Skip to content
CAI
Software that uses CAICheck a score

pcruz1905/ddd-starter-kit

69.1

Adequate · 21 September 2026

7.6k

lines of production code

Java

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a secure authentication service that manages user identity, session management, and access control. It provides a complete authentication flow including registration, login, and password management, secured by JWT-based sessions and robust password hashing. The architecture enforces fine-grained authorization through a role-based permission model and protects endpoints with rate limiting and structured audit logging.

Features

Add composable dynamic query DSL and persistence layer for authentication

Developers can now build dynamic SQL queries using a composable \Condition\ and \Predicates\ API, replacing manual string concatenation with safe, validated predicates. The \Condition\ class supports logical composition (\and\, \or\, \not\) and handles bind parameter collisions. Additionally, the adapter now includes persistence implementations for authentication: \JdbiCredentialsRepository\ and \JdbiRefreshTokenRepository\ with corresponding row mappers (\CredentialsRow\, \RefreshTokenRow\) and database migrations (V11, V12, V13) for \credentials\ and \refresh\_tokens\ tables. A schema drift test (\SchemaDriftIT\) ensures row records stay in sync with the database schema.

adapter-persistence-jdbc · high confidence

Introduces domain models and interfaces for authentication and authorization

The domain layer now includes the core building blocks for user authentication and access control. This includes the Credentials aggregate for managing password hashes, the RefreshToken aggregate for secure session management, and the TokenIssuer interface for handling short-lived access tokens. The system also introduces a sealed Role model with Admin, Member, and Viewer variants, each carrying specific Permissions that define fine-grained access rights. These domain components are supported by corresponding repository ports and a PasswordHasher interface, enabling the implementation of login, registration, and token-refresh flows.

domain · high confidence

Introduces secure authentication primitives: Argon2id password hashing, HMAC refresh tokens, and HS256 JWT issuance

The adapter-auth module now provides production-grade implementations for core authentication capabilities. Passwords are hashed using Argon2id with OWASP-aligned parameters (19 MiB memory, 2 iterations), featuring constant-time verification and automatic rehashing for weaker legacy hashes. Refresh tokens are generated using a cryptographically secure random source and hashed via HMAC-SHA256, ensuring each token is unique and deterministic for lookup. Access tokens are issued as HS256-signed JWTs containing user ID, role, and expiration, with validation that checks signature, issuer, and expiration without throwing exceptions. Comprehensive unit tests verify correctness, security properties (e.g., no timing leaks, unique salts, deterministic hashing), and error handling for all three components.

adapter-auth · high confidence

New /v1/auth endpoints for registration, login, refresh, logout, and password change

The HTTP adapter now exposes a full authentication surface: POST /v1/auth/{register,login,refresh,logout,change-password} and GET /v1/auth/me. The AuthRoutes class wires these endpoints to their respective use cases, using a new JwtBearerAuth helper to validate Bearer tokens and enforce permissions. An in-memory, IP-keyed rate limiter (AuthRateLimiter) protects the login and register endpoints (5 attempts per 15 minutes for login, 3 per hour for registration). Error mapping (AuthErrorMapper) converts domain auth errors into standardized HTTP 401/403/422/409 responses. Tests cover the rate limiter's capacity and isolation logic, as well as the JWT bearer authentication and permission-gating behavior.

adapter-http · high confidence

Behavioural changes

Added JWT-based authentication routes and token lifecycle configuration

The application now exposes HTTP routes for authentication, including JWT bearer token issuance and validation. The bootstrap layer has been updated to wire the necessary components: access and refresh token time-to-live (TTL) settings are configurable via environment variables (MYFLUXO\_ACCESS\_TOKEN\_TTL\_MINUTES, MYFLUXO\_REFRESH\_TOKEN\_TTL\_DAYS), and the application registers a JWT token issuer and HMAC-SHA256 refresh token strategy. The HTTP server is now initialized with both user and authentication routes, enabling the new auth flow.

bootstrap · high confidence

Introduces full authentication flow with JWT-based sessions and structured audit logging

Users can now register, log in, refresh sessions, log out, and change passwords through a new auth system. The implementation issues short-lived access tokens and longer-lived refresh tokens, with automatic rotation and theft detection via family revocation. Every auth event is recorded in a dedicated audit log channel (myfluxo.audit.auth) for security monitoring. The login path includes timing-attack defenses, and password changes revoke all other active sessions.

application · high confidence

Dependencies

Added auth adapter with JWT, password hashing, and rate limiting dependencies

The project now includes the 'myfluxo-adapter-auth' module, introducing dependencies for JWT handling (jjwt 0.12.6), Argon2id password hashing (password4j 1.8.2), and in-memory rate limiting (bucket4j 8.10.1). These libraries are wired into the build to support authentication features such as access token signing, secure password storage, and endpoint protection.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 67 → 69 (+1.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 99 (+0.7)
  • Architecture 100 → 77 (-23.3)
  • Maturity 75 → 75 (+0.0)
  • Readiness 50 → 54 (+4.5)
  • Security 80 → 100 (+20.3)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (17)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (application/src/main/java/myfluxo/application/auth/usecases/Login.java)
  • Duplicated block (5 lines × 2) (adapter-http/src/main/java/myfluxo/adapter/http/auth/AuthRoutes.java)
  • Duplicated block (6 lines × 2) (adapter-http/src/main/java/myfluxo/adapter/http/auth/AuthRoutes.java)
  • Duplicated block (6 lines × 2) (application/src/main/java/myfluxo/application/auth/usecases/ChangePassword.java)
  • Duplicated block (6 lines × 2) (domain/src/main/java/myfluxo/domain/auth/RefreshToken.java)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient

New (46)

  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: contradicts the code (docs/schema-drift.md)
  • Documentation: no architecture or design documentation (docs/auth.md)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (5 lines × 2) (adapter-http/src/main/java/myfluxo/adapter/http/auth/AuthRoutes.java)
  • Duplicated block (6 lines × 2) (adapter-http/src/main/java/myfluxo/adapter/http/auth/AuthRoutes.java)
  • Duplicated block (6 lines × 2) (domain/src/main/java/myfluxo/domain/auth/RefreshToken.java)
  • Duplicated block (7 lines × 2) (application/src/main/java/myfluxo/application/auth/AccessTokenTtl.java)
  • Duplicated block (7 lines × 2) (domain/src/main/java/myfluxo/domain/auth/model/PasswordHash.java)
  • Duplicated block (7 lines × 2) (domain/src/main/java/myfluxo/domain/auth/model/RefreshTokenId.java)
  • Duplicated block (7 lines × 3) (adapter-persistence-jdbc/src/main/java/myfluxo/adapter/persistence/jdbc/auth/JdbiRefreshTokenRepository.java)
  • High interface indirection
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No ADRs found
  • No assertions: catalogConstants_areConsistent (domain/src/test/java/myfluxo/domain/auth/model/PermissionTest.java)
  • No assertions: check_reportsDriftForDeliberatelyMismatchedTable (adapter-persistence-jdbc/src/test/java/myfluxo/adapter/persistence/jdbc/SchemaDriftIT.java)
  • No assertions: ctor_acceptsExactly32ByteSecret (adapter-auth/src/test/java/myfluxo/adapter/auth/HmacRefreshTokenStrategyTest.java)
  • No assertions: delete_unknownId_isSilentNoOp (adapter-persistence-jdbc/src/test/java/myfluxo/adapter/persistence/jdbc/JdbiAggregateRepositoryIT.java)
  • …and 26 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

pcruz1905/ddd-starter-kit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 15a5be38b573f44d218fcd86771224c866684425 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.