tahamajs/IE / Projects /docs /MissingAPIs.md
tahamajs's picture
|
download
raw
8.08 kB

Based on a thorough review of the entire codebase, below is a complete list of files that are missing or incompletely implemented (stubs, placeholders, or otherwise not production‑ready).


1. Missing Controllers (No REST Endpoints)

File (Expected) Reason
GrantController.java GrantService exists, but no endpoints for grants.
PreprintController.java PreprintService exists, but no dedicated preprint controller.
ProvenanceController.java ProvenanceService exists, but no API for provenance events.
MediaController.java MediaService exists, but only UploadController handles basic file uploads; full CRUD missing.
WorkspacePanelController.java WorkspacePanelRepository exists, but only a stub in WorkspaceCompatController.
BroadcastChannelController.java / BroadcastPostController.java BroadcastPostRepository exists, but no endpoints for channels or posts.
EncryptionKeyController.java EncryptionKeyRepository exists, but no endpoints (probably internal).
PreKeyController.java PreKeyRepository exists – no endpoints.
SignedPreKeyController.java SignedPreKeyRepository exists – no endpoints.
GraphNodeController.java Graph nodes are managed via GapAnalysisController but not full CRUD.
GraphEdgeController.java Same as above.
CitationGraphController.java CitationGraphService exists, but no API for citation network.
TagFollowController.java TagFollowDTO exists, but no endpoints for following tags.
ToolStoreStateController.java ToolStoreStateRepository exists – no controller.

2. Incomplete / Stub Controllers

File Issue
WorkspaceCompatController.java Most methods return hardcoded mock data; not production.
AiCompatController.java Returns stub AI responses; no real AI integration.
DataHubController.java Many methods return empty lists or throw UnsupportedOperationException (e.g., search, getVersions).
AdminToolController.java Minimal – getAllToolsAdmin returns empty list.
BlogCategoryController.java Missing bulk operations, admin reorder, etc.
BlogCommentController.java Missing proper reply threading endpoints.
UserUtilityController.java Only handles writing goals; other utilities missing.

3. Missing or Placeholder Services

File Status / Issue
WebhookService.java Completely missing – referenced in WebhookController but not provided.
VoiceSettingsService.java Missing – VoiceSettingsController expects it, but only VoiceSettingsRepository exists.
BackupService.java Placeholder – writes empty JSON arrays ("[]"); no real backup logic.
ExportService.java Many methods return empty strings or mock CSV; no real export.
IntegrationService.java All external API integrations (Zotero, Mendeley, ORCID, GitHub) return mock data.

4. Missing Configuration & Resource Files

File Needed By
firewall.properties FirewallConfig – defines IP rules.
banned_keywords.txt FirewallConfig – list of banned words.
GeoLite2-Country.mmdb GeoIpResolver – MaxMind GeoIP database (not provided).
Email templates (e.g., welcome.html, reset-password.html) MailService – referenced but not in resources.
git.properties VersionController – optional, but missing.
maven.properties VersionController – optional, missing.

5. Missing DTOs (Used in Services/Controllers but Not Defined)

Missing DTO Referenced By
GrantDTO GrantService returns model directly; no DTO.
BroadcastChannelDTO No DTO for broadcast channels.
GraphNodeDTO / GraphEdgeDTO Models used directly in GapAnalysisController.
ToolDownloadDTO / ToolInstallationDTO No DTOs for tool downloads/installations.
PollOptionDTO Only PollDTO exists; options embedded.
ProtocolDTO / ProtocolStepDTO Models used directly in DataHubController.
ResearchObjectDTO Models used directly.
RecentItemDTO Models used directly.
WorkspacePanelDTO Only model exists.

6. Incomplete Repository Implementations

Repository Missing / Stub Methods
ArticleRepository search() does not handle tag filtering (commented out).
MessageRepository findByConversationId() returns empty list (not implemented).
CommentRepository Some methods rely on in‑memory filtering; no pagination in DB.
GroupService (not a repo, but service) Several methods return empty lists (e.g., searchMessages, getMediaForMessage).
ProjectService getUsernameFromId and getUserIdFromUsername are placeholders (hash‑based).
PeerReviewService All data stored in‑memory (ConcurrentHashMap), not persisted.
PollService Same – in‑memory only.

7. Inactive / Commented‑Out Components

File Issue
RedisConfig.java Entirely commented out → Redis not active.
OpenApiGenerator.java @Component commented out → OpenAPI docs not generated.
RateLimitFilter.java Exists but not applied consistently to all endpoints.
CsrfFilter.java Exists but not integrated with Spring Security; not enforced.

8. Missing Persistence & Infrastructure

Feature Status
Database migration scripts No Flyway/Liquibase. Only Database.init() creates tables (may fail on schema changes).
Tests No unit, integration, or end‑to‑end tests.
Frontend files HomeController returns view names (index, search-results) but no .html files provided.
Real backup & restore BackupService does not actually save/restore database or files.
Real WebSocket cross‑server messaging WebSocketManager includes Redis pub/sub, but Redis is disabled (config commented).

9. Security & Session Management Gaps

Issue Description
No Spring Security integration Home‑grown SessionManager and filters; no method‑level security (@PreAuthorize).
CSRF protection not fully applied CsrfFilter exists but not wired to all state‑changing endpoints.
Password hashing duplication Uses both BCrypt (at.favre.lib) and jBCrypt (org.mindrot) – potential conflict.
JWT utilities unused JwtUtil present but never used (session uses UUID tokens).

10. Missing External Dependencies (Not Declared)

Even though the code compiles with provided JARs, the following libraries are not listed in a pom.xml or build.gradle in the provided files:

  • com.openhtmltopdf:openhtmltopdf-core (PDF export)
  • org.apache.poi:poi-ooxml (Excel export)
  • org.apache.pdfbox:pdfbox (PDF thumbnail)
  • com.maxmind.geoip2:geoip2 (IP geolocation)
  • io.jsonwebtoken:jjwt-api (JWT – though unused)
  • com.warrenstrange:googleauth (TOTP – used in TwoFactorService)
  • org.java-websocket:Java-WebSocket (WebSocket server – used)
  • redis.clients:jedis (Redis – used in WebSocketManager)
  • org.thymeleaf:thymeleaf-spring5 (email templates)
  • at.favre.lib:bcrypt (password hashing)

Summary

The codebase is structurally complete for a prototype, but at least 30+ files are either missing, stubbed, or incomplete. The most critical missing pieces for production are:

  1. Real backup, export, and integration logic (currently mock).
  2. Missing controllers (Grant, Preprint, Provenance, Media, etc.).
  3. Missing services (WebhookService, VoiceSettingsService).
  4. Configuration files (firewall.properties, banned_keywords.txt, GeoIP database).
  5. Testing and database migration infrastructure.
  6. Spring Security integration with proper role‑based access control.

Xet Storage Details

Size:
8.08 kB
·
Xet hash:
8d3101082689958bec0cf55aa9e32297f4d167ba8a9bf6ecea1069051cd86399

Xet efficiently stores files, intelligently splitting them into unique chunks and accelerating uploads and downloads. More info.