Skip to content
CAI
Software that uses CAICheck a score

nikhilnarayanan623/ecommerce-gin-clean-arch

48.2

Weak · 21 September 2026

9.3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a backend API for an e-commerce platform, built using a clean architecture in Go. It provides comprehensive commerce capabilities including user authentication, product and inventory management, shopping cart and order processing, and multi-method payment integration. The system manages core business entities such as users, products, orders, and wallets, exposing them through a structured REST API with strict input validation and JWT-based security.

Features

API server initialization and route registration

The HTTP server is now initialized with Gin, loading HTML templates and setting up Swagger documentation at /swagger. It registers distinct route groups for user and admin endpoints, injecting specific handlers (auth, user, admin, cart, payment, product, order, coupon, offer, stock, and brand) via the routes package.

pkg/api · high confidence

Add input validation for whitespace in request data

A new validator package has been introduced to handle input validation, specifically targeting whitespace in request data. The implementation registers a custom validation rule that rejects fields containing only whitespace characters, ensuring that empty or space-only inputs are flagged as invalid during request processing.

pkg/validator · medium confidence

Added Google Sign-In and Payment Selection Views

Introduced new frontend templates for user authentication and checkout flows. The 'Google SignIn' page enables direct login via Google OAuth2, while the 'Online Payment Select' page allows users to choose between Razorpay, Stripe, or Cash on Delivery, routing requests to the appropriate backend endpoints for each payment method.

views · high confidence

Added JWT authentication middleware and request body trimming

The API middleware layer now enforces JWT-based authentication for both user and admin routes, validating Bearer tokens from the Authorization header and injecting the user ID into the request context. Additionally, a new middleware trims leading and trailing whitespace from JSON request bodies to ensure clean data processing.

pkg/api/middleware · high confidence

Database initialization and automated data management

The application now automatically initializes the database by migrating all domain models, including carts, orders, and products. It also seeds essential reference data such as order statuses and payment methods, and creates an initial admin user. Additionally, database triggers are established to automatically calculate cart totals and update product stock levels when orders are placed or returned.

pkg/db · high confidence

Initial release of the API handler layer

The \pkg/api/handler\ package is introduced, providing the HTTP request handlers for the application's REST API. This includes authentication endpoints (login, signup, OTP, Google OAuth), cart management (add, remove, update, view), coupon application, brand CRUD operations, offer management, order processing, payment processing, and user profile/address/wishlist management. The implementation includes corresponding interface definitions in \interfaces/\ and unit tests for the auth handler.

pkg/api/handler · high confidence

Initialize API server with dependency injection and configuration loading

The entry point for the API server has been implemented in cmd/api/main.go. It loads application configuration, initializes the API server using a dependency injection container, and starts the HTTP server, replacing the previous empty placeholder file.

cmd/api · high confidence

Introduce repository and service implementations for authentication, cart, coupons, offers, orders, payments, products, stock, and wallets

Added new repository files (auth, brand, cart, coupon, offer, order, payment, product, stock, user, wallet) that implement data access logic for core e-commerce features, including user authentication sessions, cart management, coupon validation and usage tracking, offer and product management, order and return processing, payment method handling, and wallet transactions. Included corresponding unit tests for auth and user repositories to verify database interactions.

pkg/repository · high confidence

Introduce structured response types for admin, auth, coupons, orders, products, payments, and users

The \pkg/api/handler/response\ package now defines explicit Go structs for API responses across the application. New types include \AdminLogin\ and \SalesReport\ for admin operations; \TokenResponse\ and \OtpResponse\ for authentication; \UserCoupon\ for coupon details; \OrderItem\, \ShopOrder\, \CheckOut\, \OrderReturn\, and payment-specific responses (\RazorpayOrder\, \StripeOrder\) for order and checkout flows; \Product\, \Category\, \Variation\, \ProductItems\, and \Offer\ structures for product and category data; \OrderPayment\ for payment processing; and \User\, \Cart\, \Address\, and \WishListItem\ for user-related data. These structs standardize the JSON payloads returned by the API, ensuring consistent field naming and data types for all endpoints.

pkg/api/handler/response · high confidence

Introduced domain models for authentication, orders, coupons, and user commerce features

Added new domain entities to support core commerce and authentication capabilities. This includes models for user authentication sessions (refresh and OTP), coupon management (including usage tracking), order processing (with status and payment method definitions), and user-specific features such as shopping carts, wishlists, digital wallets with transaction history, and address management. These changes establish the data structures required for these functionalities.

pkg/domain · high confidence

Introduces request validation structs and helper utilities for the API

The codebase now includes a new \pkg/api/handler/request\ package that defines Go structs for validating and parsing incoming API requests across multiple domains, including authentication, users, products, orders, coupons, and payments. These structs enforce field-level constraints such as required fields, string length limits, email formats, and numeric ranges. Additionally, the package provides helper functions to extract and parse form values, query parameters, and file uploads from Gin context objects, standardizing how request data is processed by the handlers.

pkg/api/handler/request · high confidence

New admin and user API route definitions

The API routing structure has been refactored into two new files, \admin.go\ and \user.go\, which define the endpoints for the application. The admin routes expose endpoints for managing users, categories, brands, products, orders, payments, offers, coupons, and stock levels. The user routes define endpoints for authentication (including Google OAuth and OTP login), product browsing, cart management, order placement (including COD and third-party payment integrations like Razorpay and Stripe), account management (including wishlist and wallet), and order return requests.

pkg/api/routes · high confidence

Architecture

New repository interfaces for domain entities

The repository layer has been restructured by introducing new Go interfaces for key domain entities, including Admin, Auth, Brand, Cart, Coupon, Offer, Order, Payment, Product, Stock, and User. These interfaces define the data access contracts for each entity, replacing the previous flat or less granular structure. Additionally, the old, empty interface files (adminInterface.go and userInterface.go) have been removed.

pkg/repository/interfaces · high confidence

Behavioural changes

Centralized configuration loading with environment variable and validation support

The application now uses the Viper library to load configuration from a .env file or system environment variables into a structured Config type. The LoadConfig function reads these values and validates them using the go-playground/validator package, ensuring that all required environment variables (such as database credentials, Stripe keys, and OAuth secrets) are present and correctly formatted.

pkg/config · high confidence

Updated dependency injection wiring for new domain features

The dependency injection container has been updated to wire new and refactored components, including AWS S3 cloud service, brand management, stock updates, and separated payment, cart, and coupon functionalities. This ensures the application correctly initializes repositories, use cases, and handlers for these domains.

pkg/di · high confidence

Test coverage

Added mock implementations for usecase, repository, and service interfaces to support unit testing

Generated GoMock-based mock implementations for the \AuthUseCase\, \UserRepository\, and \TokenService\ interfaces, enabling isolated unit testing of the authentication, user, and token generation logic within the \pkg/usecase\ package.

pkg/usecase · high confidence

Dependencies

Updated Go dependencies for clean architecture ecommerce project

The project's Go dependencies have been updated, introducing a range of new and upgraded packages to support the clean architecture and ecommerce features. Key additions include \gin-gonic/gin\ v1.9.1 for the web framework, \gorm.io/gorm\ v1.25.1 and \gorm.io/driver/postgres\ v1.5.2 for database interactions, and \golang-jwt/jwt\ v4.5.0 for authentication. The update also incorporates libraries for Google authentication (\markbates/goth\), payment processing (\stripe/stripe-go\, \razorpay/razorpay-go\), and various utility packages like \spf13/viper\ and \go-playground/validator\. Indirect dependencies such as \google.golang.org/protobuf\ and \golang.org/x/net\ have also been updated.

(dependencies) · high confidence

Housekeeping

Build failure logs added to tmp directory

A new file, tmp/build-errors.log, has been added to the repository. This file contains repeated 'exit status 1' error messages, indicating that build processes in this directory are failing. This change captures build error output rather than modifying functional code or user-facing features.

tmp · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 44 → 48 (+4.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 97 (+1.6)
  • Architecture 98 → 62 (-36.0)
  • Maturity 57 → 57 (+0.0)
  • Readiness 33 → 39 (+6.0)
  • Security 56 → 66 (+10.3)
  • Domain Modelling 48 → 59 (+11.0)
  • Accessibility 49 → 50 (+0.9)

Resolved (29)

  • Change coupling: product.go ↔ offer.go (pkg/usecase/interfaces/product.go)
  • Change coupling: product.go ↔ product.go (pkg/repository/interfaces/product.go)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (pkg/usecase/auth.go)
  • Duplicated block (10 lines × 2) (pkg/usecase/auth.go)
  • Duplicated block (11 lines × 2) (pkg/usecase/auth.go)
  • Duplicated block (12 lines × 2) (pkg/api/handler/auth.go)
  • Duplicated block (16 lines × 2) (pkg/usecase/auth.go)
  • Duplicated block (17 lines × 2) (pkg/usecase/offer.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2022-0635 (go.mod)
  • …and 9 more

New (101)

  • Change coupling: admin.go ↔ admin.go (pkg/api/routes/admin.go)
  • Change coupling: admin.go ↔ order.go (pkg/api/routes/admin.go)
  • Change coupling: admin.go ↔ user.go (pkg/usecase/admin.go)
  • Change coupling: auth_google.go ↔ config.go (pkg/api/handler/auth_google.go)
  • Change coupling: offer.go ↔ product.go (pkg/api/handler/offer.go)
  • Change-coupling hub: product.go → offer.go, admin.go, product.go, offer.go (pkg/usecase/interfaces/product.go)
  • Change-coupling hub: user.go → order.go, connection.go, order.go, order.go, helper_functions.go (pkg/api/routes/user.go)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/razorpay/razorpay-go
  • Deprecated module: github.com/aws/aws-sdk-go
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (pkg/api/handler/payment_razorpay.go)
  • Duplicated block (11 lines × 2) (pkg/usecase/auth.go)
  • Duplicated block (11 lines × 2) (pkg/usecase/order.go)
  • Duplicated block (12–14 lines × 2) (pkg/usecase/auth.go)
  • Duplicated block (16 lines × 2) (pkg/api/handler/auth.go)
  • Duplicated block (16 lines × 2) (pkg/usecase/auth.go)
  • Duplicated block (18 lines × 2) (pkg/usecase/offer.go)
  • …and 81 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

nikhilnarayanan623/ecommerce-gin-clean-arch was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7d8e645bf5377422c08f5d21c20b9d809535fd11 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.