Skip to content
CAI
Software that uses CAICheck a score

MiteshSharma/go-project

46.4

Weak · 21 September 2026

2.6k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based HTTP API server designed for user management, featuring authentication, role-based authorization, and session handling. It implements a layered architecture with SQL and Redis-backed storage, dynamic configuration reloading, and comprehensive Prometheus metrics for observability. The codebase also includes infrastructure for testing, such as Dockerized MySQL environments and JMeter load tests, alongside build-time traceability via Jenkins build numbers.

Features

Added Swagger UI for API documentation

The application now includes a static Swagger UI interface to visualize and interact with the API documentation. This change adds the necessary HTML entry point, OAuth2 redirect handling, and the bundled JavaScript library to the swaggerui directory, enabling users to view the API schema directly in the browser.

swaggerui · high confidence

Added password hashing and string utility functions

The util package now includes new helper functions to support authentication and data processing. A new hashpassword.go file provides HashPassword and CheckPasswordHash functions using bcrypt with salt support for secure user credential handling, while helper.go adds RandStringBytes for generating random strings and StringArrayToString/StringToStringArray for converting between string slices and comma-separated strings.

util · high confidence

Initial Go API server with Swagger docs, config watching, and bus integration

The application now exposes a Go-based HTTP API (localhost:3002, /api/v1) with Swagger 2.0 documentation and apiKey authentication. The server supports dynamic log-level updates by watching the configuration file and passing a Jenkins build number for deployment tracking. Internally, the event dispatcher now uses a shared bus object, and middleware has been relocated to the api package.

cmd · high confidence

Introduction of BI event handling interface and test implementation

The bi package now includes an EventHandler interface and a corresponding BiTestEventHandler implementation, establishing the foundation for sending BI events. The BiTestEventHandler currently provides a basic Send method that validates the event name but does not yet dispatch events, serving as a placeholder or test double for future BI event integration.

bi · high confidence

New Docker utility for managing MySQL containers

Added a new \repository/docker\ package that provides Go utilities to programmatically start, monitor, and stop Docker containers. This includes a generic \Docker\ client capable of launching containers with specific environment variables and port mappings, along with logic to wait for the container to reach a running state and verify that its exposed port is open. A specific \MysqlDocker\ helper is also included to orchestrate a MySQL 5.7 instance with predefined credentials and volume mounts, primarily to support integration testing scenarios.

repository/docker · high confidence

Prometheus metrics integration for HTTP request tracking

The metrics module now exposes an HTTP endpoint for Prometheus scraping, allowing users to monitor request volume and latency. The implementation introduces a /metrics route via the gorilla/mux router and tracks two key indicators: the total number of HTTP requests (http\_requests\_total) and a summary of request durations (http\_request\_duration) broken down by path, status code, and method. The internal interface has been updated to support detailed request recording including duration and path, replacing the previous simpler counter-only approach.

metrics · high confidence

Redis repository now supports user session caching with SQL fallback

The Redis repository has been extended to manage user sessions by caching them in Redis while maintaining a SQL database as the source of truth. A new \UserRepository\ struct wraps the existing SQL repository, implementing methods to create, update, retrieve, and delete user sessions. When retrieving a session, the system first checks Redis; if the session is not found or Redis is unavailable, it falls back to the SQL repository. The \RedisRepository\ constructor now accepts a SQL repository instance to enable this dual-layer storage strategy.

repository/redisRepository · high confidence

User authentication, authorization, and lifecycle management

The app layer now supports full user authentication and authorization workflows. Users can sign up (CreateUser), log in (UserLogin), and log out (UserLogout), with JWT tokens generated and validated via SignToken and VerifyAndParseToken. The system enforces role-based access control through UserHasPermissionTo, allowing the application to check if a user has specific permissions. Additionally, basic user management operations such as updating user details, retrieving users, and deleting users are now implemented with proper error handling and session management.

app · high confidence

User authentication, detail management, and API testing infrastructure

The API now supports user login and logout via POST and DELETE requests to /api/v1/user/{userId}/auth, and allows updating user details via PUT to /api/v1/user/{userId}/userDetail, both protected by JWT authentication. Existing user endpoints (create, get, update, delete) have been refactored to use a centralized error-handling wrapper and explicit authentication checks. Additionally, an integration test suite has been added that spins up a Docker MySQL container to validate these user and authentication flows end-to-end.

api · high confidence

Behavioural changes

Build process now injects Jenkins build number into binary metadata

The build tooling has been updated to accept a Jenkins build number via a new command-line flag, which is then embedded into the compiled binary alongside version, commit, and branch information. This allows users and operators to identify exactly which CI/CD build is deployed by inspecting the binary's metadata, improving traceability during deployment and debugging.

(repo-wide) · high confidence

Bus initialization now requires explicit logger injection

The bus package no longer uses a global singleton; instead, the AppBus constructor requires a logger.Logger instance to be passed in. This change replaces the internal zap logger with the injected logger for debug messages and removes the global GetBus accessor, meaning consumers must now explicitly create and provide the bus instance.

bus · high confidence

Centralized request handling with authentication, authorization, and metrics

The API wrapper now manages the full request lifecycle in a single entry point, consolidating response writing and status code handling. It introduces built-in support for user authentication and role-based authorization, allowing handlers to require login or sudo permissions which are enforced before the handler logic runs. Additionally, the system now records detailed Prometheus metrics for every request, including path, method, status code, and elapsed duration.

api/wrapper · high confidence

Dynamic config reloading and build number tracking

The application now supports live configuration updates: the config file is watched, and registered listeners are notified when settings change, allowing components like log levels to update without a restart. Additionally, the build number is now captured and exposed in the application settings, enabling users to identify exactly which build is deployed.

setting · high confidence

Event dispatcher workers now use injected bus instance

The event dispatcher, dispatcher, and worker components have been updated to accept a bus.Bus instance via their constructors rather than relying on a global singleton. This change modifies the NewDispatcher, NewEventDispatcher, and NewWorker signatures to include the bus parameter, and updates the worker's Start method to call Publish on the injected bus field instead of a global GetBus() call, making the event publishing behavior dependent on the provided bus implementation.

eventdispatcher · high confidence

Expanded user repository with structured error handling and new data models

The SQL repository now supports comprehensive user management operations, including creating, updating, retrieving, and deleting users, user details, roles, and sessions. The \CreateUser\ method and all new repository functions now return a \StorageResult\ struct containing either the data or an \AppError\, replacing the previous silent failure or unstructured logging approach. Additionally, the repository automatically initializes database tables for \UserDetail\, \UserRole\, and \UserSession\ models upon startup, and database connection logic has been simplified to use a direct connection string from the configuration.

repository/sqlRepository · high confidence

Expanded user, role, and permission models with authentication support

The model layer now includes new structures for managing user permissions and roles, specifically introducing the Permission and Role models along with initialization functions to define access levels like SUPER\_ADMIN. User data handling has been enhanced with new models for user details, sessions, and role assignments, alongside a dedicated UserAuth model for returning JWT tokens and user data upon login. The User model itself has been updated to include Swagger documentation tags and stricter validation rules for names, while the ToJson method now automatically excludes passwords from serialized output. Additionally, configuration support for authentication secrets (HMAC) has been added, and the error response structure has been renamed and extended to include a RequestId for better traceability.

model · high confidence

Logger level becomes dynamically configurable via config changes

The logger now supports runtime updates to its log level without requiring a restart. The Logger interface includes an OnConfigChange method, and the ZapLogger implementation stores the current configuration to allow the log level to be adjusted on the fly when the application config changes. A helper function maps string log levels (debug, info, warn, error) to the appropriate Zap core levels.

logger · high confidence

Repository interfaces return structured storage results instead of void

The repository layer has been updated to provide detailed feedback on data operations. The \UserRepository\ interface now returns a \\*model.StorageResult\ for all user and session methods (such as \CreateUser\, \UpdateUser\, \GetUser\, etc.), replacing the previous \void\ return type. This allows callers to inspect the outcome of storage operations rather than assuming success. Additionally, the \PersistentRepository\ now holds the \UserRepository\ as an interface type, and the \PersistentCacheRepository\ exposes this via a dedicated \User()\ method while passing the SQL repository to the Redis repository for fallback handling.

repository · high confidence

Test coverage

Added JMeter load test for user APIs

Added a new JMeter test plan (httpJMeterLoadTest.jmx) in the loadTest directory to exercise user-related API endpoints. The test simulates 20 concurrent threads ramping up over 5 seconds to perform Create, Update, and Get operations on /api/v1/user against a target domain (default 127.0.0.1:3002). It includes logic to generate unique email addresses via BeanShell, extract authentication tokens and user IDs from responses, and attach the auth token to subsequent requests, with results visualized via the View Results Tree listener.

loadTest · high confidence

Dependencies

Update Go dependencies for JWT and network support

The project's Go module dependencies have been updated to include github.com/dgrijalva/jwt-go v3.2.0 for JSON Web Token handling, golang.org/x/crypto for cryptographic functions, and google.golang.org/appengine v1.4.0 for App Engine compatibility. Additionally, the golang.org/x/net dependency has been updated to a newer commit to align with these changes.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 47 → 46 (-0.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 100 (+0.2)
  • Architecture 100 → 71 (-29.2)
  • Maturity 57 → 57 (+0.0)
  • Readiness 24 → 41 (+16.8)
  • Security 97 → 89 (-8.1)
  • Domain Modelling 53 → 58 (+4.9)
  • Accessibility 38 (new)

Resolved (11)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (5 lines × 2) (repository/sqlRepository/userRepository.go)
  • Duplicated block (7 lines × 2) (repository/redisRepository/userRepository.go)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient
  • single-maintainer — knowledge-concentration (bus factor) risk

New (21)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: golang.org/x/crypto
  • Duplicated block (5 lines × 2) (repository/redisRepository/userRepository.go)
  • Duplicated block (5 lines × 2) (repository/sqlRepository/userRepository.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • Low cohesion: API (LCOM4 9) (api/api.go)
  • No ADRs found
  • Outdated: github.com/felixge/httpsnoop
  • Outdated: github.com/go-redis/redis
  • Outdated: github.com/gorilla/context
  • Outdated: github.com/gorilla/mux
  • Outdated: github.com/jinzhu/gorm
  • Outdated: github.com/opentracing/opentracing-go
  • Outdated: github.com/openzipkin/zipkin-go-opentracing
  • Outdated: github.com/prometheus/client_golang
  • Outdated: github.com/spf13/viper
  • Outdated: go.uber.org/zap
  • …and 1 more

Architecture

  • Containers 0 added · 0 removed · contexts 0 added · 1 removed · edges 0 added · 0 removed

Removed bounded contexts (1)

  • github.com/MiteshSharma/project

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

MiteshSharma/go-project was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 619b3085068fc4d01ac759cbb5fe24192a7131ba — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.