Skip to content

refactor packages architecture - #158

Merged
pramodnarayana merged 1 commit into
developmentfrom
refactor/packages-architecture
Jun 12, 2026
Merged

pramodnarayana merged 1 commit into
developmentfrom
refactor/packages-architecture

Conversation

@pramodnarayana

@pramodnarayana pramodnarayana commented Jun 12, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

Release Notes

  • Refactoring

    • Consolidated encryption service abstraction across the codebase for improved modularity.
    • Reorganized internal domain imports for better code maintainability.
  • Removals

    • Removed Transportation Management System (TMS) domain package and associated functionality.
    • Deprecated domain-core package; functionality migrated to local modules.

@coderabbitai

coderabbitai Bot commented Jun 12, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR restructures encryption service delivery and consolidates domain packages. The @soopa/infra package is renamed to @soopa/security and exported as an abstract encryption interface. Concrete encryption implementations are removed from @soopa/credentials, and all consumers migrate to dependency-injected IEncryptionService via NestJS tokens. The @soopa/domain-core and @soopa/domain-tms packages are deleted, with domain types inlined into the pipeline module.

Changes

Encryption Service Abstraction and Domain Core Consolidation

Layer / File(s) Summary
Security package rename and dependencies
packages/security/package.json, packages/credentials/package.json, packages/pipeline/package.json
Package @soopa/infra is renamed to @soopa/security and added as a workspace dependency to credentials and pipeline packages.
Credentials package encryption cleanup
packages/credentials/src/index.ts
Public API comment updated to indicate crypto utilities moved to @soopa/security, and re-exports for encryption.interface.js and encryption.service.js removed.
Token management service injection
packages/credentials/src/oauth/token-manager.service.ts, packages/credentials/src/oauth/token-manager.service.spec.ts, packages/credentials/src/oauth/token-refresh.service.ts, packages/credentials/src/oauth/token-refresh.service.spec.ts
TokenManagerService and BaseOAuthRefreshClient now inject IEncryptionService via ENCRYPTION_SERVICE token from @soopa/security instead of importing concrete EncryptionService; test mocks updated to match.
API connections module encryption wiring
apps/api/package.json, apps/api/src/modules/connections/connections.module.ts, apps/api/src/modules/connections/connections/credential.controller.ts
ConnectionsModule adds @soopa/security dependency and wires ENCRYPTION_SERVICE token instead of providing local EncryptionService → AesEncryptionService binding; CredentialController constructor uses @Inject(ENCRYPTION_SERVICE) decorator with IEncryptionService type.
API token refresh client
apps/api/src/modules/connections/connections/registry-token-refresh.service.ts, apps/api/src/modules/connections/connections/registry-token-refresh.service.spec.ts
RegistryOAuthRefreshClient constructor parameter switches to @Inject(ENCRYPTION_SERVICE) crypto: IEncryptionService; test mocks updated correspondingly.
API stitches module cleanup
apps/api/src/modules/stitches/stitches.module.ts
Removes local encryption provider binding { provide: EncryptionService, useClass: AesEncryptionService } from module since encryption is now externally provided.
Pipeline core module encryption wiring
packages/pipeline/src/pipeline-core.module.ts
Module imports IEncryptionService and ENCRYPTION_SERVICE from @soopa/security, removes the local EncryptionService provider, and updates TokenManagerService factory to receive crypto: IEncryptionService with inject: [ENCRYPTION_SERVICE].
Pipeline token refresh client
packages/pipeline/src/replication/registry-token-refresh.service.ts, packages/pipeline/src/replication/registry-token-refresh.service.integration.spec.ts
RegistryOAuthRefreshClient uses @Inject(ENCRYPTION_SERVICE) and IEncryptionService type; integration test provider configuration updated to mock via ENCRYPTION_SERVICE token.
Domain core package removal
apps/worker/package.json, packages/pipeline/package.json
Removes @soopa/domain-core and @soopa/domain-tms from workspace dependencies; pipeline adds @soopa/observability dependency.
Pipeline domain type import migration
packages/domain/tms/src/index.ts, packages/pipeline/src/delivery/delivery.service.ts, packages/pipeline/src/delivery/use-cases/claim-delivery.use-case.ts, packages/pipeline/src/replication/registry-replication.service.ts, packages/pipeline/src/replication/registry-replication.service.spec.ts, packages/pipeline/src/replication/replica.service.ts, packages/pipeline/src/replication/replica.service.spec.ts, packages/pipeline/src/shared/adapters/outbound-gateway.adapter.ts, packages/pipeline/src/shared/adapters/registry-replication.adapter.ts, packages/pipeline/src/shared/adapters/replica-state.adapter.ts
Domain types (IOutboundGatewayPort, DispatchResponse, IRegistryReplicationPort, IReplicaStatePort, etc.) are now imported from local ../shared/domain.js instead of @soopa/domain-core; TMS domain index removes re-exports.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~50 minutes

Possibly related PRs

  • pramodnarayana/nexiom#133: Directly updates the RegistryOAuthRefreshClient token-refresh service in the same file path with related encryption dependency injection changes.
  • pramodnarayana/nexiom#93: Introduces the encryption abstraction and ENCRYPTION_SERVICE DI token that this PR now adopts across all consumers.

Poem

🐰 The rabbit hops through encryption's refactored trail,
Old AesEncryptionService bids farewell,
IEncryptionService tokens now lead the way,
Domain core removed—simpler and sleek they say! ✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Title check ❓ Inconclusive The title 'refactor packages architecture' is vague and generic, using non-descriptive language that doesn't convey specific information about the primary changes in this substantial refactoring. Provide a more specific title that captures the main objective, such as 'Move encryption service to @soopa/security package' or 'Migrate encryption abstraction and remove unused domain packages'.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/packages-architecture

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install timed out. The project may have too many dependencies for the sandbox.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
packages/credentials/src/index.ts (1)

2-10: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update the entrypoint header to match the new public surface.

Line 5 still advertises @soopa/credentials as the encryption entrypoint, but Line 9 says the crypto utilities moved to @soopa/security. That top-level API comment is now misleading.

Proposed diff
- *   - `@soopa/credentials`           — runtime services (encryption, token manager)
+ *   - `@soopa/credentials`           — runtime services (token manager, OAuth refresh helpers)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/credentials/src/index.ts` around lines 2 - 10, Update the
top-of-file header comment in packages/credentials/src/index.ts so it accurately
reflects the public surface: remove or stop advertising encryption/crypto as
provided by `@soopa/credentials` and instead state that `@soopa/credentials` exposes
runtime services (e.g., token manager) while crypto utilities are provided by
`@soopa/security`; keep the mention of `@soopa/piece-framework` for
piece/action/trigger/auth/property definitions. Locate the header block in
index.ts and edit the entrypoints list and any descriptive lines referencing
encryption to reference `@soopa/security` for crypto and `@soopa/credentials` only
for runtime services.
apps/api/src/modules/connections/connections.module.ts (1)

54-77: ⚠️ Potential issue | 🔴 Critical

Fix ENCRYPTION_SERVICE wiring: register EncryptionModule.forRootAsync(...) at bootstrap

  • apps/api/src/modules/connections/connections.module.ts and packages/pipeline/src/pipeline-core.module.ts both inject ENCRYPTION_SERVICE into TokenManagerService, but neither module imports EncryptionModule.
  • apps/api/src/app/app.module.ts and apps/worker/src/app.module.ts also do not register EncryptionModule.forRootAsync(...).
  • ENCRYPTION_SERVICE is only provided by EncryptionModule.forRootAsync(...) in packages/security/src/encryption.module.ts; repo-wide it’s only referenced in docs/specs, so Nest will fail to resolve the token at startup.

Add/import EncryptionModule.forRootAsync(...) once in the API and worker app modules (or a shared global/infra module that’s actually imported) so ENCRYPTION_SERVICE exists in the DI graph.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/api/src/modules/connections/connections.module.ts` around lines 54 - 77,
TokenManagerService is injecting ENCRYPTION_SERVICE but no module registers that
provider; import and register EncryptionModule.forRootAsync(...) into the
application DI graph so ENCRYPTION_SERVICE is available. Update the top-level
application module(s) that bootstrap the API and worker (where
TokenManagerService is ultimately used) to import
EncryptionModule.forRootAsync(...) (or add a shared/global InfraModule that
imports EncryptionModule.forRootAsync(...) and then import that module into the
app modules) so the ENCRYPTION_SERVICE token is provided before
TokenManagerService is constructed.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/credentials/src/oauth/token-manager.service.ts`:
- Line 6: The import mixes a type and a value from `@soopa/security` which breaks
with verbatimModuleSyntax; change the combined import to a type-only import for
IEncryptionService and keep ENCRYPTION_SERVICE as a value import (e.g., use an
import type { IEncryptionService } for the interface and a regular import {
ENCRYPTION_SERVICE } for the token). Apply this change in
token-manager.service.ts and the other credentials OAuth files that import
IEncryptionService/ENCRYPTION_SERVICE so the type is erased at emit and the
runtime token remains a value import.

---

Outside diff comments:
In `@apps/api/src/modules/connections/connections.module.ts`:
- Around line 54-77: TokenManagerService is injecting ENCRYPTION_SERVICE but no
module registers that provider; import and register
EncryptionModule.forRootAsync(...) into the application DI graph so
ENCRYPTION_SERVICE is available. Update the top-level application module(s) that
bootstrap the API and worker (where TokenManagerService is ultimately used) to
import EncryptionModule.forRootAsync(...) (or add a shared/global InfraModule
that imports EncryptionModule.forRootAsync(...) and then import that module into
the app modules) so the ENCRYPTION_SERVICE token is provided before
TokenManagerService is constructed.

In `@packages/credentials/src/index.ts`:
- Around line 2-10: Update the top-of-file header comment in
packages/credentials/src/index.ts so it accurately reflects the public surface:
remove or stop advertising encryption/crypto as provided by `@soopa/credentials`
and instead state that `@soopa/credentials` exposes runtime services (e.g., token
manager) while crypto utilities are provided by `@soopa/security`; keep the
mention of `@soopa/piece-framework` for piece/action/trigger/auth/property
definitions. Locate the header block in index.ts and edit the entrypoints list
and any descriptive lines referencing encryption to reference `@soopa/security`
for crypto and `@soopa/credentials` only for runtime services.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 95953bfe-ca57-4574-8ee7-04488642bec2

📥 Commits

Reviewing files that changed from the base of the PR and between 7af3381 and 7f26c1d.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (64)
  • apps/api/package.json
  • apps/api/src/modules/connections/connections.module.ts
  • apps/api/src/modules/connections/connections/credential.controller.ts
  • apps/api/src/modules/connections/connections/registry-token-refresh.service.spec.ts
  • apps/api/src/modules/connections/connections/registry-token-refresh.service.ts
  • apps/api/src/modules/stitches/stitches.module.ts
  • apps/worker/package.json
  • packages/credentials/package.json
  • packages/credentials/src/crypto/encryption.interface.ts
  • packages/credentials/src/crypto/encryption.service.spec.ts
  • packages/credentials/src/crypto/encryption.service.ts
  • packages/credentials/src/index.ts
  • packages/credentials/src/oauth/token-manager.service.spec.ts
  • packages/credentials/src/oauth/token-manager.service.ts
  • packages/credentials/src/oauth/token-refresh.service.spec.ts
  • packages/credentials/src/oauth/token-refresh.service.ts
  • packages/domain/core/package.json
  • packages/domain/core/tsconfig.lib.json
  • packages/domain/core/vitest.config.ts
  • packages/domain/tms/package.json
  • packages/domain/tms/src/index.ts
  • packages/domain/tms/src/schema/tms-identifier-validator.ts
  • packages/domain/tms/src/schema/tms-provisioner.ts
  • packages/domain/tms/src/schema/tms-schema.ts
  • packages/domain/tms/src/tms-normalized-writer.ts
  • packages/domain/tms/src/tms-target-builder.ts
  • packages/domain/tms/tsconfig.json
  • packages/domain/tms/tsconfig.lib.json
  • packages/domain/tms/vitest.config.ts
  • packages/pipeline/package.json
  • packages/pipeline/src/delivery/delivery.service.ts
  • packages/pipeline/src/delivery/use-cases/claim-delivery.use-case.ts
  • packages/pipeline/src/pipeline-core.module.ts
  • packages/pipeline/src/replication/registry-replication.service.spec.ts
  • packages/pipeline/src/replication/registry-replication.service.ts
  • packages/pipeline/src/replication/registry-token-refresh.service.integration.spec.ts
  • packages/pipeline/src/replication/registry-token-refresh.service.ts
  • packages/pipeline/src/replication/replica.service.spec.ts
  • packages/pipeline/src/replication/replica.service.ts
  • packages/pipeline/src/shared/adapters/outbound-gateway.adapter.ts
  • packages/pipeline/src/shared/adapters/registry-replication.adapter.ts
  • packages/pipeline/src/shared/adapters/replica-state.adapter.ts
  • packages/pipeline/src/shared/domain.ts
  • packages/pipeline/src/shared/events/domain-events.ts
  • packages/pipeline/src/shared/logic/delivery-status.evaluator.spec.ts
  • packages/pipeline/src/shared/logic/delivery-status.evaluator.ts
  • packages/pipeline/src/shared/ports/outbound-gateway.port.ts
  • packages/pipeline/src/shared/ports/queue-publisher.port.ts
  • packages/pipeline/src/shared/ports/registry-replication.port.ts
  • packages/pipeline/src/shared/ports/replica-state.port.ts
  • packages/pipeline/src/shared/ports/state-store.port.ts
  • packages/security/eslint.config.mjs
  • packages/security/package.json
  • packages/security/src/adapters/aws-kms.adapter.ts
  • packages/security/src/adapters/local-crypto.adapter.ts
  • packages/security/src/aws-kms.adapter.spec.ts
  • packages/security/src/constants.ts
  • packages/security/src/encryption.module.spec.ts
  • packages/security/src/encryption.module.ts
  • packages/security/src/index.ts
  • packages/security/src/interfaces/encryption-service.interface.ts
  • packages/security/src/local-crypto.adapter.spec.ts
  • packages/security/tsconfig.json
  • packages/security/vitest.config.ts
💤 Files with no reviewable changes (18)
  • packages/credentials/src/crypto/encryption.interface.ts
  • packages/domain/tms/tsconfig.lib.json
  • packages/domain/core/package.json
  • packages/domain/core/vitest.config.ts
  • packages/credentials/src/crypto/encryption.service.ts
  • packages/credentials/src/crypto/encryption.service.spec.ts
  • packages/domain/tms/src/schema/tms-schema.ts
  • packages/domain/tms/src/tms-target-builder.ts
  • packages/domain/tms/src/index.ts
  • packages/domain/tms/src/schema/tms-identifier-validator.ts
  • packages/domain/tms/vitest.config.ts
  • apps/worker/package.json
  • packages/domain/core/tsconfig.lib.json
  • apps/api/src/modules/stitches/stitches.module.ts
  • packages/domain/tms/tsconfig.json
  • packages/domain/tms/package.json
  • packages/domain/tms/src/tms-normalized-writer.ts
  • packages/domain/tms/src/schema/tms-provisioner.ts

import type { DrizzleDb } from '@soopa/database';

import { EncryptionService } from '../crypto/encryption.interface.js';
import { IEncryptionService, ENCRYPTION_SERVICE } from '@soopa/security';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== TypeScript compiler flags that affect type-only imports =="
fd -HI '^tsconfig.*\.json$' -x sh -c '
  echo "--- $1"
  rg -n "\"(verbatimModuleSyntax|importsNotUsedAsValues|preserveValueImports)\"" "$1" || true
' sh {}

echo
echo "== Current IEncryptionService imports in the touched credentials files =="
rg -n 'import\s*\{[^}]*IEncryptionService[^}]*\}\s*from\s*["@'\'']`@soopa/security`["@'\'']' packages/credentials/src

echo
echo "== Security package exports for the DI token and interface =="
rg -n 'IEncryptionService|ENCRYPTION_SERVICE' packages/security/src

Repository: pramodnarayana/nexiom

Length of output: 4777


Use import type for IEncryptionService across the credentials OAuth files.

@soopa/security exports ENCRYPTION_SERVICE as a value, but IEncryptionService only as a type (packages/security/src/index.ts). With verbatimModuleSyntax: true enabled in apps/web/tsconfig*.json, these must be import type imports to avoid invalid value imports.

Proposed diff pattern
-import { IEncryptionService, ENCRYPTION_SERVICE } from '`@soopa/security`';
+import { ENCRYPTION_SERVICE } from '`@soopa/security`';
+import type { IEncryptionService } from '`@soopa/security`';
-import { IEncryptionService } from '`@soopa/security`';
+import type { IEncryptionService } from '`@soopa/security`';
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
import { IEncryptionService, ENCRYPTION_SERVICE } from '@soopa/security';
import { ENCRYPTION_SERVICE } from '`@soopa/security`';
import type { IEncryptionService } from '`@soopa/security`';
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/credentials/src/oauth/token-manager.service.ts` at line 6, The
import mixes a type and a value from `@soopa/security` which breaks with
verbatimModuleSyntax; change the combined import to a type-only import for
IEncryptionService and keep ENCRYPTION_SERVICE as a value import (e.g., use an
import type { IEncryptionService } for the interface and a regular import {
ENCRYPTION_SERVICE } for the token). Apply this change in
token-manager.service.ts and the other credentials OAuth files that import
IEncryptionService/ENCRYPTION_SERVICE so the type is erased at emit and the
runtime token remains a value import.

@pramodnarayana
pramodnarayana merged commit 6c0e7eb into development Jun 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant