Skip to content
CAI
Software that uses CAICheck a score

ricomonster/node-ddd

51.3

Adequate · 20 September 2026

843

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Node.js backend service built on a Domain-Driven Design architecture, providing user authentication and management capabilities. It exposes a secure REST API for user registration and login, utilizing JWT-based authorization to protect endpoints. The application manages data persistence through a Sequelize ORM layer and handles security concerns such as password hashing and token validation.

Features

Added domain models for User and authentication inputs

Introduced new domain entities in the \src/domain\ directory to support user management and authentication flows. The \User\ model defines core user attributes including identity, status, and timestamps, while the \auth\ subdirectory now contains \Login\ and \Register\ models that enforce validation rules for email and password fields required during sign-in and account creation.

src/domain · high confidence

Initial infrastructure for user authentication and database management

This change introduces the core infrastructure components required for user authentication and data persistence. It adds a Sequelize-based database connection layer, including a migration to create a 'users' table with fields for name, email, and password. An encryption utility using bcrypt is provided for password hashing and verification, while a JWT wrapper handles token signing and validation. The system includes a User model, a BaseRepository for generic database operations (create, find, findById), and specific repositories (AuthRepository, UserRepository) to manage authentication logic and user data access.

src/infra · high confidence

Initial project scaffolding and configuration

This change establishes the foundational structure for the Node DDD Boilerplate. It introduces configuration files for code style (.editorconfig), linting (replacing .eslintrc with standard style references in README), and test coverage (.nycrc). It adds environment variable templates (.env.example, env.example.yml) for local and serverless development, including database connection settings. The entry also includes the initial README documentation, an MIT license, a .gitignore update, and a modification to index.js to resolve and start a 'server' instance from the container instead of an 'app' instance, reflecting the initial architectural setup.

(repo-wide) · high confidence

Architecture

Adopts Awilix for dependency injection with automatic module loading

The application's dependency injection system has been replaced with Awilix, enabling automatic registration of application components via glob patterns (app, authentication, encryption, and repositories) while explicitly registering configuration, models, and the HTTP server. This change introduces a \scopePerRequest\ middleware to ensure that dependencies are resolved per HTTP request, supporting better state isolation and lifecycle management for services like repositories and authentication handlers.

src · high confidence

Behavioural changes

Centralized configuration for database, JWT, and environment settings

The application now uses a unified configuration system in the config directory to manage runtime settings. This includes dynamic database connection details (username, password, host, dialect, port) loaded from environment variables, JWT authentication parameters (secret and TTL), and general application settings like the environment mode, debug flag, and server port. The configuration automatically resolves the environment (development, test, production) based on NODE\_ENV and ensures database configuration is present before starting.

config · high confidence

HTTP interface refactored to support authentication and structured routing

The HTTP interface has been restructured to introduce a full authentication workflow and a more modular routing system. The previous monolithic server and router files have been replaced with a new \Server\ class that integrates a container middleware and a centralized route configuration. This change introduces specific endpoints for user registration and login (\/auth/register\, \/auth/login\) via new \AuthController\ and \LoginAuth\/\RegisterAuth\ classes, which handle validation, password encryption, and JWT token generation. Additionally, a new \authorize\ middleware has been added to protect routes by validating JWT tokens and attaching user data to the request context, replacing the previous generic 'Hello world' response with a secure, extensible API structure.

src/interfaces · high confidence

Removal of default public stylesheet

The default stylesheet located at public/stylesheets/style.css has been removed from the application. This file previously defined global body padding and link colors; its removal means these default styles are no longer applied to the public-facing pages.

public · high confidence

Removal of legacy bin/www server entry point

The traditional Express application entry point located at bin/www has been removed. This file previously handled HTTP server creation, port normalization, and error/listening event handling; its deletion indicates that the application's startup logic has been refactored or moved elsewhere, likely as part of the broader effort to convert functionalities into classes.

bin · high confidence

Test coverage

Added unit tests for authentication logic; Initial unit test suite for domain and infrastructure layers.

Dependencies

Migrated from Yarn to npm and upgraded core dependencies

The project has switched its package manager from Yarn to npm, replacing the deleted yarn.lock with a new package-lock.json. This change accompanies a significant upgrade of the dependency tree: the application version is set to 1.0.0, and key libraries such as Express, Sequelize, and Awilix have been updated to newer major or minor versions. Additionally, new dependencies for authentication (bcrypt, jsonwebtoken), database drivers (mysql2, pg), and testing (Mocha, Chai, Nyc) have been added, while older tools like Jade and ESLint configurations have been removed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 50 → 51 (+1.5)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 46 → 46 (+0.4)
  • Architecture 69 → 69 (+0.0)
  • Maturity 61 → 61 (+0.0)
  • Readiness 42 → 44 (+2.0)
  • Security 68 → 78 (+10.3)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (59)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — no supported dependency manifest was read
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 39 more

New (59)

  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 39 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ricomonster/node-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 96ba6f0bd957a3f83e372ccd65fb987f63a1078b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.