CanCanCommunity/cancancan
67.6
Adequate · 26 September 2026
2.6k
lines of production code
Ruby
primary language
4
measurements over time
What this system is
This system is the CanCanCan authorization library for Ruby on Rails, providing a permission system that defines access rules and enforces them via controller filters and database queries. It supports a wide range of Rails versions through version-specific model adapters and configurable SQL query strategies, while offering tools like an ability generator and strong parameter integration to simplify permission management.
How it got here
2009 — CanCanCan 3.6.0 engine rewrite
5 changes.
This period focused on releasing CanCanCan 3.6.0, which introduced a complete internal refactor of the permission checking and rule engine to improve performance and support for STI and polymorphic associations. The work also involved modernizing the project infrastructure, including migrating to RSpec 3, updating documentation, and establishing a comprehensive test suite for the new controller and ability logic.
2010 — Rails compatibility and documentation
5 changes.
The project expanded support for Rails versions 4.2 through 7.2 by refactoring model adapters with version-specific implementations and condition normalization. This period also introduced a new ability generator, comprehensive test coverage for model adapters, and a VitePress-based documentation site.
2014–2021 — Architecture refactoring and Rails compatibility
4 changes.
The project underwent significant structural refactoring, splitting the ability module and query strategies into distinct sub-components to improve maintainability and code organization. Concurrently, test infrastructure was enhanced with new support helpers, and compatibility was expanded to support Rails versions up to 7.1.0.
Features
Add ability generator
A new \cancan:ability\ generator has been added, which creates an \Ability\ class in the \app/models\ directory. The generator includes a usage description explaining that the generated file can be moved anywhere within the load path.
lib/generators/cancan/ability · high confidence
Architecture
Refactored authorization query strategies into separate files
The model adapter query strategies have been extracted from a monolithic structure into individual, dedicated files (Base, JoinedAliasEachRuleAsExistsSubquery, JoinedAliasExistsSubquery, LeftJoin, and Subquery). This refactoring improves code organization and maintainability by isolating the logic for different SQL generation approaches used to determine accessible records, without changing the external behavior of the authorization system.
_lib/cancan/model\adapters/strategies · high confidence
Behavioural changes
CanCanCan 3.6.0 introduces a rewritten rule engine and configurable query strategies
This release upgrades the library to version 3.6.0, featuring a complete internal refactor of the permission checking and resource loading logic. The core rule engine has been replaced with new \Rule\, \ConditionsMatcher\, and \ClassMatcher\ classes, which improve performance and support for Single Table Inheritance (STI) and polymorphic associations. A new \Config\ module allows users to configure the \accessible\_by\ query strategy (defaulting to \:subquery\ for Rails 5+), and the \AccessDenied\ exception now includes action, subject, and conditions details for better debugging. Controller resource loading is now handled by a dedicated \ControllerResource\ class with extracted concerns for finding, building, and sanitizing parameters.
lib/cancan · high confidence
CanCanCan library initialization and adapter structure
The library now initializes via a new \lib/cancancan.rb\ entry point that requires the legacy \cancan\ gem and defines the \CanCanCan\ module. The core \lib/cancan.rb\ file has been restructured to explicitly require version, configuration, parameter validators, and specific model adapters (including Active Record 4 and 5), along with query strategies and rule compression logic, establishing the foundational loading order for the permission system.
lib · high confidence
Project infrastructure modernization and documentation overhaul
This change replaces the legacy project setup with modern tooling and documentation standards. It introduces RuboCop for code linting, EditorConfig for consistent formatting, and Code Climate for quality analysis. The test suite is migrated from the deprecated RSpec 1.x task runner to RSpec Core, and the Appraisals file is updated to test against Rails 5.2, 6.0, 6.1, and 7.0. Documentation is restructured into a dedicated \docs\ directory built with VitePress, and the README is updated to reflect the new CanCanCan project identity, sponsors, and development workflow.
(repo-wide) · high confidence
Refactor ability module into separate concerns and improve strong parameter support
The \lib/cancan/ability\ module has been refactored to separate action aliasing, rule management, and strong parameter support into distinct sub-modules (\Actions\, \Rules\, \StrongParameterSupport\). This structural change improves the \permitted\_attributes\ method used for strong parameters by reversing the rule evaluation order, ensuring that 'can' rules add attributes before 'cannot' rules remove them, which fixes potential issues with attribute exclusion. Additionally, the implementation now uses \attribute\_names\ from ActiveRecord models to determine permitted attributes when no specific attributes are defined in a rule, replacing previous database column detection logic.
lib/cancan/ability · high confidence
Refactored model adapters with version-specific implementations and condition normalization
The model adapter layer has been restructured to support Rails 4.2 through 7.2 with distinct adapter classes (\ActiveRecord4Adapter\, \ActiveRecord5Adapter\) that handle version-specific SQL generation, enum matching, and connection management. This change introduces automatic detection of Single Table Inheritance (STI) to expand rules for subclasses, normalizes \has\_many :through\ associations in conditions, and adds a configurable rules compressor for performance optimization. Users benefit from improved compatibility with modern Rails versions, correct handling of nested and polymorphic associations, and optimized query generation.
_lib/cancan/model\adapters · high confidence
Updated ability.rb generator template for cancancan
The generated Ability class template now includes the \\# frozen\_string\_literal: true\ directive and updates the documentation comments to reference the \cancancan\ gem and its associated wiki, ensuring new projects scaffolded with this generator align with the current library's conventions and documentation.
lib/generators/cancan/ability/templates · high confidence
Test coverage
Added changelog validation and updated RSpec test infrastructure; Added comprehensive test suite for CanCan controller and ability logic; Added test support helpers for database connectivity and ability mocking; Expanded test coverage for model adapters and conditions handling.
Dependencies
Add VitePress for documentation site
The project now includes a VitePress-based documentation site, adding VitePress as a dependency and providing npm scripts to build, preview, and develop the docs locally.
(dependencies) · high confidence
Expanded Rails version support in test configuration
The gemfiles directory has been updated to include new Appraisal configurations for ActiveRecord versions 6.0.0, 6.1.0, 7.0.0, and 7.1.0, as well as a configuration pointing to the Rails main branch. This change enables the library to be tested against a broader range of Rails versions, ensuring compatibility with recent releases and upcoming development versions.
gemfiles · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 68 (+19.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 85 → 100 (+14.8)
- Architecture 96 → 96 (+0.7)
- Maturity 59 → 56 (-2.8)
- Readiness 25 → 62 (+36.9)
- Security 72 → 89 (+17.5)
Resolved (84)
- (anonymous) (cognitive 16) (docs/.vitepress/cache/deps/[e-mail redacted])
- (anonymous) (cognitive 18) (docs/.vitepress/cache/deps/chunk-ZEI2HCB7.js)
- (anonymous) (cognitive 50) (docs/.vitepress/cache/deps/vitepress___minisearch.js)
- (anonymous) (cyclomatic 37) (docs/.vitepress/cache/deps/vitepress___minisearch.js)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- FileTooLong: deps/chunk-ZEI2HCB7.js (docs/.vitepress/cache/deps/chunk-ZEI2HCB7.js)
- FileTooLong: deps/[e-mail redacted] (docs/.vitepress/cache/deps/[e-mail redacted])
- FileTooLong: deps/[e-mail redacted] (docs/.vitepress/cache/deps/[e-mail redacted])
- FileTooLong: deps/vitepress___mark__js_src_vanilla__js.js (docs/.vitepress/cache/deps/vitepress___mark__js_src_vanilla__js.js)
- FileTooLong: deps/vitepress___minisearch.js (docs/.vitepress/cache/deps/vitepress___minisearch.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 64 more
New (23)
- Documentation: no project overview (docs/index.md)
- Duplicate authorization enforcement with different signatures. The ControllerAdditions module exposes authorize! which likely delegates to or wraps the Ability's authorize!. However, exposing both creates confusion about whether the user should call the instance method on the Ability object or the module method on the controller. The controller method is a convenience wrapper, but the existence of both suggests a lack of clear boundary between the core domain logic (Ability) and the framework integration (Controller).
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No dependency advisory monitoring
- Off-boarding risk: anonymized user #1
- Orphaned files with no living knowledge
- …and 3 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- (root) — 1 commit
Notable commits
- change: Update appraisals (#863)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
CanCanCommunity/cancancan was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d1536bbd2d892975ea06f5bf9316e55cbded37e1 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.