mikker/passwordless
52.9
Adequate · 19 September 2026
820
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is a Ruby gem that provides passwordless authentication for Rails applications, enabling users to sign in via email-based magic links or tokens. It manages the complete lifecycle of authentication sessions, including secure token generation, database storage, and configurable redirect flows. The library is designed to be highly customizable, allowing developers to integrate it with existing controllers, mailers, and models while supporting multiple Rails versions.
How it got here
2017 — Passwordless v1.8.1 upgrade and Rails 8 compatibility
27 changes.
The project upgraded the Passwordless authentication library to v1.8.1, introducing a new configuration API, encrypted token digests, and support for Rails 8's lazy route loading. Significant refactoring modernized the authentication flow, controllers, and mailers to align with current Rails conventions and security standards. Comprehensive test suites and a modernized dummy application were added to ensure stability and coverage for the new features.
2018–2024 — Rails compatibility and test coverage expansion
5 changes.
This period focused on expanding test coverage for the passwordless authentication system, including models, controllers, and integration scenarios. The project also introduced a view generator to simplify setup and added Gemfiles to support testing against Rails 6.1, 7.0, 7.1, and the main branch.
Features
Add a simple view generator
A new \ViewsGenerator\ has been added to the library, allowing users to easily scaffold the default passwordless views. Running this generator copies the sign-in email template, the new session form, and the show session view into the application's \app/views/passwordless\ directory, streamlining the initial setup process for developers.
lib/generators · high confidence
Behavioural changes
Lazy route loading fix and new configuration API
The library now supports Rails 8's lazy route loading by eagerly loading routes when accessing the context, ensuring the resource registry is populated correctly. It introduces a new configuration API via \Passwordless.configure\ and a \Passwordless.context\ method to manage resources, replacing the previous empty module structure. Additionally, the obsolete \lib/tasks/passwordless\_tasks.rake\ file has been removed.
lib · high confidence
Mailer now uses configurable parent mailer and dynamic URL options
The Passwordless mailer no longer inherits directly from ActionMailer::Base but instead uses a configurable parent mailer (defaulting to the application's default mailer), allowing users to inherit custom mailer behavior. The default sender address is now pulled from configuration rather than being hardcoded. Additionally, the sign-in email method now accepts explicit URL options and a token parameter, enabling better control over link generation and supporting localized email subjects via I18n.
app/mailers · high confidence
Modernized bin/rails script syntax
The bin/rails script has been updated to use modern Ruby syntax, replacing the deprecated \_\FILE\\_ constant with \_\dir\\_ for path resolution and switching string literals from single quotes to double quotes. This change improves compatibility with current Ruby standards and aligns the script with Rubocop style guidelines.
bin · high confidence
Modernized sign-in flow with Turbo compatibility and improved UX
The passwordless sign-in experience has been updated to support Rails 7 Turbo by disabling Turbo on form submissions, ensuring reliable redirects. The email entry form now includes proper labels, placeholders, and autofocus for better accessibility, while the token confirmation page has been redesigned to use a standard form structure with autocomplete support for one-time codes. Additionally, the magic link email template has been removed in favor of a generic flash message redirect, simplifying the user journey.
app/views · high confidence
Passwordless authentication library upgraded to v1.8.1
The passwordless authentication library has been upgraded to version 1.8.1. This release introduces a new configuration system allowing customization of options such as the parent controller, redirect paths, and token generation. It also adds controller and model helpers for managing sessions, including support for custom controllers in routes, scoped post-sign-in redirects, and session fixation protection via session reset. Additionally, the library now includes test helpers for controller, request, and system tests, and uses SecureRandom for token generation to ensure non-deterministic randomness.
lib/passwordless · high confidence
Refactor authentication controllers to inherit from application base and support configurable redirects
The Passwordless engine controllers now inherit from the main application's ApplicationController instead of ActionController::Base, allowing them to leverage existing application helpers and configuration. The internal ControllerHelpers module has been removed, with authentication logic moved directly into the SessionsController. Additionally, the sign-in and sign-out flows now support configurable redirect paths, including the ability to redirect back to the original destination after signing in, rather than hardcoding redirects to the root path.
app/controllers · high confidence
Refactor session handling with encrypted tokens and route constraints
The passwordless authentication system now uses encrypted token digests instead of storing plaintext tokens, enhancing security by preventing token exposure in the database. Session validation has been updated to check both expiration and timeout states, and tokens can now be marked as claimed to prevent reuse. Additionally, new route constraints (Passwordless::Constraint and Passwordless::ConstraintNot) allow for more flexible routing logic based on authentication status and custom predicates, while a new Context class simplifies URL generation for different authenticatable resources.
passwordless · high confidence
Removal of passwordless authentication routes
The configuration for the passwordless authentication engine has been cleared, removing all previously defined routes including sign-in, sign-out, and token-based access endpoints. This change effectively disables the passwordless login functionality provided by this engine within the application.
config · high confidence
Session schema updated to support UUID identifiers and token security
The passwordless sessions database schema has been modified to improve security and identifier handling. The \token\ column has been replaced with \token\_digest\ to store hashed tokens rather than plaintext values, and a new \claimed\_at\ timestamp has been added to track when a token is used. Additionally, a new \identifier\ column (UUID) has been introduced as a unique index for sessions, while the \authenticatable\ association now explicitly specifies an integer type for the foreign key.
db · high confidence
Updated user management views with modern Rails conventions and inline styling
The user management views in the dummy application have been refactored to align with modern Rails defaults and improve UI consistency. The form partial now uses the default \form\_with\ behavior (removing explicit \local: true\) and applies inline styles for error messages and labels instead of CSS classes. The index and show pages have replaced the traditional HTML table layout with a div-based structure that renders individual user partials, and navigation links have been updated to more descriptive text (e.g., "Back to users"). Additionally, the show view now uses \button\_to\ for user deletion, enhancing security by ensuring the action requires a POST request, and the new \\_user\ partial was added to support the refactored index rendering.
test/dummy/app/views/users · high confidence
Test coverage
Added frozen\_string\_literal comments to test dummy files; Added integration tests for the passwordless authentication flow; Added test coverage for passwordless authentication components; Added test fixture for custom admin sessions controller; Added test suite and test infrastructure for Passwordless; Added test view for registration form; Added tests for Authenticatable model sessions association; Added tests for Passwordless mailer behavior; Added tests for Passwordless::Session model behavior; Clean up dummy app asset configuration; Expanded test coverage for SessionsController; Updated dummy app database schema for Rails 8.0 compatibility; Updated dummy app environment configurations for modern Rails standards; Updated dummy app layout for testing and added secrets view; Updated test dummy app configuration and scaffolding; Updated test dummy application controllers; Updated test dummy database schema for STI support; Updated test dummy models to use passwordless\_with macro.
Dependencies
Add Gemfiles for Rails 6.1, 7.0, 7.1, and main branches
The project now includes dedicated Gemfiles to support testing against Rails versions 6.1, 7.0, and 7.1, as well as the Rails main branch. These files pin specific gem versions (such as sqlite3 and concurrent-ruby) and configure the test suite dependencies for each target environment, enabling the CI matrix to validate compatibility across these Rails releases.
gemfiles · high confidence
Updated gem dependencies and removed lockfile
The project now relies on a Gemfile for dependency management instead of the gemspec alone, explicitly adding development gems like pry, puma, yard, and test tools (capybara, minitest, codecov). The sqlite3 dependency has been updated to version 2.x, and the Rails dependency has been relaxed to allow versions greater than or equal to 5.1.4. Additionally, a hard dependency on bcrypt (\>= 3.1.11) has been added to the gemspec, and the Gemfile.lock has been removed.
(dependencies) · high confidence
Housekeeping
Update documentation and build configuration
The README has been significantly expanded with comprehensive installation, usage, and configuration guides, including a new logo and CI badges. The Rakefile has been updated to use YARD for documentation generation instead of RDoc, and the test task now delegates to \bin/rails test\. Additionally, \.codecov.yml\ and \.rubyfmtignore\ have been added to configure code coverage exclusions and formatting ignores for the test dummy directory.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 53.
Lenses
- Code Health 100
- Architecture 69
- Maturity 58
- Readiness 77
- Security 95
- Domain Modelling 35
Changes since last survey
- 268 commits — 245 feature/other, 23 fixes
By area
- (root) — 151 commits
- test/dummy — 29 commits
- lib/passwordless — 23 commits
- app/controllers — 13 commits
- (repo) — 9 commits
- .github/workflows — 9 commits
- .github/FUNDING.yml — 6 commits
- app/mailers — 6 commits
- app/models — 5 commits
- app/views — 5 commits
- .github/dependabot.yml — 2 commits
- config/locales — 2 commits
- lib/passwordless.rb — 2 commits
- db/migrate — 1 commit
- docs/upgrading_to_1_0.md — 1 commit
- lib/generators — 1 commit
- test/controllers — 1 commit
- test/fixtures — 1 commit
- test/passwordless_for_test.rb — 1 commit
Notable commits
- fix: Fix :as option in passwordless_for, fix test helpers (#174)
- fix: Fix Rails 8 route lazy loading issue (#247)
- fix: Fix TOC link in Readme (#40)
- fix: Fix a whole bunch of Rubocop warnings
- fix: Fix copy
- fix: Fix downcase emails
- fix: Fix email param retrieval in new session form (#267)
- fix: Fix fixture_path deprecation warning (#165)
- fix: Fix issue with form_with from Rails (#194)
- fix: Fix passwordless_sign_in bugs (#179)
- fix: Fix readme (#119)
- fix: Fix render when using Turbo (#118)
- fix: Fix session expiry (#61)
- fix: Fix session/new label for attribute (#172)
- fix: Fix specs for rails#master (#232)
- fix: Fix standardrb notices
- fix: Fix test helpers (#181)
- fix: Merge STI model fix (#27)
- fix: Merge pull request #111 from madogiwa0124/fix-filewatcher-in-development
- fix: Rubocop auto-fixes
- …and 248 more
Architecture
- 0 containers · 1 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mikker/passwordless was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 5bed5df919006901135b9577d4d92d6efa5a25ed — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.