tomoyane/springboot-bestpractice
60.3
Adequate · 22 September 2026
2.3k
lines of production code
Java
primary language
7
measurements over time
What this system is
This system is a Spring Boot-based API service that supports multiple database backends, including MySQL, MongoDB, and Cassandra, with local in-memory storage as an option. It provides user authentication and profile management through JWT-based security and credential handling. The application features a unified error handling mechanism and enforces authentication via an interceptor, while offering a clean, modernized build and dependency structure.
How it got here
2018 — Spring Boot 2.5 migration and domain restructuring
15 changes.
The project underwent a significant modernization, migrating from Spring Boot 1.5 to 2.5.5 and upgrading the build system to Gradle 8. This period focused on restructuring the domain layer by removing obsolete controllers, services, and configuration classes, while introducing new domain services for authentication, user management, and information CRUD operations.
2024 — multi-database support and error handling
5 changes.
This period focused on enabling the application to operate with multiple database backends (MySQL, Cassandra, MongoDB) alongside a local in-memory option, selected via Spring profiles. The work included defining initial database schemas, creating startup scripts for each configuration, and implementing a unified exception handling mechanism for standard HTTP error states.
Features
Add Docker configuration for local development environments
Introduced Docker support for local development, including a new Dockerfile.app for building and running the Spring Boot application, and a docker-compose.yml file that provisions local instances of MySQL, Redis, MongoDB, and a three-node Cassandra cluster. The accompanying README.md provides usage instructions for each database service.
docker · high confidence
Add support for multiple database backends via startup script
The scripts directory now includes a new start\_server.sh script and README that allow users to start the API server with different database configurations. Users can now choose between local datasource, RDBMS (MySQL/Redis), MongoDB, or Cassandra by passing specific spring profiles (db\_local, db\_rdbms, db\_mongo, db\_cassandra) to the startup script, which sets the appropriate environment variables for each backend.
scripts · high confidence
Added Apache 2.0 license and updated project documentation
The project now includes an Apache License, Version 2.0, which defines the terms for use, reproduction, and distribution of the work. The README.md has been updated to reflect the project's architecture, which supports multiple databases including RDBMS, MongoDB, Cassandra, and Redis, and provides detailed instructions for getting started with Docker and the Spring Boot application.
(repo-wide) · high confidence
Added utility methods for date calculation, deep cloning, and Spring profile detection
A new Util class has been introduced in the common utilities package, providing three static helper methods: calculateDate() to compute a date one year in the future, deepClone() to perform deep serialization-based object cloning, and getSpringProfileActive() to retrieve the active Spring profile from environment variables. These utilities are now available for use across the application.
src/main/java/com/bestpractice/api/common/util · high confidence
Adds custom exception classes for common HTTP error states
The application now provides specific, typed exceptions for handling standard HTTP error conditions. New classes have been added to the \com.bestpractice.api.common.exception\ package, including \BadRequest\, \Conflict\, \Forbidden\, \InternalServerError\, \NotFound\, \RequestTimeout\, \ServiceUnavailable\, and \UnAuthorized\. Each extends \RuntimeException\ and provides constructors for messages and causes, allowing developers to throw distinct exception types for different error scenarios.
src/main/java/com/bestpractice/api/common/exception · high confidence
Initial database schema definitions for MySQL, Cassandra, and MongoDB
Added initial database schema definitions for three different database systems. For MySQL, a migration file (v0.0.1.sql) creates 'users' and 'infos' tables with specified columns and constraints. For Cassandra, a CQL schema file defines the 'spring\_boot' keyspace and 'infos' and 'users' tables. For MongoDB, a JavaScript file sets up the 'spring\_boot' user and creates 'users' and 'infos' collections.
db · high confidence
Introduce domain models and components for authentication and user management
Added new domain models and components to support user authentication and information management. The \AuthComponent\ handles JWT generation and validation using the Auth0 Java JWT library, while \BCryptPasswordEncryptionComponent\ provides password encoding and verification. New request and response models (\AuthByEmailRequest\, \AuthByRefreshTokenRequest\, \AuthResponse\, \Credential\, \UserRequest\, \UserResponse\, \InfoRequest\, \InfoResponse\, \ErrorResponse\) define the structure for login, token refresh, user data, and error handling. Additionally, \RequestInfoComponent\ is introduced to capture request-level context such as user ID, email, and HTTP method.
src/main/java/com/bestpractice/api/domain/model · high confidence
Introduces domain services for authentication, user management, and information CRUD
The API now exposes new domain services that handle core business logic for the application. Users can authenticate via email/password or refresh tokens (AuthService), manage user profiles and registration (UserService), and perform full CRUD operations on information items (InfoService). These services implement the domain layer's interaction with repositories and components, providing the backend logic for these features.
src/main/java/com/bestpractice/api/domain/service · high confidence
New credential configuration properties for authentication settings
A new Spring Boot configuration class, CredentialProperty, has been added to manage authentication-related settings. This component binds the 'credentials' prefix from application properties, exposing fields for key, provider, subject, algorithm (alg), HMAC secret, and expiration hour. It includes a helper method to safely convert the expiration hour string to an integer, handling empty or invalid values gracefully.
src/main/java/com/bestpractice/api/common/property · high confidence
Behavioural changes
Application entry point refactored and auto-configuration excluded
The main application class was renamed from App to Application, and the Spring Boot auto-configuration for JDBC, Security, and MongoDB was explicitly disabled in the @SpringBootApplication annotation. This change alters the startup behavior by preventing automatic setup of these components, which may affect how the application initializes and connects to databases or security providers.
src/main/java/com/bestpractice/api · medium confidence
Removal of Users domain entity
The Users domain entity, which previously defined the structure for user data including id, username, email, and password fields, has been removed from the codebase.
src/main/java/com/bestpractice/api/domain/entity · high confidence
Removal of empty database configuration classes
The empty configuration classes for Cassandra, Error, Mongo, MySQL, and Postgres have been removed from the domain config package. These were previously present as empty classes, and their removal indicates a cleanup of unused or placeholder configuration components.
src/main/java/com/bestpractice/api/domain/config · high confidence
Removal of legacy MysqlService class
The MysqlService class, which previously handled user retrieval via a field-injected UserRepository, has been removed from the codebase. This change eliminates the old service implementation, likely as part of a broader refactoring or migration to a different data access pattern.
src/main/java/com/bestpractice/api/service · medium confidence
Removal of unused UserRepository interface
The empty Spring Data JPA repository interface for the Users entity has been removed from the codebase. This cleanup eliminates an unused component that previously extended JpaRepository, simplifying the domain layer by removing a file that provided no custom query methods or additional functionality.
src/main/java/com/bestpractice/api/domain/repository · high confidence
Removed custom exception classes and error handler
The custom exception classes (Exception400, Exception401, Exception403, Exception404, Exception408, Exception500, Exception503) and the associated ErrorHandler controller advice have been removed from the application. This eliminates the previous mechanism for handling specific HTTP error codes (400, 401, 403, 404, 408, 500, 503) via these specific exception types.
src/main/java/com/bestpractice/api/exception · high confidence
Removed obsolete API controllers
The MysqlController, CassandraController, MongoController, and SampleController2 classes have been removed from the codebase. This eliminates the /api/v1/mysql/users/ endpoint and clears out empty or placeholder controllers in the v2 package, simplifying the API surface and removing unused code.
src/main/java/com/bestpractice/api/controller · high confidence
Support for multiple database backends and unified API error handling
The application now supports multiple database backends (RDBMS, Cassandra, and MongoDB) and local in-memory storage, selected via Spring profiles. This change introduces a unified exception handling mechanism via a new \AdviceController\ that returns consistent JSON error responses for standard HTTP status codes (400, 401, 403, 404, 409, 500). Additionally, a new \InterceptorController\ enforces authentication on API endpoints, validating JWT tokens and logging audit trails.
src/main/java/com/bestpractice/api/infrastrucuture · high confidence
Upgraded Gradle wrapper to version 8.0
The project now uses Gradle 8.0 (replacing 4.0) to build the application, which may affect build performance and compatibility with existing Gradle plugins.
gradle · high confidence
Test coverage
Added integration test for application context loading
Added a new integration test, ApplicationTests, which verifies that the Spring Boot application context loads successfully under the 'test' profile. This is supported by the addition of the test class and a corresponding application-test.yml configuration file that sets up an in-memory HSQL database and test credentials for the test environment.
src/test · high confidence
Dependencies
Upgrade to Spring Boot 2.5.5 and modernize build configuration
The project has been upgraded from Spring Boot 1.5.7 to 2.5.5, which includes a Java version bump to 17 and a migration from the legacy \compile\ configuration to \implementation\ and \testImplementation\ scopes. The build system now uses the Spring Boot Gradle plugin and the Spring Dependency Management plugin, replacing the manual classpath and plugin declarations. Additionally, the repository configuration was updated to use Maven Central instead of JCenter, and various dependencies were added or modified, including Spring Security, Redis, Swagger, and multiple database drivers.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 63 → 60 (-2.4)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (+0.1)
- Architecture 100 → 66 (-34.3)
- Maturity 54 → 54 (+0.0)
- Readiness 58 → 59 (+0.9)
- Security 70 → 74 (+3.9)
Resolved (15)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (6 lines × 2) (src/main/java/com/bestpractice/api/domain/service/AuthServiceImpl.java)
- Duplicated block (8 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/mongo/MongoInfoPersistentRepository.java)
- Duplicated block (9 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/local/LocalUserPersistentRepository.java)
- Duplicated block (9 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/mongo/MongoInfoPersistentRepository.java)
- Duplicated block (9 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/mongo/MongoInfoPersistentRepository.java)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium IaC: CKV_DOCKER_3 (docker/Dockerfile.app)
- No exposed public API
- Test reliability not included
- single-maintainer — knowledge-concentration (bus factor) risk
New (34)
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- Documentation: no architecture or design documentation (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/mongo/MongoInfoPersistentRepository.java)
- Duplicated block (14 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/mongo/MongoInfoPersistentRepository.java)
- Duplicated block (5 lines × 2) (src/main/java/com/bestpractice/api/domain/service/AuthServiceImpl.java)
- Duplicated block (5 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/mongo/MongoInfoPersistentRepository.java)
- Duplicated block (8 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/mongo/MongoInfoPersistentRepository.java)
- Duplicated block (9 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/local/LocalUserPersistentRepository.java)
- Duplicated block (9 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/mongo/MongoInfoPersistentRepository.java)
- Duplicated block (9 lines × 2) (src/main/java/com/bestpractice/api/infrastrucuture/persistent/rdbms/RdbmsInfoPersistentRepository.java)
- High IaC: WD-COMPOSE-0002 (docker/docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker/docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker/docker-compose.yml)
- High IaC: WD-DOCKER-0013 (docker/Dockerfile.app)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 14 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
tomoyane/springboot-bestpractice was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 40170d2067fc65909cf2f240f01981385cff3824 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-90d5d2fe38ee.