Skip to content
CAI
Software that uses CAICheck a score

snamiki1212/realworld-v1-rust-actix-web-diesel

66.6

Adequate · 21 September 2026

3.3k

lines of production code

Rust

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Rust-based backend service implementing the Conduit API specification, providing a complete social blogging platform. It manages user authentication, article creation and modification, and social graph interactions including following, favoriting, and commenting. The architecture is structured around distinct feature modules for users, articles, comments, and tags, all backed by a PostgreSQL database with Diesel ORM.

How it got here

2021 — Initial project setup and schema definition

11 changes.

This period focused on establishing the foundational architecture of the Rust-based application, including the initial Cargo configuration, dependency injection container, and centralized error handling. Simultaneously, the team defined the core database schema and migrations for users, articles, comments, favorites, follows, and tags, while also setting up end-to-end API testing infrastructure.

2022–2023 — core feature implementation

7 changes.

This period focused on implementing the core application features, including user authentication, article and comment management, and tag handling. The work established the full stack for these domains, from database entities and repositories to controllers and middleware, while also adding utility scripts for environment setup and service readiness.

Features

Add comment feature with create, read, and delete capabilities

Users can now interact with comments on articles. The application introduces a new 'comment' feature that allows users to create, fetch, and delete comments. This includes the controller endpoints for listing, creating, and deleting comments, the entity and repository layers for data access, and the use-case layer that orchestrates the business logic. The implementation supports fetching comments with associated author profiles and handles the specific logic for deleting comments, including a subquery to verify article ownership.

src/app/features/comment · high confidence

Add comments table to the database schema

A new 'comments' table has been added to the database, containing fields for id, article\_id, author\_id, body, create\_at, and updated\_at, along with indexes on article\_id and author\_id. The migration includes both an 'up' script to create the table and a 'down' script to drop it, enabling the storage of user comments linked to articles and authors.

_migrations/2021-10-24-230744\_create\_articles, migrations/2021-10-29-195721\_create\comments · high confidence

Added article and favorite management capabilities

Introduced new features for managing articles and user favorites. Users can now create, read, update, and delete articles, as well as favorite and unfavorite them. The update operation automatically generates a URL-friendly slug from the article title. Additionally, the system supports filtering articles by tag, author, or favorite status, and displays author profiles and favorite counts in the responses.

src/app/features/article · high confidence

Added initial Diesel database migration setup

The application now includes the initial database migration for Diesel, a Rust ORM. This migration creates two PostgreSQL functions, \diesel\_manage\_updated\_at\ and \diesel\_set\_updated\_at\, which automatically update an \updated\_at\ timestamp column on any table that registers with it. This enables automatic timestamp management for database rows without manual intervention.

_migrations, migrations/00000000000000\_diesel\_initial\setup · high confidence

Added tag management feature

Introduced a new 'tag' feature module containing the full stack for managing tags: an entity model, repository for database access, usecase for business logic, presenter for HTTP responses, and a controller endpoint. This enables fetching and displaying tags associated with articles.

src/app/features/tag · high confidence

Added utility scripts for environment setup and service readiness

The scripts directory now includes a shell script to copy the example environment file to the active .env file, and a wait-for-it script that polls a specified host and port to ensure a service is ready before proceeding. These changes improve the developer experience by automating environment configuration and handling service dependencies during startup.

scripts · medium confidence

Introduce structured error handling and database schema for core entities

The application now uses a centralized \AppError\ enum in \src/error.rs\ to map internal failures (from Diesel, bcrypt, JWT, and UUID libraries) to specific HTTP status codes (401, 403, 404, 422, 500) with JSON responses. Additionally, \src/schema.rs\ defines the database tables for users, articles, comments, favorites, follows, and tags, establishing the data model for the platform's core features.

src · high confidence

Introduced follow and healthcheck feature modules

The application now includes dedicated modules for managing user follows and a healthcheck endpoint. The follow feature introduces a Follow entity with database operations for creating and deleting follow relationships, as well as fetching followee IDs. The healthcheck feature exposes a simple HTTP endpoint that returns 'OK' to indicate service status.

src/app/features, src/app/features/follow, src/app/features/healthcheck · high confidence

Introduced user feature with authentication and profile management

Added a new user feature module containing controllers, entities, presenters, repositories, requests, and usecases. This enables user signup, signin, profile updates, and token generation, implementing the core authentication and user management capabilities of the application.

src/app/features/user · high confidence

Introduces a centralized dependency injection container and utility modules

The application now uses a single \DiContainer\ struct to manage the lifecycle and wiring of all domain features (Article, Comment, Favorite, Profile, Tag, User). This container, located in \src/utils/di.rs\, instantiates repositories, presenters, and use cases, replacing the previous scattered initialization logic. Additionally, new utility modules have been added to \src/utils/\: \api.rs\ for standardizing HTTP responses, \converter.rs\ for string formatting, \date.rs\ for ISO 8601 serialization, \db.rs\ for database pool management, \hasher.rs\ for password hashing, \token.rs\ for JWT handling, and \uuid.rs\ for ID parsing. These changes support a cleaner architecture by centralizing cross-cutting concerns and dependency management.

src/utils · high confidence

New authentication middleware and API route definitions

The application introduces a new authentication middleware that validates user tokens from the Authorization header and injects the current user into the request context, while also defining the full set of API routes for users, profiles, articles, and comments. The middleware enforces authentication on all endpoints except health checks and login/signup, returning 401 Unauthorized for invalid or missing tokens. The route definitions in src/app/drivers/routes.rs map HTTP methods to specific controllers for user management, profile following, article CRUD, and comment operations.

src/app/drivers · high confidence

Behavioural changes

Added database migration for the tags table

The application now includes a database migration that creates a 'tags' table to associate tags with articles. The table stores the tag name, a creation timestamp, and an update timestamp, with a foreign key linking to the 'articles' table. A database index is also created on the article\_id column to optimize lookups.

_migrations/2021-10-25-170453\_create\tags · high confidence

App module reorganization

The application's module structure has been reorganized. A new \src/app/mod.rs\ file has been introduced to define the \drivers\ and \features\ submodules, reflecting a shift in how the application's components are grouped and exposed.

src/app · medium confidence

Database migration adds the 'follows' table to support user following relationships

A new database migration introduces the 'follows' table to store user follow relationships. The table includes 'follower\_id' and 'followee\_id' columns referencing the 'users' table, with a composite primary key and indexes on both foreign keys for performance. A check constraint ensures a user cannot follow themselves. This change enables the backend to track and query social graph connections.

_migrations/2021-10-24-020751\_create\follows · medium confidence

Database migration for favorites table

A new 'favorites' table has been added to the database schema, allowing users to save articles. The table includes foreign keys for 'article\_id' and 'user\_id', along with timestamps and a unique constraint to prevent duplicate favorites for the same user and article.

_migrations/2021-10-29-224838\_create\favorites · high confidence

Initial user table schema

The database now includes a 'users' table containing columns for email (with a unique constraint), username, password, bio, image, and timestamps. This migration establishes the foundational schema for user data, including the addition of the username and bio fields alongside the existing email and password fields.

_migrations/2021-10-21-064114\_create\users · medium confidence

Test coverage

Add end-to-end API tests for the Conduit backend

Added a new e2e test suite for the Conduit API, including a Postman collection (Conduit.postman\_collection.json) and an OpenAPI specification (openapi.yml) to define the API contract. A shell script (run-api-tests.sh) was also added to execute these tests against the API, enabling automated end-to-end verification of endpoints such as user registration, login, and profile management.

e2e · high confidence

Dependencies

Initial project setup with Rust dependencies

The project now includes a Cargo.toml and Cargo.lock, establishing a Rust environment with actix-web 4.3, diesel 2.1.0, jsonwebtoken 8.3, bcrypt 0.14.0, and other supporting libraries.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 66 → 67 (+0.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 97 (-2.6)
  • Architecture 99 → 65 (-33.7)
  • Maturity 61 → 63 (+1.8)
  • Readiness 59 → 68 (+9.3)
  • Security 74 → 83 (+8.9)
  • Domain Modelling 82 → 71 (-10.3)

Resolved (30)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • Medium advisory (unmaintained): RUSTSEC-2021-0141 (Cargo.lock)
  • Medium advisory (unmaintained): RUSTSEC-2024-0436 (Cargo.lock)
  • Medium advisory (unmaintained): RUSTSEC-2025-0010 (Cargo.lock)
  • Medium advisory (unmaintained): RUSTSEC-2025-0056 (Cargo.lock)
  • Medium advisory (unsound): RUSTSEC-2025-0023 (Cargo.lock)
  • …and 10 more

New (64)

  • Change coupling: controllers.rs ↔ controllers.rs (src/app/features/article/controllers.rs)
  • Change coupling: controllers.rs ↔ usecases.rs (src/app/features/profile/controllers.rs)
  • Change coupling: presenters.rs ↔ presenters.rs (src/app/features/article/presenters.rs)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (src/app/features/article/presenters.rs)
  • Duplicated block (13–15 lines × 2) (src/app/features/article/repositories.rs)
  • Duplicated block (25–26 lines × 2) (src/app/features/article/repositories.rs)
  • Duplicated block (6–7 lines × 2) (src/app/features/article/repositories.rs)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0026 (Dockerfile)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • …and 44 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

snamiki1212/realworld-v1-rust-actix-web-diesel was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1b844c094208be54008cd993ef51d87b808eea24 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.