for MCP server components; Added tests for service configuration and environment variable handling; Added unit tests for DataSetting and Setting controllers; Improved test coverage and deduplication logic in core services.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 46 → 52 (+5.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 87 → 84 (-2.6)
  • Architecture 45 → 55 (+10.4)
  • Maturity 77 → 75 (-1.3)
  • Readiness 55 → 62 (+7.3)
  • Security 33 → 40 (+7.3)

Resolved (95)

  • Change coupling: data-setting.service.ts ↔ setting.service.ts (packages/ui-setting/src/services/data-setting.service.ts)
  • Change coupling: tenant.controller.ts ↔ tenant.service.interface.ts (packages/tenant/src/controllers/tenant.controller.ts)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
  • Critical vulnerability: [GHSA redacted] (package-lock.json)
  • Critical vulnerability: [GHSA redacted] (package-lock.json)
  • Critical vulnerability: [GHSA redacted] (packages/cli/templates/package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (packages/cli/templates/infra-local/appsync-simulator/package-lock.json)
  • High CVE: [GHSA redacted] (packages/cli/templates/infra-local/appsync-simulator/package-lock.json)
  • High CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
  • …and 75 more

New (239)

  • Assertions commented out: should preserve design:type for properties (packages/core/src/integration/reflect-metadata-behavior.spec.ts)
  • ClassTooLong: DirectoryService (packages/directory/src/directory.service.ts)
  • ClassTooLong: InfraStack (packages/cli/templates/infra/libs/infra-stack.ts)
  • CommandEventHandler.waitConfirmToken (cognitive 18) (packages/core/src/commands/command.event.handler.ts)
  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
  • CsvBatchProcessor.process (cognitive 22) (packages/import/src/event/processor/csv-batch.processor.ts)
  • CsvImportSfnEventHandler.getResultsFromS3Writer (cognitive 22) (packages/import/src/event/csv-import.sfn.event.handler.ts)
  • CsvImportSfnEventHandler.handleStepState (cognitive 35) (packages/import/src/event/csv-import.sfn.event.handler.ts)
  • …and 219 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mbc-net/mbc-cqrs-serverless was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0db0a3446901c642bdc2ab564284b848a7fee7d4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.