Skip to content
CAI
Software that uses CAICheck a score

jeremyevans/rodauth

58.7

Adequate · 19 September 2026

8.4k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Rodauth is a modular authentication library for the Roda web framework that provides comprehensive identity management capabilities, including login, password handling, and multi-factor authentication via TOTP and WebAuthn. It supports advanced security features such as active session tracking, account expiration, audit logging, and database-level password hashing functions. The system is designed for flexibility, allowing developers to configure specific authentication flows and integrate with various database backends like PostgreSQL, MySQL, and SQLite.

How it got here

2015 — Modular authentication and demo site launch

11 changes.

This period focused on restructuring the Rodauth plugin internals to support modular features and modernizing the UI with Bootstrap 4 templates. The work included expanding test coverage for core authentication flows, releasing the initial gemspec, and launching a comprehensive demo site to showcase the new capabilities.

2016–2021 — public website launch and internal refactoring

10 changes.

This period focused on establishing a public-facing documentation website to improve user onboarding and community engagement, alongside significant internal refactoring of the Rodauth library's configuration and feature DSL. The work also expanded core authentication capabilities by introducing WebAuthn support, account expiration management, and database function migration helpers, while enhancing test coverage for multiple SQL backends.

Features

Add WebAuthn authentication and setup support with autofill capability

New JavaScript modules (webauthn\_auth.js, webauthn\_setup.js, webauthn\_autofill.js) enable WebAuthn-based login, credential setup, and conditional autofill. The auth and setup scripts handle credential creation and retrieval by unpacking base64web-encoded challenges and credential IDs, packing the resulting authenticator responses, and submitting them via hidden form fields. The autofill script leverages the WebAuthn conditional mediation API to automatically prompt users for credentials when available, enhancing login convenience without requiring explicit user interaction.

javascript · high confidence

Add database function migration helpers and version constants

The library now includes a new \lib/rodauth/migrations.rb\ module that provides \create\_database\_authentication\_functions\ and \drop\_database\_authentication\_functions\ methods. These methods generate database-specific SQL functions (for PostgreSQL, MySQL, and Microsoft SQL Server) to handle password hashing and validation securely within the database, supporting both standard and Argon2 hashing schemes. Additionally, \lib/rodauth/version.rb\ introduces explicit \MAJOR\, \MINOR\, \TINY\, and \VERSION\_NUMBER\ constants, along with a \version\ method, to expose the current library version (2.47.0) programmatically.

lib/rodauth · high confidence

Add public website with documentation pages

A new public website has been added to the project, featuring a responsive layout built with Bootstrap and syntax highlighting for code examples. The site includes navigation links to 'Why', 'Documentation', and 'Development' sections, and is generated via a Ruby script that compiles ERB templates into static HTML files in the public directory.

www · high confidence

Add website styling and logo assets

The website now includes a dedicated CSS stylesheet and an SVG logo image. The stylesheet defines the visual appearance of the site, including a blue navigation bar, specific typography using 'Open Sans' and 'PT Mono', and color schemes for text and backgrounds. The new logo image displays the 'Rodauth' text centered within the icon, ensuring consistent branding across the site.

www/public · high confidence

Documentation for new authentication features and configuration methods

This release adds comprehensive documentation for several new Rodauth features, including account expiration, active sessions, audit logging, and the argon2 password hashing algorithm. It also documents new configuration methods for the base feature, such as \hmac\_secret\ for HMAC-based token security, \check\_csrf?\ for CSRF protection, and various input field attributes for accessibility and styling. The changelog is moved to \CHANGELOG.old\ to make room for the new version history.

doc · high confidence

Initial website launch with documentation and feature overview

The website is now available, providing users with a central hub to understand Rodauth's capabilities. The index page offers a quick-start code example for setting up authentication in a Roda application. The 'Why' page details the framework's security, simplicity, and flexibility advantages over other Ruby authentication libraries, while listing its extensive feature set including WebAuthn, TOTP, JWT, and various password management tools. The documentation page serves as a comprehensive index, linking to RDoc for all built-in features (such as Base, Email Base, and specific plugins like OTP, WebAuthn, and JWT), a collection of configuration guides, and links to external community gems like rodauth-oauth and rodauth-rails. Additionally, a development page outlines how to report bugs, contribute code, and join the community discussion forums.

www/pages · high confidence

Introduce demo site with comprehensive Rodauth features

The demo site is now available, providing a fully functional example application built on Roda and Rodauth. It enables a wide range of authentication features including login, logout, password management, TOTP 2FA, WebAuthn (when enabled via environment variables), JWT support, and session management. The site uses an in-memory SQLite database by default (or PostgreSQL if DATABASE\_URL is set), simulates email and SMS delivery for testing, and includes security measures like CSRF protection and file upload disallowance.

demo-site · high confidence

New account expiration and active session management features

This update introduces two new authentication capabilities. The account expiration feature allows administrators to automatically expire accounts based on inactivity or last login time, preventing access for dormant users. The active sessions feature enables tracking of all user sessions, allowing for global logout across all devices and automatic expiration of inactive sessions based on configurable inactivity and lifetime deadlines.

lib/rodauth/features · high confidence

Behavioural changes

Complete overhaul of authentication templates to support modular features and Bootstrap 4/5

The authentication UI templates have been completely rewritten to support a modular feature set (including WebAuthn, TOTP, SMS, email auth, and account management) and to be compatible with Bootstrap 4 and 5. The previous monolithic login form has been replaced by a composition of smaller, reusable sub-templates (e.g., \login-field\, \password-field\, \button\) that allow for granular configuration of form elements, labels, and error handling. This change introduces new pages and flows for two-factor authentication setup/management, password resets, account verification, and WebAuthn login, while also improving security by using HMACed secrets for OTP keys and preventing key leakage in referer headers.

templates · high confidence

Initial demo site interface with Bootstrap 4 styling

The demo site now features a new user interface built with Bootstrap 4, including a responsive layout and styled error messages. The home page displays the current authentication status, distinguishing between single-factor and multifactor (two-factor) login methods, and provides navigation links to account management actions such as changing login credentials, closing the account, and managing multifactor authentication settings.

demo-site/views · high confidence

Major refactoring of Rodauth plugin internals and removal of legacy code

The Rodauth plugin has undergone a significant internal restructuring. The previous implementation, which relied on a complex DSL with \Wrapper\ classes, dynamic method definition via \def\_auth\_method\, and a hardcoded list of \SUPPORTED\_FEATURES\, has been completely removed. The new codebase is significantly smaller, relying on standard Ruby patterns and enabling frozen string literals for performance and safety. This change likely breaks compatibility with any custom configurations or extensions that depended on the old DSL methods (such as \def\_auth\_method\, \def\_auth\_scope\_method\, or the \Wrapper\ class) and removes the explicit validation against a fixed set of features, allowing for more flexible feature integration.

lib/roda · medium confidence

New documentation guides for Rodauth configuration and features

The documentation has been reorganized into a new 'guides' directory, replacing the previous 'howto' structure. This update introduces a comprehensive set of new reference guides covering specific Rodauth configuration scenarios, including admin account activation, alternative login methods (such as usernames), case-insensitive logins, and customizing route paths and redirects. It also provides detailed instructions for managing password requirements, migrating hash algorithms (e.g., bcrypt to argon2), storing data in custom columns, and implementing multifactor authentication workflows. Additional guides address programmatic account creation, internationalization, and sharing configuration via inheritance.

doc/guides · high confidence

Refactored Rodauth configuration and feature DSL internals

The Rodauth authentication library has undergone significant internal refactoring to improve code structure and maintainability. Configuration classes are now defined as constants, and the feature DSL has been restructured to use a dedicated \FeatureDSL\ module for easier handling. Route handling has been optimized by replacing arrays of route blocks with arrays of methods, and the system now executes block handling within the \Rodauth::Auth\ instance scope. Additionally, several internal methods have been made private, unnecessary conditionals and \to\_sym\ calls have been removed, and the library now supports shape-friendly routing for better compatibility with modern Roda versions.

rodauth · medium confidence

Test coverage

Add CI gemfile for multi-version Ruby testing; Added SQL setup and teardown scripts for MSSQL and MySQL test environments; Added migration tests for OTP unlock and SQLite JSONB support; Added view templates for authentication spec tests; Expanded test coverage for core authentication features; Expanded test migration schema with multi-database and UUID support; Updated password migration tests to support multi-database and new features.

Dependencies

Initial gemspec release for Rodauth

The Rodauth gem is now available for installation, defining runtime dependencies on Sequel (\>= 4) and Roda (\>= 2.6.0), while listing development dependencies such as bcrypt, argon2, JWT, and WebAuthn to support its authentication features.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 59.

Lenses

  • Code Health 100
  • Architecture 99
  • Maturity 54
  • Readiness 57
  • Security 85
  • Accessibility 52

Changes since last survey

  • 300 commits — 269 feature/other, 31 fixes

By area

  • (root) — 151 commits
  • lib/rodauth — 65 commits
  • doc/guides — 10 commits
  • .github/workflows — 9 commits
  • spec/rodauth_spec.rb — 7 commits
  • spec/spec_helper.rb — 7 commits
  • www/pages — 5 commits
  • demo-site/rodauth_demo.rb — 3 commits
  • demo-site/views — 3 commits
  • doc/json.rdoc — 3 commits
  • doc/release_notes — 2 commits
  • doc/webauthn_autofill.rdoc — 2 commits
  • lib/rodauth.rb — 2 commits
  • spec/otp_unlock_spec.rb — 2 commits
  • spec/remember_spec.rb — 2 commits
  • doc/CHANGELOG.old — 1 commit
  • doc/active_sessions.rdoc — 1 commit
  • doc/argon2.rdoc — 1 commit
  • doc/disallow_common_passwords.rdoc — 1 commit
  • doc/error_reasons.rdoc — 1 commit

Notable commits

  • fix: Conclude registration field guide fix (#472)
  • fix: Fix CSRF checks on demo site
  • fix: Fix Roda method arity warning on demo site
  • fix: Fix Ruby 1.9 support
  • fix: Fix check_method_doc task
  • fix: Fix code in registration field guide
  • fix: Fix code in registration field guide, again
  • fix: Fix code tag in README
  • fix: Fix code tag syntax in JSON feature docs
  • fix: Fix compatibility with JWT 2.10+
  • fix: Fix db_setup_postgres rake task to work on PostgreSQL 15+
  • fix: Fix descriptions in otp_modify_email spec
  • fix: Fix duplicate active sessions when creating and verifying account
  • fix: Fix instance_variables_to_inspect place
  • fix: Fix issue where we accidentally accept a non-confirmed SMS code during sign in
  • fix: Fix login_form_footer documentation (Fixes #409)
  • fix: Fix spec authorization header to not use a newline (Fixes #330)
  • fix: Fix spec failures on Ruby 3.4.0-preview2 related to Hash#inspect change
  • fix: Fix strict_unused_block warnings when running specs on Ruby 3.4
  • fix: Fix update_password_hash spec descriptions
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jeremyevans/rodauth was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 300b56b0871a498972a44f91fc1d015d468886b2 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.