| Severity | Issue | Evidence | Recommendation | |-----------|----------------------------------------------------------------------|----------------------------------------------------------|----------------------------------------------------------------------------------------------------------| | Medium | Not all routes use standardized response decorators | Only global and custom decorators are observed | Apply consistent **`ApiSuccessResponse` / `ApiErrorResponse`** decorators across all controllers. | | Low | Authentication response mixes token property names | `auth.service.ts` returns `{ token }` while `authenticateUser` method returns `{ access_token }` | **Normalize the property name** (e.g., use `accessToken` consistently). |
ApiSuccessResponse/ApiErrorResponsedecorators across all controllers.auth.service.tsreturns{ token }whileauthenticateUsermethod returns{ access_token }accessTokenconsistently).