Skip to content
CAI
Software that uses CAICheck a score

simnova/sharethrift

56.3

Adequate · 4 August 2026

80.9k

lines of production code

TypeScript

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a monorepo-based backend and frontend application framework, specifically supporting the ShareThrift domain. It provides a structured, phase-based initialization for API services, manages authentication and onboarding flows for user portals, and enforces strict architectural boundaries between domain, persistence, and GraphQL layers. The system includes comprehensive tooling for building, testing, and verifying code quality across the entire repository.

How it got here

2025 — Monorepo migration and architectural cleanup

35 changes.

This period focused on restructuring the codebase into a Turborepo-managed monorepo, replacing legacy package structures with a standardized, typed initialization framework for the API and UI applications. Significant cleanup involved removing obsolete seedwork, event handlers, and test configurations, while introducing new features for authentication, account management, and architectural validation.

2026 — Architectural enforcement and test infrastructure

11 changes.

This period focused on establishing strict architectural boundaries and security conventions through automated code review and pre-commit hooks. It also introduced comprehensive test suites for UI, API, and end-to-end workflows, alongside new AI agent skills and internal mocking tools to support development and verification.

Features

Added E2E test suite for listing and reservation workflows

The e2e-tests package now includes a full end-to-end test suite for the ShareThrift application, using Cucumber and Playwright to automate browser interactions. The suite covers creating and validating listings, as well as creating and validating reservation requests. It includes task and step-definition files for these contexts, along with supporting infrastructure to spin up test servers (API, MongoDB, Azurite, OAuth2, and the UI portal) and handle OAuth2 login. Test credentials are stored in .env.test, and the configuration supports running tests locally or against a deployed environment.

packages/sthrift-verification/e2e-tests · high confidence

Added acceptance test suite for the ShareThrift API

Introduced a new acceptance test suite for the ShareThrift API, implementing Cucumber-based tests for listing and reservation request workflows. The change adds step definitions, task objects, and question classes to verify API behavior, alongside configuration files for code coverage and test infrastructure setup.

packages/sthrift-verification/acceptance-api · high confidence

Added agent skills for Ant Design and Apollo Client 4.x

New agent skills have been introduced to guide developers using specific libraries. The Ant Design skill provides a CLI-based workflow for querying component APIs, debugging issues, migrating between versions, and analyzing project usage. The Apollo Client 4.x skill provides comprehensive integration guides for React, Next.js, React Router, and TanStack Start, along with detailed references for caching, error handling, fragments, mutations, and queries.

.agents · high confidence

Added application services and tests for account plan and appeal request contexts

The application-services package now includes new implementations for managing account plans and appeal requests. For account plans, the system supports creating, querying by ID, querying by name, and retrieving all plans, backed by corresponding BDD-style feature files and unit tests. For appeal requests, the system supports creating listing and user appeal requests, retrieving them by ID or in paginated lists with state filters and sorting, and updating their state. These changes provide the backend logic required for users to manage their subscription plans and submit or track listing appeal requests.

packages/sthrift · high confidence

Added domain and integration event handler registration functions

New entry points have been added to the event-handler package, specifically \RegisterDomainEventHandlers\ and \RegisterIntegrationEventHandlers\. These functions accept a \DomainDataSource\ instance, with the integration handler currently logging the data source. This change introduces the initial structure for registering event handlers in both the domain and integration layers.

packages/sthrift/event-handler/src/handlers/domain, packages/sthrift/event-handler/src/handlers/integration · high confidence

Added microform styling and logo assets

The application now includes a new SVG logo icon for the ShareThrift UI, alongside a new JavaScript file that applies specific CSS styles (height, border, padding, and border-radius) to all iframes on the page, specifically targeting the microform integration.

apps/ui-sharethrift/public · high confidence

Added server-mongodb-memory-mock for internal data seeding

Introduced a new internal package, server-mongodb-memory-mock, designed to seed mock data for development and testing. The package initializes a memory-based MongoDB instance and populates it with seed data for users, admin roles, item listings, conversations, and appeal requests. It also includes environment setup and configuration files (\.env\, \turbo.json\, \tsconfig.json\) to support the mock service.

apps/server-mongodb-memory-mock · high confidence

Adds Apollo Client cache merge fix for PersonalUser type

A new shared component, \ApolloManualMergeCacheFix\, has been added to configure the Apollo Client \InMemoryCache\ for the \PersonalUser\ type. This change introduces a custom merge function for the \account\ field that utilizes \lodash/merge\ to deep-merge incoming data with existing cache data, ensuring that nested properties are preserved during updates.

apps/ui-sharethrift/src/components · high confidence

Arch-unit tests for domain, persistence, and GraphQL layers

The \packages/cellix/arch-unit-tests\ package now includes a comprehensive suite of architectural and convention checks for the codebase. This includes validation of domain layer conventions (repository, unit of work, and aggregate root patterns), persistence layer rules (MongoDB repository and adapter conventions), GraphQL resolver and schema conventions, and frontend architecture checks. The suite also enforces dependency boundaries (e.g., application services must not import infrastructure directly) and checks for circular dependencies across the application and package layers.

packages/cellix · high confidence

Centralized OIDC configuration for authentication

A new centralized configuration file (oidc-config.tsx) has been introduced to manage OpenID Connect (OIDC) settings, including B2C authority, client ID, redirect URI, and scope. This change consolidates authentication parameters and handles post-sign-in redirection logic using session storage, improving maintainability of the authentication setup.

apps/ui-sharethrift/src/config · medium confidence

Initialize Storybook configuration for ui-sharethrift

The Storybook setup for the ui-sharethrift package has been initialized with a new configuration structure. This includes a main.ts file defining the React-Vite framework, story glob patterns, and essential addons for documentation, accessibility, and Vitest integration. A preview.tsx file configures parameter matchers and accessibility testing, while a vitest.setup.ts file integrates project annotations. Additionally, a README.md file has been added to document the local development and isolation of the Storybook configuration.

apps/ui-sharethrift/.storybook · high confidence

Introduce AppContainer to manage authenticated user state and onboarding flow

The application now uses an AppContainer component that conditionally fetches the current user's profile and onboarding status via a GraphQL query. This container handles authentication state by waiting for a usable token before querying the user, ensuring that the main App component only renders when the user is authenticated and their data is loaded. The App component itself manages routing for login, signup, and the main application routes, while the container also provides user ID and onboarding status to the rest of the application. Tests and Storybook stories have been added to verify the authentication and onboarding logic.

apps/ui-sharethrift/src · high confidence

Introduce Cellix application bootstrap framework

Added the Cellix framework to the API layer, providing a structured, phase-based lifecycle for initializing infrastructure services (such as Mongoose, Blob Storage, and Token Validation), building an application context, and registering Azure Function HTTP handlers (GraphQL and REST). This new entry point replaces the previous manual startup logic with a typed, chainable API that manages service registration, context building, and application startup.

apps/api/src · high confidence

Introduce local OAuth2 mock server and configure ShareThrift UI for multi-portal OIDC development

Developers can now run a local OAuth2/OIDC mock server (apps/server-oauth2-mock) that automatically discovers portal configurations from each UI app's mock-oidc.json. The ShareThrift UI (apps/ui-sharethrift) is configured with environment variables pointing to this mock server, enabling local development of the user portal. The mock server supports multi-portal configuration, allowing each UI app to declare its own OIDC portal via a mock-oidc.json file, with the server auto-discovering them at startup. Tests are included for the portal discovery logic.

apps/ui-sharethrift · high confidence

Introduce monorepo build, security, and code quality tooling

The project now includes configuration files that establish the monorepo structure and developer tooling: \turbo.json\ and \TURBOREPO.md\ configure Turborepo for optimized builds; \pnpm-workspace.yaml\ defines the workspace layout; \codegen.yml\ sets up GraphQL code generation; \knip.json\ configures unused dependency detection; \sonar-project.properties\ and \.sourcery.yaml\ enable code analysis and quality rules; \mise.toml\ manages Node.js and Python versions; and \.snyk\ suppresses specific vulnerability alerts for transitive dependencies. These changes provide a standardized, optimized build and quality-checking environment for the monorepo.

(repo-wide) · high confidence

Introduce shared verification infrastructure for UI and API tests

The \packages/sthrift-verification/verification-shared\ package now provides a unified test infrastructure for acceptance and end-to-end testing. This includes a \PageAdapter\ interface with \jsdom\ and \Playwright\ implementations, enabling page objects (e.g., \LoginPage\, \OnboardingPage\, \ListingPage\) to work across different test environments. The package also introduces a \Cucumber\-based \AgentFormatter\ for condensed, token-efficient test output, helper utilities for date/actor/gherkin manipulation, and in-memory server stubs (\BaseMongoDBTestServer\, \GraphQLTestServer\) to support integration tests. Additionally, Gherkin scenarios for creating listings and reservation requests are added to define expected behaviors.

packages/sthrift-verification/verification-shared · high confidence

New AI agent skills added to the .claude directory

The .claude directory now includes symlinks to a new set of agent skills, including antd, apollo-client, apollo-mcp-server, apollo-server, azure-functions, graphql-operations, graphql-schema, mongoose-mongodb, turborepo, typescript-advanced-types, vercel-react-best-practices, and vitest. These additions expand the available tools for AI-assisted development workflows.

.claude · high confidence

New architectural enforcement tests for ShareThrift

The \@sthrift-verification/arch-unit-tests\ package was introduced to enforce ShareThrift-specific architectural conventions. It provides test suites and check functions for application services, data sources (Mongoose models), domain contexts, frontend architecture (container placement, GraphQL pairing, story coverage), GraphQL resolvers and schemas, and persistence factories. The package also includes shared utilities for file system operations and member ordering tests, with a README explaining usage and CI integration.

packages/sthrift-verification/arch-unit-tests · high confidence

New build-pipeline scripts for SonarQube quality gates, change detection, and coverage merging

Added four new scripts in the build-pipeline directory to enhance the CI/CD workflow. The \check-sonar-quality-gate.cjs\ script polls SonarCloud to verify that code quality gates pass before proceeding. The \detect-changes.cjs\ script identifies which parts of the monorepo have changed (infrastructure, backend, frontend, docs) to optimize build and deployment steps. The \get-pr-number.cjs\ script retrieves the current pull request number from GitHub for pipeline context. Finally, \merge-coverage.js\ combines LCOV coverage reports from various packages into a single report for SonarQube analysis.

build-pipeline/scripts · high confidence

Reorganized API and messaging mock into apps directory with new configuration files

The API application and its associated configuration files (deploy-api.yml, turbo.json, vitest.config.ts, host.json, .funcignore, .gitignore, .prettierrc.json, readme.md) have been moved from the packages directory to apps/api. A new server-messaging-mock application has been added to apps/server-messaging-mock, including its configuration files (tsconfig.json, turbo.json, .env, .gitignore, README.md) and source code (index.ts, seed-data.ts). The TypeScript configuration for both apps has been updated to extend @cellix/typescript-config/node.json instead of the previous base config. The API's tsconfig now references the server-messaging-seedwork package.

apps/api · high confidence

Restructures and expands Infrastructure-as-Code for Azure resources

The IaC directory is reorganized into modular Bicep templates for Application Insights, Function App, Search Service, Static Website (Front Door/CDN), Storage Account (Blob, Queue, Table services), and Cosmos DB. The Function App is updated to use the AVM module 0.19.3, integrates Application Insights connection strings, and replaces direct Key Vault access policies with a dedicated role-assignment module. Storage account templates now support granular configuration of Blob, Queue, and Table services, including CORS, lifecycle management, and versioning. The CDN module is removed from the static website template, and the App Service Plan template is refactored to use resource naming conventions and explicit outputs.

iac · high confidence

Removals

Removal of api-event-handler package

The api-event-handler package has been removed from the repository. This includes the deletion of the package's configuration file (package copy.json) and its main source file (src/index.ts), effectively eliminating this component from the codebase.

packages/api-event-handler · high confidence

Removal of api-persistence entry point

The main entry point for the api-persistence package has been removed. This eliminates the previous implementation that initialized a DomainDataSource using MongooseSeedwork and the @ocom/api-domain module, effectively stripping out the persistence layer's public API and associated domain context setup.

packages/api-persistence/src · high confidence

Removal of default Vite+React project scaffolding

The default Vite+React application template has been removed from the ui-applicant package. This includes the deletion of all source files (App.tsx, index.css, App.css, main.tsx), configuration files (tsconfig.json, vite.config.ts, eslint.config.js), and public assets (vite.svg). As a result, the ui-applicant package no longer contains a functional React application.

packages/ui-applicant · high confidence

Removed Mongoose and Domain Seedwork packages

The \cellix-data-sources-mongoose\ and \cellix-domain-seedwork\ packages have been removed from the repository. This includes the deletion of all source files, configuration files (such as \vitest.config.ts\), and documentation (such as \readme.md\ and \README.md\). The removal of these seedwork and data source implementations indicates a shift away from the previous Mongoose-based persistence and domain models.

packages/cellix-data-sources-mongoose · high confidence

Removed OpenTelemetry service package

The \packages/service-otel\ directory has been deleted, removing the OpenTelemetry service implementation and its associated configuration files (including \tsconfig.json\, \vitest.config.ts\, and \.prettierrc.json\). This change eliminates the local OpenTelemetry service and its unit tests from the codebase.

packages/service-otel · high confidence

Removed unused test-watch-all script

The scripts/test-watch-all.js file has been removed from the repository. This script previously iterated through all workspaces to concurrently run test watchers, but it is no longer needed.

scripts · high confidence

Behavioural changes

Added pre-commit hooks for code formatting and verification

The project now enforces code formatting and verification before each commit. A new pre-commit hook runs 'pnpm run format:staged' to automatically format staged files, updates the git index, and then runs 'pnpm run verify' to ensure code quality checks pass.

.husky · high confidence

Admin portal now requires authentication for all pages

The admin application now enforces authentication on all routes, redirecting unauthenticated users to the login page. This is implemented by wrapping the main application routes with a RequireAuth component that checks for a valid user token and redirects to /login if not authenticated. The app container also verifies the user's identity before loading the main application, ensuring that only authenticated users can access admin features.

apps/ui-admin · high confidence

Automated enforcement of DDD layer boundaries and security conventions

The project now enforces strict architectural boundaries and security conventions via automated code review rules. Domain, GraphQL, and persistence layers are restricted from importing each other's dependencies (e.g., domain cannot import Mongoose, GraphQL, or persistence packages). React components are restricted from using deep Ant Design imports. TypeScript code is scanned for security risks like innerHTML assignment and child\_process usage, as well as anti-patterns like 'as any' assertions. A new Python script (.sourcery/scripts/review.py) orchestrates these checks across the repository.

.sourcery · high confidence

Migrate service-config modules to apps/api and update internal dependencies

Moved Mongoose and OpenTelemetry service configuration files from the packages directory to apps/api, reflecting a structural reorganization of the codebase. Updated internal package imports to use the new @cellix/ scoped packages (@cellix/mongoose-seedwork, @cellix/service-otel) instead of the previous @ocom/ and @sthrift/ dependencies, ensuring the API service correctly resolves these libraries from their new locations.

apps/api/src/service-config · medium confidence

Removal of API context specification and REST handler definitions

The \@ocom/api-context-spec\ package's \index.ts\ file, which previously exported the \ApiContextSpec\ interface and \DomainDataSource\ type, has been deleted. Additionally, the \@ocom/api-rest\ package's \index.ts\ file, which defined the \HttpHandler\ type and the \restHandlerCreator\ function for Azure Functions, has been removed. These changes indicate a structural shift in how the API context and REST handlers are defined or integrated within the application.

packages/api-context-spec · medium confidence

Removal of coverage reports, IaC parameters, and test configuration files

The repository has removed several non-source files: lcov.info coverage reports for the api-domain, cellix-event-bus-seedwork-node, and service-mongoose packages; the main.bicepparam infrastructure-as-code parameter file for the API package; and vitest.config.ts test configuration files for the cellix-event-bus-seedwork-node and service-mongoose packages. Additionally, .gitignore and .prettierrc.json files for the service-mongoose package were deleted.

(repo-wide) · high confidence

Removal of empty Mongoose context builder

The empty Mongoose context builder function and its associated type definitions have been removed from the models index. This cleanup eliminates unused code and simplifies the module's public API by removing the now-obsolete context factory.

packages/api-data-sources-mongoose-models · high confidence

Removal of legacy domain event types

The domain event classes and their associated property interfaces for 'RoleDeletedReassign', 'ViolationTicketV1Created', 'ViolationTicketV1Deleted', and 'ViolationTicketV1Updated' have been removed from the API domain layer. This eliminates the corresponding event definitions from the system's event bus, meaning these specific domain events will no longer be emitted or processed.

packages/api-domain/src/domain/events · high confidence

Removed Vite-based build configuration from ui-sharethrift

The Vite build configuration files (vite.config.ts, eslint.config.js, tsconfig.\*.json, and README.md) have been removed from the ui-sharethrift package. This indicates the package is no longer built or developed as a standalone Vite/React application, likely because its code or build process has been consolidated or migrated elsewhere.

packages/ui-sharethrift · high confidence

Removed default Vite/React scaffolding from the UI package

The default Vite and React starter template files have been removed from the \ui-sharethrift\ package. This includes the boilerplate \App.tsx\ component, the associated \App.css\ and \index.css\ stylesheets, the \main.tsx\ entry point, and related assets. This change clears the initial project structure to allow for a custom application setup.

packages/ui-sharethrift/src · high confidence

Removed deprecated GraphQL server setup and context class

The placeholder GraphQL server configuration and the empty Context class have been removed from the API-graphql package. This cleanup eliminates unused scaffolding code, including the Apollo Server setup, resolvers, and Azure Functions middleware integration, as the actual implementation is being refactored.

packages/api-graphql · high confidence

Removed deprecated domain context files

The Passport domain context and the shared value-objects (Email, NullableEmail, ExternalId) have been removed from the api-domain package. This cleanup eliminates unused or legacy domain structures, simplifying the domain layer and reducing the codebase footprint.

packages/api-domain/src/domain/contexts · high confidence

Removed domain index re-exports

The domain package no longer exposes the 'Contexts' namespace or the 'Passport' type via its main index file, meaning consumers can no longer import these symbols from the top-level domain export.

packages/api-domain/src/domain · high confidence

Removed generic DomainDataSource interface from api-domain package

The generic DomainDataSource interface, which previously exposed a domainContexts property of type unknown, has been removed from the api-domain package. This change eliminates the placeholder interface in favor of more specific domain layer implementations.

packages/api-domain/src · high confidence

Removed legacy Cellix service registry and entry point

The \packages/api/src/cellix.ts\ and \packages/api/src/index.ts\ files have been deleted. This removes the previous service registry and initialization logic that previously configured the GraphQL and REST API handlers. Users will no longer interact with the old service registration pattern, as the application now relies on a different initialization mechanism.

packages/api/src · high confidence

Restructure API infrastructure-as-code into apps directory and add new resource modules

The API infrastructure-as-code (IaC) templates have been moved from the monorepo's root packages directory to the apps/api/iac directory. This change introduces new Bicep modules for Application Insights, Storage Account, and Cosmos DB, along with their corresponding parameter files (e.g., dev.bicepparam). The main.bicep template has been updated to include these new resources, with specific configurations for locations, SKUs, and environment tags. Additionally, the function app module now receives the Application Insights connection string, and the storage account module is configured with blob, queue, and table services, including CORS settings. The change also adds an output for the function app name.

apps/api/iac · high confidence

Test coverage

Added acceptance UI test suite for listing and reservation request flows; Removed obsolete community management test infrastructure.

Dependencies

Initial package structure for CellixJS and ShareThrift monorepo

The repository now includes a comprehensive set of \package.json\ files that define the dependencies, scripts, and metadata for the new monorepo structure. This includes the core CellixJS framework packages (such as \@cellix/domain-seedwork\, \@cellix/service-messaging-base\, and \@cellix/serenity-framework\), the ShareThrift application layer packages (including \@sthrift/application-services\, \@sthrift/graphql\, and \@sthrift/domain\), and the associated verification and test suites (including \@sthrift-verification/acceptance-api\, \@sthrift-verification/e2e-tests\, and \@cellix/arch-unit-tests\). These files establish the workspace dependencies, tooling configurations (Vitest, TypeScript, Biome), and external library requirements for the entire project.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 28 → 56 (+28.2)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

Lenses

  • Code Health 90 (new)
  • Architecture 90 (new)
  • Maturity 13 → 96 (+82.6)
  • Readiness 15 → 43 (+27.3)
  • Security 100 → 48 (-51.9)
  • Domain Modelling 100 (new)
  • Accessibility 77 (new)

Resolved (6)

  • Dependency hygiene not measured — no supported dependency manifest was read
  • No automated tests
  • No tests found
  • bus factor not measured — no commits were sampled
  • early-stage repository — too little history to judge knowledge freshness
  • single-commit history — no usable git history window to measure hotspots

New (84)

  • Boundary-crossing change coupling: index.ts ↔ messaging-conversation.repository.ts (packages/cellix/service-messaging-twilio/src/index.ts)
  • Boundary-crossing change coupling: oidc-config.tsx ↔ require-auth.tsx (apps/ui-sharethrift/src/config/oidc-config.tsx)
  • Change coupling: conversations.ts ↔ item-listings.ts (apps/server-mongodb-memory-mock/src/seed/conversations.ts)
  • Change coupling: index.ts ↔ messaging-conversation.repository.ts (packages/sthrift/persistence/src/datasources/index.ts)
  • Change coupling: navigation.tsx ↔ index.stories.tsx (packages/sthrift/ui-shared/src/molecules/navigation/navigation.tsx)
  • Change coupling: query-by-id.ts ↔ query-by-user.ts (packages/sthrift/application-services/src/contexts/conversation/conversation/query-by-id.ts)
  • Change coupling: reservation-card.tsx ↔ reservations-table.tsx (packages/sthrift/ui-sharethrift-route-root/src/components/pages/my-reservations/components/reservation-card.tsx)
  • Change coupling: reservation-card.tsx ↔ reservations-view.tsx (packages/sthrift/ui-sharethrift-route-root/src/components/pages/my-reservations/components/reservation-card.tsx)
  • Change coupling: reservations-grid.tsx ↔ reservations-table.tsx (packages/sthrift/ui-sharethrift-route-root/src/components/pages/my-reservations/components/reservations-grid.tsx)
  • Change coupling: reservations-view-active.container.tsx ↔ reservations-view-history.container.tsx (packages/sthrift/ui-sharethrift-route-root/src/components/pages/my-reservations/components/reservations-view-active.container.tsx)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Further orphaned files (smaller)
  • Further sole-owners (lower concentration)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 64 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

simnova/sharethrift was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 4 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ffe7637ee4926e0da829b5600a15ed7cf004b235 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.