snykk/go-rest-boilerplate
61.1
Adequate · 21 September 2026
7.1k
lines of production code
Go
primary language
4
measurements over time
What this system is
This release establishes the core authentication and user management capabilities, introducing a complete suite of endpoints for registration, login, OTP verification, and password management. The architecture has been significantly modernized with structured logging, OpenTelemetry tracing, and Prometheus metrics for full observability. Additionally, the codebase now features a robust infrastructure layer including database migrations, caching with Redis and Ristretto, and a centralized configuration system.
Features
Add OpenTelemetry instrumentation to PostgreSQL database driver
The application now wraps the PostgreSQL connection with OpenTelemetry, automatically generating spans for every query and exposing database statistics as metrics. This change introduces a new \drivers\ package containing \InitializeSQLXDatabase\ and \SetupSQLXPostgres\ functions that configure connection pooling and enable distributed tracing for database interactions.
internal/datasources/drivers · high confidence
Add database seeding command for initial data population
A new 'seed' command has been added to the application, allowing users to populate the database with initial data. The command initializes the application configuration, establishes a PostgreSQL connection using the new SetupSQLXPostgres driver, and executes a user seeder to insert default user records. This provides a convenient way to bootstrap the database for development or testing purposes.
cmd/seed · high confidence
Add password hashing, OTP generation, and array helper functions
The helpers package now includes new utility functions for generating and validating bcrypt password hashes, creating cryptographically secure OTP codes using rejection sampling to avoid modulo bias, and checking if a string exists in a string slice. Each function is accompanied by unit tests to verify correctness and robustness.
pkg/helpers · high confidence
Added OpenTelemetry tracing and Prometheus metrics for observability
The application now supports distributed tracing via OpenTelemetry, allowing HTTP server spans to be exported to stdout or an OTLP endpoint. Additionally, Prometheus metrics have been added to track cache operations (hit/miss/error), mailer outcomes, and PostgreSQL connection pool status, enabling better monitoring and debugging of these subsystems.
pkg/observability · high confidence
Added Redis and Ristretto cache implementations
The application now supports two distinct caching backends. A Redis-based cache is introduced with bounded operation timeouts, JSON serialization, and OpenTelemetry tracing instrumentation. Additionally, an in-memory Ristretto cache is added with a 5-minute safety-net TTL to prevent stale data from persisting indefinitely.
internal/datasources/caches · high confidence
Added database seeding capability for initial user data
A new seeder implementation has been introduced to populate the database with initial user records. The \seeder.go\ file defines the \Seeder\ interface and its concrete \seeder\ struct, which handles inserting user data into the \users\ table using a transactional approach. The \seeder.users.go\ file provides the default test user data (e.g., 'patrick star 7' and 'john doe') that is loaded at initialization. This allows for easy database population during development or testing.
cmd/seed/seeders · high confidence
Added development tooling and project scaffolding
The repository now includes configuration for the Air hot-reload tool (.air.toml), a Makefile with targets for building, testing, linting, and managing the local development environment, a .golangci.yml file for Go linting and formatting, and a .gitignore file to exclude build artifacts and temporary directories. Additionally, a REST API test file (rest.http) is provided to demonstrate and test authentication endpoints such as registration, login, and OTP verification.
(repo-wide) · high confidence
Added user record and mapper for database persistence
A new Users struct and its corresponding mappers (ToV1Domain, FromUsersV1Domain, ToArrayOfUsersV1Domain) have been added to the records package. This introduces the data model for user entities, mapping database fields (id, username, email, password, active status, role ID, and timestamps) to the internal domain.User model, enabling the storage and retrieval of user records.
internal/datasources/records · high confidence
HTTP middleware layer refactored with new security, observability, and rate-limiting features
The internal HTTP middleware layer has been restructured into distinct, testable components. A new access log formatter provides color-coded, structured logging that includes request IDs and latency. An authentication middleware was introduced, implementing Bearer token validation, JWT parsing, and Redis-based token revocation checks. Security hardening is addressed via a headers middleware that enforces HSTS, CSP, and other browser-side protections, alongside a body size limit middleware to prevent slow-body attacks. Additionally, a rate-limiting middleware using an in-memory IP-based limiter and a Prometheus metrics middleware for request counting and duration tracking have been added. These changes improve observability, security posture, and operational monitoring for the HTTP layer.
internal/http/middlewares · high confidence
Introduce CLI tool for executing database migrations
A new command-line interface has been added at cmd/migration to manage database schema changes. Users can now run 'up' to apply new tables, columns, or other structures, or 'down' to drop them, utilizing the internal migration runner and SQLX Postgres driver.
cmd/migration · high confidence
Introduce CurrentUser helper for HTTP authentication context
A new \context.go\ file was added to the \internal/http/auth\ package, providing a \CurrentUser\ struct and a \CurrentUserFromContext\ helper function. This change allows HTTP handlers to easily extract authenticated user details (ID, email, admin status, and JTI) from the Gin context, returning a specific \ErrNotAuthenticated\ error if the request is not authenticated.
internal/http/auth · high confidence
Introduce deterministic clock abstraction and refresh token support in JWT service
The JWT package now supports generating paired access and refresh tokens, with the access token expiring in a configurable number of hours and the refresh token expiring after 7 days. To enable deterministic testing of token expiry and issuance times, a new \pkg/clock\ package provides a \Clock\ interface with \RealClock\, \Frozen\, and \Stub\ implementations. The \jwt\ service accepts a \Clock\ via \WithClock\ or constructor, allowing tests to freeze or advance time without sleeping. This change also adds unit tests for the clock abstraction and the JWT service's token generation and parsing logic.
pkg/jwt · high confidence
Introduce password management and authentication flows
The auth use-case now includes new endpoints for changing passwords, requesting password resets, and logging in. The domain layer was refactored to include a User entity with password hashing, email normalization, and token revocation cutoffs. The auth use-case implements login with brute-force lockout, forgot-password with rate limiting, change-password with token revocation, and logout. Tests cover happy paths, error conditions, and end-to-end scenarios.
internal/business/usecases/auth · high confidence
Introduce user response DTO with token support
Added a new UserResponse struct in the HTTP data transfer layer to serialize user data for API responses. The type includes fields for authentication tokens (access and refresh), enabling the API to return token pairs alongside user details in login and refresh endpoints, while a separate path handles standard user queries without exposing sensitive token data.
internal/http/datatransfers/responses · high confidence
New /users/me endpoint to retrieve the authenticated user's profile
A new HTTP handler for the /users/me GET endpoint has been introduced, allowing users to fetch their own profile data. The handler extracts the authenticated user from the JWT, calls the users Usecase to retrieve the record, and returns the user's profile in the response. A corresponding test suite validates the happy path, 404 handling, and 401 unauthorized scenarios.
internal/http/handlers/v1/users · high confidence
New authentication and user profile endpoints
The HTTP routing layer now exposes a dedicated /auth group for anonymous operations including register, login, OTP send/verify, token refresh, logout, and password management (forgot/reset/change). A separate /users group provides a protected /users/me endpoint to fetch the current authenticated user's data. The /auth routes are secured with rate limiting and a 4 KiB body size cap, while /users/me requires valid JWT authentication.
internal/http/routes · high confidence
New v1 authentication endpoints and handlers
The v1/auth package now exposes a full authentication suite: login, register, OTP send/verify, password change/reset/forgot, logout, and token refresh. Each handler validates input, calls the corresponding usecase, and records structured audit events (login, register, OTP, password changes, logout, refresh) with correlation IDs for observability. Tests cover happy paths, validation errors, and failure modes for all endpoints.
internal/http/handlers/v1/auth · high confidence
Structured audit logging for authentication events
A new audit package has been introduced to emit a separate, structured JSON stream of security-relevant events, including register, login, logout, refresh, OTP, and password lifecycle actions. This separation from operational logs ensures that authentication and security events are retained and formatted independently, facilitating forensic analysis and alerting. The implementation includes an Event struct with fields for user ID, email, IP, and correlation IDs (RequestID, TraceID) to link audit entries to application logs and traces, along with tests verifying the JSON output and field omission behavior.
pkg/audit · high confidence
Behavioural changes
API entry point and structured logging integration
The API entry point (cmd/api/main.go) has been introduced, establishing the application startup sequence. This includes initializing the application configuration and integrating a structured Zap logger, which replaces previous logging mechanisms. The main function also configures runtime settings and starts the server, while Swagger annotations define the OpenAPI specification for the REST API.
cmd/api · medium confidence
Added request models for authentication endpoints
Introduced new request structures for authentication endpoints, including RegisterRequest, SendOTPRequest, VerifyOTPRequest, LoginRequest, RefreshRequest, ChangePasswordRequest, ForgotPasswordRequest, and ResetPasswordRequest. These models define the expected JSON payloads for user registration, OTP handling, login, token refresh, and password management operations.
internal/http/datatransfers/requests · medium confidence
Centralized endpoint, environment, error, logger, and user context constants
The application now defines key constants in the internal/constants package, including the API base path (/api/v1), environment identifiers (production/development), configuration loading errors, structured logging categories (server, config, database, HTTP, migration, CORS, seeder, cache), and the context key for authenticated users. This centralizes configuration and logging metadata, ensuring consistent paths, environment handling, error definitions, and user context keys across the codebase.
internal/constants · high confidence
Introduce structured logging, OpenTelemetry tracing, and graceful shutdown
The API server now uses a structured Zap logger instead of logrus, and integrates OpenTelemetry for distributed tracing and HTTP server-span instrumentation. The application also implements graceful shutdown, ensuring that the async OTP mailer queue is drained and the rate limiter is stopped cleanly before the HTTP server shuts down.
cmd/api/server · high confidence
Introduce unified error envelope, structured validation errors, and health check endpoints
HTTP responses now use a consistent BaseResponse envelope that includes a request ID for tracing. Error handling has been centralized: domain errors map to appropriate HTTP status codes, while validation failures return a structured 422 Unprocessable Entity response with per-field details. Additionally, new /health and /ready endpoints allow users to verify the status of the service, database, and Redis cache.
internal/http/handlers/v1 · high confidence
Introduction of typed error envelope for HTTP response mapping
The application now uses a structured 'apperror' package to handle domain errors, providing a typed envelope that maps to specific HTTP status codes. This change ensures that internal or low-level error details are not leaked to clients, as the 'DomainError' type separates the user-facing message from the underlying cause, allowing the HTTP layer to safely map error types to appropriate status codes while preserving the cause for logging.
internal/apperror · high confidence
New centralized configuration system with strict validation and defaults
The application now uses a structured configuration system (internal/config) that loads environment variables from .env files. This introduces strict validation for critical settings including JWT secrets (minimum 32 characters), port numbers, and environment-specific requirements (e.g., ALLOWED\_ORIGINS in production). It also adds configurable defaults for database connection pools (25/5/15), OTP attempts (5), mailer workers (2), and bcrypt cost (12). Additionally, it supports OpenTelemetry tracing configuration and Redis cache settings.
internal/config · high confidence
OTP and password-reset emails are now sent asynchronously with automatic retries
The mailer now processes OTP and password-reset emails via an internal worker pool, allowing HTTP requests to return immediately while emails are queued and delivered in the background. This change improves request latency by removing SMTP I/O from the hot path. The new async implementation includes automatic retry logic for transient SMTP failures, graceful queue draining on shutdown, and trace propagation so that background email sends are correctly linked to the originating request's OpenTelemetry span. A new embedded HTML template for OTP emails is also introduced.
pkg/mailer · high confidence
Restructured user repository with explicit gateway interface and per-method file separation
The user repository has been refactored to use a dedicated interface package (\_interface) that defines the gateway for all user data operations, decoupling the use-case layer from concrete database implementations. Each user repository method (Store, GetByEmail, GetByID, List, ChangeActiveUser, UpdatePassword, SoftDelete) is now implemented in its own file within the postgres/users directory, improving code navigation and diff clarity. The implementation enforces soft-delete semantics (excluding deleted rows by default) and includes integration tests verifying user lifecycle, filtering, pagination, and conflict handling.
internal/datasources/repositories · high confidence
Restructured user usecases into separate files with structured logging and cache invalidation
The user-related business logic in the 'users' package has been refactored into individual files (activate, get\_by\_email, get\_by\_id, store, update\_password) to improve maintainability. Each method now uses structured logging via the 'zap' logger, recording request and response details. Additionally, the 'Activate' and 'UpdatePassword' methods now explicitly invalidate the Ristretto in-memory cache for the affected user's email, ensuring that subsequent logins or lookups retrieve fresh data from the database rather than stale cached entries.
internal/business/usecases/users · high confidence
Structured per-field validation errors for API responses
The validation layer now returns structured, per-field error details (type ValidationErrors) instead of flat strings. This allows API consumers to identify exactly which fields failed and why, supporting the 422 Unprocessable Entity response for user registration and other endpoints.
pkg/validators · high confidence
Switch to structured logging with automatic trace and request ID correlation
The logging subsystem has been refactored to use the Zap library, replacing the previous implementation. This change introduces structured logging capabilities, allowing developers to attach key-value pairs to log entries. Additionally, the logger automatically extracts and includes the W3C trace ID (from OpenTelemetry context) and the external X-Request-ID in every log entry that carries a context, enabling easier correlation of logs with distributed traces and client requests.
pkg/logger · high confidence
User table schema and constraints updated
The users table now includes a password\_changed\_at column and enforces case-insensitive uniqueness for email and username via partial unique indexes that exclude soft-deleted rows. Email values are normalized to lowercase, and existing data is migrated to match this format.
cmd/migration/migrations · high confidence
Test coverage
Added integration test harness for auth and user flows; Added mock implementations for testing; Extracted migration runner into a testable library.
Dependencies
Modernizes Go dependencies and tooling
The project has been modernized with updated dependencies, including Go 1.25.0, Gin v1.12.0, and Go-Redis v9. The go.mod file also introduces OpenTelemetry, Prometheus, and testcontainers packages, supporting new observability and testing capabilities.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 59 → 61 (+2.5)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 95 → 92 (-2.8)
- Architecture 100 → 66 (-33.9)
- Maturity 93 → 93 (-0.0)
- Readiness 49 → 54 (+5.0)
- Security 68 → 85 (+16.7)
- Domain Modelling 51 → 56 (+5.5)
Resolved (40)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (pkg/jwt/jwt.go)
- Duplicated block (11 lines × 9) (internal/http/handlers/v1/auth/auth.change_password.go)
- Duplicated block (12 lines × 2) (internal/business/usecases/auth/auth.change_password.go)
- Duplicated block (13 lines × 2) (internal/business/usecases/auth/auth.login.go)
- Duplicated block (14 lines × 2) (internal/business/usecases/auth/auth.change_password.go)
- Duplicated block (15 lines × 2) (internal/business/usecases/auth/auth.logout.go)
- Duplicated block (15 lines × 2) (internal/business/usecases/auth/auth.register.go)
- Duplicated block (15 lines × 2) (internal/business/usecases/auth/auth.send_otp.go)
- Duplicated block (16 lines × 4) (internal/business/usecases/auth/auth.forgot_password.go)
- High vulnerability: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 20 more
New (99)
- Critical CVE: [GHSA redacted] (go.mod)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (internal/business/usecases/auth/auth.login.go)
- Duplicated block (10 lines × 2) (internal/business/usecases/auth/auth.logout.go)
- Duplicated block (10 lines × 2) (internal/http/handlers/v1/auth/auth.send_otp.go)
- Duplicated block (10 lines × 3) (internal/business/usecases/auth/auth.forgot_password.go)
- Duplicated block (11 lines × 2) (internal/business/usecases/auth/auth.change_password.go)
- Duplicated block (11 lines × 2) (internal/business/usecases/auth/auth.login.go)
- Duplicated block (11 lines × 2) (internal/http/handlers/v1/auth/auth.forgot_password.go)
- Duplicated block (11 lines × 2) (internal/http/handlers/v1/auth/auth.logout.go)
- Duplicated block (11 lines × 2) (internal/http/handlers/v1/auth/auth.refresh.go)
- Duplicated block (11 lines × 3) (internal/http/handlers/v1/auth/auth.logout.go)
- Duplicated block (11 lines × 5) (internal/http/handlers/v1/auth/auth.forgot_password.go)
- Duplicated block (12 lines × 2) (internal/datasources/repositories/postgres/users/users.soft_delete.go)
- Duplicated block (12 lines × 6) (internal/business/usecases/auth/auth.login.go)
- Duplicated block (12–15 lines × 2) (internal/business/usecases/auth/auth.login.go)
- Duplicated block (13 lines × 2) (internal/business/usecases/auth/auth.change_password.go)
- Duplicated block (13 lines × 2) (internal/business/usecases/auth/auth.send_otp.go)
- Duplicated block (13 lines × 2) (pkg/jwt/jwt.go)
- …and 79 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
snykk/go-rest-boilerplate was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 55a31186d48ed0b9a57490806d269818e9289a0e — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.