Skip to content
CAI
Software that uses CAICheck a score

stemmlerjs/ddd-forum

42.3

Weak · 21 September 2026

11.8k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a forum application that enables users to create posts, comment on them, and vote on content. It provides a RESTful and GraphQL API for managing user accounts, authentication, and forum interactions like post creation, comment replies, and voting. The architecture separates domain logic from infrastructure, utilizing a database for persistence and Redis for session management.

Features

Add ability to reply to forum posts

Users can now add comments to existing forum posts. This change introduces the 'Reply to Post' use case and its associated controller, allowing authenticated users to submit a comment on a specific post identified by its slug. The implementation includes input sanitization for the comment text and handles cases where the target post is not found.

src/modules/forum/useCases/comments/replyToPost · high confidence

Add ability to retrieve a specific comment by its ID

Users can now fetch the details of a single comment using its unique identifier. This new feature introduces a dedicated use case and controller that query the comment repository, handling both successful retrieval of comment details and error cases such as the comment not being found.

src/modules/forum/useCases/comments/getCommentByCommentId · high confidence

Added HTTP middleware for authentication, rate limiting, and domain validation

A new Middleware class was introduced in the HTTP utilities layer to handle common server-side concerns. It provides an authentication middleware that decodes and validates JWT tokens, a stricter ensureAuthenticated guard that rejects requests without valid tokens, a configurable rate-limiting wrapper, and a domain-restriction filter that blocks requests from unauthorized origins in production environments.

src/shared/infra/http/utils · high confidence

Added ability to create new forum posts

Users can now submit new posts to the forum. This change introduces the CreatePost use case and its associated controller, which handle the creation of posts with titles, text, or links. The implementation includes input sanitization on the ingress ports to ensure data safety before processing.

src/modules/forum/useCases/post/createPost · high confidence

Added ability to reply to existing comments

Users can now post replies to comments within a post. This change introduces the ReplyToComment use case and its HTTP controller, which validates the post slug, the parent comment, and the requesting member before creating the reply. The controller sanitizes the comment text on ingress and handles standard not-found or unexpected error responses.

src/modules/forum/useCases/comments/replyToComment · high confidence

Added ability to retrieve a forum post by its URL slug

Users can now fetch the details of a specific forum post by providing its unique slug. This change introduces the GetPostBySlug use case and its associated controller, which handle the logic to query the post repository and return the post details or appropriate error messages if the post is not found.

src/modules/forum/useCases/post/getPostBySlug · high confidence

Added ability to retrieve comments for a specific forum post

Users can now fetch a list of comments associated with a specific forum post. This new feature introduces a dedicated use case and controller that retrieve comment details by post slug, supporting pagination via an offset parameter. The implementation includes request and response data transfer objects to structure the data flow, and error handling for cases where the post is not found.

src/modules/forum/useCases/comments/getCommentsByPostSlug · high confidence

Added comment and post summary components for the forum

The forum UI now includes new components to display post metadata, summaries, and nested comments. Users can see post titles, author information, timestamps, and comment text with author and date details. The PostSummary component renders post text or external links, while PostComment and PostCommentAuthorAndText handle the display of comments and their replies, enabling a threaded comment view on the post page.

public/app/src/modules/forum/components/posts/post/components · high confidence

Added database setup and teardown scripts

New scripts/db/create.js and scripts/db/delete.js files have been added to the project. These Node.js scripts use the mysql2 library to programmatically create and drop the forum database based on environment-specific configuration from .env variables (DDD\_FORUM\_DB\_DEV\_DB\_NAME or DDD\_FORUM\_DB\_TEST\_DB\_NAME). This provides a way to initialize or clean up the database schema for development or testing environments.

scripts · high confidence

Added forum post submission and comment management capabilities

The public-facing application now supports creating new posts (text or link), submitting replies to posts and comments, and retrieving recent, popular, and individual post and comment data through a new Redux-based state management system. This includes UI components for post submission, comment editing, and display, along with the necessary Redux actions, reducers, and state definitions to handle these interactions.

public · high confidence

Added forum services for posts and comments

Introduced new service classes for managing forum content: PostService and CommentService. These services enable retrieving recent and popular posts, fetching individual posts and comments by ID or slug, and performing actions like creating posts, replying to comments, and upvoting/downvoting content. The implementation supports both authenticated and unauthenticated access for read operations, while write and vote operations require an authentication token.

public/app/src/modules/forum/services · high confidence

Added hover tooltip for unauthenticated users on forum post points

When a user hovers over the upvote or downvote buttons on a forum post without being logged in, a tooltip appears displaying a message encouraging them to sign up or log in to vote. This new interactive element improves the user experience by providing clear feedback and a direct path to authentication.

public/app/src/modules/forum/components/posts/points · high confidence

Added login, logout, and refresh-token use cases and controllers

Users can now log in to receive access and refresh tokens, log out to invalidate sessions, and refresh their access token using a valid refresh token. This change introduces the Login, Logout, and RefreshAccessToken use cases and their corresponding HTTP controllers, enabling the full authentication lifecycle.

src/modules/users/useCases/login · high confidence

Added member lookup and creation capabilities

Introduced new use cases and controllers to support retrieving member details by username and creating new member records. Users can now fetch a member's profile information via a dedicated lookup, and the system supports the creation of new member accounts linked to existing users.

src/modules/forum/useCases/members · high confidence

Added post stats update logic

A new use case has been introduced to update a post's statistics, including its comment count and score derived from post and comment votes. This feature allows the system to recalculate and persist the latest metrics for a specific post.

src/modules/forum/useCases/post/updatePostStats · high confidence

Added upvote and downvote functionality for forum comments

Users can now upvote or downvote comments on the forum. This change introduces the use cases, controllers, and domain logic for both upvoting and downvoting comments, allowing users to express their opinion on specific comments within a post.

src/modules/forum/useCases/comments/upvoteComment · high confidence

Added upvote and downvote functionality for forum posts

Users can now upvote or downvote posts on the forum. This change introduces the complete implementation for both actions, including the use cases (UpvotePost, DownvotePost), their corresponding HTTP controllers, data transfer objects, and error handling for scenarios such as duplicate votes or missing posts/members.

src/modules/forum/useCases/post/upvotePost · high confidence

Added user creation and deletion capabilities

The application now supports creating and deleting user accounts. The new \createUser\ use case validates input data (username, email, password) and enforces uniqueness constraints, returning specific errors for duplicate emails or usernames. The \deleteUser\ use case allows for the removal of existing user accounts. Both features are exposed via HTTP controllers that handle request/response mapping and error reporting.

src/modules/users/useCases/createUser · high confidence

Added user lookup by username

Users can now retrieve their profile by username. This change introduces a new use case and controller that accept a username, query the user repository, and return the user's data or a 'not found' error. The implementation uses a Result-based error handling pattern to manage success and failure states explicitly.

src/modules/users/useCases/getUserByUserName · high confidence

Added utility classes for forum posts and comments

Introduced CommentUtil and PostUtil helper classes in the forum module to handle data transformation and manipulation. CommentUtil provides methods to convert comment data transfer objects into view models, sort comments by date, and organize nested comment threads. PostUtil includes validation constants for post titles, links, and text, along with logic to calculate point changes and toggle upvote/downvote states on posts.

public/app/src/modules/forum/utils · high confidence

Forum voting and commenting capabilities

Users can now interact with the forum by posting comments, replying to existing comments, and upvoting or downvoting both posts and comments. The system tracks individual user votes to display whether a user has already voted on a specific item, and the comment and post models now calculate aggregate scores based on these votes.

src/modules/forum · high confidence

HTTP server and middleware layer introduced

A new HTTP infrastructure layer has been added to the application. The \app.ts\ file establishes an Express server that configures standard middleware including CORS, body parsing, compression, security headers, and logging, and mounts the v1 API router. Additionally, an \index.ts\ file exports a \Middleware\ class instance that integrates with the user authentication service, providing a centralized point for request processing.

src/shared/infra/http · high confidence

Initial database schema for users, posts, and comments

The application's database schema has been established with an initial migration that creates the core tables for the platform. This includes a 'base\_user' table for authentication and account details, a 'member' table for user profiles and reputation, a 'post' table for content, and a 'comment' table that supports nested replies. These tables form the foundational data structure for user accounts, post creation, and comment threads.

src/shared/infra/database/sequelize/migrations · high confidence

Initial project scaffolding and configuration files

The repository was initialized with essential configuration and metadata files to support development and deployment. This includes a Dockerfile for containerization, a .env.template for environment variables, a .sequelizerc for database migrations, a .nvmrc to specify Node.js version 10.0.0, and a diagram.svg for architecture visualization. Additionally, contributor metadata was added via .all-contributorsrc, and the project's license was established in LICENCE.md.

(repo-wide) · high confidence

Initializes the v1 API router with user, member, post, and comment endpoints

The v1 API entry point is established, wiring up routes for users, members, posts, and comments. This provides a unified API structure that aggregates the individual module routers, allowing clients to interact with the core application features through a single base path.

src/shared/infra/http/api · high confidence

Introduce GraphQL API for forum and user data

A new GraphQL API is introduced for the forum and user domains. The schema defines types for Post, Member, and User, along with queries for retrieving posts (including recent and popular lists) and members by ID or post link/slug. The server configuration wires up resolvers that fetch data via the forum use cases and member repository, exposing these capabilities to clients.

src/shared/infra/http/graphql · high confidence

Introduce core domain infrastructure for event sourcing and value objects

Added foundational domain classes to support domain-driven design patterns. This includes an \AggregateRoot\ base class that tracks and dispatches domain events, a \DomainEvents\ static manager for registering handlers and processing aggregates, and an \IDomainEvent\ interface. Additionally, new base classes for \Entity\ and \ValueObject\ are introduced to handle identity and structural equality, alongside a \WatchedList\ utility for tracking collection changes. These changes provide the underlying structure for managing domain state and events.

src/shared/domain · high confidence

Introduce user repository for database operations

Added a new user repository implementation using Sequelize to handle user data persistence. This includes the \SequelizeUserRepo\ class which provides methods to check if a user exists by email, retrieve users by username or ID, and save new user records to the database. The repository interface and its Sequelize-based implementation are now available for use in the users module.

src/modules/users/repos · high confidence

Introduced Redis-backed authentication service for user sessions and token management

Added a new authentication service implementation that stores and manages JWT and refresh tokens in Redis. The \authService.ts\ file defines the \IAuthService\ interface, while \redisAuthService.ts\ provides the concrete \RedisAuthService\ class that handles signing and decoding JWTs, creating and validating refresh tokens, and managing user sessions in Redis. The \abstractRedisClient.ts\ file introduces a reusable Redis client wrapper with methods for key-value operations (get, set, delete, count, etc.), and \redisConnection.ts\ establishes the Redis connection using configuration values. This change enables persistent, scalable session management for the user login and registration flows.

src/modules/users/services · high confidence

Introduced Sequelize ORM models for core entities

Added new Sequelize model definitions for BaseUser, Member, Post, Comment, PostVote, and CommentVote, establishing the database schema and relationships for user accounts, content, and voting systems.

src/shared/infra/database/sequelize/models · high confidence

Introduced abstract BaseController for Express HTTP handlers

Added a new abstract BaseController class in the shared HTTP models layer to standardize how Express request and response objects are handled. This class provides a common execute wrapper for controller logic and a suite of helper methods (ok, created, clientError, unauthorized, etc.) that simplify returning standardized JSON responses and status codes across the API.

src/shared/infra/http/models · high confidence

Introduced user domain model and persistence mapping

Added the core domain classes for the users subdomain, including the User aggregate root with properties for email, username, password, and authentication tokens. This change also introduces domain events for user lifecycle (created, deleted, logged in, email verified) and a mapper to handle serialization between the domain model and the database/persistence layer.

src/modules/users/domain · high confidence

Introduces core domain primitives for error handling and validation

Adds foundational shared-core classes that enable safer error handling and input validation across the application. The new \Result\ class wraps success or failure states, providing explicit \getValue()\ and \getErrorValue()\ accessors to prevent accidental misuse of error states. A \Guard\ class is introduced to validate arguments against null/undefined, numeric ranges, and combined result states, returning \Result\ objects. Additionally, \AppError\ and \UseCaseError\ classes standardize how unexpected and use-case-specific errors are represented and logged.

src/shared/core · high confidence

New utility classes for text processing and flow control

Added FlowUtils, which provides a static method to create a delayed promise, and TextUtils, which offers text sanitization using DOMPurify, URL and email validation, and a method to generate random numeric strings.

src/shared/utils · high confidence

Sequelize database connection configuration added

A new configuration file for the Sequelize ORM has been introduced, defining database credentials for development, test, and production environments. The system now dynamically selects the connection method based on the environment: in production, it connects using a CLEARDB\_DATABASE\_URL environment variable, while in other environments, it uses individual credentials (username, password, host, database name) with specific pool and dialect settings.

src/shared/infra/database/sequelize/config · high confidence

User authentication and account management endpoints

The application now exposes a comprehensive set of HTTP endpoints for user management and authentication. Users can create accounts, log in, log out, and refresh access tokens. The API also supports retrieving the current user's profile, fetching a user by username, and deleting user accounts. A new \DecodedExpressRequest\ interface is introduced to handle JWT claims in requests, and route definitions wire various controllers (create, delete, get, login, logout, refresh token) to the \/users\ path.

src/modules/users/infra · high confidence

Behavioural changes

Add authentication configuration module

A new authentication configuration module has been introduced to centralize auth-related settings. This includes the JWT secret, token expiry time (5 minutes), and Redis connection details (port and URL) sourced from environment variables. The configuration is exported via a new index file, making these settings available for the login and register pages.

src/config · high confidence

Added Redux operators for forum interactions

Added Redux operators for forum interactions, including creating and replying to posts and comments, retrieving post and comment data, and upvoting or downvoting content. These changes enable users to submit new posts, reply to existing comments, view post details and comments, and interact with the forum through voting mechanisms.

public/app/src/modules/forum/redux/operators · high confidence

Added voting capability to forum posts and comments

Users can now upvote or downvote both forum posts and individual comments. This is enabled by a new 'withVoting' higher-order component that injects the necessary upvote and downvote actions into the wrapped components, allowing them to interact with the forum's voting system.

public/app/src/modules/forum/hocs · high confidence

Introduced new data models and DTOs for forum posts, comments, and members

Added TypeScript interfaces for forum entities including Post, Comment, and Member, along with corresponding DTOs that define the structure for post and comment data. The Post and Comment models include fields for upvote/downvote status (wasUpvotedByMe, wasDownvotedByMe) and points, while the Member model tracks username and reputation. These changes establish the data layer for displaying and interacting with forum content.

public/app/src/modules/forum/models · medium confidence

Introduced new forum post filtering and summary components

Users can now filter forum posts by 'Popular' or 'New' and view a new post summary component. The change adds a \PostFilters\ component that renders clickable tabs for 'Popular' and 'New' sorting, along with associated SASS styles for active states and layout. Additionally, a \PostSummary\ component is introduced, likely used to display individual post details in the forum feed.

public/app/src/modules/forum/components/posts/filters, public/app/src/modules/forum/components/posts/post · low confidence

Sequelize database hooks for domain events

The application now automatically dispatches domain events for BaseUser, Member, and Post models whenever they are created, updated, saved, or destroyed. This ensures that domain events are triggered directly from the database layer, keeping the domain logic decoupled from the persistence implementation.

src/shared/infra/database/sequelize/hooks · high confidence

Dependencies

Updated frontend and backend dependencies

Added lockfiles and package manifests for the project root and the public/app frontend directory. This updates the backend's axios dependency to version 0.21.2 and introduces a new public/app/package.json and yarn.lock for the frontend, establishing the dependency graph for the React application.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 42 → 42 (+0.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 80 → 87 (+6.8)
  • Architecture 68 → 65 (-3.4)
  • Maturity 57 → 60 (+3.4)
  • Readiness 42 → 45 (+3.1)
  • Security 71 → 55 (-15.9)
  • Accessibility 28 → 30 (+2.3)

Resolved (58)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/yarn.lock)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/yarn.lock)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/yarn.lock)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • …and 38 more

New (184)

  • Critical CVE: [CVE redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/yarn.lock)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/yarn.lock)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/yarn.lock)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (public/app/package-lock.json)
  • …and 164 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

stemmlerjs/ddd-forum was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 24df03e5e3f617065855266fcf7250425f6e53b5 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.