sinanptm/clean-auth-template
55.3
Adequate · 21 September 2026
6.9k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a full-stack authentication and user management platform, comprising a Node.js/TypeScript backend and a Next.js frontend. The backend provides secure user and admin authentication, profile management, and administrative controls to block or update user accounts. The frontend implements a comprehensive UI for sign-in, sign-up, password recovery, and an admin dashboard for user management, all supported by a shared component library and state management hooks.
Features
Add user profile editing component
A new Profile component has been added to the user section, enabling users to view and edit their name and email. The component fetches the current profile data, displays the user's avatar and details, and provides an inline editing interface with save and cancel actions, using dedicated API hooks for fetching and updating the profile.
web/components/user · high confidence
Added Forgot Password and Logout Confirmation dialogs
Users can now initiate a password reset via a new ForgotPasswordDialog component, which handles email submission and validation. Additionally, a LogoutConfirmDialog has been introduced to require explicit confirmation before logging out, displaying a warning message tailored to the user's role.
web/components/dialogs · high confidence
Added LoadingOverlay component for full-screen loading states
A new LoadingOverlay component has been added to the web components. It provides a full-screen overlay with a bouncing dot animation to indicate loading states. The component supports both a global loading state via the useIsLoading hook and an explicit loading prop, preventing body scrolling while active and using framer-motion for smooth entry/exit animations.
web/components · high confidence
Added React Query hooks for user authentication flows
The application now provides dedicated React Query hooks for managing user authentication states, including sign-up, sign-in, OAuth sign-in, password reset, OTP verification, and logout. These hooks encapsulate the API calls for each stage of the authentication lifecycle, handling success states such as token storage, user session management, and navigation to appropriate routes.
web/hooks/api/user/auth · high confidence
Added authentication layout and sign-in page
A new authentication layout was introduced to manage hydration state and redirect authenticated users away from the sign-in page. The layout checks if the user is hydrated and, if so, redirects them if they are already logged in. The sign-in page itself was added to render the SigninClient component within a centered layout.
web/app/(user)/auth · high confidence
Added authentication schema validation and auth utility functions
The web library now includes formalized validation schemas for sign-in, sign-up, forgot password, reset password, and OTP verification using Zod, ensuring consistent data validation across the application. Additionally, new utility functions have been added to the utils module to handle local storage operations, display error toasts, manage token keys based on user roles, and clear authentication data, supporting the ongoing implementation of the authentication flow.
web/lib · high confidence
Added centralized API client and HTTP method utilities
The web layer now includes a new API client module that provides a reusable Axios instance configured with role-based authentication headers and automatic token refresh logic. This client is exposed through a set of generic HTTP method wrappers (GET, POST, PUT, DELETE, PATCH) that handle URL construction and response processing, simplifying how the frontend communicates with the backend.
web/lib/api · high confidence
Added client-side OAuth sign-in and password reset UI components
The authentication UI has been expanded with new client-side React components. OAuth sign-in is now supported via GitHub and Google, with the \OAuthButtons\ component handling the client-side popup flow and token exchange. Additionally, the password recovery flow is now fully implemented with \ForgotPasswordClient\, \ResetPasswordForm\, and \InvalidTokenState\ components, allowing users to request and complete password resets through the new UI.
web/components/user/auth · high confidence
Added layout components for navigation and theme switching
The web layout area now includes a new Navbar component that provides user and admin navigation links, a confirmation dialog for logging out, and a ThemeButton for switching between light and dark modes. Additionally, a QueryProvider wrapper for TanStack Query and a ThemeProvider wrapper for next-themes have been introduced to support these features.
web/components/layout · high confidence
Added new UI component library
The web application now includes a comprehensive set of reusable UI components, including alert dialogs, alerts, avatars, buttons, cards, checkboxes, command palettes, dialogs, form controls, inputs, labels, radio groups, select menus, separators, skeleton loaders, toast notifications, switches, tabs, textareas, and toggles. These components provide a consistent, accessible, and styled foundation for building the user interface.
web/components/ui · high confidence
Added new authentication form components
Introduced three new React components for the authentication flow: OtpVerificationForm for one-time password verification, SigninForm for user login, and SignupForm for new user registration. These components provide the UI for the ongoing authentication feature.
web/components/forms · high confidence
Added password reset and OTP verification flows with improved 404 handling
Users can now reset their password via a new forgot-password page that validates token expiry, and verify their email via a dedicated OTP verification page. The root layout now wraps the application with a QueryProvider, ThemeProvider, Navbar, and Toaster, while the home page displays sign-in/sign-up buttons for unauthenticated users and a profile view for authenticated ones. Additionally, the not-found page now conditionally renders an admin sign-in link for admin routes.
web/app · high confidence
Added type definitions and props interfaces for authentication and form components
New TypeScript types and interfaces have been introduced to support the authentication and form UI components. The \form.ts\ file defines data structures for sign-in, sign-up, password reset, and OTP verification forms. The \state.ts\ file introduces state management interfaces for user and admin authentication, as well as for forgot password and loading states. Additionally, \props.ts\ now includes detailed React component props for sign-in, sign-up, forgot password, OTP verification, and generic form fields, enabling stricter type checking for these UI elements.
web/types · high confidence
Added user profile API hooks
New React Query hooks are now available for fetching and updating the user's profile. useGetProfile retrieves the current user's data, while useUpdateProfile handles profile updates with success/error toast notifications.
web/hooks/api/user · high confidence
Adds admin authentication, user profile management, and OAuth support
The server now supports admin authentication and user profile management. Admins can sign in, refresh access tokens, and manage users (get users, update user details, and block/unblock users). Users can retrieve and update their own profiles. Additionally, the server now supports OAuth sign-in via Firebase, allowing users to log in using their Google/Facebook accounts. The email service has been updated to support password reset links in addition to OTPs. The admin routes are protected by a new \AdminAuthMiddleware\ that validates bearer tokens and checks for the 'Admin' role.
server/src · high confidence
Admin dashboard with user management and authentication
A new admin section has been added to the application, providing a complete authentication and user management interface. Users can now sign in as an admin via a dedicated login page that enforces authentication. Once authenticated, the admin dashboard displays a user table that allows administrators to edit user names and toggle user block status, with the layout handling hydration states and access control.
web/app/admin · high confidence
Centralized API route and type definitions for web client
The web client now uses a centralized set of TypeScript enums and interfaces to define all API endpoints and HTTP method parameters. This includes route definitions for authentication (sign-in, sign-up, password reset, OTP, OAuth 2.0, and admin login), profile management (update, get), admin user management (get, block/toggle block), and logout. The \index.ts\ file introduces a unified \Params\ and \Body\ type system for each HTTP method (Post, Get, Put, Delete, Patch), standardizing how the frontend constructs API calls with roles and parameters.
web/types/api · high confidence
New authentication and state management hooks
The web application introduces several new Zustand-based hooks to manage application state and authentication flows. For authentication, \useAuthAdmin\ and \useAuthUser\ provide client-side hydration of tokens and user data from local storage, resolving previous hydration errors. A new \useMailSetter\ hook manages the email state for the forgot password flow, while \useAuthRedirectToast\ handles displaying error toasts for authentication redirects. Additionally, \useLoading\ is added to manage global loading states. These changes support the recently added forgot password and OTP verification features.
web/hooks/store · high confidence
New custom form element components
Added a suite of new custom form components in the \web/components/forms/elements\ directory, including \CustomCheckbox\, \CustomFileInput\, \CustomInput\, \CustomRadioGroup\, \CustomSelect\, \CustomSwitch\, \CustomTextArea\, \MultipleSelector\, \CustomOTPInput\, and \SubmitButton\. Each component is integrated with a shared \FormFieldWrapper\ to provide consistent form field layouts, accessibility attributes, and error handling.
web/components/forms/elements · high confidence
New signup page with OAuth support
A new signup page has been added at /auth/signup, providing a dedicated interface for new user registration. The page includes a header, an OAuth button component for social login, and a standard signup form, allowing users to create an account via email or third-party providers.
web/app/(user)/auth/signup · high confidence
New user management table in the admin interface
The admin area now includes a dedicated UsersTable component that displays a list of users with their name, email, blocked status, and creation date. Users can be edited inline, saved, cancelled, or blocked/unblocked directly from the table, with loading states and error handling provided.
web/components/admin · high confidence
Behavioural changes
Add Firebase and server configuration for the web app
A new configuration file at web/config/index.ts initializes the Firebase app using environment variables for API keys and project details, and defines the server URL, defaulting to localhost:8000.
web/config · high confidence
Added application name constant
A new constant, APP\_NAME, has been introduced in the web constants module, defining the application name as 'Auth Template'.
web/constants · high confidence
Added environment configuration and updated Next.js image domains
The web application now includes a .env.example file containing placeholder values for the server URL and Firebase configuration, providing a template for environment setup. The .gitignore file was updated to allow committing .env files, and the empty README.md was removed. Additionally, the Next.js configuration was updated to allow image loading from specific external domains (github.com, lh3.googleusercontent.com, avatars.githubusercontent.com).
web · medium confidence
Adds global CSS variables for light and dark theme support
The application now defines a comprehensive set of CSS custom properties for theming, including variables for background, foreground, card, primary, secondary, muted, accent, destructive, border, input, and ring states in both light and dark modes. This enables consistent visual styling across components by referencing these semantic color tokens.
web/styles · high confidence
Admin panel authentication and user management hooks
The admin interface now includes dedicated React Query hooks for authentication and user management. Administrators can sign in and securely log out of the admin portal. Additionally, admins can retrieve a list of all users, update user details, and toggle user account blocks directly through these new API hooks.
web/hooks/api/admin · high confidence
Server configuration and tooling updates
Added a .env.example file to document required environment variables for database, server, JWT, email, admin, and Firebase configurations. Removed the server's ESLint configuration file. Updated the .gitignore to exclude firebase.json. Modified the Jest configuration to use a relative rootDir for test matching, added module path mappings, and included transform and module file extension settings. Updated tsconfig.json to enable isolatedModules.
server · high confidence
Test coverage
Added mock implementations for server services and repositories; Added unit tests for user authentication use cases; Removed sample test file.
Dependencies
Updated project dependencies and tooling versions
The project's dependency manifests have been updated across the root, server, and web packages. In the root, concurrently and prettier were upgraded. The server package added cookie-parser, cors, firebase-admin, helmet, and rate-limiter-flexible, while updating inversify, joi, mongoose, nodemailer, and various dev dependencies like jest and typescript. The web package added a wide range of new dependencies including Radix UI components, TanStack Query, Axios, Firebase, and React Hook Form, while updating Next.js, React, and related tooling.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 50 → 55 (+5.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 65 → 70 (+5.1)
- Architecture 77 → 67 (-9.6)
- Maturity 72 → 71 (-1.3)
- Readiness 42 → 54 (+12.2)
- Security 50 → 57 (+7.0)
- Accessibility 52 → 51 (-0.4)
Resolved (75)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical vulnerability: [GHSA redacted] (pnpm-lock.yaml)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further orphaned files (smaller)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- …and 55 more
New (130)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Documentation: no installation or build instructions (README.md)
- Dormant codebase
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- …and 110 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sinanptm/clean-auth-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7a389e08a59594d820c37568b91bd8daa3e02f53 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.