Skip to content
CAI
Software that uses CAICheck a score

numq/ecommerce-backend

48.6

Weak · 21 September 2026

5.4k

lines of production code

TypeScript

with Go

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an e-commerce backend platform built on a microservices architecture, where each domain (account, cart, catalog, order, etc.) is an independent service communicating via gRPC. It provides core commerce capabilities including user authentication, product and category management, shopping cart operations, order processing, and search functionality. The infrastructure relies on MongoDB for persistent storage, Redis for caching and session management, and message queues for asynchronous updates.

How it got here

2022 — Microservices scaffolding and core domain implementation

16 changes.

This period focused on establishing the foundational infrastructure and implementing the initial versions of key microservices, including authentication, cart, catalog, category, and delivery. The work involved setting up build systems, dependency management, and gRPC-based service contracts, while also introducing domain-specific logic and data persistence for each module.

2023 — microservice architecture implementation

16 changes.

This period focused on building out the core microservice infrastructure, introducing gRPC-based services for account, profile, order, and confirmation management. The work established a consistent pattern of using MongoDB or Redis for persistence, implementing authentication interceptors, and containerizing services with Docker. Additionally, supporting services for search, promo codes, and a central API gateway were launched to complete the distributed system's foundation.

Features

Add Redis client initialization for confirmation store

A new store.go file is added to the confirmation/store package, providing a NewClient function that initializes a Redis client using the go-redis/v9 library. The function connects to the specified Redis address, performs a ping to verify connectivity, and logs the connection status.

confirmation/store · high confidence

Add configuration for the confirmation service

The confirmation service now includes environment-specific configuration files (dev.env, prod.env) and a Go config loader that reads service name, server address, Redis connection details, and API key from environment variables or .env files, enabling the service to be deployed with distinct settings for development and production environments.

confirmation/config, token/config · medium confidence

Add gRPC server infrastructure and interceptor for the account service

The account server now includes a new interceptor that validates incoming gRPC requests by checking for specific metadata headers, returning an InvalidArgument error if they are missing or empty. Additionally, a new server implementation was added to handle gRPC connections, allowing the account service to bind to a specified TCP address and launch the gRPC server with configurable options.

account/server · medium confidence

Add order microservice with gRPC and MongoDB support

Introduces the new order microservice, providing a Node.js/TypeScript implementation for managing orders via a gRPC server. The service exposes gRPC endpoints for creating, retrieving (by ID or customer), updating, and deleting orders. It uses Inversify for dependency injection, connects to MongoDB for persistence, and includes Docker and docker-compose configurations to run the service and its database dependencies.

order · high confidence

Add phone number confirmation service and interactor

A new confirmation service has been introduced to handle phone number verification. The implementation includes a gRPC service layer (service.go) that exposes SendPhoneNumberConfirmation and VerifyPhoneNumberConfirmation endpoints. These endpoints delegate to a new interactor (interactor.go) which manages the business logic, and a repository (repository.go) that stores confirmation codes in Redis. Two new error types, NotYetTime and WrongConfirmationCode, are defined to handle specific failure states. Tests have been added to verify the repository's behavior with a mock Redis client.

confirmation/confirmation · high confidence

Added gRPC server implementation and interceptor

A new gRPC server implementation has been introduced in the token/server package. This includes a Server struct that handles TCP listening and server lifecycle management, along with a reusable interceptor that extracts and validates metadata headers from incoming gRPC requests, ensuring proper header processing before invoking the actual handler.

token/server · high confidence

Added placeholder for category media assets

A new 'category/media' directory has been introduced to the project, containing a '.gitkeep' file. This change establishes a dedicated location for storing media assets related to categories, ensuring the directory is tracked by version control.

category/media · high confidence

Added placeholder for media directory

A .gitkeep file was added to the media directory, ensuring the directory is tracked by version control.

media · high confidence

Centralized configuration for Redis and server endpoints

A new Config class has been introduced to manage environment-based settings for Redis connection details (URL and name) and the server URL, providing a single point for accessing these configuration values throughout the cart module.

cart/src/config · high confidence

Initial project scaffolding and build infrastructure

The repository was initialized with essential project files, including a MIT license, a .gitignore configuration, and a comprehensive README.md documenting the E-commerce backend's microservices architecture. Additionally, build automation scripts were added: build.sh handles code generation for TypeScript and Go services, while docker-compose.sh manages container orchestration. A Jest configuration file was removed, indicating a shift in the testing framework or configuration approach.

(repo-wide) · high confidence

Initial release of core service contracts

Added the initial set of Protocol Buffer definitions for the system's microservices. This includes the account, authentication, cart, catalog, category, confirmation, delivery, order, profile, promo, search, and token services, establishing the API contracts for these domains.

proto · high confidence

Introduce OTP-based JWT authentication microservice

The authentication service is now available as a standalone microservice, implementing OTP (one-time password) based JWT authentication with access and refresh tokens. Users can sign in via phone number, confirm their identity with a verification code, and manage their session tokens. The service exposes gRPC endpoints for sign-in, confirmation, sign-out, token refresh, and access verification, backed by repositories for accounts, confirmation codes, and tokens.

authentication · high confidence

Introduce Redis-backed cart service with gRPC interface

Added a new cart service implementation that exposes cart operations (get, increase, decrease, clear) via gRPC. The service is backed by a new \CartRepository\ that persists cart data to Redis using the \redis\ client library. This includes new files for the service, repository, and use cases (GetCart, IncreaseItemQuantity, DecreaseItemQuantity, ClearCart), as well as supporting types and mappers.

cart/src/cart · high confidence

Introduce account management capabilities

Added new files in the account/account directory that implement the core account management features. This includes the Account struct, interactor/use-case layer, repository layer with MongoDB integration, and a gRPC service implementation that exposes operations to create, retrieve, update, and remove accounts by ID, phone number, role, or status.

account/account · high confidence

Introduce account service entry point with gRPC and MongoDB integration

Added the main entry point for the account service, which initializes configuration loading, connects to a MongoDB database, and sets up a gRPC server. The service registers an account service that includes an authentication interceptor to validate API keys, ensuring that only authenticated requests are processed.

account/main · high confidence

Introduce cart response handling utilities

Added a new response handling module in the cart service. This includes a ResponseError namespace for mapping errors and an index.ts file that exports a 'response' function. This function processes TaskEither results, maps successful values using a provided mapper, and handles errors by logging them and invoking a callback with the error or the mapped result.

cart/src/response · high confidence

Introduce catalog service with sorting and message queue integration

The catalog module now supports retrieving items by tags with configurable sorting (cheapest, most expensive, discounted, newest, or alphabetical) and integrates with an AMQP message queue for updates. The implementation includes a new \MessageQueue\ class for connection management, a \CatalogRepository\ that handles MongoDB operations and publishes to the queue, and a \CatalogService\ that exposes gRPC endpoints for adding, retrieving, updating, and removing catalog items.

catalog/src · high confidence

Introduce category management via gRPC service

The category module now exposes a gRPC-based service that supports creating, retrieving, updating, and deleting categories. The implementation introduces a layered architecture: a gRPC service layer (CategoryService) delegates to domain use cases (AddCategory, GetCategoryById, GetCategories, GetCategoriesByTags, UpdateCategory, RemoveCategory), which in turn interact with a MongoDB repository (CategoryRepository). A mapper handles conversion between internal Category entities and gRPC messages, while dependency injection wires the components together.

category/src · high confidence

Introduce confirmation service entry point

A new main.go file has been added to the confirmation/main directory, serving as the entry point for the confirmation service. This file initializes the application by loading configuration, setting up a Redis client, and configuring a gRPC server with an authentication interceptor that validates API keys.

confirmation/main · high confidence

Introduce delivery service with gRPC interface and domain logic

The delivery module now provides a complete gRPC-based service for managing deliveries. This includes a new \DeliveryService\ that exposes gRPC endpoints for starting, updating, canceling, completing, and removing deliveries, as well as querying deliveries by ID, courier, or order ID. The implementation introduces a domain model (\Delivery\, \DeliveryItem\, \DeliveryStatus\) and use cases (\StartDelivery\, \GetDeliveryById\, etc.) that interact with a MongoDB-backed \DeliveryRepository\. Configuration is centralized in \Config\, and the application entry point (\index.ts\) initializes the database connection and launches the gRPC server.

delivery/src · high confidence

Introduce dependency injection for the cart module

The cart module now uses a structured dependency injection (DI) system to manage its internal components. A new \module.ts\ file defines the DI container and registers all relevant services and repositories, including \CartService\, \CartRepository\, and various cart action handlers like \GetCart\, \IncreaseItemQuantity\, and \ClearCart\. Corresponding type definitions in \types.ts\ provide the necessary symbols for binding these dependencies, ensuring consistent and testable access to cart-related logic throughout the application.

cart/src/di · medium confidence

Introduce gRPC server implementation for the cart service

A new Server class has been added to the cart module, providing the core logic for launching a gRPC server. This component initializes the gRPC server using the configured URL and insecure credentials, then binds it to a dynamic port and starts the server. This change establishes the server-side infrastructure for the cart service.

cart/src/server · high confidence

Introduce new search service with gRPC and message queue integration

Adds a new search service implementation that exposes a gRPC API for searching, inserting, updating, and removing items. The service integrates with an Elasticsearch cluster for data persistence and uses RabbitMQ to consume asynchronous messages for indexing updates. Configuration is managed via environment files for both development and production environments, and the service is containerized with a multi-stage Dockerfile.

search · high confidence

Introduce profile service with gRPC server and MongoDB integration

The profile module now includes a complete gRPC-based service for managing user profiles. This adds a new server entry point that exposes create, read, update, and delete operations for profiles. The implementation introduces a MongoDB-backed repository layer, a dependency injection setup using Inversify, and a set of use cases (CreateProfile, GetProfileById, UpdateProfile, RemoveProfile) that handle the business logic. Configuration is externalized via environment variables for MongoDB and server URLs.

profile/src · high confidence

Introduce token management service with gRPC interface

Added new token management capabilities including generating access and refresh tokens, verifying token validity, and revoking tokens. The change introduces a gRPC-based service layer (token/token/service.go) that exposes these operations, backed by a repository layer (token/token/repository.go) that handles JWT signing and Redis-based token storage. A test suite (token/token/repository\_test.go) validates the repository's behavior.

token/token · high confidence

Introduce token service and Redis-backed store for account management

Users can now manage accounts through a new token service that persists data in a Redis store. The application now connects to a Redis instance (using the go-redis library) and exposes gRPC endpoints for account operations, with API key-based authentication enforced via a gRPC interceptor.

token/main · high confidence

Introduces a generic UseCase abstract class for cart interactions

A new abstract class named UseCase is added to the cart interactor layer. It provides a generic interface with an execute method that returns a TaskEither, establishing a standard pattern for executing cart-related use cases.

cart/src/interactor · high confidence

Introduces application bootstrap logic for the cart service

Adds new entry-point files that initialize the application environment and launch the cart service server. The \index.ts\ file sets up environment variables, initializes the dependency injection module, opens the store connection, and launches the gRPC server with the cart service implementation. The \application/index.ts\ file provides a helper to manage the initialization and execution phases of the application lifecycle.

cart/src · high confidence

Launch of the Gateway service with full microservice routing and authentication

The gateway service is now available, providing a unified entry point for the system's microservices. It routes requests to authentication, cart, catalog, category, delivery, order, profile, promo, and search services via gRPC. The gateway enforces access control by validating access tokens for all requests except those targeting the authentication service itself, ensuring that users must be authenticated to interact with the rest of the platform.

gateway · high confidence

Promo microservice launched with gRPC and Redis support

A new promo microservice has been introduced, providing gRPC-based endpoints to insert, retrieve, and remove promotional codes. The service is built with Node.js and TypeScript, utilizing Inversify for dependency injection and connecting to a Redis store for persistence. It is fully containerized via Docker and docker-compose, allowing the promo service and its Redis dependency to be started with a single command.

promo · high confidence

Behavioural changes

Add confirmation server infrastructure with gRPC interceptor

The confirmation service now includes a new server implementation that exposes a gRPC endpoint. This update introduces a server launcher that binds the gRPC server to a specified address and registers a unary interceptor. The interceptor extracts a specific header from incoming requests and passes it to a callback function for processing, allowing the service to validate or handle confirmation headers before executing the actual RPC handler.

confirmation/server · high confidence

Dependencies

Added dependency manifests for multiple microservices

New Go module files (go.mod and go.sum) were added for the account and authentication services, and new Node.js package files (package.json and package-lock.json) were added for the cart, catalog, and category services. These files establish the project's dependency trees, specifying required libraries such as gRPC, MongoDB drivers, and various utility packages, thereby enabling the build and runtime environments for these services.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 47 → 49 (+1.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 72 → 86 (+14.5)
  • Architecture 100 → 91 (-8.6)
  • Maturity 56 → 56 (+0.0)
  • Readiness 27 → 29 (+2.5)
  • Security 60 → 58 (-2.0)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (64)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (cart/package-lock.json)
  • Critical CVE: [GHSA redacted] (catalog/package-lock.json)
  • Critical CVE: [GHSA redacted] (account/go.mod)
  • Critical CVE: [GHSA redacted] (cart/package-lock.json)
  • Critical CVE: [GHSA redacted] (profile/package-lock.json)
  • Critical CVE: [GHSA redacted] (promo/package-lock.json)
  • Critical CVE: [GHSA redacted] (cart/package-lock.json)
  • Critical CVE: [GHSA redacted] (cart/package-lock.json)
  • Critical CVE: [GHSA redacted] (promo/package-lock.json)
  • Critical CVE: [GHSA redacted] (account/go.mod)
  • Critical CVE: [GHSA redacted] (authentication/go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 3) (search/search/dispatcher.go)
  • Duplicated block (10 lines × 6) (account/config/config.go)
  • Duplicated block (12 lines × 2) (account/account/repository.go)
  • Duplicated block (14 lines × 6) (account/main/main.go)
  • Duplicated block (9 lines × 3) (account/main/main.go)
  • Duplicated block (9 lines × 4) (account/server/interceptor.go)
  • Duplicated block (9 lines × 6) (account/server/server.go)
  • …and 44 more

New (143)

  • Critical CVE: [GHSA redacted] (cart/package-lock.json)
  • Critical CVE: [GHSA redacted] (catalog/package-lock.json)
  • Critical CVE: [GHSA redacted] (search/go.mod)
  • Critical CVE: [GHSA redacted] (account/go.mod)
  • Critical CVE: [GHSA redacted] (cart/package-lock.json)
  • Critical CVE: [GHSA redacted] (profile/package-lock.json)
  • Critical CVE: [GHSA redacted] (promo/package-lock.json)
  • Critical CVE: [GHSA redacted] (cart/package-lock.json)
  • Critical CVE: [GHSA redacted] (cart/package-lock.json)
  • Critical CVE: [GHSA redacted] (promo/package-lock.json)
  • Critical CVE: [GHSA redacted] (account/go.mod)
  • Critical CVE: [GHSA redacted] (authentication/go.mod)
  • Deprecated module: go.mongodb.org/mongo-driver
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (11 lines × 3) (search/search/dispatcher.go)
  • Duplicated block (12 lines × 2) (account/account/repository.go)
  • Duplicated block (12 lines × 2) (account/account/role.go)
  • Duplicated block (12 lines × 6) (account/config/config.go)
  • Duplicated block (12 lines × 6) (account/main/main.go)
  • Duplicated block (12 lines × 6) (account/server/server.go)
  • …and 123 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

numq/ecommerce-backend was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ef9536cd62cb19cc65e70e275b3e8355ebfee8ad — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.