binarylogic/authlogic
66.6
Adequate · 26 September 2026
4.8k
lines of production code
Ruby
primary language
4
measurements over time
What this system is
Features
Authlogic 6.6.1 release with new internal modules
The Authlogic gem has been updated to version 6.6.1. This release introduces several new internal modules to support the library's architecture, including \Authlogic::Config\ for managing configuration settings, \Authlogic::CookieCredentials\ for handling session data in cookies, \Authlogic::CryptoProviders\ for managing cryptographic algorithms, \Authlogic::I18n\ for internationalization, and \Authlogic::Random\ for generating secure tokens. Additionally, the \Authlogic::TestCase\ module has been expanded to include mock controllers, request adapters, and logger utilities to facilitate testing. The \Authlogic::Errors\ module has been consolidated to include specific error classes like \ModelSetupError\ and \NilCryptoProvider\.
lib/authlogic · high confidence
New and updated crypto providers: SCrypt, BCrypt, SHA1, SHA256, SHA512, and MD5
Authlogic now ships with built-in support for several password hashing algorithms. SCrypt is introduced as the new default provider, offering memory-bound security. BCrypt is added as a standard adaptive hash option. SHA1, SHA256, SHA512, and MD5 are also provided as legacy or alternative options, with V2 variants available for some. Users can now configure \acts\_as\_authentic\ to use any of these providers via the \crypto\_provider\ option.
_lib/authlogic/crypto\providers · high confidence
New mock controller and request helpers for testing
Authlogic now provides a set of mock classes (MockAPIController, MockController, MockCookieJar, MockLogger, MockRequest, and RailsRequestAdapter) to simplify testing. These allow developers to interact with Authlogic in a controlled environment, inspecting state changes and verifying behavior without needing a full Rails stack. The MockCookieJar supports signed and encrypted cookies, and the MockRequest handles IP address and content type, making functional tests for authentication flows easier to write and maintain.
_lib/authlogic/test\case · high confidence
Support for Rack middleware and Sinatra frameworks
Authlogic now supports non-Rails HTTP frameworks. A new \RackAdapter\ allows Authlogic to function as a Rack middleware, while a \SinatraAdapter\ provides integration with the Sinatra framework. The \AbstractAdapter\ was introduced to provide a common base for these new adapters, ensuring consistent behavior across different web environments.
_lib/authlogic/controller\adapters · high confidence
Removals
Removed Authgasm library files
The \lib/authgasm\ directory has been removed from the codebase, deleting the \acts\_as\_authentic.rb\, \controller.rb\, \sha256\_crypto\_provider.rb\, and \version.rb\ files. This eliminates the Authgasm authentication library and its associated components from the application.
lib/authgasm · high confidence
Removed session module files
The session module files (active\_record\_trickery.rb, base.rb, callbacks.rb, config.rb, errors.rb) have been deleted from the library. This removes the internal implementation of the session handling, which previously managed authentication state, cookie/session storage, and configuration options.
lib/authgasm/session · high confidence
Removed test\_app Rails application scaffolding and assets
Deleted the entire test\_app directory, including all generated Rails application files. This includes the Rakefile, boot and environment configuration files, controllers, models, helpers, views, and public assets (JavaScript libraries like Prototype and script.aculo.us, CSS, and error pages). The removal eliminates the default Rails structure and associated client-side dependencies from the test application.
_test\app · high confidence
Behavioural changes
Add customizable i18n translator class
A new \Authlogic::I18n::Translator\ class has been introduced, allowing users to replace the default translation behavior with a custom implementation. The class provides a \translate\ method that delegates to the \I18n\ gem if available, otherwise falling back to the \:default\ option.
lib/authlogic/i18n · high confidence
Add support for Rails 7.2, 8.0, and 8.1
The gemfiles directory now includes dedicated dependency configurations for Rails 7.2, 8.0, and 8.1, enabling the library to be tested and used with these specific versions of the Rails framework.
gemfiles · high confidence
Consolidated session base class with new security and configuration options
The Authlogic session base class has been consolidated into a single file, introducing built-in brute force protection that suspends accounts after consecutive failed login attempts. The session now supports a 'logout\_on\_timeout' configuration option to automatically log out inactive users, and includes a 'disable\_magic\_states' option. Additionally, the class now returns an object when a session is stale, allowing developers to determine why a user must log back in.
lib/authlogic/session · high confidence
Migrated from Authgasm to Authlogic
The library has been renamed from Authgasm to Authlogic. The old \lib/authgasm.rb\ entry point has been removed and replaced with \lib/authlogic.rb\, which now loads the Authlogic components. This change reflects the official rebranding of the gem, ensuring that the correct namespace and file structure are used for authentication and session management.
lib · high confidence
Refactor case-sensitive query logic into dedicated classes
The case-sensitive query logic for finding records has been extracted into new \CaseSensitivity\ and \FindWithCase\ classes within the \lib/authlogic/acts\_as\_authentic/queries\ directory. This refactoring isolates the logic for determining case sensitivity and executing the corresponding SQL comparison (using Rails' \case\_insensitive\_comparison\ and \case\_sensitive\_comparison\ methods), making the authentication query behavior more modular and maintainable.
_lib/authlogic/acts\_as\authentic/queries · medium confidence
Restructure \`acts\_as\_authentic\` into modular components
The \acts\_as\_authentic\ functionality has been refactored from a single monolithic module into separate, distinct modules for each feature (Email, Login, Password, etc.), each with its own configuration and methods. This change improves code organization and allows for more granular control over which authentication features are included in a model.
_lib/authlogic/acts\_as\authentic · high confidence
Standardized project configuration and documentation structure
The project introduced a standardized \.rubocop.yml\ configuration file to enforce code style and metrics, alongside a \.rubocop\_todo.yml\ to track existing offenses. Documentation was migrated from RST/RDOC to Markdown, with \README.rdoc\ and \UPD\ replaced by \README.md\ and \UPGRADING.md\. The \Manifest\ file was removed, and the \MIT-LICENSE\ was renamed to \LICENSE\. The \init.rb\ and \Rakefile\ were updated to use Bundler and include RuboCop and Coveralls tasks.
(repo-wide) · high confidence
Test coverage
Add comprehensive test coverage for session authentication and persistence; Added comprehensive test suite for \acts\_as\_authentic\ configuration and behavior; Added test fixtures for Authlogic models and sessions; Added tests for new and updated crypto providers; New test suite for core Authlogic components.
Dependencies
Authlogic v3.5.0: Rails 7.2+ and Ruby 3.2+ support
Authlogic has been updated to require Ruby 3.2.0 or higher and support Rails 7.2 through 8.1. The gem now depends on specific versions of activemodel, activerecord, and activesupport (\>= 7.2, \< 8.2). Development dependencies have also been updated, including bcrypt, byebug, and various testing and linting tools.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 47 → 67 (+19.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 98 (-1.6)
- Architecture 96 → 100 (+4.0)
- Maturity 57 → 55 (-2.3)
- Readiness 25 → 62 (+36.9)
- Security 59 → 87 (+27.7)
Resolved (14)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No exposed public API
- No tests found
- Rotate the exposed credentials — git history can't be un-committed
- Test reliability not included
- The README's table of contents lists sections like 'Add-ons' and 'Internals', but none are shown in the visible text. (README.md)
- The table of contents lists sections like 'Magic Columns' and 'Magic States', but the Introduction section itself is cut off mid-sentence, so the subsections under Overview (e.g. configure logout_on_timeout true) are not visible in the text. (README.md)
New (21)
- Base.credentials= (cognitive 18) (lib/authlogic/session/base.rb)
- FileTooLong: session/base.rb (lib/authlogic/session/base.rb)
- Further orphaned files (smaller)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent boolean method naming for password validation state. The model instance method is valid_password?, while the session state property is invalid_password?. While semantically opposite, the asymmetry in naming (valid vs invalid) for related concepts can be confusing. Usually, one prefers valid? and valid_password? or invalid? and invalid_password?.
- Inconsistent naming convention for class-level finders. The Session class uses a generic find method, while the PerishableToken module uses specific find_using_perishable_token methods. Additionally, the bang variants (!) are present in PerishableToken but not explicitly named in the Session find signature (though find often implies raising in some ORMs, the explicit naming here creates a pattern mismatch).
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No dependency advisory monitoring
- Orphaned knowledge (lib/authlogic/session/base.rb)
- TodoComment (lib/authlogic/config.rb)
- TodoComment (lib/authlogic/session/base.rb)
- TodoComment (lib/authlogic/test_case.rb)
- TodoComment (lib/authlogic/test_case/mock_cookie_jar.rb)
- TodoComment (test/session_test/session_test.rb)
- TooManyMethods: Base (lib/authlogic/session/base.rb)
- …and 1 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
binarylogic/authlogic was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9b8cfe8b14b9cc172d45c570f2823298b0bdf0ed — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.