Skip to content
CAI
Software that uses CAICheck a score

systemsdk/docker-symfony-api

46.1

Weak · 22 September 2026

26.3k

lines of production code

PHP

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Symfony-based backend service that manages user identities, API keys, and roles through a Domain-Driven Design architecture. It exposes these capabilities via a standardized REST API with full CRUD operations, while handling authentication via JWT and encrypted API keys. The platform also includes robust operational features for logging, health monitoring, and asynchronous message processing, supported by a modernized infrastructure stack using Docker, Elasticsearch, and RabbitMQ.

How it got here

2020 — Symfony 5.4 migration and legacy cleanup

39 changes.

The project underwent a major upgrade to Symfony 5.4 and PHP 8, replacing the legacy REST framework, custom entity traits, and manual argument resolvers with modern runtime components and explicit data handling. This refactoring was accompanied by a comprehensive overhaul of the Docker infrastructure, introducing dedicated staging and test environments with Elasticsearch and Kibana integration, while isolating development tooling into version-pinned Composer packages.

2021–2022 — DDD architecture and REST framework

69 changes.

The project underwent a comprehensive architectural shift to Domain-Driven Design, reorganizing the codebase into strict module boundaries for Users, Roles, API Keys, and Logging. A generic REST framework was introduced to standardize CRUD operations, while core infrastructure was modernized with PHP 8.3, Doctrine 3.5 compatibility, and encrypted API key storage.

2023–2025 — Domain infrastructure and API expansion

18 changes.

This period focused on establishing a robust domain layer by introducing structured enums, standardized exception hierarchies, and configurable message handling via Symfony Messenger. Concurrently, the project expanded its API surface with comprehensive controllers for managing API keys, roles, and users, while implementing secure cryptographic services for token encryption and synchronization.

Features

API key authentication with optional token encryption

The system now supports authentication via API keys sent in the Authorization header. A new authenticator validates the key by looking it up in the database, and the user provider can optionally encrypt the token before storage using OpenSSL and a configurable hash algorithm, controlled by the \apiKeyTokenOpenSslEncrypt\ and \apiKeyTokenHashAlgo\ configuration parameters.

src/ApiKey/Application/Security/Provider · high confidence

Added API Key resource application layer

Introduced the application-layer resource classes and their corresponding interfaces for the ApiKey domain. This includes specific resources for listing, finding, creating, updating, patching, deleting, and counting API keys, which delegate to the underlying repository via shared REST traits.

src/ApiKey/Application/Resource · high confidence

Added API key-based user identity implementation

Introduced the ApiKeyUser class to represent users authenticating via API keys. This class implements Symfony's UserInterface and a custom ApiKeyUserInterface, mapping an API key token to a user identifier and automatically assigning the API role alongside any other provided roles.

src/ApiKey/Application/Security · high confidence

Added Bitbucket Pipelines dependency installation script

A new shell script (.bitbucket/dependencies.sh) has been added to the repository to handle environment setup within Bitbucket Pipelines. This script installs essential build tools including bash, make, and docker-cli-compose using Alpine's package manager, ensuring the pipeline environment has the necessary dependencies to run Docker Compose commands.

.bitbucket · high confidence

Added DQL functions for UUID and binary conversion

Two new Doctrine DQL custom functions, BinToUuidOT and UuidOTToBin, have been added to the infrastructure layer. BinToUuidOT allows converting binary data to UUIDs in queries by wrapping the database's BIN\_TO\_UUID function, while UuidOTToBin enables converting UUIDs to binary format using UUID\_TO\_BIN. These functions provide a convenient way to handle UUID storage and retrieval directly within Doctrine ORM queries.

src/General/Infrastructure/DQL · high confidence

Added Fish shell completions for Composer and Symfony Console

Users of the Fish shell now have automatic command-line completion for Composer and the Symfony Console. The \docker/fish\ directory includes completion scripts that provide suggestions for Composer commands, flags, and packages (derived from \composer.json\ and \composer.lock\), as well as for the Symfony \console\ command. A configuration file sources these completions, and a wrapper function aliases the Symfony console binary for easier access.

docker/fish · high confidence

Added Redis container configuration with memory and persistence settings

A new Dockerfile and redis.conf have been added to the docker/redis directory to define a Redis service using version 8.10. The configuration sets a 1GB memory limit with a volatile-lru eviction policy, disables disk saving and append-only file persistence for I/O optimization, and specifies the custom configuration file as the startup command.

docker/redis · high confidence

Added SearchTermInterface for REST search criteria

A new interface, SearchTermInterface, has been introduced in the REST infrastructure layer to define the contract for generating search term criteria. This interface exposes constants for logical operands (OR, AND) and matching modes (starts with, ends with, full) and declares a static getCriteria method. This method allows users to specify search columns and terms, along with optional operand and mode parameters, to produce structured query criteria arrays for REST API requests.

src/General/Infrastructure/Rest/Interfaces · high confidence

Added UUID helper for Doctrine type resolution

A new UuidHelper utility class has been introduced in the General Domain layer to manage UUID operations using the Ramsey UUID library. This helper provides static methods to retrieve UUID instances from strings, convert them to binary bytes, and automatically determine the correct Doctrine database type (binary, binary ordered time, or standard) based on the UUID version, facilitating consistent UUID handling in the application's data layer.

src/General/Domain/Rest · high confidence

Added application-layer REST resources for domain entities

New application resource classes have been introduced to expose CRUD operations for several domain entities via REST. Specifically, resources are now available for DateDimension, Role, Health, LogLogin, LogRequest, and LogLoginFailure. These classes extend the existing RestResource base and inject their respective infrastructure repositories. Notably, the LogLoginFailureResource includes a custom reset method that allows clearing login failure logs for a specific user.

(repo-wide) · high confidence

Added console command to manage Elastic index templates

A new Symfony console command, \elastic:create-or-update-template\, has been introduced to allow users to create or update index templates in Elasticsearch. This command delegates the operation to the underlying \CreateOrUpdateTemplateServiceInterface\, providing interactive feedback on success when run in an interactive mode.

src/Tool/Transport/Command/Elastic · high confidence

Added domain service interfaces for Elasticsearch, mailer, and messaging

New interface contracts have been introduced in the domain service layer to define capabilities for Elasticsearch operations (including indexing, searching, and template management), email delivery, and asynchronous message sending. These interfaces establish the expected method signatures and constants for these services, enabling decoupled implementation within the application architecture.

src/General/Domain/Service · high confidence

Added error notification email template

A new HTML email template for error notifications has been introduced. Users will now receive an email containing the specific error message when an error occurs, with instructions to contact the support team for investigation.

templates/Emails · high confidence

Added form data transformers for Role and UserGroup entities

New data transformers have been introduced to handle the conversion between Role/UserGroup domain entities and their string identifiers within Symfony forms. The RoleTransformer manages single Role objects, while the UserGroupTransformer handles collections of UserGroup objects, ensuring that form submissions correctly resolve entity IDs back to their corresponding domain objects via their respective resources.

src/Role/Transport/Form, src/User/Transport/Form/DataTransformer · high confidence

Added infrastructure repositories for API keys and date dimensions

New repository classes have been introduced for the ApiKey and DateDimension domains. These implementations extend the shared BaseRepository and adhere to their respective domain interfaces, providing the underlying data access layer for these entities within the application's infrastructure.

src/ApiKey/Infrastructure/Repository, src/DateDimension/Infrastructure · high confidence

Added infrastructure repositories for login, request, and login failure logging with automatic history cleanup

New Doctrine-based repository implementations have been added for the Log module, providing concrete data access for login events, HTTP requests, and login failures. These repositories introduce automated history maintenance capabilities: login and request logs are now automatically purged based on configurable retention periods (databaseLogLoginHistoryDays and databaseLogRequestHistoryDays), while login failure records can be explicitly cleared for specific users. This ensures that logging data remains bounded and does not grow indefinitely without manual intervention.

src/Log/Infrastructure · high confidence

Added infrastructure service implementations for Elasticsearch, Mailer, and Messaging

New service classes have been introduced in the infrastructure layer to provide concrete implementations for domain interfaces. The ElasticsearchService enables indexing, searching, and template management via the Elasticsearch client, including automatic index naming based on timestamps. The MailerService wraps Symfony's mailer to send HTML emails, and the MessageService leverages Symfony Messenger to dispatch high and low priority messages through the message bus.

src/General/Infrastructure/Service · high confidence

Added log cleanup and database health-check utilities

Introduced two new utility services to improve system maintenance and observability. The CleanupLogService now allows for the programmatic removal of historical login and request logs by delegating to their respective domain repositories. Additionally, the CheckDatabaseConnectionService provides a mechanism to verify database connectivity by executing a simple table enumeration query via Doctrine's EntityManager.

src/Log/Application/Service/Utils, src/Tool/Infrastructure/Service · high confidence

Added message handler interfaces and example handlers

Added empty interfaces \MessageHighInterface\ and \MessageLowInterface\ in the message domain, and introduced example Symfony Messenger handlers (\ExternalHandler\ and \TestHandler\) that log processed messages. These files provide a starting point for handling external and test messages, with handlers marked by the \\#\[AsMessageHandler\]\ attribute and ready for integration.

src/General/Domain/Message, src/Tool/Transport/MessageHandler · high confidence

Added role data fixtures for database seeding

A new data fixture (LoadRoleData) has been introduced to automatically populate the database with Role entities during development or testing. This fixture retrieves role definitions via the RolesServiceInterface, creates corresponding Role domain entities with generated descriptions, persists them to the database, and establishes references for use in other fixtures.

src/Role/Infrastructure/DataFixtures · high confidence

Added user and user group data fixtures

New Doctrine data fixtures have been introduced to seed the database with test data. LoadUserGroupData creates UserGroup entities linked to existing roles, while LoadUserData creates User entities (specifically 'john' variants) assigned to those groups. These fixtures ensure that development and testing environments are populated with consistent, deterministic user and role data.

src/User/Infrastructure/DataFixtures · high confidence

Automated daily log cleanup capability

Users can now automatically maintain database hygiene through a new scheduled job that runs daily at midnight to clean up entries in the log\_login and log\_request tables. This is implemented via a new 'logs:cleanup' command for manual execution and a 'scheduler:cleanup-logs' command that registers the cron job, ensuring old log data is removed without manual intervention.

src/Log/Transport · high confidence

Automatic encryption and decryption of API key tokens in the database

The system now automatically encrypts API key tokens before they are saved to the database and decrypts them when loaded, using OpenSSL. This is handled by a new Doctrine lifecycle event listener that triggers encryption on persist and update operations, and decryption on post-persist, post-update, and post-load events. The feature is controlled by a configuration flag, ensuring that existing unencrypted keys remain accessible while new or updated keys are securely stored.

src/ApiKey/Transport/EventListener · high confidence

Automatic locale detection from Accept-Language header

The application now automatically sets the request locale based on the client's Accept-Language header. A new AcceptLanguageSubscriber listens to kernel requests and applies the detected language, falling back to the configured default if the header value is not supported.

src/Tool/Transport/EventSubscriber · high confidence

Automatic resolution of entities, DTOs, and logged-in users in controllers

This change introduces three new Symfony value resolvers in the transport layer to simplify controller signatures. The EntityValueResolver automatically resolves route or query parameters into domain entities based on type hints and argument names. The RestDtoValueResolver automatically maps incoming request data to specific DTOs for create, update, and patch actions using AutoMapperPlus. The LoggedInUserValueResolver injects the current authenticated user entity directly into controller methods, handling JWT token validation.

src/General/Transport/ValueResolver · high confidence

Configurable retry strategy for failed messenger messages

A new \FailedRetry\ class has been added to the messenger infrastructure, implementing \RetryStrategyInterface\ to control how messages from the failed transport are retried. This strategy allows the system to be configured via dependency injection to either permit or block retries (\isRetryable\) and to specify a fixed waiting period (\retryWaitingTime\) before attempting to resend a failed message, giving users explicit control over the failure recovery behavior.

src/General/Infrastructure/Messenger · high confidence

Introduction of API Key User Provider Interface

A new interface, ApiKeyUserProviderInterface, has been added to define the contract for API key authentication. This interface specifies that implementations must accept configuration for OpenSsl encryption and hash algorithms, along with dependencies for API key and role repositories, and provides a method to retrieve an API key entity from a token.

src/ApiKey/Application/Security/Provider/Interfaces · high confidence

Introduction of Role domain model and predefined role types

The application now includes a core Role domain entity and a corresponding enumeration of standard roles. The Role entity serves as the persistent model for user roles, storing a unique identifier, an optional description, and a collection of associated user groups, while also supporting audit fields for creation and modification. Alongside this, a new Role enum defines five specific, system-wide role types—Logged, User, Admin, Root, and API—each with a human-readable label, providing a structured way to reference these permissions throughout the system.

src/Role/Domain/Entity · high confidence

Introduction of Roles Service Interface for Role Management

A new interface, RolesServiceInterface, has been added to the application security layer to define the contract for role management services. This interface specifies methods for retrieving all roles as a list, obtaining human-readable labels and short names for specific roles, and resolving inherited roles based on a configured role hierarchy. It integrates with Symfony's security component by accepting a RoleHierarchyInterface in its constructor, enabling the application to query and manipulate role definitions consistently.

src/Role/Application/Security/Interfaces · high confidence

Introduction of a structured enum system with shared interfaces and traits

This change introduces a new domain-level enum infrastructure in the General/Domain/Enum directory, providing a standardized way to handle string-backed enumerations. It adds four interfaces (DatabaseEnumInterface, EnumWithDefaultInterface, LabeledEnumInterface, StringEnumInterface) and a GetValues trait to enforce consistent behavior across enums. Two concrete enums, Language and Locale, are implemented using this structure, both supporting string values (en, ru, ua, fi) and defining 'en' as the default value.

src/General/Domain/Enum · high confidence

Introduction of base exception classes and interfaces for the domain layer

The application now includes a structured exception hierarchy in the domain layer, introducing \BaseException\ and \BaseTranslatableException\ along with their corresponding interfaces (\ExceptionInterface\ and \TranslatableExceptionInterface\). This provides a standardized foundation for domain-specific errors, with translatable exceptions supporting parameter and domain context retrieval, enabling more consistent error handling and localization across the system.

src/General/Domain/Exception · high confidence

Introduction of encrypted API key storage capability

The ApiKey domain entity now supports storing encrypted API key tokens in the database. This is implemented by adding a \token\_hash\ column for the encrypted value and a \token\_parameters\ JSON column to store decryption metadata, allowing the system to securely manage API keys without storing them in plaintext.

src/ApiKey/Domain · high confidence

Introduction of generic BaseRepository with automatic query join and callback handling

A new abstract BaseRepository class has been added to the infrastructure layer, implementing the BaseRepositoryInterface and utilizing traits for common repository methods. This class provides a standardized way to persist and remove entities, while introducing a mechanism to automatically process and deduplicate inner and left joins, as well as custom callbacks, on query builders. This change establishes a foundational repository pattern that ensures consistent query construction and prevents duplicate joins across the application.

src/General/Infrastructure/Repository · high confidence

New 'Is User Himself' security voter

A new security voter has been added to allow applications to check if the currently authenticated user is the same as a specific user entity. This voter supports the 'IS\_USER\_HIMSELF' attribute and grants access only when the authenticated user's UUID matches the ID of the subject user, enabling fine-grained authorization for self-specific actions.

src/User/Application/Security/Voter · high confidence

New API endpoints for health checks, version info, and root access

The API now exposes three new endpoints to support application monitoring and discovery: a health check at /health that returns a timestamp to verify the application is running, a version endpoint at /version that returns the current REST API version string, and a root endpoint at / that returns an empty JSON response. These controllers are implemented using Symfony's attribute-based routing and OpenAPI documentation, integrating with existing service interfaces to provide structured responses.

src/Tool/Transport/Controller/Api · high confidence

New API endpoints for localization metadata

Added three new read-only API endpoints under the /v1/localization path to help frontend applications determine available formatting options: GET /v1/localization/language returns a list of supported language codes (e.g., 'en', 'ru', 'fi'), GET /v1/localization/locale returns supported locale strings for number, date, and time formatting, and GET /v1/localization/timezone returns a list of timezone objects including identifier, GMT offset, and user-friendly value. These endpoints rely on the existing LocalizationServiceInterface and are documented via OpenAPI attributes.

src/Tool/Transport/Controller/Api/V1 · high confidence

New API transport controllers for API Key, Role, and User management

This change introduces a comprehensive set of new HTTP controllers in the transport layer to expose API Key, Role, and User management capabilities. For API Keys, it adds a unified V1 controller handling standard CRUD operations alongside a V2 API with dedicated endpoints for count, create, delete, list, patch, update, and view actions. Role management now includes V1 endpoints to retrieve specific roles, list inherited roles, and perform administrative queries. User management is expanded with V1 endpoints for authentication (token retrieval), profile access (groups, roles, and profile data), and administrative user operations including creation, updates, deletion, and the attachment/detachment of users to and from user groups.

src/ApiKey/Transport/Controller, src/Role/Transport/Controller, src/User/Transport/Controller · high confidence

New DateDimension entity for date-based analytics

Added a new read-only DateDimension entity that maps to the 'date\_dimension' table, providing structured date attributes (year, month, day, quarter, week number, etc.) for analytical queries. The entity uses UUIDs for identification and exposes fields via serialization groups, enabling consumers to access pre-calculated date components directly from the database.

src/DateDimension/Domain/Entity · high confidence

New Doctrine DBAL types and JSON utility added

This change introduces new Doctrine DBAL type classes for handling PHP backed enums (Language, Locale, LogLogin) stored as SQL ENUMs, along with a centralized registry for these types. It also adds a new JSON utility class with safe encode/decode methods that throw exceptions on error, and refactors the existing UTCDateTimeType to use modern PHP 8+ syntax and Doctrine 3.x exception classes.

src/General/Domain/Doctrine · high confidence

New REST API action traits for admin, authenticated, logged, and anonymous access levels

Added a comprehensive set of PHP traits in the \src/General/Transport/Rest/Traits/Actions\ directory to standardize REST controller endpoints. These traits provide CRUD operations (Create, Find, FindOne, Update, Patch, Delete), along with Count and Ids actions, organized by access level: Admin (ROLE\_ADMIN), Authenticated (IS\_AUTHENTICATED\_FULLY), Logged (ROLE\_LOGGED), and Anonymous. Each trait includes Symfony routing, security attributes, and OpenAPI documentation, delegating logic to corresponding method traits.

src/General/Transport/Rest/Traits/Actions · high confidence

New REST method helper trait for controller logic

A new \RestMethodHelper\ trait has been added to the REST transport layer, providing shared functionality for controllers. It includes logic to validate HTTP methods against allowed lists, retrieve and verify DTO classes, and handle REST-specific exceptions by mapping Doctrine and HTTP errors to appropriate status codes (such as 404 for not found or 500 for internal server errors). The trait also manages entity detachment from the Doctrine Unit of Work to prevent unintended persistence during exception handling.

src/General/Transport/Rest/Traits · high confidence

New REST resources for User and User Group management

This change introduces two new application-layer resources, UserResource and UserGroupResource, which extend the base RestResource to provide standard CRUD operations (create, read, update, delete) for User and UserGroup entities. The UserResource includes a specific capability to retrieve users belonging to a specific group, taking into account role inheritance via the injected RolesServiceInterface.

src/User/Application/Resource · high confidence

New RoleRepository with bulk role clearing capability

A new RoleRepository has been introduced in the Role infrastructure layer, implementing the domain's RoleRepositoryInterface and extending the existing BaseRepository. This addition provides a specific bulk operation, clearRoles, which allows users to efficiently remove all roles from the system except for a specified set of IDs in a single database query, rather than requiring multiple individual deletion calls.

src/Role/Infrastructure/Repository · high confidence

New RolesService for role management and hierarchy resolution

A new RolesService has been added to the application security layer to centralize role-related operations. This service implements RolesServiceInterface and leverages Symfony's RoleHierarchyInterface to resolve inherited roles, ensuring that users receive the full set of accessible permissions based on their assigned roles. It also provides utility methods to retrieve all defined roles from the Role enum, map role identifiers to human-readable labels, and generate short lowercase identifiers for roles.

src/Role/Application/Security · high confidence

New SecurityUserFactory implements UserProviderInterface

A new SecurityUserFactory class has been added to handle user loading and refreshing for the application's security system. It implements Symfony's UserProviderInterface to load users by identifier (supporting UUID v1) and refresh user sessions, utilizing the UserRepository and RolesService to fetch user data and inherited roles, returning a SecurityUser instance.

src/User/Application/Security/Provider · high confidence

New User and UserGroup repositories with identity lookup and caching

The application now includes infrastructure repositories for User and UserGroup entities, implementing domain interfaces to manage persistence. The UserRepository introduces a loadUserByIdentifier method that supports lookup by either UUID or username/email, includes a static cache to reduce database hits, and joins user groups and roles in a single query. It also provides methods to check username and email uniqueness. The UserGroupRepository provides standard CRUD operations for user groups.

src/User/Infrastructure/Repository · high confidence

New application services for health, localization, versioning, and infrastructure checks

This change introduces a suite of new application-layer services in the Tool module. The HealthService now performs a database health check by cleaning, creating, and reading data. The LocalizationService provides functionality to retrieve available languages, locales, and formatted timezones with caching. The VersionService retrieves the application version from composer.json, also using cache. Additionally, new services handle Elasticsearch template management (CreateOrUpdateTemplateService), scheduled command creation (ScheduledCommandService), namespace directory discovery (CheckDependenciesService), messenger message cleanup (MessengerMessagesService), and connection checks for databases (WaitDatabaseService) and Elasticsearch (WaitElasticService).

src/Tool/Application/Service · high confidence

New cryptographic service for API keys and role synchronization capability

This change introduces two new application services. The OpenSslCryptApiKeyService provides a mechanism to encrypt and decrypt API key tokens using OpenSSL, storing the encrypted data and parameters directly on the ApiKey entity while also computing a hash of the original token. Additionally, the SyncRolesService adds the ability to synchronize defined roles with the database, creating any missing roles and removing those that are no longer defined, returning a count of created and removed roles.

src/ApiKey/Application/Service, src/Role/Application/Service · high confidence

New domain entities and repository interfaces for login and request logging

The Log domain now includes new Doctrine entities to persist authentication and API activity: LogLogin records successful logins with detailed client, OS, and device information; LogLoginFailure tracks failed authentication attempts per user; and LogRequest captures HTTP request details (method, URI, headers, status code) and response metrics, including sensitive property masking. Supporting these are the LogEntityTrait and LogRequestProcessRequestTrait which handle common timestamping, IP/agent extraction, and request processing logic. Additionally, repository interfaces (LogLoginRepositoryInterface, LogLoginFailureRepositoryInterface, LogRequestRepositoryInterface) have been introduced to manage these logs, specifically providing methods to clean historical data or clear failure records for a user.

src/Log/Domain · high confidence

New domain infrastructure for health checks, encryption, and localization

This update introduces new domain components within the Tool service to support health monitoring, secure data handling, and localization. A new Health entity and repository interface allow the system to track and manage health check records in the database. An OpenSslCryptService implementation and its associated interfaces provide a mechanism to encrypt and decrypt sensitive data (such as API keys) using configurable OpenSSL algorithms. Additionally, a LocalizationService interface is added to manage application languages, locales, and timezones, while utility interfaces for database connection checks and scheduled command management are also included to support operational tooling.

src/Tool/Domain · high confidence

New external message serializer for Symfony Messenger transport

A new \ExternalMessageSerializer\ class has been added to handle serialization and deserialization of \ExternalMessage\ objects for the Symfony Messenger transport. This component decodes incoming JSON messages into \ExternalMessage\ instances and encodes outgoing envelopes, specifically managing message stamps by serializing them into headers for redelivery/retry scenarios while excluding non-sendable stamps and large error details to optimize message size.

src/Tool/Transport/Serializer · high confidence

New generic REST method traits for resource operations

Added a set of new PHP traits in src/General/Transport/Rest/Traits/Methods to standardize REST resource handling. These traits—CountMethod, CreateMethod, DeleteMethod, FindMethod, FindOneByMethod, FindOneMethod, IdsMethod, PatchMethod, UpdateMethod, and RestMethodProcessCriteria—provide generic implementations for common CRUD and query operations. They integrate with existing RequestHandler and ResponseHandler components to manage criteria, search terms, pagination, and tenant context, allowing resources to easily expose these endpoints via the RestResourceInterface and its specialized variants.

src/General/Transport/Rest/Traits/Methods · high confidence

New generic REST resource layer with lifecycle hooks and validation

This change introduces a new application-layer framework for building REST APIs, centered on the \RestResource\ and \RestSmallResource\ abstract classes and their corresponding interfaces (e.g., \RestCreateResourceInterface\, \RestListResourceInterface\). It provides a standardized way to handle CRUD operations (create, read, update, delete, list, count, patch) via traits that enforce a consistent lifecycle of before/after hooks for extensibility. The implementation includes a \ResourceCollection\ for managing registered REST resources, a \StopwatchCompilerPass\ and \StopwatchDecorator\ to automatically instrument application services for performance monitoring, and a \ValidatorException\ that implements \ClientErrorInterface\ to ensure validation errors are properly exposed to clients with correct HTTP status codes.

src/General/Application · high confidence

New login and HTTP request logging services

Added \LoginLoggerService\ and \RequestLoggerService\ (with their interfaces) to the application layer. The login logger captures authentication events, parsing device information from the user agent and storing the result in the database. The request logger records HTTP request/response details, including user and API key associations, while respecting a configurable list of sensitive properties to exclude from the stored logs.

src/Log/Application/Service · high confidence

New repository traits for standardized data access and entity management

This change introduces two new PHP traits, RepositoryMethodsTrait and RepositoryWrappersTrait, within the General Infrastructure layer. RepositoryMethodsTrait provides a consistent set of data retrieval operations (find, findBy, findAll, countAdvanced, etc.) that handle entity manager selection and query building, while RepositoryWrappersTrait offers utility methods for managing entity references, retrieving class metadata, and creating query builders with sanitized aliases. These traits standardize how repositories interact with Doctrine ORM across the application.

src/General/Infrastructure/Repository/Traits · high confidence

New security user abstraction and identity resolution helper

Added a new SecurityUser class that implements Symfony's UserInterface and PasswordAuthenticatedUserInterface, wrapping the domain User entity to expose authentication data (identifier, password, roles) alongside user preferences (language, locale, timezone). Introduced a UserTypeIdentification helper service that resolves the current authenticated identity from the token storage, supporting both standard web users (SecurityUser) and API key users (ApiKeyUser), and providing convenience methods to retrieve the underlying domain User or ApiKey entities.

src/User/Application/Security · high confidence

New staging environment configuration with Nginx, PHP-FPM, and Kibana

The staging environment now includes dedicated configuration files for the web server, PHP runtime, and observability tools. An Nginx configuration (nginx.conf) is added to handle SSL termination, gzip compression, caching for static assets, and proxying PHP requests to the Symfony backend on port 9000. A PHP-FPM pool configuration (www.conf) defines the worker process management settings, and a production-oriented PHP configuration (php.ini) is provided. Additionally, a Kibana configuration file (kibana.yml) is introduced to connect to the Elasticsearch instance, enabling log and metric visualization for the staging environment.

docker/staging · high confidence

New utility console commands for dependency checks and service health checks

Added four new Symfony console commands to the tooling suite: \check-dependencies\ allows developers to scan vendor packages for available updates with optional filtering for minor or patch versions; \db:wait\ and \elastic:wait\ provide health-check utilities that poll the database and Elasticsearch services respectively until they become available, aiding in startup sequencing; and \scheduler:cleanup-messenger-messages\ automates the creation of a daily cron job to clean up the \messenger\_messages\ table, while the underlying \messenger:messages-cleanup\ command performs the actual deletion.

src/Tool/Transport/Command/Utils · high confidence

New validation constraints for language, locale, timezone, and user uniqueness

Added custom Symfony Validator constraints (Language, Locale, Timezone) that validate input against the application's supported localization options via LocalizationService, and added UniqueEmail and UniqueUsername constraints that check for existing user records in the database to prevent duplicate accounts.

src/Tool/Application/Validator, src/User/Application/Validator · high confidence

RabbitMQ container now supports delayed message exchange

The RabbitMQ Docker image has been updated to version 4.2 and now includes the rabbitmq\_delayed\_message\_exchange plugin (version 4.2.0). This enables users to utilize delayed message functionality within their RabbitMQ instances without needing to manually install or configure the plugin.

docker/rabbitmq · high confidence

Removals

Removal of deprecated REST interface contracts

The \RepositoryInterface\, \RestResourceInterface\, and \SearchTermInterface\ classes in the \App\\Rest\\Interfaces\ namespace have been removed. These interfaces, which previously defined contracts for repository operations, REST resource handling, and search term constants, are no longer part of the codebase, likely as part of the ongoing refactoring and migration to newer Symfony/PHP standards.

src/Rest/Interfaces · high confidence

Removal of legacy Doctrine repository layer

The custom repository classes in src/Repository (including ApiKey, DateDimension, LogLogin, LogLoginFailure, LogRequest, Role, UserGroup, and UserRepository) and their shared BaseRepository have been deleted. This removes the legacy Doctrine ORM repository implementation that provided generic CRUD operations, query builder helpers, and specific methods like username/email availability checks and login history cleanup, indicating a shift away from this repository pattern in the application.

src/Repository · high confidence

Removal of legacy REST action traits

The \src/Rest/Traits/Actions\ directory has been removed, deleting all legacy action traits (such as \CountAction\, \CreateAction\, \FindAction\, \UpdateAction\, etc.) for Admin, Anonymous, Authenticated, and Logged user roles. These traits, which previously provided standard REST endpoints with Swagger annotations and security configurations, are no longer part of the application.

src/Rest/Traits/Actions · high confidence

Removal of legacy REST framework components

The \src/Rest\ directory has been removed, deleting the legacy REST controller infrastructure including the abstract \Controller\, \ControllerCollection\, \RestResource\, and \UuidHelper\ classes. This change eliminates the previous abstraction layer for REST endpoints and UUID handling, indicating a shift away from this specific implementation pattern in the application.

src/Rest · high confidence

Removal of legacy REST method traits

The generic REST method traits in src/Rest/Traits/Methods have been removed. This includes AbstractGenericMethods and the specific operation traits (CountMethod, CreateMethod, DeleteMethod, FindMethod, FindOneMethod, IdsMethod, PatchMethod, and UpdateMethod). These traits previously provided standard CRUD and counting logic for REST resources by delegating to resource implementations and handling request validation and response formatting. Their removal indicates a shift away from this trait-based inheritance model for handling REST operations.

src/Rest/Traits/Methods · high confidence

Removal of legacy REST resource traits

The \src/Rest/Traits\ directory has been completely removed, deleting all legacy PHP traits that previously provided generic CRUD operations (such as \RestResourceBaseMethods\, \RestResourceCreate\, \RestResourceUpdate\, \RestResourceDelete\, and \RestResourcePatch\) and their associated lifecycle hooks. This change eliminates the automatic REST resource generation and validation logic that was previously available to controllers via these traits.

src/Rest/Traits · high confidence

Removal of legacy database migration scripts

The \src/Migrations\ directory has been cleaned up by deleting the \.gitignore\ file and several historical Doctrine migration classes (including \Version20190222213409.php\ and \Version20191001194001.php\). These removed files contained the initial database schema definitions for core entities such as \role\, \user\, \api\_key\, and various logging tables. This change indicates that the database structure is now managed through a different mechanism or that these specific migration steps are no longer required for new deployments.

src/Migrations · high confidence

Removal of legacy entity classes and custom Doctrine types

The \src/Entity\ directory has been cleared of all previously defined domain models and supporting infrastructure. This includes the deletion of the custom Doctrine DBAL types (\EnumType\, \EnumLogLoginType\) used for database enum mapping, as well as all entity classes such as \ApiKey\, \User\, \UserGroup\, \Role\, \Health\, \DateDimension\, \LogLogin\, \LogLoginFailure\, and \LogRequest\. Consequently, the application no longer persists or queries these specific data structures in its current state.

src/Entity · high confidence

Removal of legacy entity trait classes

The \Blameable\, \LogEntity\, \LogRequestProcessRequest\, \Timestampable\, and \UserRelations\ traits have been removed from the \src/Entity/Traits\ directory. This change eliminates the automatic tracking of creation and update metadata (who and when), the automatic logging of HTTP request details (headers, IP, user agent), and the built-in management of user-to-group relationships and role inheritance. Entities that previously used these traits will no longer automatically maintain these audit logs or relationship helpers, requiring explicit implementation or alternative approaches for these capabilities.

src/Entity/Traits · high confidence

Removal of legacy event subscribers and validation constraints

The \src/EventSubscriber\ directory has been cleared of all legacy event subscribers, including \AuthenticationFailureSubscriber\, \AuthenticationSuccessSubscriber\, \LockedUserSubscriber\, \RequestSubscriber\, \ResponseSubscriber\, and \BlameableDecorator\. Additionally, the custom validation constraints \EntityReferenceExists\ (and its validator) and the uniqueness checks for email and username (\UniqueEmail\/\UniqueUsername\ and their validators) have been removed. This change eliminates the previous logic for logging authentication events, tracking request/response details, enforcing account lockouts, and validating entity references and user uniqueness.

src/EventSubscriber · high confidence

Removal of legacy security and console command components

The \src/Security\ area has removed the entire legacy security implementation, including the \ApiKeyUser\ and \SecurityUser\ classes, the \ApiKeyAuthenticator\ (which previously handled token-based authentication via the \Authorization\ header), the \ApiKeyUserProvider\, the \RolesService\ (which managed role hierarchies and labels), and the \IsUserHimselfVoter\. Additionally, several console commands located in \src/Command\—such as \ApiKeyManagementCommand\, \RemoveApiKeyCommand\, \CreateRolesCommand\, \ManagementCommand\, \CheckDependencies\, and \WaitDatabaseCommand\—along with their supporting traits, have been deleted. This cleanup eliminates the old API key authentication flow, role management logic, and administrative CLI tools from the application.

src/Security · high confidence

Removal of legacy service classes and interfaces

The \src/Service\ directory has been cleaned up by removing several service classes and their corresponding interfaces: \HealthService\, \LoginLoggerService\ (and \LoginLoggerServiceInterface\), \RequestLoggerService\ (and \RequestLoggerServiceInterface\), and \VersionService\. These files, which previously handled health checks, login logging, request logging, and application version caching, are no longer present in the codebase.

src/Service · high confidence

Behavioural changes

Added role cleanup capability to the repository interface

The file previously defining the ApiKeyCreate DTO has been renamed and repurposed to define the RoleRepositoryInterface within the Role domain. This interface now includes a new clearRoles method, allowing users to remove existing roles from the database that no longer correspond to actual entities.

src/Role/Domain/Repository · high confidence

Base template adds favicon, importmap, and FrankenPHP hot-reload support

The base layout template now includes a default SVG favicon for the application. JavaScript assets are now managed via Symfony's importmap system by default, replacing the previous empty block. Additionally, when the FRANKENPHP\_HOT\_RELOAD environment variable is set, the template injects the necessary meta tags and scripts to enable client-side hot reloading using Idiomorph and the FrankenPHP hot-reload module.

templates · high confidence

Console entry point migrated to Symfony Runtime

The bin/console script has been refactored to use the Symfony Runtime component instead of the legacy bootstrap process. This change removes manual environment variable handling, the deprecated Debug component, and custom time-limit settings, replacing them with a standard runtime return function that initializes the Kernel and Application. Users will now rely on the vendor/autoload\_runtime.php file for bootstrapping, ensuring compatibility with modern Symfony runtime standards.

bin · high confidence

Database schema updates for API key encryption and logging structure

The database schema has been updated to support encrypted API keys and improved logging data structures. The \api\_key\ table now includes \token\_hash\ and \token\_parameters\ columns to store encrypted token data and decryption parameters, while the \token\ column length has been increased from 40 to 255 characters. Additionally, the \log\_request\ table's \headers\ and \parameters\ fields have been changed from LONGTEXT to JSON type to better structure request metadata.

migrations · high confidence

Enhanced production Docker configuration with ElasticSearch, Kibana, and security/performance improvements

The production Docker environment now includes ElasticSearch and Kibana for centralized logging and monitoring, configured via a new kibana.yml file. Nginx has been updated to use HTTP/1.1 for gzip compression, buffer access logs, and deny direct PHP execution in the uploads directory to prevent security vulnerabilities. PHP-FPM is reconfigured to use a dynamic process manager with adjusted worker limits, expose status and ping endpoints, and bind to a specific interface. Additionally, PHP settings have been refined to disable deprecated error reporting, enable assertions in development but disable them in production, and update documentation links.

docker/prod · high confidence

Localized JWT authentication failure messages

Authentication failures for JSON Web Tokens now return error messages in the user's preferred language. A new TranslatedAuthenticationFailureHandler replaces the default behavior by injecting a translator to localize the 'Invalid credentials.' message, ensuring that users see error text in their configured locale rather than a hardcoded English string.

src/User/Application/Security/Handler · high confidence

Migrated Docker Compose to v2 syntax and added staging environment support

The project has migrated its Docker Compose files from the legacy v3 syntax to the modern v2 format, replacing the old \docker-compose.yml\ files with new \compose.yaml\, \compose-prod.yaml\, \compose-staging.yaml\, and \compose-test-ci.yaml\ files. This change introduces a dedicated staging environment configuration, allowing users to deploy and test changes in a staging context separate from development and production. The new compose files also standardize service definitions across environments, incorporating Elasticsearch, Kibana, and Redis into the staging and production stacks, and update the default MySQL image version to leverage environment variables for versioning.

(repo-wide) · high confidence

New authentication logging and account lockout controls

The application now tracks login success and failure events via dedicated subscribers, storing failure attempts to enforce account lockout after a configurable number of tries. Additionally, JWT payloads are enriched with user-specific localization data (language, locale, timezone) upon creation, and Doctrine 'blameable' metadata is automatically populated for the current user on every request.

src/User/Transport/EventSubscriber · high confidence

New repository implementations and refactored health data cleanup

The system now includes dedicated infrastructure repositories for managing messenger message history and scheduled commands, allowing for explicit cleanup of old messenger messages based on a configurable retention period and standardized persistence for scheduled command entities. Additionally, the health monitoring repository has been refactored to use dependency injection for its retention configuration (replacing environment variable access) and updated to use immutable date objects and explicit type mapping for more robust database health record cleanup.

src/Tool/Infrastructure/Repository · high confidence

REST transport layer refactored and reorganized under General/Transport

The REST transport components have been reorganized from the root \src/Rest\ directory into \src/General/Transport/Rest\, introducing a new abstract \Controller\ class and a \ControllerCollection\ for managing REST endpoints. The \RequestHandler\ now explicitly supports multi-tenant environments via a new \getTenant\ method and distinguishes between query and request parameters for criteria, ordering, and limits. Additionally, the \ResponseHandler\ has been updated to support \RestSmallResourceInterface\ alongside \RestResourceInterface\, and now merges serializer contexts from resources to improve serialization flexibility.

src/General/Transport/Rest · high confidence

Refactored API Key request mapping to use constructor injection and updated namespace structure

The API Key request mapper has been reorganized to align with the new domain-driven transport layer structure. The \RequestMapper\ class was moved from \src/AutoMapper/ApiKey\ to \src/ApiKey/Transport/AutoMapper/ApiKey\ and updated to extend \RestRequestMapper\ from the general transport package. Dependency injection for \UserGroupResource\ now uses PHP 8.0+ constructor property promotion, and the class now correctly references \UserGroupResource\ and \UserGroup\ from the \User\ application and domain layers. A new \AutoMapperConfiguration\ class was added to register the specific request mappers (\ApiKeyCreate\, \ApiKeyUpdate\, \ApiKeyPatch\) for this module.

src/ApiKey/Transport/AutoMapper · high confidence

Refactored API key management console commands to follow DDD structure

The API key management console commands (create, list, edit, remove, change token) have been reorganized from a flat structure into a Domain-Driven Design layout under src/ApiKey/Transport/Command. This change updates the namespace to App\\ApiKey\\Transport\\Command\\ApiKey, moves the form type to src/ApiKey/Transport/Form/Type/Console, and refactors the commands to use constructor property promotion and the \#\[AsCommand\] attribute. The commands now rely on application-layer resources (ApiKeyResource) and domain entities (ApiKey) rather than direct repository access, and the helper logic has been consolidated into ApiKeyHelper to standardize user interaction for key selection and messaging.

src/ApiKey/Transport/Command · high confidence

Refactored ApiKey DTOs into DDD structure with modernized validation

The ApiKey data transfer objects have been reorganized from a flat src/DTO directory into the domain-specific src/ApiKey/Application/DTO structure to support a Domain-Driven Design architecture. This change introduces new specific DTOs for creation (ApiKeyCreate) and updating (ApiKeyUpdate) operations, while the base ApiKey DTO now uses modern PHP 8+ attributes for validation constraints (e.g., \#\[Assertlank\]) instead of legacy docblock annotations. Additionally, the internal logic for updating user groups has been refactored to use anonymous functions, and the DTOs now correctly extend from the general application DTO interfaces.

src/ApiKey/Application/DTO · high confidence

Refactored ApiKey data fixture to use dependency injection and static UUIDs

The LoadApiKeyData fixture in the ApiKey infrastructure layer has been refactored to remove the deprecated ContainerAwareInterface in favor of constructor injection for the RolesService. This change also introduces a static map of predefined UUIDs for test entities and updates the entity creation logic to use the injected service, ensuring deterministic data loading for functional tests.

src/ApiKey/Infrastructure/DataFixtures · high confidence

Refactored AutoMapper configuration and request mapping to use constructor injection and strict typing

The \RestAutoMapperConfiguration\ and \RestRequestMapper\ classes have been moved to the \App\\General\\Transport\\AutoMapper\ namespace and refactored to improve type safety and dependency management. Configuration now uses constructor injection for the \MapperInterface\ instead of a protected property, and the mapper classes enforce strict typing on method parameters (e.g., \mixed $source\, \mixed $destination\) and return types. Additionally, the \getObject\ method in \RestRequestMapper\ now uses reflection to detect array types in the destination DTO, allowing it to correctly retrieve array data via \$request-\>request-\>all()\ instead of a single value, ensuring accurate mapping for complex request payloads.

src/General/Transport/AutoMapper · high confidence

Refactored DateDimension entity creation command to use domain resource

The console command for creating DateDimension entities has been moved to the DateDimension transport layer and refactored to depend on a DateDimensionResource instead of a direct repository. This change updates the command's namespace, adopts Symfony 7+ attributes for command registration, and modifies the entity generation logic to end at 23:59:59 instead of 00:00:00, while also extending the maximum supported year from 2070 to 2999.

src/DateDimension/Transport · high confidence

Refactored HTTP transport event subscribers and added request logging

Moved existing event subscribers (Body, Exception) from src/EventSubscriber to src/General/Transport/EventSubscriber and updated them to use modern Symfony event classes (e.g., RequestEvent instead of KernelEvents::REQUEST). The BodySubscriber now explicitly checks for non-empty content before parsing JSON, and the ExceptionSubscriber now uses a Translator for error messages and a UserService for identity checks. Additionally, a new RequestLogSubscriber was added to log request/response details for authenticated users and API keys, while a new ResponseSubscriber attaches an X-API-VERSION header to all responses.

src/General/Transport/EventSubscriber · high confidence

Refactored REST infrastructure classes and migrated codebase to PHP 8.3

The \RepositoryHelper\ and \SearchTerm\ classes have been moved from \src/Rest\ to \src/General/Infrastructure/Rest\ and updated to the \App.General.Infrastructure.Rest\ namespace. This change includes a migration to PHP 8.3 syntax, replacing \strpos\ with \str\_contains\, using \match\ expressions instead of \switch\, and applying strict type hints (e.g., \array\<int\|string, mixed\>\). The refactoring also modernizes empty-array checks (using \=== \[\]\ instead of \count() === 0\) and updates docblocks to reflect the new structure and types.

src/General/Infrastructure/Rest · high confidence

Refactored User and UserGroup DTOs to new DDD structure with updated validation

The User and UserGroup data transfer objects have been reorganized into the src/User/Application/DTO directory to align with the new Domain-Driven Design structure. This change includes migrating from legacy docblock-based Symfony validator constraints to modern PHP 8 attributes (e.g., \#\[Assert"\]), updating namespaces to reflect the new package structure (e.g., App\\User\\Application\\DTO), and introducing specific DTOs for create, update, and patch operations (UserCreate, UserUpdate, UserPatch, UserGroupCreate, UserGroupUpdate, UserGroupPatch). A new trait, PatchUserGroups, was added to handle the logic for patching user group associations, and the UserGroup DTO now explicitly references the Role entity from the Role domain.

src/User/Application/DTO · high confidence

Refactored background job execution and removed legacy Xdebug script

The Docker environment now manages asynchronous message queues with greater specificity and reliability. The generic messenger consumer has been replaced by two distinct supervised processes: 'messenger-consume' handles internal high and low priority queues, while 'messenger-consume-external' handles external queues, both configured with a 3600-second time limit and proper log redirection to the container's standard streams. Additionally, the legacy shell script for conditional Xdebug installation has been removed, and the cron scheduler has been updated to run as the www-data user with sudo privileges to ensure correct log output.

docker/general · high confidence

Refactored console command traits and reorganized namespace structure

Moved console command helper traits from the root App\\Command namespace to App\\General\\Transport\\Command, renaming them for clarity (e.g., StyleSymfony to SymfonyStyleTrait, ExecuteMultipleCommand to ExecuteMultipleCommandTrait). Updated the ExecuteMultipleCommandTrait to use the new GetApplicationTrait for retrieving the console application, improved type safety in HelperConfigure by using arrow functions and explicit array types, and refined the command execution loop to properly handle return codes and null termination.

src/General/Transport/Command · high confidence

Refactored entity structure and added timestampable trait

The entity layer has been reorganized under the General/Domain namespace, moving the EntityInterface and Uuid trait to their new locations. A new Timestampable trait was introduced to automatically manage created\_at and updated\_at fields for entities like ApiKey, Role, User, and UserGroup via Doctrine and Gedmo annotations. The EntityInterface was simplified to remove the getCreatedAt method declaration, and the Uuid trait's internal helper method was renamed from getUuid to createUuid, with a new public getUuid accessor added.

src/General/Domain/Entity · high confidence

Refactored form type traits and introduced label constants interface

The form building infrastructure has been reorganized under the General/Transport namespace. A new FormTypeLabelInterface was added to centralize form field configuration constants (such as label, required, and choices). The AddBasicFieldToForm trait was moved to this new location and updated to use the spread operator for calling the builder's add method, replacing the previous call\_user\_func\_array approach.

src/General/Transport/Form · high confidence

Refactored user and role management console commands to use Symfony 7+ conventions

The user and role management console commands have been refactored to align with modern Symfony practices. Commands now use the \#\[AsCommand\] attribute for registration and define their names as constants, while constructor injection is used for dependencies instead of manual configuration. The codebase has been reorganized into a DDD structure, moving commands from src/Command to src/User/Transport/Command and src/Role/Transport/Command, and replacing direct repository access with application-layer resources and interfaces. Additionally, edit commands now use a patch operation for updates, and list commands have been updated to use explicit ordering parameters.

src/Role/Transport/Command, src/User/Transport/Command · high confidence

Refactored user group form logic and introduced new domain interfaces

The UserGroupChoices trait has been moved from the generic Form namespace to the User module's Transport layer, updating its namespace and dependencies to use the new User-specific UserGroupResource. This change is accompanied by the introduction of new domain interfaces: ApiKeyUserInterface for managing API key-based user roles and an empty DateDimensionRepositoryInterface, signaling the start of a DateDimension repository pattern. These changes reflect a broader architectural shift towards Domain-Driven Design and improved separation of concerns within the User and ApiKey modules.

src/ApiKey/Application/Security/Interfaces, src/DateDimension/Domain/Repository, src/User/Transport/Form/Type/Traits · medium confidence

Removal of LoggerAware and StopwatchAware traits

The \LoggerAware\ and \StopwatchAware\ traits in \src/Utils/Traits\ have been removed. These traits previously provided setter methods (\setLogger\ and \setStopwatch\) to inject \Psr\\Log\\LoggerInterface\ and \Symfony\\Component\\Stopwatch\\Stopwatch\ dependencies into classes using them. Their removal indicates a shift away from this specific injection pattern, likely relying on constructor injection or other service container configurations instead.

src/Utils/Traits · high confidence

Removal of custom REST resource param converter

The custom \RestResourceConverter\ class, which previously handled automatic parameter conversion for REST API controller actions via annotations, has been removed from the application. This change eliminates the legacy mechanism for resolving resource entities from request attributes, requiring controllers to adopt alternative approaches for data binding.

src/Request · high confidence

Removal of custom Symfony argument resolvers and form data transformers

The application no longer uses the custom \EntityValueResolver\, \LoggedInUserValueResolver\, and \RestDtoValueResolver\ classes for automatic controller argument resolution, nor the \RoleTransformer\ and \UserGroupTransformer\ for form data transformation. Additionally, the \FormTypeLabelInterface\ has been removed. This change eliminates the automatic resolution of entities, logged-in users, and DTOs from request parameters, as well as the automatic conversion of role and user group IDs to their corresponding entity objects in forms, requiring controllers and forms to handle these mappings explicitly or rely on different mechanisms.

src/ArgumentResolver, src/Form · high confidence

Removal of legacy API controllers

The legacy API controllers in src/Controller/Api have been removed, eliminating endpoints for API key management, authentication, user profiles, roles, users, user groups, health checks, and version information. This change removes the previous Swagger-based API documentation annotations and the custom REST controller infrastructure these endpoints relied on, indicating a shift to a new API implementation or framework version.

src/Controller · high confidence

Removal of legacy AutoMapper configurations and JSON utility class

The application has removed several internal components: the specific AutoMapper configuration classes for ApiKey, User, and UserGroup entities, along with the UserGroup RequestMapper that handled role transformation, and the custom JSON utility class in src/Utils/JSON.php. These deletions indicate a shift away from the previous manual mapping and JSON handling implementations, likely as part of the broader refactoring to PHP 8 and Symfony 5.4.

src/AutoMapper, src/Utils · high confidence

Removal of legacy REST resource classes and collection

The \src/Resource\ directory has been completely removed, deleting all legacy REST resource classes (including \ApiKeyResource\, \DateDimensionResource\, \HealthResource\, \LogLoginFailureResource\, \LogLoginResource\, \LogRequestResource\, \RoleResource\, \UserGroupResource\, and \UserResource\) as well as the \ResourceCollection\ utility. This eliminates the previous resource-based abstraction layer that handled entity persistence and retrieval, indicating a structural shift in how the application manages data access and API endpoints.

src/Resource · high confidence

Removal of legacy repository traits

The \RepositoryMethods\ and \RepositoryWrappers\ traits in \src/Repository/Traits\ have been removed. This eliminates the custom wrapper methods for Doctrine operations such as \find\, \findOneBy\, \findBy\, \findAll\, \findAdvanced\, \getReference\, and \createQueryBuilder\, as well as helper methods for entity metadata and manager retrieval. Users relying on these specific trait implementations for repository behavior will need to adjust their code to use standard Doctrine repository methods or the new repository structure.

src/Repository/Traits · high confidence

Repository interface refactored to support multi-EntityManager and Doctrine 3.5 compatibility

The base repository interface has been moved to the General Domain layer and updated to align with Doctrine 3.5. Key changes include the addition of an optional \entityManagerName\ parameter to core methods (such as \find\, \findOneBy\, \findBy\, \getReference\, and \createQueryBuilder\), enabling the repository to operate against specific entity managers rather than a single default instance. The interface also adopts stricter type hints, including \LockMode\ for locking strategies and \AssociationMapping\ for association data, while reorganizing method signatures to improve clarity and type safety.

src/General/Domain/Repository · high confidence

Symfony 5.4 kernel refactoring and dev-only stopwatch integration

The application kernel has been updated to align with Symfony 5.4 conventions, replacing the legacy \registerBundles\, \configureContainer\, and \configureRoutes\ methods with the modern \build\ method. This change also introduces strict typing and adds a \StopwatchCompilerPass\ that is registered only in the development environment, enabling performance profiling for developers without affecting production behavior.

src · high confidence

Symfony 5.4 migration and configuration restructuring

The application has been upgraded to Symfony 5.4, requiring a significant reconfiguration of the service container and routing. The legacy bootstrap logic has been removed in favor of modern environment loading, and the bundle list has been updated to reflect the new framework version, including the removal of deprecated bundles like DoctrineCacheBundle and SwiftmailerBundle. Routing has shifted from commented-out defaults to explicit attribute-based resource imports for API controllers. Service definitions have been expanded to include new dependencies for features such as API key encryption, Elasticsearch integration, and request logging, while the service discovery scope has been narrowed to support a more granular Domain-Driven Design structure.

config · high confidence

Updated Doctrine migration template and Swagger parameter template

The Doctrine migration template now enforces MySQL-only execution by checking for AbstractMySQLPlatform in both up() and down() methods, replaces the generic class name with a specific \<className\> placeholder, updates the default description to 'TODO: Describe reason for this migration', and removes deprecated DBALException imports and annotations. The Swagger parameter template has been adjusted to remove leading indentation from the associations list and usage examples section.

templates/Doctrine · high confidence

Updated Symfony entry point and added configuration checker

The public/index.php entry point has been refactored to use the modern Symfony runtime component (autoload\_runtime.php) instead of the legacy Debug and Request handling, aligning with the Symfony 5.4 and PHP 8.1 upgrade. Additionally, a new public/check.php script has been added to allow users to verify their server configuration and requirements via a browser, and a robots.txt file has been introduced to disallow search engine indexing.

public · high confidence

Updated development environment configuration and tooling

The development environment has been updated to support PHP 8+ and Symfony 5.4+ with improved debugging and security settings. Xdebug configuration has been refactored from legacy remote settings to modern Xdebug 3 modes (coverage, debug) with separate profiles for main and macOS hosts. Kibana has been added to the stack for Elasticsearch monitoring. Nginx configuration now uses HTTP/1.1 for gzip compression, disables caching for static assets in development, restricts direct PHP execution in the uploads directory, and increases FastCGI timeouts. PHP-FPM pool settings have been adjusted to use dynamic process management with higher limits, and various PHP INI comments have been updated to reflect current best practices and documentation links.

docker/dev · high confidence

User and User Group forms now support language, locale, and timezone selection

The User form now includes fields for selecting a user's language, locale, and timezone, utilizing new enum types and a localization service to populate timezone options. The User Group form has been refactored to use interface-based dependency injection and updated namespace paths, aligning with the application's DDD structure. These changes enhance user profile configuration capabilities while improving code maintainability.

src/User/Transport/Form/Type/Console · high confidence

User and UserGroup request mapping and password hashing updated

The User and UserGroup request mappers have been restructured to support new fields and modernized password handling. For Users, the mapper now processes 'language', 'locale', and 'timezone' fields, validating them against specific enums and throwing exceptions for invalid values, while also updating the namespace and constructor to use readonly properties. For UserGroups, a new mapper configuration and request mapper have been added to handle 'name' and 'role' properties, with the role being transformed via a resource reference. Additionally, the User entity event listener has been moved to the new transport layer and updated to use the modern PasswordHasherInterface instead of the deprecated encoder, ensuring passwords are hashed correctly during creation and updates.

src/User/Transport/AutoMapper · high confidence

User domain model and relationships restructured

The User domain has been reorganized into a strict DDD structure under src/User/Domain, introducing a new UserGroup entity and a many-to-many relationship between Users and UserGroups. This change adds audit tracking via a Blameable trait (recording created\_by and updated\_by users) and exposes user activity logs (requests, logins, failures) through dedicated relations. The User entity now implements a new UserGroupAwareInterface to manage group assignments, and repository interfaces have been updated to support username and email availability checks alongside identifier-based user loading.

src/User/Domain · high confidence

Fixes

Moved Elasticsearch data placeholder to var directory

The .gitignore file previously located in src/DataFixtures has been renamed to .gitkeep and moved to var/elasticsearch-data. This change ensures that the elasticsearch-data directory is tracked by version control, likely to preserve the directory structure for Elasticsearch data storage.

var · low confidence

Test coverage

Added integration tests for API Key, Role, and Tool controllers; Added test bootstrap and removed example functional test; Added test infrastructure for API authentication; Added test utility helpers for reflection and data serialization; Added tests for OpenSslCryptApiKeyService and validator constraint helpers; Added unit tests for DateDimension entity; Added unit tests for EntityReferenceExistsValidator; Added unit tests for OpenSslCryptService error handling; Refactored unit test base class and assertions; Removed legacy test utility classes; Test environment configuration updates.

Dependencies

New isolated tooling environments for PHP development

Added eight new Composer-based tooling directories under \tools/\ (phpunit, phpstan, ecs, php-coveralls, phpinsights, phpmd, phpmetrics, rector), each with its own \composer.json\ and \composer.lock\ locked to PHP 8.5. These provide isolated, version-pinned environments for testing (phpunit 13.3, dama/doctrine-test-bundle 8.6), static analysis (phpstan 2.2, phpstan-deprecation-rules 2.0, phpstan-phpunit 2.0, phpstan-symfony 2.0), code style (php-cs-fixer 3.95, php\_codesniffer 4.0, easy-coding-standard 13.2), coverage (php-coveralls 2.9), code quality metrics (phpinsights 2.14, phpmd 3.x-dev, phpmetrics 2.11), and refactoring (rector 2.6), all including roave/security-advisories for vulnerability checks.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 46 (-13.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.4)
  • Architecture 100 → 89 (-11.1)
  • Maturity 67 → 48 (-19.5)
  • Readiness 52 → 55 (+3.4)
  • Security 54 → 65 (+11.1)
  • Domain Modelling 79 → 81 (+2.2)
  • Accessibility 32 (new)

Resolved (24)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (src/General/Transport/Rest/Traits/Methods/CountMethod.php)
  • High CVE: [GHSA redacted] (tools/04_php-coveralls/composer.lock)
  • High IaC: DS-0025 (docker/nginx/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Low CVE: [GHSA redacted] (tools/06_phpmd/composer.lock)
  • Medium CVE: [GHSA redacted] (tools/04_php-coveralls/composer.lock)
  • Medium IaC: CKV_DOCKER_2 (Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (docker/elasticsearch/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (docker/kibana/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (docker/nginx/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (docker/rabbitmq/Dockerfile)
  • Medium IaC: CKV_DOCKER_7 (docker/redis/Dockerfile)
  • Medium IaC: CKV_DOCKER_8 (Dockerfile)
  • Medium IaC: DS-0001 (docker/redis/Dockerfile)
  • No exposed public API
  • …and 4 more

New (60)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (src/User/Transport/Command/User/ListUserGroupsCommand.php)
  • Duplicated block (11–13 lines × 2) (src/General/Transport/Rest/Traits/Methods/CountMethod.php)
  • Duplicated block (12 lines × 2) (src/User/Transport/Command/User/EditUserCommand.php)
  • Duplicated block (14 lines × 2) (src/ApiKey/Transport/Form/Type/Console/ApiKeyType.php)
  • Duplicated block (14 lines × 2) (src/DateDimension/Transport/Command/Utils/CreateDateDimensionEntitiesCommand.php)
  • Duplicated block (6 lines × 3) (src/ApiKey/Domain/Entity/ApiKey.php)
  • Duplicated block (7 lines × 2) (src/ApiKey/Application/DTO/ApiKey/ApiKey.php)
  • Duplicated block (7 lines × 2) (src/Tool/Application/Validator/Constraints/LanguageValidator.php)
  • Duplicated block (7 lines × 2) (src/User/Application/Validator/Constraints/UniqueEmail.php)
  • Duplicated block (8 lines × 2) (src/Log/Infrastructure/Repository/LogLoginRepository.php)
  • Duplicated block (9 lines × 2) (src/ApiKey/Infrastructure/DataFixtures/ORM/LoadApiKeyData.php)
  • Duplicated block (9 lines × 2) (src/General/Infrastructure/DQL/BinToUuidOT.php)
  • Duplicated block (9 lines × 2) (src/User/Application/Validator/Constraints/UniqueEmailValidator.php)
  • Further orphaned files (smaller)
  • High IaC: WD-COMPOSE-0002 (compose.yaml)
  • High IaC: WD-DOCKER-0002 (docker/nginx/Dockerfile)
  • High: security finding (details withheld)
  • …and 40 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • src/General — 1 commit

Notable commits

  • change: Symfony 8.1, MySQL 9.7, Nginx 1.31, Redis 8.10, updated composer dependencies, refactoring.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

systemsdk/docker-symfony-api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 019aa7770bf450f44ba7190543d119ec14eb1188 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.