| Based on a thorough review of the entire codebase, below is a **complete list of files that are missing or incompletely implemented** (stubs, placeholders, or otherwise not production‑ready). | |
| --- | |
| ## 1. Missing Controllers (No REST Endpoints) | |
| | File (Expected) | Reason | | |
| |----------------|--------| | |
| | `GrantController.java` | `GrantService` exists, but no endpoints for grants. | | |
| | `PreprintController.java` | `PreprintService` exists, but no dedicated preprint controller. | | |
| | `ProvenanceController.java` | `ProvenanceService` exists, but no API for provenance events. | | |
| | `MediaController.java` | `MediaService` exists, but only `UploadController` handles basic file uploads; full CRUD missing. | | |
| | `WorkspacePanelController.java` | `WorkspacePanelRepository` exists, but only a stub in `WorkspaceCompatController`. | | |
| | `BroadcastChannelController.java` / `BroadcastPostController.java` | `BroadcastPostRepository` exists, but no endpoints for channels or posts. | | |
| | `EncryptionKeyController.java` | `EncryptionKeyRepository` exists, but no endpoints (probably internal). | | |
| | `PreKeyController.java` | `PreKeyRepository` exists – no endpoints. | | |
| | `SignedPreKeyController.java` | `SignedPreKeyRepository` exists – no endpoints. | | |
| | `GraphNodeController.java` | Graph nodes are managed via `GapAnalysisController` but not full CRUD. | | |
| | `GraphEdgeController.java` | Same as above. | | |
| | `CitationGraphController.java` | `CitationGraphService` exists, but no API for citation network. | | |
| | `TagFollowController.java` | `TagFollowDTO` exists, but no endpoints for following tags. | | |
| | `ToolStoreStateController.java` | `ToolStoreStateRepository` exists – no controller. | | |
| --- | |
| ## 2. Incomplete / Stub Controllers | |
| | File | Issue | | |
| |------|-------| | |
| | `WorkspaceCompatController.java` | Most methods return hardcoded mock data; not production. | | |
| | `AiCompatController.java` | Returns stub AI responses; no real AI integration. | | |
| | `DataHubController.java` | Many methods return empty lists or throw `UnsupportedOperationException` (e.g., `search`, `getVersions`). | | |
| | `AdminToolController.java` | Minimal – `getAllToolsAdmin` returns empty list. | | |
| | `BlogCategoryController.java` | Missing bulk operations, admin reorder, etc. | | |
| | `BlogCommentController.java` | Missing proper reply threading endpoints. | | |
| | `UserUtilityController.java` | Only handles writing goals; other utilities missing. | | |
| --- | |
| ## 3. Missing or Placeholder Services | |
| | File | Status / Issue | | |
| |------|----------------| | |
| | `WebhookService.java` | **Completely missing** – referenced in `WebhookController` but not provided. | | |
| | `VoiceSettingsService.java` | **Missing** – `VoiceSettingsController` expects it, but only `VoiceSettingsRepository` exists. | | |
| | `BackupService.java` | Placeholder – writes empty JSON arrays (`"[]"`); no real backup logic. | | |
| | `ExportService.java` | Many methods return empty strings or mock CSV; no real export. | | |
| | `IntegrationService.java` | All external API integrations (Zotero, Mendeley, ORCID, GitHub) return mock data. | | |
| --- | |
| ## 4. Missing Configuration & Resource Files | |
| | File | Needed By | | |
| |------|-----------| | |
| | `firewall.properties` | `FirewallConfig` – defines IP rules. | | |
| | `banned_keywords.txt` | `FirewallConfig` – list of banned words. | | |
| | `GeoLite2-Country.mmdb` | `GeoIpResolver` – MaxMind GeoIP database (not provided). | | |
| | Email templates (e.g., `welcome.html`, `reset-password.html`) | `MailService` – referenced but not in resources. | | |
| | `git.properties` | `VersionController` – optional, but missing. | | |
| | `maven.properties` | `VersionController` – optional, missing. | | |
| --- | |
| ## 5. Missing DTOs (Used in Services/Controllers but Not Defined) | |
| | Missing DTO | Referenced By | | |
| |-------------|---------------| | |
| | `GrantDTO` | `GrantService` returns model directly; no DTO. | | |
| | `BroadcastChannelDTO` | No DTO for broadcast channels. | | |
| | `GraphNodeDTO` / `GraphEdgeDTO` | Models used directly in `GapAnalysisController`. | | |
| | `ToolDownloadDTO` / `ToolInstallationDTO` | No DTOs for tool downloads/installations. | | |
| | `PollOptionDTO` | Only `PollDTO` exists; options embedded. | | |
| | `ProtocolDTO` / `ProtocolStepDTO` | Models used directly in `DataHubController`. | | |
| | `ResearchObjectDTO` | Models used directly. | | |
| | `RecentItemDTO` | Models used directly. | | |
| | `WorkspacePanelDTO` | Only model exists. | | |
| --- | |
| ## 6. Incomplete Repository Implementations | |
| | Repository | Missing / Stub Methods | | |
| |------------|------------------------| | |
| | `ArticleRepository` | `search()` does not handle tag filtering (commented out). | | |
| | `MessageRepository` | `findByConversationId()` returns empty list (not implemented). | | |
| | `CommentRepository` | Some methods rely on in‑memory filtering; no pagination in DB. | | |
| | `GroupService` (not a repo, but service) | Several methods return empty lists (e.g., `searchMessages`, `getMediaForMessage`). | | |
| | `ProjectService` | `getUsernameFromId` and `getUserIdFromUsername` are placeholders (hash‑based). | | |
| | `PeerReviewService` | All data stored in‑memory (`ConcurrentHashMap`), not persisted. | | |
| | `PollService` | Same – in‑memory only. | | |
| --- | |
| ## 7. Inactive / Commented‑Out Components | |
| | File | Issue | | |
| |------|-------| | |
| | `RedisConfig.java` | Entirely commented out → Redis not active. | | |
| | `OpenApiGenerator.java` | `@Component` commented out → OpenAPI docs not generated. | | |
| | `RateLimitFilter.java` | Exists but not applied consistently to all endpoints. | | |
| | `CsrfFilter.java` | Exists but not integrated with Spring Security; not enforced. | | |
| --- | |
| ## 8. Missing Persistence & Infrastructure | |
| | Feature | Status | | |
| |---------|--------| | |
| | **Database migration scripts** | No Flyway/Liquibase. Only `Database.init()` creates tables (may fail on schema changes). | | |
| | **Tests** | No unit, integration, or end‑to‑end tests. | | |
| | **Frontend files** | `HomeController` returns view names (`index`, `search-results`) but no `.html` files provided. | | |
| | **Real backup & restore** | `BackupService` does not actually save/restore database or files. | | |
| | **Real WebSocket cross‑server messaging** | `WebSocketManager` includes Redis pub/sub, but Redis is disabled (config commented). | | |
| --- | |
| ## 9. Security & Session Management Gaps | |
| | Issue | Description | | |
| |-------|-------------| | |
| | No Spring Security integration | Home‑grown `SessionManager` and filters; no method‑level security (`@PreAuthorize`). | | |
| | CSRF protection not fully applied | `CsrfFilter` exists but not wired to all state‑changing endpoints. | | |
| | Password hashing duplication | Uses both `BCrypt` (at.favre.lib) and `jBCrypt` (org.mindrot) – potential conflict. | | |
| | JWT utilities unused | `JwtUtil` present but never used (session uses UUID tokens). | | |
| --- | |
| ## 10. Missing External Dependencies (Not Declared) | |
| Even though the code compiles with provided JARs, the following libraries are **not listed in a `pom.xml` or `build.gradle`** in the provided files: | |
| - `com.openhtmltopdf:openhtmltopdf-core` (PDF export) | |
| - `org.apache.poi:poi-ooxml` (Excel export) | |
| - `org.apache.pdfbox:pdfbox` (PDF thumbnail) | |
| - `com.maxmind.geoip2:geoip2` (IP geolocation) | |
| - `io.jsonwebtoken:jjwt-api` (JWT – though unused) | |
| - `com.warrenstrange:googleauth` (TOTP – used in `TwoFactorService`) | |
| - `org.java-websocket:Java-WebSocket` (WebSocket server – used) | |
| - `redis.clients:jedis` (Redis – used in `WebSocketManager`) | |
| - `org.thymeleaf:thymeleaf-spring5` (email templates) | |
| - `at.favre.lib:bcrypt` (password hashing) | |
| --- | |
| ## Summary | |
| The codebase is **structurally complete** for a prototype, but at least **30+ files** are either missing, stubbed, or incomplete. The most critical missing pieces for production are: | |
| 1. **Real backup, export, and integration logic** (currently mock). | |
| 2. **Missing controllers** (Grant, Preprint, Provenance, Media, etc.). | |
| 3. **Missing services** (`WebhookService`, `VoiceSettingsService`). | |
| 4. **Configuration files** (`firewall.properties`, `banned_keywords.txt`, GeoIP database). | |
| 5. **Testing and database migration** infrastructure. | |
| 6. **Spring Security integration** with proper role‑based access control. | |
Xet Storage Details
- Size:
- 8.08 kB
- Xet hash:
- 8d3101082689958bec0cf55aa9e32297f4d167ba8a9bf6ecea1069051cd86399
·
Xet efficiently stores files, intelligently splitting them into unique chunks and accelerating uploads and downloads. More info.