Skip to content
CAI
Software that uses CAICheck a score

jaliss/securesocial

39.0

Weak · 27 September 2026

6.7k

lines of production code

Scala

with JavaScript, Java

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release delivers the initial scaffolding and core architecture for SecureSocial 2, introducing a comprehensive set of abstractions for authentication, identity, and eventing. The framework now supports a wide range of OAuth1/OAuth2 providers, password-based login, and account linking, all backed by new service interfaces and Java/Scala APIs. Additionally, the project migrates to Play 2.6 and SBT 1.1.1, while providing default UI templates, email utilities, and demo applications to illustrate integration patterns.

Features

Add default configuration for SecureSocial redirect targets

Introduces a new default configuration file for SecureSocial that defines the default redirect URLs for various authentication and account management steps, including login, logout, sign-up, password reset, and password change. This establishes the baseline behavior for where users are redirected after these actions.

module-code/conf/securesocial · high confidence

Add demo application configuration files for SecureSocial 2

The Java demo application now includes configuration files (application.conf, routes, and securesocial.conf) that define the application's secret key, internationalization, logging, and SecureSocial 2 settings. These files configure OAuth providers (Twitter, Facebook, Google, LinkedIn, Soundcloud, GitHub, Foursquare, Dropbox, XING) and set up the authentication routes, enabling the demo to function with the new SecureSocial 2 framework.

samples/java/demo/conf · high confidence

Added Bootstrap 2.0.3 CSS assets to the public directory

The SecureSocial module now includes the Bootstrap 2.0.3 CSS framework (both standard and minified versions) in its public assets directory. This change resolves potential conflicts with applications that also use Bootstrap by isolating the styles, ensuring that the framework's responsive design and layout utilities are available for the demo applications and the SecureSocial interface without interfering with the host application's own stylesheets.

module-code/public · high confidence

Added Java API classes for authorization, password handling, and user actions

Added new Java classes to the \securesocial.core.java\ package, including \Authorization\ and \DummyAuthorization\ for customizing access control, \BasePasswordHasher\ and \BasePasswordValidator\ for password management, \Secured\ and \UserAware\ action classes with their corresponding annotations (\SecuredAction\, \UserAwareAction\) for protecting or making actions user-aware, and \DefaultSecuredActionResponses\ for handling unauthorized/unauthenticated responses. These additions provide a Java-friendly API for implementing custom authorization logic, password validation, and user-aware controllers.

module-code/app/securesocial/core/java · high confidence

Added Java demo application with SecureSocial integration

A new Java-based demo application has been added to the samples directory, demonstrating how to integrate SecureSocial with the Play framework. This includes a DemoModule for dependency injection, an Application controller showcasing secured and user-aware actions, and a WithProvider authorization filter, providing a concrete example of the library's Java API.

samples/java/demo/app/controllers · high confidence

Added Java demo service implementations for SecureSocial 2

Introduced new Java-based service classes in the demo application to support SecureSocial 2. This includes a \DemoUser\ model and an \InMemoryUserService\ that implements the \UserService\ interface, enabling users to manage user identities and authentication states in memory for demonstration purposes.

samples/java/demo/app/service · high confidence

Added default UI templates for login, password change, and error pages

The module now ships with default HTML templates for the login page, password change form, and an unauthorized access error page. These views provide a ready-to-use user interface for authentication flows, including support for external OAuth providers, username/password login, and CSRF protection.

module-code/app/securesocial/views · high confidence

Added demo configuration files for SecureSocial integration

The demo application now includes dedicated configuration files (application.conf, securesocial.conf, routes, and play.plugins) that define the SecureSocial authentication flow, including OAuth2 settings for Twitter, Facebook, Google, LinkedIn, Soundcloud, GitHub, Foursquare, Dropbox, and Xing, as well as cookie and redirect behavior.

samples/scala/demo/conf · high confidence

Added email notification and password management utilities

Added new utility classes for sending email notifications and managing password hashing/validation. The Mailer trait and its Default implementation provide methods for sending various system emails (e.g., password reset, welcome, sign-up) using Play's mailer client. Additionally, the PasswordHasher and PasswordValidator traits and their default implementations are introduced, enabling configurable password hashing (via BCrypt) and validation (minimum length checks) within the secure social core providers.

module-code/app/securesocial/core/providers/utils · high confidence

Added email templates for password reset, account confirmation, and notifications

The module now includes new email templates for password reset, account confirmation, and notifications. Specifically, it adds templates for welcome emails, sign-up confirmation, password change notices, and alerts for already-registered or unknown email addresses. These templates utilize the BasicProfile and RuntimeEnvironment to generate dynamic content, such as user names and route URLs, for various authentication-related email communications.

module-code/app/securesocial/views/mails · high confidence

Added internationalization (i18n) message files for login, signup, and password workflows

The module now includes localized message files for multiple languages, including Arabic, German, Greek, Spanish, Finnish, French, Hebrew, Hungarian, Japanese, Dutch, Polish, Brazilian Portuguese, Russian, Serbian, Swedish, Turkish, and Simplified Chinese. These files provide translated text for the login, sign-up, password reset, and email notification templates, enabling the application to display interface text in the user's preferred language.

module-code/conf · high confidence

Added new social authentication providers

Added new OAuth2 and OAuth1 providers for Concur, Dropbox, Facebook, Foursquare, GitHub, Google, Instagram, LinkedIn (both OAuth1 and OAuth2), Slack, Soundcloud, Spotify, Twitter, Vk, Weibo, and Xing, as well as a UsernamePassword provider for email/password authentication. This expands the range of social networks and authentication methods supported by the application.

module-code/app/securesocial/core/providers · high confidence

Added password reset and user registration views

The SecureSocial module now includes new template files for the password reset and user registration flows. Specifically, it adds views for starting a password reset, completing the password reset, starting a new user sign-up, and the actual sign-up form. These templates handle the user interface for requesting a password reset email, entering a new password, and creating a new account via email validation.

module-code/app/securesocial/views/Registration · high confidence

Added sample Scala demo service implementations for user and event handling

The demo application now includes concrete implementations for the user service and environment configuration. A new InMemoryUserService provides an in-memory store for user profiles and tokens, implementing methods for finding, saving, and linking users, as well as updating password information. The MyEnvironment class wires up this service and custom providers into the runtime environment. Additionally, a MyEventListener is added to log login, logout, signup, password reset, and password change events, allowing developers to see how to hook into the framework's event system.

samples/scala/demo/app/service · high confidence

Added sample views for account linking and user details

The Java demo application now includes new views for displaying user profile details and managing linked accounts. The index view presents the current user's identity, authentication method, and OAuth information, while also providing links to change passwords and link additional social accounts. A new linkResult view displays the list of currently linked identities and their associated profile data, allowing users to see which accounts are connected to their profile.

samples/java/demo/app/views · high confidence

Added test-kit helpers for unit and integration testing of SecureSocial controllers

The test-kit module now includes new Scala classes and objects to facilitate testing of SecureSocial controllers. This includes an AlwaysValidIdentityProvider for simplified authentication during tests, a FakeAuthenticatorStore to manage test state, a SocialUserGenerator to create mock users, and a WithLoggedUser base class that automatically configures a mock UserService and authenticator store for test scenarios.

test-kit · high confidence

Demo apps now include Bootstrap v2.0.3 stylesheets

The Java and Scala demo applications now include the Bootstrap v2.0.3 CSS framework, adding \bootstrap.css\, \bootstrap.min.css\, \bootstrap-responsive.css\, and \bootstrap-responsive.min.css\ to the public assets directory. This provides a consistent, responsive design system for the demo applications.

samples/java/demo/public, samples/scala/demo/public · high confidence

Initial configuration for SecureSocial 2

The project now includes the initial configuration files for SecureSocial 2, introducing a new 'conf' directory containing 'play.plugins' and 'securesocial.conf'. The 'play.plugins' file registers the InMemoryUserService and the Twitter, Facebook, and Google authentication providers. The 'securesocial.conf' file provides the default settings for these social providers, including placeholders for consumer keys and client IDs, and includes default configuration values.

conf · high confidence

Initial project scaffolding and documentation

Added the initial project structure including a .gitignore file to exclude build artifacts and IDE files, a .travis.yml file to configure continuous integration for Scala 2.11 and 2.12, a ChangeLog to track version history, and documentation files (README, license, and icon attributions) to establish the repository's baseline.

(repo-wide) · high confidence

Introduces core authentication, identity, and eventing abstractions

The core module now provides the foundational types for the authentication framework, including the \AuthenticationMethod\ to distinguish between OAuth1, OAuth2, OpenID, and password-based logins, and the \Event\ system to track login, logout, signup, and password change activities. The \IdentityProvider\ base class and its \OAuth1Provider\/\OAuth2Provider\ implementations define the standard flow for external identity providers, while \SecureSocial\ introduces \SecuredAction\ and \UserAwareAction\ to protect routes and retrieve the current user. Additionally, \UserProfile\ and \BasicProfile\ define the user data model, and \RuntimeEnvironment\ centralizes the services (like \AuthenticatorService\ and \CacheService\) required for the framework to operate.

module-code/app/securesocial/core · high confidence

New controllers for login, registration, password reset, and password change

The SecureSocial module now provides default controller implementations for core authentication flows. This includes a new LoginApi for programmatic/mobile authentication, a LoginPage for standard web login, and dedicated controllers for user registration, password reset, and password changes. These controllers handle the associated form submissions, token validation, and redirection logic, making these features available out-of-the-box.

module-code/app/securesocial/controllers · high confidence

New core service abstractions and implementations

The framework introduces a set of new core services to decouple functionality and improve testability. These include \AuthenticatorService\ for managing authenticator builders, \AvatarService\ for retrieving user avatars, \CacheService\ for caching operations, \HttpService\ for HTTP client interactions, \RoutesService\ for URL generation, and \UserService\ for user profile and token management. These services provide interfaces and default implementations that replace previous hardcoded or tightly coupled logic, allowing for easier customization and integration with different backends.

module-code/app/securesocial/core/services · high confidence

Behavioural changes

Added account linking and password change views to the Scala demo app

The Scala demo application now includes new views to support account linking and password management. The index page displays user details, OAuth information, and provides links to change passwords or link additional accounts. A new 'linkResult' view displays the details of all linked accounts, allowing users to see their connected identities. These changes reflect the library's new support for linking accounts and customizing views via the TemplatesPlugin.

samples/scala/demo/app/views · high confidence

Build system upgraded to Play 2.6 and SBT 1.1.1

The project's build configuration has been updated to support Play version 2.6.12 (default) and Scala 2.12.6 (default, with 2.11.12 as a cross-version). The SBT version is set to 1.1.1, and the build includes the Play sbt plugin, Scalariform, and sbt-pgp 1.1.1 for artifact signing.

project · medium confidence

Introduces configurable execution contexts for authenticators

The authenticator components in the \securesocial/core/authenticator\ package now accept an \ExecutionContext\ as a parameter, replacing previously hardcoded execution contexts. This change allows the asynchronous execution context used by the \AuthenticatorStore\ and related classes to be injected or configured externally, rather than relying on a default or static context.

module-code/app/securesocial/core/authenticator · high confidence

Updated Scala demo app to use Play 2.6 and dependency injection

The Scala demo application has been migrated to Play 2.6, adopting the standard Play dependency injection pattern via Guice. The \Application\ controller now uses constructor injection for \ControllerComponents\ and the \RuntimeEnvironment\, replacing the previous \SecureSocialController\ base class approach. A new \DemoModule\ is introduced to bind the \RuntimeEnvironment\ to a custom \MyEnvironment\ implementation. Additionally, a \CustomLoginController\ is added to demonstrate how to override the default login page, and the \Application\ controller now explicitly implements an authorization check for Twitter users using the \WithProvider\ helper.

samples/scala/demo/app/controllers · high confidence

Test coverage

Added unit and integration tests for the demo application; Added unit tests for OAuth clients and authentication providers.

Dependencies

Migrated to Play 2.6 and modernized build structure

The project has been upgraded to support Play 2.6, introducing an authenticator cookie for tracking users instead of relying on the Play session. The build structure was refactored into a multi-project SBT setup, separating the core library, a Scala demo, and a Java demo. Additionally, the documentation build was updated to use Middleman 3.2.1.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 39 → 39 (+0.0)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 97 (-2.5)
  • Architecture 69 → 93 (+23.8)
  • Maturity 22 → 24 (+1.8)
  • Readiness 24 → 60 (+35.3)
  • Security 100 → 87 (-13.3)
  • Accessibility 26 (new)

Resolved (7)

  • Customizing SecureSocial Templates is described but the accompanying plugin creation steps (implementing TemplatesPlugin trait) are not shown in the visible portion. (views-customization.md)
  • Dimension evaluation failed
  • No automated tests
  • No exposed public API
  • No tests found
  • Test reliability not included
  • The Customizing SecureSocial Static Files section lists Bootstrap CSS but does not explain how to load an external version of Bootstrap (e.g. CDN) instead of the default one. (views-customization.md)

New (23)

  • BaseLoginApi.authenticate (cognitive 17) (module-code/app/securesocial/controllers/LoginApi.scala)
  • BaseProviderController.handleAuth (cognitive 31) (module-code/app/securesocial/controllers/ProviderController.scala)
  • BaseRegistration.handleSignUp (cognitive 19) (module-code/app/securesocial/controllers/Registration.scala)
  • Documentation: written for insiders (docs/src/manual/source/guide/authorization.md)
  • Dormant codebase
  • Duplicated block (5 lines × 2) (module-code/app/securesocial/core/providers/GitHubProvider.scala)
  • Duplicated block (6 lines × 2) (module-code/app/securesocial/core/providers/LinkedInOAuth2Provider.scala)
  • Duplicated block (9 lines × 2) (module-code/app/securesocial/core/providers/GoogleProvider.scala)
  • Duplicated block (9–10 lines × 2) (module-code/app/securesocial/core/providers/LinkedInOAuth2Provider.scala)
  • FileTooLong: js/bootstrap.js (module-code/public/securesocial/bootstrap/js/bootstrap.js)
  • No ADRs found
  • No SBOM
  • No build provenance
  • No dependency advisory monitoring
  • OAuth1Provider.authenticate (cognitive 17) (module-code/app/securesocial/core/OAuth1Provider.scala)
  • Outdated: pygments.rb
  • TodoComment (module-code/app/securesocial/controllers/LoginApi.scala)
  • TodoComment (module-code/app/securesocial/controllers/ProviderController.scala)
  • TodoComment (module-code/app/securesocial/controllers/Registration.scala)
  • TodoComment (module-code/app/securesocial/core/OAuth2Provider.scala)
  • …and 3 more

Architecture

  • Containers 0 added · 0 removed · contexts 3 added · 0 removed · edges 2 added · 0 removed

Added bounded contexts (3)

  • demo
  • module-code
  • repository

Added dependency edges (2)

  • demo → module-code (coupling)
  • repository → module-code (coupling)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jaliss/securesocial was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0f9710325724da34a46c5ecefb439121fce837b7 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.