meysamhadeli/booking-microservices
58.2
Weak · 21 September 2026
11.2k
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is a .NET 10-based microservices platform for managing flight bookings, comprising distinct services for Identity, Flight, Passenger, and Booking operations. It employs a CQRS architecture with vertical slices, utilizing PostgreSQL for write models and MongoDB for read models, while coordinating state changes via RabbitMQ and EventStoreDB. The infrastructure supports distributed communication through an API Gateway and gRPC, ensuring reliability with patterns like the outbox and standardized resilience policies.
How it got here
2022 — Initial microservices scaffolding and infrastructure
75 changes.
The project established a .NET 10-based microservices architecture, initializing core building blocks for event sourcing, CQRS, and distributed transactions. Key services including Flight, Booking, Identity, and Passenger were scaffolded with minimal APIs, PostgreSQL write models, and MongoDB read models. The period concluded with the implementation of integration and end-to-end tests using Dockerized infrastructure to validate the new system foundations.
2023 — Domain modeling and vertical slice architecture
28 changes.
This period focused on implementing core domain logic and architectural patterns across the Flight, Identity, and Passenger services. Key work included introducing vertical slice architecture, dual persistence with SQL and MongoDB, and strongly-typed value objects with strict validation. Additionally, foundational features such as user registration, flight management, and seat reservation were established alongside comprehensive testing infrastructure.
2024–2026 — Observability and development infrastructure
6 changes.
This period focused on enhancing developer experience and system observability by introducing .NET Aspire for local orchestration and OpenTelemetry for comprehensive distributed tracing. The team also standardized service configurations with ServiceDefaults and enforced code quality through Husky hooks, while adding PactNet contract tests to ensure API reliability.
Features
Add FlightDto record for flight data transfer
A new FlightDto record has been introduced in the Flights/Dtos folder to serve as a data transfer object for flight information. This record encapsulates key flight attributes including identifiers (Id, FlightNumber, AircraftId, DepartureAirportId, ArriveAirportId), temporal data (DepartureDate, ArriveDate, FlightDate), operational details (DurationMinutes, Price), and current status (Status), providing a structured model for handling flight data within the service.
src/Services/Flight/src/Flight/Flights/Dtos · high confidence
Add OpenAPI documentation and UI support
The OpenApi building block now includes extensions to register and configure OpenAPI document generation, Swagger UI, and Scalar API reference UI. It automatically adds Bearer (JWT) and API Key security schemes to the generated OpenAPI documents, ensuring that API consumers can see and use the correct authentication methods in the interactive documentation.
src/BuildingBlocks/OpenApi · high confidence
Add RegisterIdentityUserException class
A new RegisterIdentityUserException class has been added to the Identity service's exception handling structure. This specific exception inherits from the base AppException and is designed to handle errors specifically related to the registration of identity users, providing a dedicated error type for this scenario within the vertical slice architecture.
src/Services/Identity/src/Identity/Identity/Exceptions · high confidence
Add centralized health check infrastructure with UI and multi-backend support
The application now includes a built-in health check system that monitors the status of PostgreSQL, RabbitMQ, MongoDB, and EventStore. This feature exposes standard endpoints at /health and /alive, and provides a dedicated dashboard at /health-ui for visualizing health status. The system is configurable via HealthOptions and integrates with the existing dependency injection and configuration pipelines.
src/BuildingBlocks/HealthCheck · high confidence
Add domain event contracts for flight, identity, passenger, and reservation domains
New integration event contracts have been introduced to define the messages exchanged via the event bus. These include flight lifecycle events (created, updated, deleted), aircraft and airport creation, seat management (created, reserved), user identity events (created), passenger registration and creation, and booking creation. These records implement the IIntegrationEvent interface, enabling downstream services to react to these domain changes.
src/BuildingBlocks/Contracts · high confidence
Add flight update capability with dual persistence support
Users can now update existing flight details via a new PUT endpoint at /flight. The implementation supports both SQL and MongoDB backends: the primary handler updates the flight entity in the relational database and publishes a domain event, while a separate command handler synchronizes the read model in MongoDB to ensure consistency across data stores.
src/Services/Flight/src/Flight/Flights/Features/UpdatingFlight · high confidence
Added FluentValidation pipeline behavior and helper extensions
The validation building block now includes a MediatR pipeline behavior (ValidationBehavior) that automatically resolves and executes FluentValidation validators for incoming requests, throwing a ValidationException on failure. This is supported by new helper extensions for handling validation asynchronously, a model for serializing validation results, and a class representing individual validation errors.
src/BuildingBlocks/Validation · high confidence
Added PassengerDto record for passenger data transfer
A new PassengerDto record has been introduced in the passenger service's DTO layer to structure passenger data for transfer. This record encapsulates the passenger's unique identifier (Guid), name, passport number, passenger type, and age, providing a standardized contract for exposing passenger details.
src/Services/Passenger/src/Passenger/Passengers/Dtos · high confidence
Added booking microservices architecture diagram
A new diagram illustrating the booking microservices architecture has been added to the assets folder. The visual depicts the system's components, including an API layer, an Identity Service, and an Outbox Processor, along with their interactions and connections to Azure App Services and Kubernetes.
assets · high confidence
Added passenger validation exception types
The Passenger service now includes specific exception classes for validation errors, allowing the system to return precise error messages for invalid passenger data. New exceptions include InvalidAgeException for null or negative ages, InvalidNameException for empty or whitespace names, InvalidPassportNumberException for empty or whitespace passport numbers, PassengerAlreadyExist for registration attempts on existing passengers, and PassengerNotFoundException for missing passenger records. These exceptions inherit from base error types in the BuildingBlocks.Exception namespace to ensure consistent error handling.
src/Services/Passenger/src/Passenger/Passengers/Exceptions · high confidence
Added utility classes for synchronization context management, service location, and assembly type resolution
This change introduces three new utility classes in the BuildingBlocks.Utils namespace. NoSynchronizationContextScope provides a disposable scope to temporarily suppress the synchronization context, which is useful for avoiding deadlocks in asynchronous code. ServiceLocator acts as a static accessor to the application's service provider, allowing services to be resolved by type or generic type parameter outside of constructor injection. TypeProvider offers helper methods to resolve types from any referencing assembly, find types in the current application domain, retrieve all referenced assemblies, and load assemblies marked with ApplicationPartAttribute, facilitating dynamic type discovery and assembly loading.
src/BuildingBlocks/Utils · high confidence
Automated kubectl installation for Gitpod environments
A new setup script, setup\_kubectl\_gitpod.sh, has been added to the scripts directory to streamline the configuration of Gitpod workspaces. This script automatically downloads the latest stable version of the kubectl binary for Linux (amd64), makes it executable, and installs it to /usr/local/bin, ensuring that Kubernetes command-line tools are available immediately upon workspace initialization.
scripts · high confidence
Flight API initializes with minimal API structure and multi-environment configuration
The Flight API service is now bootstrapped using a minimal API pattern, registering infrastructure and endpoints via extension methods in Program.cs. Configuration is provided through environment-specific appsettings files (Development, Docker, Test, and default), establishing connections for PostgreSQL, MongoDB, RabbitMQ, and JWT authentication, while also enabling OpenTelemetry observability and health checks.
src/Services/Flight/src/Flight.Api · high confidence
Flight service data layer initialized with PostgreSQL and MongoDB
The data access layer for the Flight service has been established, introducing a write model backed by PostgreSQL (via Npgsql) and a read model backed by MongoDB. This includes the creation of the FlightDbContext for managing flight, aircraft, airport, and seat entities, alongside a FlightReadDbContext for querying denormalized read models. A DesignTimeDbContextFactory is also provided to support EF Core tooling and migrations against a local PostgreSQL instance.
src/Services/Flight/src/Flight/Data · high confidence
Flight service now seeds initial reference data into both database and read store
The Flight service now automatically populates its database with initial reference data (airports, aircraft, flights, and seats) upon startup. This seed process ensures that the primary database is populated first, and then synchronizes the data into the MongoDB read store using Mapster for mapping, providing a consistent initial state for both read and write models without requiring manual data entry.
src/Services/Flight/src/Flight/Data/Seed · high confidence
Identity service database layer initialized with PostgreSQL and optimistic concurrency
The Identity service's data access layer has been established with a new Entity Framework Core context (IdentityContext) configured to use PostgreSQL via Npgsql. This implementation introduces optimistic concurrency control by automatically incrementing a version field on entities implementing IVersion during save operations, and includes design-time support for migrations. The context also handles domain event retrieval and basic transaction management.
src/Services/Identity/src/Identity/Data · high confidence
Initial API Gateway setup with Yarp reverse proxy
The API Gateway service has been initialized with a new entry point that configures Yarp as a reverse proxy. It defines routing rules to forward requests for identity, flight, passenger, and booking services, stripping the respective path prefixes before forwarding. Configuration files are provided for local development and Docker environments, specifying the target backend addresses for each service.
src/ApiGateway/src · high confidence
Initial Booking service scaffolding with event mapping and projections
The Booking service is introduced with core infrastructure components: an assembly configuration exposing internals to test projects, a BookingEventMapper that translates domain events (such as BookingCreated) into integration events, and a BookingProjection that processes these events to update the MongoDB read model via BookingReadDbContext. A placeholder BookingRoot class is also added to define the service namespace.
src/Services/Booking/src/Booking · high confidence
Initial Identity Server configuration and resource owner password validation
The identity service now includes explicit configuration for Duende Identity Server, defining identity resources (OpenID, Profile, Email), API scopes and resources for Flight, Passenger, Booking, and Identity APIs, and a default client setup using the Resource Owner Password Credentials grant type with a 1-hour token lifetime. Additionally, a custom user validator is introduced to handle username/password authentication against the ASP.NET Core Identity store, issuing JWT tokens containing the user's name identifier and name upon successful login.
src/Services/Identity/src/Identity/Configurations · high confidence
Initial booking domain model and reservation creation endpoint
The Booking service now exposes a new API endpoint to create flight reservations. This change introduces the core domain model, including the Booking aggregate, value objects for Trip and PassengerInfo, and specific validation exceptions (e.g., InvalidFlightDateException, BookingAlreadyExistException). It also adds the necessary infrastructure for this feature, such as the CreateBooking command handler, DTOs, Mapster mappings, and a MongoDB read model (BookingReadModel) with its corresponding DbContext.
src/Services/Booking/src/Booking/Booking · high confidence
Initial identity data seeding for default roles and users
The Identity service now automatically seeds default administrative and standard user accounts along with their corresponding roles upon startup. This is achieved through the new IdentityDataSeeder and InitialData classes, which create the 'Admin' and 'User' roles and provision two default users ('samh' and 'samh2') if they do not already exist. The seeder also integrates with the event bus to publish a UserCreated event for each newly provisioned user, ensuring downstream services are notified of the initial account creation.
src/Services/Identity/src/Identity/Data/Seed · high confidence
Initial implementation of seat management features and mappings
This change introduces the foundational structure for seat management within the Flight service. It adds a SeatDto to represent seat data and establishes SeatMappings using Mapster to handle conversions between domain models (Seat), request DTOs (CreateSeatRequestDto, ReserveSeatRequestDto), and read models (SeatReadModel). The mappings also integrate NewId for generating unique identifiers during the conversion process, supporting the creation and reservation of seats.
src/Services/Flight/src/Flight/Seats/Features · high confidence
Initial project scaffolding with .NET 10 and standardized build configuration
The repository has been initialized with a new solution structure targeting .NET 10.0, enforced via a global Directory.Build.props file that also enables implicit usings, nullable reference types, and a suite of Roslyn analyzers (StyleCop, Meziantou, Roslynator, etc.). A global.json file pins the SDK to version 10.0.103. The commit also introduces standard development infrastructure files including .editorconfig for C\# coding conventions, .dockerignore and .gitignore for build artifact exclusion, .gitattributes for line-ending normalization, and CONTRIBUTION.md outlining the use of Conventional Commits.
(repo-wide) · high confidence
Initial release of the Identity API service
The Identity API service is introduced as a new component within the system, providing core identity management capabilities. It is built on a minimal API architecture, utilizing a shared 'BuildingBlocks' infrastructure for endpoint mapping and service configuration. The service is configured to use PostgreSQL for data persistence and RabbitMQ for messaging, with specific connection settings defined for development, Docker, and test environments. It also includes initial observability support via OpenTelemetry and health check options, establishing the foundational wiring for identity-related operations.
src/Services/Identity/src/Identity.Api, src/Services/Passenger/src/Passenger.Api · high confidence
Introduce .NET Aspire AppHost for local development orchestration
The AppHost project now uses .NET Aspire to define and orchestrate the local development environment. This includes configuring infrastructure services such as PostgreSQL, MongoDB, Redis, EventStore, RabbitMQ, and observability tools (Jaeger, Zipkin, OpenTelemetry Collector, Prometheus) via the Aspire builder API. The host also supports Docker Compose deployment and exposes the Aspire dashboard on localhost:18888, with unsecured transport allowed for local development.
src/Aspire/src/AppHost · high confidence
Introduce EF Core building blocks with caching, optimistic concurrency, and distributed transactions
The EF Core building block now includes a MediatR caching pipeline (CachingBehavior and InvalidateCachingBehavior) that automatically caches and invalidates responses based on request interfaces, and an EfTxBehavior that wraps requests in a distributed transaction scope with automatic domain event dispatching and retry logic. The base DbContext (AppDbContextBase) now enforces optimistic concurrency via a Version column, handles DbUpdateConcurrencyException by refreshing database values, and applies soft-delete filters and snake\_case naming conventions for PostgreSQL. Database registration defaults to Npgsql with legacy timestamp behavior enabled, and design-time factories are standardized for SQL Server.
src/BuildingBlocks/EFCore · high confidence
Introduce EventStoreDB building block with event sourcing and projection support
This change adds a new EventStoreDB integration to the BuildingBlocks library, providing the infrastructure for event-sourced aggregates and event-driven projections. It includes an \EventStoreDBRepository\ for persisting and retrieving aggregates via stream operations, a \BackgroundWorker\-hosted subscription mechanism to consume all events from the store, and a \ProjectionPublisher\ to dispatch events to registered \IProjectionProcessor\ implementations. The package also handles serialization via JSON.NET with non-default constructor support, manages subscription checkpoints (with both in-memory and EventStoreDB-backed repositories), and offers DI extension methods to wire these components into the application.
src/BuildingBlocks/EventStoreDB · high confidence
Introduce Flight domain model and read model
The Flight service now includes a new Flight aggregate root and a corresponding FlightReadModel. The Flight aggregate manages flight lifecycle operations (create, update, delete) and emits domain events, while the read model provides a simplified structure for querying flight data.
src/Services/Flight/src/Flight/Flights/Models · high confidence
Introduce MongoDB persistence layer with repository and unit-of-work patterns
This change adds a new MongoDB integration block that provides a structured data-access layer for applications. It introduces a \MongoDbContext\ that manages database connections, registers MongoDB serialization conventions (including support for immutable POCOs), and handles transactional operations via \SaveChangesAsync\. The block exposes standard repository and unit-of-work interfaces (\IMongoRepository\, \IMongoUnitOfWork\) along with concrete implementations (\MongoRepository\, \MongoUnitOfWork\) to abstract CRUD operations. Additionally, it provides DI extension methods in \Extensions.cs\ to simplify registering the MongoDB context and options, including support for Aspire connection strings.
src/BuildingBlocks/Mongo · high confidence
Introduce Passenger domain and read models
The Passenger service now includes the core Passenger aggregate root and a corresponding PassengerReadModel. The domain model defines passenger attributes such as name, passport number, type, and age, and exposes methods to complete registration or create a new passenger, each emitting specific domain events. The read model provides a flat structure with required fields for ID, passenger ID, passport number, name, type, age, and deletion status, supporting efficient querying of passenger data.
src/Services/Passenger/src/Passenger/Passengers/Models · high confidence
Introduce Seat domain model and read model
Added the Seat aggregate root and a corresponding SeatReadModel to the Seats feature area. The Seat model defines core properties (seat number, type, class, flight association) and enforces mandatory initialization via the 'required' keyword on the read model, while the aggregate handles creation and reservation logic with associated domain events.
src/Services/Flight/src/Flight/Seats/Models · high confidence
Introduce core domain model and pagination infrastructure
The core building block now includes foundational domain model classes (Entity, Aggregate) and interfaces (IEntity, IAggregate, IVersion) that support optimistic concurrency via a Version property and domain event management. Additionally, a new pagination subsystem has been added, featuring interfaces for page requests and queries, a PageList result type, and extension methods to integrate with the Sieve library for filtering, sorting, and paging entity collections.
src/BuildingBlocks/Core/Model · high confidence
Introduce minimal API support with API versioning and endpoint scanning
The web building block now supports ASP.NET Core minimal APIs alongside traditional controllers. It includes an \ApiVersioningExtensions\ setup that enables API versioning via URL segments and headers (defaulting to v1.0), a \BaseController\ for MVC apps, and a new \IMinimalEndpoint\ interface with \MinimalApiExtensions\ to automatically discover and map endpoint implementations from specified assemblies. Additional utilities include correlation ID tracking, configuration binding helpers, and service collection replacement methods for testing.
src/BuildingBlocks/Web · high confidence
Introduction of Aircraft domain and read models
The Flight service now includes core data structures for managing aircraft information. The domain model (Aircraft) defines the entity with properties for name, model, and manufacturing year, utilizing specific value objects and generating domain events upon creation. Additionally, a dedicated read model (AircraftReadModel) has been added to support efficient querying of aircraft data, including fields for ID, name, model, manufacturing year, and deletion status.
src/Services/Flight/src/Flight/Aircrafts/Models · high confidence
Introduction of Airport domain and read models
The Flight service now includes core data structures for managing airport information. The domain model (Airport) defines the entity's identity, name, address, and code, and handles the creation logic along with the associated domain event. Additionally, a read model (AirportReadModel) has been added to support efficient querying of airport details, including deletion status.
src/Services/Flight/src/Flight/Airports/Models · high confidence
Introduction of DTOs for Aircraft and Airport entities
New Data Transfer Objects (DTOs) have been added to define the shape of data for Aircraft and Airport entities. The AircraftDto includes fields for Id, Name, Model, and ManufacturingYear, while the AirportDto includes Id, Name, Address, and Code. These records serve as the structured data contracts for these specific domains within the flight service.
src/Services/Flight/src/Flight/Aircrafts/Dtos, src/Services/Flight/src/Flight/Airports/Dtos · high confidence
Introduction of standard API scope constants
A new Constants class has been added to the Identity service, defining standard OAuth2/OIDC scope strings for internal APIs. This includes specific scopes for roles, flight, passenger, booking, and identity APIs, providing a centralized source of truth for authorization requirements across the system.
src/Services/Identity/src/Identity/Identity/Constants · high confidence
Introduction of strongly-typed flight value objects
The Flight service now uses dedicated value objects (ArriveDate, DepartureDate, DurationMinutes, FlightDate, FlightId, FlightNumber, and Price) to represent core flight data. These types enforce validation rules—such as rejecting null dates, empty flight numbers, or negative prices and durations—at creation time via static factory methods, replacing the previous practice of passing raw primitive types directly.
src/Services/Flight/src/Flight/Flights/ValueObjects · high confidence
Introduction of strongly-typed seat value objects
Added new value objects for SeatId and SeatNumber to enforce type safety and validation within the flight booking domain. SeatId now validates that the underlying GUID is not empty, while SeatNumber ensures the value is not null or whitespace, throwing specific exceptions for invalid inputs. These objects replace raw Guid and string types in seat-related logic, providing clearer intent and built-in validation at the point of creation.
src/Services/Flight/src/Flight/Seats/ValueObjects · high confidence
New JWT authentication and HTTP header forwarding components
The \src/BuildingBlocks/Jwt\ package now includes \AuthHeaderHandler\ and \JwtExtensions\. \AuthHeaderHandler\ is a delegating HTTP handler that forwards the current request's Authorization header to downstream services, enabling seamless token propagation in client-side HTTP calls. \JwtExtensions\ configures the application's authentication pipeline using \Duende.IdentityServer\ and \JwtBearer\ settings, reducing the default clock skew to 2 seconds, mapping claims to standard user/role properties, and defining authorization policies for API scopes and specific roles (Admin, User).
src/BuildingBlocks/Jwt · high confidence
New OpenTelemetry observability building block for CQRS applications
This change introduces a new \OpenTelemetryCollector\ building block that provides comprehensive distributed tracing, metrics, and logging for applications using a CQRS pattern. It includes an \ObservabilityPipelineBehavior\ for MediatR that automatically wraps command and query handlers in OpenTelemetry activities, capturing execution duration, success/failure status, and detailed exception information. The module exposes specific metrics for command and query handlers (active count, total executions, success/failure counts, and duration histograms) and integrates with standard .NET instrumentation (ASP.NET Core, HttpClient, Entity Framework Core, Npgsql) via a centralized \Extensions\ class. It supports multiple telemetry exporters (OTLP, Prometheus, Jaeger, Zipkin, Grafana) and allows configuration of service identity and instrumentation settings through \ObservabilityOptions\.
src/BuildingBlocks/OpenTelemetryCollector · high confidence
New ServiceDefaults extension methods for health, observability, and resilience
A new \ServiceDefaults\ library has been introduced, providing \AddServiceDefaults\ and \UseServiceDefaults\ extension methods to standardize service configuration. These methods automatically register custom health checks, observability collectors, and service discovery. Additionally, they configure HttpClient defaults with standard resilience handlers (including circuit breaking and retries) and enable service discovery by default for all outgoing HTTP requests.
src/Aspire/src/ServiceDefaults · high confidence
New endpoints to complete passenger registration and retrieve passenger details
This change introduces two new API endpoints for the Passenger service. The POST /passenger/complete-registration endpoint allows users to finalize a passenger's registration by providing their passport number, type, and age; it validates the input, updates the passenger record in the database, and returns the updated passenger details. Additionally, the GET /passenger/{id} endpoint enables users to retrieve a specific passenger's information by their unique ID, returning the passenger details if found. Both endpoints are versioned at V1 and require authorization.
src/Services/Passenger/src/Passenger/Passengers/Features/CompletingRegisterPassenger · high confidence
New gRPC service contracts for flight and passenger operations
The Booking service now exposes new gRPC interfaces for managing flight and passenger data. Users can retrieve flight details, check available seats, and reserve seats via the FlightGrpcService, while passenger information can be fetched via the PassengerGrpcService. These contracts define the request and response structures, including flight status, seat types, and passenger details, enabling clients to interact with these specific booking capabilities.
src/Services/Booking/src/Booking/GrpcClient · high confidence
New passenger registration consumer and domain event
A new consumer handler (RegisterNewUserHandler) has been added to process UserCreated messages, creating a Passenger record in the database if one does not already exist for the given passport number, and subsequently publishing a PassengerCreatedDomainEvent. A corresponding domain event record (PassengerCreatedDomainEvent) has also been introduced to represent this state change.
src/Services/Passenger/src/Passenger/Identity · high confidence
New seat reservation capability for flights
Users can now reserve a specific seat on a flight via a new V1 API endpoint (POST /flight/reserve-seat). The feature validates the flight and seat identifiers, updates the seat status in the primary database, and synchronizes the read model to reflect the reservation.
src/Services/Flight/src/Flight/Seats/Features/ReservingSeat · high confidence
New user registration endpoint with distributed event publishing
A new API endpoint has been added at /identity/register-user (V1) that allows users to register by providing their first name, last name, username, email, password, and passport number. The feature validates that passwords match and all fields are present, creates the user account with the 'User' role, and publishes a 'UserCreated' event to the distributed event bus upon successful registration.
src/Services/Identity/src/Identity/Identity/Features/RegisteringNewUser · high confidence
Structured error handling with Problem Details and gRPC interception
The application now provides a standardized, structured error response mechanism. For HTTP APIs, the new \UseCustomProblemDetails\ middleware intercepts exceptions (such as \ValidationException\, \NotFoundException\, and \ConflictException\) and returns responses in the RFC 7807 Problem Details format, including a custom error code and exception details in development mode. For gRPC services, the \GrpcExceptionInterceptor\ ensures that server-side exceptions are consistently translated into \RpcException\ responses, preventing unhandled crashes and providing uniform error signaling to clients.
src/BuildingBlocks/Exception · high confidence
Behavioural changes
Add passenger entity configuration with value object mapping and concurrency control
The passenger data model is now explicitly configured in Entity Framework Core, mapping the Passenger entity to its table and defining primary key behavior. Value objects for Name, PassportNumber, and Age are persisted as owned types with specific column names and length constraints. The configuration also enforces optimistic concurrency using a Version token and stores the PassengerType enum as a string with a default value of Unknown.
src/Services/Passenger/src/Passenger/Data/Configurations · high confidence
Added airport mapping configuration for command-to-read-model conversion
A new mapping configuration file has been introduced to define how airport-related commands and DTOs are converted into read models. Specifically, it maps the CreateAirportMongo command and Airport entity to the AirportReadModel, utilizing NewId.NextGuid() for ID generation, and maps the CreateAirportRequestDto to the CreateAirport command using Mapster conventions.
src/Services/Flight/src/Flight/Airports/Features · high confidence
Added specific validation exceptions for aircraft data
The Flight service now includes dedicated exception classes for aircraft validation errors, including AircraftAlreadyExistException, InvalidAircraftIdException, InvalidManufacturingYearException, InvalidModelException, and InvalidNameException. These exceptions provide specific error messages for invalid aircraft IDs, manufacturing years (must be greater than 1900), and empty or whitespace-only model and name fields, enabling more precise error handling for aircraft-related data validation.
src/Services/Flight/src/Flight/Aircrafts/Exceptions · high confidence
Aircraft creation mapping uses NewId for read model generation
The AircraftMappings configuration now explicitly maps incoming aircraft creation requests to the AircraftReadModel, utilizing the NewId library to generate unique identifiers for the read model instances. This ensures that when a new aircraft is created, the corresponding read model is populated with a distinct ID generated via NewId.NextGuid(), aligning the data transfer with the distributed ID generation strategy.
src/Services/Flight/src/Flight/Aircrafts/Features · high confidence
Aircraft value objects now validate input via static factory methods
The Aircraft value objects (AircraftId, ManufacturingYear, Model, Name) now enforce their invariants through static \Of\ factory methods rather than constructor validation. This change ensures that invalid aircraft data—such as empty GUIDs, manufacturing years before 1900, or null/whitespace model and name strings—is rejected immediately with specific exceptions at the point of creation, improving data integrity for aircraft-related operations.
src/Services/Flight/src/Flight/Aircrafts/ValueObjects · high confidence
Airport value objects now enforce validation via static factory methods
The Airport domain now uses dedicated value objects (Address, AirportId, Code, Name) that validate input data through static \Of\ factory methods rather than constructors. This ensures that invalid states (such as empty strings or empty GUIDs) are rejected immediately upon creation, throwing specific exceptions like \InvalidAddressException\ or \InvalidAirportIdException\. These objects also support implicit conversion to their underlying primitive types (string or Guid) for easier usage in code.
src/Services/Flight/src/Flight/Airports/ValueObjects · high confidence
Booking API adopts minimal API architecture with OpenTelemetry observability
The Booking API entry point has been refactored to use the minimal API pattern, replacing the previous startup class with a concise Program.cs that registers infrastructure and maps endpoints. Configuration is now structured across environment-specific appsettings files, introducing dedicated sections for observability (OpenTelemetry, Zipkin, Jaeger, Prometheus) and resilience policies (retry and circuit breaker). The service is configured to connect to EventStore, MongoDB, and RabbitMQ, with gRPC addresses defined for downstream Flight and Passenger services.
src/Services/Booking/src/Booking.Api · high confidence
Centralized mapping configuration for flight features
The flight feature handlers now use a centralized Mapster configuration class to define how domain models, DTOs, and read models are converted. This change standardizes the mapping logic for creating, updating, and deleting flights, ensuring consistent data transformation across the vertical slice architecture.
src/Services/Flight/src/Flight/Flights/Features · high confidence
Centralized mapping configuration for user registration
The identity service now uses a centralized mapping class to handle conversions between Data Transfer Objects and internal domain models. Specifically, a new mapping is defined to convert the RegisterNewUserRequestDto into the RegisterNewUser command, ensuring consistent data transformation during the user registration process.
src/Services/Identity/src/Identity/Identity/Features · high confidence
Centralized passenger data mapping configuration
The passenger feature now uses a centralized Mapster configuration class to handle object mapping. This change consolidates the mapping logic for converting between the registration command, read models, and DTOs, ensuring consistent data transformation when processing passenger registration and retrieval operations.
src/Services/Passenger/src/Passenger/Passengers/Features · high confidence
Consolidated infrastructure and MediatR configuration for the Passenger service
The Passenger service now uses a unified \InfrastructureExtensions\ class to register its core dependencies, including Entity Framework Core and MongoDB contexts, JWT authentication, gRPC services, and the new Wolverine message broker integration. This change also introduces a dedicated \MediatRExtensions\ file that configures MediatR with validation, logging, and transaction pipeline behaviors, replacing previous scattered setup logic.
src/Services/Passenger/src/Passenger/Extensions · high confidence
Consolidated infrastructure and MediatR pipeline configuration
The Flight service now centralizes its startup logic in new InfrastructureExtensions and MediatRExtensions classes. InfrastructureExtensions registers core dependencies including EF Core and MongoDB contexts, JWT authentication, gRPC services, EasyCaching, and Wolverine transport, while also applying the built-in ASP.NET Core ProblemDetails middleware. MediatRExtensions configures MediatR with a standardized pipeline of behaviors for validation, logging, database transactions, and caching, ensuring consistent request handling across the service.
src/Services/Flight/src/Flight/Extensions · high confidence
Enforce commit message and code formatting via Husky
Husky is now configured to automatically enforce development standards before changes are committed. The pre-commit hook runs formatting scripts to ensure code consistency, while the commit-msg hook validates that commit messages adhere to the defined conventional commit style.
.husky · high confidence
Flight and Passenger services migrate gRPC implementation from MagicOnion to gRPC-AspNetCore
The gRPC server implementations for the Flight and Passenger services have been rewritten to use the standard gRPC-AspNetCore framework instead of the previous MagicOnion library. This change introduces new Protocol Buffer definitions (flight.proto and passenger.proto) and corresponding service classes that leverage MediatR for command/query handling and Mapster for object mapping, aligning the transport layer with standard .NET gRPC practices.
src/Services/Flight/src/Flight/GrpcServer, src/Services/Passenger/src/Passenger/GrpcServer · high confidence
Flight creation now supports dual persistence via SQL and MongoDB
The flight creation feature has been restructured to support a dual-persistence model. The primary write path (CreateFlight) now persists flight data to a SQL database using Entity Framework Core, while a new background handler (CreateFlightMongo) automatically synchronizes the created flight to a MongoDB read store. This change introduces a new result model for better command handling structure and ensures that the read-side database is updated immediately upon successful flight creation, supporting the vertical slice architecture.
src/Services/Flight/src/Flight/Flights/Features/CreatingFlight · high confidence
Flight service database schema migrated to PostgreSQL
The Flight service's initial database migration has been updated to target PostgreSQL instead of SQL Server. This change introduces new migration files (initial.Designer.cs, initial.cs, and FlightDbContextModelSnapshot.cs) that define the schema for Aircraft, Airport, Flight, and Seat entities using PostgreSQL-specific types (e.g., uuid, timestamp with time zone, text) and conventions (e.g., snake\_case column names, identity columns). Users deploying this service will now require a PostgreSQL database instance, and existing SQL Server-based deployments will need to migrate their data or re-initialize the schema.
src/Services/Flight/src/Flight/Data/Migrations · high confidence
Identity models now enforce optimistic concurrency and mandatory user properties
The identity domain models (User, Role, and their associated claims, logins, roles, and tokens) have been updated to support optimistic concurrency control by implementing the IVersion interface with a long Version property. Additionally, the User model now requires FirstName, LastName, and PassPortNumber to be set at initialization, ensuring these fields are mandatory for new user records.
src/Services/Identity/src/Identity/Identity/Models · high confidence
Identity service database schema migrated to PostgreSQL with optimistic concurrency
The Identity service's initial database migration has been updated to target PostgreSQL (using Npgsql) instead of SQL Server, introducing specific column types such as 'uuid' and 'timestamp with time zone'. Additionally, optimistic concurrency control is now enforced on the core identity entities (Users, Roles, and RoleClaims) via 'ConcurrencyStamp' and 'Version' columns, ensuring that concurrent updates to these records are detected and prevented.
src/Services/Identity/src/Identity/Data/Migrations · high confidence
Identity service infrastructure and identity server configuration
The identity service now initializes its core infrastructure and authentication stack via new extension methods. It configures ASP.NET Core Identity with Entity Framework Core for user and role storage, and integrates IdentityServer4 for token issuance, using in-memory definitions for clients, API resources, and scopes. The middleware pipeline enforces authentication and authorization, supports reverse-proxy scenarios via forwarded headers, and returns standard HTTP 401/403 status codes for unauthenticated or forbidden requests instead of redirects. Additionally, it registers MediatR with validation and logging pipeline behaviors, adds problem details, OpenAPI (in development), API versioning, Mapster mapping, and Wolverine-based messaging, while applying database migrations at startup.
src/Services/Identity/src/Identity/Extensions · high confidence
Initial database schema for Passenger service using PostgreSQL
The Passenger service now uses PostgreSQL as its write database, replacing the previous SQL Server implementation. This change introduces the initial EF Core migration (20230611213031\_initial) which defines the 'passenger' table. The schema includes columns for passenger identity (UUID), type, and soft-delete status, along with embedded value objects for Name, Age, and PassportNumber stored within the same table. It also tracks concurrency via a 'version' column and audit fields (created/modified timestamps and user IDs).
src/Services/Passenger/src/Passenger/Data/Migrations · high confidence
Initial project scaffolding and core infrastructure setup
This change introduces the foundational structure for the application, including a Mapster extension for dependency injection in the BuildingBlocks, configuration options for gRPC addresses in the Booking service, and internal visibility settings for testing in the Flight service. It also establishes the Flight service's event mapping logic, which translates domain events (such as flight creation, updates, and deletions) into integration events and internal commands for downstream processing.
src/BuildingBlocks/Mapster, src/Services/Booking/src/Booking/Configuration, src/Services/Flight/src/Flight · medium confidence
Introduce EF Core configurations for domain entities with value objects and concurrency control
The Flight service now defines explicit Entity Framework Core mapping configurations for its core domain entities: Aircraft, Airport, Flight, and Seat. These configurations map value objects (such as Name, Model, Address, FlightNumber, Price, and Dates) to specific database columns and enforce length constraints. Additionally, the mappings establish the relational structure between entities (e.g., Flight linking to Aircraft and Airports, Seat linking to Flight) and enable optimistic concurrency control via a Version token on each entity.
src/Services/Flight/src/Flight/Data/Configurations · high confidence
Introduce soft-delete and read-model synchronization for flights
The flight service now implements a soft-delete mechanism where deleting a flight marks it as deleted rather than removing it from the database, and synchronizes this state to the MongoDB read model to ensure queries for available flights correctly exclude deleted records.
src/Services/Flight/src/Flight/Flights/Features/DeletingFlight · high confidence
Introduce structured event types and message envelopes
The event handling foundation has been restructured to explicitly distinguish between domain events, integration events, and internal commands via a new EventType enum and corresponding interfaces (IDomainEvent, IIntegrationEvent, IInternalCommand). The base IEvent interface now automatically generates unique event IDs using NewId and tracks occurrence timestamps. Additionally, a new MessageEnvelope class has been added to wrap messages with optional headers, supporting both generic objects and Protobuf IMessage types, facilitating structured message passing within the system.
src/BuildingBlocks/Core/Event · high confidence
Introduce validated value objects for passenger attributes
The passenger service now enforces business rules at the data level by introducing dedicated value objects for Age, Name, PassengerId, and PassportNumber. Each object encapsulates its underlying type (int, string, or Guid) and validates input via a static \Of\ factory method, throwing specific exceptions for invalid states such as non-positive ages, empty names, or empty GUIDs. This ensures that invalid passenger data cannot be instantiated within the domain model.
src/Services/Passenger/src/Passenger/Passengers/ValueObjects · high confidence
Introduce versioned vertical slice for creating aircraft with dual persistence
The aircraft creation capability is now implemented as a versioned vertical slice (V1) that supports both SQL and MongoDB backends. The primary handler persists aircraft data to the SQL database, enforcing uniqueness by model and returning a structured result, while a separate MongoDB handler synchronizes the read model to the flight read database. This change introduces a new API endpoint at \/flight/aircraft\ for creating aircraft, utilizing MediatR for command handling and Mapster for DTO mapping, effectively splitting the write and read concerns within the same feature folder.
src/Services/Flight/src/Flight/Aircrafts/Features/CreatingAircraft · high confidence
Introduce vertical slice architecture with explicit result models for airport and seat creation
The airport and seat creation features have been restructured to follow a vertical slice architecture pattern. This change introduces dedicated result models (e.g., \CreateAirportResult\, \CreateSeatResult\) for command handlers to improve structure and clarity. The implementation now explicitly separates the write model (using EF Core via \FlightDbContext\) from the read model (using MongoDB via \FlightReadDbContext\), with specific handlers (\CreateAirportMongoHandler\, \CreateSeatMongoHandler\) managing the asynchronous update of the read-side data. Additionally, the codebase has been refactored to use \NewId\ for generating unique identifiers in distributed systems, replacing the previous \IdGen\ library.
src/Services/Flight/src/Flight/Airports/Features/CreatingAirport, src/Services/Flight/src/Flight/Seats/Features/CreatingSeat · high confidence
Introduces CQRS data access with PostgreSQL and MongoDB
The Passenger service now implements a CQRS data layer, separating write and read operations. The write side uses a new PassengerDbContext backed by PostgreSQL (Npgsql) with snake\_case naming conventions, replacing the previous SQL Server setup. The read side introduces a PassengerReadDbContext that queries a MongoDB collection for passenger read models. A DesignTimeDbContextFactory is also added to support EF Core tooling against the PostgreSQL instance.
src/Services/Passenger/src/Passenger/Data · high confidence
Introduces gRPC resilience and standardized infrastructure wiring
The Booking service now registers gRPC clients for Flight and Passenger with built-in resilience policies, including retry, circuit breaker, and timeout handling, ensuring more robust communication with downstream services. Additionally, the infrastructure layer has been consolidated into dedicated extension methods that configure core dependencies such as MediatR with validation and logging behaviors, MongoDB context, EventStoreDB, JWT authentication, and standardized problem details, providing a cleaner and more maintainable startup configuration.
src/Services/Booking/src/Booking/Extensions · high confidence
Introduction of domain-specific enumerations for flights, seats, and passengers
New strongly-typed enumerations have been added to define core domain concepts within the Flight and Passenger services. The Flight service now includes FlightStatus (Unknown, Flying, Delay, Canceled, Completed), SeatClass (Unknown, FirstClass, Business, Economy), and SeatType (Unknown, Window, Middle, Aisle). The Passenger service introduces PassengerType (Unknown, Male, Female, Baby). These changes replace implicit or untyped representations with explicit, validated values for status, seating, and passenger categories.
src/Services/Flight/src/Flight/Flights/Enums, src/Services/Flight/src/Flight/Seats/Enums, src/Services/Passenger/src/Passenger/Passengers/Enums · high confidence
Introduction of specific domain and application exceptions for the Passenger service
The Passenger service now includes dedicated exception classes to provide clearer error handling for specific validation and lookup scenarios. New domain exceptions cover invalid passenger data, including \InvalidAgeException\ for null or negative ages, \InvalidNameException\ for empty or whitespace-only names, \InvalidPassportNumberException\ for invalid passport entries, and \InvalidPassengerIdException\ for invalid GUIDs. Additionally, application-level exceptions \PassengerNotExist\ and \PassengerNotFoundException\ have been added to explicitly handle cases where a passenger is not found or has not registered, returning appropriate HTTP 404 status codes.
src/Services/Passenger/src/Passenger/Exceptions · high confidence
Optimistic concurrency control added to Identity entities
The Identity service now enforces optimistic concurrency for User, Role, and their associated claim, login, role, and token entities. This is achieved by configuring the Version property as a concurrency token in the Entity Framework Core model configurations, ensuring that concurrent updates to these records are detected and prevented from silently overwriting each other.
src/Services/Identity/src/Identity/Data/Configurations · high confidence
Replaces MassTransit with Wolverine for messaging and introduces CQRS and outbox patterns
The core building block now uses Wolverine instead of MassTransit for message bus operations, configuring RabbitMQ or in-memory transports with PostgreSQL-based durable outboxes and inboxes for reliable message delivery. This change introduces a new CQRS foundation with MediatR-based ICommand and IQuery interfaces, alongside an event dispatching system that maps domain events to integration events and internal commands via a composite mapper, ensuring consistent correlation and user context headers across all messages.
src/BuildingBlocks/Core · high confidence
Restructured flight and seat retrieval endpoints into vertical slice architecture
The flight service endpoints for retrieving a specific flight and listing available seats have been refactored to follow a vertical slice architecture. The \GetFlightById\ and \GetAvailableSeats\ features now encapsulate their own request records, result models, validators, and handlers within dedicated feature folders (e.g., \Flights/Features/GettingFlightById/V1\). This change improves code organization by co-locating related logic for each API operation, while preserving the existing HTTP GET routes, authorization requirements, and API versioning (v1.0) for these endpoints.
src/Services/Flight/src/Flight/Flights/Features/GettingFlightById, src/Services/Flight/src/Flight/Seats/Features/GettingAvailableSeats · high confidence
Structured exception handling for Airport, Flight, and Seat domains
The Flight service now introduces specific, strongly-typed exception classes for validation and business-rule violations across the Airport, Flight, and Seat aggregates. This includes domain exceptions for invalid inputs (such as empty names, invalid IDs, or negative prices) and application exceptions for state conflicts (such as duplicate entries or full seat capacity). These changes provide more granular error reporting and consistent HTTP status code mapping for users interacting with these resources.
src/Services/Flight/src/Flight/Airports/Exceptions, src/Services/Flight/src/Flight/Flights/Exceptions, src/Services/Flight/src/Flight/Seats/Exceptions · high confidence
Test infrastructure now uses Docker containers for external dependencies
The test base in src/BuildingBlocks/TestBase has been refactored to replace external or hardcoded service dependencies with managed Docker containers via Testcontainers. This change introduces support for PostgreSQL (including a separate instance for persisted messages), MongoDB, RabbitMQ, and EventStoreDb, allowing integration tests to run against isolated, reproducible infrastructure without requiring pre-existing local services.
src/BuildingBlocks/TestBase · high confidence
Test coverage
Added Flight end-to-end test infrastructure and configuration; Added PactNet contract tests for Booking, Flight, Identity, and Passenger services; Added end-to-end tests for flight creation and retrieval; Added integration test for aircraft creation; Added integration test for creating an airport; Added integration test for user registration; Added integration test infrastructure for the Booking service; Added integration tests for Flight service CRUD operations; Added integration tests for seat availability and reservation; Added integration tests for the CreateBooking feature; Added integration tests for the Passenger service; Added k6 performance test scripts for Booking, Flight, Identity, and Passenger services; Added test fakes and API route constants for flight end-to-end tests; Added test fakes for Flight domain command validation; Added test fakes for Flight service commands; Added test fakes for booking integration tests; Added test fakes for passenger registration completion; Added test fakes for user registration; Added test infrastructure for the Flight service; Added test solution files for Booking, Flight, Identity, and Passenger services; Added unit tests for Flight DTO mapping; Added unit tests for airport and seat creation features; Added unit tests for flight creation and update domain logic; Added unit tests for the Create Aircraft feature.
Dependencies
Upgrade to .NET 10 and Aspire 13.1
The project has been upgraded to target .NET 10.0, with the Aspire hosting infrastructure (AppHost and ServiceDefaults) updated to version 13.1.1. This change updates the core building blocks and all service projects (Booking, Flight, Identity, Passenger) to use .NET 10-compatible packages, including EF Core 10.0.3, Swashbuckle 10.1.2, and various Microsoft.Extensions libraries. The Aspire host now references specific hosting packages for MongoDB, PostgreSQL, RabbitMQ, Redis, and Elasticsearch, aligning the entire solution with the latest .NET 10 runtime and Aspire orchestration features.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 61 → 58 (-3.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 77 → 55 (-22.2)
- Architecture 77 → 77 (+0.1)
- Maturity 74 → 74 (+0.5)
- Readiness 56 → 56 (+0.0)
- Security 61 → 59 (-2.7)
- Domain Modelling 73 → 81 (+7.7)
- Event-Driven 82 → 82 (+0.2)
- Performance 63 → 63 (+0.0)
Resolved (62)
- Bounded contexts not declared
- Duplicated block (11 lines × 3) (src/Services/Booking/src/Booking/Extensions/Infrastructure/InfrastructureExtensions.cs)
- Duplicated block (12 lines × 2) (src/Services/Identity/src/Identity/Data/IdentityContext.cs)
- Duplicated block (16 lines × 2) (src/Services/Identity/src/Identity/Data/IdentityContext.cs)
- Duplicated block (19 lines × 3) (src/BuildingBlocks/OpenTelemetryCollector/CoreDiagnostics/Commands/CommandHandlerMetrics.cs)
- Duplicated block (19 lines × 3) (src/BuildingBlocks/OpenTelemetryCollector/CoreDiagnostics/Query/QueryHandlerMetrics.cs)
- Duplicated block (24 lines × 2) (src/Services/Identity/src/Identity/Data/IdentityContext.cs)
- Duplicated block (9 lines × 2) (src/Services/Flight/src/Flight/Flights/Features/CreatingFlight/V1/CreateFlight.cs)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: MessagePack 2.5.192
- High CVE: MessagePack 2.5.192
- High IaC: KSV-0014 (deployments/kubernetes/booking-microservices.yml)
- High IaC: KSV-0121 (deployments/kubernetes/booking-microservices.yml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- …and 42 more
New (784)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- AnalyzerSeverityNone (.editorconfig)
- …and 764 more
API surface
- Unchanged — 1 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
meysamhadeli/booking-microservices was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d187d431b157e4cb538fa62591de3d679edac855 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.