Skip to content
CAI
Software that uses CAICheck a score

NimblePros/eShopOnWeb

49.1

Weak · 21 September 2026

6.8k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a .NET 10 e-commerce platform built on a clean architecture, featuring a public API for catalog and order management, a Razor Pages web frontend for customer shopping, and a Blazor WebAssembly admin portal for user and role administration. It handles core domain logic for product catalogs, shopping baskets, and order processing, supported by ASP.NET Core Identity for authentication and authorization. The infrastructure utilizes Azure SQL and Key Vault, with local development orchestrated via .NET Aspire and comprehensive test coverage across unit, functional, and integration layers.

How it got here

2017 — Initial project scaffolding and core domain implementation

31 changes.

This period established the foundational architecture of the eShopOnWeb application, initializing the repository structure, .NET 10/Aspire configuration, and Docker-based development environment. It involved implementing the core domain model for catalog, basket, and order management, alongside setting up ASP.NET Core Identity for user authentication and authorization. The work also included building the initial web layer with Blazor support, Razor views, and minimal APIs, supported by corresponding infrastructure and unit tests.

2018–2020 — Blazor Admin and API modernization

39 changes.

This period focused on introducing a Blazor WebAssembly-based Admin interface for comprehensive catalog and user management, alongside migrating the Public API to .NET 10 and the FastEndpoints library. The work also included consolidating the web presentation layer into Razor Pages, implementing robust domain entities for baskets and orders, and establishing extensive functional and unit test coverage across the application.

2021–2026 — Admin panel and API expansion

27 changes.

This period focused on expanding the Blazor Admin interface and Public API with comprehensive user and role management capabilities, including new endpoints, models, and integration tests. It also introduced infrastructure-as-code for Azure deployment, standardized local development with .NET Aspire, and added end-to-end testing via Playwright.

Features

Add API and Home Page health checks

New health check implementations have been added to the web application to monitor service availability. The API health check verifies that the catalog-items endpoint is reachable and returns expected content, using IHttpClientFactory for proper resource management and respecting cancellation tokens. The home page health check validates that the main web interface is serving content correctly by checking for specific text in the response.

src/Web/HealthChecks · high confidence

Add account and user management view models

The application now includes a comprehensive set of view models to support user account management features. These include models for login, registration, and password reset, as well as specific support for two-factor authentication via authenticator apps (including enabling, verifying, and displaying recovery codes). Additionally, view models are provided for managing user profile information, changing passwords, and handling external login associations.

src/Web/ViewModels/Manage · high confidence

Add product catalog management interface

The Blazor Admin portal now includes a complete interface for managing the product catalog. Administrators can view a list of catalog items, create new entries, edit existing details (including name, description, brand, type, and price), view item specifics, and delete items. The List page serves as the main entry point at /admin, orchestrating the Create, Edit, Details, and Delete modals to provide full CRUD capabilities for catalog data.

src/BlazorAdmin/Pages/CatalogItemPage · high confidence

Added Aspire AppHost for local development orchestration

Introduced a new Aspire AppHost project that orchestrates the local development environment. This host provisions a Seq logging service and configures the PublicApi and Web projects to reference it, ensuring they wait for the logging service to be ready before starting. It also includes standard launch settings and configuration files to support running the distributed application locally via the .NET Aspire tooling.

src/eShopWeb.AppHost · high confidence

Added Aspire Service Defaults for centralized observability and resilience

A new \AspireServiceDefaults\ library has been introduced to standardize cross-cutting concerns across service projects. This component configures OpenTelemetry for metrics and tracing (including ASP.NET Core, HTTP client, and runtime instrumentation), enables default health checks for liveness and readiness, integrates service discovery, and applies standard resilience handlers to HTTP clients. It also exposes Prometheus scraping endpoints and supports OTLP export, simplifying the setup of monitoring and reliability features for applications referencing this package.

src/eShopWeb.AspireServiceDefaults · high confidence

Added Identity hosting startup configuration

A new IdentityHostingStartup class has been added to the Identity area, implementing IHostingStartup to allow for service configuration during web host building. This file serves as the entry point for customizing Identity services within this specific area, currently providing an empty configuration block.

src/Web/Areas/Identity · high confidence

Added Order History and Order Detail views

Users can now view a list of their past orders and inspect the details of a specific order. The new MyOrders view displays order number, date, total, and status, with links to view details or cancel submitted orders. The new Detail view presents comprehensive information including shipping address and individual line items with prices and quantities.

src/Web/Views/Order · high confidence

Added account lockout and two-factor authentication login views

The application now includes dedicated UI views for account lockout scenarios and two-factor authentication (2FA) login. Users will see a specific message when an account is locked out, and users with 2FA enabled will be prompted to enter their authenticator code during login, with an option to use a recovery code if the authenticator device is unavailable.

src/Web/Views/Account · high confidence

Added catalog data models and validation rules

Introduced a new set of data models in the shared library to support catalog management features. This includes base classes for lookup data (CatalogBrand, CatalogType) and detailed models for catalog items (CatalogItem, CreateCatalogItemRequest) that enforce validation rules such as required fields, price ranges, and image file constraints (size and extension). Response models (CatalogBrandResponse, CatalogTypeResponse, PagedCatalogItemResponse) were also added to structure API payloads for listing and creating catalog entries.

src/BlazorShared/Models · high confidence

Added email notification for new orders

The application now sends an email confirmation when a new order is created. This is implemented via a new \OrderCreatedEvent\ domain event and a corresponding \OrderCreatedHandler\ that utilizes the Mediator library to process the event and trigger the \IEmailSender\ service.

src/ApplicationCore/Entities/OrderAggregate/Handlers · high confidence

Added logger-based email sender for development

A new LoggerEmailSender implementation of IEmailSender has been added to the infrastructure services. This component logs email details (recipient, subject, and message) instead of sending actual emails, providing a safe, non-operational alternative for development and testing environments.

src/Infrastructure/Services · high confidence

Added new view models for catalog, basket, and order features

Introduced a set of new view models in the Web layer to support UI components for catalog browsing, basket status, and order history. This includes CatalogIndexViewModel for filtering and pagination, CatalogItemViewModel for product details, BasketComponentViewModel for cart item counts, and a hierarchy of OrderViewModel, OrderDetailViewModel, and OrderItemViewModel to display order information and line items.

src/Web/ViewModels · high confidence

Added scaffolded Identity account pages for login, registration, logout, and email confirmation

The application now includes dedicated Razor Pages for user account management under the Identity area. Users can log in (with support for transferring anonymous baskets to their account), register new accounts (which triggers an email confirmation flow), log out (with cookie identity key revocation), and confirm their email addresses. These pages replace previous implicit or missing scaffolding, providing a standard UI for authentication and account verification.

src/Web/Areas/Identity/Pages/Account · high confidence

Added shared catalog UI components for product display, editing, and pagination

New shared Razor partial views have been introduced to standardize the catalog interface: \_product.cshtml renders individual items with an 'Add to Basket' form, \_editCatalog.cshtml provides an edit interface for catalog items, and \_pagination.cshtml handles page navigation while preserving existing query parameters to maintain filter state across pages.

src/Web/Pages/Shared · high confidence

Basket aggregate entity implementation

The Basket and BasketItem domain entities have been introduced to model the shopping cart structure. The Basket entity manages a collection of items, calculates the total quantity, and provides methods to add items (merging quantities for existing items) and remove empty entries. The BasketItem entity enforces data integrity by preventing negative quantities through guard clauses on quantity updates, ensuring that item counts remain valid within the basket.

src/ApplicationCore/Entities/BasketAggregate · high confidence

GitHub OAuth integration for user identity

The application now supports authentication via GitHub OAuth. A new helper component in the Identity area handles the OAuth ticket creation process by fetching the user's profile from GitHub's API and mapping profile fields (ID, login, name, and URL) into security claims for the authenticated session.

src/Web/Areas/Identity/Helpers · high confidence

Initial ASP.NET Core Identity infrastructure setup

The application now includes a dedicated identity layer within the Infrastructure project, introducing a new \AppIdentityDbContext\ for database persistence and an \ApplicationUser\ entity extending \IdentityUser\. A seed mechanism (\AppIdentityDbContextSeed\) is provided to automatically provision default administrative and product manager roles and users upon database migration. Additionally, an \IdentityTokenClaimService\ has been implemented to generate JWT tokens containing user roles, and a specific \UserNotFoundException\ is now used to handle missing user scenarios, replacing generic application exceptions.

src/Infrastructure/Identity · high confidence

Initial Blazor Admin shared UI components

This change introduces the foundational shared UI components for the new Blazor Admin interface. It includes a CustomInputSelect to handle integer parsing in Blazor forms, a MainLayout with authentication checks and toast notifications, a NavMenu with role-based access control for admin features, a RedirectToLogin component for unauthenticated access, and reusable Spinner and Toast components for user feedback.

src/BlazorAdmin/Shared · high confidence

Initial Blazor Admin web assets and configuration

The Blazor Admin application now includes its foundational web resources, enabling the admin interface to render and operate. This adds environment-specific configuration files (Development, Docker, and default) that define API and web base URLs for local and containerized deployments. It also introduces the static assets required for the UI, including the Bootstrap v4.3.1 framework, the Open Iconic icon library, and custom CSS for the admin layout, sidebar, and toast notification components.

src/BlazorAdmin/wwwroot · high confidence

Initial CSS styling and asset structure for the web application

The web application now includes a complete set of CSS stylesheets and font assets to define the visual appearance of the user interface. This change introduces SCSS source files and their compiled CSS/minified counterparts for core layout components (app, header, footer), as well as specific feature areas including the catalog, basket, orders, and identity (user menu). It also establishes a shared variables file for consistent theming (colors, fonts, breakpoints) and bundles the Montserrat font family to ensure consistent typography across the site.

src/Web/wwwroot · high confidence

Initial Web application scaffold with .NET 10, Aspire, and Blazor support

The src/Web project has been initialized with a new .NET 10 Dockerfile and a minimal API Program.cs that integrates Aspire service defaults, ASP.NET Core Identity, and GitHub OAuth. The application now supports Blazor via a dedicated service registration and includes a UserContextEnrichmentMiddleware to enrich logging with user IDs. Front-end tooling is established through libman (pulling jQuery, Bootstrap 3.4.1, and SignalR), SCSS compilation configurations, and CSS/JS bundling settings. Configuration files are provided for local, Docker, and development environments, including connection strings and Seq logging endpoints.

src/Web · high confidence

Initial identity database schema added

The application now includes the initial Entity Framework Core migration for the identity infrastructure, establishing the database schema for user and role management. This change adds the \InitialIdentityModel\ migration and its corresponding model snapshot, which define the \AspNetUsers\, \AspNetRoles\, and associated claim, login, role, and token tables required for ASP.NET Core Identity within the \AppIdentityDbContext\.

src/Infrastructure/Identity/Migrations · high confidence

Initial infrastructure-as-code deployment template for Azure

The \infra\ directory now includes a complete Bicep-based deployment template (\main.bicep\) and supporting configuration files (\abbreviations.json\, \main.parameters.json\) for provisioning the application's Azure resources. This template defines the resource group, an App Service Plan (SKU B1), the Web App targeting .NET 9.0, a Key Vault for secrets, and two SQL Server instances (Catalog and Identity). It uses abbreviations for consistent naming and retrieves SQL passwords from the Key Vault or generates random ones during deployment.

infra · high confidence

Initial project scaffolding and repository configuration

The repository has been initialized with the core project structure, including the solution file (eShopOnWeb.slnx), project definitions, and a .NET 10 SDK constraint in global.json. Essential developer tooling and configuration files have been added, such as .editorconfig for coding conventions, .dockerignore, and .gitattributes. The project now supports local development via Docker Compose (defining web, API, and SQL Server services) and Azure deployment via azure.yaml. Additionally, a C\# script (BuildTestFormat.cs) is provided to automate restore, build, test, and format verification, and standard documentation files (README, CONTRIBUTING, LICENSE) are in place.

(repo-wide) · high confidence

Initial shared view templates for layout, identity, and error handling

The application now includes the core shared Razor view templates that define the user interface structure. The main layout (\_Layout.cshtml) establishes the page shell with responsive Bootstrap styling, environment-specific asset bundling, and integration of the login partial and basket component. The \_LoginPartial.cshtml renders the user identity menu, providing access to order history, account management, and role-based admin links for Administrators and Product Managers. Additionally, new templates handle error display (Error.cshtml), cookie consent compliance (\_CookieConsentPartial.cshtml), and client-side validation scripts (\_ValidationScriptsPartial.cshtml).

src/Web/Views/Shared · high confidence

Introduce Basket and Order services with Mediator integration

The application core now exposes dedicated services for managing shopping baskets and creating orders. BasketService handles adding items, updating quantities, deleting baskets, and transferring anonymous baskets to authenticated users. OrderService orchestrates the checkout process by validating the basket, resolving catalog item details, constructing the order, and publishing an OrderCreatedEvent via the Mediator interface to support domain event handling.

src/ApplicationCore/Services · high confidence

Introduce Blazor WebAssembly Admin application

Adds a new Blazor WebAssembly-based Admin interface for managing the application. This includes the core application shell with authentication-aware routing, a custom authentication state provider that fetches user details from the API, and helper components for toast notifications and UI refresh broadcasting. The entry point registers necessary services (including local storage and catalog lookup decorators) and clears specific local storage caches on startup, providing the foundational UI and service layer for administrative tasks.

src/BlazorAdmin · high confidence

Introduce Order and Buyer domain aggregates

The ApplicationCore now includes the foundational domain models for the ordering system. This adds the Order aggregate root (Order.cs, OrderItem.cs) which encapsulates order creation, item management, and total calculation, along with value objects for shipping address (Address.cs) and order item snapshots (CatalogItemOrdered.cs). Additionally, the Buyer aggregate (Buyer.cs) and its associated PaymentMethod value object (PaymentMethod.cs) are introduced to support buyer identity and payment tracking within the domain layer.

src/ApplicationCore/Entities/OrderAggregate · high confidence

Introduction of core domain entities and configuration for the catalog system

The application core now includes the foundational domain model for the catalog feature, introducing \CatalogItem\, \CatalogBrand\, and \CatalogType\ entities that inherit from a new \BaseEntity\ and implement the \IAggregateRoot\ interface. \CatalogItem\ exposes specific behavior for managing product details, brand, type, and image URIs through dedicated update methods with validation. Additionally, a new \CatalogSettings\ class has been added to support external configuration of the catalog base URL.

src/ApplicationCore/Entities · high confidence

Introduction of typed logging adapter

A new LoggerAdapter class has been added to the Infrastructure layer, implementing the IAppLogger interface to wrap Microsoft.Extensions.Logging. This provides a consistent, type-safe logging mechanism for application components, allowing them to log warnings and information through a standardized abstraction rather than direct framework calls.

src/Infrastructure/Logging · high confidence

New API endpoints for role membership management

The public API now exposes two new endpoints for administrators to manage role memberships. You can retrieve the list of users assigned to a specific role via a GET request to \api/roles/{roleName}/members\, and remove a user from a role using a DELETE request to \api/roles/{RoleId}/members/{UserId}\. Both endpoints require administrator authentication and return appropriate HTTP status codes (200/204 for success, 404 if the role or user is not found).

src/PublicApi/RoleMembershipEndpoints · high confidence

New FileViewModel for file metadata

A new FileViewModel class has been introduced in the Web/ViewModels/File namespace to represent file-related data. It exposes three nullable string properties: FileName, Url, and DataBase64, allowing the application to pass file name, location, and base64-encoded content data to views.

src/Web/ViewModels/File · high confidence

New JavaScript interop helpers for the Blazor Admin page

The Blazor Admin page now includes dedicated C\# wrappers for JavaScript interop, enabling the admin interface to manage browser cookies (get and delete), control the body overflow CSS state (show and hide), and trigger external navigation (route outside). These new classes (Cookies, Css, Route) and the JSInteropConstants definition provide the specific client-side capabilities required by the new admin UI.

src/BlazorAdmin/JavaScript · high confidence

New Razor Pages for Admin Catalog Management

Added Razor Pages (EditCatalogItem and Index) to the Admin area to support catalog item editing and administration. The EditCatalogItem page provides a form for updating catalog item details (name, price, ID) and includes server-side validation, while the Index page serves as the entry point for the admin section. Both pages are protected by role-based authorization, requiring the 'Administrators' role to access.

src/Web/Pages/Admin · high confidence

New Role Management interface in the Blazor Admin panel

Administrators can now manage roles directly within the Blazor Admin UI. The new /roles page lists existing roles and provides actions to create, edit, and delete them. Additionally, administrators can view the members of a specific role and remove users from it, with the exception of the '[e-mail redacted]' user who is protected from removal.

src/BlazorAdmin/Pages/RolePage · high confidence

New User Management API endpoints

The Public API now exposes a comprehensive set of endpoints for managing user accounts, accessible at the /api/users path. Administrators can create, retrieve (by ID or username), update, and delete user profiles, as well as list all users. Additionally, role management is supported via endpoints to retrieve a user's assigned roles and to add or remove roles. All endpoints require JWT authentication and are restricted to users with the ADMINISTRATORS role.

src/PublicApi/UserManagementEndpoints · high confidence

New User Management interface in the Admin panel

The Blazor Admin application now includes a dedicated /users page that allows administrators to create, edit, and delete user accounts. This new interface displays a list of users and provides modal dialogs for managing details such as username, email, phone number, and role assignments. To ensure security, the system prevents users from editing their own accounts and restricts the deletion or modification of the default '[e-mail redacted]' account.

src/BlazorAdmin/Pages/UserPage · high confidence

New account management views for profile, password, and two-factor authentication

The Manage area now includes a complete set of Razor views for user account settings. Users can update their profile information (email, phone number) on the MyAccount page, change or set local passwords, and manage external login providers. A new Two-factor authentication section allows users to enable authenticator apps, view and generate recovery codes, and reset authenticator keys, with the navigation structure and status message partials supporting these interactions.

src/Web/Views/Manage · high confidence

New data models for user and role management

The BlazorAdmin application now includes a comprehensive set of request and response models to support user and role management operations. This introduces data structures for creating, updating, and deleting users and roles, as well as retrieving user lists, role lists, and specific role memberships. The models define the contract for the user management API, including validation rules for user names and emails, and support for assigning roles to users.

src/BlazorAdmin/Models · high confidence

New guard clause and JSON serialization extensions in ApplicationCore

The ApplicationCore now includes two new extension classes to support domain validation and data handling. GuardExtensions introduces a specific guard for the BasketAggregate that throws an EmptyBasketOnCheckoutException when a checkout is attempted with an empty basket, enforcing business rules at the validation layer. JsonExtensions provides reusable, case-insensitive JSON serialization helpers (FromJson and ToJson) using System.Text.Json, simplifying how objects are converted to and from JSON strings within the core application logic.

src/ApplicationCore/Extensions · high confidence

New infrastructure modules for Azure SQL, App Service, and Key Vault

Added new Bicep modules in infra/core to provision Azure SQL Server and databases, App Service plans and web apps, and Key Vault with access policies. These modules standardize the deployment of core infrastructure resources, including database initialization scripts, managed identity configuration for App Services, and secure secret management via Key Vault.

infra/core · high confidence

New public API endpoints for role management

The PublicApi now exposes a complete set of endpoints for managing application roles, allowing administrators to create, read, update, and delete roles via the REST interface. New endpoints include POST /api/roles for creating a role (returning the created role details), GET /api/roles for listing all roles, GET /api/roles/{roleId} for retrieving a specific role, PUT /api/roles for updating a role's name, and DELETE /api/roles/{roleId} for removing a role (with protection against deleting roles currently assigned to users). All endpoints require administrator authentication via JWT and are built using the FastEndpoints framework.

src/PublicApi/RoleManagementEndpoints · high confidence

New service interfaces and attribute for catalog data access

This change introduces new interface definitions in the BlazorShared layer to standardize how catalog data is accessed. It adds ICatalogItemService for CRUD operations on catalog items (create, edit, delete, get by ID, list) and a generic ICatalogLookupDataService\<T\> for retrieving lookup data lists. Additionally, a new EndpointAttribute is added to support metadata tagging for endpoints, and ILookupDataResponse\<T\> is defined to structure lookup data responses. These interfaces provide the contract for the underlying service implementations.

src/BlazorShared/Interfaces · high confidence

New user, order, and account management controllers

The application introduces three new controllers to handle core user interactions: ManageController for account settings (profile, password, 2FA), OrderController for viewing order history and details via MediatR, and UserController for retrieving current user info and handling logout with cookie cache invalidation.

src/Web/Controllers · high confidence

New user, role, and catalog management services with local caching

The Blazor Admin application now includes dedicated services for managing users, roles, and catalog items, enabling administrators to create, update, delete, and list these entities. User and role management features allow for full lifecycle operations, including assigning roles to users and viewing role memberships. Catalog item management is enhanced with a local storage caching layer that stores item lists for one minute to reduce API calls, while also automatically refreshing the cache when items are created, edited, or deleted. All operations provide user feedback through toast notifications for success or error states.

src/BlazorAdmin/Services · high confidence

Behavioural changes

Added scaffolded Identity pages with shared layout and validation scripts

The application now includes scaffolded Identity pages (such as Login) located in the Areas/Identity/Pages directory. These pages are configured to use the main application layout defined in Views/Shared/\_Layout.cshtml and include client-side validation scripts (jQuery Validate) for both development and production environments, ensuring consistent user experience and form validation for authentication flows.

src/Web/Areas/Identity/Pages · high confidence

Adopt Mediator pattern for order queries

The My Orders and Order Details features now use the Mediator pattern (via the Mediator library) to handle requests. New request handlers (GetMyOrdersHandler, GetOrderDetailsHandler) process queries using cancellation tokens and repository specifications, returning structured view models (OrderViewModel, OrderDetailViewModel) to the client.

src/Web/Features/MyOrders, src/Web/Features/OrderDetails · high confidence

Application Core interfaces standardized and expanded

The application core's interface layer has been restructured to support a cleaner architecture and new capabilities. A new IAggregateRoot marker interface and specialized read/write repository interfaces (IReadRepository, IRepository) based on Ardalis.Specification replace previous generic patterns. New service interfaces have been introduced: IBasketQueryService for efficient basket item counting, IBasketService for basket operations, IOrderService for order creation, ITokenClaimsService for token retrieval, IAppLogger for dependency-free logging, IEmailSender for email dispatch, and IUriComposer for image URL generation.

src/ApplicationCore/Interfaces · high confidence

The Basket view component has been updated to verify that the anonymous basket cookie contains a valid GUID before using it to count items. This prevents potential issues with malformed or manipulated cookie data, ensuring that only properly formatted basket identifiers are processed for anonymous users.

src/Web/Pages/Shared/Components · high confidence

The shared basket component view has been updated to include a hyperlink wrapping the cart icon and item count badge. Clicking the cart icon now redirects the user to the /Basket/Index page, providing direct access to the basket contents instead of the previous behavior.

src/Web/Views/Shared/Components · high confidence

Centralized API configuration and user mapping logic

The PublicApi project now uses dedicated extension methods to streamline startup configuration and user data handling. ServiceCollectionExtensions centralizes the registration of repositories, logging, JWT authentication, CORS policies, and Swagger documentation. WebApplicationExtensions provides a standardized method to seed both the catalog and identity databases. Additionally, new extension methods for ApplicationUser simplify the conversion between domain entities and DTOs, supporting the basic user management endpoints.

src/PublicApi/Extensions · high confidence

Centralized database context configuration with in-memory fallback

The infrastructure layer now centralizes database setup in a new \Dependencies\ class, introducing a \ConfigureLocalDatabaseContexts\ method that registers \CatalogContext\ and \AppIdentityDbContext\. This configuration supports an in-memory database mode when the \UseOnlyInMemoryDatabase\ setting is enabled, while the default SQL Server setup now explicitly applies a \DbCallCountingInterceptor\ to both contexts, replacing previous extension method attempts that were noted as non-functional in code comments.

src/Infrastructure · high confidence

Database schema enforces non-nullable constraints on order and catalog fields

The data layer now applies stricter validation rules to the database schema. The \BuyerId\ column in both the \Orders\ and \Baskets\ tables is no longer optional and is limited to 256 characters, aligning with identity provider requirements. Additionally, all shipping address fields in the \Orders\ table (Street, City, State, Country, ZipCode) are now mandatory. Finally, several fields in the \OrderItems\ table (\ItemOrdered\_CatalogItemId\, \ItemOrdered\_ProductName\, \ItemOrdered\_PictureUri\) and the \Description\ field in the \Catalog\ table have been changed from optional to required, ensuring these data points are always present.

src/Infrastructure/Data/Migrations · high confidence

Deprecation of BaseApiController in favor of minimal APIs

The BaseApiController class has been removed from active use and is now included solely as a reference implementation. It is marked with a comment indicating it is no longer used, signaling that the application has migrated away from traditional controller-based API endpoints toward minimal APIs or endpoint-based routing.

src/Web/Controllers/Api · high confidence

Introduces local user info and claim models in BlazorAdmin

The BlazorAdmin project now includes its own \UserInfo\ and \ClaimValue\ classes within the \BlazorAdmin.Authorization\ namespace. This change decouples the admin application's user identity representation from the shared \BlazorShared\ library, allowing BlazorAdmin to manage authentication state and claim data independently.

src/BlazorAdmin/Authorization · high confidence

Introduction of Product Managers role and combined role constants

The application now defines a 'Product Managers' role alongside the existing 'Administrators' role. A new constant aggregates both roles into a single string, enabling authorization logic to check for users holding either the Administrator or Product Manager role.

src/BlazorShared/Authorization · high confidence

Introduction of dedicated ViewModel services for catalog and basket UI logic

The application now uses specific services in the Web layer to handle UI-related data mapping and presentation logic, separating it from core domain logic. A new \BasketViewModelService\ manages basket creation and item mapping, leveraging \IBasketQueryService\ for efficient item counting. Catalog browsing is handled by \CatalogViewModelService\ (which builds pagination and filter lists) and a new \CachedCatalogViewModelService\ that wraps it with in-memory caching to improve performance. Additionally, \CatalogItemViewModelService\ provides a dedicated endpoint for updating catalog item details via the public API.

src/Web/Services · high confidence

Introduction of hardcoded authorization constants

A new AuthorizationConstants class has been added to the ApplicationCore, defining static strings for an authentication key, a default password, and a JWT secret key. These values are currently hardcoded with placeholder text and include TODO comments indicating they are not suitable for production use, as they should eventually be moved to environment variables or more secure storage mechanisms.

src/ApplicationCore/Constants · high confidence

Introduction of specific application core exception types

The application core now includes dedicated exception classes to handle specific business logic scenarios, replacing generic error handling with more precise types. Users will encounter distinct error conditions for missing baskets (BasketNotFoundException), duplicate entries (DuplicateException), attempting to checkout with an empty basket (EmptyBasketOnCheckoutException), and attempts to delete roles that are still assigned to users (RoleStillAssignedException).

src/ApplicationCore/Exceptions · high confidence

Migrate authentication endpoint to FastEndpoints

The authentication endpoint has been refactored to use the FastEndpoints library, replacing the previous implementation with a minimal API structure. This change introduces dedicated request and response models (AuthenticateRequest, AuthenticateResponse) and utilizes primary constructors for dependency injection, resulting in a cleaner, more maintainable API contract for user login operations.

src/PublicApi/AuthEndpoints · high confidence

Migrate catalog brand and type endpoints to minimal API style

The public API endpoints for listing catalog brands and catalog types have been rewritten using the FastEndpoints library with minimal API patterns (primary constructors and \EndpointWithoutRequest\). This change updates the implementation of the \GET api/catalog-brands\ and \GET api/catalog-types\ routes, introducing dedicated DTOs (\CatalogBrandDto\, \CatalogTypeDto\) and response classes while preserving the existing behavior of returning the list of brands and types.

src/PublicApi/CatalogBrandEndpoints, src/PublicApi/CatalogTypeEndpoints · high confidence

Migrate catalog item endpoints to FastEndpoints

The catalog item API endpoints (GetById, ListPaged, Create, Update, Delete) have been rewritten using the FastEndpoints library, replacing the previous implementation. This change introduces primary constructors for dependency injection, explicit HTTP method routing (GET, POST, PUT, DELETE) with JWT Bearer authentication for modification endpoints, and standardized request/response DTOs. The list endpoint now calculates page count using ceiling division for accurate pagination, and the delete endpoint returns a 204 NoContent status on success.

src/PublicApi/CatalogItemEndpoints · high confidence

Migrate to EF Core configuration classes

The data access layer now uses dedicated configuration classes (implementing IEntityTypeConfiguration) for all aggregate roots and related entities, including Basket, BasketItem, CatalogBrand, CatalogItem, CatalogType, Order, and OrderItem. This change centralizes mapping rules such as property constraints (e.g., BuyerId max length of 256, decimal precision for prices), relationship definitions, and value object ownership, replacing previous configuration methods to improve maintainability and encapsulation of the database schema definition.

src/Infrastructure/Data/Config · high confidence

Migrated application specifications to Ardalis.Specification library

The specification classes in the Application Core have been rewritten to use the Ardalis.Specification library, replacing the previous implementation. This change introduces new specifications for querying baskets with items, filtering and paginating catalog items, and retrieving customer orders with their associated items, ensuring consistent data retrieval patterns across the application.

src/ApplicationCore/Specifications · high confidence

Migration to Razor Pages structure

The web application's presentation layer has been consolidated into a standard Razor Pages structure under src/Web/Pages. This change introduces dedicated page models (such as IndexModel for the catalog and ErrorModel for error handling) and corresponding view files, replacing previous architectural patterns. Users will now interact with the catalog and error pages through this new, unified page-based routing system, which includes specific handling for catalog filtering, pagination, and request ID tracking.

src/Web/Pages · high confidence

New Razor Pages-based Basket and Checkout UI

The basket and checkout experience has been rebuilt using ASP.NET Core Razor Pages. This introduces dedicated views for the basket index, checkout review, and order success, along with view models (BasketItemViewModel, BasketViewModel) to structure the data. Users can now update item quantities directly on the basket page, see a 'Continue Shopping' link when the basket is empty, and proceed through a secure checkout flow that validates input and handles order creation.

src/Web/Pages/Basket · high confidence

New application startup and extension helpers

This change introduces a set of new extension methods in the Web layer to standardize application initialization. It adds database context configuration that switches between local SQL Server and Azure Key Vault-based credentials depending on the environment, registers cookie authentication with secure cookie policies, and sets up Blazor Admin services including local storage and HTTP clients. Additionally, it implements email confirmation link generation, user claim synchronization for external logins, database seeding logic, and environment-specific middleware pipelines (including Metronome logging in development and HSTS in production).

src/Web/Extensions · high confidence

PublicApi migrated to .NET 10 and FastEndpoints

The PublicApi project has been upgraded to .NET 10, as evidenced by the Dockerfile base images and the Program.cs configuration. The API architecture has shifted from the previous controller-based approach to the FastEndpoints library, which now handles endpoint registration and Swagger generation. This change introduces a new base message structure (BaseMessage, BaseRequest, BaseResponse) for standardized correlation IDs and includes specific configuration for Aspire service defaults, JWT authentication, and database context setup.

src/PublicApi · high confidence

Refactor authentication and service configuration

The web application's configuration layer has been restructured to improve security and modularity. Authentication now uses a dedicated cookie named 'EshopIdentifier' with strict SameSite policies, and includes a new 'RevokeAuthenticationEvents' mechanism that invalidates sessions when a user logs out or their identity is revoked. Service registrations have been consolidated into specific configuration classes: core domain services (like Basket and Order) are registered as scoped, while MediatR handlers are explicitly configured as scoped to manage request lifetimes correctly. Additionally, a new 'BaseUrlConfiguration' class has been introduced to centralize API base URL settings.

src/Web/Configuration · high confidence

Refactored data access layer with EF Core and Specifications

The data access infrastructure has been restructured to use Entity Framework Core with the Ardalis.Specifications library. A new CatalogContext defines the database schema for catalog, basket, and order entities, while a dedicated seed class populates initial catalog brands, types, and items. Repository operations are now implemented via EfRepository, which extends RepositoryBase from the Ardalis.Specifications package, replacing the previous generic IRepository interface with specification-based queries.

src/Infrastructure/Data · high confidence

Renamed service interfaces to clarify ViewModel responsibility

The service interfaces in the Web layer have been renamed to explicitly indicate they operate on ViewModels rather than domain entities. IBasketService is now IBasketViewModelService, CatalogServices is now CatalogViewModelService, and a new ICatalogItemViewModelService has been introduced. This change improves code clarity by distinguishing these presentation-layer contracts from core domain services.

src/Web/Interfaces · high confidence

Restored Basket Query Service for efficient item counting

The BasketQueryService has been re-added to the infrastructure layer, implementing the IBasketQueryService interface to provide a dedicated method for counting total basket items. This service leverages Entity Framework Core to perform the summation directly in the database, ensuring that the total quantity of items for a specific user is calculated efficiently without loading all basket data into memory.

src/Infrastructure/Data/Queries · high confidence

Standardize Razor view imports and layout configuration

The Razor view configuration has been standardized to use the \Microsoft.eShopWeb\ namespace hierarchy. The \\_ViewImports.cshtml\ file now explicitly registers view models for Account and Manage areas, includes Identity and Infrastructure namespaces, and sets the default page namespace, while \\_ViewStart.cshtml\ establishes \\_Layout\ as the default layout for all views.

src/Web/Views · high confidence

Structured exception handling for API errors

The Public API now includes an ExceptionMiddleware that intercepts unhandled errors and returns consistent JSON error responses instead of generic server failures. Specifically, DuplicateException and RoleStillAssignedException are now caught and returned with a 409 Conflict status code, while all other exceptions result in a 500 Internal Server Error, both including the exception message in the response body.

src/PublicApi/Middleware · high confidence

Test coverage

Added Playwright end-to-end tests for catalog and basket functionality; Added Public API integration test infrastructure; Added functional test for the home page; Added functional test infrastructure for web components; Added functional tests for basket page interactions; Added functional tests for the Public API authentication endpoint; Added functional tests for web controllers; Added integration test for removing basket items via zero quantity; Added integration tests for Catalog Item API endpoints; Added integration tests for Order repository retrieval methods; Added integration tests for Role Management API endpoints; Added integration tests for User Management API endpoints; Added integration tests for role membership endpoints; Added integration tests for the Authenticate endpoint; Added test builders for Address, Basket, and Order entities; Added unit tests for Basket entity behavior; Added unit tests for BasketService operations; Added unit tests for JSON serialization extensions; Added unit tests for Order total calculation; Added unit tests for application core specifications; Added unit tests for cache key generation helpers; Added unit tests for order-related mediator handlers.

Dependencies

Upgrade to .NET 10 and Aspire 13.x

The project has been upgraded to target .NET 10.0, updating all Microsoft.AspNetCore.\* and Microsoft.EntityFrameworkCore packages to version 10.0.9. Additionally, the solution now integrates Aspire 13.x for orchestration and service defaults, and adopts xunit v3 for testing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 49 (+0.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 74 → 73 (-0.4)
  • Architecture 86 → 86 (-0.4)
  • Maturity 68 → 67 (-0.1)
  • Readiness 70 → 70 (+0.0)
  • Security 77 → 65 (-12.1)
  • Domain Modelling 49 → 57 (+7.6)
  • Accessibility 34 → 33 (-1.1)

Resolved (36)

  • BarePragmaDisable (src/ApplicationCore/Entities/BuyerAggregate/Buyer.cs)
  • BarePragmaDisable (src/ApplicationCore/Entities/OrderAggregate/Address.cs)
  • BarePragmaDisable (src/ApplicationCore/Entities/OrderAggregate/CatalogItemOrdered.cs)
  • BarePragmaDisable (src/ApplicationCore/Entities/OrderAggregate/Order.cs)
  • BarePragmaDisable (src/ApplicationCore/Entities/OrderAggregate/OrderItem.cs)
  • BarePragmaDisable (src/Infrastructure/Data/CatalogContext.cs)
  • Bounded contexts not declared
  • Build did not complete in the analyzer
  • Change coupling: CatalogItemListPagedEndpoint.cs ↔ CreateCatalogItemEndpoint.cs (src/PublicApi/CatalogItemEndpoints/CatalogItemListPagedEndpoint.cs)
  • CommentedOutCode (tests/FunctionalTests/PublicApi/AuthEndpoints/AuthenticateEndpoint.cs)
  • CommentedOutCode (tests/FunctionalTests/PublicApi/AuthEndpoints/AuthenticateEndpoint.cs)
  • Duplicated block (11 lines × 2) (src/PublicApi/Extensions/WebApplicationExtensions.cs)
  • Duplicated block (7 lines × 2) (src/BlazorShared/Models/CatalogItem.cs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 16 more

New (73)

  • CommentedOutCode (src/eShopWeb.AspireServiceDefaults/Extensions.cs)
  • Documentation: no architecture or design documentation (docs/walkthroughs/playwright-lab-manual-instructor-notes.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no installation or build instructions (docs/walkthroughs/running-locally-on-a-linux-container-from-vs-for-mac.md)
  • Documentation: no project overview (README.md)
  • Documentation: written for insiders (docs/features/user-management.md)
  • Duplicated block (10 lines × 2) (src/BlazorAdmin/Services/HttpService.cs)
  • Duplicated block (11 lines × 2) (src/Web/Areas/Identity/Pages/Account/Logout.cshtml.cs)
  • Duplicated block (11 lines × 3) (src/BlazorAdmin/Services/HttpService.cs)
  • Duplicated block (12 lines × 2) (src/BlazorAdmin/Services/CatalogItemService.cs)
  • Duplicated block (12 lines × 2) (src/Web/ViewModels/Manage/ChangePasswordViewModel.cs)
  • Duplicated block (14 lines × 2) (src/BlazorAdmin/Services/HttpService.cs)
  • Duplicated block (18 lines × 2) (src/BlazorAdmin/Services/CachedCatalogItemServiceDecorator.cs)
  • Duplicated block (20 lines × 2) (src/PublicApi/Extensions/WebApplicationExtensions.cs)
  • Duplicated block (8 lines × 2) (src/BlazorShared/Models/CatalogItem.cs)
  • Duplicated block (9 lines × 2) (src/Web/Areas/Identity/Pages/Account/Register.cshtml.cs)
  • FileScopedPragmaDisable (src/ApplicationCore/Entities/BuyerAggregate/Buyer.cs)
  • FileScopedPragmaDisable (src/ApplicationCore/Entities/OrderAggregate/Address.cs)
  • FileScopedPragmaDisable (src/ApplicationCore/Entities/OrderAggregate/CatalogItemOrdered.cs)
  • FileScopedPragmaDisable (src/ApplicationCore/Entities/OrderAggregate/Order.cs)
  • …and 53 more

Changes since last survey

  • 4 commits — 3 feature/other, 1 fixes

By area

  • (repo) — 3 commits
  • src/PublicApi — 1 commit

Notable commits

  • fix: fix build fail: incompatible .net version
  • change: Merge pull request #267 from NimblePros/dependabot/nuget/MSTest.TestFramework-4.3.2
  • change: Merge pull request #268 from NimblePros/dependabot/nuget/NSubstitute-6.0.0
  • change: Merge pull request #276 from snehansh/main

API surface

  • Unchanged — 25 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

NimblePros/eShopOnWeb was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cbd7f0c0d50aa93257250b00432ab9e624a6aa9e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.