vardius/go-api-boilerplate
45.0
Weak · 21 September 2026
12.2k
lines of production code
Go
with TypeScript
4
measurements over time
What this system is
This system is a microservices-based authentication and user management platform, comprising separate services for handling OAuth2 client credentials, access tokens, and user registration via email and social providers. It features a React web application for user interaction and a Go backend that supports pluggable persistence backends (MySQL, MongoDB, or in-memory) with event-sourced repositories. The architecture exposes HTTP and gRPC interfaces for all services, supported by shared infrastructure for event buses, middleware, and Kubernetes deployment.
How it got here
2017–2019 — Service extraction and infrastructure modernization
48 changes.
The project underwent a major architectural shift, extracting the authentication and user services into independent, containerized components with dedicated gRPC and HTTP interfaces. This period focused on modernizing the build and CI/CD pipelines, replacing legacy in-memory and DynamoDB storage with robust MySQL and MongoDB persistence, and introducing structured error handling and event-sourced repositories for improved reliability and scalability.
2020 — Full-stack architecture and persistence layer
22 changes.
This period focused on establishing a complete full-stack architecture, introducing a React-based web client alongside a robust Go backend. Significant work was done to implement configurable persistence backends (MySQL, MongoDB, SQLite) and comprehensive middleware for HTTP, gRPC, and authentication, while also adding event-driven messaging capabilities.
2021 — Persistence and infrastructure modernization
8 changes.
This period focused on modernizing the system's data layer by introducing MongoDB persistence for authentication and user services, alongside in-memory alternatives for testing. Concurrently, the infrastructure was refactored to use Terraform and Helm, standardizing the deployment of microservices on Kubernetes.
Features
Add HTTP handlers for authentication, client management, and health checks
The auth service now exposes HTTP endpoints for OAuth2 authorization and token issuance, client management (create, read, list), and token management (create, list by client or user). Additionally, liveness and readiness probes are implemented, with the readiness check validating SQL, MongoDB, and gRPC connections.
cmd/auth/internal/interfaces/http/handlers · high confidence
Add HTTP middleware for authenticating requests via credentials, headers, query, or cookies
The authenticator package is introduced to authorize HTTP requests by validating credentials or tokens. It provides a CredentialsAuthenticator for basic authentication and a TokenAuthenticator that supports extracting tokens from the Authorization header, query parameters, or cookies. This middleware adds the authenticated Identity to the request context for downstream use.
pkg/http/middleware/authenticator · high confidence
Add HTTP response flushing utility
A new \response\ package is introduced in \pkg/http/response\, providing a \Flush\ helper that safely calls the \Flush\ method on an \http.ResponseWriter\ if it implements the \http.Flusher\ interface, enabling support for streaming responses.
pkg/http/response · high confidence
Add IP address extraction utility
A new \Ip\ function is introduced in the \pkg/http/request\ package to extract the client's IP address from an HTTP request. The function checks the \X-Real-IP\ and \X-Forwarded-For\ headers, falling back to the remote address, and parses the resulting string into a \net.IP\ object, handling port separation and validation.
pkg/http/request · high confidence
Add JSON response helpers and error handling
The pkg/http/response/json package introduces new utility functions for serializing HTTP responses as JSON. It provides JSON and MustJSON to write structured data with appropriate headers, alongside JSONError and MustJSONError to format application errors into JSON responses. The package also includes NotFound and NotAllowed handlers for common HTTP error scenarios, with corresponding example and unit tests validating the serialization and error formatting behavior.
pkg/http/response/json · high confidence
Add MongoDB and SQLite event store implementations
The application now supports persisting domain events to MongoDB and SQLite databases. The MongoDB implementation uses BSON for storage and creates specific indexes for event ID, stream, and expiration. The SQLite implementation stores events in a table with JSON columns for payload and metadata. Both implementations provide the same event store interface, allowing users to choose their preferred persistence backend.
pkg/eventstore/mongo · high confidence
Add MySQL database connection and type support
The application now supports MySQL as a persistent storage backend. A new \pkg/mysql\ package provides a \ConnectionConfig\ struct and a \NewConnection\ function to establish database connections with configurable parameters like host, port, and connection limits. Additionally, custom JSON marshalling/unmarshalling types (NullInt64, NullBool, NullFloat64, NullString, NullTime) are introduced to handle SQL null values in JSON serialization, ensuring consistent data representation.
pkg/mysql · high confidence
Add MySQL persistence for OAuth2 clients and tokens
The auth service now stores OAuth2 client credentials and access/refresh tokens in a MySQL database. New repository implementations (client\_repository, token\_repository) and data models (client\_model, token\_model) manage the auth\_clients and auth\_tokens tables, enabling persistent storage of client registrations and token lifecycles.
cmd/auth/internal/infrastructure/persistence/mysql · high confidence
Add React context providers for authentication, user state, and locale
The application now provides global state management for authentication tokens, user profile data, and locale settings through new React context providers. The AuthContext manages the auth token via cookies and URL parameters, the UserContext fetches and maintains the current user's profile with loading states, and the LocaleContext manages the application's language setting. These contexts are exported from a central index file to be used throughout the web client.
cmd/web/src/context · high confidence
Add React-based web application with Docker and Kubernetes configuration
A new React-based web application is introduced in the \cmd/web\ directory, providing a frontend interface for the system. The change includes the standard Create React App structure, including a Dockerfile for containerized builds, a Kubernetes deployment manifest (main.yml) exposing port 3000, and configuration files (tsconfig.json, .gitignore, public assets). This establishes the web client component of the application, distinct from the backend or infrastructure code.
cmd/web · high confidence
Add build info CLI for version reporting
A new buildinfo package provides version, Git commit, and build time as build-time injected variables. Users can now pass the -v flag to the CLI to print the current version, Git commit, and build time, then exit immediately.
pkg/buildinfo · high confidence
Add configurable persistence backends (MongoDB, MySQL, Memory) via service container
The user service now supports pluggable persistence layers, allowing the application to run with in-memory, MongoDB, or MySQL storage depending on build tags. A new \ServiceContainer\ centralizes dependencies, wiring up the appropriate event store, repositories, and gRPC connections for each backend. Additionally, a new \mailer\ package enables sending HTML login emails with a configurable host and port.
cmd/user/internal/application/services · high confidence
Add domain models for client credentials and access tokens
The auth service now supports creating and removing client credentials and access tokens. A new client domain manages client credentials (including domain, redirect URL, and scopes), while a new token domain handles access tokens (storing token data as JSON in the event store). These changes enable the backend to manage the lifecycle of OAuth2 clients and user access tokens.
cmd/auth/internal/domain/token · high confidence
Add email-based and social login event handlers
The user service now includes event handlers for email registration, Google, and Facebook authentication, as well as email change and access token requests. These handlers process their respective events, update the user repository, and publish an access token request command. Additionally, email templates and a login email template are added to support email-based login flows.
cmd/user/internal/application/eventhandler · high confidence
Add execution context helper for managing execution flags
A new \executioncontext\ package has been added to provide helper functions for setting, clearing, and toggling execution flags within a Go context. This allows applications to store and retrieve boolean-like state (such as LIVE or REPLAY modes) directly in the context, with corresponding example and unit tests included.
pkg/executioncontext · high confidence
Add gRPC middleware for error handling, logging, metadata propagation, and metrics
New gRPC server and client interceptors have been introduced to standardize error translation, request logging, metadata handling, and request counting. The \errors.go\ file adds interceptors that map application errors to appropriate gRPC status codes (e.g., InvalidArgument, Unauthenticated) and vice versa. The \logger.go\ file introduces interceptors that log the start and end of unary and stream requests, including duration and errors. The \metadata.go\ file adds interceptors to serialize and deserialize metadata from the context for both client and server sides. Additionally, \metrics.go\ adds simple counters for incoming unary and stream requests using \expvar\. These changes provide a consistent way to handle errors, log gRPC traffic, pass metadata, and track request volumes across the gRPC layer.
pkg/grpc/middleware · high confidence
Add identity package for request authorization
A new \pkg/identity\ package has been introduced to handle request authorization. It provides an \Identity\ struct containing user and client identifiers, a token, and a \Permission\ flag type for managing access rights. The package also includes context helpers (\ContextWithIdentity\, \FromContext\) to propagate identity information through the application's execution context.
pkg/identity · high confidence
Add in-memory command bus implementation
Introduces a new in-memory command bus implementation located in the \pkg/commandbus/memory\ package. This component provides a \CommandBus\ that supports publishing and subscribing to commands using a message bus, with support for context-based timeouts and unsubscription. The change includes the core implementation, a README, and associated tests to verify publish, subscribe, and unsubscribe behaviors.
pkg/commandbus/memory · high confidence
Add in-memory event bus implementation
A new in-memory implementation of the event bus has been added to the application. This component provides a memory-based message bus that supports publishing events, subscribing to event types, and unsubscribing from them. The implementation includes full test coverage for the new functionality, ensuring that event publishing and subscription mechanisms work correctly in a non-persistent, in-memory environment.
pkg/eventbus/memory · high confidence
Add in-memory event store implementation
A new in-memory implementation of the domain event store has been added under pkg/eventstore/memory. This provides a lightweight, single-pod event store suitable for development and testing, storing events in a thread-safe map and supporting retrieval by ID, stream, and event type with chronological ordering.
pkg/eventstore/memory · high confidence
Add in-memory persistence for client and token repositories
The auth service now supports an in-memory persistence layer for client and token data. New \client\_repository.go\ and \token\_repository.go\ files implement the \ClientRepository\ and \TokenRepository\ interfaces using thread-safe maps protected by \sync.RWMutex\. This provides a non-persistent, volatile storage option for the authentication system, allowing the application to operate without a database for these specific entities.
cmd/auth/internal/infrastructure/persistence/memory · high confidence
Add new Helm chart for microservice deployment
A new Helm chart for the microservice has been introduced, providing a standardized way to deploy the service on Kubernetes. The chart includes a Deployment template that supports configurable replicas, image settings, environment variables from secrets and config maps, and readiness/liveness probes. It also defines a Service resource to expose the application's ports and includes a test hook to verify connectivity. Default values for image, service type, and resource limits are provided to simplify initial setup.
k8s/helm/charts/microservice · high confidence
Add request container for easy logger access
A new 'container' package is introduced to facilitate passing a shared container (specifically for logger access) through the request context. This provides a centralized way to access the logger within the request lifecycle, as demonstrated by the new ContextWithContainer and FromContext functions.
pkg/container · medium confidence
Add request metadata tracking via context
A new \pkg/metadata\ package introduces a \Metadata\ struct that carries request-level information such as trace ID, IP address, HTTP status code, user agent, and remote address. The package provides \ContextWithMetadata\ and \FromContext\ functions to store and retrieve this metadata within a Go context, enabling consistent request tracing and logging across the application.
pkg/metadata · high confidence
Add web application hooks for API, authentication, and state management
Introduced a new set of React hooks in the web client to support authentication and API interactions. The \useAuthToken\ hook retrieves the current authentication token from the AuthContext, while \useApi\ manages API client instances for different endpoints (users, auth) using the token. Additional hooks include \useUser\ and \useLocale\ for accessing user and locale contexts, \useQuery\ for parsing URL search parameters, and \useDocumentClick\ for handling global click events.
cmd/web/src/hooks · high confidence
Added gRPC authentication service definitions and generated code
The \cmd/auth/proto\ directory now contains the \authentication.proto\ service definition and the corresponding Go code generated by \protoc\. This introduces a new \AuthenticationService\ with RPCs for validating bearer tokens (\ValidationBearerToken\) and dispatching client or token commands (\DispatchClientCommand\, \DispatchTokenCommand\). The change includes the \.proto\ file, the generated \authentication.pb.go\ implementation, and helper files (Makefile, README) to support building the gRPC interfaces.
cmd/auth/proto · high confidence
Added gRPC protocol buffer definitions and generated Go code for the user service
The user service now exposes a gRPC interface defined in user.proto, including RPCs for dispatching user commands, retrieving a user by ID, and listing users with pagination. The diff adds the proto definition file, the corresponding Go implementation (user.pb.go), and supporting build/documentation files (Makefile, README.md) to generate and maintain the gRPC client and server interfaces.
cmd/user/proto · high confidence
Added gRPC server for authentication and token validation
A new gRPC server implementation has been introduced in the auth service to handle authentication commands and token validation. The server exposes three main capabilities: dispatching token commands, dispatching client commands, and validating bearer tokens. The token validation endpoint allows the system to verify the existence of access tokens by loading them from the OAuth2 server manager, enabling other services to check token validity without direct database calls.
cmd/auth/internal/interfaces/grpc · high confidence
Added security panel for managing OAuth2 client credentials and user sessions
The application now includes a dedicated Security panel in the UI, accessible via the header menu. This panel allows users to manage their active sessions by viewing and invalidating authentication tokens. Additionally, users can create new OAuth2 client credentials, specifying a domain, redirect URL, and scopes, with the system automatically generating the necessary client ID and secret. The interface provides code snippets for implementing both client credentials and authorization code flows.
cmd/web/src/containers · high confidence
Centralized configuration management for the auth service
The authentication service now uses a structured configuration system that reads environment variables to define connection details for HTTP, gRPC, MongoDB, and MySQL, as well as OAuth and debug settings. This change allows the service to be configured entirely through environment variables, providing a consistent way to manage settings across different environments.
cmd/auth/internal/application/config · high confidence
Centralized environment-based configuration for all services
The application now loads its settings from environment variables using the \github.com/caarlos0/env/v6\ library. This introduces a structured \Config\ type that maps environment variables for HTTP, gRPC, MongoDB, MySQL, Auth, and social providers (Facebook, Google) to Go structs. The \FromEnv()\ function parses these variables, applying defaults and fallbacks (e.g., CPU count for queue sizes), allowing users to configure the user service and its dependencies via environment variables rather than static files or hardcoded values.
cmd/user/internal/application/config · high confidence
Expose user management gRPC endpoints
The user service now exposes gRPC endpoints for dispatching commands, retrieving individual users, and listing users with pagination support. These new server methods allow clients to interact with user data and commands via the gRPC interface.
cmd/user/internal/interfaces/grpc · high confidence
Extracted and containerized the authentication service
The authentication service has been extracted into its own dedicated component, complete with a Dockerfile for building the Go 1.17 binary and a Kubernetes deployment manifest (main.yml) that configures HTTP (port 3000) and gRPC (port 3001) ports along with readiness and liveness health checks.
cmd/auth · high confidence
HTTP router and middleware configuration for the auth service
The HTTP interface for the auth service is now defined by a new router setup that configures global middleware, including recovery, metadata, logging, security headers (XSS, HSTS), authentication checks (header, query, cookie), CORS, request body limits, metrics, and rate limiting. The router registers OAuth2 endpoints (/authorize, /token), client and token management endpoints, and health/readiness probes, all mounted under /v1.
cmd/auth/internal/interfaces/http · high confidence
In-memory user persistence layer added
A new in-memory implementation of the user repository has been introduced, allowing the application to store and retrieve user data in RAM rather than a database. This includes a User model and a repository that supports operations like finding users by ID, email, or social provider IDs (Facebook/Google), as well as standard CRUD operations. This provides a lightweight, thread-safe (using RWMutex) alternative for development or testing without requiring an external database.
cmd/user/internal/infrastructure/persistence/memory · high confidence
Introduce HTTP handlers for user management, authentication, and health checks
The user service now exposes HTTP endpoints for managing users, handling OAuth2 social authentication flows, and performing health checks. Users can now register via social providers (Google, Facebook, etc.) which creates client credentials during registration. The API provides endpoints to retrieve the current user's profile, fetch a specific user by ID, and list users with pagination support. Additionally, liveness and readiness probes are exposed, checking connectivity to SQL, MongoDB, and gRPC services.
cmd/user/internal/interfaces/http/handlers · high confidence
Introduce application lifecycle and debug adapters
The application now manages the startup and graceful shutdown of registered adapters, ensuring all components are started concurrently and stopped with a configurable timeout. Additionally, a debug adapter is provided to expose HTTP endpoints for Go's pprof and expvar tools, aiding in runtime diagnostics.
pkg/application · medium confidence
Introduce gRPC server and client infrastructure
The application now includes a new \pkg/grpc\ package that provides the foundational infrastructure for gRPC communication. This includes an \Adapter\ for managing the gRPC server lifecycle, a \Server\ builder that configures keepalive policies and chains multiple unary and stream interceptors (including logging, error transformation, and identity handling), and a \Connection\ builder for gRPC clients that applies similar interceptor chains. Additionally, a health check utility is provided to verify service status, and a helper converts internal application errors into standard gRPC status codes.
pkg/grpc · high confidence
Introduce persistence interfaces for OAuth2 clients and tokens
Added new persistence layer interfaces for managing OAuth2 client and token data. The \ClientRepository\ and \TokenRepository\ interfaces define the contract for storing and retrieving client and token information, supporting both memory and database-backed implementations. This enables the authentication service to persist OAuth2 credentials and tokens, laying the groundwork for stateful OAuth2 flows.
cmd/auth/internal/infrastructure/persistence · medium confidence
Introduce pub/sub and push/pull event bus implementations
The event bus package now provides two distinct messaging patterns: a pub/sub model (in pkg/eventbus/pubsub) for broadcasting events to all subscribers, and a push/pull model (in pkg/eventbus/pushpull) for queue-based processing where only one handler consumes each event. Both implementations serialize events with request metadata and enforce a configurable handler timeout, ensuring that event handlers do not inherit the HTTP request context, which prevents premature cancellation of background processing.
pkg/eventbus/pubsub · high confidence
Introduce public command and event bus interfaces
The repository now exposes public interfaces for command and event buses, allowing external applications to interact with the internal message routing mechanisms. The \commandbus\ package provides a one-to-one command dispatch interface, while the \eventbus\ package offers a one-to-many event subscription interface, including a \PublishAndAcknowledge\ method that blocks and returns grouped errors after all handlers are executed. These interfaces are now available for import via \go get\.
pkg/eventbus · high confidence
Introduce public event store interface
The eventstore package now exposes a public GoDoc and README, making the event store interfaces available for external applications. The EventStore interface defines methods for saving, loading, and querying events, including finding all events, retrieving by ID, and fetching event streams by type.
pkg/eventstore · high confidence
Introduce structured error handling with stack traces
The errors package now provides a structured AppError type that wraps standard Go errors and automatically captures stack traces using the github.com/vardius/trace library. This allows developers to access a formatted stack trace via the new StackTrace() method, which is particularly useful for debugging HTTP and internal server errors. The change includes a set of predefined application-level errors (such as ErrUnauthorized, ErrForbidden, and ErrInternal) and adds comprehensive tests to verify the wrapping and unwrapping behavior.
pkg/errors · medium confidence
Introduce web client infrastructure for API communication and internationalization
Added core web client files that establish the foundation for API interaction and localization. This includes an HTTP client wrapper (api.ts) that handles JSON fetching, header injection (including Bearer token authorization), and structured error mapping (errors.ts). It also introduces a routing configuration (routes.ts) defining paths for home, login, security, and client authorization. Additionally, the update adds an internationalization (i18n) system with English and Polish translation files (i18n/en.json, i18n/pl.json) and a loader (i18n.ts) to switch between locales. The entry also includes type definitions (types.ts) for User, Client, and Token entities, and sets up the React application entry point (index.tsx) with necessary context providers.
cmd/web/src · high confidence
Introduces MongoDB persistence layer for user data
A new MongoDB implementation for the user repository has been added, including the User model and repository methods for creating, reading, and updating user records. The repository enforces unique indexes on user\_id, email\_address, facebook\_id, and google\_id fields to ensure data integrity. This change provides the concrete storage mechanism for user data in the system.
cmd/user/internal/infrastructure/persistence/mongo · high confidence
MongoDB persistence layer for client and token data
Added a new MongoDB-based persistence implementation for the auth service, introducing models and repositories for storing and retrieving client and token information. The client repository manages client records with unique indexes on client\_id and composite indexes on user\_id and domain, while the token repository handles token records with unique indexes on token\_id and additional indexes on code, access, and refresh fields. Both repositories provide standard CRUD operations and query methods, enabling the auth service to persist and query OAuth2 client and token data in MongoDB.
cmd/auth/internal/infrastructure/persistence/mongo · high confidence
MySQL event store implementation added
A new MySQL-backed event store has been introduced in the \pkg/eventstore/mysql\ package. This implementation persists domain events into a MySQL database, storing event payloads and metadata as JSON strings. It provides the core \EventStore\ interface methods (\Store\, \Get\, \FindAll\, \GetStream\) for MySQL, enabling the application to use MySQL as the default event storage backend instead of the previous in-memory or other database options.
pkg/eventstore/mysql · high confidence
MySQL persistence layer for user data
The user service now supports MySQL as a backend for storing user information. This includes a new database schema for the 'user\_users' table and a repository implementation that handles user creation, retrieval by ID, email, and social media IDs (Facebook, Google), as well as updates to email and social IDs. This provides a persistent, scalable storage option for user data, distinct from the previous in-memory or other database implementations.
cmd/user/internal/infrastructure/persistence/mysql · high confidence
New common UI components for login, theming, and data display
The web application now includes a suite of reusable UI components. Users can switch between dark and light themes using the new ColorModeSwitcher. A login flow is introduced via the LoginForm and LoginDrawerButton, which handle email-based authentication and display success or error states. Additionally, the interface gains a PaginatedTable for displaying data with navigation controls, an ErrorBoundary for graceful error handling, a LanguageSwitcher for locale changes, and utility components like SubmitMessage and withForwardRef.
cmd/web/src/components · high confidence
New gRPC firewall middleware for identity and permission checks
A new firewall middleware package has been added to the gRPC layer, providing server-side interceptors to extract user identity from incoming requests and enforce permission-based access control. This allows the API to validate that authenticated users possess the required permissions before executing handlers, returning unauthorized or forbidden errors when access is denied.
pkg/grpc/middleware/firewall · high confidence
User domain model and command handlers for registration and access token requests
The user domain now includes new command handlers for registering users via email, Google, and Facebook, as well as requesting access tokens. The domain model supports these flows by defining corresponding command types (RegisterWithEmail, RegisterWithGoogle, RegisterWithFacebook, RequestAccessToken) and their associated domain events (WasRegisteredWithEmail, WasRegisteredWithGoogle, WasRegisteredWithFacebook, AccessTokenWasRequested). An EmailAddress value object with validation is also introduced to ensure email addresses are valid before processing. These changes implement the core user registration and authentication request logic within the user service.
cmd/user/internal/domain/user · high confidence
User service containerization and configuration
The user service is now fully containerized with a multi-stage Dockerfile that builds the Go binary with build-time versioning and links to SSL certificates. The main entry point initializes a service container, registers the user domain, and configures HTTP and gRPC adapters with specific timeout and interceptor settings. Additionally, a Kubernetes deployment manifest (main.yml) is added, defining HTTP (port 3000) and gRPC (port 3001) ports, along with readiness and liveness health check endpoints (/readiness and /health) on port 3000.
cmd/user · high confidence
Removals
Removal of DynamoDB-based event store implementation
The DynamoDB-based event store implementation has been removed from the codebase. This change eliminates the existing mechanism for storing and retrieving domain events using Amazon DynamoDB, which previously handled operations such as storing, querying, and retrieving event data via the AWS SDK.
pkg/dynamodb · high confidence
Behavioural changes
Add JSONRawMessage type for MongoDB BSON serialization
A new JSONRawMessage type is introduced in the mongo package to handle JSON data as a string when serializing to MongoDB's BSON format. This ensures that JSON content is stored as a string rather than a binary blob, providing a consistent interface for JSON data in the database.
pkg/mongo · high confidence
Add configurable persistence backends for the auth service
The auth service now supports multiple persistence backends—memory, MySQL, and MongoDB—selected at build time via build tags (persistence\_mysql, persistence\_mongodb). Each backend provides its own ServiceContainer that wires up the appropriate repositories, event stores, and OAuth2 token management. The ServiceContainer’s Close() method now properly waits for all connection closures (SQL, MongoDB, gRPC) to complete within a 5-second timeout, preventing race conditions during shutdown.
cmd/auth/internal/application/services · high confidence
Added event handlers for client and token lifecycle events
New event handlers have been introduced to manage the creation and removal of clients and tokens. Specifically, the system now processes 'WasCreated' and 'WasRemoved' events for both clients and tokens, persisting these changes to the repository layer. Each handler enforces a 120-second timeout on the processing context to prevent long-running operations from blocking the event bus.
cmd/auth/internal/application/eventhandler · high confidence
Added internal package documentation for service layers
Added new \doc.go\ files in the \infrastructure\ and \interfaces\ packages for both the \auth\ and \user\ services. These files provide internal documentation explaining the roles of secondary/driven adapters and primary/driving adapters, clarifying the internal architecture and layering of the application.
(repo-wide) · high confidence
Domain initialization and event registration for auth and user services
The domain layers for the auth and user services now include explicit initialization logic that registers domain events and subscribes command and event handlers. In the auth service, token and client domain events are registered and wired to their respective repositories and event handlers. In the user service, user domain events (such as registration via email, Google, or Facebook, as well as email changes and access token requests) are registered and subscribed to persistence and command bus handlers. This ensures that domain events are properly routed to their handlers during application startup.
cmd/auth/internal/domain, cmd/user/internal/domain · medium confidence
Event-sourced repositories for client and token management
The authentication service now uses event-sourced repositories for managing OAuth2 clients and tokens. New \client\_repository.go\ and \token\_repository.go\ files implement persistence logic that stores domain events to an event store and publishes them via an event bus, enabling state reconstruction from history. This change supports the broader OAuth2 flow improvements by providing a consistent, event-driven persistence layer for client and token entities.
cmd/auth/internal/infrastructure/repository · high confidence
HTTP router and middleware configuration for user service
The HTTP interface for the user service is now defined in the \cmd/user/internal/interfaces/http\ package, which constructs a \gorouter\-based router. This router applies global middleware including recovery, metadata, logging, XSS protection, HSTS, and CORS. It also enforces authentication via headers, query parameters, or cookies, and applies rate limiting. Specific routes are registered for user listing, retrieval, and command dispatch, as well as Google and Facebook OAuth2 callback endpoints. Health and readiness probes are also exposed at the root path.
cmd/user/internal/interfaces/http · high confidence
Implement event-sourced user repository with event bus integration
The user service now persists user state changes to an event store and publishes each resulting event via an event bus, enabling event distribution to multiple pod instances. The repository is constructed using interfaces for the event store and event bus, and the Get method retrieves the current user state by replaying events from the store.
cmd/user/internal/infrastructure/repository · medium confidence
Introduce HTTP error mapping for application errors
A new \http.go\ file in \pkg/http/errors\ adds an \HttpError\ struct and a \NewHttpError\ function that maps internal application errors (e.g., \ErrInvalid\, \ErrUnauthorized\) to specific HTTP status codes (e.g., 400, 401, 403, 404, 408, 500, 503). The function also attaches the request trace ID from the context to the error response.
pkg/http/errors · high confidence
Introduce user persistence interfaces
A new persistence package has been added to the user service, defining the User model interface and the UserRepository interface. The repository interface specifies methods for finding, retrieving, adding, deleting, and updating user records, providing a contract for the underlying storage implementation.
cmd/user/internal/infrastructure/persistence · high confidence
Introduces OAuth2 password credentials flow with scoped token generation
Users can now obtain OAuth2 access tokens using the password credentials grant flow. The new implementation in pkg/auth/oauth2 defines specific scopes (all, user\_read, user\_write) and provides a TokenProvider that retrieves tokens by exchanging user credentials. The provider also attaches request metadata to internal service calls, enabling better tracing and context propagation for authenticated requests.
pkg/auth/oauth2 · medium confidence
Migrate Kubernetes infrastructure to Terraform
The Kubernetes deployment has been refactored to use Terraform for infrastructure-as-code management. This change introduces a new Terraform configuration that defines the cluster namespace, secrets, and core services including cert-manager, ingress-nginx, and MongoDB. Additionally, a reusable service module is introduced to standardize the deployment of microservices (web-ui, auth-api, user-api) with consistent labels, annotations, and environment variable injection from secrets.
k8s, k8s/modules/service · high confidence
Modernized build and CI/CD infrastructure
The project's build and deployment workflows have been significantly updated. The legacy Dockerfile and environment configuration files (dist.env, dist.server.env) were removed in favor of a new Makefile that supports building, tagging, and publishing Docker images with explicit version and git commit metadata. A Travis CI configuration (.travis.yml) was added to automate testing and code coverage reporting. Additionally, the project now supports Terraform-based Kubernetes deployments and Telepresence for local debugging, while the .gitignore and .editorconfig files were updated to reflect the new directory structure and Go-specific formatting rules.
(repo-wide) · high confidence
Refactored HTTP middleware package and added security and logging features
The HTTP middleware package was reorganized and expanded. Several existing middleware components (CORS, headers, logger) were moved from pkg/middleware to pkg/http/middleware. The CORS middleware was replaced by a new GrantAccessFor middleware that enforces identity and permission checks. New middleware were added to improve security and observability: HSTS (Strict-Transport-Security), XSS protection headers (X-Content-Type-Options, X-Frame-Options), request body size limiting, and a rate limiter. A new container middleware was introduced to manage request-scoped dependencies. The logger middleware was updated to capture and log HTTP status codes and error stack traces.
pkg/http/middleware · high confidence
Refactored authentication and authorization logic
The authentication package was restructured to separate concerns: the \Authenticator\ interface now handles low-level JWT signing and verification, while the \TokenAuthorizer\ interface manages higher-level identity resolution and remote validation. This replaces the previous monolithic \JwtService\ and \auth.go\/\context.go\/\identity.go\ files. Additionally, the \middleware\ package was removed, indicating that authentication and error-handling middleware are no longer part of this package.
pkg/auth · high confidence
Refactored domain layer with new event and metadata structures
The domain package was restructured to support a more robust event sourcing model. The previous \Event\ struct was replaced with a new \Event\ type that includes an \ExpiresAt\ field and a pointer to \EventMetadata\ (containing identity, IP address, user agent, and referer). A \RawEvent\ interface was introduced to allow flexible payload types, and \NewEventFromRawEvent\ was added to construct events from raw data. Additionally, a thread-safe event factory registry was added to manage event types, and the old \CommandBus\, \EventBus\, and \EventStore\ interfaces were removed from this package.
pkg/domain · high confidence
Removal of in-memory message bus and event store implementations
The in-memory implementations for the message bus, event bus, command bus, and event store have been removed from the codebase. This eliminates the memory-based backends for publishing/subscribing to events and commands, as well as the in-memory storage for event streams.
pkg/memory · high confidence
Removal of legacy nginx configuration and snippets
The nginx configuration files have been removed, including the main nginx.conf and the proxy-params.conf and ssl-params.conf snippets. This eliminates the previous setup that proxied requests to port 3000 and applied specific SSL/TLS headers and security headers. Users relying on these default nginx configurations will need to provide their own nginx configuration or use the new proxy/crypto package and firewall middleware as indicated by the commit message.
nginx · high confidence
Removal of obsolete CLI entry point
The main.go file in the cmd/cli directory has been removed. This eliminates a standalone CLI command that previously printed a static message, indicating a cleanup of unused or placeholder code within the CLI package.
cmd/cli · high confidence
Removed legacy auth and command dispatch controllers
The \auth.go\ and \dispatch.go\ files in \pkg/controller\ have been deleted. This removes the HTTP handlers for Facebook and Google OAuth flows and the generic command dispatch endpoint, indicating a shift away from the previous controller-based request handling in this package.
pkg/controller · high confidence
Removed legacy database tables and introduced new access control types
The system has removed legacy database tables (auth\_tokens, clients, events, and users) via new migration scripts, cleaning up the database schema. Additionally, new access control abstractions have been introduced: a Scope type for authentication scopes (all, user\_read, user\_write) and a Role type for user permissions (USER, ADMIN, SUPER\_ADMIN), accompanied by corresponding unit tests.
(repo-wide) · medium confidence
Removed user domain implementation
The entire user domain implementation has been removed from the codebase. This includes the user entity, its associated command and event structures, the event-sourced repository, and the command/event handlers that previously managed user registration and email changes.
pkg/domain/user · high confidence
Dependencies
Added web client dependencies and Go backend modules
The web application's frontend dependencies were added to \cmd/web/package.json\ and \cmd/web/yarn.lock\, including React 16.13.1, Chakra UI, and various Babel and testing libraries. Simultaneously, the Go backend's \go.mod\ and \go.sum\ files were introduced, establishing the project's Go module structure with dependencies such as gRPC, MySQL driver, and MongoDB driver.
(dependencies) · high confidence
Removed Go dependency management and startup scripts
The project has removed the Gopkg.lock and Gopkg.toml files, which previously managed Go dependencies using the 'dep' tool. Additionally, the cmd/server/start.sh script, which handled dependency installation and debugging setup, has been deleted. This indicates a shift away from the 'dep' dependency manager for this component.
cmd/server · high confidence
Housekeeping
Added package documentation for the application layer
Added doc.go files to the application packages in the auth and user commands, providing package-level documentation that describes the application layer's role in driving workflows, handling transactions, and coordinating domain objects.
cmd/auth/internal/application, cmd/user/internal/application · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 46 → 45 (-0.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 91 → 93 (+1.7)
- Architecture 90 → 76 (-14.7)
- Maturity 59 → 59 (+0.0)
- Readiness 33 → 32 (-1.6)
- Security 52 → 52 (-0.1)
- Domain Modelling 73 → 77 (+4.1)
- Event-Driven 55 → 55 (+0.0)
- Event Sourcing 75 → 75 (+0.0)
- Accessibility 57 → 57 (+0.0)
Resolved (119)
- Change coupling clique: when_token_was_created.go, when_user_email_address_was_changed.go, when_user_was_registered_with_facebook.go, when_user_was_registered_with_google.go (cmd/auth/internal/application/eventhandler/when_token_was_created.go)
- Change coupling: connection.go ↔ server.go (pkg/grpc/connection.go)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical vulnerability: [GHSA redacted] (cmd/web/yarn.lock)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (cmd/auth/internal/infrastructure/persistence/mongo/token_repository.go)
- Duplicated block (10 lines × 2) (pkg/eventstore/mysql/event_store.go)
- …and 99 more
New (238)
- Change coupling: auth.go ↔ user.go (cmd/auth/internal/interfaces/http/handlers/auth.go)
- Change coupling: auth.go ↔ user.go (cmd/user/internal/interfaces/http/handlers/auth.go)
- Change coupling: token_store.go ↔ server.go (cmd/auth/internal/application/services/oauth2/token_store.go)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (cmd/web/yarn.lock)
- Critical vulnerability: [GHSA redacted] (cmd/web/yarn.lock)
- Dependency pinned to a stale untagged commit: github.com/asaskevich/govalidator
- Dependency pinned to a stale untagged commit: golang.org/x/oauth2
- Dependency pinned to a stale untagged commit: golang.org/x/time
- …and 218 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
vardius/go-api-boilerplate was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 1fb92f6f5a50157a9840bb6bedc84a63885ed482 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.