Skip to content
CAI
Software that uses CAICheck a score

sqshq/piggymetrics

32.5

Weak · 25 September 2026

6.1k

lines of production code

JavaScript

with Java

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a microservices-based financial management platform that enables users to create and manage personal accounts, track income and expenses, and view statistical analytics. The system comprises distinct services for authentication, account management, and financial statistics, all secured via OAuth2. It also includes supporting infrastructure for service discovery, configuration, monitoring, and automated email notifications.

Features

Account service exposes REST endpoints for account management

The account-service now provides a new REST API for managing user accounts. Users can retrieve their current account details, update their account information, create new accounts, and fetch accounts by name. The API includes security checks via OAuth2 scope validation and handles validation errors with appropriate HTTP status codes.

account-service/src/main/java/com/piggymetrics/account/controller · high confidence

Add MongoDB container configuration and demo data

The MongoDB service is now fully containerized with a Dockerfile that sets up the environment, installs dependencies, and executes an initialization script. The init.sh script handles user authentication setup and executes a JavaScript dump file to pre-populate the database with demo account data, including expenses, incomes, and savings.

mongodb · high confidence

Add Spring Boot 2.0.3-based monitoring service with Hystrix dashboard

A new monitoring service has been introduced, built on Spring Boot 2.0.3 and Spring Cloud Finchley. The service is configured via bootstrap.yml to connect to a config server and includes a Hystrix dashboard for monitoring. A corresponding test class ensures the application context loads correctly.

monitoring/src · high confidence

Add Turbine Stream Service for monitoring

A new Turbine Stream Service is introduced to aggregate and stream monitoring metrics. The service is configured via Spring Boot with discovery client and Turbine Stream support, exposing port 8989, and includes a basic integration test to verify the application context loads correctly.

turbine-stream-service · high confidence

Add repository and converters for time-series data points

The statistics service now persists time-series data points in MongoDB using a composite key of account and date. A new DataPointRepository interface provides a query method to retrieve data points by account, while custom Spring converters handle the serialization and deserialization of the composite DataPointId (account + date) to and from MongoDB DBObjects.

statistics-service/src/main/java/com/piggymetrics/statistics/repository · high confidence

Add statistics service REST controller

A new REST controller for the statistics service has been introduced, exposing endpoints to retrieve current account statistics, fetch statistics by account name, and save account statistics. The controller integrates with the existing StatisticsService and enforces OAuth2 scope-based authorization for write and specific read operations.

statistics-service/src/main/java/com/piggymetrics/statistics/controller · high confidence

Add user management endpoints in the auth service

A new UserController is introduced in the auth-service, exposing a GET /users/current endpoint that returns the current user's principal and a POST /users endpoint (protected by OAuth2 'server' scope) to create new users.

auth-service/src/main/java/com/piggymetrics/auth/controller · high confidence

Added Feign clients for auth and statistics services with fallback handling

The account-service now includes new Feign client interfaces for communicating with the auth-service and statistics-service. The statistics-service client includes a fallback implementation (StatisticsServiceClientFallback) that logs errors instead of failing, ensuring resilience when the statistics service is unavailable.

account-service/src/main/java/com/piggymetrics/account/client · high confidence

Added Spring Boot gateway application entry point

A new main class for the gateway service has been introduced, configuring the application as a Spring Boot service that enables discovery client and Zuul proxy capabilities.

gateway/src/main/java · high confidence

Added user persistence model and repository for the auth service

Introduced a new domain model, User, which implements Spring Security's UserDetails interface to represent user accounts in the authentication service. This model is backed by a MongoDB collection named 'users' and includes fields for username and password. Alongside the domain class, a corresponding Spring Data repository, UserRepository, was added to provide database access capabilities for the User entity, enabling the storage and retrieval of user credentials.

auth-service/src/main/java/com/piggymetrics/auth/domain, auth-service/src/main/java/com/piggymetrics/auth/repository · high confidence

Added user registration and authentication support in the auth service

The auth-service now includes core user management capabilities. A new UserService interface and UserServiceImpl implementation allow for creating new users, which includes hashing passwords with BCrypt and checking for duplicates before saving to the repository. Additionally, a MongoUserDetailsService has been added to handle Spring Security's user lookup by username, enabling authentication flows against the MongoDB-backed user store.

auth-service/src/main/java/com/piggymetrics/auth/service · high confidence

Auth service application entry point and configuration

The auth service is now bootstrapped as a Spring Boot application with OAuth2 resource server capabilities, service discovery, and global method security enabled.

auth-service/src/main/java/com/piggymetrics/auth · high confidence

Eureka registry service and Docker configuration

Users can now run the Eureka registry as a standalone containerized service. A new Dockerfile configures the registry to run with a 200MB memory limit and exposes port 8761. The application is configured to connect to a central config server and disables client-side Eureka registration, ensuring the registry operates as a server-only instance.

registry · high confidence

Introduce account domain model and repository

The account-service now includes a new domain model for managing user accounts, including the Account, User, Item, Saving, Currency, and TimePeriod classes, along with a Spring Data MongoDB repository for account persistence. This establishes the core data structures for tracking income, expenses, and savings, enabling the service to store and retrieve account-related information.

account-service/src/main/java/com/piggymetrics/account/domain · high confidence

Introduce account management and update capabilities

The account-service now provides a new AccountService interface and implementation that allows creating new user accounts and saving changes to existing ones. When a new user is created, the system automatically initializes the account with default financial settings (zero balance, no deposit, no capitalization) and links the user to the authentication service. Existing accounts can be updated with new income, expense, and saving configurations, which then triggers an update to the statistics service to keep financial data synchronized.

account-service/src/main/java/com/piggymetrics/account/service · high confidence

Introduce automated backup and reminder email notifications

A new notification service has been added to the application, enabling automated email notifications for scheduled backup and reminder tasks. Users can now configure notification preferences via a new /recipients API endpoint, and the system will automatically send emails based on configurable cron schedules for backup and reminder types.

notification-service/src/main/java · high confidence

Introduce domain models for the statistics service

Added new domain classes to the statistics-service to support financial tracking and time-series data storage. This includes the Account model for managing incomes, expenses, and savings, along with supporting types like Currency, TimePeriod, and Saving. Additionally, new classes for exchange rate data (ExchangeRatesContainer) and time-series data points (DataPoint, ItemMetric, StatisticMetric) have been introduced to store and normalize financial metrics over time.

statistics-service/src/main/java/com/piggymetrics/statistics/domain · high confidence

Introduce statistics service with exchange rate conversion

Added new service classes (ExchangeRatesService, StatisticsService) and their implementations to the statistics-service module. The ExchangeRatesService fetches and caches daily foreign exchange rates, providing a method to convert amounts between currencies. The StatisticsService handles saving account statistics as time-series data points, normalizing income and expense amounts to a base currency using the exchange rates.

statistics-service/src/main/java/com/piggymetrics/statistics/service · high confidence

OAuth2 resource server and application entry point added

The account-service now includes a dedicated Spring Boot application class (AccountApplication) and a resource server configuration (ResourceServerConfig) that enables OAuth2 authentication, Feign client support, and circuit breaking. The configuration sets up a custom token service (CustomUserInfoTokenServices) and allows unauthenticated access to the root and /demo endpoints, while requiring authentication for all other requests.

account-service/src/main/java/com/piggymetrics/account · high confidence

Behavioural changes

Add fallback for exchange rates client

The statistics service now includes a fallback implementation for the exchange rates client. If the external exchange rate API is unavailable, the system returns an empty rates container instead of failing, ensuring the service remains resilient to external dependencies.

statistics-service/src/main/java/com/piggymetrics/statistics/client · high confidence

Config server secured with HTTP Basic authentication

The config server now enforces authentication for all requests except those to the /actuator/\\ endpoints, which remain publicly accessible. Access to the configuration endpoints requires valid credentials via HTTP Basic authentication.

config/src/main/java · high confidence

Custom OAuth2 token services for account and statistics services

Added CustomUserInfoTokenServices implementations in both the account-service and statistics-service. These classes extend the default Spring Boot OAuth2 UserInfoTokenServices to expose the calling service's clientId and scope, enabling controller-level security checks to validate the origin of incoming requests.

account-service/src/main/java/com/piggymetrics/account/service/security, statistics-service/src/main/java/com/piggymetrics/statistics/service/security · high confidence

Migrate to Spring Security 5 with BCrypt password encoding

The authentication service now enforces stronger password hashing by switching from the previous default encoder to BCrypt, satisfying Spring Security 5's requirement for a specific password encoder. The OAuth2 authorization configuration has been refactored into a dedicated \OAuth2AuthorizationConfig\ class, and the browser client is configured to use no password (\{noop}\) while service clients continue to use environment-variable-based secrets.

auth-service/src/main/java/com/piggymetrics/auth/config · high confidence

Migrated frontend assets to gateway static directory

The frontend assets, including HTML templates, CSS stylesheets, JavaScript files, and fonts, have been moved from the legacy \src/main/webapp/assets\ directory to the new \gateway/src/main/resources/static\ directory. This structural change updates the base paths for static resources (e.g., CSS links and image URLs) to reflect the new location, ensuring the application correctly serves the UI components from the gateway module.

gateway/src/main/resources/static · high confidence

Removal of English and Russian i18n resource files

The English (i18n.properties) and Russian (i18n\_ru.properties) localization files have been deleted from the application. This removes all associated user-facing text, including login, registration, financial categories, and email templates, which will likely cause missing translation errors or fallback to default text for these locales.

src/main/resources/i18n · high confidence

Removal of legacy Spring Security authentication and user management components

The application has removed the previous user management and authentication infrastructure, including the \PiggyUser\ class, associated DAOs, and controllers (\AppController\, \SecureController\, \UserController\). Additionally, the Spring Security success and failure handlers (\SuccessHandler\, \FailureHandler\) and the \AppInterceptor\ have been deleted, indicating a significant restructuring of how user sessions and security are handled in the application.

src/main/java · high confidence

Removed environment-specific configuration files

The environment-specific configuration files for development (dev.properties) and production (prod.properties) have been removed from the project. These files previously defined system properties such as the application URL for each environment.

src/main/resources/config · high confidence

Removed legacy JSP view templates

The JSP templates for the admin, hello, login, and update pages have been removed from the application. This eliminates the old server-side rendering approach for these specific views, likely as part of a broader migration away from JSP-based UI.

src/main/webapp/WEB-INF/views · high confidence

Removed legacy JSP views for the app interface

The legacy JSP templates for the main application interface have been removed. This includes the base layout template, the dashboard view, the greeting/header component, the launch/login page, and the settings page. These files contained the HTML structure and Spring taglib directives for rendering the user interface, indicating a shift away from server-side rendered JSP templates for these specific views.

src/main/webapp/WEB-INF/views/app · high confidence

Removed legacy client-side JavaScript files

The files launch.js, translation.js, and unauth\_launch.js have been deleted from the assets directory. This removes client-side logic for initial page loading, language translation mapping, and unauthenticated user interactions such as login, registration, and avatar upload.

src/main/webapp/assets · high confidence

Statistics service bootstraps with custom OAuth2 token handling

The statistics service now includes its own application entry point and security configuration. It registers custom MongoDB converters for data points and wires a custom OAuth2 token service to handle user information, ensuring the service can authenticate and process requests securely.

statistics-service/src/main/java/com/piggymetrics/statistics · medium confidence

Test coverage

Added Spring Boot integration test for StatisticsServiceApplication; Added application context test for notification service; Added initial test infrastructure for the gateway service; Added tests for DataPoint repository; Added unit and integration tests for the auth-service; Added unit tests for AccountService; Added unit tests for StatisticsServiceClientFallback; Added unit tests for notification service components; Added unit tests for notification service repository and controller; Added unit tests for the AccountController; Added unit tests for the account service and its repository; Added unit tests for the exchange rates client.

Dependencies

Upgrade to Spring Boot 2.0.3 and Spring Cloud Finchley

The project's build configuration has been updated to use Spring Boot 2.0.3 and Spring Cloud Finchley. This upgrade introduces a new set of dependencies and libraries across the microservices, including Spring Cloud Sleuth for distributed tracing, Spring Cloud Netflix components like Eureka and Hystrix, and various Spring Boot starters for security, web, and data access.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 38 → 32 (-5.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 37 → 45 (+7.2)
  • Architecture 100 → 74 (-25.9)
  • Maturity 44 → 44 (+0.0)
  • Readiness 34 → 30 (-4.3)
  • Security 63 → 42 (-20.6)
  • Accessibility 34 → 26 (-8.4)

Resolved (44)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (account-service/src/main/java/com/piggymetrics/account/service/security/CustomUserInfoTokenServices.java)
  • Duplicated block (5 lines × 2) (account-service/src/main/java/com/piggymetrics/account/service/security/CustomUserInfoTokenServices.java)
  • Duplicated block (8 lines × 2) (account-service/src/main/java/com/piggymetrics/account/service/security/CustomUserInfoTokenServices.java)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_3 (account-service/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (auth-service/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (config/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (gateway/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (mongodb/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (monitoring/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (registry/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (statistics-service/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (turbine-stream-service/Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (account-service/Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (auth-service/Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (config/Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (gateway/Dockerfile)
  • …and 24 more

New (115)

  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (25 lines × 2) (account-service/src/main/java/com/piggymetrics/account/service/security/CustomUserInfoTokenServices.java)
  • Duplicated block (48 lines × 2) (account-service/src/main/java/com/piggymetrics/account/domain/Account.java)
  • Duplicated block (5 lines × 2) (account-service/src/main/java/com/piggymetrics/account/service/security/CustomUserInfoTokenServices.java)
  • Duplicated block (53 lines × 2) (account-service/src/main/java/com/piggymetrics/account/domain/Item.java)
  • Duplicated block (61 lines × 2) (account-service/src/main/java/com/piggymetrics/account/domain/Saving.java)
  • Duplicated block (8 lines × 2) (account-service/src/main/java/com/piggymetrics/account/service/security/CustomUserInfoTokenServices.java)
  • Duplicated block (8 lines × 2) (account-service/src/main/java/com/piggymetrics/account/service/security/CustomUserInfoTokenServices.java)
  • Duplicated block (9 lines × 2) (account-service/src/main/java/com/piggymetrics/account/service/security/CustomUserInfoTokenServices.java)
  • FunctionTooLong: dashboard.initStatisticPage (gateway/src/main/resources/static/js/dashboard.js)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • …and 95 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sqshq/piggymetrics was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6bb2cf9ddbca980b664d3edbb6ff775d75369278 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-f917f263222d.