GymTron is a modern, cross-platform fitness tracking ecosystem built with .NET. It serves as an architectural sandbox to explore and demonstrate Clean Architecture, Domain-Driven Design (DDD), and CQRS across mobile, web, and REST API clients.
While developed as an experimental project rather than a commercial product, it is engineered to production-grade standards: OWASP security hardening, strict automated architecture gates, and comprehensive test coverage (including 100% Domain line and branch coverage).
| Resource | Target / Access | Description |
|---|---|---|
| Web Dashboard | http://gymtron.runasp.net/ | Live ASP.NET Core Razor Pages application |
| REST API | http://gymtronapi.runasp.net/ | Backend Minimal API service (Health: /health) |
| Android App (APK) | Download GymTron v1.0.0 APK (Release Notes) | Direct download for .NET MAUI Android client |
| Presentation Slides | GymTron Pitch Deck (Google Drive PDF) | Project presentation and architecture pitch |
| Demo Video | GymTron Walkthrough & Architecture Demo (Google Drive) | Walkthrough and live demonstration |
Use this pre-seeded account to evaluate both the live Web application and mobile App:
| Username | Password | Scope & Access |
|---|---|---|
user |
password |
Workout tracking, personal routines, exercises, body metrics |
Note
Live vs. Local Environment: While the table above points to the public cloud deployments, you can run the full containerized environment demonstrated in the video (API + MySQL + Scalar UI) locally by executing:
./StartDockerScript.ps1This script builds and starts the local Docker containers and exposes the API with interactive Scalar documentation at http://localhost:5000/scalar/v1. See Getting Started for prerequisite setup.
- Workout & Routine Tracking: Design custom, multi-day training routines with specific sets, target repetitions, reserve repetitions (RIR), and rest intervals. Record live workout sessions and track completion status.
- Exercise Catalog & Parameterization: Rich database of exercises categorizing movement patterns, target muscle groups, and technique execution tips.
- Body Metrics & Composition: Log body weight, track Body Mass Index (BMI/IMC), and monitor long-term historical trends.
- Secure Authentication & Multi-Tenancy: Built according to OWASP guidelinesβJWT authentication, refresh tokens, PBKDF2 password hashing, and user-scoped data isolation (BOLA/IDOR prevention).
- User & Role Administration: Administrative Backweb management (
/Users) allowing administrators (TypeId = 2) to view, create, edit, and soft-delete user accounts with role assignments. - Cross-Platform Experience: Mobile client (.NET MAUI for Android & Windows) for in-gym tracking alongside a responsive Web dashboard (ASP.NET Core Razor Pages) for desktop management.
- Multilingual Experience: Native localization supporting Catalan (default), Spanish, and English.
The solution consists of three primary entry points sharing core domain and application libraries:
- GymTron.App (.NET 9 MAUI): Cross-platform mobile client targeting Android and Windows x64. Allows users to track workouts, log exercise details, monitor body measurements (weight and BMI), and view historical progress. Consumes the backend exclusively via HTTP through
GymTron.Api. - GymTron.Web (ASP.NET Core 10 Razor Pages): Web dashboard for routine management, exercise cataloging, and training summaries.
- GymTron.Api (ASP.NET Core 10 Minimal API): Secure backend service boundary implementing the REPR (Request-Endpoint-Response) pattern, JWT Bearer authentication, rate limiting, RFC 7807
ProblemDetails, and interactive API documentation powered by Scalar. - GymTron.Domain & GymTron.Application: Encapsulate the core business models, domain events, MediatR command/query handlers, FluentValidation pipeline behaviors, and deterministic UTC clock abstractions (
IClock). - GymTron.Infrastructure: Data access layer built with Dapper and MySQL, featuring transactional atomicity and connection isolation.
GymTron/
βββ .github/workflows/ # CI/CD pipelines (validation, security scanning, releases)
βββ docs/ # Architectural documentation, ADRs, and points of truth
βββ eng/ # Build scripts and code coverage assertion gates
βββ scripts/ # Automation and database helper scripts
βββ src/
β βββ GymTron.Api/ # ASP.NET Core 10 Minimal API backend (REPR, JWT, Scalar docs)
β βββ GymTron.App/ # .NET 9 MAUI cross-platform client (Android & Windows)
β βββ GymTron.Application/ # CQRS commands/queries (MediatR) and validation behaviors
β βββ GymTron.Domain/ # Core domain entities, aggregate roots, repository contracts
β βββ GymTron.Infrastructure/ # Persistence layer (Dapper, MySQL repositories)
β βββ GymTron.Web/ # ASP.NET Core 10 Razor Pages web application
βββ tests/
β βββ GymTron.UnitTests/ # Unit & architecture tests (NetArchTest, 100% Domain coverage)
β βββ GymTron.IntegrationTests/ # MySQL integration tests via Testcontainers
β βββ GymTron.Web.Tests/ # Web Razor Pages and API client tests
βββ docker-compose.yml # Container configuration for local MySQL database
βββ init.sql # Database schema creation and initial seed data
βββ StartDockerScript.ps1 # Automation script to start the local database container
- Clean Architecture & DDD: Dependencies strictly point inward. Core business logic is encapsulated in
GymTron.Domainand orchestrated viaGymTron.Application, independent of external frameworks or databases. - CQRS with MediatR: Commands and queries are cleanly segregated with cross-cutting concerns (validation, logging, exception handling) handled via pipeline behaviors.
- REPR Pattern & Minimal APIs: API endpoints are organized around individual request-endpoint-response classes rather than bloated controllers.
- Automated Architecture Enforcement: NetArchTest suites in
tests/GymTron.UnitTests/Architectureenforce layer boundaries, dependency rules, and package restrictions on every build. - OWASP Security Baseline: Client isolation via API, JWT-based authentication, rate limiting on sensitive endpoints, and zero plaintext credentials in source control.
GymTron provides full multi-language support across the mobile and web clients:
- Supported Languages: Catalan (default), Spanish, and English.
- MAUI: Resource strings in
src/GymTron.App/Resources/Strings/, managed viaLocalizationServiceandTranslateExtensionXAML markup. - Web: Resource strings in
src/GymTron.Web/Resources/Pages/, utilizingIViewLocalizerand cookie-based culture persistence.
- .NET 10 SDK (build baseline selects
10.0.301viaglobal.json) - Docker Desktop (for local MySQL instance)
- .NET MAUI Workload (optional, only needed for mobile builds):
androidormaui-windows
git clone https://github.com/eduardlorente/GymTron.git
cd GymTron- Create a
.envfile in the repository root (see.env.examplefor reference):MYSQL_ROOT_PASSWORD=YourSecurePasswordHere MYSQL_DATABASE=gymtron JWT_SECRET_KEY=Your32ByteMinimumSecretKeyHere!
- Start the containers (Database & API):
Alternatively, run
./StartDockerScript.ps1docker compose up -dto start the database container only.
Never commit credentials to tracked JSON files. Use ASP.NET Core User Secrets for local development:
-
Web Application:
dotnet user-secrets set "ConnectionStrings:DefaultConnection" "Server=localhost;Database=gymtron;Uid=root;Pwd=YourSecurePasswordHere;" --project src/GymTron.Web/GymTron.Web.csproj
-
REST API:
dotnet user-secrets set "ConnectionStrings:DefaultConnection" "Server=localhost;Database=gymtron;Uid=root;Pwd=YourSecurePasswordHere;" --project src/GymTron.Api/GymTron.Api.csproj dotnet user-secrets set "Jwt:SecretKey" "Your32ByteMinimumSecretKeyHere!" --project src/GymTron.Api/GymTron.Api.csproj
-
Mobile App (MAUI): Configure
ApiUrlinsrc/GymTron.App/Resources/Json/appsettings.jsonpointing to your localGymTron.Apiinstance.
dotnet run --project src/GymTron.Api/GymTron.Api.csproj- URL:
https://localhost:7251(HTTP:http://localhost:5275) - Interactive API Documentation (Scalar):
https://localhost:7251/scalar/v1
dotnet run --project src/GymTron.Web/GymTron.Web.csproj- URL:
https://localhost:5000(HTTP:http://localhost:5001)
# Windows Desktop
dotnet run --project src/GymTron.App/GymTron.App.csproj -f net9.0-windows10.0.19041.0
# Android (Device or Emulator attached)
dotnet build src/GymTron.App/GymTron.App.csproj -t:Run -f net9.0-androidThe database initialization script (init.sql) automatically provisions seed accounts for local development and testing:
| Role / Type | Username | Password | Permissions | |
|---|---|---|---|---|
| Standard User | user |
user@gymtron.local |
password |
Workouts, routines, body weights |
| Administrator | administrator |
administrator@gymtron.local |
password |
User Management CRUD (/Users) & full platform access |
Note
Seed routines, workout history, and sample body measurements are linked to test user 1 (user) out of the box. Administrative user management (/Users) is accessible exclusively by logging in as administrator.
The codebase maintains strict automated quality gates:
# Run unit and architecture tests
dotnet test tests/GymTron.UnitTests/GymTron.UnitTests.csproj
# Run web frontend tests
dotnet test tests/GymTron.Web.Tests/GymTron.Web.Tests.csproj
# Run MySQL integration tests (requires Docker)
dotnet test tests/GymTron.IntegrationTests/GymTron.IntegrationTests.csproj- Unit Tests: Full coverage of Domain logic (enforced at 100% line and branch coverage) and Application handlers (enforced at >= 80% coverage).
- Architecture Tests: Automated checks preventing illegal layer references (e.g., UI directly referencing persistence).
- Web Tests: Automated tests for Razor Pages models and HTTP API client implementations.
- Integration Tests: Tested against real MySQL instances using Testcontainers.
- Static Analysis: Roslyn analyzers (
SonarAnalyzer.CSharp,Meziantou.Analyzer) with warnings treated as errors. - CI/CD: GitHub Actions workflows enforce build verification, coverage gates, security scanning (Gitleaks, vulnerable packages), and automated release publishing.
Detailed design records, conventions, and operational manuals are maintained in the repository:
POINTS_OF_TRUTH.mdβ Index of canonical documentation.DESIGN.mdβ Current-state architectural charter.docs/architecture/β Dependency maps and architectural guidelines.docs/decisions/β Architecture Decision Records (ADRs).docs/onboarding/getting-started.mdβ Contributor guide and verified build matrix.docs/requirements/technical-requirements.mdβ Active capability backlog.
- Fork the repository.
- Create a feature branch (
git checkout -b feature/my-new-feature). - Commit your changes following Conventional Commits.
- Ensure all tests and coverage gates pass (
dotnet test). - Open a Pull Request.
This project is licensed under the MIT License β see the LICENSE file for details.
Eduard Lorente β eduardlorente@gmail.com