finds.dev← search

// the find

luizomf/clean-architecture-api-boilerplate

★ 254 · TypeScript · MIT · updated Jan 2021

A boilerplate for creating TypeScript APIs following the Clean Architecture principles.

A TypeScript and Express starter that lays out a Clean Architecture folder structure (domain, application, presentation, infrastructure, main) with user CRUD, sign-in, and refresh tokens already wired up. It suits someone who wants a worked example of keeping use cases independent of HTTP and the database, not a production auth service to build on as-is.

Password hashing and JWT signing sit behind interfaces in application/ports/security with bcrypt and JWT adapters in common/adapters, and the repositories are ports with knex implementations under infrastructure, so the database or the crypto library can change without touching use cases. Refresh tokens live in their own table behind a token repository with find-by-token and delete-by-user-id ports, so they can be revoked rather than being purely stateless. Most units have a colocated spec file, including use cases, controllers, validation composites and the security adapters, which makes each layer testable on its own. ESLint, Prettier, husky and lint-staged are configured from the start.

The last push was January 2021, more than five years before today, and the README still calls the project under development with authentication as the goal, so the dependency versions and lockfile are from that era and will need an upgrade before anything else. The indirection is heavy for a three-route API: one feature like create-user spans a use-case interface in domain, its implementation in application, a validation composite with leaves, a controller, a factory in main and a route, and much of the middle is pass-through. Route tests cover only sign-in and users; there is no test file for the refresh-token route or the rate-limit middleware, which sit closest to the auth edge where bugs cost the most. The README says nothing about token expiry, refresh rotation, secret management or sign-out, which are the parts that usually go wrong when a boilerplate is copied into production.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →