Skip to content
CAI
Software that uses CAICheck a score

tlandeka/authentication-microservice-with-domain-driven-design

53.1

Adequate · 22 September 2026

3.7k

lines of production code

Java

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Java-based Spring Boot application that implements a Domain-Driven Design architecture for user management. It provides core authentication and account management capabilities, including email and social login, password recovery, and registration workflows. The codebase is containerized with Docker and PostgreSQL, featuring a command/query pattern for handling user operations and comprehensive test coverage for these flows.

Features

Added Maven Wrapper for reproducible builds

The project now includes the Maven Wrapper, which ensures that builds use a specific, pinned version of Maven (3.8.3) and the Maven Wrapper JAR (0.5.6). This allows developers to build the project without pre-installing Maven, as the correct version is downloaded automatically.

.mvn · high confidence

Initial project scaffolding and CI/CD configuration

The repository is initialized with essential build and deployment infrastructure. A Maven wrapper (mvnw) and its configuration are added to standardize the Java build environment. Docker and Docker Compose files are introduced to containerize the application and its PostgreSQL 12 database dependency, enabling consistent local and CI testing environments. A SQL initialization script is included to set up the database schema and user. Additionally, the project's .gitignore is updated to exclude IDE-specific files and build artifacts, and the README is expanded to document the Domain-Driven Design approach, architecture, and testing procedures.

(repo-wide) · high confidence

Introduce command and query handlers for authentication, registration, and password recovery

The application now implements a command/query-based architecture for user authentication and account management. Users can log in via email or social providers (Facebook, Google) and manage sessions. The system also supports password recovery workflows, including generating and sending recovery codes, verifying recovery codes, and updating passwords. Additionally, users can register new accounts, confirm their registration, and change their passwords. These features are exposed through specific command and query handlers that process requests and return appropriate DTOs.

src/main · high confidence

Test coverage

Added integration and unit tests for authentication and registration flows

Added comprehensive test coverage for the authentication and registration subsystems. Integration tests verify the behavior of command handlers for email, Facebook, and Google login, as well as logout, session management, password recovery, user registration confirmation, and user details updates. Unit tests validate domain rules for user registration status, password recovery code expiration, password matching, and email uniqueness, ensuring that business rules are correctly enforced across the application.

src/test · high confidence

Dependencies

Initial Maven project setup with Spring Boot and security dependencies

Added the project's primary build configuration (pom.xml), establishing a Spring Boot 2.6.2-based Java 11 application. The configuration includes dependencies for Spring Security (including OAuth2 client), JWT handling (jjwt), database migration (Flyway), and various utility libraries (Lombok, ModelMapper, JavaFaker, Mailgun, Jersey, Gson, Swagger/Springfox, Mockito). It also references a local repository and a shared 'ddd\_common' library.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 55 → 53 (-2.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-1.0)
  • Architecture 100 → 87 (-13.3)
  • Maturity 60 → 60 (+0.0)
  • Readiness 32 → 34 (+2.6)
  • Security 82 → 88 (+6.1)
  • Domain Modelling 91 → 65 (-26.7)

Resolved (14)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (9 lines × 2) (src/main/java/com/tomo/mcauthentication/application/authentication/FacebookLoginCommandHandler.java)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • The README does not state which tools (e.g. Docker) are required to run the tests. (README.md)
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient
  • single-maintainer — knowledge-concentration (bus factor) risk

New (25)

  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (7 lines × 2) (src/main/java/com/tomo/mcauthentication/application/recovery/SendPasswordRecoveryEmailCommandHandler.java)
  • Duplicated block (9 lines × 2) (src/main/java/com/tomo/mcauthentication/application/authentication/FacebookLoginCommandHandler.java)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inverted test pyramid
  • Low IaC: DS-0026 (Dockerfile)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose-ci.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • No assertions: shouldCreateUserRegistration (src/test/java/com/tomo/mcauthentication/weblayer/springboot/controller/RegistrationControllerTest.java)
  • No dependency advisory monitoring
  • Rotate the exposed credentials — git history can't be un-committed
  • Scanner failed to run — not a clean result
  • Scanner failed to run — not a clean result
  • Secret: generic-api-key (src/main/resources/application-local.yml)
  • TodoComment (src/main/java/com/tomo/mcauthentication/application/recovery/CreatePasswordRecoveryCodeCommandHandler.java)
  • …and 5 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tlandeka/authentication-microservice-with-domain-driven-design was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a7cfd82824d91d90e1f07a613cdeae1bd59f91e0 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-90d5d2fe38ee.