Skip to content
CAI
Software that uses CAICheck a score

heartcombo/devise

63.3

Adequate · 26 September 2026

5.8k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release delivers Devise 5.0.4, headlined by critical security fixes for open redirect and race condition vulnerabilities. The update introduces a comprehensive suite of default controllers, mailers, and views that modernize the user experience with HTML5 semantics, accessibility improvements, and Hotwire/Turbo compatibility. Internally, the codebase has been significantly refactored into modular components and generators, while adding support for Rails 8.1 and Ruby 2.7+.

Features

Add ActiveRecord generator for Devise migrations

Introduced a new ActiveRecord generator that creates Devise-related database migrations. The generator now supports specifying a custom primary key type via the \--primary-key-type\ option. It also adapts the generated migration schema based on the database adapter, using \inet\ columns for PostgreSQL and \string\ for others, and includes logic to handle existing models or revoking migrations.

_lib/generators/active\record · high confidence

Add Mongoid generator for Devise integration

A new generator at lib/generators/mongoid/devise\_generator.rb has been introduced to support Devise with the Mongoid ORM. This generator handles the creation of the model and injects the necessary field definitions (such as email, encrypted\_password, and reset\_password\_token) into the Mongoid document, while explicitly excluding the 'trackable' module fields.

lib/generators/mongoid · medium confidence

Add Rails 7.0, 7.1, 7.2, 8.0, and main branch test configurations

New Gemfile configurations have been added to enable testing against Rails versions 7.0, 7.1, 7.2, 8.0, and the Rails main branch. Each configuration specifies the corresponding Rails version, along with compatible versions of dependencies such as Mongoid and SQLite3, ensuring the library's compatibility across these environments.

gemfiles · high confidence

Add controller templates for customizing Devise authentication flows

The generator now provides pre-built controller templates for Confirmations, OmniauthCallbacks, Passwords, Registrations, Sessions, and Unlocks, each containing commented-out method overrides. This allows users to easily customize authentication behavior by uncommenting and modifying specific actions in their own controllers. Additionally, a README template is included to guide users on overriding routes for the generated controllers.

lib/generators/templates/controllers · high confidence

Add default Devise controllers for authentication flows

The application now includes default implementations for Devise's authentication controllers, including Confirmations, OmniauthCallbacks, Passwords, Registrations, Sessions, and Unlocks. These controllers handle standard user flows such as signing in, signing out, registering new accounts, resetting passwords, confirming email addresses, and unlocking accounts. Each controller defines the necessary actions (e.g., new, create, edit, update, destroy) and protected helper methods for redirects and flash messages, providing a complete, out-of-the-box authentication experience.

app/controllers/devise · high confidence

Add default email templates for Devise mailers

The application now includes default HTML email templates for Devise authentication events, including account confirmation, email change notifications, password changes, password resets, and account unlocks. These templates provide users with clear, formatted notifications for each security-related action, ensuring consistent and readable email content across the application.

app/views/devise/mailer · high confidence

Add new migration templates for Devise model generation

The generator now includes dedicated ERB templates for creating ActiveRecord migrations: a new template for initial model creation and a separate template for adding Devise fields to an existing model. The initial migration template uses the modern \.change\ method for Rails 3.1+, while the existing model template uses the \.up\/\.down\ pattern with an irreversible rollback, ensuring users get appropriate migration code whether they are creating a new model or modifying an existing one.

_lib/generators/active\record/templates · high confidence

Add simple\_form\_for template for confirmation resend

A new template for the confirmation resend page is added at lib/generators/templates/simple\_form\_for/confirmations/new.html.erb. It renders a form to resend confirmation instructions, including an email input with autofocus and autocomplete, displays the confirmation token error, and includes shared links.

_lib/generators/templates/simple\_form\for/confirmations · medium confidence

Add simple\_form\_for template for unlock page

A new template for the unlock page is added to the simple\_form\_for generator, providing a form that allows users to request a new unlock token via email. The form includes an email input with autofocus enabled and renders shared links.

_lib/generators/templates/simple\_form\for/unlocks · high confidence

Add simple\_form\_for templates for Devise registration and session views

The generator now includes new ERB templates for the registration (edit, new) and session (new) views, styled with Simple Form. These templates provide the default UI for user sign-up, account editing, and login, incorporating modern browser features like HTML5 autocomplete hints and Turbo confirmation dialogs for account cancellation.

_lib/generators/templates/simple\_form\for/registrations · high confidence

Added Markdown-based email templates for Devise notifications

New .markerb template files have been added to the generator templates for confirmation, email change, password change, reset password, and unlock instructions. These templates provide Markdown-formatted email content for these authentication flows, giving users a new, more readable email format when these notifications are sent.

lib/generators/templates/markerb · high confidence

Devise routing and Warden compatibility layer

This change introduces the core routing infrastructure for Devise within the Rails application. It adds \lib/devise/rails/routes.rb\, which extends \ActionDispatch::Routing::Mapper\ with the \devise\_for\ method, enabling the automatic generation of authentication routes (sessions, passwords, registrations, etc.) based on configured Devise modules. It also adds \lib/devise/rails/warden\_compat.rb\, which provides a compatibility shim for Warden, ensuring proper request, session, and cookie handling within the Rails environment. This allows developers to integrate Devise authentication into their Rails apps by simply calling \devise\_for\ in their routes file.

lib/devise/rails · high confidence

Extracted mailer logic into a reusable helper module

The mailer functionality has been extracted into a new \Devise::Mailers::Helpers\ module, which provides shared methods for sending emails. This includes the \devise\_mail\ method that initializes the record and generates headers, as well as helper methods for subject translation and template path resolution. This change allows custom mailers to easily inherit and reuse Devise's email-sending logic without duplicating code.

lib/devise/mailers · medium confidence

Initialize Devise configuration and autoload structure

The library's main entry point (lib/devise.rb) is established, defining the central configuration namespace with default settings for authentication, session management, and security (e.g., stretches, timeout, email validation). It also sets up the autoload paths for core components like strategies, controllers, and test helpers, ensuring the framework is ready to load its modules and apply user-defined configurations.

lib · high confidence

Introduce Devise::Mailer with configurable parent mailer and email change notifications

A new Devise::Mailer class is introduced to handle email templates for confirmation, password reset, unlock, email change, and password change notifications. The mailer inherits from a customizable parent mailer (Devise.parent\_mailer), allowing engines and applications to override default behavior. Additionally, the mailer now supports email\_changed and password\_change notifications, enabling users to be notified when their email or password is updated.

app/mailers · high confidence

New OmniAuth configuration and URL helper methods

Added lib/devise/omniauth/config.rb and lib/devise/omniauth/url\_helpers.rb to provide structured configuration for OmniAuth strategies and generate authorization and callback URLs. The config file introduces a StrategyNotFound exception and a Config class that resolves strategies by name or class, while the url\_helpers module defines methods like omniauth\_authorize\_path and omniauth\_callback\_url to route requests to the correct OmniAuth endpoints.

lib/devise/omniauth · high confidence

New generators for Devise controllers, models, and views

The Devise gem now includes new Rails generators to scaffold authentication components directly into your application. The \devise:controllers\ generator creates inherited controller classes for sessions, registrations, passwords, confirmations, unlocks, and OmniAuth callbacks. The \devise\ generator creates a model with Devise configuration and a migration file. The \devise:install\ generator sets up the initializer and locale files, while the \devise:views\ generator copies default view templates. These generators streamline the initial setup and customization of Devise in a Rails app.

lib/generators/devise · high confidence

New test helper modules for controller and integration tests

Added \Devise::Test::ControllerHelpers\ and \Devise::Test::IntegrationHelpers\ to provide dedicated testing utilities. \ControllerHelpers\ allows testing controllers in isolation by enabling \sign\_in\ and \sign\_out\ methods for \ActionController::TestCase\. \IntegrationHelpers\ provides similar \sign\_in\ and \sign\_out\ functionality for \ActionDispatch::IntegrationTest\ by integrating with Warden's test mode. Both modules include the \frozen\_string\_literal\ pragma.

lib/devise/test · high confidence

Security

Release Devise 5.0.4 with security fixes

This release addresses two security vulnerabilities: an open redirect vulnerability in the \FailureApp\ via an unvalidated \Referer\ header ([CVE redacted]), and a race condition in the \confirmable\ module that could allow confirming an email address the user does not own ([CVE redacted]).

(repo-wide) · high confidence

Architecture

Extract authentication hooks into dedicated modules

The authentication logic has been refactored into separate, dedicated hook files (activatable, csrf\_cleaner, forgetable, lockable, proxy, rememberable, timeoutable, and trackable) within lib/devise/hooks. This change organizes Warden manager callbacks into distinct modules, each handling a specific aspect of the authentication lifecycle, such as session timeout, tracking, CSRF cleanup, and account activation.

lib/devise/hooks · high confidence

Refactor authentication models into modular components

The authentication logic in lib/devise/models has been restructured into distinct, modular components (Authenticatable, DatabaseAuthenticatable, Confirmable, Lockable, Recoverable, etc.). This change improves code organization and allows each module to be used or extended independently. Users will see no functional change, but the internal structure is now more maintainable and extensible.

lib/devise/models · high confidence

Refactored authentication strategies into a modular base class

The authentication logic has been restructured into a new \Authenticatable\ base strategy that handles common concerns like parameter and HTTP header parsing, validation, and CSRF cleanup. Specific strategies like \DatabaseAuthenticatable\ and \Rememberable\ now inherit from this base, improving code reuse and allowing other strategies to hook into the authentication flow more cleanly.

lib/devise/strategies · high confidence

Behavioural changes

Add DeviseHelper for backward compatibility

A new \DeviseHelper\ module has been added to the application's helpers directory. This empty module is kept in place to maintain backward compatibility for existing code that may depend on the presence of this helper.

app/helpers · high confidence

Add confirmation resend view with improved UX and security

Introduced a new view for resending confirmation instructions, featuring an email field with HTML5 autofocus and autocomplete attributes for better user experience, while also addressing a potential security leak in the email reconfirmation flow by ensuring the form uses the POST method and rendering error messages via a shared partial.

app/views/devise/confirmations · medium confidence

Centralize Devise controller logic into a single base class

All Devise controllers now inherit from a single \DeviseController\ base class, which centralizes shared behavior such as resource management, flash message handling, and i18n support. This change ensures consistent behavior across all Devise controllers and allows for easier customization by overriding methods in the base controller.

app/controllers · high confidence

Extracted Devise shared views into partials

The error messages and navigation links for Devise are now rendered via new partials: \_error\_messages.html.erb and \_links.html.erb. The error messages partial now includes a data-turbo-temporary attribute on the error explanation container, and the links partial uses button\_to with data-turbo=false for OmniAuth providers, ensuring Hotwire/Turbo compatibility.

app/views/devise/shared · high confidence

Introduce ORM adapter integration for Active Record and Mongoid

Devise now supports multiple ORMs through a modular adapter pattern. The library now includes dedicated integration files for Active Record and Mongoid, which load the corresponding adapters from the \orm\_adapter\ gem and extend the respective document classes with Devise's model functionality. This change replaces the previous monolithic approach, allowing users to choose their preferred ORM while maintaining a consistent API for authentication features.

lib/devise/orm · high confidence

Redesign of the sign-in form with improved accessibility and UX

The sign-in view has been updated to use semantic HTML5 elements, including an email input with autocomplete and autofocus for better user experience. The form now uses 'Log in' instead of 'Sign in', and the layout has been adjusted to use divs with class 'field' instead of paragraphs, aligning with Rails scaffolding conventions. Additionally, the password field includes autocomplete attributes to support browser password managers, and the remember-me checkbox is conditionally rendered.

app/views/devise/sessions · high confidence

Redesign unlock view with HTML5 and improved UX

The unlock page has been updated to use a new template that includes HTML5 attributes for better user experience. Specifically, the email input field now features autofocus and autocomplete set to 'email', and the form method is explicitly set to POST. The layout has also been adjusted to use paragraph tags and a 'field' class for the email input, replacing previous structural elements.

app/views/devise/unlocks · high confidence

Redesigned password reset and change forms with improved UX and accessibility

The password reset (new) and password change (edit) views have been updated to improve user experience and accessibility. The forms now use semantic HTML5 elements, including the 'email' input type for the email field and 'new-password' for password fields, which helps browsers and password managers. Autofocus is enabled on the first input for faster interaction. The layout uses 'div' elements with 'field' and 'actions' classes, aligning with Rails scaffolding conventions. Additionally, the minimum password length is displayed on the change password page, and error messages are rendered via a shared partial.

app/views/devise/passwords · high confidence

Redesigned registration and edit forms with improved structure and accessibility

The registration (sign-up) and edit profile views have been completely rewritten to follow modern Rails scaffolding conventions, using semantic HTML5 elements like \<p\> and \<em\> for better structure. The forms now include HTML5 autocomplete attributes (e.g., 'email', 'new-password') to assist browsers in auto-filling user data, and the edit view includes a confirmation dialog for account deletion. Additionally, the edit view now conditionally displays the minimum password length hint and shows the pending confirmation email if applicable.

app/views/devise/registrations · high confidence

Refactored authentication helpers into modular controller modules

The authentication helpers in lib/devise/controllers have been reorganized into distinct, reusable modules (SignInOut, StoreLocation, UrlHelpers, etc.) that are included in the main Helpers module. This refactoring improves code maintainability and allows for more flexible integration with frameworks like Hotwire/Turbo via the new Responder class, while preserving existing functionality such as sign-in, sign-out, and location storage.

lib/devise/controllers · high confidence

Release Devise 5.0.4

The library has been updated to version 5.0.4. This release includes a security fix for a race condition vulnerability in the \unconfirmed\_email\ attribute, ensuring it is always saved correctly. Additionally, the default encryptor is now set to Bcrypt, which automatically adds a pepper on generation, and the codebase has been refactored to remove deprecated code and improve compatibility with modern Rails versions.

lib/devise · high confidence

Updated Devise initializer template with new default configurations

The generated Devise initializer template has been updated to reflect new default settings and improved documentation. Key changes include enabling \reconfirmable\ by default, setting \expire\_all\_remember\_me\_on\_sign\_out\ to true, and configuring \password\_length\ to 6..128. The template also includes comments explaining the impact of changing the bcrypt stretching factor and provides setup instructions for mailer, routes, and flash messages.

lib/generators/templates · high confidence

Updated simple\_form\_for templates for password reset views

The templates for the password reset flow (new and edit views) have been updated to use simple\_form\_for. The edit view now displays the minimum password length requirement as a hint, includes an autocomplete attribute for new passwords, and renders the shared links partial. The new view includes an email input with autocomplete and autofocus, and also renders the shared links partial.

_lib/generators/templates/simple\_form\for/passwords · high confidence

Test coverage

Add ORM test configuration files for ActiveRecord and Mongoid; Add Rails integration test support for Webrat; Add a dummy Rails application for integration testing; Add bin/test executable for running tests; Add comprehensive generator tests for all Devise generators; Add integration test template for bug reports; Add test app controller for OmniAuth callbacks; Add test helper for RegistrationsController block yielding; Add test support for Rails 4.1 compatibility; Add tests for Devise test helpers; Added ActiveRecord test models for Devise; Added Mongoid test models for authentication strategies; Added application layout template for the test Rails app; Added comprehensive test coverage for all Devise mailers; Added comprehensive test suite for Devise core components; Added controller test suite for Devise; Added integration tests for all authentication modules; Added test controllers for the Rails application; Added test coverage for Webrat compatibility; Added test helper modules for Rails application; Added test mailers for Devise email configuration; Added test support infrastructure for assertions, helpers, and integration testing; Added test view templates for home page; Added test view templates for the admin module; Added tests for Devise helper error messages; Added tests for OmniAuth configuration and URL helpers; Added unit tests for all Devise model modules.

Dependencies

Update dependencies for Rails 8.1 and Ruby 2.7+

The project's dependency manifest has been updated to support Rails 8.1 and enforce a minimum Ruby version of 2.7.0. The Gemfile now specifies Rails 8.1.0, along with updated versions for testing and authentication libraries including omniauth 2.1.4, omniauth-oauth2 1.9.0, and mocha 2.1. The gemspec has been regenerated to reflect the new dependency constraints, including warden \~\> 1.2.3, orm\_adapter \~\> 0.1, and bcrypt \~\> 3.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 50 → 63 (+13.4)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 98 (-1.4)
  • Architecture 94 → 86 (-7.6)
  • Maturity 57 → 54 (-2.5)
  • Readiness 30 → 86 (+55.5)
  • Security 63 → 64 (+1.1)
  • Accessibility 66 (new)

Resolved (10)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Test reliability not included

New (48)

  • Ambiguous naming: 'resend' implies re-sending an existing token or retrying a failed send, while 'send' implies initial generation and sending. However, in the context of Confirmable, both often trigger the same underlying mailer action (confirmation_instructions) but may differ in whether they reset the confirmation token or just re-send. The distinction is not immediately obvious from the names alone, and 'resend' is often a user-facing alias for 'send again'.
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Further orphaned files (smaller)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (Gemfile.lock)
  • Low CVE: [GHSA redacted] (Gemfile.lock)
  • Mapper.devise_for (cognitive 24) (lib/devise/rails/routes.rb)
  • Mapper.devise_for (cyclomatic 20) (lib/devise/rails/routes.rb)
  • …and 28 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

heartcombo/devise was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 372b295fe6f63b4af3269f5dcd51a18c0bc2016c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.