🏛️ Architecture_Review.md - Architecture Review & Code Audit (รายงานผลการตรวจโค้ดสถาปัตยกรรมสะอาด)

This document reviews the structural integrity of the SplitDee backend implementation, identifying boundary violations, code smells, and alignment with Clean Architecture principles.
เอกสารรายงานการประเมินคุณภาพและความพร้อมใช้งานของซอร์สโค้ดหลังบ้าน ค้นหารอยต่อรั่วไหล และสเปกวิศวกรรมสถาปัตยกรรมสะอาด (Clean Architecture)


🇹🇭 ภาษาไทย (สำหรับผู้ใช้งาน)

🔍 1. รายงานผลการประเมินรายชั้นเลเยอร์ (Layer-by-Layer Evaluation)

  • ชั้นสเปกโดเมนหลัก (Domain Layer - app/domain):
    • คลาสโมเดลหลักใน user.py ถูกจัดวางในรูปแบบ python dataclass สะอาดหมดจด แยกเดี่ยวออกจากโมเดลฐานข้อมูล SQLAlchemy และโมเดลคัดกรอง Pydantic ชัดเจน
    • คลาสต้นแบบคีย์รับส่งอินเตอร์เฟส user_repository.py กำหนดพฤติกรรมสืบค้นไว้อย่างถูกต้อง นำเข้าเฉพาะเอนทิตีระดับโดเมนเท่านั้น
  • ชั้นยูสเคสประมวลผล (Use Cases Layer - app/use_cases):
    • รวบรวมตรรกะดำเนินการสมัครสมาชิกใน register.py และตรวจประวัติล็อกอินใน login.py ครบถ้วน
  • ชั้นสถาปัตยกรรมด้านล่าง (Infrastructure Layer - app/infrastructure):
    • บันทึกโมเดล SQLAlchemy ลงตาราง PostgreSQL ถูกต้อง แต่พบข้อผิดพลาดระบบแฮชและโทเค็นความปลอดภัยที่ต้องรีแฟคเตอร์ย้ายสิทธิ์ Interface
  • ชั้นนำเสนอและรับสัญญาณอินพุต (Presentation Layer - app/presentation):
    • โค้ดเร้าเตอร์ใน auth.py รับสัญญาณและฉีดความสัมพันธ์ DB เข้ามาประมวลผลถูกต้อง

🚨 2. ประเด็นข้ามเส้นขอบเขตระบบย่อยที่ผิดหลักสถาปัตยกรรมสะอาด (Critical Violations)

  • ข้อตรวจพบที่ 1 (นำเข้าฟังก์ชันแฮชตรงๆ): โค้ด register.py มีการนำเข้าฟังก์ชันแฮช hash_password จากโฟลเดอร์อินฟราโดยตรง ซึ่งผิดกฎที่เลเยอร์ในสุดห้ามอ้างอิงโค้ดเลเยอร์นอกสุด ➔ วิธีแก้ไข: ตั้งคลาสกลาง PasswordHasher ในชั้นโดเมน และฉีดความสัมพันธ์เข้ามาในโมเดลยูสเคสแทน
  • ข้อตรวจพบที่ 2 (นำเข้าฟังก์ชัน JWT ตรงๆ): โค้ด login.py นำเข้าคลาส Token เกตเวย์และฟังก์ชันรหัสผ่านจากโครงสร้างอินฟราโดยตรง ➔ วิธีแก้ไข: ตั้งคลาสกลาง TokenGenerator ในชั้นโดเมนเพื่อแยกสิทธิ์การใช้งาน
  • ข้อตรวจพบที่ 3 (อายุตั๋ว Access Token ยาวเกินไป): ใน token.py มีการฮาร์ดโค้ดตั้งค่าอายุ JWT ไว้นานถึง 24 ชั่วโมง ซึ่งขัดต่อนโยบายความปลอดภัยที่ระบุไว้ให้ใช้งานตั๋วได้คนละไม่เกิน 15 นาที ➔ วิธีแก้ไข: ขยับปรับปรุงสเปกเวลาให้เหลือ 15 นาทีตามหลัก

📉 3. คะแนนสเปกความสะอาดสากล: 85 / 100

สัดส่วนการแยกโฟลเดอร์โครงการทำได้ดีเยี่ยมมาก แต่มีปัญหาเลเยอร์ use cases ยึดโยงข้ามชั้นไปหาเครื่องมือยืนยันความปลอดภัย ซึ่งต้องรีแฟคเตอร์ให้เรียบร้อยก่อนที่จะแช่แข็งระบบ Gate 1 ได้


🇬🇧 English (For AI Agents)

🔍 1. Layer-by-Layer Evaluation

  • Domain Layer (app/domain): Dataclasses in user.py are cleanly isolated from SQLAlchemy DB tables and Pydantic schemas. Repository contracts in user_repository.py import only domain entities. Excellent.
  • Use Cases Layer (app/use_cases): Houses user registration and login logics in register.py and login.py.
  • Infrastructure Layer (app/infrastructure): SQLAlchemy mappings configured with composite unique indices. Helper security utilities in hasher.py and token.py wrap Bcrypt and PyJWT.
  • Presentation Layer (app/presentation): FastAPI endpoints properly accept dependency-injected sessions and invoke use cases.

🚨 2. Clean Architecture Boundary Violations

  • 🚫 Violation 1: Direct Hasher Import in Register Use Case
    • Location: app/use_cases/auth/register.py:5
    • Issue: Outer layer dependency: use case directly imports concrete Bcrypt utils (from backend.app.infrastructure.security.hasher import hash_password).
    • Remedy: Define abstract interface PasswordHasher inside the domain layer and pass it via dependency injection.
  • 🚫 Violation 2: Direct Token Generator & Hasher Import in Login Use Case
    • Location: app/use_cases/auth/login.py:2-3
    • Issue: Decoupling violation: use case directly calls infrastructure security token routines.
    • Remedy: Define abstract interface TokenGenerator inside the domain layer and inject it.
  • ⚠️ Observation 3: Hardcoded Token Expiration
    • Location: app/infrastructure/security/token.py:7
    • Issue: Access token lifespan is set to 24 hours (1 day) instead of the 15 minutes specified by the security policy.

📉 3. Overall Architecture Score: 85/100

Code layout is solid but boundary violations must be addressed in Sprint 2 to ensure long-term stability and clean isolation.