Based on a thorough review of the entire codebase, below is a complete list of files that are missing or incompletely implemented (stubs, placeholders, or otherwise not production‑ready).
1. Missing Controllers (No REST Endpoints)
| File (Expected) | Reason |
|---|---|
GrantController.java |
GrantService exists, but no endpoints for grants. |
PreprintController.java |
PreprintService exists, but no dedicated preprint controller. |
ProvenanceController.java |
ProvenanceService exists, but no API for provenance events. |
MediaController.java |
MediaService exists, but only UploadController handles basic file uploads; full CRUD missing. |
WorkspacePanelController.java |
WorkspacePanelRepository exists, but only a stub in WorkspaceCompatController. |
BroadcastChannelController.java / BroadcastPostController.java |
BroadcastPostRepository exists, but no endpoints for channels or posts. |
EncryptionKeyController.java |
EncryptionKeyRepository exists, but no endpoints (probably internal). |
PreKeyController.java |
PreKeyRepository exists – no endpoints. |
SignedPreKeyController.java |
SignedPreKeyRepository exists – no endpoints. |
GraphNodeController.java |
Graph nodes are managed via GapAnalysisController but not full CRUD. |
GraphEdgeController.java |
Same as above. |
CitationGraphController.java |
CitationGraphService exists, but no API for citation network. |
TagFollowController.java |
TagFollowDTO exists, but no endpoints for following tags. |
ToolStoreStateController.java |
ToolStoreStateRepository exists – no controller. |
2. Incomplete / Stub Controllers
| File | Issue |
|---|---|
WorkspaceCompatController.java |
Most methods return hardcoded mock data; not production. |
AiCompatController.java |
Returns stub AI responses; no real AI integration. |
DataHubController.java |
Many methods return empty lists or throw UnsupportedOperationException (e.g., search, getVersions). |
AdminToolController.java |
Minimal – getAllToolsAdmin returns empty list. |
BlogCategoryController.java |
Missing bulk operations, admin reorder, etc. |
BlogCommentController.java |
Missing proper reply threading endpoints. |
UserUtilityController.java |
Only handles writing goals; other utilities missing. |
3. Missing or Placeholder Services
| File | Status / Issue |
|---|---|
WebhookService.java |
Completely missing – referenced in WebhookController but not provided. |
VoiceSettingsService.java |
Missing – VoiceSettingsController expects it, but only VoiceSettingsRepository exists. |
BackupService.java |
Placeholder – writes empty JSON arrays ("[]"); no real backup logic. |
ExportService.java |
Many methods return empty strings or mock CSV; no real export. |
IntegrationService.java |
All external API integrations (Zotero, Mendeley, ORCID, GitHub) return mock data. |
4. Missing Configuration & Resource Files
| File | Needed By |
|---|---|
firewall.properties |
FirewallConfig – defines IP rules. |
banned_keywords.txt |
FirewallConfig – list of banned words. |
GeoLite2-Country.mmdb |
GeoIpResolver – MaxMind GeoIP database (not provided). |
Email templates (e.g., welcome.html, reset-password.html) |
MailService – referenced but not in resources. |
git.properties |
VersionController – optional, but missing. |
maven.properties |
VersionController – optional, missing. |
5. Missing DTOs (Used in Services/Controllers but Not Defined)
| Missing DTO | Referenced By |
|---|---|
GrantDTO |
GrantService returns model directly; no DTO. |
BroadcastChannelDTO |
No DTO for broadcast channels. |
GraphNodeDTO / GraphEdgeDTO |
Models used directly in GapAnalysisController. |
ToolDownloadDTO / ToolInstallationDTO |
No DTOs for tool downloads/installations. |
PollOptionDTO |
Only PollDTO exists; options embedded. |
ProtocolDTO / ProtocolStepDTO |
Models used directly in DataHubController. |
ResearchObjectDTO |
Models used directly. |
RecentItemDTO |
Models used directly. |
WorkspacePanelDTO |
Only model exists. |
6. Incomplete Repository Implementations
| Repository | Missing / Stub Methods |
|---|---|
ArticleRepository |
search() does not handle tag filtering (commented out). |
MessageRepository |
findByConversationId() returns empty list (not implemented). |
CommentRepository |
Some methods rely on in‑memory filtering; no pagination in DB. |
GroupService (not a repo, but service) |
Several methods return empty lists (e.g., searchMessages, getMediaForMessage). |
ProjectService |
getUsernameFromId and getUserIdFromUsername are placeholders (hash‑based). |
PeerReviewService |
All data stored in‑memory (ConcurrentHashMap), not persisted. |
PollService |
Same – in‑memory only. |
7. Inactive / Commented‑Out Components
| File | Issue |
|---|---|
RedisConfig.java |
Entirely commented out → Redis not active. |
OpenApiGenerator.java |
@Component commented out → OpenAPI docs not generated. |
RateLimitFilter.java |
Exists but not applied consistently to all endpoints. |
CsrfFilter.java |
Exists but not integrated with Spring Security; not enforced. |
8. Missing Persistence & Infrastructure
| Feature | Status |
|---|---|
| Database migration scripts | No Flyway/Liquibase. Only Database.init() creates tables (may fail on schema changes). |
| Tests | No unit, integration, or end‑to‑end tests. |
| Frontend files | HomeController returns view names (index, search-results) but no .html files provided. |
| Real backup & restore | BackupService does not actually save/restore database or files. |
| Real WebSocket cross‑server messaging | WebSocketManager includes Redis pub/sub, but Redis is disabled (config commented). |
9. Security & Session Management Gaps
| Issue | Description |
|---|---|
| No Spring Security integration | Home‑grown SessionManager and filters; no method‑level security (@PreAuthorize). |
| CSRF protection not fully applied | CsrfFilter exists but not wired to all state‑changing endpoints. |
| Password hashing duplication | Uses both BCrypt (at.favre.lib) and jBCrypt (org.mindrot) – potential conflict. |
| JWT utilities unused | JwtUtil present but never used (session uses UUID tokens). |
10. Missing External Dependencies (Not Declared)
Even though the code compiles with provided JARs, the following libraries are not listed in a pom.xml or build.gradle in the provided files:
com.openhtmltopdf:openhtmltopdf-core(PDF export)org.apache.poi:poi-ooxml(Excel export)org.apache.pdfbox:pdfbox(PDF thumbnail)com.maxmind.geoip2:geoip2(IP geolocation)io.jsonwebtoken:jjwt-api(JWT – though unused)com.warrenstrange:googleauth(TOTP – used inTwoFactorService)org.java-websocket:Java-WebSocket(WebSocket server – used)redis.clients:jedis(Redis – used inWebSocketManager)org.thymeleaf:thymeleaf-spring5(email templates)at.favre.lib:bcrypt(password hashing)
Summary
The codebase is structurally complete for a prototype, but at least 30+ files are either missing, stubbed, or incomplete. The most critical missing pieces for production are:
- Real backup, export, and integration logic (currently mock).
- Missing controllers (Grant, Preprint, Provenance, Media, etc.).
- Missing services (
WebhookService,VoiceSettingsService). - Configuration files (
firewall.properties,banned_keywords.txt, GeoIP database). - Testing and database migration infrastructure.
- Spring Security integration with proper role‑based access control.
Xet Storage Details
- Size:
- 8.08 kB
- Xet hash:
- 8d3101082689958bec0cf55aa9e32297f4d167ba8a9bf6ecea1069051cd86399
·
Xet efficiently stores files, intelligently splitting them into unique chunks and accelerating uploads and downloads. More info.