micheleangioni/sls-node-ts
54.3
Adequate · 21 September 2026
1.5k
lines of production code
TypeScript
with JavaScript
4
measurements over time
What this system is
This system is a serverless application that manages user data through a dual-database architecture supporting both DynamoDB and MongoDB. It exposes user creation and retrieval capabilities via GraphQL and REST APIs, with a unified error handling and structured logging infrastructure. The application also publishes domain events to AWS SNS and integrates with AWS Secrets Manager for configuration.
How it got here
2019 — User domain and infrastructure modernization
17 changes.
This period focused on modernizing the project's build and linting tooling while introducing a comprehensive user management feature. The team refactored the infrastructure layer to support both MongoDB and DynamoDB, standardized error handling across API and GraphQL layers, and implemented domain-driven design patterns for user entities and events.
2020–2021 — DynamoDB migration and infrastructure
7 changes.
This period focused on migrating the data layer to use DynamoDB as the default database while maintaining MongoDB support, alongside implementing structured logging and domain event publishing via AWS SNS. The work included building repository implementations, configuring the local development environment with LocalStack, and adding comprehensive tests for the new infrastructure.
Features
Added AWS Secrets Manager integration for loading environment variables
A new module at src/infrastructure/secrets/index.ts introduces the ability to fetch secrets from AWS Secrets Manager and populate process.env with the retrieved key-value pairs. The implementation uses the AWS SDK's SecretsManager client, parses the secret string as JSON, and conditionally loads secrets based on the fetchSecretsFromAWS flag, with the region sourced from the region environment variable.
src/infrastructure/secrets · high confidence
Added Lambda authorizer implementations for API Gateway v1 and v2
Added new files to implement the Lambda authorizer logic for both API Gateway v1 (REST API) and v2 (HTTP API) formats. The v1 implementation uses the legacy callback-based interface, while the v2 implementation uses the modern async/handler interface, each generating IAM policies to control access to API Gateway resources.
src/api/authorizer · high confidence
Added User API endpoints and GraphQL resolvers
Introduced new capabilities for user management, including a GraphQL schema and resolvers for creating and retrieving users, as well as a REST endpoint for listing users. The implementation includes a user transformer to map internal user objects to a standardized response shape and adds timestamp fields (createdAt, updatedAt) to the User type.
src/api/user · medium confidence
Added domain event infrastructure
Introduced new domain classes to support domain-driven design patterns. This includes a BaseEntity abstract class that manages a queue of domain events, allowing entities to accumulate and release events. A BaseEvent abstract class and an IDomainEvent interface are also added to standardize event structure and data access. These changes provide the foundational support for tracking and processing domain events within the application's core logic.
src/domain · high confidence
Added domain event publishing via AWS SNS
The application now supports publishing domain events to AWS SNS. A new \EventPublisher\ class handles the conversion of internal domain events into CloudEvents format and publishes them via a message broker. This capability is controlled by the \SEND\_DOMAIN\_EVENTS\ environment variable, allowing users to enable or disable event publishing without code changes.
src/application · high confidence
Added user creation and retrieval capabilities via UserService
Introduced the UserService class in the application layer, which provides methods to retrieve all users and create new users. The create functionality includes validation to prevent duplicate emails or usernames, throwing specific ApplicationError responses for forbidden or invalid data scenarios, and persists the user via the repository.
src/application/user · high confidence
Introduce DynamoDB as the default database with LocalStack support
The application now uses DynamoDB as the default database, configured via the new \src/infrastructure/dynamo\ module. The implementation connects to DynamoDB using Dynamoose, with specific handling for local development environments: it dynamically sets the connection string using the \AWS\_ENDPOINT\_URL\ environment variable when running in LocalStack, or defaults to \http://localhost:4566\ for other local setups. A new \usersSchema\ defines the User model, including global secondary indexes for email and username fields, while the main module ensures the correct table name is used from environment variables or defaults to 'Users'.
src/infrastructure/dynamo · high confidence
Introduce structured logging with a new Logger implementation
A new logging infrastructure has been added, featuring an ILogger interface and a default Logger class that formats messages using a new stringifyMessage utility. This change enables structured logging by converting error objects and other messages into JSON strings that include the log level, improving how logs are captured and processed.
src/infrastructure/logger · high confidence
Introduced MongoDB connection logic and User model initialization
Added src/infrastructure/mongo/index.ts to handle MongoDB connectivity and user repository initialization. The new code reads the MONGO\_URI environment variable, falling back to a default connection string that includes the environment name, and initializes the User model using Mongoose.
src/infrastructure/mongo · high confidence
Introduced User domain model with Dayjs timestamps and domain events
The User domain now includes a new entity class that uses Dayjs for handling createdAt and updatedAt timestamps, and emits a UserCreated domain event when dates are first set. The user repository interface (IUserRepo) and related declarations have been added to support these changes.
src/domain/user · high confidence
Behavioural changes
Centralized Lambda entry point and environment detection utilities
The application's Lambda entry point has been consolidated into a single \src/handler.ts\ file, which now manages the initialization and routing for both the GraphQL server and the REST API endpoints. This change introduces dedicated handler functions for each API type, ensuring that service instances and infrastructure components are correctly instantiated and shared across Lambda cold starts. Additionally, new utility functions (\isRunningInLocalStack\ and \isRunningLocally\) have been added to the infrastructure layer to detect the execution environment, while the previous \src/resolvers.ts\ file has been removed.
src · high confidence
Infrastructure initialization now supports DynamoDB and MongoDB with optional SNS event publishing
The infrastructure layer now initializes a user repository based on the DB environment variable, defaulting to DynamoDB while still supporting MongoDB. It also sets up an optional SNS-based event publisher for domain events, with local development configurations pointing to LocalStack endpoints. This change introduces the core wiring for database selection and event publishing in the application's startup sequence.
src/infrastructure · high confidence
Introduce MongoDB user schema with email, username, and timestamps
A new MongoDB schema for users has been added, defining the 'email' and 'username' fields as unique string types, with 'username' marked as sparse. The schema also enables Mongoose timestamps, automatically managing 'createdAt' and 'updatedAt' fields.
src/infrastructure/mongo/schemas · high confidence
Migrated from TSLint to ESLint and replaced Webpack with serverless-plugin-typescript
The project's linting tooling has been migrated from TSLint to ESLint, introducing a comprehensive ESLint configuration with TypeScript and Jest support. Concurrently, the build system was updated to use \serverless-plugin-typescript\ for in-place TypeScript compilation, replacing the previous Webpack-based bundling approach. This change also updates the default Node.js runtime to 14, configures the project to use es2019/es2021 as the TypeScript target and library, and updates the \.gitignore\ and \tsconfig\ files to reflect the new build and linting setup.
(repo-wide) · high confidence
Removed MongoDB connection configuration
The MongoDB connection setup, including the mongoose configuration and connection export, has been removed from the infrastructure layer.
src/infrastructure/db · high confidence
Simplified MongoDB configuration and added SNS topic mapping
The MongoDB configuration has been refactored to use a single \MONGO\_URI\ environment variable, replacing the previous multi-variable setup (protocol, host, port, credentials, replica set, etc.). Additionally, the config now includes a mapping for AWS SNS topics, specifically defining the \events\_aggregate\_user\ topic for domain events.
src/config · high confidence
Standardized error handling and response formatting across API layers
The API layer now uses dedicated error handlers for both GraphQL (Apollo) and HTTP (Lambda) contexts, ensuring consistent error codes and status codes are returned to clients. The \apolloErrorHandler\ maps GraphQL errors to specific HTTP status codes (e.g., 401, 403, 412) and logs internal errors appropriately. Similarly, the \applicationErrorHandler\ processes \ApplicationError\ instances to return structured JSON responses with correct status codes. A new \responseGenerator\ module provides a unified way to format both success and error responses, reducing duplication and ensuring a consistent API contract.
src/api · high confidence
Updated LocalStack to v0.14.2 and configured development environment
The development environment is now configured using a new docker-compose.yaml file that sets up LocalStack v0.14.2, MongoDB, and a setup-resources container to initialize AWS services like SNS topics and DynamoDB tables at startup. The LocalStack configuration includes environment variables for the API key, debug mode, and lambda executor settings, along with volume mounts for data persistence. Additionally, an example environment file (.example.env) is provided to store the LOCALSTACK\_API\_KEY.
dev · high confidence
User repository implementations for DynamoDB and MongoDB
Added new repository implementations for the User domain: a DynamoDB-based repository (UserDynamoRepo) and a MongoDB-based repository (UserMongoRepo), both implementing the IUserRepo interface. These changes provide concrete data access layers for user persistence using either NoSQL or document-store databases, supporting the system's shift to DynamoDB as the default while maintaining full MongoDB support.
src/infrastructure/repos · medium confidence
Test coverage
Added integration tests for the UserService; Added test seeders for DynamoDB and MongoDB; Added tests for DynamoDB and MongoDB user repository implementations; Added unit tests for the User entity.
Dependencies
Updated project dependencies and tooling
The project has been updated with newer versions of its dependencies and development tools. Key upgrades include Mongoose to v6, GraphQL to v16, Jest to v28, and TypeScript to v4.6. Additionally, the build system was migrated from Webpack to the serverless-plugin-typescript, and ESLint rules were made stricter. The package version was also bumped to 1.1.2.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 57 → 54 (-3.1)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 97 → 98 (+0.7)
- Architecture 88 → 53 (-35.0)
- Maturity 50 → 50 (+0.0)
- Readiness 46 → 50 (+4.4)
- Security 72 → 71 (-1.1)
Resolved (57)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 37 more
New (91)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- End-of-life runtime: Node.js 14
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 71 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
micheleangioni/sls-node-ts was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 36bd42279b5e3420507c339dd18e248a77f9b5d6 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.