nikhilnarayanan623/ecommerce-gin-clean-arch
48.2
Weak · 21 September 2026
9.3k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a backend API for an e-commerce platform, built using a clean architecture in Go. It provides comprehensive commerce capabilities including user authentication, product and inventory management, shopping cart and order processing, and multi-method payment integration. The system manages core business entities such as users, products, orders, and wallets, exposing them through a structured REST API with strict input validation and JWT-based security.
Features
API server initialization and route registration
The HTTP server is now initialized with Gin, loading HTML templates and setting up Swagger documentation at /swagger. It registers distinct route groups for user and admin endpoints, injecting specific handlers (auth, user, admin, cart, payment, product, order, coupon, offer, stock, and brand) via the routes package.
pkg/api · high confidence
Add input validation for whitespace in request data
A new validator package has been introduced to handle input validation, specifically targeting whitespace in request data. The implementation registers a custom validation rule that rejects fields containing only whitespace characters, ensuring that empty or space-only inputs are flagged as invalid during request processing.
pkg/validator · medium confidence
Added Google Sign-In and Payment Selection Views
Introduced new frontend templates for user authentication and checkout flows. The 'Google SignIn' page enables direct login via Google OAuth2, while the 'Online Payment Select' page allows users to choose between Razorpay, Stripe, or Cash on Delivery, routing requests to the appropriate backend endpoints for each payment method.
views · high confidence
Added JWT authentication middleware and request body trimming
The API middleware layer now enforces JWT-based authentication for both user and admin routes, validating Bearer tokens from the Authorization header and injecting the user ID into the request context. Additionally, a new middleware trims leading and trailing whitespace from JSON request bodies to ensure clean data processing.
pkg/api/middleware · high confidence
Database initialization and automated data management
The application now automatically initializes the database by migrating all domain models, including carts, orders, and products. It also seeds essential reference data such as order statuses and payment methods, and creates an initial admin user. Additionally, database triggers are established to automatically calculate cart totals and update product stock levels when orders are placed or returned.
pkg/db · high confidence
Initial release of the API handler layer
The \pkg/api/handler\ package is introduced, providing the HTTP request handlers for the application's REST API. This includes authentication endpoints (login, signup, OTP, Google OAuth), cart management (add, remove, update, view), coupon application, brand CRUD operations, offer management, order processing, payment processing, and user profile/address/wishlist management. The implementation includes corresponding interface definitions in \interfaces/\ and unit tests for the auth handler.
pkg/api/handler · high confidence
Initialize API server with dependency injection and configuration loading
The entry point for the API server has been implemented in cmd/api/main.go. It loads application configuration, initializes the API server using a dependency injection container, and starts the HTTP server, replacing the previous empty placeholder file.
cmd/api · high confidence
Introduce repository and service implementations for authentication, cart, coupons, offers, orders, payments, products, stock, and wallets
Added new repository files (auth, brand, cart, coupon, offer, order, payment, product, stock, user, wallet) that implement data access logic for core e-commerce features, including user authentication sessions, cart management, coupon validation and usage tracking, offer and product management, order and return processing, payment method handling, and wallet transactions. Included corresponding unit tests for auth and user repositories to verify database interactions.
pkg/repository · high confidence
Introduce structured response types for admin, auth, coupons, orders, products, payments, and users
The \pkg/api/handler/response\ package now defines explicit Go structs for API responses across the application. New types include \AdminLogin\ and \SalesReport\ for admin operations; \TokenResponse\ and \OtpResponse\ for authentication; \UserCoupon\ for coupon details; \OrderItem\, \ShopOrder\, \CheckOut\, \OrderReturn\, and payment-specific responses (\RazorpayOrder\, \StripeOrder\) for order and checkout flows; \Product\, \Category\, \Variation\, \ProductItems\, and \Offer\ structures for product and category data; \OrderPayment\ for payment processing; and \User\, \Cart\, \Address\, and \WishListItem\ for user-related data. These structs standardize the JSON payloads returned by the API, ensuring consistent field naming and data types for all endpoints.
pkg/api/handler/response · high confidence
Introduced domain models for authentication, orders, coupons, and user commerce features
Added new domain entities to support core commerce and authentication capabilities. This includes models for user authentication sessions (refresh and OTP), coupon management (including usage tracking), order processing (with status and payment method definitions), and user-specific features such as shopping carts, wishlists, digital wallets with transaction history, and address management. These changes establish the data structures required for these functionalities.
pkg/domain · high confidence
Introduces request validation structs and helper utilities for the API
The codebase now includes a new \pkg/api/handler/request\ package that defines Go structs for validating and parsing incoming API requests across multiple domains, including authentication, users, products, orders, coupons, and payments. These structs enforce field-level constraints such as required fields, string length limits, email formats, and numeric ranges. Additionally, the package provides helper functions to extract and parse form values, query parameters, and file uploads from Gin context objects, standardizing how request data is processed by the handlers.
pkg/api/handler/request · high confidence
New admin and user API route definitions
The API routing structure has been refactored into two new files, \admin.go\ and \user.go\, which define the endpoints for the application. The admin routes expose endpoints for managing users, categories, brands, products, orders, payments, offers, coupons, and stock levels. The user routes define endpoints for authentication (including Google OAuth and OTP login), product browsing, cart management, order placement (including COD and third-party payment integrations like Razorpay and Stripe), account management (including wishlist and wallet), and order return requests.
pkg/api/routes · high confidence
Architecture
New repository interfaces for domain entities
The repository layer has been restructured by introducing new Go interfaces for key domain entities, including Admin, Auth, Brand, Cart, Coupon, Offer, Order, Payment, Product, Stock, and User. These interfaces define the data access contracts for each entity, replacing the previous flat or less granular structure. Additionally, the old, empty interface files (adminInterface.go and userInterface.go) have been removed.
pkg/repository/interfaces · high confidence
Behavioural changes
Centralized configuration loading with environment variable and validation support
The application now uses the Viper library to load configuration from a .env file or system environment variables into a structured Config type. The LoadConfig function reads these values and validates them using the go-playground/validator package, ensuring that all required environment variables (such as database credentials, Stripe keys, and OAuth secrets) are present and correctly formatted.
pkg/config · high confidence
Updated dependency injection wiring for new domain features
The dependency injection container has been updated to wire new and refactored components, including AWS S3 cloud service, brand management, stock updates, and separated payment, cart, and coupon functionalities. This ensures the application correctly initializes repositories, use cases, and handlers for these domains.
pkg/di · high confidence
Test coverage
Added mock implementations for usecase, repository, and service interfaces to support unit testing
Generated GoMock-based mock implementations for the \AuthUseCase\, \UserRepository\, and \TokenService\ interfaces, enabling isolated unit testing of the authentication, user, and token generation logic within the \pkg/usecase\ package.
pkg/usecase · high confidence
Dependencies
Updated Go dependencies for clean architecture ecommerce project
The project's Go dependencies have been updated, introducing a range of new and upgraded packages to support the clean architecture and ecommerce features. Key additions include \gin-gonic/gin\ v1.9.1 for the web framework, \gorm.io/gorm\ v1.25.1 and \gorm.io/driver/postgres\ v1.5.2 for database interactions, and \golang-jwt/jwt\ v4.5.0 for authentication. The update also incorporates libraries for Google authentication (\markbates/goth\), payment processing (\stripe/stripe-go\, \razorpay/razorpay-go\), and various utility packages like \spf13/viper\ and \go-playground/validator\. Indirect dependencies such as \google.golang.org/protobuf\ and \golang.org/x/net\ have also been updated.
(dependencies) · high confidence
Housekeeping
Build failure logs added to tmp directory
A new file, tmp/build-errors.log, has been added to the repository. This file contains repeated 'exit status 1' error messages, indicating that build processes in this directory are failing. This change captures build error output rather than modifying functional code or user-facing features.
tmp · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 44 → 48 (+4.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 96 → 97 (+1.6)
- Architecture 98 → 62 (-36.0)
- Maturity 57 → 57 (+0.0)
- Readiness 33 → 39 (+6.0)
- Security 56 → 66 (+10.3)
- Domain Modelling 48 → 59 (+11.0)
- Accessibility 49 → 50 (+0.9)
Resolved (29)
- Change coupling: product.go ↔ offer.go (pkg/usecase/interfaces/product.go)
- Change coupling: product.go ↔ product.go (pkg/repository/interfaces/product.go)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (pkg/usecase/auth.go)
- Duplicated block (10 lines × 2) (pkg/usecase/auth.go)
- Duplicated block (11 lines × 2) (pkg/usecase/auth.go)
- Duplicated block (12 lines × 2) (pkg/api/handler/auth.go)
- Duplicated block (16 lines × 2) (pkg/usecase/auth.go)
- Duplicated block (17 lines × 2) (pkg/usecase/offer.go)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2022-0635 (go.mod)
- …and 9 more
New (101)
- Change coupling: admin.go ↔ admin.go (pkg/api/routes/admin.go)
- Change coupling: admin.go ↔ order.go (pkg/api/routes/admin.go)
- Change coupling: admin.go ↔ user.go (pkg/usecase/admin.go)
- Change coupling: auth_google.go ↔ config.go (pkg/api/handler/auth_google.go)
- Change coupling: offer.go ↔ product.go (pkg/api/handler/offer.go)
- Change-coupling hub: product.go → offer.go, admin.go, product.go, offer.go (pkg/usecase/interfaces/product.go)
- Change-coupling hub: user.go → order.go, connection.go, order.go, order.go, helper_functions.go (pkg/api/routes/user.go)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: github.com/razorpay/razorpay-go
- Deprecated module: github.com/aws/aws-sdk-go
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (pkg/api/handler/payment_razorpay.go)
- Duplicated block (11 lines × 2) (pkg/usecase/auth.go)
- Duplicated block (11 lines × 2) (pkg/usecase/order.go)
- Duplicated block (12–14 lines × 2) (pkg/usecase/auth.go)
- Duplicated block (16 lines × 2) (pkg/api/handler/auth.go)
- Duplicated block (16 lines × 2) (pkg/usecase/auth.go)
- Duplicated block (18 lines × 2) (pkg/usecase/offer.go)
- …and 81 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nikhilnarayanan623/ecommerce-gin-clean-arch was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7d8e645bf5377422c08f5d21c20b9d809535fd11 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.