Skip to content
CAI
Software that uses CAICheck a score

VinoStudio/auth_service

56.3

Adequate · 20 September 2026

22.8k

lines of production code

Python

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an authentication and authorization service built on a CQRS architecture, managing user identities, roles, and permissions through a domain-driven design. It provides role-based access control with JWT validation, OAuth integration, and session management, backed by an asynchronous SQLAlchemy database and Kafka messaging. The infrastructure includes a containerized observability stack for monitoring and a comprehensive test suite covering domain logic, application handlers, and infrastructure components.

Features

Added Grafana, Prometheus, Loki, and Alloy observability stack

This change introduces a complete containerized observability stack for monitoring the application. It adds Docker Compose configurations to run Grafana, Prometheus, Loki, and Grafana Alloy as services. Alloy is configured to discover Docker containers and scrape metrics, while also tailing local logs and forwarding them to Loki. Prometheus is set up to scrape metrics from the application and Alloy. Grafana is provisioned with datasources for both Prometheus and Loki, and includes a pre-built dashboard for visualizing Litestar application metrics such as total requests and request counts by path.

observation · high confidence

Application layer CQRS foundation and RBAC command handlers

The application layer now implements a CQRS architecture with dedicated command and query mediators, providing the core infrastructure for handling user, role, and permission operations. This includes a new RBAC system with command handlers for creating, updating, and deleting roles and permissions, all protected by a new \authorization\_required\ decorator that validates JWT tokens and injects security context. The change also introduces base abstractions for event sourcing, session management, and security (JWT/cookies), wiring these components via dependency injection to support the new access control and user management workflows.

src/application, src/presentation · high confidence

Initial domain model for authentication, authorization, and user management

This change introduces the core domain entities and value objects required for user authentication and role-based access control. It defines the User aggregate, which manages roles, sessions, and OAuth accounts, alongside dedicated entities for OAuthAccount, Role, Permission, and Session. The implementation includes a predefined permission catalog and system role hierarchy (e.g., Super Admin, System Admin) to support RBAC, along with base classes for entities and value objects to enforce validation and immutability.

src/domain · high confidence

Initial infrastructure layer for persistence, messaging, and logging

This change introduces the foundational infrastructure components for the application. It establishes an asynchronous SQLAlchemy database layer with Alembic migrations, defining core domain models for Users, Roles, Permissions, OAuth accounts, and Sessions. It also provides a Kafka-based message broker implementation (producer/consumer) for internal and external event handling, a structured logging configuration using Structlog, and a set of base repository interfaces and infrastructure-specific exceptions to support the domain and application layers.

src/infrastructure · high confidence

Test coverage

Added mock request and response utilities for testing; Added unit tests for JWT and RBAC services; Added unit tests for infrastructure database and repository layers; Initial test coverage for user domain and handlers; Initial test infrastructure and user validation test data.

Dependencies

Initial dependency configuration for auth-service

The project now includes a pyproject.toml file defining the initial set of dependencies for the auth-service. This configuration specifies a Python 3.12+ runtime and includes core libraries for the web framework (Litestar), data validation (Pydantic), database access (SQLAlchemy, asyncpg, Alembic), authentication (python-jose, bcrypt), and background task processing (Celery, Redis). It also adds development and tooling dependencies such as Ruff, Black, MyPy, and Pytest.

(dependencies) · high confidence

Housekeeping

Added empty src package initialization

An empty \_\init\\_.py file was added to the src directory, initializing it as a Python package. This change has no functional impact on the product.

src · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 56 (-1.7)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-0.3)
  • Architecture 100 → 79 (-20.7)
  • Maturity 75 → 75 (+0.0)
  • Readiness 27 → 29 (+2.9)
  • Security 88 → 78 (-10.1)
  • Domain Modelling 100 → 100 (-0.0)

Resolved (17)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (11 lines × 2) (src/infrastructure/repositories/converters.py)
  • Duplicated block (12 lines × 2) (src/infrastructure/repositories/converters.py)
  • Duplicated block (13 lines × 2) (src/application/services/tasks/email_templates.py)
  • Duplicated block (14 lines × 2) (src/application/cqrs/user/commands/register_oauth_user.py)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No exposed public API
  • Rotate the exposed credentials — git history can't be un-committed
  • Secret: generic-api-key (src/presentation/api/v1/base_responses.py)
  • Test reliability not included
  • The 'Accessing Services' section lists HTTP endpoints but does not show how to access each service (e.g., auth-api, grafana, alloy) directly from a browser or curl. (README.md)
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient

New (95)

  • Critical CVE: [GHSA redacted] (uv.lock)
  • Critical CVE: [GHSA redacted] (uv.lock)
  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Duplicated block (10–11 lines × 2) (src/infrastructure/repositories/converters.py)
  • Duplicated block (12–13 lines × 5) (src/infrastructure/db/migrations/versions/20250515-154426_a5a0703734e0_database_initialization.py)
  • Duplicated block (14 lines × 2) (src/application/services/tasks/email_templates.py)
  • Duplicated block (16 lines × 2) (src/infrastructure/repositories/converters.py)
  • Duplicated block (18 lines × 2) (src/application/cqrs/user/commands/register_oauth_user.py)
  • Duplicated block (18–19 lines × 2) (src/infrastructure/db/migrations/versions/20250515-154426_a5a0703734e0_database_initialization.py)
  • Duplicated block (18–20 lines × 2) (src/infrastructure/db/migrations/versions/20250515-154426_a5a0703734e0_database_initialization.py)
  • Duplicated block (19 lines × 2) (src/application/exceptions/oauth.py)
  • Duplicated block (5 lines × 2) (src/infrastructure/db/migrations/versions/20250515-154426_a5a0703734e0_database_initialization.py)
  • Duplicated block (5 lines × 2) (src/infrastructure/db/migrations/versions/20250515-154426_a5a0703734e0_database_initialization.py)
  • Duplicated block (7 lines × 2) (src/infrastructure/repositories/role/role_repo.py)
  • Duplicated block (7–9 lines × 2) (src/infrastructure/db/migrations/versions/20250515-154426_a5a0703734e0_database_initialization.py)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • …and 75 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

VinoStudio/auth_service was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ba912fdcc1be48244580ec6a8b94280ec21e3899 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.