youssefbennour/AspNetCore.Starter
44.0
Weak · 21 September 2026
2.5k
lines of production code
C#
primary language
4
measurements over time
What this system is
This system is a production-ready .NET 9 modular monolith starter template designed for building scalable backend services. It provides a complete infrastructure including a BFF layer with OIDC authentication, a shared common library for error handling and validation, and a Docker-based development environment with observability tools. The codebase demonstrates practical implementations of contracts, passes, and offers, supported by comprehensive unit and integration tests.
Features
Add BFF authentication and authorization
The BFF (Backend for Frontend) layer now includes a new authentication and authorization module. This adds OpenID Connect (OIDC) support, configuring cookie-based sessions and an authorization policy that requires users to be authenticated. The implementation reads OIDC settings (such as client ID, secret, and scopes) from configuration and environment variables, and registers the necessary middleware to handle authentication and authorization flows.
src/Starter.BFF/Auth · high confidence
Add Contracts module with full CRUD and event bus support
Users can now create, sign, and retrieve contracts through new API endpoints. The Contracts module includes a database schema with automatic migrations, business rule validation (e.g., age and height limits), and an event bus with outbox pattern for eventual consistency. The module also supports paginated retrieval of all contracts.
src/Starter · high confidence
Centralized common infrastructure extracted into Starter.Common library
The Starter.Common library has been extracted into a separate class library, consolidating shared infrastructure components. This includes a new API configuration module for setting up controllers, CORS, OpenAPI/Swagger, and API versioning. Authentication is centralized with a new AuthModule that configures JWT Bearer authentication and default authorization policies. A comprehensive error handling system is introduced, featuring a GlobalExceptionHandler, specific exception types (e.g., BadRequestException, NotFoundException), and standardized problem details. Additionally, the library now provides utilities for pagination, search, and business rule validation, alongside an implementation of the transactional outbox pattern for eventual consistency.
src/Starter.Common · high confidence
Initial release of the .NET Modular Monolith Starter template
The repository now provides a complete, production-ready starter template for building modular monolith applications using .NET 9. The project includes a Backend-For-Frontend (BFF) implementation with Keycloak authentication, along with a Docker Compose setup that orchestrates the application services, PostgreSQL, and observability tools including OpenTelemetry, Jaeger, Prometheus, Grafana, and Loki. The solution also features a shared common library, unit and integration tests, and comprehensive documentation for local development and API access.
(repo-wide) · high confidence
Test coverage
Added integration tests for contract, pass, offer, and localization features; Added unit tests for contract business rules and request validation; Added unit tests for the Business Rules Engine; Added unit tests for the global exception handler.
Dependencies
Upgrade to .NET 9 and update test dependencies
The application and its test projects have been upgraded to .NET 9. Additionally, test dependencies have been updated, including xUnit to 2.9.2, Microsoft.NET.Test.Sdk to 17.12.0, and the addition of NSubstitute, Bogus, FluentAssertions, and Testcontainers.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 56 → 44 (-11.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 98 → 97 (-1.5)
- Architecture 77 → 77 (+0.0)
- Maturity 75 → 75 (+0.0)
- Readiness 38 → 17 (-21.2)
- Security 71 → 62 (-9.4)
- Event-Driven 66 → 66 (+0.0)
Resolved (21)
- BarePragmaDisable (src/Starter/Program.cs)
- Duplicated block (9 lines × 3) (src/Starter/Contracts/EventBus/Persistent/ContractsOutboxWorker.cs)
- Medium IaC: CKV_DOCKER_3 (src/Starter.BFF/Dockerfile)
- Medium IaC: CKV_DOCKER_3 (src/Starter/Dockerfile)
- Medium IaC: CKV_DOCKER_7 (src/Starter/Dockerfile)
- Medium IaC: CKV_SECRET_6 (src/Starter.BFF/appsettings.Development.json)
- Medium IaC: CKV_SECRET_6 (src/Starter.BFF/appsettings.json)
- Medium IaC: CKV_SECRET_6 (src/Starter.BFF/bin/Debug/net9.0/appsettings.Development.json)
- Medium IaC: CKV_SECRET_6 (src/Starter.BFF/bin/Debug/net9.0/appsettings.json)
- No context/problem and no consequences for not recording decisions (e.g. lost or duplicated work) are stated (docs/ArchitectureDecisionLog/0001-record-architecture-decisions.adoc)
- No exposed public API
- Secret: generic-api-key (Configs/keycloak/sample-realm.json)
- Secret: generic-api-key (src/Starter.BFF/appsettings.Development.json)
- Secret: generic-api-key (src/Starter.BFF/appsettings.Development.json)
- Secret: generic-api-key (src/Starter.BFF/appsettings.Development.json)
- Secret: generic-api-key (src/Starter.BFF/appsettings.json)
- Secret: generic-api-key (src/Starter.BFF/appsettings.json)
- Secret: generic-api-key (src/Starter.BFF/appsettings.json)
- The Getting Started section omits a prerequisite for Keycloak authentication, which is critical to local development and appears in the Local Development Guide link. (README.adoc)
- dormant codebase — no living knowledge left to concentrate
- …and 1 more
New (91)
- Banned license: MySql.Data.OpenTelemetry
- BlanketAnalyzerSeverityNone (.editorconfig)
- Context is a single option list with no rationale and consequences omit trade-offs (server-side cost vs client-side responsiveness) (docs/ArchitectureDecisionLog/0013-use-backend-localization.adoc)
- Documentation: no installation or build instructions (README.adoc)
- Documentation: no usage examples (README.adoc)
- Duplicated block (10 lines × 3) (src/Starter/Contracts/EventBus/Persistent/ContractsOutboxWorker.cs)
- End-of-life runtime: .NET net9.0
- FileScopedPragmaDisable (src/Starter/Program.cs)
- High secret: WD-SECRET-0002 (Configs/keycloak/sample-realm.json)
- High secret: WD-SECRET-0002 (src/Starter.BFF/appsettings.Development.json)
- High secret: WD-SECRET-0002 (src/Starter.BFF/appsettings.json)
- Leaked secret: high-entropy-secret (Configs/keycloak/sample-realm.json)
- Leaked secret: signing-key (src/Starter.BFF/appsettings.json)
- Low coverage: src/Starter.Common/ApiConfiguration/ApiConfigurationModule.cs (src/Starter.Common/ApiConfiguration/ApiConfigurationModule.cs)
- Low coverage: src/Starter.Common/ApiConfiguration/ApiVersioningConfiguration.cs (src/Starter.Common/ApiConfiguration/ApiVersioningConfiguration.cs)
- Low coverage: src/Starter.Common/ApiConfiguration/Cors/CorsExtensions.cs (src/Starter.Common/ApiConfiguration/Cors/CorsExtensions.cs)
- Low coverage: src/Starter.Common/ApiConfiguration/OpenApiConfiguration.cs (src/Starter.Common/ApiConfiguration/OpenApiConfiguration.cs)
- Low coverage: src/Starter.Common/Auth/AuthModule.cs (src/Starter.Common/Auth/AuthModule.cs)
- Low coverage: src/Starter.Common/Auth/JwtBearer/JwtAuthenticationModule.cs (src/Starter.Common/Auth/JwtBearer/JwtAuthenticationModule.cs)
- Low coverage: src/Starter.Common/Auth/JwtBearer/JwtOptions.cs (src/Starter.Common/Auth/JwtBearer/JwtOptions.cs)
- …and 71 more
API surface
- Unchanged — 2 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
youssefbennour/AspNetCore.Starter was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 784d23eda909cbb27a439e571a90d9260e1a0a59 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.