Skip to content
CAI
Software that uses CAICheck a score

mmacneil/CleanAspNetCoreWebApi

35.0

Weak · 21 September 2026

972

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a .NET Core Web API that provides user authentication and registration services. It exposes endpoints for creating new accounts and logging in, utilizing JWT-based security and a clean architecture with separate core logic and infrastructure layers. The application manages user data via Entity Framework Core and returns standardized JSON responses.

Features

Added JWT authentication and user data access infrastructure

The application now supports JSON Web Token (JWT) based authentication. A new \JwtFactory\ generates encoded tokens containing user claims, configured via \JwtIssuerOptions\. User identity and data access are implemented through \ApplicationDbContext\ (extending ASP.NET Core Identity's \IdentityDbContext\), \AppUser\ entity, and a \UserRepository\ that maps between domain models and the database. The \InfrastructureModule\ registers these components, enabling the system to issue tokens and manage user data.

src/Web.Api.Infrastructure · high confidence

Added account registration and authentication endpoints

New API endpoints are now available for user registration and login. Users can register new accounts via a POST to /api/accounts, which accepts a request containing first name, last name, email, username, and password. Additionally, a login endpoint is exposed at POST /api/auth/login, accepting username and password credentials. Both controllers integrate with their respective use cases and presenters to handle the requests and return appropriate HTTP responses.

src/Web.Api/Controllers · high confidence

Added solution file for Clean ASP.NET Core Web API project

A new solution file (CleanAspNetCoreWebApi.sln) has been added, defining the build structure for the Web.Api, Web.Api.Infrastructure, and Web.Api.Core projects, along with their corresponding unit test projects.

src · high confidence

Introduce core domain models, DTOs, and use-case handlers for user registration and login

The \src/Web.Api.Core\ module now includes the foundational building blocks for user authentication and registration. This includes the \User\ domain entity, request/response DTOs (e.g., \LoginRequest\, \RegisterUserRequest\, \LoginResponse\, \RegisterUserResponse\), and the corresponding use-case implementations (\LoginUseCase\, \RegisterUserUseCase\) that coordinate with repository and JWT factory interfaces. The \CoreModule\ registers these use cases for dependency injection, enabling the application to process login and registration workflows.

src/Web.Api.Core · medium confidence

Behavioural changes

Added IOutputPort interface for use-case responses

A new IOutputPort interface has been introduced in the Web.Api.Core module, defining a generic Handle method for processing use-case responses. This addition supports the ongoing implementation of the post and user registration features.

Web.Api.Core · medium confidence

Added JSON presentation logic for user authentication and registration

Introduced new presenters for handling login and user registration endpoints. The LoginPresenter maps authentication outcomes to HTTP 200 or 401 status codes, serializing either a token or error details. The RegisterUserPresenter maps registration outcomes to HTTP 200 or 400 status codes, serializing the response. Both rely on a new JsonContentResult class to standardize JSON responses.

src/Web.Api/Presenters · high confidence

Added request models for user login and registration

New request models have been introduced to support user authentication and account creation. The LoginRequest model enables users to authenticate using a username and password. The RegisterUserRequest model allows new users to provide their first name, last name, email, username, and password. Additionally, a validator has been added to enforce length constraints on the registration fields.

src/Web.Api/Models · medium confidence

Custom JSON serialization with camelCase properties

The API now serializes JSON responses with camelCase property names, achieved by introducing a custom JsonSerializer that uses a CamelCasePropertyNamesContractResolver. This changes the casing of JSON keys in API responses from the default PascalCase to camelCase, which is a behavioral change for consumers of the API.

src/Web.Api/Serialization · medium confidence

Initial Web.Api project scaffolding with JWT authentication and Identity integration

The Web.Api project has been introduced with a new startup configuration that enables JSON Web Token (JWT) authentication, ASP.NET Core Identity, and Swagger documentation. The application now supports user registration and authentication via JWT, with a default password policy requiring only a 6-character length. Additionally, the API exposes Swagger UI for API exploration and includes a custom error handling middleware that returns application errors via a header.

src/Web.Api · high confidence

Test coverage

Added unit tests for login and user registration use cases; Added unit tests for user authentication and registration flows.

Dependencies

Initial project structure and test suite setup

The repository now includes a new .NET Core 2.1-based solution structure, introducing separate projects for the API, core logic, and infrastructure. The infrastructure layer integrates Entity Framework Core 2.2.0-preview2 for database access, AutoMapper 7.0.1 for object mapping, and System.IdentityModel.Tokens.Jwt 5.2.4 for authentication. The API project adds Swagger for API documentation and FluentValidation for request validation. Additionally, new unit test projects have been created for both the API and core logic, utilizing xUnit 2.3.1, Moq 4.10.0, and the Microsoft.NET.Test.Sdk 15.8.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 35 → 35 (-0.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 83 → 83 (+0.0)
  • Architecture 82 → 82 (+0.0)
  • Maturity 55 → 55 (+0.0)
  • Readiness 30 → 27 (-3.0)
  • Security 20 → 21 (+1.0)

Resolved (35)

  • High CVE: Microsoft.AspNetCore.App 2.1.1
  • High CVE: Microsoft.AspNetCore.App 2.1.1
  • High CVE: Microsoft.AspNetCore.App 2.1.1
  • High CVE: Microsoft.AspNetCore.App 2.1.1
  • High CVE: Microsoft.AspNetCore.App 2.1.1
  • High CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.1.1
  • High CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.1.1
  • High CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.1.3
  • High CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.1.3
  • High CVE: Microsoft.NETCore.App 2.1.0
  • High CVE: Microsoft.NETCore.App 2.1.0
  • High CVE: Microsoft.NETCore.App 2.1.0
  • High CVE: Microsoft.NETCore.App 2.1.0
  • High CVE: automapper 7.0.1
  • High CVE: microsoft.aspnetcore.app 2.1.4
  • High CVE: microsoft.aspnetcore.app 2.1.4
  • High CVE: microsoft.aspnetcore.app 2.1.4
  • High CVE: microsoft.aspnetcore.app 2.1.4
  • Medium CVE: Microsoft.AspNetCore.App 2.1.1
  • Medium CVE: Microsoft.AspNetCore.App 2.1.1
  • …and 15 more

New (11)

  • Documentation: no usage examples (README.md)
  • End-of-life runtime: .NET netcoreapp2.1
  • High CVE: Microsoft.AspNetCore.App 2.1.1
  • High CVE: Microsoft.NETCore.App 2.1.0
  • High CVE: microsoft.aspnetcore.app 2.1.4
  • Leaked secret: signing-key (src/Web.Api/Startup.cs)
  • Medium CVE: Microsoft.AspNetCore.Authentication.JwtBearer 2.1.2
  • Medium CVE: System.Security.Cryptography.Xml 4.5.0
  • redundant comment (src/Web.Api/Controllers/AccountsController.cs)
  • redundant comment (src/Web.Api/Startup.cs)
  • redundant comment (src/Web.Api/Startup.cs)

API surface

  • Unchanged — 2 HTTP endpoints

Architecture

  • Unchanged — 2 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mmacneil/CleanAspNetCoreWebApi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f8668fb2d2949579d4b8c930c67e111f3f421053 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.