Skip to content
CAI
Software that uses CAICheck a score

v-v-d/carts

54.2

Adequate · 21 September 2026

4.4k

lines of production code

Python

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a shopping cart management service that handles cart creation, item manipulation, and coupon application through public, internal, and admin REST APIs. It enforces business rules for cart state transitions, quantity limits, and abandoned cart notifications via background tasks. The architecture is built on a clean separation of domain, application, and infrastructure layers, utilizing SQLAlchemy for persistence and Arq for asynchronous task processing.

How it got here

2023 — cart domain and infrastructure foundation

39 changes.

This period established the core shopping cart domain model, including entities for carts, items, coupons, and notifications, alongside the necessary database migrations. It also introduced the application layer with use cases for cart management, abandoned cart processing, and distributed locking, supported by a new REST API and CLI interface. Additionally, the infrastructure layer was built with async SQLAlchemy repositories, HTTP clients, and background task processing via Arq.

2024 — cart functionality test coverage

4 changes.

This period focused on expanding test coverage for cart-related features, including functional tests for cart use cases and unit tests for internal REST API endpoints and CLI commands. The work ensured comprehensive validation of cart creation, item management, and cart lifecycle operations.

Features

Added Arq-based task producers and workers for abandoned cart notifications

New files were added to the Arq infrastructure layer to support background task processing. The \producers.py\ file introduces an \ArqTaskProducer\ that enqueues example tasks and abandoned cart notification tasks to Redis queues. The \workers.py\ file defines the corresponding consumers, registering \send\_abandoned\_cart\_notification\ and \example\_task\ as background functions, and sets up periodic processing for abandoned carts. This enables the system to handle asynchronous events and scheduled jobs via Arq.

src/app/infra/events/arq · high confidence

Added HTTP client implementations and retry system infrastructure

New HTTP client implementations for coupons, notifications, and products have been added to the application, each providing methods to interact with remote services via an HTTP transport layer. Additionally, a retry system infrastructure has been introduced, featuring a base interface and a backoff-based retry implementation that handles transient HTTP errors with configurable retry strategies.

src/app/infra/http/clients · high confidence

Added SQL repository implementations for cart, items, coupons, and notifications

New SQLAlchemy-based repository classes have been introduced to handle database interactions for the cart system. This includes the base database engine configuration, models for carts, cart items, cart coupons, cart configuration, and cart notifications, along with their respective repository implementations that perform create, read, update, and delete operations on these entities.

src/app/infra/repositories · high confidence

Added abandoned cart processing and notification logic

Introduced the AbandonedCartsService in the application layer to handle abandoned cart workflows. This service retrieves abandoned cart data via a unit of work, enqueues notification tasks through a task producer, and sends user notifications using a notification client, while persisting sent notifications to the database.

_src/app/app\_layer/use\cases · high confidence

Added authentication and distributed locking infrastructure

The application now includes a fake JWT-based authentication system that validates tokens and retrieves user data, including admin role checks, alongside a Redis-based distributed lock system for managing concurrent access. These new infrastructure components provide the underlying mechanisms for user identity verification and resource locking, supporting features like admin logic and order processing.

src/app/infra · high confidence

Added background tasks for abandoned carts and example workflows

New background tasks have been introduced to support abandoned cart notifications and an example workflow. The \abandoned\_carts\ module now includes \send\_abandoned\_cart\_notification\ and \process\_abandoned\_carts\ functions that interact with the \AbandonedCartsService\ to handle cart expiration logic and notifications. Additionally, an \example\_task\ has been added to demonstrate cart retrieval functionality. These changes enable asynchronous processing of cart-related events.

src/app/api/events · high confidence

Added cart notification domain model

Introduced the core domain model for cart notifications, including the CartNotification entity with a factory method to create abandoned cart notifications, a corresponding DTO for data transfer, and a value object defining the notification type.

_src/app/domain/cart\notifications · high confidence

Added client interface definitions for coupons, notifications, and products

The application now defines abstract client interfaces and associated data transfer objects (DTOs) for three distinct domains: coupons, notifications, and products. Specifically, this adds the \ICouponsClient\ interface with a \get\_coupon\ method and \CouponOutputDTO\; the \INotificationsClient\ interface with a \send\_notification\ method and \SendNotificationInputDTO\; and the \IProductsClient\ interface with a \get\_product\ method and \ProductOutputDTO\. These interfaces establish the contracts for external client interactions in these areas.

_src/app/app\layer/interfaces/clients · high confidence

Added event queue infrastructure

Introduced the initial structure for the application's event system by adding the \src/app/infra/events\ package. This includes an \\_\init\\_.py\ file and a \queues.py\ module that defines \QueueNameEnum\ with \EXAMPLE\_QUEUE\ and \PERIODIC\_QUEUE\ constants, laying the groundwork for message queue integration.

src/app/infra/events · medium confidence

Added task producer interface and exception types

Introduced a new module for task management, defining the ITaskProducer interface with methods to enqueue example tasks and abandoned cart notifications, alongside custom exception classes for task production errors.

_src/app/app\layer/interfaces/tasks · high confidence

Admin API for managing cart configurations and listing carts

Added new REST endpoints for administrators to retrieve and update cart configuration settings, as well as to list and create shopping carts. The new \admin\ module exposes \GET/PUT /v1/cart\_config\ for managing cart limits, costs, and abandoned cart text, and \POST/GET /v1/carts\ for creating and listing carts with pagination support.

src/app/api/rest/admin · medium confidence

Async SQLAlchemy unit of work implementation

The infrastructure layer now provides an asynchronous SQLAlchemy-based unit of work that manages database transactions and repositories. This implementation supports concurrent operations by using async sessions and includes repositories for items, carts, cart coupons, and cart notifications, enabling transactional consistency across these entities.

_src/app/infra/unit\_of\work · high confidence

Cart item management: add, update, and delete operations

Users can now add, update, and delete items in their shopping cart. The new cart item use cases enforce user ownership checks to ensure users can only modify their own carts, while administrators are exempt from these restrictions. Each operation is protected by a distributed lock on the cart to prevent concurrent modification issues.

_src/app/app\_layer/use\_cases/cart\items · high confidence

Initial Alembic migration configuration for async SQLAlchemy support

Added the initial Alembic migration setup to support asynchronous database operations. The new \env.py\ configures Alembic to use the application's database connection via the dependency injection container, enabling async migration execution. The \script.py.mako\ template is also added to generate migration scripts with proper type hints and SQLAlchemy imports.

src/alembic · high confidence

Introduce CLI entrypoint for cart operations

A new CLI entrypoint has been added to the application, exposing a command-line interface for managing cart items. Users can now execute the 'add\_item' command via the CLI, which accepts parameters for item ID, quantity, cart ID, and authentication data, and routes the request through the existing AddCartItemUseCase.

src/app/api/cli · medium confidence

Introduce authentication system interface and data models

Added the initial structure for the authentication system interface, including the IAuthSystem abstract base class with methods for validating auth data, retrieving user data, and checking admin status. This also introduces the corresponding Data Transfer Object (UserDataOutputDTO) and custom exception classes (BaseAuthSystemError, InvalidAuthDataError, OperationForbiddenError) to handle authentication-related errors.

_src/app/app\_layer/interfaces/auth\system · high confidence

Introduce cart configuration and distributed locking infrastructure

The application now supports configurable cart limits and abandoned cart tracking through a new \CartConfig\ domain model and DTO, allowing settings like \max\_items\_qty\, \min\_cost\_for\_checkout\, and \hours\_since\_update\_until\_abandoned\ to be managed. Additionally, a distributed lock system interface and its Redis-based implementation have been added to the \app\_layer\, enabling safe concurrent access to cart resources. These changes are wired into the application's dependency injection container, making these new capabilities available to cart-related use cases.

src/app · medium confidence

Introduce public API for cart and cart item management

Added new REST endpoints for managing shopping carts and their items. Users can now create, retrieve, and deactivate carts, as well as add, update, and delete cart items. The API also supports applying and removing coupons on a cart. These endpoints are exposed under the /v1/carts and /v1/carts/{cart\_id}/items routes, enabling full cart lifecycle and item manipulation via the public API.

src/app/api/rest/public · high confidence

Introduces repository interfaces for cart, items, and coupons

The codebase now defines abstract repository interfaces for managing shopping carts, cart items, and cart coupons. Specifically, it adds \ICartsRepository\ with methods for creating, retrieving, updating, clearing, and listing carts, as well as managing cart configuration. It also introduces \IItemsRepository\ for adding, updating, and deleting cart items, and \ICartCouponsRepository\ for managing cart coupons. These interfaces establish the contract for data access layers, enabling the implementation of persistence logic for these domain entities.

src/app/domain/interfaces · high confidence

New HTTP transport implementations with retry support

Added new HTTP transport implementations for \aiohttp\ and \httpx\, each providing an asynchronous \request\ method that parses JSON or text responses. A base module defines the \IHttpTransport\ interface and data transfer objects, while a \RetryableHttpTransport\ wrapper enables configurable retry logic for any transport. These changes introduce a new way to make HTTP requests with built-in error handling and optional retry behavior.

src/app/infra/http/transports · high confidence

New REST API entry point and error handling

The application now exposes a structured REST API via FastAPI, with a new main entry point (main.py) that initializes the API and manages the application lifespan. Controllers are organized into public, internal, and admin routers, each mounted under specific prefixes (/api, /api/internal, /api/admin). Additionally, a comprehensive set of HTTP error definitions (errors.py) has been introduced to handle various cart and coupon-related failures, such as unauthorized access, forbidden actions, cart state issues, and coupon application errors.

src/app/api/rest · high confidence

New cart management use cases and DTOs

Added a comprehensive set of cart management use cases including creating, retrieving, listing, and deleting carts, as well as applying and removing coupons. The implementation includes user ownership validation, distributed locking for concurrency control, and DTOs for cart and coupon data.

_src/app/app\_layer/use\cases/carts · high confidence

Project configuration and linting rules added

The project now includes configuration files for code coverage (.coveragerc), import linting (.importlinter), database migrations (alembic.ini), and general Python tooling (setup.cfg). These files define how the application is tested, how module dependencies are restricted, how database migrations are managed, and how code quality is enforced via pytest, isort, coverage, flake8, and mypy settings.

src · high confidence

Behavioural changes

Added cart coupon domain model and validation

Introduced the core domain components for cart coupons, including the CartCoupon entity which calculates discounted cart costs and checks application conditions. The change adds data transfer objects (CartCouponDTO), value objects for validating cart cost and discount amounts, and specific domain exceptions for validation errors.

_src/app/domain/cart\coupons · high confidence

Added empty Python package init files across application layers

Empty \_\init\\_.py files have been added to the api, app\_layer, app\_layer.interfaces, domain, and infra.http directories. These changes establish the directory structure for the application's modular components, enabling them to be recognized as Python packages.

(repo-wide) · low confidence

Database schema updates for cart configuration and abandoned cart notifications

The database schema was updated to support cart configuration and abandoned cart reminders. A new \cart\_config\ table was added to store system-wide cart settings, including parameters for abandonment thresholds (e.g., hours since update) and notification limits. Additionally, a \cart\_notifications\ table was introduced to track abandoned cart reminder events, storing the notification type, text, and timestamp for each reminder sent to users.

src/alembic/versions · high confidence

Internal API for cart lifecycle management

Added internal REST endpoints to lock, unlock, and complete a shopping cart. The new controllers expose /v1/carts/{cart\_id}/lock, /v1/carts/{cart\_id}/unlock, and /v1/carts/{cart\_id}/complete, each delegating to the corresponding use case and returning a CartViewModel with items, costs, and status.

src/app/api/rest/internal · high confidence

Introduce cart domain model with item quantity limits and status transitions

Added the core domain models for shopping carts and cart items, including validation for item quantities and overall cart limits. The Cart entity now enforces specific item quantity limits and a maximum total quantity, raising errors when these limits are exceeded. Additionally, the cart supports status transitions (OPENED, DEACTIVATED, LOCKED, COMPLETED) with a defined ruleset, and includes a checkout\_enabled property that determines if the cart is eligible for checkout based on a minimum cost threshold.

src/app/domain/carts · high confidence

Introduction of SQL-based Unit of Work interface for cart operations

A new SQL-based Unit of Work interface has been introduced to manage database transactions for cart-related entities. This change adds an abstract base class defining the contract for database interactions, specifically integrating repositories for carts, cart items, cart coupons, and cart notifications. The interface supports asynchronous context management for automatic commit or rollback handling, providing a structured way to execute and manage cart-related database operations.

_src/app/app\_layer/interfaces/unit\_of\work · medium confidence

Test coverage

Added empty \_\init\\_.py files for unit test packages; Added functional tests for cart configuration management; Added functional tests for cart use cases; Added functional tests for the cart creation use case; Added test environment for cart operations; Added test infrastructure and fixtures for cart domain; Added test infrastructure for the REST API; Added unit tests for CLI commands; Added unit tests for cart domain logic; Added unit tests for cart lock, unlock, and complete operations; Added unit tests for infrastructure components; Added unit tests for public REST API endpoints; Functional test infrastructure and fixtures added.

Dependencies

Initial project setup with Python 3.11 tooling and core dependencies

The project is initialized with a defined set of dependencies and development tooling. Production dependencies include web frameworks (FastAPI, aiohttp, httpx), task management (arq), dependency injection (dependency-injector), database layers (SQLAlchemy, alembic, asyncpg), and serialization (orjson). Development tooling adds linters (black, ruff, flake8, mypy), test frameworks (pytest, pytest-asyncio), and code quality tools (bandit, coverage, isort). The Python target version is set to 3.11 in both Black and Ruff configurations.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 54 → 54 (+0.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-0.4)
  • Architecture 100 → 72 (-28.4)
  • Maturity 48 → 48 (+0.0)
  • Readiness 33 → 40 (+6.9)
  • Security 84 → 90 (+5.8)
  • Domain Modelling 100 → 100 (-0.0)

Resolved (17)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (6 lines × 2) (src/app/infra/http/transports/aiohttp.py)
  • Duplicated block (6 lines × 4) (src/app/app_layer/use_cases/cart_items/add_item.py)
  • High CVE: [GHSA redacted] (requirements.txt)
  • High CVE: [GHSA redacted] (requirements.txt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (requirements-dev.txt)
  • Medium CVE: [GHSA redacted] (requirements-dev.txt)
  • Medium CVE: PYSEC-2024-38 (requirements.txt)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (Dockerfile)
  • No exposed public API
  • Test reliability not included
  • The overview mentions 'обрабатывает логику применения промокодов и купонов' (processes coupon and discount logic), but the body never explains how this is implemented in code or tested, leaving it a thin hook. (README.md)
  • dormant codebase — no living knowledge left to concentrate

New (47)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (14 lines × 5) (src/alembic/versions/2023_12_23_2342-e51fb2e3bd72_initial.py)
  • Duplicated block (5 lines × 4) (src/app/app_layer/use_cases/cart_items/add_item.py)
  • Duplicated block (6 lines × 2) (src/app/infra/http/transports/aiohttp.py)
  • Duplicated block (8 lines × 3) (src/app/app_layer/use_cases/carts/cart_complete.py)
  • Duplicated block (9 lines × 3) (src/app/app_layer/use_cases/cart_items/add_item.py)
  • High CVE: [GHSA redacted] (requirements.txt)
  • High CVE: [GHSA redacted] (requirements.txt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0026 (Dockerfile)
  • Medium CVE: [GHSA redacted] (requirements-dev.txt)
  • Medium CVE: [GHSA redacted] (requirements-dev.txt)
  • Medium CVE: PYSEC-2024-38 (requirements.txt)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • …and 27 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

v-v-d/carts was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 625a5e5068885934acd3b10814b21e2ea0a45be1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.