SSWConsulting/SSW.CleanArchitecture
67.8
Adequate · 21 September 2026
2k
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is a .NET-based web API that manages superheroes, their powers, and their associated teams and missions. It implements a Clean Architecture with CQRS and MediatR, providing endpoints to create, update, and retrieve heroes and teams, as well as execute and complete missions. The application enforces strict domain rules, such as calculating team power levels and handling eventual consistency through domain events. The infrastructure layer handles database persistence, audit tracking, and automated migrations, while the test suite ensures architectural integrity and endpoint correctness.
How it got here
2023 — Clean Architecture template and .NET 10 upgrade
14 changes.
This period focused on modernizing the project's foundation by upgrading to .NET 10 and implementing a comprehensive Clean Architecture template. The work introduced .NET Aspire for observability, established a new domain model for Heroes and Teams, and standardized the development environment with CQRS templates and global usings.
2024–2025 — Domain-Driven Design and API implementation
23 changes.
This period focused on establishing a Domain-Driven Design architecture, introducing foundational base classes and interfaces for aggregates, auditing, and events. The work extended to implementing the Heroes and Teams domains with corresponding application layer use cases and API endpoints. Additionally, infrastructure was added for database migrations, seeding, and comprehensive integration testing using xUnit v3.
Features
Add CurrentUserService to retrieve the current user's identity
A new CurrentUserService implementation was added to the WebApi layer. This service resolves the current user's identity by extracting the NameIdentifier claim from the HTTP context, exposing it via the ICurrentUserService interface for use across the application.
src/WebApi/Services · high confidence
Add Entity Framework DbContext health check
The application now includes a dedicated health check for the Entity Framework DbContext, verifying both database connectivity and the execution of a sample query. This is registered alongside the existing SQL Server connectivity check, providing more granular insight into the state of the database context and data access layer.
src/WebApi/HealthChecks · high confidence
Add application-layer pipeline behaviors for logging, performance monitoring, and validation
New pipeline behaviors have been introduced in the application layer to enhance observability and error handling. A LoggingBehaviour now records incoming requests, while a PerformanceBehaviour logs warnings for requests exceeding 500ms. An UnhandledExceptionBehaviour ensures all exceptions are logged before rethrowing, and a ValidationErrorOrResultBehaviour automatically validates requests and returns structured validation errors. These changes improve debugging, performance tracking, and input validation for all MediatR handlers.
src/Application/Common/Behaviours · high confidence
Add domain models for Teams and Missions
Introduced the Teams domain with new models for Team, Mission, and their associated error types and status enums. Teams can now be created, have heroes added or removed (updating total power level), and manage missions. Users can start a mission for a team (which requires at least one hero) and complete the current mission, with validation ensuring teams are available and not already on a mission.
src/Domain/Teams · medium confidence
Add on-demand database drop command for Azure SQL
Users can now drop the Azure SQL database on demand via a new 'drop-database' command exposed in the App Host. This is implemented in SqlServerCommandExt.cs, which adds a WithDropDatabaseCommand extension method that connects to the database using the connection string and calls EnsureDeletedAsync to remove it.
tools/AppHost/Commands · high confidence
Added CQRS command and query templates for Clean Architecture
New project templates are now available for generating CQRS command and query items within the SSW Clean Architecture solution. The command template scaffolds a command handler and validator, while the query template scaffolds a query handler and DTO, both pre-configured with Entity Framework Core and MediatR interfaces to streamline the creation of new use cases.
templates · high confidence
Adds .editorconfig and solution file to enforce code style and structure
The template now includes an .editorconfig file that enforces consistent C\# coding styles, formatting, and code analysis rules across all projects. Additionally, a new .slnx solution file is introduced to explicitly define the project structure, while supporting files like Directory.Build.props, global.json, and various markdown documentation files (README, CONTRIBUTING, LICENSE, etc.) are added to standardize the development environment and project metadata.
(repo-wide) · high confidence
Adds Entity Framework Core configuration for domain entities
New configuration classes are introduced to map domain entities to the database schema. An abstract AuditableConfiguration base class is added to handle common audit fields (CreatedBy, CreatedAt, UpdatedBy) for all auditable entities. Specific configurations are implemented for Hero, Mission, and Team entities, defining primary keys, required string lengths, and relationships (e.g., Team to Missions and Heroes). Additionally, a converter is added to handle Vogen strongly-typed IDs in Entity Framework Core.
src/Infrastructure/Persistence/Configuration · high confidence
Automated audit tracking and domain event dispatching via EF Core interceptors
Added two new Entity Framework Core save-change interceptors to the persistence layer. The \EntitySaveChangesInterceptor\ automatically populates \Created\ and \Updated\ timestamps and user IDs on all \IAuditable\ entities before they are saved to the database. The \DispatchDomainEventsInterceptor\ publishes domain events to the MediatR pipeline after the database transaction commits, routing them to either immediate processing or an offline queue depending on whether the user is waiting for a response.
src/Infrastructure/Persistence/Interceptors · high confidence
Automated database initialization and sample data seeding
The migration service now includes a new \ApplicationDbContextInitializer\ that automatically creates the database schema and seeds it with sample Hero and Team data (20 heroes and 5 teams) on startup. A base \DbContextInitializerBase\ handles database and table existence checks before applying migrations or creating tables, ensuring the database is ready for use without manual intervention.
tools/MigrationService/Initializers · high confidence
Initial database migration for Heroes, Teams, and Missions
The initial database migration has been added to the persistence layer, establishing the schema for the Hero, Team, and Mission entities. This migration creates the 'Heroes', 'Teams', and 'Mission' tables, along with the necessary foreign key relationships and indexes. This change supports the new domain models for managing superheroes and their associated teams and missions.
src/Infrastructure/Persistence/Migrations · high confidence
Introduce .NET Aspire AppHost for local and Azure deployment
Added a new AppHost project that bootstraps the application using .NET Aspire, configuring an Azure App Service environment, a SQL Server container for local development, and a migration service. The host also sets up external HTTP endpoints for the API, waits for the database, and conditionally configures Azure Application Insights and Log Analytics for published deployments.
tools/AppHost · high confidence
Introduce .NET Aspire service defaults and OpenAPI/Scalar support
The WebApi project now integrates .NET Aspire service defaults and configures OpenAPI with Scalar for API documentation. A new DependencyInjection class centralizes service registration, including the HttpContextAccessor, OpenAPI, and health checks. The Program.cs entry point is updated to wire up these services, and the WebApi.http file provides sample requests for Heroes and Teams endpoints. Additionally, a marker interface IWebApiMarker is added to support functional testing with WebApplicationFactory.
src/WebApi · high confidence
Introduce .NET Aspire service defaults and infrastructure dependency injection
The infrastructure layer now registers core application services via a new \DependencyInjection.cs\ file, which configures the SQL Server DbContext with domain event and save changes interceptors, and registers the \TimeProvider\. Additionally, \ServiceDefaults/Extensions.cs\ adds .NET Aspire service defaults, enabling OpenTelemetry-based observability (metrics, tracing, logging), default health checks, and HTTP client resilience and service discovery.
src/Infrastructure · high confidence
Introduce Heroes application layer with Create, Update, and List capabilities
Added new use-case implementations for managing heroes, including CreateHeroCommand, UpdateHeroCommand, and GetAllHeroesQuery. Each command and query is backed by a dedicated handler and a FluentValidation validator, enabling users to create new heroes, update existing ones, and retrieve a list of all heroes with their associated powers.
src/Application/UseCases/Heroes · high confidence
Introduce application layer dependency injection and global usings
The application layer now registers its services via a new DependencyInjection class, configuring MediatR with behaviors for unhandled exceptions, validation errors, and performance tracking. Global usings are added for FluentValidation, MediatR, Ardalis.Specification.EntityFrameworkCore, ErrorOr, and Microsoft.EntityFrameworkCore to simplify imports across the project.
src/Application · high confidence
Introduce dedicated migration service for database initialization and seeding
A new background service has been added to the codebase to handle database migrations and data seeding. This service, implemented via a hosted worker process, is responsible for ensuring the database schema exists, creating necessary schemas, and optionally seeding initial data in development environments. The implementation includes a dedicated user service to satisfy dependency injection requirements for the migration context.
tools/MigrationService · high confidence
Introduce domain base classes and interfaces for aggregates, auditing, and events
The domain layer now includes foundational base classes and interfaces to support Domain-Driven Design patterns. \AggregateRoot\ and \Entity\ provide the core structure for domain models, with \AggregateRoot\ managing domain events via \AddDomainEvent\ and \PopDomainEvents\. \Auditable\ and \IAuditable\ introduce automatic tracking of creation and modification timestamps and users, enforcing length constraints on user identifiers. Additionally, \IDomainEvent\ extends MediatR's \INotification\ to support event-driven architectures, while \IValueObject\ serves as a marker for immutable value types. New error handling for eventual consistency is also introduced via \EventualConsistencyError\ and \EventualConsistencyException\.
src/Domain/Common · high confidence
Introduce team management commands and queries
Added new application-layer use cases for managing teams, including creating teams, adding heroes to teams, executing and completing missions, and retrieving team details. The implementation uses the ErrorOr pattern to handle potential errors gracefully and includes validators to ensure required fields are present. Additionally, an event handler was added to update team power levels when a hero's power level changes.
src/Application/UseCases/Teams · medium confidence
New Hero and Team API endpoints
Added new endpoint definitions for managing heroes and teams. The Hero endpoints now support retrieving all heroes, creating a new hero, and updating an existing hero. The Team endpoints now support creating a team, retrieving all teams, fetching a specific team, adding a hero to a team, executing a mission, and completing a mission.
src/WebApi/Endpoints · high confidence
Behavioural changes
Added middleware for eventual consistency domain event processing
A new middleware component has been introduced to handle domain events after the HTTP response is completed. This middleware collects domain events from the request context and publishes them using a transactional strategy, ensuring that events are processed only after the main request logic succeeds.
src/Infrastructure/Middleware · high confidence
Introduce application-level interfaces for database context and user service
Added new interfaces for the application layer: IApplicationDbContext now exposes DbSet properties for Hero and Team entities along with a SaveChangesAsync method, while ICurrentUserService provides access to the current user's ID. These interfaces define the contracts for database interactions and user context retrieval within the application.
src/Application/Common/Interfaces · medium confidence
Introduce new persistence layer with Hero and Team entities
The application's database context has been updated to include the new Hero and Team aggregates, replacing the previous Todo-focused model. The configuration now registers Vogen EF Core converters for strongly typed IDs and applies entity configurations from the assembly, establishing the foundation for the new domain model.
src/Infrastructure/Persistence · high confidence
Introduced Hero domain model with validation and domain events
Added the Hero aggregate root, Power value object, and associated domain events. The Hero entity now enforces string length constraints (Name and Alias max 100 characters) and Power name length (50 characters) using built-in guard clauses. It also includes a PowerLevelUpdatedEvent to signal changes in power levels, supporting eventual consistency patterns.
src/Domain/Heroes · medium confidence
Simplified domain layer with global usings and built-in guard clauses
The domain layer now uses a GlobalUsings file to centralize imports for the Ardalis.Specification library, ErrorOr, Vogen, and various .NET exception types, reducing the need for repetitive using statements across files. Additionally, the project has removed the external Ardalis.Guard library in favor of built-in .NET guard clauses, streamlining dependencies and leveraging native language features for argument validation.
src/Domain · medium confidence
Standardizes API response formatting and endpoint configuration
The WebApi project introduces a set of extension methods to standardize how the API handles errors and defines routes. Custom problem details are now configured to include request context (instance, trace ID, and activity ID) in error responses. A new result helper maps domain errors to specific HTTP status codes (400, 404, 409, 500) and distinguishes validation errors from general failures. Additionally, route builders now automatically apply standard HTTP status codes for GET, POST, PUT, and DELETE operations, and API groups are consistently prefixed with 'api/' and tagged for OpenAPI documentation.
src/WebApi/Extensions · high confidence
Test coverage
Add architecture and domain tests using xUnit v3 and AwesomeAssertions; Add test factories for Hero and Team entities; Added integration test for team power level updates; Added integration test for the GetAllHeroes query; Added integration test infrastructure for SQL Server and Web API hosting; Added integration tests for Hero creation and update commands; Added integration tests for Team endpoints; Added unit tests for Hero and Power domain models; Added unit tests for Team and Mission domain logic; Refactored integration test base and fixture for xUnit v3.
Dependencies
Centralized package version management and .NET 10 upgrade
The project now uses a centralized package management system via Directory.Packages.props, which defines versions for all NuGet packages across the solution. This includes upgrading to .NET 10, with key dependencies such as Microsoft.EntityFrameworkCore, Microsoft.AspNetCore.OpenApi, and Microsoft.Extensions.\* packages updated to version 10.0.3. Other notable updates include AspNetCore.HealthChecks to 9.0.0, xUnit v3, and Scalar.AspNetCore to 2.13.1.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 69 → 68 (-1.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 83 → 82 (-0.3)
- Architecture 92 → 92 (-0.2)
- Maturity 82 → 82 (+0.0)
- Readiness 84 → 70 (-14.3)
- Security 57 → 58 (+0.8)
- Domain Modelling 74 → 78 (+4.0)
- Event-Driven 100 → 100 (+0.0)
Resolved (21)
- Bounded contexts not declared
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- LLM evaluation failed
- No exposed public API
- …and 1 more
New (45)
- CommentedOutCode (src/Infrastructure/ServiceDefaults/Extensions.cs)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (5 lines × 3) (src/Domain/Heroes/Hero.cs)
- High CVE: SSH.NET 2025.1.0
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 25 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
SSWConsulting/SSW.CleanArchitecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit adcff2facc9359cb668bc4ee7a7bb579c76b8102 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.