v-v-d/carts
54.2
Adequate · 21 September 2026
4.4k
lines of production code
Python
primary language
4
measurements over time
What this system is
This system is a shopping cart management service that handles cart creation, item manipulation, and coupon application through public, internal, and admin REST APIs. It enforces business rules for cart state transitions, quantity limits, and abandoned cart notifications via background tasks. The architecture is built on a clean separation of domain, application, and infrastructure layers, utilizing SQLAlchemy for persistence and Arq for asynchronous task processing.
How it got here
2023 — cart domain and infrastructure foundation
39 changes.
This period established the core shopping cart domain model, including entities for carts, items, coupons, and notifications, alongside the necessary database migrations. It also introduced the application layer with use cases for cart management, abandoned cart processing, and distributed locking, supported by a new REST API and CLI interface. Additionally, the infrastructure layer was built with async SQLAlchemy repositories, HTTP clients, and background task processing via Arq.
2024 — cart functionality test coverage
4 changes.
This period focused on expanding test coverage for cart-related features, including functional tests for cart use cases and unit tests for internal REST API endpoints and CLI commands. The work ensured comprehensive validation of cart creation, item management, and cart lifecycle operations.
Features
Added Arq-based task producers and workers for abandoned cart notifications
New files were added to the Arq infrastructure layer to support background task processing. The \producers.py\ file introduces an \ArqTaskProducer\ that enqueues example tasks and abandoned cart notification tasks to Redis queues. The \workers.py\ file defines the corresponding consumers, registering \send\_abandoned\_cart\_notification\ and \example\_task\ as background functions, and sets up periodic processing for abandoned carts. This enables the system to handle asynchronous events and scheduled jobs via Arq.
src/app/infra/events/arq · high confidence
Added HTTP client implementations and retry system infrastructure
New HTTP client implementations for coupons, notifications, and products have been added to the application, each providing methods to interact with remote services via an HTTP transport layer. Additionally, a retry system infrastructure has been introduced, featuring a base interface and a backoff-based retry implementation that handles transient HTTP errors with configurable retry strategies.
src/app/infra/http/clients · high confidence
Added SQL repository implementations for cart, items, coupons, and notifications
New SQLAlchemy-based repository classes have been introduced to handle database interactions for the cart system. This includes the base database engine configuration, models for carts, cart items, cart coupons, cart configuration, and cart notifications, along with their respective repository implementations that perform create, read, update, and delete operations on these entities.
src/app/infra/repositories · high confidence
Added abandoned cart processing and notification logic
Introduced the AbandonedCartsService in the application layer to handle abandoned cart workflows. This service retrieves abandoned cart data via a unit of work, enqueues notification tasks through a task producer, and sends user notifications using a notification client, while persisting sent notifications to the database.
_src/app/app\_layer/use\cases · high confidence
Added authentication and distributed locking infrastructure
The application now includes a fake JWT-based authentication system that validates tokens and retrieves user data, including admin role checks, alongside a Redis-based distributed lock system for managing concurrent access. These new infrastructure components provide the underlying mechanisms for user identity verification and resource locking, supporting features like admin logic and order processing.
src/app/infra · high confidence
Added background tasks for abandoned carts and example workflows
New background tasks have been introduced to support abandoned cart notifications and an example workflow. The \abandoned\_carts\ module now includes \send\_abandoned\_cart\_notification\ and \process\_abandoned\_carts\ functions that interact with the \AbandonedCartsService\ to handle cart expiration logic and notifications. Additionally, an \example\_task\ has been added to demonstrate cart retrieval functionality. These changes enable asynchronous processing of cart-related events.
src/app/api/events · high confidence
Added cart notification domain model
Introduced the core domain model for cart notifications, including the CartNotification entity with a factory method to create abandoned cart notifications, a corresponding DTO for data transfer, and a value object defining the notification type.
_src/app/domain/cart\notifications · high confidence
Added client interface definitions for coupons, notifications, and products
The application now defines abstract client interfaces and associated data transfer objects (DTOs) for three distinct domains: coupons, notifications, and products. Specifically, this adds the \ICouponsClient\ interface with a \get\_coupon\ method and \CouponOutputDTO\; the \INotificationsClient\ interface with a \send\_notification\ method and \SendNotificationInputDTO\; and the \IProductsClient\ interface with a \get\_product\ method and \ProductOutputDTO\. These interfaces establish the contracts for external client interactions in these areas.
_src/app/app\layer/interfaces/clients · high confidence
Added event queue infrastructure
Introduced the initial structure for the application's event system by adding the \src/app/infra/events\ package. This includes an \\_\init\\_.py\ file and a \queues.py\ module that defines \QueueNameEnum\ with \EXAMPLE\_QUEUE\ and \PERIODIC\_QUEUE\ constants, laying the groundwork for message queue integration.
src/app/infra/events · medium confidence
Added task producer interface and exception types
Introduced a new module for task management, defining the ITaskProducer interface with methods to enqueue example tasks and abandoned cart notifications, alongside custom exception classes for task production errors.
_src/app/app\layer/interfaces/tasks · high confidence
Admin API for managing cart configurations and listing carts
Added new REST endpoints for administrators to retrieve and update cart configuration settings, as well as to list and create shopping carts. The new \admin\ module exposes \GET/PUT /v1/cart\_config\ for managing cart limits, costs, and abandoned cart text, and \POST/GET /v1/carts\ for creating and listing carts with pagination support.
src/app/api/rest/admin · medium confidence
Async SQLAlchemy unit of work implementation
The infrastructure layer now provides an asynchronous SQLAlchemy-based unit of work that manages database transactions and repositories. This implementation supports concurrent operations by using async sessions and includes repositories for items, carts, cart coupons, and cart notifications, enabling transactional consistency across these entities.
_src/app/infra/unit\_of\work · high confidence
Cart item management: add, update, and delete operations
Users can now add, update, and delete items in their shopping cart. The new cart item use cases enforce user ownership checks to ensure users can only modify their own carts, while administrators are exempt from these restrictions. Each operation is protected by a distributed lock on the cart to prevent concurrent modification issues.
_src/app/app\_layer/use\_cases/cart\items · high confidence
Initial Alembic migration configuration for async SQLAlchemy support
Added the initial Alembic migration setup to support asynchronous database operations. The new \env.py\ configures Alembic to use the application's database connection via the dependency injection container, enabling async migration execution. The \script.py.mako\ template is also added to generate migration scripts with proper type hints and SQLAlchemy imports.
src/alembic · high confidence
Introduce CLI entrypoint for cart operations
A new CLI entrypoint has been added to the application, exposing a command-line interface for managing cart items. Users can now execute the 'add\_item' command via the CLI, which accepts parameters for item ID, quantity, cart ID, and authentication data, and routes the request through the existing AddCartItemUseCase.
src/app/api/cli · medium confidence
Introduce authentication system interface and data models
Added the initial structure for the authentication system interface, including the IAuthSystem abstract base class with methods for validating auth data, retrieving user data, and checking admin status. This also introduces the corresponding Data Transfer Object (UserDataOutputDTO) and custom exception classes (BaseAuthSystemError, InvalidAuthDataError, OperationForbiddenError) to handle authentication-related errors.
_src/app/app\_layer/interfaces/auth\system · high confidence
Introduce cart configuration and distributed locking infrastructure
The application now supports configurable cart limits and abandoned cart tracking through a new \CartConfig\ domain model and DTO, allowing settings like \max\_items\_qty\, \min\_cost\_for\_checkout\, and \hours\_since\_update\_until\_abandoned\ to be managed. Additionally, a distributed lock system interface and its Redis-based implementation have been added to the \app\_layer\, enabling safe concurrent access to cart resources. These changes are wired into the application's dependency injection container, making these new capabilities available to cart-related use cases.
src/app · medium confidence
Introduce public API for cart and cart item management
Added new REST endpoints for managing shopping carts and their items. Users can now create, retrieve, and deactivate carts, as well as add, update, and delete cart items. The API also supports applying and removing coupons on a cart. These endpoints are exposed under the /v1/carts and /v1/carts/{cart\_id}/items routes, enabling full cart lifecycle and item manipulation via the public API.
src/app/api/rest/public · high confidence
Introduces repository interfaces for cart, items, and coupons
The codebase now defines abstract repository interfaces for managing shopping carts, cart items, and cart coupons. Specifically, it adds \ICartsRepository\ with methods for creating, retrieving, updating, clearing, and listing carts, as well as managing cart configuration. It also introduces \IItemsRepository\ for adding, updating, and deleting cart items, and \ICartCouponsRepository\ for managing cart coupons. These interfaces establish the contract for data access layers, enabling the implementation of persistence logic for these domain entities.
src/app/domain/interfaces · high confidence
New HTTP transport implementations with retry support
Added new HTTP transport implementations for \aiohttp\ and \httpx\, each providing an asynchronous \request\ method that parses JSON or text responses. A base module defines the \IHttpTransport\ interface and data transfer objects, while a \RetryableHttpTransport\ wrapper enables configurable retry logic for any transport. These changes introduce a new way to make HTTP requests with built-in error handling and optional retry behavior.
src/app/infra/http/transports · high confidence
New REST API entry point and error handling
The application now exposes a structured REST API via FastAPI, with a new main entry point (main.py) that initializes the API and manages the application lifespan. Controllers are organized into public, internal, and admin routers, each mounted under specific prefixes (/api, /api/internal, /api/admin). Additionally, a comprehensive set of HTTP error definitions (errors.py) has been introduced to handle various cart and coupon-related failures, such as unauthorized access, forbidden actions, cart state issues, and coupon application errors.
src/app/api/rest · high confidence
New cart management use cases and DTOs
Added a comprehensive set of cart management use cases including creating, retrieving, listing, and deleting carts, as well as applying and removing coupons. The implementation includes user ownership validation, distributed locking for concurrency control, and DTOs for cart and coupon data.
_src/app/app\_layer/use\cases/carts · high confidence
Project configuration and linting rules added
The project now includes configuration files for code coverage (.coveragerc), import linting (.importlinter), database migrations (alembic.ini), and general Python tooling (setup.cfg). These files define how the application is tested, how module dependencies are restricted, how database migrations are managed, and how code quality is enforced via pytest, isort, coverage, flake8, and mypy settings.
src · high confidence
Behavioural changes
Added cart coupon domain model and validation
Introduced the core domain components for cart coupons, including the CartCoupon entity which calculates discounted cart costs and checks application conditions. The change adds data transfer objects (CartCouponDTO), value objects for validating cart cost and discount amounts, and specific domain exceptions for validation errors.
_src/app/domain/cart\coupons · high confidence
Added empty Python package init files across application layers
Empty \_\init\\_.py files have been added to the api, app\_layer, app\_layer.interfaces, domain, and infra.http directories. These changes establish the directory structure for the application's modular components, enabling them to be recognized as Python packages.
(repo-wide) · low confidence
Database schema updates for cart configuration and abandoned cart notifications
The database schema was updated to support cart configuration and abandoned cart reminders. A new \cart\_config\ table was added to store system-wide cart settings, including parameters for abandonment thresholds (e.g., hours since update) and notification limits. Additionally, a \cart\_notifications\ table was introduced to track abandoned cart reminder events, storing the notification type, text, and timestamp for each reminder sent to users.
src/alembic/versions · high confidence
Internal API for cart lifecycle management
Added internal REST endpoints to lock, unlock, and complete a shopping cart. The new controllers expose /v1/carts/{cart\_id}/lock, /v1/carts/{cart\_id}/unlock, and /v1/carts/{cart\_id}/complete, each delegating to the corresponding use case and returning a CartViewModel with items, costs, and status.
src/app/api/rest/internal · high confidence
Introduce cart domain model with item quantity limits and status transitions
Added the core domain models for shopping carts and cart items, including validation for item quantities and overall cart limits. The Cart entity now enforces specific item quantity limits and a maximum total quantity, raising errors when these limits are exceeded. Additionally, the cart supports status transitions (OPENED, DEACTIVATED, LOCKED, COMPLETED) with a defined ruleset, and includes a checkout\_enabled property that determines if the cart is eligible for checkout based on a minimum cost threshold.
src/app/domain/carts · high confidence
Introduction of SQL-based Unit of Work interface for cart operations
A new SQL-based Unit of Work interface has been introduced to manage database transactions for cart-related entities. This change adds an abstract base class defining the contract for database interactions, specifically integrating repositories for carts, cart items, cart coupons, and cart notifications. The interface supports asynchronous context management for automatic commit or rollback handling, providing a structured way to execute and manage cart-related database operations.
_src/app/app\_layer/interfaces/unit\_of\work · medium confidence
Test coverage
Added empty \_\init\\_.py files for unit test packages; Added functional tests for cart configuration management; Added functional tests for cart use cases; Added functional tests for the cart creation use case; Added test environment for cart operations; Added test infrastructure and fixtures for cart domain; Added test infrastructure for the REST API; Added unit tests for CLI commands; Added unit tests for cart domain logic; Added unit tests for cart lock, unlock, and complete operations; Added unit tests for infrastructure components; Added unit tests for public REST API endpoints; Functional test infrastructure and fixtures added.
Dependencies
Initial project setup with Python 3.11 tooling and core dependencies
The project is initialized with a defined set of dependencies and development tooling. Production dependencies include web frameworks (FastAPI, aiohttp, httpx), task management (arq), dependency injection (dependency-injector), database layers (SQLAlchemy, alembic, asyncpg), and serialization (orjson). Development tooling adds linters (black, ruff, flake8, mypy), test frameworks (pytest, pytest-asyncio), and code quality tools (bandit, coverage, isort). The Python target version is set to 3.11 in both Black and Ruff configurations.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 54 → 54 (+0.7)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 99 (-0.4)
- Architecture 100 → 72 (-28.4)
- Maturity 48 → 48 (+0.0)
- Readiness 33 → 40 (+6.9)
- Security 84 → 90 (+5.8)
- Domain Modelling 100 → 100 (-0.0)
Resolved (17)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (6 lines × 2) (src/app/infra/http/transports/aiohttp.py)
- Duplicated block (6 lines × 4) (src/app/app_layer/use_cases/cart_items/add_item.py)
- High CVE: [GHSA redacted] (requirements.txt)
- High CVE: [GHSA redacted] (requirements.txt)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (requirements-dev.txt)
- Medium CVE: [GHSA redacted] (requirements-dev.txt)
- Medium CVE: PYSEC-2024-38 (requirements.txt)
- Medium IaC: CKV_DOCKER_3 (Dockerfile)
- Medium IaC: CKV_DOCKER_4 (Dockerfile)
- No exposed public API
- Test reliability not included
- The overview mentions 'обрабатывает логику применения промокодов и купонов' (processes coupon and discount logic), but the body never explains how this is implemented in code or tested, leaving it a thin hook. (README.md)
- dormant codebase — no living knowledge left to concentrate
New (47)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (14 lines × 5) (src/alembic/versions/2023_12_23_2342-e51fb2e3bd72_initial.py)
- Duplicated block (5 lines × 4) (src/app/app_layer/use_cases/cart_items/add_item.py)
- Duplicated block (6 lines × 2) (src/app/infra/http/transports/aiohttp.py)
- Duplicated block (8 lines × 3) (src/app/app_layer/use_cases/carts/cart_complete.py)
- Duplicated block (9 lines × 3) (src/app/app_layer/use_cases/cart_items/add_item.py)
- High CVE: [GHSA redacted] (requirements.txt)
- High CVE: [GHSA redacted] (requirements.txt)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low IaC: DS-0026 (Dockerfile)
- Medium CVE: [GHSA redacted] (requirements-dev.txt)
- Medium CVE: [GHSA redacted] (requirements-dev.txt)
- Medium CVE: PYSEC-2024-38 (requirements.txt)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium: security finding (details withheld)
- …and 27 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
v-v-d/carts was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 625a5e5068885934acd3b10814b21e2ea0a45be1 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.