Skip to content
CAI
Software that uses CAICheck a score

nulab/scala-oauth2-provider

52.7

Adequate · 20 September 2026

819

lines of production code

Scala

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Scala-based OAuth 2.0 provider library that manages authentication flows, including authorization codes, client credentials, and refresh tokens. It supports modern security standards like PKCE and provides a modular architecture for handling protected resources and token endpoints. The library is designed for integration with frameworks like Play and Akka HTTP, offering comprehensive error handling and validation for OAuth requests.

Removals

Removal of legacy OAuth2 provider implementation

The legacy OAuth2 provider implementation has been removed from the codebase. This change deletes the Play 2-specific \TokenController\ and the core \scala-provider\ components, including the \DataHandler\ trait, \EndPoint\ logic, and all grant handlers (Authorization Code, Refresh Token, Client Credentials, and Password). Consequently, the associated test suites for these components have also been removed.

play2-provider, scala-provider · high confidence

Behavioural changes

Library documentation and build configuration updates

The README has been significantly expanded to provide comprehensive setup instructions for Play Framework, Akka HTTP, and other frameworks, along with detailed code examples for implementing the DataHandler trait and using AuthInfo. The configuration file .scalafmt.conf has been added to enforce code formatting with Scala 3 dialect, and the .gitignore file has been updated to exclude the .bsp directory.

(repo-wide) · high confidence

OAuth 2.0 provider core refactored with PKCE support and improved error handling

The library introduces a new provider architecture in src/main/scala/scalaoauth2/provider, adding support for PKCE (RFC 7636) via new \codeChallenge\ and \codeChallengeMethod\ fields in \AuthInfo\ and \CodeChallengeMethod\ types. The core authorization flow is now structured around dedicated traits (\AuthorizationHandler\, \GrantHandler\, \ProtectedResourceHandler\) and request models (\AuthorizationRequest\, \ProtectedResourceRequest\) that replace the previous monolithic \Request\ class. Error handling is improved by making \OAuthError\ exceptions carry their description as the exception message and correcting HTTP status codes (e.g., \RedirectUriMismatch\ now returns 400/invalid\_request instead of 401).

src/main · high confidence

Test coverage

Added comprehensive unit tests for OAuth2 provider components

Added a new suite of unit tests in src/test/scala/scalaoauth2/provider covering core OAuth2 functionality, including access token expiration logic, authorization header parsing (OAuth and Bearer schemes), authorization code and client credentials grant flows, implicit and password grant handling, protected resource validation, refresh token operations, and PKCE code challenge method parsing. The tests also verify correct HTTP status codes for various OAuth error scenarios and ensure the TokenEndpoint correctly routes and validates requests.

src/test · high confidence

Dependencies

Initial build configuration for scala-oauth2-core

The project now uses a build.sbt file to define its build settings, establishing scala-oauth2-core as the project name with a default Scala version of 3.3.0 and cross-compilation support for 2.13.12, 2.12.18, and 2.11.12. Test dependencies are explicitly set to scalatest 3.2.17 and logback-classic 1.4.11, and the build is configured to publish to Sonatype OSS repositories.

(dependencies) · high confidence

Migrate build system from SBT 0.13 to 1.9.6 and replace sbt-idea with sbt-scalafmt

The project has upgraded its build tool from SBT version 0.13.0 to 1.9.6, requiring users to ensure their local environment supports the newer SBT 1.x series. Additionally, the legacy sbt-idea plugin has been removed and replaced with sbt-scalafmt (version 2.5.2) to handle code formatting, changing how developers generate IDE project files and format code.

project · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 53.

Lenses

  • Code Health 100
  • Architecture 69
  • Maturity 30
  • Readiness 65
  • Security 92

Changes since last survey

  • 275 commits — 250 feature/other, 25 fixes

By area

  • (root) — 101 commits
  • scala-oauth2-core/src — 52 commits
  • project/Build.scala — 36 commits
  • (repo) — 35 commits
  • play2-oauth2-provider/src — 23 commits
  • .github/workflows — 12 commits
  • src/main — 5 commits
  • src/test — 5 commits
  • project/build.properties — 3 commits
  • .github/dependabot.yml — 1 commit
  • akka-http-oauth2-provider/src — 1 commit
  • scala-provider/src — 1 commit

Notable commits

  • fix: #6 fix Authentication header get key name by case insensitive
  • fix: Authorization Header Specification fixes (#110)
  • fix: Fix #47: Add implicit grant
  • fix: Fix StringIndexOutOfBoundException when client sent invalid Authorization parameter
  • fix: Fix deprecation warning
  • fix: Fix document and format code
  • fix: Fix some warnings
  • fix: Fixed #68
  • fix: Fixed Implicit grant does not support the issuance of refresh tokens #70
  • fix: Fixed implicit override
  • fix: Merge pull request #14 from centraldesktop/bugfix/rfc6749-section5.1
  • fix: bugfix() http://tools.ietf.org/html/rfc6749#section-5.1
  • fix: fix MatchError on auth header parameter
  • fix: fix Play name
  • fix: fix README
  • fix: fix access token error doesn't have WWW-Authenticate in header
  • fix: fix comparing mill seconds for access token
  • fix: fix crossScalaVersions (#160)
  • fix: fix description
  • fix: fix package object #74
  • …and 255 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

nulab/scala-oauth2-provider was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ad54cbd909c4a9cd1a651840777c41f2d503c8ff — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.