onebeyond/onebeyond-studio-obelisk
61.4
Adequate · 21 September 2026
7k
lines of production code
C#
primary language
4
measurements over time
What this system is
This release introduces a comprehensive authentication and user management system, featuring Azure AD integration, JWT token handling, and two-factor authentication capabilities. The architecture is modernized with a .NET 10 and Aspire 13 upgrade, alongside a shift to native OpenAPI documentation and centralized project configuration. Infrastructure is significantly expanded with new Terraform modules for Azure resources, Docker-based local development, and automated background workers for domain events. Additionally, the release includes robust error handling middleware, health checks, and a suite of integration tests to ensure system reliability.
Features
Add Azure Function App module with .NET 10 and Linux hosting
A new Terraform module is introduced to provision an Azure Linux Function App. The configuration sets the .NET runtime version to 10.0 and enables 'always on' to ensure non-HTTP triggers function reliably. The module also configures system-assigned identity for Key Vault access and enforces HTTPS-only traffic.
_devops/Terraform/modules/az\function · high confidence
Added configuration and repository for JWT authentication tokens
The system now includes database configurations for AuthUser and AuthToken entities, defining constraints such as login ID length and refresh token indexing. Additionally, an AuthTokenRepository has been introduced to manage JWT-related data access, including a method to clear expired JWT tokens.
src/OneBeyond.Studio.Obelisk.Infrastructure/Data/AuthUsers · high confidence
Added database mapping and projection configurations for email templates and user entities
The application now includes Entity Framework Core configuration classes that define how the EmailTemplate, UserBase, User, and UserLoginLog entities map to the database schema, including column lengths and required fields. Additionally, new projection classes have been introduced to map these domain entities to their corresponding Data Transfer Objects (DTOs), enabling efficient data retrieval for user lists, lookups, and template details.
src/OneBeyond.Studio.Obelisk.Infrastructure/Data/EmailTemplates, src/OneBeyond.Studio.Obelisk.Infrastructure/Data/Users · medium confidence
Added helper classes for client application links and UI build file management
New helper classes have been introduced in the WebApi project to support the client application and UI build processes. ClientApplicationLinkGenerator and ClientApplicationOptions provide structured generation of password reset and set-password URLs, ensuring proper formatting and validation. Additionally, UIBuildFileHelpers and ControllerHelpers offer utility methods for resolving UI build files and managing common controller query parameters like pagination and sorting.
src/OneBeyond.Studio.Obelisk.WebApi/Helpers · high confidence
Added new data access and authentication infrastructure
The application now includes a new \DomainContext\ for Entity Framework Core, along with repository classes (\RWRepository\, \RORepository\, \RWBulkRepository\) that provide read, write, and bulk-write capabilities for domain aggregates. Additionally, authentication support has been introduced with \AuthUser\ and \AuthRole\ entities, a custom \AuthUserStore\, and extension methods to seed default roles and users, enabling the system to manage user identities and roles directly within the database.
src/OneBeyond.Studio.Obelisk.Infrastructure/Data · high confidence
Automated seeding of initial email templates and admin user
The application now automatically populates the database with predefined email templates and an initial administrator account upon startup. A new \EmailTemplatesSeeder\ ensures all system email templates are present in the database, while the \IdentitiesSeeder\ creates a default 'ObeliskAdmin' user with the ADMINISTRATOR role, using a configurable password. This ensures a functional admin account and necessary system data are available immediately after deployment.
src/OneBeyond.Studio.Obelisk.Infrastructure/Data/Seeding · high confidence
Introduce Azure AD sign-in provider and infrastructure modules
Users can now authenticate using Azure AD, as a new \AzureADSignInProvider\ implementation has been added to handle identity claims and email retrieval. This is supported by a \SignInProviderFactory\ that routes authentication requests to the correct provider, and an \ISigningProvider\ interface that standardizes login ID and email extraction. Additionally, new Terraform modules have been added to manage App Service custom hostnames and SSL certificate bindings, while a \CodeCoverage.runsettings\ file has been introduced to configure code coverage exclusions for test runs.
(repo-wide) · high confidence
Introduce Docker-based local development environment and Terraform infrastructure for Obelisk
A new local development environment is provided via Docker Compose, configuring Azurite, MSSQL, and the web/worker applications with standardized ports and connection strings. Simultaneously, the Terraform configuration is introduced to provision Azure infrastructure, including a resource group, Key Vault, SQL Server, Application Insights, and a Flex Consumption Function App module, establishing the baseline for the Obelisk backend deployment.
devops/Terraform · high confidence
Introduce automated SQL Server password generation and storage in Azure Key Vault
A new Terraform module has been added to the DevOps infrastructure, providing automated generation of a 16-character SQL Server password containing lowercase, uppercase, numeric, and special characters (specifically !\#%\-\+?@.\\). The module stores this generated password as a secret in Azure Key Vault and exposes the secret name and value as outputs for downstream consumption.
_devops/Terraform/modules/random\_password\_in\_key\vault · high confidence
Introduce bulk update configuration and mapping infrastructure
Added new classes to support bulk update operations: \BulkUpdateConfiguration\ scans entity types to map properties to database columns, \EntityTypeMapping\ stores the resulting type and property mappings, and \PropertyMapping\ captures column details including handling for enum types. These changes enable the system to perform bulk updates on aggregate roots by automatically mapping entity properties to their corresponding database columns.
src/OneBeyond.Studio.Obelisk.Infrastructure/Data/BulkUpdate · high confidence
Introduce centralized data access configuration and repository registration
The application now uses a new \DataAccessBuilder\ and \IDataAccessBuilder\ interface to configure data access and register repositories (including \RWBulkRepository\ and \AuthUsers\ repositories) via a fluent API. The \ServiceCollectionExtensions\ provide \AddDataAccess\ and \AddDataAccessSeeding\ methods that wire up SQL Server connections, enable retry-on-failure for cloud deployments, and register domain event receivers and seeding handlers.
src/OneBeyond.Studio.Obelisk.Infrastructure/DependencyInjection · high confidence
Introduce user management domain model and commands
Added new domain models and commands for user management, including CreateUser, UpdateUser, SendResetPasswordEmail, and UnlockUser. The User entity now supports creation, updates, and status changes (lock/unlock), with associated domain events and login logging.
src/OneBeyond.Studio.Obelisk.Domain/Features/Users · high confidence
Introduces ambient context accessors and identity extensions for the Web API layer
The Web API layer now includes new internal classes to manage ambient context and user identity claims. AmbientContextAccessor extracts user details (ID, type, role) from the HTTP context, while ApplicationClaims defines the specific claim keys. ApplicationClaimsIdentityFactory extends the default identity creation to include custom application claims, and IdentityExtensions provide helper methods to extract user attributes from the identity.
src/OneBeyond.Studio.Obelisk.WebApi/AmbientContexts · high confidence
Introduces application-layer services and infrastructure for authentication, email templates, and ambient context
The application layer now includes a new ambient context to track the current user's identity and role, along with an authentication flow handler that manages sign-in validation, two-factor authentication checks, and login logging. A new bulk repository interface and exception types are added to support domain operations. Additionally, an email template service is introduced to retrieve email content by key, and dependency injection is configured to register these services, including Mediator request handlers and domain event handlers.
src/OneBeyond.Studio.Obelisk.Application · high confidence
Introduces user management capabilities including creation, updates, and queries
The application now supports creating, updating, and listing users, as well as retrieving the current user's identity. New command handlers allow creating users, sending password reset emails, unlocking accounts, and updating user details. Query handlers provide a 'Who Am I' endpoint and a list users endpoint. Data transfer objects (DTOs) and domain event handlers for email notifications are also added.
src/OneBeyond.Studio.Obelisk.Application/Features/Users · high confidence
New API request models for authentication and pagination
The API now exposes new request models to support the migration of cshtml pages to Vue.js. This includes specific models for the password reset flow (ChangePasswordRequest, ForgotPasswordRequest, ResetPasswordRequest), a new two-factor authentication request (EnableTfaRequest), and shared pagination models (BaseListRequest, ListRequest) that support list filtering and sorting for the frontend.
src/OneBeyond.Studio.Obelisk.WebApi/Requests · high confidence
New authentication and user management API controllers
The API now exposes dedicated controllers for authentication, two-factor authentication, and user management. The AuthController handles basic sign-in, two-factor authentication, password reset, and password change flows, including a delay in the forgot password endpoint to mitigate timing attacks. The JWTAuthenticationController provides endpoints for JWT-based sign-in, token refresh, and sign-out. The UsersController allows administrators to create, update, and unlock users, as well as generate password reset tokens. The TFAController enables users to manage their two-factor authentication settings, including generating keys, enabling/disabling TFA, and generating recovery codes. These controllers implement the core authentication and user management capabilities of the application.
src/OneBeyond.Studio.Obelisk.WebApi/Controllers · high confidence
New background worker for processing domain events and cleaning up JWT tokens
A new Azure Functions-based worker service has been introduced to handle background tasks. This includes a domain event processor that listens to a message queue to dispatch domain events, and a scheduled timer job that clears down expired JWT tokens. The worker is configured with environment-specific settings for email sending (using either a local folder or SendGrid) and includes logging and dependency injection setup for the application's shared kernel.
src/OneBeyond.Studio.Obelisk.Workers · high confidence
New exception handling and security headers middleware
The API now includes dedicated middleware components for standardized error responses and security headers. The ErrorResultGeneratorMiddleware catches specific application exceptions (ValidationException, OneBeyondException) to return structured ProblemDetails JSON responses with appropriate HTTP status codes (400, 404) and trace IDs. Additionally, a new SecurityHeadersMiddleware enforces security headers (e.g., X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security) via a configurable policy, and an ExceptionHandlingMiddleware maps domain and application exceptions to specific HTTP status codes (400, 401, 403, 500). A UnitOfWorkScope middleware was also added to manage database unit of work lifecycles per request.
src/OneBeyond.Studio.Obelisk.WebApi/Middlewares · high confidence
Behavioural changes
Added ObeliskInfrastructureException for infrastructure-level error handling
A new exception class, ObeliskInfrastructureException, has been introduced in the Obelisk.Infrastructure layer. This class inherits from the existing OneBeyondException base and provides constructors for standard error messaging and inner exception handling, enabling more specific error categorization for infrastructure-related failures.
src/OneBeyond.Studio.Obelisk.Infrastructure/Exceptions · high confidence
Added default service health check endpoints
The service defaults library now registers and maps default health check endpoints at /health/ready and /health/live. This ensures that all environments expose these standard health check routes, allowing external systems or orchestrators to verify the application's readiness and liveness status.
src/OneBeyond.Studio.Obelisk.ServiceDefaults · high confidence
Database migration for authentication token replay attack mitigation
A new database migration named 'AuthTokenReplayAttack' is introduced to support security improvements against token replay attacks. This migration modifies the 'Users' table by constraining the 'Discriminator' column to a maximum length of 8 characters and adds a 'Refreshed' boolean column to the 'AuthTokens' table, along with a corresponding index on the 'RefreshToken' column.
src/OneBeyond.Studio.Obelisk.Infrastructure/Migrations · medium confidence
Email layout template is now loaded from the database at startup
The application now registers the email layout template from the database during startup, using the latest template if available or falling back to a default. This change moves email template management from static code to a database-driven approach, allowing layout updates without code changes.
src/OneBeyond.Studio.Obelisk.Infrastructure/Extensions · medium confidence
Email templates moved to external files with layout support
Email templates for account setup and password reset are now loaded from external HTML files embedded as resources, allowing for easier maintenance and styling. A shared layout template with a header and footer is applied to all emails, and the layout includes a base64-encoded logo image.
src/OneBeyond.Studio.Obelisk.Domain/Features/EmailTemplates · medium confidence
Migrate solution to slnx format and centralize project configuration
The solution has been migrated from the legacy .sln format to the modern .slnx (XML-based) format, which now explicitly defines the project structure and dependencies. Additionally, common project properties such as the .NET 10.0 target framework, language version, and nullable reference types are now centrally managed via a new Directory.Build.props file, ensuring consistent build behavior across all projects in the repository.
(repo-wide) · high confidence
Migrated authentication logic to a new command-handler structure
The authentication module has been refactored to use a command-handler pattern for all core identity operations. This includes new handlers for signing in (via password, provider, or JWT), signing out, changing or setting passwords, generating password reset tokens, and updating user details. The implementation introduces a combined authentication scheme that supports both Identity-based cookies and JWT tokens, with specific handling for cross-site cookie requirements and security stamp validation intervals.
src/OneBeyond.Studio.Obelisk.Authentication · high confidence
Native OpenAPI document generation replaces Swagger
The API documentation system has been migrated from Swagger to the native ASP.NET Core OpenAPI implementation. This change introduces a suite of OpenAPI transformers that automatically populate security schemes, handle mixed-source model binding, format SmartEnums, and display authorization requirements in the generated OpenAPI document. Additionally, the API versioning is now reflected in the OpenAPI title and description, and the Swagger UI is configured to automatically fill in the version parameter.
src/OneBeyond.Studio.Obelisk.WebApi · high confidence
New health checks and exception handling middleware
The API now includes dedicated health check endpoints for the SQL Server database, Azure Queue Storage, and Azure Blob Storage (in non-development environments), allowing users to monitor the status of these critical dependencies. Additionally, a new middleware has been added to catch unhandled exceptions during HTTP requests, ensuring that internal server errors return a generic 'unexpected error' message to the user rather than leaking sensitive stack traces or internal details.
src/OneBeyond.Studio.Obelisk.WebApi/Extensions · high confidence
Fixes
Added SignInJwtDto for JWT authentication
A new data transfer object, SignInJwtDto, was added to the WebApi layer to handle username and password credentials for JWT authentication. This change supports the JWT authentication fix by providing a structured model for sign-in requests.
src/OneBeyond.Studio.Obelisk.WebApi/Dto · medium confidence
Test coverage
Added integration tests for the ErrorResultGeneratorMiddleware; Added unit tests for string helper utilities.
Dependencies
Upgrade to .NET 10 and Aspire 13 with centralized package management
The project has been upgraded to .NET 10, with all Microsoft and OneBeyond Studio core libraries updated to version 10.0.x. The solution now uses centralized package management via Directory.Packages.props to define versions for all dependencies, including Aspire 13, OpenTelemetry, and various Azure SDKs. This change simplifies dependency management and aligns the codebase with the latest .NET and Aspire ecosystems.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 65 → 61 (-3.3)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 94 → 95 (+0.8)
- Architecture 93 → 93 (+0.0)
- Maturity 62 → 62 (-0.0)
- Readiness 71 → 66 (-5.4)
- Security 61 → 65 (+3.6)
- Domain Modelling 66 → 55 (-10.5)
Resolved (46)
- Bounded contexts not declared
- High CVE: MessagePack 2.5.192
- High CVE: MessagePack 2.5.192
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High IaC: DS-0002 (src/OneBeyond.Studio.Obelisk.Workers/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 26 more
New (93)
- Base-context workflow trigger runs with an unscoped token
- CRAP 210: FromMixedSourceOperationTransformer.TransformAsync (src/OneBeyond.Studio.Obelisk.WebApi/OpenApi/FromMixedSourceOperationTransformer.cs)
- CRAP 42: SecurityHeadersBuilder.AddSecurityPolicyFromConfiguration (src/OneBeyond.Studio.Obelisk.WebApi/Middlewares/Security/SecurityHeadersBuilder.cs)
- CRAP 56: ExceptionHandlingExtension.HandleDomainException (src/OneBeyond.Studio.Obelisk.WebApi/Middlewares/ExceptionHandling/ExceptionHandlingExtension.cs)
- CRAP 72: AuthorizeSummaryOperationTransformer.TransformAsync (src/OneBeyond.Studio.Obelisk.WebApi/OpenApi/AuthorizeSummaryOperationTransformer.cs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (src/OneBeyond.Studio.Obelisk.Application/Features/Users/CommandHandlers/SendResetPasswordEmailHandler.cs)
- Duplicated block (7 lines × 2) (src/OneBeyond.Studio.Obelisk.Application/Features/Users/CommandHandlers/UnlockUserHandler.cs)
- Duplicated block (7 lines × 6) (src/OneBeyond.Studio.Obelisk.Authentication/OneBeyond.Studio.Obelisk.Authentication.Application/CommandHandlers/ChangePasswordHandler.cs)
- Duplicated block (9 lines × 2) (src/OneBeyond.Studio.Obelisk.Application/Features/Users/Dto/GetUserDto.cs)
- High CVE: MessagePack 2.5.192
- High CVE: System.Security.Cryptography.Xml 10.0.0
- High IaC: WD-COMPOSE-0002 (devops/Docker/docker-compose.yaml)
- High IaC: WD-COMPOSE-0002 (devops/Docker/docker-compose.yaml)
- High IaC: WD-COMPOSE-0002 (devops/Docker/docker-compose.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 73 more
API surface
- Unchanged — 25 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
onebeyond/onebeyond-studio-obelisk was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e972870df6ad851fe65b064d5851283a67ec4a9c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.