Skip to content
CAI
Software that uses CAICheck a score

binarylogic/authlogic

66.6

Adequate · 26 September 2026

4.8k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Authlogic 6.6.1 release with new internal modules

The Authlogic gem has been updated to version 6.6.1. This release introduces several new internal modules to support the library's architecture, including \Authlogic::Config\ for managing configuration settings, \Authlogic::CookieCredentials\ for handling session data in cookies, \Authlogic::CryptoProviders\ for managing cryptographic algorithms, \Authlogic::I18n\ for internationalization, and \Authlogic::Random\ for generating secure tokens. Additionally, the \Authlogic::TestCase\ module has been expanded to include mock controllers, request adapters, and logger utilities to facilitate testing. The \Authlogic::Errors\ module has been consolidated to include specific error classes like \ModelSetupError\ and \NilCryptoProvider\.

lib/authlogic · high confidence

New and updated crypto providers: SCrypt, BCrypt, SHA1, SHA256, SHA512, and MD5

Authlogic now ships with built-in support for several password hashing algorithms. SCrypt is introduced as the new default provider, offering memory-bound security. BCrypt is added as a standard adaptive hash option. SHA1, SHA256, SHA512, and MD5 are also provided as legacy or alternative options, with V2 variants available for some. Users can now configure \acts\_as\_authentic\ to use any of these providers via the \crypto\_provider\ option.

_lib/authlogic/crypto\providers · high confidence

New mock controller and request helpers for testing

Authlogic now provides a set of mock classes (MockAPIController, MockController, MockCookieJar, MockLogger, MockRequest, and RailsRequestAdapter) to simplify testing. These allow developers to interact with Authlogic in a controlled environment, inspecting state changes and verifying behavior without needing a full Rails stack. The MockCookieJar supports signed and encrypted cookies, and the MockRequest handles IP address and content type, making functional tests for authentication flows easier to write and maintain.

_lib/authlogic/test\case · high confidence

Support for Rack middleware and Sinatra frameworks

Authlogic now supports non-Rails HTTP frameworks. A new \RackAdapter\ allows Authlogic to function as a Rack middleware, while a \SinatraAdapter\ provides integration with the Sinatra framework. The \AbstractAdapter\ was introduced to provide a common base for these new adapters, ensuring consistent behavior across different web environments.

_lib/authlogic/controller\adapters · high confidence

Removals

Removed Authgasm library files

The \lib/authgasm\ directory has been removed from the codebase, deleting the \acts\_as\_authentic.rb\, \controller.rb\, \sha256\_crypto\_provider.rb\, and \version.rb\ files. This eliminates the Authgasm authentication library and its associated components from the application.

lib/authgasm · high confidence

Removed session module files

The session module files (active\_record\_trickery.rb, base.rb, callbacks.rb, config.rb, errors.rb) have been deleted from the library. This removes the internal implementation of the session handling, which previously managed authentication state, cookie/session storage, and configuration options.

lib/authgasm/session · high confidence

Removed test\_app Rails application scaffolding and assets

Deleted the entire test\_app directory, including all generated Rails application files. This includes the Rakefile, boot and environment configuration files, controllers, models, helpers, views, and public assets (JavaScript libraries like Prototype and script.aculo.us, CSS, and error pages). The removal eliminates the default Rails structure and associated client-side dependencies from the test application.

_test\app · high confidence

Behavioural changes

Add customizable i18n translator class

A new \Authlogic::I18n::Translator\ class has been introduced, allowing users to replace the default translation behavior with a custom implementation. The class provides a \translate\ method that delegates to the \I18n\ gem if available, otherwise falling back to the \:default\ option.

lib/authlogic/i18n · high confidence

Add support for Rails 7.2, 8.0, and 8.1

The gemfiles directory now includes dedicated dependency configurations for Rails 7.2, 8.0, and 8.1, enabling the library to be tested and used with these specific versions of the Rails framework.

gemfiles · high confidence

Consolidated session base class with new security and configuration options

The Authlogic session base class has been consolidated into a single file, introducing built-in brute force protection that suspends accounts after consecutive failed login attempts. The session now supports a 'logout\_on\_timeout' configuration option to automatically log out inactive users, and includes a 'disable\_magic\_states' option. Additionally, the class now returns an object when a session is stale, allowing developers to determine why a user must log back in.

lib/authlogic/session · high confidence

Migrated from Authgasm to Authlogic

The library has been renamed from Authgasm to Authlogic. The old \lib/authgasm.rb\ entry point has been removed and replaced with \lib/authlogic.rb\, which now loads the Authlogic components. This change reflects the official rebranding of the gem, ensuring that the correct namespace and file structure are used for authentication and session management.

lib · high confidence

Refactor case-sensitive query logic into dedicated classes

The case-sensitive query logic for finding records has been extracted into new \CaseSensitivity\ and \FindWithCase\ classes within the \lib/authlogic/acts\_as\_authentic/queries\ directory. This refactoring isolates the logic for determining case sensitivity and executing the corresponding SQL comparison (using Rails' \case\_insensitive\_comparison\ and \case\_sensitive\_comparison\ methods), making the authentication query behavior more modular and maintainable.

_lib/authlogic/acts\_as\authentic/queries · medium confidence

Restructure \`acts\_as\_authentic\` into modular components

The \acts\_as\_authentic\ functionality has been refactored from a single monolithic module into separate, distinct modules for each feature (Email, Login, Password, etc.), each with its own configuration and methods. This change improves code organization and allows for more granular control over which authentication features are included in a model.

_lib/authlogic/acts\_as\authentic · high confidence

Standardized project configuration and documentation structure

The project introduced a standardized \.rubocop.yml\ configuration file to enforce code style and metrics, alongside a \.rubocop\_todo.yml\ to track existing offenses. Documentation was migrated from RST/RDOC to Markdown, with \README.rdoc\ and \UPD\ replaced by \README.md\ and \UPGRADING.md\. The \Manifest\ file was removed, and the \MIT-LICENSE\ was renamed to \LICENSE\. The \init.rb\ and \Rakefile\ were updated to use Bundler and include RuboCop and Coveralls tasks.

(repo-wide) · high confidence

Test coverage

Add comprehensive test coverage for session authentication and persistence; Added comprehensive test suite for \acts\_as\_authentic\ configuration and behavior; Added test fixtures for Authlogic models and sessions; Added tests for new and updated crypto providers; New test suite for core Authlogic components.

Dependencies

Authlogic v3.5.0: Rails 7.2+ and Ruby 3.2+ support

Authlogic has been updated to require Ruby 3.2.0 or higher and support Rails 7.2 through 8.1. The gem now depends on specific versions of activemodel, activerecord, and activesupport (\>= 7.2, \< 8.2). Development dependencies have also been updated, including bcrypt, byebug, and various testing and linting tools.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 47 → 67 (+19.4)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 98 (-1.6)
  • Architecture 96 → 100 (+4.0)
  • Maturity 57 → 55 (-2.3)
  • Readiness 25 → 62 (+36.9)
  • Security 59 → 87 (+27.7)

Resolved (14)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Rotate the exposed credentials — git history can't be un-committed
  • Test reliability not included
  • The README's table of contents lists sections like 'Add-ons' and 'Internals', but none are shown in the visible text. (README.md)
  • The table of contents lists sections like 'Magic Columns' and 'Magic States', but the Introduction section itself is cut off mid-sentence, so the subsections under Overview (e.g. configure logout_on_timeout true) are not visible in the text. (README.md)

New (21)

  • Base.credentials= (cognitive 18) (lib/authlogic/session/base.rb)
  • FileTooLong: session/base.rb (lib/authlogic/session/base.rb)
  • Further orphaned files (smaller)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent boolean method naming for password validation state. The model instance method is valid_password?, while the session state property is invalid_password?. While semantically opposite, the asymmetry in naming (valid vs invalid) for related concepts can be confusing. Usually, one prefers valid? and valid_password? or invalid? and invalid_password?.
  • Inconsistent naming convention for class-level finders. The Session class uses a generic find method, while the PerishableToken module uses specific find_using_perishable_token methods. Additionally, the bang variants (!) are present in PerishableToken but not explicitly named in the Session find signature (though find often implies raising in some ORMs, the explicit naming here creates a pattern mismatch).
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No dependency advisory monitoring
  • Orphaned knowledge (lib/authlogic/session/base.rb)
  • TodoComment (lib/authlogic/config.rb)
  • TodoComment (lib/authlogic/session/base.rb)
  • TodoComment (lib/authlogic/test_case.rb)
  • TodoComment (lib/authlogic/test_case/mock_cookie_jar.rb)
  • TodoComment (test/session_test/session_test.rb)
  • TooManyMethods: Base (lib/authlogic/session/base.rb)
  • …and 1 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

binarylogic/authlogic was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9b8cfe8b14b9cc172d45c570f2823298b0bdf0ed — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.