medevorg/nodetskeleton
54.0
Adequate · 21 September 2026
4.3k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a Node.js backend application structured around a clean architecture, featuring an API gateway that routes requests to distinct microservices for authentication and user management. It implements a modular design with dedicated adapters for HTTP controllers, data repositories, and external providers, all orchestrated by a shared dependency injection kernel. The application provides secure user registration and login capabilities, supported by robust middleware for localization, tracing, and error handling.
How it got here
2020–2021 — Authentication and security infrastructure
45 changes.
The project implemented a comprehensive authentication and security layer, introducing JWT-based login, session management, and password encryption. This period also established a robust infrastructure for error handling, dependency injection, and localized messaging, while modernizing the codebase with Node 20+ and updated dependencies.
2022 — API gateway and user service implementation
20 changes.
This period focused on establishing the core infrastructure for the Users and Auth services, including an API gateway for routing and a new Users controller. The work involved implementing middleware for authorization and client information, setting up structured logging and tracing, and creating shared utility classes and dependency injection containers to support the new services.
2023–2025 — infrastructure and API standardization
13 changes.
This period focused on establishing a robust, type-safe foundation for the application by introducing shared abstractions for HTTP clients, DTOs, and result handling. The team standardized API documentation, implemented health checks, and added middleware for logging, while also enforcing code quality through pre-commit hooks.
Features
Add Users controller with OpenAPI documentation
A new UsersController class has been introduced in the adapters/controllers/users directory, providing endpoints for user sign-up and retrieval. The controller integrates with a service container to resolve use cases and includes comprehensive OpenAPI (Swagger) annotations, defining request/response schemas, HTTP methods, and status codes for the /v1/users/sign-up and /v1/users/:maskedUid routes.
src/adapters/controllers/users · high confidence
Add application status codes
A new file, applicationStatus.ts, was added to the shared status module, introducing an ApplicationStatus enum that maps status codes (e.g., SUCCESS, INTERNAL\_ERROR, NOT\_FOUND) to their corresponding string values.
src/application/shared/status · medium confidence
Add in-memory user and session storage for authentication
A new in-memory data store has been introduced to support user authentication and session management. The \User.model.ts\ file implements the \IUserModel\ interface, providing methods to retrieve users by email, masked UID, or authentication credentials, as well as creating new users. Additionally, it handles session lifecycle by registering logout events and retrieving active sessions. This is backed by \db.mock.json\, which contains a mock user record and an empty logoff array to simulate database interactions for testing or development purposes.
src/infrastructure/dataBases/nodeTsKeleton · high confidence
Add user registration use case with password encryption and validation
The user registration flow now enforces strict validation on email and password fields, returning 400/404 errors for invalid inputs or duplicate emails. Passwords are encrypted using a worker provider (or direct encryption in dev mode) before storage, and the implementation includes comprehensive unit tests for all error and success paths.
src/application/modules/users/useCases/register · high confidence
Added API status and not-found use cases
New use cases were added to the application's status module: a PongUseCase that returns a 200 success status for API health checks, and a NotFoundUseCase that returns a 404 error for non-existent endpoints. Both are accompanied by corresponding unit tests.
src/application/modules/status/useCases/pong · high confidence
Added BaseIterator to orchestrate sequential use-case execution
A new abstract class, BaseIterator, has been introduced in the shared iterator module. It accepts an array of BaseUseCase instances and executes them sequentially, passing the result data from each step as the input for the next. The iteration stops early if any use case fails, ensuring that downstream tasks are not executed on erroneous data.
src/application/shared/iterator · high confidence
Added DTOs for authentication credentials and tokens
New data transfer objects were introduced to handle authentication data. A CredentialsDto class was added to manage email and password information, extending a base DTO for validation. Additionally, a TokenDto class was created to represent authentication tokens and their expiration times.
src/application/modules/auth/dtos · high confidence
Added English, Spanish, and Brazilian Portuguese translations for core UI labels
The application now supports English, Spanish, and Brazilian Portuguese for key interface terms such as email, password, name, gender, encryption, session, and user ID. These translations are implemented as TypeScript modules that map internal keys to localized strings, enabling the application to display these labels in the user's preferred language.
src/application/shared/locals/words · high confidence
Added GetUserUseCase for retrieving user details
A new use case, GetUserUseCase, has been introduced in the users module to handle fetching user data by masked UID. This addition provides a dedicated application-layer component for retrieving user information, integrating with the existing repository and DTO structures to return user data in a standardized format.
src/application/modules/users/useCases/get · high confidence
Added HTTP request logging middleware
A new logger middleware has been introduced to automatically log HTTP requests, capturing the method, path, status code, and request duration for each response. This provides visibility into request handling times and status codes across the application.
src/infrastructure/middleware/logger · high confidence
Added IWorkerProvider interface for task execution
A new IWorkerProvider interface has been introduced in the shared worker contracts, defining an executeTask method that accepts a WorkerTask and returns a Promise, enabling consistent task execution across worker implementations.
src/application/shared/worker/providerContracts · high confidence
Added JWT authorization middleware
A new JWT authorization middleware has been introduced to the infrastructure layer. It intercepts requests, validates the Authorization header, and verifies the JWT token using the registered AuthProvider. If the token is missing, malformed, or invalid, the middleware returns an UNAUTHORIZED error; otherwise, it attaches the parsed session to the request context.
src/infrastructure/middleware/authorization/jwt, src/infrastructure/middleware/authorization/session · high confidence
Added Logger implementation for structured logging
A new Logger class has been introduced in the infrastructure layer, implementing the ILogger interface. It provides methods for info, error, message, and warning logs, each outputting a timestamped, JSON-serialized representation of the event or error to the console.
src/infrastructure/logger · high confidence
Added WorkerProvider for executing tasks via Node.js worker threads
A new WorkerProvider class has been introduced in the worker adapter, implementing the IWorkerProvider interface to execute tasks using Node.js worker threads. This change enables the application to offload specific tasks to separate threads, with the provider handling message passing, error handling, and exit code checking for worker threads.
src/adapters/providers/worker · high confidence
Added authentication endpoints for login and logout
A new AuthController has been introduced to handle user authentication. It exposes a login endpoint that accepts email and base64-encoded password credentials to issue tokens, and a logout endpoint that invalidates the current session. Both endpoints are configured with OpenAPI documentation, specifying the request and response schemas for API consumers.
src/adapters/controllers/auth · high confidence
Added client information extraction middleware
A new middleware has been introduced to automatically extract and attach client details to each request. It populates the request object with the IP address (checking both the direct IP and the 'X-Forwarded-For' header), the user agent string, and the origin or referrer header, making this data readily available for downstream processing.
src/infrastructure/middleware/clientInfo · high confidence
Added encryption utility for secure data handling
A new Encryption class has been introduced in the shared security module, providing a static utility for encrypting text using the PBKDF2 algorithm with SHA-512. This component allows the application to securely process sensitive data, initializing with configurable keys, iteration counts, and key sizes.
src/application/shared/security · high confidence
Added environment configuration files for auth and users services
New environment configuration files (.env\_security\_context and .env\_users\_context) were added to the tsk-gateway/envs directory. These files define service-specific settings for the auth and users microservices respectively, including server ports (3003 and 3004), encryption keys, and JWT secrets, enabling the gateway to manage these services dynamically.
tsk-gateway/envs · high confidence
Added health status provider implementation
A new HealthProvider class was added to the health adapters layer, implementing the IStatusProvider interface. This provider uses an injected HTTP client to optionally make remote requests to check service status, returning a status message that includes remote request results when available.
src/adapters/providers/health · high confidence
Added localization middleware to parse Accept-Language headers
A new LocalizationMiddleware has been introduced to automatically detect and set the request's locale based on the HTTP Accept-Language header. The middleware parses the header, prioritizes languages by quality value, and maps them to supported locale types, defaulting to a configured fallback if no match is found.
src/infrastructure/middleware/localization · high confidence
Added login use case with validation and session management
Introduced the LoginUseCase, which handles user authentication by validating credentials, encrypting the password, and generating a JWT-based session. The implementation includes comprehensive test coverage for error scenarios (missing or invalid credentials) and successful login flows, ensuring that users receive appropriate error messages or a valid token upon successful authentication.
src/application/modules/auth/useCases/login · high confidence
Added password encryption utility for worker threads
A new \encryptPassword.js\ script was added to the worker provider, introducing a \pbkdf2Sync\-based encryption function that processes tasks via \parentPort\ messaging. This script handles parameter validation and returns structured error or data responses, enabling the worker to perform secure password hashing operations.
src/adapters/providers/worker/scripts · high confidence
Added pre-commit hook script
A new pre-commit hook has been added to the .husky directory. This hook executes the 'npm run pre-commit' command before each commit, ensuring that pre-commit checks are automatically enforced in the development workflow.
.husky · high confidence
Added route whitelist middleware for authorization
A new RouteWhiteListMiddleware has been introduced to manage an allowlist of public routes that bypass standard authorization checks. The middleware evaluates the incoming request path against a list of rules (supporting 'equal' and 'starts-with' matching) and sets an 'isWhiteList' flag on the request context, allowing unauthenticated access to specific endpoints such as /status, /v1/auth/login, /v1/users/sign-up, and the /docs directory.
src/infrastructure/middleware/authorization/whiteList · high confidence
Added session data contract
A new interface ISession was added to define the structure of session data, including fields for session ID, masked user UID, email, email verification status, name, and token timestamps.
src/domain/session · high confidence
Added shared utility classes for async, date/time, and GUID generation
New utility classes have been introduced in the application's shared utilities to provide standardized helper methods. AsyncUtil offers a promise-based wait function for asynchronous delays. DateTimeUtils implements the IDateTimeUtil interface to handle current date/time retrieval and timestamp conversion using the Luxon library. GuidUtil implements the IGuidUtil interface to generate UUIDs, including a variant that removes hyphens, utilizing the uuid package. These changes enhance code reusability and standardize common utility functions across the application.
src/application/shared/utils · high confidence
Added status controller for API health checks
A new StatusController has been introduced in the adapters/controllers/status directory, providing a GET /status endpoint that returns a pong response for health checks. The controller is configured with OpenAPI documentation support and handles 404 not-found scenarios, integrating with the application's service container and base controller infrastructure.
src/adapters/controllers/status · high confidence
Added trace logging for use cases
A new trace logging capability has been introduced, allowing use cases to register trace information. This includes a new interface IUseCaseTraceRepository and its implementation UseCaseTraceRepository, which currently logs trace data to the console.
src/adapters/repositories/trace · high confidence
Added trace middleware for request tracking
A new middleware has been introduced to capture and store trace information for each request. This middleware initializes a UseCaseTrace object with request details such as path, HTTP method, parameters, query, and client information (IP, user agent), enabling better observability and debugging of use cases.
src/infrastructure/middleware/trace · high confidence
Adds shared utility classes for common data operations
New utility classes have been introduced in the shared domain layer to standardize common operations. These include ArrayUtil for list manipulations, BooleanUtil for equality and boolean checks, DefaultValue for handling null/undefined fallbacks, JSONfn for safe function serialization, NumberUtil for numeric checks, ObjectPropertyUtil for dynamic property assignment and removal, StringUtil for encoding and formatting, TryWrapper for safe synchronous and asynchronous execution, and TypeParser for type casting. These utilities provide reusable, type-safe helpers for the rest of the application.
src/domain/shared/utils · high confidence
Centralized application configuration via AppSettings
A new AppSettings class has been introduced to centralize application configuration. It provides static properties for environment, service context, server details, and security settings, which are initialized via a single init method. This change allows the application to manage its settings in a single, accessible location.
src/application/shared/settings · high confidence
Centralized error handling and logging middleware
A new error handling middleware has been introduced to centralize the management of application and uncaught Node.js exceptions. This middleware logs errors via an integrated log provider, distinguishes between controlled application errors and uncontrolled exceptions, and returns standardized JSON error responses to the client.
src/infrastructure/middleware/error · high confidence
Introduce AppWrapper for centralized application initialization and dynamic controller loading
The application startup process has been refactored to use a new AppWrapper class that centralizes the initialization of middleware, controllers, and services. This change introduces support for both constructor-based and dynamic loading of controllers, allowing the application to automatically discover and register controllers based on configuration. The AppWrapper also handles the setup of core services, including encryption, localization, and API documentation generation, providing a single entry point for starting the application.
src/infrastructure/app · high confidence
Introduce BaseDto for shared validation and mapping logic
A new abstract BaseDto class has been added to the shared DTO layer, providing a centralized foundation for Data Transfer Objects. This base class encapsulates common dependencies including message resources, word translations, a mapper instance, and a Validator instance configured with specific error handling for missing parameters. This change consolidates shared validation and mapping responsibilities, allowing concrete DTOs to inherit these capabilities automatically.
src/application/shared/dto · high confidence
Introduce HTTP status code mapping for application statuses
Added new files to map internal application statuses to standard HTTP status codes. The \HttpStatusEnum\ enum defines all standard HTTP status codes, while \AppStatusMapping\ provides a mapping from application-specific statuses (like \ApplicationStatus\ or \INVALID\_INPUT\) to their corresponding HTTP codes (like \BAD\_REQUEST\ or \INTERNAL\_SERVER\_ERROR\). The \HttpStatusResolver\ class uses this mapping to resolve the appropriate HTTP status code for a given application status, defaulting to \418 (I\_AM\_A\_TEAPOT)\ if no specific mapping is found.
src/adapters/controllers/base/httpResponse · high confidence
Introduce HttpServer class for application startup and lifecycle management
A new HttpServer class has been added to manage the HTTP server lifecycle. It wraps the AppWrapper to initialize services and start the server, logging startup time and service status. The server also handles saving OpenAPI documentation during development.
src/infrastructure/app/server · medium confidence
Introduce InfrastructureServiceContainer for dependency injection
A new InfrastructureServiceContainer class has been added to manage the application's dependency injection container. It is responsible for registering essential providers (Logger, UseCaseTraceRepository), services (HttpClient), and loading repositories and database models into the kernel, centralizing the initialization of the infrastructure layer.
src/infrastructure/container · high confidence
Introduce UserDto for user data transfer and validation
A new UserDto class has been added to handle user data transfer, mapping, and validation. This class extends BaseDto and implements methods to convert between domain models, DTOs, and JSON, as well as validating user input fields such as name, email, and gender.
src/application/modules/users/dtos · high confidence
Introduce base controller with unified error handling and tracing
A new abstract \BaseController\ class has been added to the \src/adapters/controllers/base\ directory. This class centralizes common HTTP response handling, header management, and error catching logic for all controllers. It integrates with the service container to resolve logging and tracing dependencies, ensuring that use-case traces are consistently recorded and that errors are propagated to the next handler via a shared \try/catch\ block in methods like \handleResult\ and \handleResultDto\.
src/adapters/controllers/base · high confidence
Introduce base worker model and task definitions
Added new model files for the shared worker module: a base worker class that provides access to application messages, words, status, and validation; an interface for worker results containing optional error or data payloads; an enumeration for task types (currently ENCRYPT\_PASSWORD); and a WorkerTask class to encapsulate task type and arguments.
src/application/shared/worker/models · high confidence
Introduce dependency injection container for provider initialization
A new \container\ provider module has been added to centralize the initialization of application providers (Log, Auth, Health, and Worker) using a shared kernel. This change introduces a \loadProviders\ function that registers these providers as singletons within the container, establishing a dependency injection pattern for managing provider lifecycles and dependencies.
src/adapters/providers/container · high confidence
Introduce shared HTTP client interfaces and types
Added new shared HTTP client abstractions to the \src/adapters/shared/httpClient\ directory. This includes a \BaseHttpClient\ abstract class with a generic \send\ method, a strongly-typed \ITResponse\ interface for handling HTTP responses and errors, and a \SerializationTypeEnum\ to define supported serialization formats. These changes provide a standardized, type-safe way to perform HTTP requests across the application.
src/adapters/shared/httpClient · high confidence
Introduce shared kernel module for dependency injection and status management
A new shared kernel module has been added to provide a centralized entry point for the dependency injection container and application status handling. This module initializes the DI container with internal error codes, application messages, and status configurations, and exports the service container interface for use across the application.
src/adapters/shared/kernel · medium confidence
Introduced containerized dependency injection for status controllers
Added a new TypeScript module at src/adapters/controllers/status/container/index.ts that registers the PongUseCase and NotFoundUseCase with the application's dependency injection kernel. This change encapsulates the instantiation of these status-related use cases, ensuring they receive the required LogProvider and HealthProvider dependencies through the shared kernel, thereby improving modularity and testability of the status adapter layer.
src/adapters/controllers/status/container · high confidence
Introduces HTTP context interfaces and enums for the adapter layer
New interfaces (IRequest, IResponse, IRouter, INextFunction) and enums (HttpContentTypeEnum, HttpHeaderEnum, HttpMethodEnum) are added to the base context, providing a structured, decoupled contract for HTTP handling in the adapter layer.
src/adapters/controllers/base/context · high confidence
Introduces IUserRepository interface for user data access
A new IUserRepository interface is introduced to define the contract for user data operations. This interface specifies three methods: getByEmail, getByMaskedUid, and register, each returning a Promise that resolves to a user object or null. This change establishes a clear contract for user repository implementations, likely supporting the dynamic controller loading and other user-related features mentioned in the commit history.
src/application/modules/users/providerContracts · high confidence
Introduces a shared mapper module wrapping mapper-tsk
A new shared mapper module has been added at src/application/shared/mapper/index.ts. It re-exports the default mapper function and the IMap interface from the external library mapper-tsk, providing a centralized entry point for mapping functionality across the application.
src/application/shared/mapper · high confidence
Introduces shared type exports for result handling, validation, and resources
A new index file at src/application/shared/types now re-exports key types and interfaces from the result-tsk, validator-tsk, and resources-tsk libraries. This centralizes access to result handling (IResult, Result, IResultT, ResultT), execution wrappers (ResultExecution, ResultExecutionPromise), validation logic (Validator), and resource definitions (Resources, IResources) for use across the application.
src/application/shared/types · high confidence
Introduces the IAuthProvider contract for authentication operations
A new interface, IAuthProvider, is introduced to define the contract for authentication services. This interface specifies methods for user login, JWT generation and verification, session management, and logout functionality, establishing the expected behavior for authentication providers within the application.
src/application/modules/auth/providerContracts · high confidence
Introduces user domain models and validation logic
Adds the core user domain entities to the application, including the User class which encapsulates user profile data (uid, name, email, gender, etc.) and provides a method to create a session. The update also introduces an Email value object with regex-based validation, a PasswordBuilder for handling password encoding and validation, and a Gender enumeration. These changes establish the foundational data structures and validation rules for user authentication and profile management.
src/domain/user · high confidence
Introduces user repository interface and implementation
Adds a new IUserModel interface and a corresponding UserRepository class in the user adapter layer. The interface defines methods for retrieving users by email, masked UID, and session, as well as creating and logging out users. The UserRepository implements the IUserRepository contract, delegating to the IUserModel and handling email type casting, effectively decoupling the user repository logic from the infrastructure layer.
src/adapters/repositories/user · medium confidence
New API gateway service for routing requests
A new API gateway has been introduced to route requests to backend services. The gateway listens on port 8080 and proxies traffic to the Security service (port 3003) and the Users service (port 3004). It supports both local and Docker-based routing configurations, allowing the gateway to dynamically adjust target hosts based on the environment.
tsk-gateway/src · high confidence
New JWT-based authentication provider implementation
A new AuthProvider class has been introduced to handle authentication logic, including JWT token generation and verification, user login, and session management. This implementation relies on the jsonwebtoken library for cryptographic operations and integrates with existing domain models and interfaces.
src/adapters/providers/auth · high confidence
New logging and tracing infrastructure
Added new classes for structured logging and use-case tracing. The \EventLog\ and \ErrorLog\ classes provide a standardized way to capture events and errors, while \UseCaseTrace\ records detailed request and session data for each use case execution. An \ILogProvider\ interface defines the contract for logging providers, enabling integration with different logging backends.
src/application/shared/log · high confidence
New logging provider implementation
A new logging provider has been introduced to the adapters layer, featuring an \ILogger\ interface and a \LogProvider\ class that implements \ILogProvider\. This change decouples the adapters layer from the infrastructure layer by providing a concrete implementation for logging events, errors, and messages through the \LogProvider\.
src/adapters/providers/log · high confidence
New mock builder infrastructure and test fixtures for application layer
The application layer now includes a generic MockBuilder utility that simplifies the creation of mock objects for testing. This infrastructure supports new mock classes for ApplicationError, Session, UseCaseTrace, User, and UserDto, each providing a fluent API to configure test data. Additionally, a MockConstants class is introduced to centralize sample data such as user IDs, emails, and passwords, making it easier to write consistent and readable tests across the application.
src/application/mocks · high confidence
New utility contracts for date/time and GUID generation
Added new interfaces IDateTimeUtil and IGuidUtil to the shared utility contracts, defining standardized methods for date/time operations (getISONow, getCurrentDate, getCurrentTime, toDateTMZ) and GUID generation (getV4, getV4WithoutDashes). These contracts enable decoupling of utility implementations through a facade pattern, allowing for more flexible and testable code.
src/domain/shared/utilityContracts · high confidence
Repository container initialization and registration
A new container module is introduced to manage the registration of repository dependencies. Specifically, it defines a \loadRepositories\ function that registers the \UserRepository\ as a singleton within the shared kernel, establishing the foundation for dependency injection in the repository layer.
src/adapters/repositories/container · high confidence
Behavioural changes
Added TaskDictionary model for worker provider
A new model file, TaskDictionary.ts, was added to the worker provider's models directory. This class defines a static constant, ENCRYPT\_PASSWORD, which points to the path of a script used for password encryption, establishing the data structure for task-related operations within the worker adapter.
src/adapters/providers/worker/models · high confidence
Auth controller container registers login and logout use cases
The authentication controller now explicitly registers the Login and Logout use cases in the dependency injection container. This change wires the login and logout flows to their respective providers (LogProvider and AuthProvider) via the shared kernel, ensuring that each request gets a fresh (scoped) instance of these use cases.
src/adapters/controllers/auth/container · medium confidence
Centralized configuration for server, security, and controller paths
The configuration module has been refactored to centralize environment-based settings. The server now defaults to port 3003 and root path /api. Security parameters for JWT expiration (defaulting to 3600 seconds) and encryption iterations are now explicitly configured. Additionally, controller loading paths are dynamically constructed based on the service context, supporting both status and context-specific controller directories.
src/infrastructure/config · medium confidence
Centralized cryptographic and encoding constants
A new AppConstants class has been introduced to centralize definitions for cryptographic algorithms (SHA-512, SHA-256, HS512) and encoding standards (Base64, ASCII). This provides a single source of truth for these security-related constants across the application.
src/domain/shared · medium confidence
Introduce BaseUseCase with centralized error handling and tracing
A new abstract BaseUseCase class has been added to the shared application layer. This base class provides a standardized structure for all use cases, including automatic initialization of locale-based messages, a handleResultError method that throws on failure, and a trace initialization method for auditing. This change means all use cases now inherit consistent error handling and logging capabilities.
src/application/shared/useCase · high confidence
Introduce HttpClient with native fetch and form-data support
Added a new HttpClient implementation that leverages the native fetch API, removing the previous node-fetch dependency. The update includes improved handling of multipart/form-data requests using the Busboy library, allowing for robust parsing of file uploads and form fields. Additionally, a new TResponse class was introduced to standardize HTTP response handling, providing a consistent interface for success and error states.
src/infrastructure/httpClient · high confidence
Introduce ServiceContext enum for shared service identifiers
A new ServiceContext enum is added to the shared adapters layer, defining string constants for Node, skeleton, users, and auth services. This provides a centralized place for service context identifiers used across the application.
src/adapters/shared · high confidence
Introduce base provider class for shared provider logic
A new abstract BaseProvider class has been added to the application, providing a common foundation for provider implementations. This class initializes shared dependencies including a logger, a validator, a mapper, and application status codes, ensuring consistent setup across all provider implementations.
src/adapters/providers/base · medium confidence
Introduce structured application error handling
The application layer now uses a dedicated error handling mechanism. A new \ApplicationError\ class is introduced to wrap errors with a context, message, and error code, providing a structured way to handle application-level failures. Additionally, a \Throw\ utility class is added to facilitate throwing these structured errors conditionally, improving error management and debugging.
src/application/shared/errors · high confidence
Introduces a base repository class for shared repository functionality
A new abstract BaseRepository class has been added to provide a common foundation for all repository implementations. This class initializes shared dependencies including a mapper, a validator, and application message resources, and exposes an ApplicationStatus constant for consistent status code handling across repositories.
src/adapters/repositories/base · medium confidence
Introduces database model registration in the infrastructure container
A new TypeScript file at src/infrastructure/dataBases/container/index.ts has been added to centralize the registration of database models. Specifically, it registers the UserModel as a singleton within the shared kernel, ensuring that the repository layer can access the correct model implementation.
src/infrastructure/dataBases/container · high confidence
New API documentation schema for Result types
The system now generates OpenAPI documentation for the generic Result type, exposing fields for message, error, statusCode, and success status. A new ResultDescriber class defines the base schema, while a generic ResultTDescriber handles parameterized results by including a 'data' field that references the specific payload type. This change updates the API documentation strategy to better reflect the structure of API responses.
src/adapters/controllers/base/apiDoc · high confidence
New localized message system for error and user feedback
The application now uses a structured TypeScript-based localization system to manage user-facing messages. This change introduces a new enum for supported locales (English, Spanish, and Brazilian Portuguese) and replaces the previous JSON-based approach with dedicated TypeScript modules for each language. Users will see consistent, translatable error messages and feedback in their preferred language, with the system defaulting to English unless otherwise specified.
src/application/shared/locals/messages · medium confidence
Project configuration and tooling updates
The project has been updated with new configuration files including a Dockerfile, compose.yaml, and .dockerignore to support containerized builds and runs. ESLint configuration was migrated from the legacy .eslintrc.js to a modern eslint.config.mjs with TypeScript and Prettier plugins. The TypeScript configuration (tsconfig.json) was updated to target ES2022, enable strict mode, and adjust compiler options. Additionally, the Jest test configuration was updated to exclude specific directories from coverage and test runs, and the .gitignore file was updated to include pnpm-lock.yaml and other build artifacts.
(repo-wide) · high confidence
Refactored server initialization and error handling
The application's startup process has been refactored to use a new \AppWrapper\ and \HttpServer\ structure, replacing the previous direct Express.js server setup. Additionally, global uncaught exception and unhandled rejection handlers have been added to route errors through a centralized error handling middleware, ensuring consistent error logging and graceful shutdown behavior.
src · high confidence
Removed example service and controller for basic math operations
The example service and its interface have been removed, along with the corresponding controller that handled basic math operations like summing two numbers or an array of numbers. This eliminates the previous implementation that relied on the ExampleService for these specific endpoints.
src/controllers, src/services · high confidence
Users controller container now registers use cases via the shared kernel
The users controller adapter now explicitly registers the RegisterUserUseCase and GetUserUseCase with the application's dependency injection container. This change wires the use cases to their required dependencies (LogProvider, WorkerProvider, and UserRepository) through the shared kernel, ensuring that each request gets a fresh, scoped instance of these use cases.
src/adapters/controllers/users/container · high confidence
Test coverage
Added unit tests for the Logout use case; Removed example service tests.
Dependencies
Upgrade to Node 20+ and modernize dependencies
The project now requires Node.js 20 or higher and npm 10 or higher. The dependency list has been significantly modernized: Express has been upgraded to v5, and many older libraries (such as Koa, moment, and various @types packages) have been removed or replaced with newer alternatives like helmet, jsonwebtoken, and swagger-ui-express. This update improves security, performance, and compatibility with modern JavaScript features.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 58 → 54 (-3.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 82 → 85 (+2.3)
- Architecture 87 → 75 (-11.7)
- Maturity 68 → 65 (-2.8)
- Readiness 35 → 33 (-1.3)
- Security 87 → 86 (-1.5)
Resolved (22)
- Change coupling: Auth.controller.ts ↔ Status.controller.ts (src/adapters/controllers/auth/Auth.controller.ts)
- Change coupling: Auth.controller.ts ↔ Users.controller.ts (src/adapters/controllers/auth/Auth.controller.ts)
- Change coupling: Health.provider.ts ↔ AppWrapper.ts (src/adapters/providers/health/Health.provider.ts)
- Change coupling: Health.provider.ts ↔ index.ts (src/adapters/providers/health/Health.provider.ts)
- Change coupling: Status.controller.ts ↔ Health.provider.ts (src/adapters/controllers/status/Status.controller.ts)
- Change coupling: Status.controller.ts ↔ Users.controller.ts (src/adapters/controllers/status/Status.controller.ts)
- Change coupling: index.ts ↔ index.ts (src/adapters/controllers/auth/container/index.ts)
- Change coupling: index.ts ↔ index.ts (src/adapters/controllers/auth/container/index.ts)
- Change coupling: index.ts ↔ index.ts (src/adapters/controllers/status/container/index.ts)
- Change coupling: index.ts ↔ index.ts (src/application/modules/auth/useCases/login/index.ts)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Medium IaC: CKV_DOCKER_3 (Dockerfile)
- Medium IaC: CKV_DOCKER_3 (tsk-gateway/Dockerfile)
- Medium IaC: CKV_DOCKER_4 (tsk-gateway/Dockerfile)
- No exposed public API
- Scanner failed to run — not a clean result
- Secret: generic-api-key (tsk-gateway/envs/.env_security_context)
- Secret: generic-api-key (tsk-gateway/envs/.env_security_context)
- Secret: generic-api-key (tsk-gateway/envs/.env_users_context)
- …and 2 more
New (23)
- Change coupling: User.repository.ts ↔ index.ts (src/adapters/repositories/user/User.repository.ts)
- Change coupling: Worker.provider.ts ↔ index.ts (src/adapters/providers/worker/Worker.provider.ts)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
- High IaC: WD-COMPOSE-0002 (tsk-gateway/compose.yml)
- High IaC: WD-COMPOSE-0002 (tsk-gateway/compose.yml)
- High IaC: WD-COMPOSE-0002 (tsk-gateway/compose.yml)
- High secret: WD-SECRET-0002 (src/infrastructure/dataBases/nodeTsKeleton/db.mock.json)
- HttpClient.formData (cognitive 23) (src/infrastructure/httpClient/HttpClient.ts)
- HttpClient.formData (cyclomatic 20) (src/infrastructure/httpClient/HttpClient.ts)
- Leaked secret: high-entropy-secret (src/infrastructure/dataBases/nodeTsKeleton/db.mock.json)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (tsk-gateway/Dockerfile)
- MethodTooLong: HttpClient.formData (src/infrastructure/httpClient/HttpClient.ts)
- No ADRs found
- Scanner failed to run — not a clean result
- Scanner failed to run — not a clean result
- Secret: generic-api-key (tsk-gateway/envs/.env_security_context)
- Secret: generic-api-key (tsk-gateway/envs/.env_security_context)
- Secret: generic-api-key (tsk-gateway/envs/.env_users_context)
- …and 3 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
medevorg/nodetskeleton was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 5021642b75ed3479247cb9f529726d54f2b61260 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.