Skip to content
CAI
Software that uses CAICheck a score

pauljamescleary/scala-pet-store

62.0

Adequate · 28 September 2026

1.4k

lines of production code

Scala

with Python

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Scala-based REST API for managing a pet store, built on the TypeLevel stack including Http4s, Doobie, and TSec. It provides CRUD operations for pets, orders, and users, secured with JWT-based authentication and role-based access control. The architecture separates domain logic from infrastructure, supporting both in-memory storage for development and H2 database persistence via Flyway migrations.

Features

Initial configuration for logging and server/database settings

The application now includes default configuration files for logging and runtime settings. Logback is configured to output colored logs to the console, and the reference configuration defines default values for the H2 in-memory database (including a connection pool size of 10) and the HTTP server (binding to 0.0.0.0 on port 8080).

src/main/resources · high confidence

Initial project scaffolding and documentation

This change introduces the foundational structure for the Scala Pet Store project. It adds essential documentation files including a comprehensive README detailing the TypeLevel stack (http4s, Circe, Doobie, Cats), an Apache 2.0 LICENSE, a Code of Conduct, and an AUTHORS file listing maintainers and contributors. It also establishes development and testing infrastructure by adding a \.scalafmt.conf\ for code formatting, a \.mergify.yml\ for automated dependency PR merging, a \.gitignore\ for build artifacts, and shell scripts (\build.sh\, \post-pet.sh\) alongside a sample \pet.json\ to facilitate functional testing against the API.

(repo-wide) · high confidence

Initial server entry point with HTTP4s, Doobie, and TSec authentication

The application now includes a main server entry point (Server.scala) that bootstraps the HTTP service using Http4s Blaze. This server integrates domain services for pets, users, and orders, backed by Doobie for database access and Flyway for migrations. It implements authentication and password hashing using the TSec library (HMACSHA256 and BCrypt) and configures the server host and port via external configuration.

src/main/scala/io/github/pauljamescleary/petstore · high confidence

Introduce in-memory repository implementations for Orders, Pets, and Users

This change adds new in-memory interpreter classes for the Order, Pet, and User domain aggregates, replacing previous ad-hoc or missing storage logic with explicit, typed repository implementations. The OrderRepositoryInMemoryInterpreter provides basic create, read, and delete operations using a concurrent TrieMap. The PetRepositoryInMemoryInterpreter expands on this with update, find-by-name-and-category, list with pagination, and filter-by-status/tag capabilities. The UserRepositoryInMemoryInterpreter integrates with TSec's IdentityStore to support user lookup by username and deletion by username, while also handling standard CRUD operations. These components collectively provide a complete, in-memory data layer for the pet store's core entities, enabling local development and testing without external database dependencies.

src/main/scala/io/github/pauljamescleary/petstore/infrastructure/repository/inmemory · high confidence

Introduces structured domain models and authentication support

This change adds core domain entities and configuration structures to the application, including Pet, Order, User, and Role models, along with specific status enums (PetStatus, OrderStatus) using enumeratum. It introduces a new authentication domain layer with LoginRequest and SignupRequest classes that integrate with TSec for password hashing, and defines a ValidationError trait to handle domain-specific errors. Additionally, it establishes the DatabaseConfig and PetStoreConfig case classes to structure application settings for database connections and server configuration.

repository · high confidence

Behavioural changes

Database schema updates for user authentication and role management

The database schema has been updated to support secure user authentication and role-based access. The initial setup (V1) introduced tables for pets, orders, and users. Migration V2 renamed the 'PASSWORD' column in the USERS table to 'HASH' to reflect secure password storage practices. Migration V3 added a JWT table for managing authentication tokens, linked to users, and modified the ORDERS table to include a USER\_ID foreign key, associating orders with specific users. Additionally, a 'ROLE' column was added to the USERS table with a default value of 'Customer'.

src/main/resources/db · high confidence

JWT-based authentication with role-based access control

The authentication module now uses TSec to provide JWT-based authentication with role-based access control (RBAC). This introduces bearer token authentication with a 1-hour expiry, backed by a token store and user identity store. The system supports two authorization levels: 'allRoles' for any authenticated user and 'adminOnly' restricted to users with the Admin role. The implementation leverages TSec's JWT authenticator and RBAC services to secure API endpoints.

src/main/scala/io/github/pauljamescleary/petstore/domain/authentication · high confidence

Migrate authentication to TSec with JWT-based security

The infrastructure endpoints now use TSec for authentication, replacing previous mechanisms with JWT-based security. This change introduces \JWTMacAlgo\ constraints on endpoint classes and utilizes \SecuredRequestHandler\ and \AugmentedJWT\ for request handling. The User endpoints now include a login flow that validates passwords using \PasswordHasher\ and issues JWT tokens, while other endpoints (Pet, Order, User management) require authentication via \asAuthed\ directives, enforcing role-based access control (e.g., admin-only operations). Pagination helpers are also extracted to a dedicated object for reuse across authenticated endpoints.

src/main/scala/io/github/pauljamescleary/petstore/infrastructure/endpoint · high confidence

Migrate configuration decoding to circe-config

The application's configuration loading mechanism has been refactored to use circe-config, replacing the previous pureconfig implementation. This change updates the internal configuration package to derive Circe decoders for server, database, and pet store settings, ensuring configuration parsing relies on the new library.

src/main/scala/io/github/pauljamescleary/petstore/config · high confidence

New Doobie-based repository implementations for all domain entities

The infrastructure layer now uses Doobie to provide database access for Pets, Orders, Users, and Authentication tokens. This introduces specific repository interpreters (DoobiePetRepositoryInterpreter, DoobieOrderRepositoryInterpreter, DoobieUserRepositoryInterpreter, and DoobieAuthRepositoryInterpreter) that handle CRUD operations and authentication backing store logic. The implementation includes SQL pagination support via a dedicated SQLPagination object and custom type mappings for domain-specific fields like PetStatus, OrderStatus, and User Role.

src/main/scala/io/github/pauljamescleary/petstore/infrastructure/repository/doobie · high confidence

Refactor user domain into explicit validation and repository algebra layers

The user management logic has been restructured to separate concerns: a new \UserRepositoryAlgebra\ defines the persistence interface (create, update, get, delete, list, and username-based lookup), while a dedicated \UserValidationAlgebra\ and its \UserValidationInterpreter\ handle business rules such as preventing duplicate usernames and verifying user existence before updates. The \UserService\ now orchestrates these layers, ensuring that operations like creating or updating a user are validated against the repository state before execution, resulting in clearer error handling and more maintainable domain code.

src/main/scala/io/github/pauljamescleary/petstore/domain/users · high confidence

Refactored order domain into explicit repository algebra and service layer

The order domain logic has been restructured to separate concerns: a new \OrderRepositoryAlgebra\ trait defines the persistence interface (create, get, delete), and a new \OrderService\ class implements the business logic using this repository. The service now explicitly handles order placement, retrieval with error mapping via \EitherT\, and deletion, providing a cleaner, more testable structure for order operations.

src/main/scala/io/github/pauljamescleary/petstore/domain/orders · high confidence

Refactored pet domain into explicit repository and validation algebras

The pet domain logic has been restructured to separate concerns, introducing dedicated \PetRepositoryAlgebra\ and \PetValidationAlgebra\ traits alongside their implementations. This change replaces previous implicit or monolithic storage semantics with explicit \create\ and \update\ operations in the repository layer, while the \PetService\ now strictly coordinates these repositories with validation checks (such as ensuring a pet does not already exist or that it exists before updating) using \EitherT\ for error handling.

src/main/scala/io/github/pauljamescleary/petstore/domain/pets · high confidence

Test coverage

Added Python 3 functional test suite for the Pet Store API; Added endpoint integration tests for authentication, users, pets, and orders; Added functional live tests for user, pet, and order management; Added property-based test arbitraries for domain models and authentication; Added query type-checking tests for Doobie repository layer.

Dependencies

Initial dependency configuration for Scala Pet Store

The project build is initialized with a comprehensive set of Scala dependencies, including Cats 2.6.1, Circe 0.14.1, Doobie 0.13.4, Http4s 0.21.28, and Tsec 0.2.1 for authentication, alongside Flyway 7.15.0 for database migrations. The build also configures testing libraries (ScalaTest 3.2.9, ScalaCheck 1.15.4) and enables plugins for formatting, Docker packaging, and microsite generation. Additionally, Python functional test requirements are defined, specifying pytest 3.0.6, pyhamcrest 1.8.0, and requests.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 60 → 62 (+2.5)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 55 → 55 (+0.0)
  • Readiness 50 → 55 (+5.0)
  • Security 83 → 85 (+2.3)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (1)

  • Documentation: no installation or build instructions (README.md)

New (5)

  • No ADRs found
  • Outdated: mock
  • Outdated: pyformance
  • Outdated: pyhamcrest
  • Outdated: pytest

Architecture

  • Unchanged — 0 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

pauljamescleary/scala-pet-store was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a4391027771146daaa4b5a6599d36e6462d645b3 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.