wiringbits/scala-webapp-template
53.8
Weak · 20 September 2026
5.8k
lines of production code
Scala
primary language
1
measurement over time
What this system is
This system is a reusable web application template built with Scala, Scala.js, and React, designed to provide a complete foundation for user-centric web services. It implements core identity management features, including user registration, authentication, email verification, and password recovery, backed by a PostgreSQL database and asynchronous background job processing. The architecture separates a Play Framework-based API server from a Scala.js frontend, offering typed validation, secure session handling, and administrative tools for user oversight.
How it got here
2021 — Initial project scaffolding and core infrastructure
17 changes.
This period established the foundational architecture of the Wiringbits Scala/Scala.js web application template, defining the project structure, build tooling, and deployment configurations. It implemented the core backend services for user authentication, account management, and background job processing using Play Framework and Pekko. The work also included the initial frontend skeleton and comprehensive integration tests to validate the new system.
2022–2026 — Authentication and background job infrastructure
20 changes.
This period focused on building the core backend infrastructure for user authentication, including email verification, password reset, and secure token management. It introduced typed domain models for validation, implemented background job processing for asynchronous tasks like email delivery, and established the corresponding API endpoints and UI components to support these flows.
Features
Admin service implementation for user logs and user listing
The AdminService has been introduced to handle administrative requests for retrieving user logs and listing users. It leverages the Chimney library to automatically map repository entities to API response models (AdminGetUserLogs and AdminGetUsers), reducing boilerplate conversion code. This service acts as the backend logic layer, fetching data from the UserLogsRepository and UsersRepository and transforming it into the structured responses expected by the API.
server/src/main/scala/net/wiringbits/services · high confidence
Initial API endpoint definitions for authentication, user management, and administration
This change introduces the core API endpoint definitions for the application, establishing the contract for client interactions. It includes authentication routes for logging in, logging out, and retrieving the current user profile; user management endpoints for account creation, email verification, password reset, and profile updates; and administrative endpoints for listing users and viewing user logs. Additionally, it provides a health check endpoint and an environment configuration endpoint to expose necessary settings to the frontend. These definitions are built using sttp-tapir and include shared utilities for error handling, session management, and admin authentication.
lib/api/shared/src/main/scala/net/wiringbits/api/endpoints · high confidence
Initial Nginx and server deployment configuration
This change introduces the foundational infrastructure configuration for deploying the application. It adds Nginx templates to serve the web and admin interfaces, including SSL termination via Let's Encrypt, basic authentication for admin routes, and proxying for API and Swagger endpoints. It also includes the main Nginx configuration, MIME types, and a systemd service file to manage the application server process, alongside a development environment template for database and application secrets.
infra/config · high confidence
Initial build scripts for admin, server, and web components
Added shell scripts (build-admin.sh, build-server.sh, build-web.sh) to automate the build and packaging process for the admin, server, and web applications. These scripts handle environment variable configuration (such as API\_URL and SWAGGER\_API\_BASEPATH), invoke sbt to build the respective modules, and package the outputs into zip files within the apps directory.
infra/scripts · high confidence
Initial database schema for user management and background jobs
The application now includes its initial database schema, introducing tables for user accounts (users), activity tracking (user\_logs), and verification tokens (user\_tokens). It also establishes a system for handling asynchronous tasks via a background\_jobs table and a user\_notifications table to queue email delivery, providing the foundational data structures required for user registration, authentication, and background processing.
server/src/main/resources/evolutions · high confidence
Initial implementation of background job processing and user authentication actions
This change introduces the core server-side logic for user account management and asynchronous task execution. It adds a suite of new action classes under \server/src/main/scala/net/wiringbits/actions\ to handle user lifecycle events, including registration (\CreateUserAction\), login (\LoginAction\), password management (\ForgotPasswordAction\, \ResetPasswordAction\, \UpdatePasswordAction\), and email verification (\VerifyUserEmailAction\, \SendEmailVerificationTokenAction\). Additionally, it implements the infrastructure for background job processing, featuring a \StreamPendingBackgroundJobsForeverAction\ to continuously fetch pending jobs and a \BackgroundJobsExecutorTask\ that executes these jobs (currently supporting email sending) with retry logic and throttling.
server/src/main/scala/net/wiringbits/actions · high confidence
Initial implementation of data access objects for core domain entities
This change introduces the foundational repository layer for the application, adding new DAOs to manage persistence for Users, User Logs, User Tokens, and Background Jobs. The implementation provides specific capabilities for user management (creation, lookup, name updates, verification, and password resets), token handling for authentication flows, logging of user activities, and a streaming interface to fetch and process pending background jobs from the database.
server/src/main/scala/net/wiringbits/repositories/daos · high confidence
Initial implementation of user and background job data models
This change introduces the core data models for the application's user management and background job systems. It adds \User\ and \UserLog\ models to handle user profiles, authentication credentials, and activity logging, alongside \UserToken\ and \UserTokenType\ to support email verification and password reset workflows. Additionally, \BackgroundJobData\ is added to define the structure for scheduled and executed background tasks, including their status, payload, and execution timestamps.
server/src/main/scala/net/wiringbits/repositories/models · high confidence
Initial release of the Wiringbits Scala/Scala.js web application template
This commit introduces the initial skeleton for a reusable web application template built with Scala, Scala.js, and React. It establishes the foundational configuration and tooling, including a \.gitignore\ for IDE and build artifacts, \.nvmrc\ and \.sdkmanrc\ to pin Node.js (v24) and Java (v25) versions, and \.scalafmt.conf\ to enforce Scala 3 code formatting. It also provides a \custom.webpack.config.js\ that patches OpenSSL compatibility issues for Node 18+ and configures a development proxy to forward API requests to a local server while handling cookie domains. The entry includes a \README.md\ documenting the template's features, such as user authentication, PostgreSQL integration, and CI workflows, along with demo links.
(repo-wide) · high confidence
Initial release of the Wiringbits web application template
This change introduces the complete frontend skeleton for the Wiringbits web application, built with Scala.js and React (via Slinky). It provides a fully functional single-page application featuring user authentication (sign-in, sign-up, email verification, password reset), a user profile management section (editing name and password), and a dashboard. The app includes a responsive Material UI-based layout with an app bar, footer, and routing, along with internationalization support and a landing page describing the template's features.
web/src/main · high confidence
Initial server configuration and routing skeleton
This change introduces the foundational configuration files for the Play Framework server, including application.conf, logback.xml, messages, and routes. It establishes the default settings for database connectivity (PostgreSQL), session management, CORS filtering, and logging, while defining the primary API routing entry point at the root path.
server/src/main/resources · high confidence
Initial server module wiring and configuration setup
The server application now initializes its core infrastructure through a new set of Guice modules in the \modules\ package. This includes \ConfigModule\ to load and log settings for email, AWS, ReCaptcha, Swagger, and background jobs; \ApisModule\ to dynamically select the email provider (AWS or local logging); \ExecutorsModule\ to configure the database execution context; \TasksModule\ to register the background jobs executor; \ClockModule\ to provide a UTC clock; and \ApisModule\ to wire up the email API. This establishes the foundational dependency injection structure required for the application's email, background task, and configuration capabilities.
server/src/main/scala/net/wiringbits/modules · high confidence
Introduction of background job models and secret value wrappers
The models package now includes foundational types for a new background job system, defining \BackgroundJobPayload\ (currently supporting \SendEmail\), \BackgroundJobStatus\ (Pending, Success, Failed), and \BackgroundJobType\ (SendEmail). Additionally, new case classes for AWS credentials (\AWSAccessKeyId\, \AWSSecretAccessKey\) and ReCaptcha keys (\ReCaptchaSiteKey\, \ReCaptchaSecret\) have been added, all extending a new \SecretValue\ abstract class that masks the underlying string in \toString\ output to prevent accidental logging of sensitive data.
server/src/main/scala/net/wiringbits/models · high confidence
Introduction of dedicated configuration models for AWS, email, ReCaptcha, and user tokens
The server now includes a set of new configuration case classes in the \net.wiringbits.config\ package to structure environment-specific settings. These include \AWSConfig\ for AWS credentials and region, \EmailConfig\ for sender details and provider, \ReCaptchaConfig\ for security keys, \UserTokensConfig\ for managing expiration times and HMAC secrets for email verification and password resets, \BackgroundJobsExecutorConfig\ for job scheduling intervals, \SwaggerConfig\ for API documentation metadata, and \WebAppConfig\ for the application host. These models replace ad-hoc configuration access with typed, validated configuration objects, enabling better support for AWS integration, reCAPTCHA verification, and token-based security flows.
server/src/main/scala/net/wiringbits/config · high confidence
Introduction of email sending and reCAPTCHA verification APIs
This change introduces new API abstractions and implementations for email delivery and bot protection. The EmailApi trait and its AWS SES-based implementation (EmailApiAWSImpl) enable sending HTML and text emails via Amazon Simple Email Service, while a new ReCaptchaApi provides verification against Google's reCAPTCHA service. These components are supported by the new EmailRequest model, establishing the backend infrastructure for secure user registration and communication flows.
server/src/main/scala/net/wiringbits/apis · high confidence
Introduction of typed, validated input components
The UI library now includes a new \ValidatedTextInput\ component that integrates with the project's form field system to provide automatic validation for text inputs. This change introduces specific input components for Name, Email, and Password fields, which leverage the new \TextValidator\ mechanism to display validation errors and manage input state directly within the UI layer.
lib/ui · high confidence
New email verification and password reset infrastructure
The server now includes a complete utility layer to support email-based account verification and password recovery flows. This introduces an \EmailsHelper\ that generates HMAC-SHA1 signed tokens for security, sends verification and password-reset emails via the \EmailApi\, and manages token storage in the \UserTokensRepository\. Supporting this are new models and utilities: \EmailMessage\ defines the HTML content for registration, confirmation, and password reset emails (with HTML escaping for user data), \TokenGenerator\ creates unique identifiers, \TokensHelper\ handles the cryptographic signing and validation, \StringUtils\ provides data masking for logs, and \DelayGenerator\ offers retry delay calculations. This change enables the backend to securely issue and validate email tokens required for the new forgot/reset password and registration confirmation endpoints.
server/src/main/scala/net/wiringbits/util · high confidence
New validation components for user authentication and security
The server now includes dedicated validation components to enforce security and integrity checks during user operations. These include verifying reCAPTCHA responses, ensuring email availability or registration status, validating password matches using bcrypt, checking user verification status, and validating the expiration of user tokens. These components provide a consistent way to handle common authentication and user management validations across the application.
server/src/main/scala/net/wiringbits/validations · high confidence
User account management and background job infrastructure
This change introduces the core repository layer for user account lifecycle management and background job processing. Users can now have their accounts created, updated, and verified, with password reset capabilities that trigger asynchronous email notifications via a new background job system. The implementation includes dedicated repositories for managing user tokens (for email verification), user activity logs, and background jobs, all wired to a dedicated database execution context to ensure non-blocking database operations.
server/src/main/scala/net/wiringbits/repositories · high confidence
Behavioural changes
API request and response models are split into dedicated files with Tapir schema support
The API models in the shared library have been reorganized so that each request and response type (such as Login, CreateUser, and AdminGetUsers) is defined in its own file. These models now include explicit Play JSON formats and Tapir Schema definitions, enabling automatic serialization and structured API documentation generation.
lib/api/shared/src/main/scala/net/wiringbits/api/models · high confidence
Initial release of Play/Pekko/Tapir-based API controllers
The server's controller layer has been rewritten from scratch to use Play Framework 3, Pekko, and Tapir, replacing the previous implementation. This change introduces new controllers (Admin, Auth, EnvironmentConfig, Health, Users) that expose endpoints for user management, authentication, and system health. Key behavioral updates include session management via Play cookies (handled by PlayTapirBridge), email masking in admin user logs, and a unified error handling strategy that returns generic ErrorResponse objects for failures. The ApiRouter now aggregates these new Tapir endpoints and integrates Swagger documentation.
server/src/main/scala/controllers · high confidence
Introduction of typed domain models for user input validation
The shared models library now includes strongly-typed wrappers for Captcha, Email, Name, Password, and UserToken. These new classes enforce specific validation rules at the model level: Captcha requires a non-empty string, Email is validated against a standard regex pattern, Name must be at least two characters long, Password requires a minimum length of eight characters, and UserToken is parsed from a UUID-based string format. This change shifts validation logic from generic strings to specific types, ensuring data integrity for user registration and authentication flows.
lib/common/shared/src/main/scala/net/wiringbits/common/models · high confidence
New API client with cookie-based session handling and date formatting utility
The API client library has been replaced with a new implementation that manages authentication state by persisting session cookies from login responses and automatically attaching them to subsequent requests, ensuring seamless user sessions for non-browser clients. This client exposes endpoints for user management (creation, verification, updates), authentication (login, logout, password reset), and administrative functions (user logs, user listing), along with environment configuration retrieval. Additionally, a new utility has been added to format date-time values into a localized string representation for display purposes.
lib/api/shared/src/main/scala/net/wiringbits/api · high confidence
New error message for unverified email addresses
A new error message constant has been added to the common library to inform users when their email address has not been verified, specifically suggesting they check their spam folder if the verification email is missing.
lib/common/shared/src/main/scala/net/wiringbits/common · high confidence
Fixes
Added automated health check script for the dev-web server
A new shell script (scripts/test-dev-web.sh) has been added to automate the validation of the local development web server. This script starts the sbt dev-web task, waits for the webpack-dev-server to become ready, and then performs specific health checks: it verifies that the root URL returns an HTTP 200 status, confirms the response body contains the expected application bundle reference, and ensures the JavaScript bundle itself is accessible without 404 errors. This provides a robust, automated way to verify that the dev environment is functioning correctly before proceeding with further development tasks.
scripts · high confidence
Test coverage
Added controller integration tests for authentication, user management, and admin features; Added repository tests for background jobs, user logs, user tokens, and users; Added test infrastructure for API and database testing; Added test infrastructure for repository integration tests; Added test utility for secure random number generation; Added test utility helpers for execution contexts, login flows, and repository data creation; Added tests for ReCaptcha API verification; Added tests for SecureRandom in lib/common/js; Added unit tests for DelayGenerator and TokensHelper utilities; Added unit tests for authentication and user management form data validation; Added validation tests for email, name, password, and user token models.
Dependencies
Upgrade to Scala 3.8.3, Play 3.0.11, and Pekko
The build configuration has been updated to use Scala 3.8.3 and migrate the server runtime from Akka to Pekko (version 1.6.0). The Play framework has been upgraded to version 3.0.11, with Play JSON set to 3.0.6. Additionally, several core libraries have been bumped, including sttp to 3.11.0, anorm to 3.0.0, enumeratum to 1.9.7, tapir to 1.13.19, and chimney to 1.10.0, while the web dependencies now use React 18.2.0 and slinky-hot 0.7.5.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 54.
Lenses
- Code Health 96
- Architecture 60
- Maturity 64
- Readiness 41
- Security 68
- Accessibility 74
Changes since last survey
- 300 commits — 279 feature/other, 21 fixes
By area
- (root) — 144 commits
- server/src — 47 commits
- project/plugins.sbt — 33 commits
- web/src — 30 commits
- lib/api — 10 commits
- .github/workflows — 6 commits
- project/build.properties — 6 commits
- docs/assets — 3 commits
- infra/config — 3 commits
- admin/src — 2 commits
- lib/common — 2 commits
- lib/ui — 2 commits
- tapir/core — 2 commits
- (repo) — 1 commit
- docs/README.md — 1 commit
- docs/architecture.md — 1 commit
- docs/design-decisions.md — 1 commit
- docs/design-docs.md — 1 commit
- docs/postgres.md — 1 commit
- docs/setup-dev-environment.md — 1 commit
Notable commits
- fix: Fix ReCaptcha tests (#108)
- fix: Fix api client (#408)
- fix: Fix build.sbt (#277)
- fix: Fix captcha not being necessary to sign in or sign up (#209)
- fix: Fix compile error
- fix: Fix compile warning
- fix: Fix compile warnings on the sjs swagger annotations (#248)
- fix: Fix deployment scripts
- fix: Fix dev-web 404 and strengthen CI content check (#442)
- fix: Fix sbt dev-web on Node 24 / webpack 5 (#440)
- fix: Fix scalafmt
- fix: Fix server tests
- fix: Fix tests
- fix: Fix token parser match exhaustive error (#398)
- fix: Fix warning
- fix: Let's fix the ApiClient so that it works with cookie authentication in tests (#274)
- fix: More fixes to the swagger integration
- fix: Revert "Update sbt-scalajs-bundler to 0.21.1 (#312)"
- fix: Update webapp-utils and admin fixed dependencies (#273)
- fix: Use ReactDOMClient.createRoot to fix React 18 warning (#444)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
wiringbits/scala-webapp-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 652db5be0b6b736981ca2efd91d1f6407e225be3 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.