sinantok/aspnetcore-webapi-template
59.1
Adequate · 20 September 2026
2.6k
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is a .NET 8 Web API that provides user authentication and note management capabilities. It supports role-based access control via JWT, allows users to create, retrieve, and delete notes, and tracks login activity. The architecture utilizes SQL Server and MongoDB for data persistence, Redis for caching, and exposes functionality through both REST and GraphQL endpoints.
How it got here
2020 — Initial architecture and API implementation
26 changes.
This period established the foundational architecture of the application, introducing a layered design with distinct libraries for data access, identity management, and core services. Key developments included implementing JWT authentication, Redis-based caching, and generic repository patterns, alongside the creation of the initial Web API presentation layer with GraphQL and REST endpoints.
2021–2024 — Docker support and MongoDB integration
4 changes.
This period focused on enhancing the development environment by adding Docker Compose support for local orchestration of the application stack. It also introduced a new MongoDB data access library with generic repository patterns and added unit tests for the Note API.
Features
Added Docker support for local development environment
Developers can now easily spin up the full application stack locally using Docker Compose. The new \docker-compose.yml\ file orchestrates the WebApi service along with its required dependencies: a SQL Server 2022 database, a MongoDB instance, and a Redis cache. A \.dockerignore\ file has also been added to optimize build contexts by excluding unnecessary files like build artifacts and local configuration secrets.
src · high confidence
Added EF Core mapping infrastructure and initial Note entity configuration
The Data.Mapping library now provides a reusable base class for Entity Framework Core entity configurations, allowing entities to define their database schema via the IMappingConfiguration interface. As a concrete example, the Note entity is mapped to a 'Notes' table with specific column constraints (e.g., max length 255 for Title, Category, Description, OwnerEmail) and a default SQL value for the CreateUTC timestamp.
src/Libraries/Data/Mapping · high confidence
Added EmailRequest data transfer object
Introduced the EmailRequest DTO class within the Models.DTOs.Email namespace, defining the structure for email transmission requests with properties for the recipient (To), sender (From), subject line, and message body.
src/Libraries/Models/DTOs/Email · high confidence
Added IP address helper utility
A new IpHelper class has been introduced in the Core Helpers library, providing a static method to retrieve the local machine's IPv4 address by resolving the hostname and filtering for InterNetwork address families.
src/Libraries/Core/Helpers · high confidence
Added LogDto data transfer object
A new LogDto class has been introduced in the Models.DTOs.Log namespace to represent log data. This data transfer object includes properties for recipient (To), subject, body, sender (From), user email, and login time, enabling structured handling of log-related information within the application.
src/Libraries/Models/DTOs/Log · high confidence
Added Redis-based caching library with distributed locking
A new caching library has been introduced in the Caching namespace, providing a Redis-backed implementation for application data caching. This includes an ICacheManager interface and a RedisCacheManager implementation that handles asynchronous and synchronous get/set operations, key prefix removal, and cache clearing. The library also integrates RedLock for distributed locking via an ILocker interface and RedisConnectionWrapper, allowing safe concurrent access to shared resources. Service extensions are provided to register these components in the dependency injection container, configuring them via RedisSettings.
src/Libraries/Caching · high confidence
Added account management and authentication services
The identity library now includes concrete implementations for user account operations, exposing an \IAccountService\ interface with methods for registering new users, authenticating via email and password, confirming email addresses, resetting passwords, refreshing JWT tokens, and logging out. This service layer integrates with ASP.NET Core Identity for user management and role handling, utilizes JWT for session tokens, and coordinates with an email service for verification and password reset flows.
src/Libraries/Identity/Services · high confidence
Added account-related data transfer objects
New DTOs have been introduced in the account module to support user registration, authentication, password management, and token handling. This includes RegisterRequest for user sign-up with validation, AuthenticationRequest for login, RefreshToken and RefreshTokenRequest for session management, ForgotPasswordRequest and ResetPasswordRequest for password recovery flows, and UserDto for representing user profile data with associated roles.
src/Libraries/Models/DTOs/Account · high confidence
Added configuration models for JWT, Mail, and Redis settings
New settings classes have been introduced to support externalized configuration for authentication, email delivery, and caching. JWTSettings defines properties for the signing key, issuer, audience, and token duration. MailSettings provides fields for SMTP host, port, credentials, and sender display name. RedisSettings includes configuration for the connection string, database ID, cache time, and a specific key for data protection.
src/Libraries/Models/Settings · high confidence
Added default role and super-admin user seeding
The Identity library now includes seed data to automatically create four default roles (SuperAdmin, Admin, Moderator, Basic) and a default super-admin user account upon initialization. This ensures that the application starts with a predefined administrative user (sinantok) assigned to all roles, simplifying initial setup and access.
src/Libraries/Identity/Seeds · high confidence
Added email sending capability via SMTP
A new EmailService implementation has been added to the Core Services library, enabling the application to send emails via SMTP. This service integrates with existing MailSettings for configuration (host, port, credentials) and uses MailKit to construct and transmit MIME messages, wrapping any transmission errors in an ApiException for consistent error handling.
src/Libraries/Core/Services · high confidence
Added login log tracking and note management services
New concrete service implementations have been introduced to handle specific domain operations. LoginLogService provides functionality to record and retrieve login activity by email using a MongoDB repository. NoteService exposes methods for managing user-specific notes, including retrieving all notes owned by the authenticated user, fetching individual notes by ID, filtering by category, inserting new notes, and deleting notes, all backed by a generic repository.
src/Libraries/Services/Concrete · high confidence
Added response model classes for authentication and base API responses
Introduced new model classes in the ResponseModels library to standardize API response structures. The new AuthenticationResponse class defines the shape of authentication results, including user identity details, roles, verification status, and JWT/refresh tokens. Additionally, a generic BaseResponse class was added to provide a consistent wrapper for API responses, supporting success/failure states, messages, error lists, and typed data payloads.
src/Libraries/Models/ResponseModels · high confidence
Core library adds service registration for email, database, and Swagger
The Core library now provides a centralized service extension method that registers the new IEmailService interface and its implementation, configures the ApplicationDbContext with SQL Server and ensures the database is created on startup, sets up generic repositories and the UnitOfWork pattern, registers application services like NoteService and LoginLogService, and enables Swagger UI with JWT Bearer authentication support.
src/Libraries/Core · high confidence
Identity library adds JWT authentication and database initialization
The Identity library now includes a ServiceExtensions class that registers account services, configures JWT Bearer authentication with specific token validation parameters, and sets up Entity Framework Core with SQL Server. It also ensures the database schema is created on startup via EnsureCreated().
src/Libraries/Identity · high confidence
Initial Identity database schema migration added
The Identity library now includes the initial Entity Framework Core migration to establish the user and role management database structure. This migration creates the 'Identity' schema and defines tables for Users, Roles, and their associated claims, logins, and tokens, along with the necessary indexes for normalized names and emails.
src/Libraries/Identity/Migrations · high confidence
Initial Web API presentation layer with authentication, GraphQL, and caching
This change introduces the \WebApi\ project within \src/Presentations\, establishing the core HTTP interface for the application. It provides REST controllers for account management (registration, login, password reset, logout) and note operations, alongside a GraphQL endpoint for querying and mutating notes. The implementation includes a custom \CachedAttribute\ for response caching via Redis, an \ErrorHandlerMiddleware\ for standardized error responses, and an \AuthenticatedUserService\ to resolve the current user's identity. Additionally, it configures Serilog for logging, Swagger for API documentation, and GraphiQL for interactive GraphQL testing.
src/Presentations · high confidence
Initial database schema for Notes entity
The application's data layer now includes the initial Entity Framework Core migrations to establish the database schema. This introduces a 'Notes' table containing fields for Id, Title, Category, Description, OwnerEmail, and CreateUTC, with the latter automatically populated with the current UTC timestamp upon creation.
src/Libraries/Data/Migrations · high confidence
Introduction of ApiException with HTTP status code support
A new ApiException class has been added to the Core.Exceptions namespace, extending the standard Exception type to include a StatusCode property. This allows the application to associate specific HTTP status codes with API errors, facilitating more precise error handling and response generation in the middleware layer.
src/Libraries/Core/Exceptions · high confidence
Introduction of Roles enumeration for access control
A new Roles enumeration has been added to the Models library, defining four distinct user levels: SuperAdmin, Admin, Moderator, and Basic. This enum provides a structured way to represent and manage user permissions within the application.
src/Libraries/Models/Enums · high confidence
Introduction of UnitOfWork pattern for data access
A new UnitOfWork implementation has been added to the Data library, providing a centralized way to manage database contexts and repositories. This change introduces an IUnitOfWork interface and a concrete UnitOfWork class that wraps the ApplicationDbContext, allowing consumers to retrieve generic repositories for specific entity types and commit all changes to the database in a single transaction via the Complete method.
src/Libraries/Data/UnitOfWork · high confidence
Introduction of abstracted database context for entity mapping
The application now includes a new \ApplicationDbContext\ and \IDbContext\ interface within the data library. This change introduces a mechanism to automatically discover and apply entity mappings at runtime by scanning the assembly for types inheriting from \MappingEntityTypeConfiguration\<\>\, simplifying the registration of database entities without manual configuration in the context.
src/Libraries/Data/Contexts · high confidence
Introduction of database entity models for notes
Added new data models to the application's domain layer, introducing a base entity class with standard identification and creation timestamp fields, and a specific Note entity that extends this base to include title, category, description, and owner email properties. These classes define the structure for persisting note data in the database.
src/Libraries/Models/DbEntities · high confidence
Introduction of generic repository pattern for data access
A new generic repository implementation has been added to the data layer, providing a standardized interface for common database operations such as retrieving, inserting, updating, and deleting entities. This change introduces \IGenericRepository\<T\>\ and \GenericRepository\<T\>\, which encapsulate Entity Framework Core interactions and allow for consistent data access patterns across the application without needing specific repository classes for every entity type.
src/Libraries/Data/Repos · high confidence
MongoDB data access library added
A new MongoDB integration library has been introduced, providing a generic repository pattern for data access. This includes configuration support via \MongoDbOptions\, a base document class for schema handling, and a \BsonCollectionAttribute\ to map entities to specific collections. The library exposes standard CRUD operations (Create, Read, Update, Delete) through \IMongoRepository\ and \MongoRepository\, and registers these services along with the MongoDB client and database instances into the dependency injection container via the \AddMongo\ extension method.
src/Libraries/Data.Mongo · high confidence
New service interfaces for authentication, login logs, and notes
The application now exposes dedicated service contracts to manage user identity, security auditing, and note storage. IAuthenticatedUserService provides access to the current user's email address. ILoginLogService enables recording login events and retrieving login history by email. INoteService expands note management capabilities by adding methods to retrieve all notes for the current user (both synchronous and asynchronous versions), alongside existing operations for inserting, retrieving by ID or category, and deleting notes.
src/Libraries/Services/Interfaces · high confidence
Behavioural changes
Custom Identity database schema and table mappings
The IdentityContext now configures the ASP.NET Core Identity database schema to use the 'Identity' default schema and maps core entities to specific table names: 'User' for users, 'Role' for roles, 'UserRoles' for the join table, 'UserClaims', 'UserLogins', 'RoleClaims', and 'UserTokens'. This changes the underlying database structure for identity data compared to the default IdentityDbContext conventions.
src/Libraries/Identity/Contexts · high confidence
Custom Identity models with integer keys and extended user/role data
The Identity library now uses custom entity classes for users, roles, and their associated claims, logins, and tokens, all based on ASP.NET Core Identity but configured to use integer primary keys instead of strings. The new ApplicationUser model includes FirstName and LastName properties, while ApplicationRole includes a CreatedDate timestamp and explicit navigation properties to link users and roles. These changes enable more granular user data storage and role-based access control with typed keys.
src/Libraries/Identity/Models · high confidence
Test coverage
Added unit tests for the Note API
Added unit tests for the Note API, including an ApiFactory helper to configure an in-memory database and authenticated HTTP clients, and test cases verifying fetching all notes and adding a new note.
src/Tests · high confidence
Dependencies
Upgrade to .NET 8 and refresh library dependencies
The solution has been upgraded from .NET 5 to .NET 8, affecting all nine project files in the Libraries, Presentations, and Tests directories. This migration updates the target framework to net8.0 and refreshes key dependencies, including Microsoft.EntityFrameworkCore, Microsoft.AspNetCore.Identity, and Microsoft.AspNetCore.Authentication.JwtBearer to version 8.0.7. Additional packages such as AutoMapper, GraphQL, Serilog, and health check libraries have also been added or updated to support the new runtime and architectural structure.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 63 → 59 (-4.1)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 57 → 54 (-2.8)
- Architecture 89 → 89 (+0.1)
- Maturity 63 → 67 (+4.1)
- Readiness 74 → 68 (-6.7)
- Security 72 → 57 (-15.1)
Resolved (14)
- Boundary-crossing change coupling: AccountService.cs ↔ AccountController.cs (src/Libraries/Identity/Services/Concrete/AccountService.cs)
- Bounded contexts not declared
- Coverage not measured — analyzer environment
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low CVE: Microsoft.Identity.Client 4.56.0
- Medium CVE: Azure.Identity 1.10.3
- Medium CVE: Azure.Identity 1.10.3
- Medium CVE: SharpCompress 0.23.0
- Medium CVE: SharpCompress 0.23.0
- No exposed public API
- The 'Features' and 'Purpose of this Project' sections are present in the outline but not shown; completeness cannot be confirmed from the excerpt. (README.md)
- dormant codebase — no living knowledge left to concentrate
New (19)
- Documentation: no licence statement (README.md)
- Duplicated block (17 lines × 2) (src/Libraries/Identity/Services/Concrete/AccountService.cs)
- High IaC: WD-COMPOSE-0002 (src/docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (src/docker-compose.yml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: Azure.Identity 1.10.3
- Medium CVE: SharpCompress 0.23.0
- Medium IaC: WD-COMPOSE-0002 (src/docker-compose.yml)
- Medium IaC: WD-DOCKER-0003 (src/Presentations/WebApi/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (src/Presentations/WebApi/Dockerfile)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- WriteOnlyPrivateField (src/Libraries/Identity/Services/Concrete/AccountService.cs)
- WriteOnlyPrivateField (src/Libraries/Services/Concrete/NoteService.cs)
- WriteOnlyPrivateField (src/Presentations/WebApi/Controllers/NoteController.cs)
- redundant comment (src/Libraries/Caching/RedisCacheManager.cs)
API surface
- Unchanged — 13 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sinantok/aspnetcore-webapi-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit faf733fbceb7359644ad7431576a52aed109948e — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.