Skip to content
CAI
Software that uses CAICheck a score

meysamhadeli/shop-golang-microservices

59.0

Adequate · 21 September 2026

4.6k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based microservices architecture that manages product and identity domains through distinct services. It provides HTTP and gRPC interfaces for creating, retrieving, and searching products, alongside user authentication via OAuth2 and JWT validation. The architecture leverages PostgreSQL for persistence, RabbitMQ for asynchronous event publishing, and OpenTelemetry for distributed tracing and observability.

How it got here

2022 — internal infrastructure and security

10 changes.

This period focused on establishing the project's internal infrastructure, introducing structured logging, HTTP and gRPC server implementations, and essential security middleware for authentication and tracing. The work standardized cross-cutting concerns like correlation IDs, JWT validation, and OpenTelemetry integration across the codebase.

2023 — Microservices and testing infrastructure

13 changes.

This period focused on implementing core microservices for product and identity management, alongside establishing the necessary testing infrastructure. The work included building out the product and inventory services with full CRUD and search capabilities, while simultaneously introducing test containers and mock implementations for PostgreSQL and RabbitMQ to support integration and end-to-end testing.

Features

Add ability to create products with inventory count

Users can now create new products by specifying a name, description, price, inventory ID, and a count. The system validates the input, persists the product, and publishes a 'ProductCreated' event to the message queue, exposing the creation via a new POST /api/v1/products endpoint.

_internal/services/product\_service/product/features/creating\product · high confidence

Add gRPC client/server and OpenTelemetry tracing infrastructure

The codebase now includes a new gRPC package providing a configurable gRPC client and server implementation, along with mocks for testing. Additionally, OpenTelemetry tracing support is introduced, featuring a Jaeger exporter for trace data, an Echo framework middleware for HTTP request tracing, and utility functions for propagating tracing headers in AMQP messages.

internal/pkg/grpc · high confidence

Added OAuth2 password credentials authentication flow

The application now supports authenticating users via username and password using the OAuth2 protocol. This change introduces a new \password\_credentials.go\ module that configures an OAuth2 server with a password authorization handler, allowing clients to exchange user credentials for access tokens. The implementation includes a \validateBearerToken\ endpoint for token validation and registers the OAuth2 token endpoint at \/connect/token\.

internal/pkg/oauth2 · high confidence

Added contribution guidelines and API testing tools

The repository now includes a CONTRIBUTION.md file that outlines the process for submitting pull requests and the conventional commit message format required for releases. Additionally, a shop.rest file has been added to facilitate API testing using the VS Code REST Client, and the Makefile has been updated to include targets for generating Swagger OpenAPI documentation for each microservice.

(repo-wide) · high confidence

Added microservices architecture diagram assets

Added a new Excalidraw diagram file and its corresponding SVG export for the shop-golang-microservices architecture, providing a visual representation of the system's components and their interactions.

assets · high confidence

Added product retrieval and search endpoints

Introduced new API endpoints for the product service: a GET /api/v1/products/{id} route to fetch a single product by ID, a GET /api/v1/products route to retrieve a paginated list of all products, and a GET /api/v1/products/search route to search products by text. Each feature includes the full stack of request/response DTOs, HTTP handlers, and query handlers to support these operations.

_internal/services/product\_service/product/features/getting\_product\_by\_id, internal/services/product\_service/product/features/getting\_products, internal/services/product\_service/product/features/searching\product · high confidence

Added utility packages for pagination, password hashing, and worker management

The internal/pkg/utils package now includes three new files: pagination.go provides a generic ListResult struct and ListQuery helper to standardize API pagination, filtering, and ordering; password.go adds HashPassword and ComparePasswords functions using bcrypt for secure password handling; and workers\_runner.go introduces a WorkersRunner to manage the lifecycle (Start/Stop) of multiple background workers concurrently.

internal/pkg/utils · high confidence

Adds correlation ID and JWT validation middleware

Two new middleware functions have been added to the HTTP server pipeline. The first, CorrelationIdMiddleware, automatically generates and propagates a unique correlation ID for each request to improve observability. The second, ValidateBearerToken, enforces authentication by parsing and validating a JWT access token from the Authorization header or request form data, returning a 401 Unauthorized error if validation fails (except in test environments).

internal/pkg/http/echo/middleware · high confidence

Introduce GORM PostgreSQL client and generic repository

Added new files in internal/pkg/gorm\_pgsql to provide a GORM-based PostgreSQL client (db.go) and a generic repository implementation (generic\_repository.go). The client handles database connection, automatic database creation, and migration, while the repository offers standard CRUD operations (Add, Get, Update, Delete, etc.) with context support.

_internal/pkg/gorm\pgsql · high confidence

Introduce new identity and product microservices

The diff introduces two new microservices, \identity\_service\ and \product\_service\, each with a complete application structure including configuration, dependency injection, and server setup. The identity service provides user registration and retrieval via HTTP and gRPC, while the product service exposes endpoints for creating, retrieving, and searching products. Both services include Swagger documentation, database migrations, and data seeding capabilities.

_internal/services/product\service · high confidence

Introduce structured logging and object mapping utilities

Added a new internal logging package that wraps the Logrus library to provide a consistent, configurable logging interface for the application, and a new internal mapping package that enables automatic struct-to-struct and custom function-based object mapping via reflection.

internal/pkg/logger · high confidence

Introduce the new Inventory Service

The new Inventory Service is now available, providing core inventory management capabilities. It introduces a \ProductItem\ model to track product stock levels and an \InventoryUpdated\ event to notify other services of inventory changes. The service is configured to connect to a PostgreSQL database and a RabbitMQ broker, with initial seed data for 'food' and 'health' inventories. This service enables the system to manage and update product inventory counts asynchronously via message queues.

_internal/services/inventory\service · high confidence

Introduces HTTP server implementation with header-based API versioning

A new Echo-based HTTP server implementation is added, providing configuration for timeouts, headers, and host. The server supports graceful shutdown and includes a middleware to inject the 'version' header into the request path for API versioning.

internal/pkg/http/echo/server · high confidence

New RabbitMQ client library with retry and tracing

The internal/pkg/rabbitmq package now provides new Consumer and Publisher implementations that automatically declare exchanges, queues, and bindings, and include OpenTelemetry tracing and logging. The connection setup uses exponential backoff retries (up to 5 attempts over 10 seconds) to handle RabbitMQ connectivity issues.

internal/pkg/rabbitmq · medium confidence

New internal reflection and HTTP client utilities

Added a new HTTP client implementation in \internal/pkg/http\_client\ that configures a \resty\ client with OpenTelemetry tracing and custom transport settings. Additionally, introduced reflection helper utilities in \internal/pkg/reflection\ to access and modify struct fields by name or index, including support for unexported (private) fields via unsafe pointers. Also added a type mapper and registry in \internal/pkg/reflection\ to discover, register, and instantiate types by name or package path at runtime.

_internal/pkg/http\client, internal/pkg/reflection · high confidence

Behavioural changes

Refactored HTTP package structure and naming conventions

The internal/pkg/http package has been refactored to align with updated folder and file naming conventions. This change includes the introduction of a new file, context\_provider.go, which provides a NewContext function to manage application lifecycle signals (interrupt, SIGTERM, SIGINT) and log context cancellation events.

internal/pkg/http · medium confidence

Test coverage

Add end-to-end test for creating a product; Added RabbitMQ test container for integration testing; Added integration test for creating a product; Added mock implementations for RabbitMQ consumer and publisher interfaces; Added tests for the new PostgreSQL test container helper; Added unit tests for the product creation handler.

Dependencies

Add Go module files for internal packages and services

Introduced go.mod and go.sum files for the internal/pkg, internal/services/identity\_service, and internal/services/inventory\_service modules. These files define the Go version (1.23.2) and declare direct and indirect dependencies, including libraries for HTTP clients, database drivers, and OpenTelemetry, establishing the module structure for the project's internal packages and microservices.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 56 → 59 (+3.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 96 (+1.4)
  • Architecture 100 → 93 (-6.5)
  • Maturity 62 → 62 (+0.0)
  • Readiness 49 → 53 (+3.1)
  • Security 57 → 67 (+10.1)
  • Domain Modelling 56 → 59 (+3.2)
  • Event-Driven 76 → 76 (+0.0)

Resolved (65)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
  • Critical CVE: [GHSA redacted] (internal/services/identity_service/go.mod)
  • Critical CVE: [GHSA redacted] (internal/services/inventory_service/go.mod)
  • Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
  • Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
  • Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (13 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
  • Duplicated block (13 lines × 3) (internal/services/identity_service/server/server.go)
  • Duplicated block (18 lines × 3) (internal/services/identity_service/config/config.go)
  • Duplicated block (6 lines × 2) (internal/pkg/mapper/mapper.go)
  • Duplicated block (6 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
  • Duplicated block (6 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
  • Duplicated block (6 lines × 3) (internal/services/identity_service/server/server.go)
  • Duplicated block (7 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
  • Duplicated block (8 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
  • Duplicated block (9 lines × 2) (internal/pkg/mapper/mapper.go)
  • Duplicated block (9 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
  • Duplicated block (9 lines × 2) (internal/services/identity_service/cmd/main.go)
  • …and 45 more

New (141)

  • Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
  • Critical CVE: [GHSA redacted] (internal/services/identity_service/go.mod)
  • Critical CVE: [GHSA redacted] (internal/services/inventory_service/go.mod)
  • Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
  • Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
  • Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
  • Deprecated module: github.com/streadway/amqp
  • Deprecated module: github.com/streadway/amqp
  • Deprecated module: github.com/streadway/amqp
  • Deprecated module: go.opentelemetry.io/otel/exporters/jaeger
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (internal/pkg/mapper/mapper.go)
  • Duplicated block (11 lines × 2) (internal/services/inventory_service/config/config.go)
  • Duplicated block (16 lines × 3) (internal/services/identity_service/server/server.go)
  • Duplicated block (17–18 lines × 3) (internal/services/identity_service/identity/configurations/middleware_configurations.go)
  • Duplicated block (21 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
  • Duplicated block (32 lines × 3) (internal/services/identity_service/config/config.go)
  • Duplicated block (5 lines × 2) (internal/services/product_service/product/features/creating_product/v1/endpoints/create_product_endpoint.go)
  • Duplicated block (5 lines × 3) (internal/services/identity_service/config/config.go)
  • …and 121 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

meysamhadeli/shop-golang-microservices was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 76c34f1ab7e428f6106c5cf291570502df4ff257 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.