📊 Automated Code Coverage & Quality Metrics¶
The Payflow API continuous integration pipeline strictly enforces automated bytecode static analysis via SpotBugs and bundle-level code coverage thresholds via JaCoCo (jacoco-maven-plugin:0.8.15).
🎯 Coverage Quality Thresholds & Status¶
| Quality Dimension | Enforced Gate Threshold | Current Achieved Status | Status |
|---|---|---|---|
| Line Coverage | 80% minimum |
90% (across core business packages) | |
| Branch Coverage | 70% minimum |
73% (across complex conditional paths) | |
| Unit & Integration Tests | 100% passing |
191 / 191 tests (0 failures, 0 errors) | |
| Missed Classes | 0 missed |
0 missed classes | |
| SpotBugs Bytecode Audit | Max Priority: Low (0 bugs) | 0 bugs, 0 errors detected |
🚀 Live Interactive JaCoCo Report¶
The complete, class-by-class interactive JaCoCo coverage report is automatically generated on every build and published alongside the documentation portal.
📊 Launch Interactive JaCoCo Code Coverage Report →
Seamless Navigation
Every page within the interactive JaCoCo report features an integrated, persistent top navigation header allowing seamless single-click bidirectional navigation:
- ← Back to Documentation Portal: Returns directly to the root documentation homepage.
- 📊 Coverage Quality Gates: Returns directly to this Quality Gate & Thresholds summary page.
📦 Package Coverage Breakdown¶
Coverage enforcement is focused on operational correctness, concurrency invariants, and data integrity:
| Package | Key Architectural Responsibilities | Coverage Profile |
|---|---|---|
com.payflow.service |
TransactionService, UserService, SpendInsightsService, RedissonDistributedLockService |
High Line & Branch coverage; all edge cases tested |
com.payflow.filter |
IdempotencyFilter, RequestLoggingFilter, request payload SHA-256 caching |
High branch coverage for in-flight contention & key reuse |
com.payflow.security |
JwtAuthenticationFilter, JwtTokenProvider, SecurityUtils, RBAC |
100% path coverage for authentication & principal authorization |
com.payflow.resilience |
PerUserRateLimiterAspect, UserRateLimiterService, Circuit Breaker |
Full verification of token bucket permissions & 429 translation |
com.payflow.controller |
TransactionController, UserController, AuthController |
WebMvcTest verification of HTTP status codes & RFC 7807 payloads |
com.payflow.event |
TransferCompletedEvent, TransferEventListener, Kafka externalization |
Verification of transactional outbox event lifecycle |
🛡️ Excluded Packages & Justification¶
Following industry best practices (ADR-030), purely declarative components without executable logic are excluded from bundle-level coverage metrics to prevent artificial metric skew:
- Entities & Value Objects (
com/payflow/entity/*): Pure JPA entities with getters/setters/builders. - Data Transfer Objects (
com/payflow/dto/*): Validation records and request/response payloads. - Generated Mappers (
com/payflow/mapper/*Impl*): Compile-time generated MapStruct mapping bytecode. - Spring Configuration Classes (
com/payflow/config/*): Declarative@Beanwiring definitions.