soybeanjs/soybean-admin-nestjs
33.2
Weak · 21 September 2026
30.1k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a full-stack administrative platform providing identity and access management, including user, role, and menu configuration. It features a NestJS backend with RBAC, API key authentication, and audit logging, alongside a Vue.js frontend with dynamic layout and UI component libraries. The architecture is a monorepo with shared infrastructure for caching, logging, and database management.
Features
Add HTTP client scripts for domain, role, and user management
A new \api.http\ file has been added to the backend, providing ready-to-use HTTP client scripts for testing the API. These scripts cover authentication, as well as full CRUD operations (list, create, update, delete) for domains, roles, and users. The file also includes scripts for managing routes, API endpoints, login/operation logs, and authorization assignments (permissions, routes, and users).
backend/.http · high confidence
Add backend crypto library with AES and RSA encryption support
A new \backend/libs/infra/crypto\ library has been introduced to provide data encryption and decryption capabilities. The library supports both AES and RSA encryption methods, allowing for configurable modes (CBC, ECB, CTR for AES; PKCS1, PKCS1\_OAEP for RSA) and padding schemes. It exposes a \CryptoModule\ that registers a \CryptoService\ and a \CryptoInterceptor\ to automatically handle request decryption and response encryption based on method and direction metadata. The module also provides decorators (\@Crypto\, \@AESCrypto\, \@RSACrypto\) to configure encryption behavior on specific endpoints.
backend/libs/infra/crypto · high confidence
Add frontend build configuration, Dockerfile, and UI components
The frontend area now includes a complete build and deployment setup. A Dockerfile is added to containerize the application using Node.js for building and Nginx for serving static files. Build configuration files (proxy, time, HTML plugin, router, unocss, and unplugin setups) are introduced to configure Vite. Additionally, reusable page-tab components (button and Chrome-style tabs) are added to the materials package to support the application's navigation interface.
frontend · high confidence
Add reusable pagination and API response helpers
The backend infrastructure library now includes a shared \PaginationParams\ class for standardizing page and size query parameters, along with a generic \ApiRes\ class that provides static factory methods (e.g., \success\, \error\, \ok\) to structure consistent JSON API responses.
backend/libs/infra/rest · high confidence
Added API data collection and Swagger documentation initialization to the bootstrap library
The bootstrap library now includes an ApiDataService that automatically scans all NestJS controllers and methods to collect API endpoint metadata, then emits an event with the collected data. Additionally, the library provides an initDocSwagger function that configures and initializes Swagger UI documentation for the application, including security schemes and versioning information.
backend/libs/bootstrap · high confidence
Added Prisma database seeding for initial system data
The backend now includes a Prisma-based seed script that initializes the database with default system data. This includes creating a built-in domain, default user accounts (Soybean, Administrator, GeneralUser) with pre-set credentials, system roles (Super Admin, Admin, User), menu configurations, role-to-menu assignments, and Casbin authorization rules. Running the seed populates the database with the necessary baseline data for the application to function.
backend/prisma/seeds · high confidence
Added Prisma schema for authentication, logging, and RBAC
The backend database schema now includes models for managing user authentication tokens (access and refresh tokens), login and operation audit logs, and core identity management entities including users, roles, domains, endpoints, and organizations. Additionally, a table for Casbin-based access control rules has been introduced to support role-based permissions.
backend/prisma · high confidence
Added database schema for user, role, menu, and access key management
The backend database schema has been initialized with tables for user management (sys\_user), role-based access control (sys\_role, sys\_user\_role), and menu configuration (sys\_menu). Additionally, the schema includes tables for domain management (sys\_domain), organization structure (sys\_organization), and audit logging (sys\_login\_log, sys\_operation\_log). A new sys\_tokens table is introduced to store access and refresh tokens, while a separate sys\_access\_key table is added to manage access keys and secrets, supporting authentication and API security features.
backend/prisma/migrations · high confidence
Added frontend color, layout, and UI component packages
Introduced new frontend packages for color management, layout, and UI components. The color package provides color palette generation (including AntD-style palettes and recommended palettes) and color name resolution. The materials package introduces an AdminLayout component for header, tab, sider, and footer management, along with a SimpleScrollbar component. Additionally, a UnoCSS preset for common utility classes and a global breadcrumb component for navigation were added.
(repo-wide) · high confidence
Added initial database schema and seed data for deployment
The deployment package now includes a complete set of PostgreSQL migration scripts (01 through 08) that create the core application tables, including users, roles, menus, domains, and audit logs. It also provides seed data to initialize default accounts (Soybean, Administrator, GeneralUser), pre-configure role-to-menu permissions, and set up initial Casbin access control rules, ensuring the database is ready for use upon first deployment.
deploy · high confidence
Centralized constants for API keys, caching, events, and REST responses
The backend/libs/constants library now provides a centralized set of constants to standardize configuration across the application. This includes API key authentication options and strategies (e.g., 'api-key', 'signed-request'), cache prefixes (e.g., 'soybean:cache:'), event names for route collection, operation logging, and API key validation, as well as standard REST response codes and header keys. These constants replace scattered string literals and enums, ensuring consistent naming and values for API key validation, caching, event emission, and REST response handling.
backend/libs/constants · medium confidence
Introduce REST API controllers and DTOs for IAM, access keys, endpoints, and audit logs
The backend's base-system module now exposes a comprehensive set of REST endpoints for managing users, roles, domains, menus, and routes, alongside access key management and login/operation log querying. New controllers (Authentication, Authorization, Domain, Menu, Role, User, AccessKey, Endpoint, LoginLog, and OperationLog) are registered in ApiModule, each backed by corresponding DTOs for request validation and Swagger documentation. This establishes the primary API surface for identity, access, and audit management within the application.
backend/apps/base-system · high confidence
Introduce base-demo app with crypto, file upload, and cache endpoints
A new base-demo application is introduced, providing public endpoints for encryption/decryption (GET/POST /crypto), file uploads with dynamic storage and MD5-based naming, and cache testing. The module configures rate limiting via Redis, integrates Casbin for authorization, and sets up a Fastify-based server with Swagger documentation.
backend/apps/base-demo/src · high confidence
New API key authentication guard and validation services
A new API key authentication system has been introduced, featuring an ApiKeyGuard that validates requests using either simple or complex strategies. Simple keys are validated against a Redis set, while complex keys undergo signature verification (MD5, SHA1, SHA256, HMAC-SHA256) with timestamp and nonce checks against Redis. The implementation includes dedicated services (SimpleApiKeyService, ComplexApiKeyService) and an ApiKeyValidationEvent to emit validation outcomes. Additionally, a JwtAuthGuard was added to handle JWT-based authentication with support for public endpoints.
backend/libs/infra/guard · high confidence
New centralized logging library with request/response tracking
A new backend/libs/logger library has been introduced, providing a centralized logging solution built on Winston. It includes a NestJS interceptor that automatically logs HTTP requests, responses, and errors, with sensitive data (passwords, tokens) redacted from logs. The module supports both synchronous and asynchronous configuration for console and file-based logging, and ensures logs are flushed on application shutdown.
backend/libs/logger · high confidence
New frontend hooks library and global sidebar layout
The frontend now includes a new shared hooks library at \frontend/packages/hooks\ that provides reusable Vue composition functions, including \useBoolean\, \useLoading\, \useCountDown\, \useContext\, \useSvgIconRender\, \useHookTable\, and \useSignal\ for reactive state management. Additionally, a new \GlobalSider\ layout component has been added to the global sidebar module, which manages the sidebar's visual state, logo visibility, and menu wrapper based on the current layout mode and theme settings.
frontend/packages/hooks, frontend/src/layouts/modules/global-sider · high confidence
New global exception filter for consistent error responses
A new \AllExceptionsFilter\ has been added to the \backend/libs/infra/filters\ library. This filter standardizes how the backend responds to various exceptions, including \UnprocessableEntityException\, \HttpException\, and custom \BizException\ types. It ensures that all error responses follow a consistent structure with a status code, message, and error details, improving the reliability of error handling across the application.
backend/libs/infra/filters · high confidence
New utility modules for environment, ID generation, IP resolution, and tree structures
Added new utility modules to the backend's shared utils library. These include environment variable helpers (env.ts) for reading typed configuration, a ULID generator (id.util.ts) for unique identifiers, an IP address resolver (ip.util.ts) that inspects common proxy headers and socket properties, and a tree-building utility (tree.util.ts) that converts flat lists into nested structures with optional sorting. These changes support the backend's refactoring into a monorepo architecture.
backend/libs/utils · high confidence
Behavioural changes
Added Fastify adapter and security middleware integration
The backend now includes a new Fastify adapter that configures multipart upload limits (10 fields, 6MB file size, 5 file fields) and registers the @fastify/helmet middleware to enforce security headers including Content Security Policy, XSS filtering, MIME type sniffing prevention, HSTS, and referrer policy. An error hook is also added to log not-found requests with IP, user agent, and URL details.
backend/libs/infra/adapter · high confidence
Backend project structure and configuration overhaul
The backend has been restructured into a monorepo with a new library-based architecture. This includes adding configuration files for Docker (.dockerignore, Dockerfile), environment variables (.env), and build tools (Makefile, ecosystem.config.js). New library modules have been introduced under libs/infra (decorators, strategies) and libs/typings, defining types like IAuthentication and ApiResponse. Additionally, a local route migration script (local-route.migrate.ts) has been added to sync frontend routes with the database, and TypeScript path mappings have been updated to support the new @lib/ and @src/ aliases.
backend · high confidence
Casbin authorization library moved to backend/libs/infra/casbin
The casbin library has been restructured and moved to the backend/libs/infra/casbin directory. This refactoring introduces a new modular architecture for authorization, including a Prisma adapter for policy storage, a NestJS DynamicModule (AuthZModule) for configuration, and dedicated services for RBAC and management operations. The change also adds a UsePermissions decorator and an AuthZGuard to enforce access control on routes, while exposing a comprehensive API for role and permission management through the new service layer.
backend/libs/infra/casbin · high confidence
Centralized configuration management for app, security, and infrastructure
The backend configuration has been refactored into a modular structure, introducing dedicated configuration modules for the application server, CORS, Redis, security (including JWT and Casbin), and rate limiting. Each module now registers its settings via environment variables with sensible defaults, and the \index.ts\ file exports a unified \AllConfigType\ interface to standardize access to these settings across the application.
backend/libs/config · high confidence
Introduce Keyv-based Redis caching with cluster support
The backend's global library now provides a new cache management module that uses Keyv as the cache adapter for NestJS's cache-manager. This replaces the previous custom Redis cache store implementation, enabling support for both standalone and Redis cluster connection modes. The change also includes a global CQRS module and a shared module that wires up configuration, HTTP, scheduling, event emission, Prisma, and the new cache manager, making these capabilities available across the application.
backend/libs/global · high confidence
New global menu layout with multiple navigation modes
The global menu has been refactored to support four distinct navigation layouts: vertical, vertical-mix, horizontal, and horizontal-mix. The main menu component now dynamically renders the appropriate layout component based on the user's theme settings. Each layout mode is implemented in its own Vue component, with the vertical-mix layout featuring a collapsible sidebar for sub-menus and a top-level menu for primary navigation.
frontend/src/layouts/modules/global-menu · high confidence
New logging and response transformation interceptors
Added two new NestJS interceptors to the backend infrastructure library: LogInterceptor, which captures request metadata and emits an event for operation logging, and TransformInterceptor, which wraps API responses in a standard success envelope and enforces a 3000ms timeout. These changes introduce new behavior for request logging and response formatting.
backend/libs/infra/interceptors · high confidence
Shared backend libraries reorganized into a monorepo structure
The shared backend libraries have been refactored into a monorepo structure, moving packages such as errors, ip2region, oss, prisma, and redis into the backend/libs/shared directory. This change introduces new module and service implementations for each shared library, including a global Prisma service, an IP2Region service supporting file, vector index, and full search modes, an OSS service for object storage, and a Redis utility for cluster or standalone connections. Each library now includes its own module, configuration service, and TypeScript configuration, enabling independent compilation and clearer separation of concerns within the shared codebase.
backend/libs/shared · medium confidence
Test coverage
Added end-to-end tests for the base-demo application
Added an end-to-end test suite for the base-demo application, including a new e2e spec file that verifies the root endpoint returns 'Hello World!' and a Jest configuration file to configure the e2e test runner.
backend/apps/base-demo/test · high confidence
Dependencies
Updated backend and frontend dependencies
The backend and frontend \package.json\ and \pnpm-lock.yaml\ files have been updated to reflect the latest dependency versions. Key backend updates include NestJS 11.1.3, Fastify 5.4.0, Prisma 6.10.1, and various security and utility libraries. The frontend template 'soybean-admin' has been updated to version 1.3.13, with corresponding updates to Vue 3.5.13, NaiveUI 2.41.0, and related development tools.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 35 → 33 (-1.4)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 86 → 88 (+2.1)
- Architecture 65 → 66 (+0.9)
- Maturity 56 → 55 (-0.4)
- Readiness 19 → 18 (-1.2)
- Security 65 → 60 (-5.0)
- Accessibility 29 → 31 (+1.4)
Resolved (58)
- Change coupling: en-us.ts ↔ zh-cn.ts (frontend/src/locales/langs/en-us.ts)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
- …and 38 more
New (167)
- Coverage not measured — JavaScript/TypeScript suite
- Critical CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- FunctionTooLong: index.useRouteStore (frontend/src/store/modules/route/index.ts)
- FunctionTooLong: index.useTabStore (frontend/src/store/modules/tab/index.ts)
- FunctionTooLong: table.useTable (frontend/src/hooks/common/table.ts)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (backend/pnpm-lock.yaml)
- …and 147 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
soybeanjs/soybean-admin-nestjs was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b4936f86f0cedc3e0eec8b855ec1c6bbab4944f8 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.