Files
git.stella-ops.org/docs/implplan-blocked/audits/csproj-standards/VexHub/StellaOps.VexHub.WebService/StellaOps.VexHub.WebService.md

1.5 KiB

Audit - StellaOps.VexHub.WebService

Project

  • Path: src/VexHub/StellaOps.VexHub.WebService/StellaOps.VexHub.WebService.csproj
  • Module: VexHub
  • Kind: WebService
  • SDK: Microsoft.NET.Sdk.Web
  • TargetFramework: net10.0
  • Audit date (UTC): 2026-01-30

Coding Standards Findings

  • Status: FAIL
  • Nullable: enable
  • TreatWarningsAsErrors: explicit true
  • Deterministic: inherited true
  • 100-line rule violations: 3
  • Service locator usage (BuildServiceProvider/GetService): 0
  • Analyzer enforcement: missing repo-wide (see summary).

Details

  • 100-line files:
    • src/VexHub/StellaOps.VexHub.WebService/Extensions/VexHubEndpointExtensions.cs (272 lines)
    • src/VexHub/StellaOps.VexHub.WebService/Middleware/RateLimitingMiddleware.cs (232 lines)
    • src/VexHub/StellaOps.VexHub.WebService/Middleware/ApiKeyAuthenticationHandler.cs (135 lines)
  • Service locator matches:
    • none

Fix Guidance

  • Split files over 100 lines into smaller types or partials.

Testing Fullness Findings

  • Status: FAIL
  • Expected layers: Unit, Integration, Security, Offline
  • Detected test projects: src/VexHub/__Tests/StellaOps.VexHub.WebService.Tests/StellaOps.VexHub.WebService.Tests.csproj [Unit]
  • Missing layers: Integration, Security, Offline

Manual checks required

  • Observability contract tests for WebService/Worker.
  • Offline execution (tests must run without network access).

Fix Guidance

  • Add integration tests for cross-component flows.
  • Add security tests for authn/authz or input validation.
  • Add offline/airgap coverage with fixtures only.