Skip to content
CAI
Software that uses CAICheck a score

sahat/hackathon-starter

44.4

Weak · 1 October 2026

6.4k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive Node.js boilerplate application designed to demonstrate modern web development practices, with a strong emphasis on AI integration and robust authentication. It provides ready-to-use examples for building AI agents, Retrieval-Augmented Generation (RAG) pipelines, and computer vision features using LangChain and various LLM providers. The platform also serves as a reference implementation for secure user management, supporting passkeys, multi-factor authentication, and numerous OAuth providers, all built on a Bootstrap 5 frontend with dark mode support.

How it got here

2013 — v10.0.0 AI and Auth overhaul

6 changes.

This period marked the release of version 10.0.0, introducing major architectural upgrades including AI agent capabilities with RAG, comprehensive passkey and OAuth authentication, and a migration to Node 24 and Express 5. The update also modernized the codebase by removing legacy dependencies, enhancing security with session management and rate limiting, and adding user-facing features like dark mode and cookie consent.

2015–2016 — Bootstrap 5 migration and dark mode support

5 changes.

The project migrated its frontend infrastructure from Bootstrap 4 to Bootstrap 5, introducing comprehensive native dark mode support across layouts, partials, and API examples. This period also focused on modernizing user authentication by integrating passkeys, passwordless login, and multi-factor authentication, while enhancing security and compliance through reCAPTCHA and consent-based analytics.

2020–2025 — AI integration and test infrastructure

8 changes.

This period focused on expanding the application's capabilities with new AI features, including agent, RAG, vision, and classification demos, while simultaneously establishing a robust testing framework. Significant effort was dedicated to comprehensive end-to-end testing using Playwright and fixing dependency deprecations to ensure long-term stability and code quality.

Features

Account management now supports passkeys, passwordless login, and multi-factor authentication

The account views have been updated to support modern authentication methods. Users can now sign up and log in without a password (passwordless via email link), and the login page includes a button to authenticate using passkeys or biometrics (WebAuthn) where supported. The profile page now allows users to enable, manage, and remove biometric login credentials, as well as configure two-factor authentication using either an authenticator app (TOTP) or email verification codes. Additionally, the signup flow includes an option to create an account without a password, and the account deletion process now requires explicit confirmation.

views/account · high confidence

Add pre-commit hook for linting and testing

A new pre-commit hook has been added to the project to automatically run linting and tests before each commit. The hook executes \npx lint-staged\ to format and lint only the staged files, followed by \npm test\ to run the core test suite, ensuring code quality and stability are maintained at commit time.

.husky · high confidence

Users now have a cookie consent modal that manages analytics and marketing preferences (including Google Consent Mode v2 and Facebook Pixel gating) and a dark mode toggle that persists their theme preference across tabs and syncs with the cookie consent UI.

public/js · high confidence

The public directory now includes dedicated HTML pages for the Privacy Policy and Terms of Use, providing users with clear information on data collection, GDPR compliance, and usage rights. Additionally, a Bootstrap logo SVG and an updated favicon.ico have been added to improve branding consistency.

public · high confidence

Expanded API integration examples with new and updated views

The API examples section now includes dedicated views for Chart.js with Alpha Vantage, Facebook, Foursquare, GIPHY, GitHub, Google Drive, Google Maps, Google Sheets, HERE Maps, Last.fm, Lob, New York Times, PayPal, PubChem, QuickBooks, Web Scraping, Steam, Stripe, Tumblr, and Twilio. The index page has been updated to list all available examples, and specific views like HERE Maps now support dark mode theme switching.

views/api · high confidence

Major v10.0.0 release with AI, authentication, and integration updates

This release introduces a comprehensive suite of new capabilities and architectural improvements. Key additions include an AI Agent boilerplate using LangChain with ReAct reasoning, RAG (Retrieval-Augmented Generation) examples, and various LLM integrations (Groq, Huggingface, OpenAI). Authentication is significantly enhanced with support for passwordless login, passkeys (WebAuthn), 2FA via email/TOTP, and new OAuth providers like Discord and Microsoft. The application now features configurable rate limiting via environment variables, consolidated error handling, and improved session management. Several legacy integrations and dependencies have been removed or updated, including the removal of Pinterest, SendGrid, and lodash, while others like Foursquare and reCAPTCHA have been migrated to newer APIs. The project also adds extensive E2E testing with Playwright and API recording/replay capabilities.

(repo-wide) · high confidence

New AI agent, RAG, and passkey authentication capabilities

This update introduces three major new capabilities to the application. First, it adds a new AI Agent controller (ai-agent.js) that implements a ReAct-style agent using LangChain and Groq, featuring a built-in prompt guard to detect jailbreaks and injections, and persistent memory via MongoDB. Second, it adds a new AI controller (ai.js) that provides a Retrieval-Augmented Generation (RAG) example, allowing users to upload PDF documents which are then chunked, embedded using Hugging Face, and stored in a MongoDB vector search index for semantic querying. Third, it introduces WebAuthn (passkey) support via a new webauthn.js controller, enabling users to register and log in using biometrics or device security keys, alongside a new passwordless login flow via email links in the user controller.

controllers · high confidence

New AI integration examples: Agent, RAG, Vision, and Classification

The AI examples section now features four distinct, consolidated demos. The new AI Agent page provides a customer service chat interface using a LangChain v1 ReAct agent with tool calling, SSE streaming, and MongoDB session persistence. The RAG page demonstrates Retrieval-Augmented Generation using LangChain, Hugging Face embeddings, and MongoDB Atlas Vector Search. The LLM Vision page allows users to capture photos via their device camera and analyze them using the Groq Qwen model. Finally, the LLM Classifier page offers a one-shot text classification example for routing customer messages. These pages replace previous examples and are accessible from the updated AI integration index.

views/ai · high confidence

New session management and enhanced user authentication model

This change introduces a new Session model to manage user sessions, including a method to revoke all valid sessions for a user by validating the user ID against MongoDB ObjectId format to prevent regex injection. The User model has been significantly expanded to support modern authentication features: it now includes fields for WebAuthn (passkeys/biometrics), two-factor authentication (email and TOTP), and email verification. It also adds support for multiple OAuth providers (Discord, Facebook, GitHub, Google, LinkedIn, Microsoft, QuickBooks, Steam, Tumblr, Twitch, X) and stores their respective IDs. The profile section now supports multiple pictures via a Map structure. Security improvements include using @node-rs/bcrypt for password hashing, SHA256 for Gravatar URL generation, and middleware to automatically clear expired tokens (password reset, email verification, login, 2FA) upon save.

models · high confidence

Behavioural changes

Contact form reCAPTCHA integration and dark mode support

The contact form now includes Google reCAPTCHA validation for unauthenticated users, with client-side checks preventing submission if the widget is incomplete. The application layout supports a dark mode that respects the user's system preference or stored choice, applying the appropriate theme class before styles load. Additionally, the layout integrates Google Analytics 4 and Facebook Pixel, gating their execution behind user consent via CookieConsent.

views · high confidence

Enhanced request logging, custom flash messages, and OAuth token revocation support

The application now includes a custom request logger (config/morgan.js) that provides detailed, color-coded logs with parsed user agents and byte counts, while hiding IP addresses in production for privacy. Flash message handling has been replaced with a custom middleware (config/flash.js) to remove unmaintained dependencies, and email sending is now centralized in config/nodemailer.js. Additionally, the system now supports revoking OAuth tokens from providers when unlinking accounts or deleting them, implemented via config/token-revocation.js and integrated into the updated passport configuration.

config · high confidence

Migrate UI components to Bootstrap 5 and add dark mode support

The header, footer, and flash message partials have been rewritten to use Bootstrap 5 classes and JavaScript attributes (such as data-bs-toggle and data-bs-dismiss), replacing the previous Bootstrap 4 structure. The header now includes a dark mode toggle button that switches themes, and the flash messages utilize the new Bootstrap 5 alert styling with a close button. This change updates the visual appearance and interaction behavior of the navigation, footer links, and system notifications to align with the Bootstrap 5 framework.

views/partials · high confidence

Upgrade to Bootstrap 5 and add native dark mode support

The main stylesheet has been migrated from LESS to SCSS and upgraded to Bootstrap 5.3, enabling a native dark mode that respects the user's system preference or explicit choice via a toggle. This change includes specific styling adjustments for social login buttons (Discord, Twitch, Twitter, Google) to ensure brand compliance and visibility, fixes for hardcoded light-background elements in dark mode, and updates to icon display logic for the theme switcher.

public/css · high confidence

Fixes

Patch passport libraries to replace deprecated URL APIs

Applied patches to passport, passport-oauth1, and passport-oauth2 to remove usage of the deprecated Node.js \url\ module. The changes replace \url.parse()\, \url.resolve()\, and \url.format()\ with the modern \URL\ constructor and \URLSearchParams\ API, ensuring compatibility with current Node.js versions and removing deprecation warnings during authentication flows.

patches · high confidence

Test coverage

Added E2E tests for multiple API integrations and AI features; Added Playwright E2E tests for API integrations, file upload, and dark mode; Comprehensive test infrastructure and documentation overhaul; New test tooling for API record/replay and link validation.

Dependencies

Upgrade to version 10.0.0 with Node 24 and major dependency updates

The project has been upgraded to version 10.0.0, requiring Node.js 24.18.0 or later. This release updates core dependencies to their latest major versions, including Express 5, Mongoose 9, MongoDB 7, Stripe 22, and Nodemailer 10. It also introduces new AI capabilities via LangChain (Groq integration), adds support for passkeys using SimpleWebAuthn, and integrates Google Drive and Sheets APIs. Development tooling has been modernized with ESLint 10, Mocha 12, and Playwright 1.63, while legacy packages like jQuery have been updated to version 4.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 47 → 44 (-2.9)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 35 → 36 (+1.3)
  • Architecture 74 → 78 (+4.0)
  • Maturity 60 → 60 (-0.5)
  • Readiness 58 → 44 (-14.0)
  • Security 79 → 64 (-15.2)
  • Domain Modelling 100 → 100 (+0.0)
  • Accessibility 50 → 49 (-0.3)
  • Performance 60 (new)

Resolved (18)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1
  • api.fetchMovieDetails (cognitive 19) (controllers/api.js)
  • api.fetchMovieDetails (cyclomatic 19) (controllers/api.js)
  • getTrakt (cognitive 16) (controllers/api.js)
  • getWikipedia (cognitive 31) (controllers/api.js)
  • getWikipedia (cyclomatic 29) (controllers/api.js)
  • isAuthorized (cognitive 32) (config/passport.js)
  • postAIAgentChat (cognitive 19) (controllers/ai-agent.js)
  • postContact (cognitive 18) (controllers/contact.js)
  • postLogin (cognitive 19) (controllers/user.js)
  • postLogin (cyclomatic 17) (controllers/user.js)
  • postRegisterVerify (cyclomatic 16) (controllers/webauthn.js)
  • postUpdateProfile (cognitive 20) (controllers/user.js)
  • postUpdateProfile (cyclomatic 20) (controllers/user.js)

New (17)

  • Off-boarding risk: anonymized user #1
  • Outdated (npm): @langchain/core
  • Outdated (npm): langchain
  • Outdated (npm): nodemailer
  • Outdated (npm): stripe
  • ai-agent.postAIAgentChat (cognitive 19) (controllers/ai-agent.js)
  • api.getWikipedia (cognitive 31) (controllers/api.js)
  • api.getWikipedia (cyclomatic 29) (controllers/api.js)
  • app.app.use() (cognitive 16) (app.js)
  • contact.postContact (cognitive 18) (controllers/contact.js)
  • passport.isAuthorized (cognitive 32) (config/passport.js)
  • user.getOauthUnlink (cognitive 16) (controllers/user.js)
  • user.postLogin (cognitive 19) (controllers/user.js)
  • user.postLogin (cyclomatic 17) (controllers/user.js)
  • user.postUpdateProfile (cognitive 20) (controllers/user.js)
  • user.postUpdateProfile (cyclomatic 20) (controllers/user.js)
  • webauthn.postRegisterVerify (cyclomatic 16) (controllers/webauthn.js)

Changes since last survey

  • 14 commits — 14 feature/other, 0 fixes

By area

  • (root) — 12 commits
  • test/fixtures — 2 commits

Notable commits

  • change: chore(deps): bump @simplewebauthn/server in the patch-updates group (#1766)
  • change: chore(deps): bump @simplewebauthn/server in the patch-updates group (#1777)
  • change: chore(deps): bump mongoose in the patch-updates group (#1770)
  • change: chore(deps): bump multer from 2.3.0 to 2.4.0 in the minor-updates group (#1767)
  • change: chore(deps): bump nodemailer (#1768)
  • change: chore(deps): bump sass in the minor-updates group (#1774)
  • change: chore(deps): bump the major-updates group with 2 updates (#1769)
  • change: chore(deps): bump the patch-updates group with 3 updates (#1772)
  • change: chore(deps): bump the patch-updates group with 5 updates (#1775)
  • change: chore(deps-dev): bump lint-staged in the minor-updates group (#1776)
  • change: chore(deps-dev): bump supertest in the minor-updates group (#1773)
  • change: chore: update dependencies
  • change: chore: update nock
  • change: feat!: remove trakt api example

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sahat/hackathon-starter was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d390f8184ad60a587f182cb32b00c7a4389748b1 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.