mtarld/apip-ddd
67.1
Adequate · 22 September 2026
4.9k
lines of production code
PHP
primary language
7
measurements over time
What this system is
This system is a modernized book store API built on Symfony 8.1 and API Platform 4, designed to manage books, authors, categories, and orders through a strict domain-driven architecture. It exposes REST endpoints for creating, updating, and querying bookstore entities, while supporting a subscription feature that notifies users via email when new books are published. The codebase enforces immutability and value objects within its domain layer and utilizes FrankenPHP for runtime execution.
Features
Bookstore API Platform integration and application commands
This change introduces the application-layer command handlers (CQRS) and the API Platform infrastructure for the Bookstore domain. It adds handlers for creating, amending, classifying, declassifying, discounting, reviewing, and anonymizing books, as well as creating authors, categories, and placing orders. The infrastructure layer provides the corresponding API Platform resources, payloads, state processors, and object mappers to expose these operations via REST endpoints, including specific endpoints for listing cheapest books and managing book classifications.
src/BookStore/Infrastructure · high confidence
Introduces BookStore domain value objects and exceptions
This change adds a comprehensive set of value objects to the BookStore domain, including identifiers (AuthorId, BookId, CategoryId, OrderId, ReviewId), descriptive fields (AuthorName, BookName, BookDescription, BookContent, CategoryName, ReviewComment), and business logic types (Price, Quantity, Discount, Isbn, Actor, AnonymizationReason, OrderItem, PurchasedBook). These objects enforce validation rules such as ISBN-13 check digits, price ranges, and string lengths, and are mapped as Doctrine embeddables. Additionally, specific domain exceptions (MissingAuthorException, MissingBookException, MissingCategoryException, MissingOrderException, MissingReviewException) are introduced to handle cases where domain entities cannot be found by their identifiers.
src/BookStore/Domain/ValueObject · high confidence
New book subscription feature with API and event-driven notifications
Users can now subscribe to book announcements via a new email-based subscription endpoint exposed through the API Platform resources. The system automatically notifies all subscribers when a new book is published, logging the announcement details (title, price, and subscriber email) for tracking purposes.
src/Subscription · high confidence
Removals
Removal of Book Library domain and application logic
The application no longer supports managing books in the library. This change removes the entire Book domain model, including the Book entity and its repository interface, as well as all associated application-layer command and query handlers (Create, Update, Anonymize, Find, and FindCheapest). Users can no longer create, update, search, or anonymize book records through the system.
src/Application, src/Domain · high confidence
Behavioural changes
Domain model rewritten for API Platform 4 with value objects and immutability
The domain entities in src/BookStore/Domain/Model (Book, Author, Category, Classification, Order, OrderLine, Review) have been completely rewritten to align with API Platform 4. This change introduces strict immutability by using value objects (e.g., BookId, Price, AuthorName) and readonly properties, replacing previous public writable fields. The Book entity now exposes read-only collections for reviews and classifications, enforces event recording via the RecordsEvents trait, and includes behavioral methods for renaming, describing, revising content, repricing, and applying discounts. Order creation is now controlled via a static factory method that validates non-empty purchases. These changes ensure the domain model is compatible with API Platform 4's serialization and validation expectations while improving encapsulation.
src/BookStore/Domain/Model · high confidence
Introduction of domain-specific repository interfaces
New repository interfaces have been added for the Author, Book, Category, and Order domain entities. These interfaces define the contract for data access, introducing methods such as \add\, \get\, and \all\ (with pagination support for Authors and Categories), as well as specific queries like \findByName\ for Authors and \idsByAuthor\ for Books. This establishes a collection-oriented repository pattern within the domain layer, separating the data access contracts from their implementations.
src/BookStore/Domain/Repository · high confidence
Migrate Symfony configuration from PHP to YAML
All package and route configuration files in the config directory have been converted from PHP-based configuration scripts (.php) to YAML files (.yaml). This change standardizes the configuration format, simplifying maintenance and readability for components such as API Platform, Doctrine, Messenger, and routing, while preserving the existing behavior and environment-specific overrides.
config/packages · high confidence
Migrated to API Platform 4, FrankenPHP, and Castor-based development
The project has been rewritten to use API Platform 4, Symfony 8.1, and PHP 8.5, replacing the previous API Platform 3 and Symfony 6 stack. The development environment has shifted from Docker Compose to FrankenPHP, with container orchestration now managed via Castor tasks (e.g., \castor install\, \castor start\) instead of direct \docker-compose\ commands. Additionally, the repository now enforces architectural boundaries using Deptrac for both bounded contexts and hexagonal layers, and includes configuration for PHPStan, Rector, and PHP-CS-Fixer to maintain code quality.
(repo-wide) · high confidence
Migration to FrankenPHP and introduction of BookStore domain events
The application runtime has shifted from the standard Symfony PHP container to FrankenPHP, introducing a new Caddyfile configuration, specific PHP INI settings for development and production (including Xdebug and OPcache tuning), and an entrypoint script that handles dependency installation, database readiness checks, and migration execution. Concurrently, the BookStore domain layer now includes event-driven capabilities: a \RecordsEvents\ trait allows entities to track and release domain events, while specific event classes (\BookPublished\ and \BooksAnonymized\) have been added to capture book publication and author data anonymization activities.
frankenphp, src/BookStore/Domain/Event · high confidence
Refactor service configuration for API Platform 4 and directory restructuring
The service configuration has been rewritten to support API Platform 4, including a new definition for the URI variables converter in config/services/api\_platform.php. The directory structure has been reorganized: the previous monolithic library configuration is removed, and service loading is now split into specific files for the BookStore, Subscription, and Shared domains. Additionally, the configuration files have been renamed from the packages directory to the services directory (e.g., routing.php to book\_store.php, monolog.php to mcp.php), and the MCP registry alias is updated to resolve the new per-server registry structure introduced in symfony/mcp-bundle 0.13+.
config/services · high confidence
Refactored shared infrastructure to support API Platform 4 and domain-driven value objects
This change restructures the shared application layer to align with API Platform 4 and a stricter domain model. It introduces a new event bus interface and messenger-based implementation, replacing the previous query bus with a command bus that now returns void. The codebase now includes robust support for domain value objects: they are automatically unwrapped in API responses, validated via a new AssertValueObject constraint, and mapped as Doctrine embeddables. Additionally, pagination is standardized through a new PaginatedCollection and Pagination classes, and API resource links are handled via a dedicated ResourceLink attribute and resolver.
src/Shared · high confidence
Removal of custom ApiPlatform state providers, processors, and repository infrastructure
This change removes the custom ApiPlatform state providers and processors (such as BookCrudProvider, AnonymizeBooksProcessor, and DiscountBookProcessor) that previously bridged API operations to the application's command and query buses. It also deletes the custom metadata classes (CommandOperation, QueryOperation) used to define these operations, the Doctrine and InMemory repository implementations (DoctrineBookRepository, InMemoryBookRepository) along with their shared base classes and paginators, and the compiler pass that cleared native ApiPlatform tags. These removals indicate a shift away from the previous custom infrastructure layer for handling API state and data persistence.
src/Infrastructure · high confidence
Removal of legacy Docker infrastructure files
The Docker configuration for the application has been significantly cleaned up by removing several legacy files that are no longer needed. Specifically, the Caddyfile (which previously configured HTTP/3 and Mercure) has been deleted, along with the PHP production INI settings, the custom PHP entrypoint script, the healthcheck script, and the PHP-FPM configuration. This change simplifies the container setup by relying on default or external configurations instead of these specific local overrides.
docker · high confidence
Removal of legacy base HTML template
The \templates/base.html.twig\ file, which previously provided the standard HTML structure including Webpack Encore asset injection and basic block definitions, has been removed. This change eliminates the default layout foundation for the application's views, requiring templates to either define their own structure or rely on a new base template introduced elsewhere.
templates · high confidence
Updated Symfony kernel preload path and registered MCP bundle
The application's preload configuration now targets the renamed kernel container class (App\_Shared\_Infrastructure\_Symfony\_KernelProdContainer) to align with the new kernel naming convention. Additionally, the Symfony AI MCP Bundle has been registered to enable Model Context Protocol support, while the Security Bundle has been removed from the default bundle list.
config · high confidence
Updated bin scripts for API Platform 4 and namespace reorganization
The bin/phpunit script has been rewritten to support API Platform 4, adding logic to prioritize the local vendor phpunit binary while falling back to the Symfony PHPUnit Bridge. Additionally, the bin/console script has been updated to reflect a namespace reorganization, changing the Kernel import from App\\Infrastructure\\Shared\\Symfony\\Kernel to App\\Shared\\Infrastructure\\Symfony\\Kernel.
bin · high confidence
Updated public entry point for PHP 8+ syntax and namespace alignment
The public/index.php entry point has been refactored to use modern PHP syntax, including strict types, a static arrow function for the kernel instantiation, and explicit directory resolution. Additionally, the Kernel class import has been updated to reflect a new namespace structure (App\\Shared\\Infrastructure\\Symfony\\Kernel), aligning the public interface with the internal codebase reorganization.
public · high confidence
Test coverage
Added acceptance and functional tests for the BookStore API; Added acceptance tests for subscription management and book announcement; Added test bootstrap and PHPStan object-manager configuration; Added test service configuration for Book Store and shared spies.
Dependencies
Upgrade to Symfony 8.1 and API Platform 4.3
This update upgrades the project's core dependencies, moving from Symfony 6.0 to Symfony 8.1 and from API Platform 2.x (dev-main) to API Platform 4.3. The PHP requirement has been raised to version 8.5 or higher. Additionally, Doctrine ORM and Doctrine Bundle have been upgraded to versions 3.6 and 3.2 respectively, and several new development tools including Deptrac, PHP-CS-Fixer, and PHPUnit 13.1 have been added to the dev dependencies. The project license has also been changed from proprietary to MIT.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 54 → 67 (+13.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 100 → 74 (-25.9)
- Maturity 44 → 61 (+17.6)
- Readiness 44 → 72 (+28.7)
- Security 59 → 87 (+28.3)
- Domain Modelling 100 → 66 (-34.0)
Resolved (37)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (composer.lock)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further orphaned files (smaller)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High IaC: DS-0002 (Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 17 more
New (21)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium: security finding (details withheld)
- No ADRs found
- No assertions: testItHandsEveryFieldOfTheEventToTheAuditTrail (tests/BookStore/Unit/RecordAnonymizationListenerTest.php)
- No dependency advisory monitoring
- Outdated: doctrine/doctrine-bundle
- Outdated: doctrine/orm
- Outdated: symfony/console
- Outdated: symfony/framework-bundle
- Outdated: symfony/json-streamer
- Outdated: symfony/messenger
- Outdated: symfony/monolog-bundle
- Outdated: symfony/property-info
- Outdated: symfony/twig-bundle
- Outdated: symfony/validator
- …and 1 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- src/BookStore — 1 commit
Notable commits
- change: Rewrite for API Platform 4
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mtarld/apip-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 55a4b3b955823ccb11a799e85e32004d68e62be0 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.