Rayato159/quests-tracker
51.5
Adequate · 21 September 2026
2.3k
lines of production code
Rust
primary language
4
measurements over time
What this system is
Features
Add authentication, quest management, and crew switchboard endpoints
The infrastructure layer now exposes HTTP endpoints for user authentication (login and token refresh for both adventurers and guild commanders), quest operations (add, edit, remove), journey ledger status updates, and crew switchboard actions (join, leave). These are backed by new Axum routers, middleware for JWT-based authorization, and PostgreSQL repositories for data access. A graceful shutdown signal and a health check endpoint are also added.
src/infrastructure · high confidence
Add database migration scripts for game entities
Added SQL migration scripts to initialize the database schema. The 'up' script creates tables for quests, adventurers, guild commanders, and the junction table linking quests to adventurers, along with necessary foreign key constraints. The 'down' script provides the corresponding cleanup by dropping these tables.
assets · high confidence
Added domain entities for adventurers, guild commanders, and quests
New domain entity structs have been introduced to represent core game data: AdventurerEntity and RegisterAdventurerEntity for the adventurers table, GuildCommanderEntity and RegisterGuildCommanderEntity for the guild\_commanders table, and QuestEntity, AddQuestEntity, and EditQuestEntity for the quests table. These structs define the data models and database mappings for these entities, enabling the application layer to interact with the database using Diesel.
src/domain/entities · medium confidence
Introduce structured configuration loading from environment variables
The application now loads configuration from environment variables using the \dotenvy\ crate. This introduces new structs for server settings (port, body limit, timeout), database URL, and JWT secrets for adventurers and guild commanders, all parsed from the environment. It also adds a \Stage\ enum to represent the current environment (Local, Development, Production).
src/config · medium confidence
Introduces domain value objects for quests, adventurers, and guild commanders
The src/domain/value\_objects module now includes new Rust structs and enums that define the data structures for quest management, adventurer registration, guild commander registration, and quest status filtering. These value objects serve as the domain layer's interface for creating, editing, and querying quests, as well as linking adventurers to quests. The changes add serialization/deserialization support (via serde) and database mapping (via diesel) to these models, enabling the application layer to interact with the domain entities.
_src/domain/value\objects · high confidence
New application use cases for adventurers, authentication, and quests
The application layer now includes use cases for registering and managing adventurers and guild commanders, handling login and token refresh for both user types, and managing quest operations such as joining, leaving, and tracking journey status. These additions provide the core business logic for user authentication, quest participation, and quest lifecycle management.
src/application · high confidence
New domain repository interfaces for core game entities
The application layer now exposes repository interfaces for managing adventurers, guild commanders, quests, and journey states. Specifically, the system introduces \AdventurersRepository\ for registering and finding adventurers, \GuildCommandersRepository\ for commander registration and lookup, \QuestOpsRepository\ for adding, editing, and removing quests, and \QuestViewingRepository\ for viewing quest details and board listings. Additionally, \JourneyLedgerRepository\ tracks quest completion or failure states, while \CrewSwitchboardRepository\ handles joining or leaving quest-adventurer junctions. A \TransactionProvider\ is also introduced to manage database transactions.
src/domain/repositories · high confidence
Behavioural changes
Initialize application with Postgres and HTTP server
The application now initializes by loading environment variables, establishing a connection to a Postgres database, and starting an HTTP server. Previously, the main entry point only printed a message to the console; it now integrates configuration loading, database connection pooling, and server startup logic.
src · medium confidence
Removal of domain services
The services module has been removed from the domain layer. This eliminates the services layer from the domain, leaving only entities, repositories, and value objects as the primary domain components.
src/domain · medium confidence
Removed obsolete config loader files
The 'config' directory's 'dotenvy\_loader.rs' and 'mod.rs' files have been deleted. This removes the previous configuration loading mechanism, likely as part of a broader refactor to a new config folder location.
config · medium confidence
Dependencies
Update Rust edition and add new dependencies
The project has been upgraded to the 2024 Rust edition. Several new dependencies have been added to support application features: \anyhow\ for error handling, \argon2\ for password hashing, \rand\ for random number generation, and \jsonwebtoken\ for JWT handling. Additionally, the \diesel\ dependency has been updated to include the \r2d2\ feature, and \chrono\ has been updated to include the \serde\ feature. The \axum-extra\ crate has also been added.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 48 → 52 (+3.0)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 97 (-1.3)
- Architecture 100 → 78 (-21.9)
- Maturity 56 → 51 (-4.9)
- Readiness 21 → 33 (+11.4)
- Security 73 → 78 (+5.0)
- Domain Modelling 100 → 100 (+0.0)
Resolved (24)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High vulnerability: [GHSA redacted] (Cargo.lock)
- Medium CVE: [GHSA redacted] (Cargo.lock)
- Medium CVE: [GHSA redacted] (Cargo.lock)
- Medium CVE: [GHSA redacted] (Cargo.lock)
- Medium CVE: [GHSA redacted] (Cargo.lock)
- Medium CVE: RUSTSEC-2025-0055 (Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2025-0023 (Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0097 (Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0134 (Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0135 (Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0190 (Cargo.lock)
- No exposed public API
- Secret: jwt (quest_tracker.postman_collection.json)
- Secret: jwt (quest_tracker.postman_collection.json)
- Secret: jwt (quest_tracker.postman_collection.json)
- Secret: jwt (quest_tracker.postman_collection.json)
- Secret: jwt (quest_tracker.postman_collection.json)
- Secret: jwt (quest_tracker.postman_collection.json)
- …and 4 more
New (46)
- Duplicated block (12 lines × 2) (src/application/usecases/authentication.rs)
- Duplicated block (14 lines × 2) (src/application/usecases/adventurers.rs)
- Duplicated block (14 lines × 3) (src/application/usecases/authentication.rs)
- Duplicated block (15 lines × 2) (src/infrastructure/axum_http/middleware.rs)
- Duplicated block (19 lines × 4) (src/infrastructure/axum_http/routers/authentication.rs)
- Duplicated block (5 lines × 2) (src/infrastructure/axum_http/middleware.rs)
- Duplicated block (6 lines × 2) (src/application/usecases/authentication.rs)
- Duplicated block (6 lines × 3) (src/infrastructure/postgres/repositories/journey_ledger.rs)
- Duplicated block (6 lines × 4) (src/infrastructure/axum_http/routers/authentication.rs)
- Duplicated block (6–8 lines × 2) (src/application/usecases/authentication.rs)
- Duplicated block (8 lines × 2) (src/infrastructure/axum_http/routers/adventures.rs)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- Inconsistent parameter ordering and inclusion. 'add' takes the owner ID as the first parameter, while 'edit' and 'remove' take the resource ID first. Additionally, 'add' does not require the owner ID in the model (it's passed separately), whereas 'edit' and 'remove' require the owner ID for authorization checks. This creates a confusing API surface where the caller must remember different argument orders and requirements for similar CRUD operations.
- Leaked implementation details and test artifacts in public API. The UseCase exposes a method named 'join_and_delete_transaction' which implies a specific transactional behavior rather than a business intent (likely 'join' or 'transfer'). Furthermore, the Repository interface exposes methods explicitly named 'for_transaction_test_1' and 'for_transaction_test_2', which are clearly internal testing helpers that should not be part of the domain repository contract.
- Medium CVE: [GHSA redacted] (Cargo.lock)
- Medium CVE: [GHSA redacted] (Cargo.lock)
- Medium CVE: [GHSA redacted] (Cargo.lock)
- Medium CVE: [GHSA redacted] (Cargo.lock)
- Medium CVE: RUSTSEC-2025-0055 (Cargo.lock)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- …and 26 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Rayato159/quests-tracker was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9ef1fc8289346114972eda42bb562fc4527142c6 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.