mdp/rotp
59.7
Adequate · 19 September 2026
443
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is a Ruby library for generating and verifying One-Time Passwords (OTP) according to HOTP and TOTP standards. It provides core cryptographic functionality for token generation, including support for time drift and counter retries, alongside a command-line interface for direct usage. The library also handles the creation of provisioning URIs for authenticator app integration and implements its own Base32 encoding to minimize external dependencies.
Features
Executable CLI entry point for OTP generation
A new executable script at bin/rotp has been added, allowing users to generate TOTP and HOTP codes directly from the command line. The script initializes the Ruby load path to include the library directory and invokes the ROTP::CLI interface to handle user arguments.
bin · high confidence
New URI class for generating OTP provisioning links
A new ROTP::OTP::URI class has been introduced to generate standard otpauth:// provisioning URIs for TOTP and HOTP secrets. This allows users to easily create scannable QR code data or manual entry strings that include standard parameters (secret, issuer, algorithm, digits, period) as well as any custom provisioning parameters defined on the OTP object, facilitating integration with authenticator apps that support non-standard params like icons.
lib/rotp/otp · high confidence
Behavioural changes
ROTP 6.3.1: New CLI, Base32, and enhanced TOTP/HOTP verification
This release introduces a new command-line interface (lib/rotp/cli.rb) for generating TOTP and HOTP codes, alongside a pure-Ruby Base32 implementation (lib/rotp/base32.rb) that replaces external dependencies. The core OTP classes now support provisioning URIs with issuer and account name parameters, and verification methods have been enhanced: TOTP\#verify now supports time drift (drift\_ahead/drift\_behind) and anti-replay (after), while HOTP\#verify supports counter retries. Additionally, verification uses constant-time comparison to mitigate timing attacks, and the library version is bumped to 6.3.1.
lib/rotp · high confidence
Refactor library structure and dependencies
The library has been restructured to use a native Base32 implementation (lib/rotp/base32) instead of the external 'base32' gem, and now explicitly requires 'openssl' and 'erb' at the top level. The main module has been renamed from 'Rotp' to 'ROTP', and a new URI handler (lib/rotp/otp/uri) has been introduced to support provisioning URIs for both HOTP and TOTP.
lib · high confidence
Test coverage
Added comprehensive test coverage for OTP generation, CLI, and Base32 utilities; Added tests for ROTP::OTP::URI generation; Updated RSpec configuration and added code coverage reporting.
Dependencies
Update gemspec and move development dependencies
The gemspec now declares a minimum Ruby version of 2.3 and includes development dependencies for rake, rspec, simplecov, and timecop, which have been removed from the Gemfile. The base32 dependency has been removed from the gemspec, and the homepage URL has been updated to the GitHub repository.
(dependencies) · high confidence
Housekeeping
Repository maintenance and infrastructure updates
This change introduces several infrastructure and documentation updates: it adds a .dockerignore file, new Dockerfiles for Ruby 2.3, 2.7, and 3.0, and a docker-compose.yml to facilitate testing across these versions. It also adds a Guardfile for automated test running, a LICENSE file, and a release-please configuration. The Rakefile has been removed, and the .gitignore has been updated to exclude .yardoc, coverage, and Gemfile.lock.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 60.
Lenses
- Code Health 100
- Architecture 69
- Maturity 47
- Readiness 69
- Security 68
Changes since last survey
- 292 commits — 255 feature/other, 37 fixes
By area
- (root) — 135 commits
- lib/rotp — 70 commits
- (repo) — 58 commits
- .github/workflows — 10 commits
- spec/lib — 6 commits
- bin/rtotp — 2 commits
- doc/ROTP — 2 commits
- lib/rotp.rb — 2 commits
- spec/spec_helper.rb — 2 commits
- .devcontainer/Dockerfile — 1 commit
- .devcontainer/devcontainer.json — 1 commit
- .github/dependabot.yml — 1 commit
- spec/base_spec.rb — 1 commit
- spec/totp_spec.rb — 1 commit
Notable commits
- fix: 1.7.1 revert breaking api
- fix: Add in encoding fix for 6.0.0
- fix: Bug fix: (in spec) regexp didn't test the full string, only a single char
- fix: Bug fix: TOTP#verify_with_drift produced wrong result when drift was not a multiple of interval
- fix: Bug fix: make #verify accept a string too, like the doc says
- fix: Bump version for padding fix
- fix: Bump version, revert changes
- fix: Fix 'erb' require, remove redundant rakefile, update README
- fix: Fix Base32 implementation, closes #16
- fix: Fix PR link
- fix: Fix Travis CI
- fix: Fix Travis badge
- fix: Fix a bug with base32, fixes #14
- fix: Fix bundler for travis
- fix: Fix documentation and cli help output
- fix: Fix gemspec for travis
- fix: Fix issue when using --enable-frozen-string-literal Ruby option
- fix: Fix links to RFCs
- fix: Fix sample code
- fix: Fix the issue of case sensitivity
- …and 272 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mdp/rotp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit bad1a3564fdc030422c2fb009e9341413814e9cb — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.