Skip to content
CAI
Software that uses CAICheck a score

onebeyond/onebeyond-studio-obelisk

61.4

Adequate · 21 September 2026

7k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release introduces a comprehensive authentication and user management system, featuring Azure AD integration, JWT token handling, and two-factor authentication capabilities. The architecture is modernized with a .NET 10 and Aspire 13 upgrade, alongside a shift to native OpenAPI documentation and centralized project configuration. Infrastructure is significantly expanded with new Terraform modules for Azure resources, Docker-based local development, and automated background workers for domain events. Additionally, the release includes robust error handling middleware, health checks, and a suite of integration tests to ensure system reliability.

Features

Add Azure Function App module with .NET 10 and Linux hosting

A new Terraform module is introduced to provision an Azure Linux Function App. The configuration sets the .NET runtime version to 10.0 and enables 'always on' to ensure non-HTTP triggers function reliably. The module also configures system-assigned identity for Key Vault access and enforces HTTPS-only traffic.

_devops/Terraform/modules/az\function · high confidence

Added configuration and repository for JWT authentication tokens

The system now includes database configurations for AuthUser and AuthToken entities, defining constraints such as login ID length and refresh token indexing. Additionally, an AuthTokenRepository has been introduced to manage JWT-related data access, including a method to clear expired JWT tokens.

src/OneBeyond.Studio.Obelisk.Infrastructure/Data/AuthUsers · high confidence

Added database mapping and projection configurations for email templates and user entities

The application now includes Entity Framework Core configuration classes that define how the EmailTemplate, UserBase, User, and UserLoginLog entities map to the database schema, including column lengths and required fields. Additionally, new projection classes have been introduced to map these domain entities to their corresponding Data Transfer Objects (DTOs), enabling efficient data retrieval for user lists, lookups, and template details.

src/OneBeyond.Studio.Obelisk.Infrastructure/Data/EmailTemplates, src/OneBeyond.Studio.Obelisk.Infrastructure/Data/Users · medium confidence

New helper classes have been introduced in the WebApi project to support the client application and UI build processes. ClientApplicationLinkGenerator and ClientApplicationOptions provide structured generation of password reset and set-password URLs, ensuring proper formatting and validation. Additionally, UIBuildFileHelpers and ControllerHelpers offer utility methods for resolving UI build files and managing common controller query parameters like pagination and sorting.

src/OneBeyond.Studio.Obelisk.WebApi/Helpers · high confidence

Added new data access and authentication infrastructure

The application now includes a new \DomainContext\ for Entity Framework Core, along with repository classes (\RWRepository\, \RORepository\, \RWBulkRepository\) that provide read, write, and bulk-write capabilities for domain aggregates. Additionally, authentication support has been introduced with \AuthUser\ and \AuthRole\ entities, a custom \AuthUserStore\, and extension methods to seed default roles and users, enabling the system to manage user identities and roles directly within the database.

src/OneBeyond.Studio.Obelisk.Infrastructure/Data · high confidence

Automated seeding of initial email templates and admin user

The application now automatically populates the database with predefined email templates and an initial administrator account upon startup. A new \EmailTemplatesSeeder\ ensures all system email templates are present in the database, while the \IdentitiesSeeder\ creates a default 'ObeliskAdmin' user with the ADMINISTRATOR role, using a configurable password. This ensures a functional admin account and necessary system data are available immediately after deployment.

src/OneBeyond.Studio.Obelisk.Infrastructure/Data/Seeding · high confidence

Introduce Azure AD sign-in provider and infrastructure modules

Users can now authenticate using Azure AD, as a new \AzureADSignInProvider\ implementation has been added to handle identity claims and email retrieval. This is supported by a \SignInProviderFactory\ that routes authentication requests to the correct provider, and an \ISigningProvider\ interface that standardizes login ID and email extraction. Additionally, new Terraform modules have been added to manage App Service custom hostnames and SSL certificate bindings, while a \CodeCoverage.runsettings\ file has been introduced to configure code coverage exclusions for test runs.

(repo-wide) · high confidence

Introduce Docker-based local development environment and Terraform infrastructure for Obelisk

A new local development environment is provided via Docker Compose, configuring Azurite, MSSQL, and the web/worker applications with standardized ports and connection strings. Simultaneously, the Terraform configuration is introduced to provision Azure infrastructure, including a resource group, Key Vault, SQL Server, Application Insights, and a Flex Consumption Function App module, establishing the baseline for the Obelisk backend deployment.

devops/Terraform · high confidence

Introduce automated SQL Server password generation and storage in Azure Key Vault

A new Terraform module has been added to the DevOps infrastructure, providing automated generation of a 16-character SQL Server password containing lowercase, uppercase, numeric, and special characters (specifically !\#%\-\+?@.\\). The module stores this generated password as a secret in Azure Key Vault and exposes the secret name and value as outputs for downstream consumption.

_devops/Terraform/modules/random\_password\_in\_key\vault · high confidence

Introduce bulk update configuration and mapping infrastructure

Added new classes to support bulk update operations: \BulkUpdateConfiguration\ scans entity types to map properties to database columns, \EntityTypeMapping\ stores the resulting type and property mappings, and \PropertyMapping\ captures column details including handling for enum types. These changes enable the system to perform bulk updates on aggregate roots by automatically mapping entity properties to their corresponding database columns.

src/OneBeyond.Studio.Obelisk.Infrastructure/Data/BulkUpdate · high confidence

Introduce centralized data access configuration and repository registration

The application now uses a new \DataAccessBuilder\ and \IDataAccessBuilder\ interface to configure data access and register repositories (including \RWBulkRepository\ and \AuthUsers\ repositories) via a fluent API. The \ServiceCollectionExtensions\ provide \AddDataAccess\ and \AddDataAccessSeeding\ methods that wire up SQL Server connections, enable retry-on-failure for cloud deployments, and register domain event receivers and seeding handlers.

src/OneBeyond.Studio.Obelisk.Infrastructure/DependencyInjection · high confidence

Introduce user management domain model and commands

Added new domain models and commands for user management, including CreateUser, UpdateUser, SendResetPasswordEmail, and UnlockUser. The User entity now supports creation, updates, and status changes (lock/unlock), with associated domain events and login logging.

src/OneBeyond.Studio.Obelisk.Domain/Features/Users · high confidence

Introduces ambient context accessors and identity extensions for the Web API layer

The Web API layer now includes new internal classes to manage ambient context and user identity claims. AmbientContextAccessor extracts user details (ID, type, role) from the HTTP context, while ApplicationClaims defines the specific claim keys. ApplicationClaimsIdentityFactory extends the default identity creation to include custom application claims, and IdentityExtensions provide helper methods to extract user attributes from the identity.

src/OneBeyond.Studio.Obelisk.WebApi/AmbientContexts · high confidence

Introduces application-layer services and infrastructure for authentication, email templates, and ambient context

The application layer now includes a new ambient context to track the current user's identity and role, along with an authentication flow handler that manages sign-in validation, two-factor authentication checks, and login logging. A new bulk repository interface and exception types are added to support domain operations. Additionally, an email template service is introduced to retrieve email content by key, and dependency injection is configured to register these services, including Mediator request handlers and domain event handlers.

src/OneBeyond.Studio.Obelisk.Application · high confidence

Introduces user management capabilities including creation, updates, and queries

The application now supports creating, updating, and listing users, as well as retrieving the current user's identity. New command handlers allow creating users, sending password reset emails, unlocking accounts, and updating user details. Query handlers provide a 'Who Am I' endpoint and a list users endpoint. Data transfer objects (DTOs) and domain event handlers for email notifications are also added.

src/OneBeyond.Studio.Obelisk.Application/Features/Users · high confidence

New API request models for authentication and pagination

The API now exposes new request models to support the migration of cshtml pages to Vue.js. This includes specific models for the password reset flow (ChangePasswordRequest, ForgotPasswordRequest, ResetPasswordRequest), a new two-factor authentication request (EnableTfaRequest), and shared pagination models (BaseListRequest, ListRequest) that support list filtering and sorting for the frontend.

src/OneBeyond.Studio.Obelisk.WebApi/Requests · high confidence

New authentication and user management API controllers

The API now exposes dedicated controllers for authentication, two-factor authentication, and user management. The AuthController handles basic sign-in, two-factor authentication, password reset, and password change flows, including a delay in the forgot password endpoint to mitigate timing attacks. The JWTAuthenticationController provides endpoints for JWT-based sign-in, token refresh, and sign-out. The UsersController allows administrators to create, update, and unlock users, as well as generate password reset tokens. The TFAController enables users to manage their two-factor authentication settings, including generating keys, enabling/disabling TFA, and generating recovery codes. These controllers implement the core authentication and user management capabilities of the application.

src/OneBeyond.Studio.Obelisk.WebApi/Controllers · high confidence

New background worker for processing domain events and cleaning up JWT tokens

A new Azure Functions-based worker service has been introduced to handle background tasks. This includes a domain event processor that listens to a message queue to dispatch domain events, and a scheduled timer job that clears down expired JWT tokens. The worker is configured with environment-specific settings for email sending (using either a local folder or SendGrid) and includes logging and dependency injection setup for the application's shared kernel.

src/OneBeyond.Studio.Obelisk.Workers · high confidence

New exception handling and security headers middleware

The API now includes dedicated middleware components for standardized error responses and security headers. The ErrorResultGeneratorMiddleware catches specific application exceptions (ValidationException, OneBeyondException) to return structured ProblemDetails JSON responses with appropriate HTTP status codes (400, 404) and trace IDs. Additionally, a new SecurityHeadersMiddleware enforces security headers (e.g., X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security) via a configurable policy, and an ExceptionHandlingMiddleware maps domain and application exceptions to specific HTTP status codes (400, 401, 403, 500). A UnitOfWorkScope middleware was also added to manage database unit of work lifecycles per request.

src/OneBeyond.Studio.Obelisk.WebApi/Middlewares · high confidence

Behavioural changes

Added ObeliskInfrastructureException for infrastructure-level error handling

A new exception class, ObeliskInfrastructureException, has been introduced in the Obelisk.Infrastructure layer. This class inherits from the existing OneBeyondException base and provides constructors for standard error messaging and inner exception handling, enabling more specific error categorization for infrastructure-related failures.

src/OneBeyond.Studio.Obelisk.Infrastructure/Exceptions · high confidence

Added default service health check endpoints

The service defaults library now registers and maps default health check endpoints at /health/ready and /health/live. This ensures that all environments expose these standard health check routes, allowing external systems or orchestrators to verify the application's readiness and liveness status.

src/OneBeyond.Studio.Obelisk.ServiceDefaults · high confidence

Database migration for authentication token replay attack mitigation

A new database migration named 'AuthTokenReplayAttack' is introduced to support security improvements against token replay attacks. This migration modifies the 'Users' table by constraining the 'Discriminator' column to a maximum length of 8 characters and adds a 'Refreshed' boolean column to the 'AuthTokens' table, along with a corresponding index on the 'RefreshToken' column.

src/OneBeyond.Studio.Obelisk.Infrastructure/Migrations · medium confidence

Email layout template is now loaded from the database at startup

The application now registers the email layout template from the database during startup, using the latest template if available or falling back to a default. This change moves email template management from static code to a database-driven approach, allowing layout updates without code changes.

src/OneBeyond.Studio.Obelisk.Infrastructure/Extensions · medium confidence

Email templates moved to external files with layout support

Email templates for account setup and password reset are now loaded from external HTML files embedded as resources, allowing for easier maintenance and styling. A shared layout template with a header and footer is applied to all emails, and the layout includes a base64-encoded logo image.

src/OneBeyond.Studio.Obelisk.Domain/Features/EmailTemplates · medium confidence

Migrate solution to slnx format and centralize project configuration

The solution has been migrated from the legacy .sln format to the modern .slnx (XML-based) format, which now explicitly defines the project structure and dependencies. Additionally, common project properties such as the .NET 10.0 target framework, language version, and nullable reference types are now centrally managed via a new Directory.Build.props file, ensuring consistent build behavior across all projects in the repository.

(repo-wide) · high confidence

Migrated authentication logic to a new command-handler structure

The authentication module has been refactored to use a command-handler pattern for all core identity operations. This includes new handlers for signing in (via password, provider, or JWT), signing out, changing or setting passwords, generating password reset tokens, and updating user details. The implementation introduces a combined authentication scheme that supports both Identity-based cookies and JWT tokens, with specific handling for cross-site cookie requirements and security stamp validation intervals.

src/OneBeyond.Studio.Obelisk.Authentication · high confidence

Native OpenAPI document generation replaces Swagger

The API documentation system has been migrated from Swagger to the native ASP.NET Core OpenAPI implementation. This change introduces a suite of OpenAPI transformers that automatically populate security schemes, handle mixed-source model binding, format SmartEnums, and display authorization requirements in the generated OpenAPI document. Additionally, the API versioning is now reflected in the OpenAPI title and description, and the Swagger UI is configured to automatically fill in the version parameter.

src/OneBeyond.Studio.Obelisk.WebApi · high confidence

New health checks and exception handling middleware

The API now includes dedicated health check endpoints for the SQL Server database, Azure Queue Storage, and Azure Blob Storage (in non-development environments), allowing users to monitor the status of these critical dependencies. Additionally, a new middleware has been added to catch unhandled exceptions during HTTP requests, ensuring that internal server errors return a generic 'unexpected error' message to the user rather than leaking sensitive stack traces or internal details.

src/OneBeyond.Studio.Obelisk.WebApi/Extensions · high confidence

Fixes

Added SignInJwtDto for JWT authentication

A new data transfer object, SignInJwtDto, was added to the WebApi layer to handle username and password credentials for JWT authentication. This change supports the JWT authentication fix by providing a structured model for sign-in requests.

src/OneBeyond.Studio.Obelisk.WebApi/Dto · medium confidence

Test coverage

Added integration tests for the ErrorResultGeneratorMiddleware; Added unit tests for string helper utilities.

Dependencies

Upgrade to .NET 10 and Aspire 13 with centralized package management

The project has been upgraded to .NET 10, with all Microsoft and OneBeyond Studio core libraries updated to version 10.0.x. The solution now uses centralized package management via Directory.Packages.props to define versions for all dependencies, including Aspire 13, OpenTelemetry, and various Azure SDKs. This change simplifies dependency management and aligns the codebase with the latest .NET and Aspire ecosystems.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 65 → 61 (-3.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 95 (+0.8)
  • Architecture 93 → 93 (+0.0)
  • Maturity 62 → 62 (-0.0)
  • Readiness 71 → 66 (-5.4)
  • Security 61 → 65 (+3.6)
  • Domain Modelling 66 → 55 (-10.5)

Resolved (46)

  • Bounded contexts not declared
  • High CVE: MessagePack 2.5.192
  • High CVE: MessagePack 2.5.192
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High IaC: DS-0002 (src/OneBeyond.Studio.Obelisk.Workers/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 26 more

New (93)

  • Base-context workflow trigger runs with an unscoped token
  • CRAP 210: FromMixedSourceOperationTransformer.TransformAsync (src/OneBeyond.Studio.Obelisk.WebApi/OpenApi/FromMixedSourceOperationTransformer.cs)
  • CRAP 42: SecurityHeadersBuilder.AddSecurityPolicyFromConfiguration (src/OneBeyond.Studio.Obelisk.WebApi/Middlewares/Security/SecurityHeadersBuilder.cs)
  • CRAP 56: ExceptionHandlingExtension.HandleDomainException (src/OneBeyond.Studio.Obelisk.WebApi/Middlewares/ExceptionHandling/ExceptionHandlingExtension.cs)
  • CRAP 72: AuthorizeSummaryOperationTransformer.TransformAsync (src/OneBeyond.Studio.Obelisk.WebApi/OpenApi/AuthorizeSummaryOperationTransformer.cs)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (src/OneBeyond.Studio.Obelisk.Application/Features/Users/CommandHandlers/SendResetPasswordEmailHandler.cs)
  • Duplicated block (7 lines × 2) (src/OneBeyond.Studio.Obelisk.Application/Features/Users/CommandHandlers/UnlockUserHandler.cs)
  • Duplicated block (7 lines × 6) (src/OneBeyond.Studio.Obelisk.Authentication/OneBeyond.Studio.Obelisk.Authentication.Application/CommandHandlers/ChangePasswordHandler.cs)
  • Duplicated block (9 lines × 2) (src/OneBeyond.Studio.Obelisk.Application/Features/Users/Dto/GetUserDto.cs)
  • High CVE: MessagePack 2.5.192
  • High CVE: System.Security.Cryptography.Xml 10.0.0
  • High IaC: WD-COMPOSE-0002 (devops/Docker/docker-compose.yaml)
  • High IaC: WD-COMPOSE-0002 (devops/Docker/docker-compose.yaml)
  • High IaC: WD-COMPOSE-0002 (devops/Docker/docker-compose.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 73 more

API surface

  • Unchanged — 25 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

onebeyond/onebeyond-studio-obelisk was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e972870df6ad851fe65b064d5851283a67ec4a9c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.