Skip to content
CAI
Software that uses CAICheck a score

sayeed1999/home

42.4

Weak · 21 September 2026

3k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a microservices-based platform comprising an API gateway, an authentication service, and specialized services for home (social feed), e-commerce, and real-time chat. The architecture relies on asynchronous event-driven communication via message queues to synchronize user lifecycle events across services. Core capabilities include user management, social networking features like posts and comments, product catalog management, and WebSocket-based messaging.

Features

API Gateway initializes with proxy middleware for backend services

The API Gateway has been initialized with a new proxy middleware configuration that routes requests to backend microservices. Specifically, requests to /auth, /home, /ecom, and /chat are now proxied to their respective services running on ports 4001, 4002, 4004, and 4005. This establishes the core routing logic for the gateway, allowing it to act as a single entry point for these specific endpoints.

api-gateway/src · high confidence

Added REST API routes for posts, comments, and users

The home-service now exposes new API endpoints for managing posts, comments, and users. Post routes include CRUD operations, retrieval of comments by post ID, and an undo-delete feature for soft-deleted posts. Comment routes provide full CRUD functionality protected by an authentication middleware. User routes expose standard CRUD operations. All post and comment endpoints require authentication, while user endpoints are currently unauthenticated.

home-service/src/api/routes · high confidence

Added category and product management capabilities

Introduced new modules for managing categories and products within the ecom-service. The category module now supports creating, reading, updating, and deleting categories via REST endpoints and service layer functions. Similarly, the product module allows creating products with associated category IDs, enabling basic product catalog management.

ecom-service/src/modules/category · high confidence

Added message queue worker for user lifecycle events

Implemented a BullMQ worker in home-service to process user creation, update, and deletion events from the auth-service. The worker handles incoming jobs for UserCreated, UserUpdated, and UserDeleted events, calling the respective user service methods. Error handling is included to prevent the worker from crashing on failed jobs.

home-service/src/message-queue · high confidence

Added user management endpoints and service layer

The home service now exposes REST endpoints for creating, retrieving, updating, and deleting users. This change introduces a new user module containing a controller that maps HTTP requests to service calls, a service layer that inherits from a generic base service, and a repository that extends a base repository for database interactions. Users can now perform full CRUD operations on user data through the API.

home-service/src/modules/comment, home-service/src/modules/user · high confidence

Added user management endpoints in the chat service

The chat service now exposes a full set of RESTful endpoints for managing users, including creating, retrieving, updating, and deleting user records. This introduces a new user module within the chat service, providing controllers, services, and repository layers that interact with the database to support user lifecycle operations.

chat-service/src/modules/user · high confidence

Added utility modules for authentication and error handling

The home-service now includes new utility modules to support authentication and error management. A JWT helper was added to verify tokens, enabling the service to authenticate requests. Additionally, a custom error class was introduced to standardize error responses with status codes and additional properties. Constants for message queues and job types were also added to support background job processing.

home-service/src/utils · high confidence

Auth service exposes REST endpoints for user management

The auth-service now exposes REST endpoints for user registration, login, retrieving the current user's profile, updating the current user's profile, and deleting the current user's account. These endpoints are implemented in the new \rest.ts\ controller file, which handles request validation and response formatting. The underlying repository layer provides the necessary database operations for these user management tasks.

auth-service/src/modules/auth/controllers · high confidence

Initial home-service server and database connection setup

The home-service is initialized as a new Express application that establishes a connection to MongoDB using Mongoose. The service configures standard middleware including CORS, JSON parsing, and logging, and registers global error and route-not-found handlers. This change introduces the foundational server entry point and database connectivity for the home-service.

home-service/src · high confidence

Initial launch of the chat-service with REST and WebSocket support

The chat-service is now available, providing a new endpoint for real-time chat via Socket.IO and REST APIs for managing users and dual-person conversations. Users can access their profile and manage their account through the new /users endpoints, while the /conversations/dual route allows for retrieving conversation lists and messages. The service also integrates with a message queue to handle user creation, update, and deletion events asynchronously.

chat-service/src · high confidence

Initial scaffolding of the ecom-service with core data models and routing

The ecom-service has been initialized with a new project structure, including a database provider for managing Sequelize models for Products, Categories, Carts, and Discounts. The service exposes REST endpoints for creating and managing categories and products, and includes middleware for route handling and JWT-based authentication.

ecom-service · medium confidence

Introduce database models for user, role, and user-role entities

The auth-service now defines database models for Users, Roles, and the many-to-many UserRole association using Sequelize. The User model includes fields for authentication and profile data (name, email, password, salt, status, verification tokens, phone, address, preferences, and ban status), while the Role model supports role-based access control. These models are instantiated via a singleton Provider class that manages the database connection and model relationships.

auth-service/src/models · high confidence

Introduce generic base repository and service classes

Added generic base classes for the home service: a \BaseRepository\ that provides common CRUD operations (create, find, update, delete) with support for skip, limit, populate, and sort, and a \BaseService\ that delegates to a repository. These new base classes allow specific repositories and services to inherit standard database functionality, reducing code duplication across the home service module.

home-service/src/modules/base · high confidence

Introduce post-log module with REST endpoints and service layer

A new post-log module has been added to the home-service, providing a complete stack for managing post logs. This includes a REST controller exposing endpoints for creating, retrieving, and deleting logs, a service layer that handles business logic (such as mapping post IDs), and a repository that extends a base repository for database operations. This change introduces new functionality rather than modifying existing behavior.

home-service/src/modules/post-log · high confidence

Introduced dual and group conversation capabilities

Added REST controllers and service implementations for managing one-on-one (dual) and group conversations. Users can now send and retrieve messages in private chats, view their conversation list, and create or manage group chats by adding or removing participants. The group conversation service reuses the dual conversation service for shared logic, ensuring consistent message handling across both conversation types.

chat-service/src/modules/dual-conversation · high confidence

User module scaffolding added

Empty placeholder files were added for the user module's controller, repository, and service layers. These files currently contain no implementation, indicating the initial project structure for the user feature has been established.

ecom-service/src/modules/user · high confidence

Architecture

Extracted authentication helper functions into separate modules

The authentication logic in the auth-service has been refactored by separating concerns into distinct utility modules: email validation, JWT token generation and verification, and password hashing/verification. This structural change organizes the codebase by functionality, making each component (email, jwt, password) independently maintainable.

auth-service/src/utils/helpers · high confidence

Behavioural changes

Adds message queue integration for user lifecycle events

The auth-service now publishes user creation, update, and deletion events to message queues (BullMQ). This enables other microservices, such as ecom-service and home-service, to subscribe and react to these user events asynchronously.

auth-service/src/message-queue · medium confidence

Auth service exposes user profile endpoints with security middleware

The auth-service now exposes REST endpoints for registering, logging in, and managing the current user's profile (get, update, delete). Crucially, the update and delete operations are protected by a new \secureUpdateOrDelete\ middleware that prevents users from modifying or removing other users' profiles, ensuring each user can only interact with their own data.

auth-service/src/api/routes · high confidence

Auth service implements user lifecycle management with cross-service notifications

The auth service now exposes a complete user lifecycle including registration, login, retrieval, update, and deletion. A key behavioral change is that user creation, updates, and deletions now trigger asynchronous fanout events to other microservices (ecom-service, home-service) via a message queue, ensuring downstream services are notified of these state changes.

auth-service/src/modules/auth/services · medium confidence

Auth service initialization with event subscription for other microservices

The auth-service has been initialized as a standalone microservice, replacing the previous embedded implementation. The service now runs on port 4001 and includes middleware for logging, CORS, and error handling. A key behavioral change is the introduction of an observer pattern via the 'set-subscriber-for-services' loader, which allows other microservices (specifically home and chat) to subscribe to user events through a message queue, enabling asynchronous communication between the auth service and other parts of the system.

auth-service/src · medium confidence

Empty job and subscriber modules in auth-service

The files auth-service/src/jobs/index.ts and auth-service/src/subscribers/index.ts have been created as empty modules. This change reflects a structural adjustment where the auth service is being reorganized, likely to support its evolution into a separate microservice, though the current diff only shows the creation of empty index files without any actual job or subscriber logic.

auth-service/src/jobs, auth-service/src/subscribers · low confidence

Introduce PostRepository with soft-delete and pagination support

The PostRepository class has been introduced to handle post data access, extending BaseRepository to reuse common database functionalities. This change moves database operations from the service layer to the repository, including logic for adding comments to posts. The repository now supports filtering by soft-delete status (showing or hiding deleted posts) and includes pagination parameters (limit, skip) and comment count population in the findAll method.

home-service/src/modules/post/repository · medium confidence

Introduce soft delete and cascade deletion for posts and users

The home-service models now support soft deletion of posts via a new \deletedAt\ field, allowing posts to be restored from a recycle bin. Additionally, the system enforces cascade deletion: deleting a user automatically removes all their posts and associated comments, while deleting a post automatically removes all its comments and related log entries. These behaviors are implemented via Mongoose pre-hooks on delete operations.

home-service/src/models · high confidence

Introduces a custom error class for standardized error handling

A new CustomError class is added to the auth-service, extending the native Error class to include a statusCode and additional properties. This enables more structured error handling across the service by allowing errors to carry HTTP status codes and extra context.

auth-service/src/utils/errors · medium confidence

New authentication and validation middleware for home-service

Added new middleware functions to the home-service API layer to enforce security and data validation. The \authenticate\ middleware validates JSON Web Tokens (JWT) to verify user identity, while \secureUpdateOrDelete\ ensures users can only update or delete their own resources. Additionally, a \validatePostOnCommentRoutes\ middleware was introduced to verify the existence of posts before processing comments. These changes provide a centralized way to handle authentication, authorization, and input validation for the home service.

home-service/src/api/middlewares · high confidence

New message queue and job constant definitions in auth-service

The auth-service now exposes new constants for message queue names (auth\_home\_queue, auth\_ecom\_queue, auth\_chat\_queue) and user lifecycle job types (user\_created, user\_updated, user\_deleted), alongside enums for account status and gender. These constants support the new microservice architecture where the auth-service notifies other services (e.g., ecom-service, home-service) upon user creation, update, or deletion.

auth-service/src/utils/constants · medium confidence

New middleware exports for authentication, error handling, and access control

The auth-service now exports a set of reusable middleware functions from a central index. This includes an authenticate middleware that validates JWTs and attaches user data to requests, a secureUpdateOrDelete middleware that prevents users from modifying other users' profiles, and utility middlewares for global error handling and route not-found responses. These changes improve security by enforcing user-level access control and standardize error responses across the service.

auth-service/src/api/middlewares · high confidence

New post management endpoints including soft delete and undo

The home-service now exposes new REST controllers for post management. Users can create, retrieve (separately for users and admins), update, and delete posts. A key behavioral change is the introduction of soft delete functionality: posts can be soft-deleted and subsequently restored (undo delete) via the new \undoDeletePostById\ endpoint. Additionally, a dedicated endpoint allows fetching comments associated with a specific post.

home-service/src/modules/post/controllers · high confidence

Post service refactored with base class inheritance and soft delete support

The PostService class has been refactored to inherit from a generic BaseService, allowing it to reuse common service methods. This change introduces a soft delete mechanism for posts, enabling users to recover deleted posts from a recycle bin via a new undoDelete method. Additionally, the service now distinguishes between admin and user views for fetching posts, and includes logic to log post creation, updates, and deletions.

home-service/src/modules/post/services · high confidence

Test coverage

Added empty test file for auth service; Added unit tests for the home service workflow.

Dependencies

Initial dependency setup for microservices

Added package.json and package-lock.json files for the api-gateway, auth-service, chat-service, ecom-service, and home-service. Each service is initialized with its specific dependencies, such as express, typescript, and service-specific libraries like socket.io for the chat-service or sequelize for the auth-service.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 42 → 42 (+0.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 78 → 84 (+5.9)
  • Architecture 90 → 79 (-10.2)
  • Maturity 47 → 47 (+0.0)
  • Readiness 16 → 20 (+3.7)
  • Security 74 → 74 (-0.1)

Resolved (60)

  • Change coupling: index.ts ↔ index.ts (home-service/src/modules/comment/services/index.ts)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (auth-service/package-lock.json)
  • Critical CVE: [GHSA redacted] (auth-service/package-lock.json)
  • Critical CVE: [GHSA redacted] (chat-service/package-lock.json)
  • Critical CVE: [GHSA redacted] (home-service/package-lock.json)
  • Critical CVE: [GHSA redacted] (auth-service/package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (api-gateway/package-lock.json)
  • High CVE: [GHSA redacted] (auth-service/package-lock.json)
  • High CVE: [GHSA redacted] (home-service/package-lock.json)
  • High CVE: [GHSA redacted] (chat-service/package-lock.json)
  • High CVE: [GHSA redacted] (chat-service/package-lock.json)
  • High CVE: [GHSA redacted] (api-gateway/package-lock.json)
  • High CVE: [GHSA redacted] (chat-service/package-lock.json)
  • High CVE: [GHSA redacted] (api-gateway/package-lock.json)
  • High CVE: [GHSA redacted] (auth-service/package-lock.json)
  • High CVE: [GHSA redacted] (auth-service/package-lock.json)
  • High CVE: [GHSA redacted] (home-service/package-lock.json)
  • High CVE: [GHSA redacted] (home-service/package-lock.json)
  • …and 40 more

New (72)

  • Critical CVE: [GHSA redacted] (auth-service/package-lock.json)
  • Critical CVE: [GHSA redacted] (auth-service/package-lock.json)
  • Critical CVE: [GHSA redacted] (chat-service/package-lock.json)
  • Critical CVE: [GHSA redacted] (home-service/package-lock.json)
  • Critical CVE: [GHSA redacted] (auth-service/package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [CVE redacted] (auth-service/package-lock.json)
  • High CVE: [CVE redacted] (home-service/package-lock.json)
  • High CVE: [GHSA redacted] (auth-service/package-lock.json)
  • High CVE: [GHSA redacted] (home-service/package-lock.json)
  • High CVE: [GHSA redacted] (home-service/package-lock.json)
  • High CVE: [GHSA redacted] (home-service/package-lock.json)
  • High CVE: [GHSA redacted] (chat-service/package-lock.json)
  • High CVE: [GHSA redacted] (chat-service/package-lock.json)
  • High CVE: [GHSA redacted] (api-gateway/package-lock.json)
  • High CVE: [GHSA redacted] (chat-service/package-lock.json)
  • High CVE: [GHSA redacted] (auth-service/package-lock.json)
  • High CVE: [GHSA redacted] (auth-service/package-lock.json)
  • …and 52 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sayeed1999/home was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2321105bfeccd24f01addd6085b3d0ad2ea5e794 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.