Skip to content
CAI
Software that uses CAICheck a score

owen2345/camaleon-cms

45.9

Weak · 20 September 2026

17.9k

lines of production code

Ruby

with JavaScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a modular, multi-tenant Content Management System (CMS) built on Rails, designed to manage websites with distinct sites, themes, and plugins. It provides a comprehensive administrative interface for creating and editing content across various post types, managing user roles and permissions, and configuring site settings including media storage and email delivery. The platform supports extensibility through a plugin and theme architecture, offering tools for developers to generate custom components and integrate with external services.

How it got here

2015 — Rails 8 upgrade and security hardening

153 changes.

The project underwent a major upgrade from Rails 4.2 to Rails 8.1, accompanied by a comprehensive security overhaul that replaced legacy controllers, helpers, and views with modern, authorization-enforced implementations. This period focused on eliminating technical debt by removing obsolete plugins and assets, while simultaneously hardening the codebase against XSS, CSRF, and mass-assignment vulnerabilities through strict input validation and secure session management.

2016–2026 — Security hardening and Rails 8 compatibility

16 changes.

This period focused on significant security hardening, including strict path validation for media uploads, SSRF mitigation in URL validators, and mass-assignment protection for custom fields. The project simultaneously upgraded core dependencies to jQuery 2 and Bootstrap 3.4.1, while expanding CI support to cover Rails 7.1 through 8.1 and adding comprehensive test coverage for admin and plugin security features.

Features

Add camaleon\_first default theme assets and configuration

The dummy application now includes the 'camaleon\_first' theme, providing a complete default theme package. This adds the necessary frontend assets, including CSS stylesheets (main, magnific-popup, wpbase, style), JavaScript libraries (jQuery 2, Modernizr, Magnific Popup, hover zoom), and a manifest file to compile them. It also introduces the theme's configuration, a main helper that defines theme settings and install/uninstall hooks, and the core view templates (index and mailer layout) that render the theme's layout and content.

spec/dummy/app/apps/themes · high confidence

Added HTML email templates for user notifications

The application now includes specific HTML email templates for the Camaleon CMS, enabling formatted notifications for users. New views have been added for account confirmation (welcome message and confirmation link), password resets (greeting and reset link), and a generic mailer template that renders custom subjects and HTML content. These templates ensure that system-generated emails are presented with proper structure and styling rather than plain text.

_app/views/camaleon\_cms/html\mailer · high confidence

Added TinyMCE language packs for German, English, Spanish, French, Italian, Dutch, Portuguese (Brazil), and Russian

The admin TinyMCE editor now includes dedicated translation files for German (de), English (en\_GB), Spanish (es), French (fr\_FR), Italian (it), Dutch (nl), Portuguese (pt-BR), and Russian (ru). Users can now see the editor interface in their preferred language, with specific locale variants like en\_GB and fr\_FR ensuring correct regional spelling and terminology.

_app/assets/javascripts/camaleon\cms/admin/tinymce · high confidence

Added custom error pages and flash message partial

The CMS now includes dedicated view templates for 404 (Page Not Found) and 500 (Internal Server Error) responses, displaying localized messages and optional error details. Additionally, a new \\_flash\_messages.html.erb\ partial has been added to standardize the rendering of flash notices, info, errors, and alerts with Bootstrap-style alert classes, allowing for consistent user feedback across the application.

_app/views/camaleon\cms · high confidence

Added placeholder asset directories for gem plugin templates

The gem plugin generator template now includes empty \.keep\ files in the images, JavaScript, and stylesheets asset directories. This ensures that these asset folders are created when a new gem plugin is generated, providing a standard location for developers to add plugin-specific assets.

_lib/generators/camaleon\_cms/gem\_plugin\_template/app/assets/images/plugins/my\_plugin, lib/generators/camaleon\_cms/gem\_plugin\_template/app/assets/javascripts/plugins/my\_plugin, lib/generators/camaleon\_cms/gem\_plugin\_template/app/assets/stylesheets/plugins/my\plugin · high confidence

Added rake tasks for migration generation and RSpec testing

The Camaleon CMS engine now provides two new rake tasks to assist with setup and testing. The \camaleon\_cms:generate\_migrations\ task allows users to manually copy plugin migrations to the application's migration folder, controlled by the new \auto\_include\_migrations\ setting. Additionally, the \camaleon\_cms:rspec\ task enables running the CMS's feature specs, either for all files or a specific file, streamlining the testing workflow for developers integrating the engine.

_lib/tasks/camaleon\cms · high confidence

Added sample plugin model initializer template

The gem plugin template now includes a sample initializer file (custom\_models.rb) that demonstrates how to register a custom model association within a CamaleonCms site. This serves as a reference for plugin developers to understand how to extend site models using the to\_prepare hook.

_lib/generators/camaleon\_cms/gem\_plugin\template/config/initializers · high confidence

Authoring Post plugin allows changing post authors

The Authoring Post plugin now includes a UI control in the post creation and editing forms that lets users select the post author from a list of site users (excluding those with the 'client' role). The helper module renders a dropdown for this selection, defaulting to the current user for new posts, and disables the control if the user lacks permission to edit other users' posts or publish content.

_app/apps/plugins/authoring\post · high confidence

Default theme adds JSON API and RSS feeds for all content views

The default theme now provides structured data outputs for frontend integration and syndication. HTML views for categories, tags, post types, single posts, search, and the homepage are accompanied by corresponding JSON (Jbuilder) and RSS (RSS.builder) templates, allowing external clients to consume content listings and details. Additionally, custom field rendering templates (audio, video, image, checkbox, etc.) have been added to the default theme to support the display of various custom field types.

_app/views/camaleon\_cms/default\theme · high confidence

Gem plugin generator now includes default admin settings form

The gem plugin generator template now provides a default settings edit form for the admin panel. When generating a new gem plugin, developers will receive an \admin/settings.html.erb\ view that includes fields for standard options and metadata, along with support for custom field groups, allowing for immediate configuration of plugin settings without manual template creation.

_lib/generators/camaleon\_cms/gem\_plugin\_template/app/views/plugins/my\plugin · high confidence

New URL validation and slug uniqueness validators

This change introduces three new validators to the application. The UserUrlValidator adds robust security checks for user-provided URLs, including SSRF mitigation by resolving hostnames and rejecting local, link-local, and shared IP addresses, as well as path traversal and HTML injection prevention. The PostUniqValidator and UniqValidator replace previous logic to enforce slug uniqueness for posts and taxonomy terms respectively, ensuring that duplicate slugs are rejected during record creation or updates.

app/validators · high confidence

New admin controllers for managing navigation menus and themes

This change introduces two new controllers in the admin panel: \NavMenusController\ and \ThemesController\. The \NavMenusController\ provides full CRUD capabilities for navigation menus, including adding items (custom, external, or auto-generated), reordering items with proper site-scoping to prevent cross-site data leakage, and managing custom field settings for menu items. The \ThemesController\ allows administrators to list available themes, activate a theme by setting its status, and load theme-specific data (such as post types, menus, and sliders) from a \data.json\ file. Both controllers enforce permission checks (\:manage\ for nav menus and themes) and integrate with the existing admin layout and breadcrumbs.

_app/controllers/camaleon\cms/admin/appearances · high confidence

New admin dashboard and search interface with post type support

The admin interface now includes a dedicated dashboard view that displays notifications and dashboard items via hooks, and a new search page that allows filtering by content, categories, tags, and post types. The search results table now includes a column for post types and supports hierarchical content listing for items, enhancing the ability to locate and manage different types of CMS content.

_app/views/camaleon\cms/admin · high confidence

New admin interface for managing custom field groups

The admin settings area now includes a dedicated interface for creating and organizing custom field groups. Administrators can define groups of fields and assign them to specific content types, including posts, post types, categories, post tags, users, sites, themes, and navigation menus. The new UI supports grouping fields, setting validation rules (required, multiple values, translatable), and managing field order via drag-and-drop sorting.

_app/views/camaleon\_cms/admin/settings/custom\fields · high confidence

New admin interface for managing post tags with custom field support

The admin section now includes a dedicated interface for managing post tags, featuring a new form view that supports custom fields defined for the PostTag kind. The list view displays tag details including name, description, slug, and associated post count, with actions to view, edit, or delete tags. The implementation uses AJAX requests for form submissions and integrates with the existing theme structure.

_app/views/camaleon\_cms/admin/post\tags · high confidence

New admin interface for managing post-type categories

The admin area now includes dedicated views for managing categories within specific post types. Users can view a hierarchical list of categories (including name, description, slug, and item count) and add or edit them via a new form that supports parent-child relationships, translatable fields, and custom field groups. This change consolidates category management into the post-type context rather than a global list.

_app/views/camaleon\cms/admin/categories · high confidence

New custom field types for admin settings

The admin settings interface for custom fields now supports a comprehensive set of new field types, allowing administrators to collect diverse data in posts and other content. This update introduces dedicated UI components for audio, video, and file uploads (including private files), as well as standard input types like text, textarea, email, phone, numeric, URL, color picker, and date. It also adds complex selection fields including single/multiple checkboxes, radio buttons, standard selects, and a dynamic select-eval option. Furthermore, new relational field types enable linking content to categories, post types, specific posts, and users, while a dedicated 'Attributes' field supports key-value pairs. Many of these fields support translation and required validation.

_app/views/camaleon\_cms/admin/settings/custom\fields/fields · high confidence

New file manager plugin for TinyMCE editor

A new TinyMCE plugin named 'filemanager' has been added to the admin interface. This introduces a new 'Insert file' button and menu item that opens a file uploader. When a user selects a file, it is inserted into the editor content as a hyperlink with the file's name as the link text, opening in a new tab.

_app/assets/javascripts/camaleon\cms/admin/tinymce/plugins/filemanager · high confidence

New generators for gem plugins, themes, and installation scaffolding

The \lib/generators/camaleon\_cms\ directory now includes three new Rails generators: \gem\_plugin\_generator\ creates a full gem-based plugin structure with pre-configured admin and frontend routes; \theme\_generator\ scaffolds a new theme directory with configuration and helper files; and \install\_generator\ sets up the initial CMS structure, including copying default themes and configuring Sprockets 4+ asset manifests. These tools allow developers to quickly bootstrap custom plugins and themes within the Camaleon CMS ecosystem.

_lib/generators/camaleon\cms · high confidence

New repair and security audit Rake tasks for data integrity and content safety

This release introduces a suite of new Rake tasks in the \camaleon\_cms\ namespace to repair existing data inconsistencies and audit stored content against new security gates. Key repairs include \rehome\_cross\_site\_field\_groups\ to fix tenancy mismatches in custom field groups, \backfill\_custom\_fields\_permission\ and \backfill\_select\_eval\_permission\ to ensure admin roles have necessary permissions, \repair\_media\_visibility\ to rebuild the media cache after a routing fix, \reassign\_orphaned\_comments\ to reassign comments from deleted users, \repair\_private\_upload\_acls\ to fix S3 permissions, \backfill\_site\_field\_group\_objectid\ to fix missing object IDs, and \demodulize\_user\_field\_groups\ to correct namespaced user model references. Additionally, \scan\_content\ and \scan\_uploads\ are provided as read-only audit tools to list stored posts, custom fields, templates, and media files that would now be rejected by stricter security validation rules, allowing operators to review and clean up legacy data.

lib/tasks · high confidence

New theme management interface with data import support

The admin panel now includes a dedicated themes index page that displays available themes as cards with thumbnails, descriptions, and actions to preview or activate them. A new preview modal allows administrators to view themes in an iframe before selection. Additionally, a theme data loading view has been introduced to handle importing sample data (data.json) for themes, displaying success, warning, or error messages during the process.

_app/views/camaleon\cms/admin/appearances/themes · high confidence

The admin navigation menu editor has been rebuilt to support custom fields, custom menu items, and external links with target attributes. Administrators can now add custom links to menus, configure custom settings for menu items, and manage menu hierarchy. The editor includes hooks for extending menu functionality and supports custom field rendering for menu items.

_app/views/camaleon\_cms/admin/appearances/nav\menus · high confidence

Removals

Admin comments interface removed

The legacy admin views for managing comments have been deleted, removing the previous UI for listing posts with comment counts, editing individual comments, and replying to or moderating comments via inline buttons and forms. This change eliminates the associated client-side JavaScript for status changes and replies, indicating the comments management functionality has been replaced or moved elsewhere.

app/views/admin/comments · high confidence

Ecommerce plugin removed

The entire Ecommerce plugin has been removed from the application. This deletion eliminates all associated administrative controls for managing orders, coupons, payment methods, shipping methods, tax rates, and pricing, as well as the front-end checkout flow, cart functionality, and payment processing logic (including PayPal and credit card validation). Users will no longer have access to any e-commerce features provided by this plugin.

(repo-wide) · high confidence

Removal of Admin Post Drafts Controller

The \Admin::Posts::DraftsController\ has been removed from the application. This change eliminates the backend API endpoints previously used to create, update, and manage post drafts within the admin interface, meaning users can no longer interact with draft-specific functionality through this controller.

app/controllers/admin/posts · high confidence

Removal of FrontendConcern controller module

The \FrontendConcern\ module, previously located in \app/controllers/concerns/\, has been removed from the application. This deletion eliminates the shared controller logic for generating sitemaps (including XML rendering and fallback handling), serving robots files, and saving post comments with user attribution and IP tracking. Users relying on these specific controller behaviors will no longer have access to them through this concern.

app/controllers/concerns · high confidence

Removal of admin panel CSS assets

The admin panel's stylesheet manifest and several bundled CSS files (including Animate.css, Bootstrap datetimepicker, and others referenced in the manifest) have been deleted. This removes the previously included third-party animation and UI styling libraries from the admin interface.

app/assets/stylesheets/admin · high confidence

Removal of dedicated plugins and themes admin/frontend controllers

The dedicated controllers for managing plugins and themes in both the admin and frontend areas have been removed. Specifically, \PluginsAdminController\, \PluginsFrontController\, \ThemesAdminController\, and \ThemesFrontController\ are deleted, eliminating the previous logic that initialized plugin/theme contexts and dynamically adjusted view paths based on the controller name and slug. This change likely indicates a shift in how these resources are routed or rendered, requiring users to rely on alternative mechanisms for plugin and theme presentation.

app/controllers/apps · high confidence

Removal of default theme admin settings view

The admin settings view for the default theme has been removed. This file previously rendered custom field groups for the current theme, and its deletion indicates that this specific interface for managing theme settings is no longer available in this location.

_app/views/default\theme/admin · high confidence

Removal of default theme layout templates

The default theme's layout structure has been removed, specifically deleting the header partial (\_header.html.erb), footer partial (\_footer.html.erb), and the main index layout (index.html.erb). This eliminates the previous HTML structure that included a fixed-top navbar with user login/register dropdowns, a footer with social links, and the inclusion of Font Awesome 4.3.0 via CDN.

_app/views/default\theme/layouts · high confidence

Removal of default theme view templates

The default theme's view templates have been completely removed from the application. This includes the layout and content rendering for the home page (index), category listings, individual posts, post tags, post types, search results, and the sitemap. Additionally, the robots.txt template has been deleted. Users relying on this default theme for rendering these standard pages will no longer have these views available.

_app/views/default\theme · high confidence

Removal of installer form and welcome views

The installer form view (app/views/admin/installers/form.html.erb) and the post-installation welcome view (app/views/admin/installers/welcome.html.erb) have been deleted. This removes the UI components used for configuring the site domain, name, and theme during installation, as well as the success message providing links to the frontend and admin panel along with default credentials.

app/views/admin/installers · high confidence

Removal of legacy TinyMCE YouTube plugin and theme asset manifests

The TinyMCE 'youtubeIframe' plugin has been removed from the application, deleting its JavaScript logic, styles, language packs, and dialog interface that previously allowed users to insert YouTube videos via iframe or Flash embed. Additionally, the asset manifest files for the 'my\_theme' theme generator (main.css and main.js) have been deleted, removing the explicit requirements for Bootstrap and jQuery in the generated theme assets.

_app/assets/stylesheets/tinymce/plugins/youtubeIframe, lib/generators/ctheme\_template/app/apps/themes/my\theme/assets · high confidence

Removal of legacy admin JavaScript assets

The admin panel no longer includes several legacy client-side libraries and their integration manifest. Specifically, the \actions.js\ file (handling panel interactions and sidebar navigation), the \admin-manifest.js\ Sprockets manifest, and standalone copies of \bootstrap-colorpicker.js\, \bootstrap-datepicker.js\, \bootstrap-datetimepicker.min.js\, \bootstrap-select.js\, and \bootstrap.min.js\ have been deleted. This removes the bundled versions of these UI components from the admin asset pipeline.

app/assets/javascripts/admin · high confidence

Removal of legacy admin and frontend controllers

The legacy controller files for the admin panel (including settings for custom fields, post types, and sites) and the main frontend routing have been removed from the application. This cleanup eliminates the previous implementation of these administrative and public-facing request handlers, indicating a shift to a new architecture or framework for handling these areas.

app/controllers · high confidence

Removal of legacy admin appearance controllers

The navigation menu, theme, and widget management controllers have been removed from the admin interface. This eliminates the legacy code paths for managing nav menus, switching themes, and configuring widgets and sidebars, indicating these features are no longer supported or have been replaced by a different implementation.

app/controllers/admin/appearances · high confidence

Removal of legacy admin category and taxonomy views

The legacy admin views for managing categories and taxonomies have been removed. This includes the deletion of the form, edit, and index templates for both the \admin/categories\ and \admin/taxonomy\ sections. Users will no longer have access to the previous UI for creating, editing, or listing these entities through these specific view files.

app/views/admin/categories · high confidence

Removal of legacy admin layout templates

The admin interface no longer includes the dedicated layout templates for AJAX responses, flash messages, form errors, the sidebar navigation, and the installation wizard. Users will no longer see the previous sidebar profile information, flash alerts, or the specific installer UI structure, as these view components have been completely removed from the application.

app/views/layouts/admin · high confidence

Removal of legacy admin plugins list views

The legacy plugin management interface in the admin panel has been removed. Specifically, the \app/views/admin/plugins/index.html.erb\ page and its \\_plugins\_list.html.erb\ partial, which previously displayed a table of plugins with tabs for active and all plugins, toggle buttons for enabling/disabling, and modal documentation links, have been deleted from the codebase. This change eliminates the old UI for managing plugins, implying the functionality has been replaced or deprecated elsewhere.

app/views/admin/plugins · high confidence

Removal of legacy admin post views

The legacy admin post interface files have been removed from the application. This includes the post listing page (index), the post editing form (form), the post detail view (show), and the status filter partial (\_filter\_posts). These files are no longer part of the admin interface.

app/views/admin/posts · high confidence

Removal of legacy admin settings views

The admin interface no longer includes the dedicated configuration pages for site details and language management. The \site.html.erb\ view, which previously allowed administrators to edit site metadata (name, description, keywords, logo, favicon), set home/404 pages, manage pagination, and toggle user registration, has been removed. Similarly, the \languages.html.erb\ view, which provided a UI for selecting available and admin interface languages, has been deleted. These changes indicate that site configuration and language settings are now managed through a different mechanism or interface outside of these specific view files.

app/controllers/admin, app/views/admin/settings · high confidence

Removal of legacy admin views for post tags and site settings

The legacy ERB template files for the admin post tags management (form, edit, and index pages) and the admin site settings management (form and index pages) have been deleted. This removes the user-facing UI components for creating, editing, listing, and deleting post tags and site configurations from the admin interface.

_app/views/admin/post\tags, app/views/admin/settings/sites · high confidence

Removal of legacy admin, application, and login layout templates

The legacy layout files for the admin panel, the main application, and the login screen have been deleted. This removes the previous HTML structure, including the sidebar navigation, breadcrumb trails, and specific asset inclusions (such as Font Awesome 4.3.0 and locale-specific JavaScript) that were previously rendered by these templates.

app/views/layouts · high confidence

Removal of legacy application helper modules

The application has removed ten helper modules from the \app/helpers\ directory, including \ApplicationHelper\, \CaptchaHelper\, \ContentHelper\, \HooksHelper\, \HtmlHelper\, \PluginsHelper\, \SessionHelper\, \ShortCodeHelper\, \SiteHelper\, \ThemeHelper\, \UploaderHelper\, and \UserRolesHelper\. This change eliminates the underlying logic for session management, captcha generation, shortcode rendering, plugin/theme asset path resolution, and file uploading, indicating a significant architectural shift or migration away from these legacy implementation patterns.

app/helpers · high confidence

Removal of legacy custom fields and post types admin views

The legacy admin interface for managing custom field groups and post types has been removed. This change deletes the view templates for the custom fields settings (including the meta data editor, field rendering, and group form) and the post types management pages (including the list, edit, and form views). Users will no longer be able to configure or view these specific legacy settings through the admin panel.

_app/views/admin/settings/custom\fields · high confidence

Removal of legacy frontend helper modules

The frontend application helper modules—ApplicationHelper, NavMenuHelper, SeoHelper, and SiteHelper—have been removed from the codebase. This deletion eliminates the previous implementation of navigation menu rendering, SEO attribute generation (including Open Graph and Twitter card metadata), site URL/path detection, and visibility verification logic. Users relying on these specific helper methods for custom view logic or theme development will no longer have access to these utilities.

app/helpers/frontend · high confidence

Removal of legacy model concerns

Deleted the \app/models/concerns\ directory and its constituent files (\categories\_tags\_for\_posts\, \custom\_fields\_read\, \metas\, \metas\_saved\, \site\_public\), removing the associated logic for managing post categories/tags, custom field reading, meta/options storage, and site public helpers.

app/models/concerns · high confidence

Removal of the admin dashboard view template

The view template for the admin dashboard (app/views/admin/dashboard/index.html.erb) has been deleted. This removes the UI component that previously displayed the welcome message and the dashboard title to administrators.

app/views/admin/dashboard · high confidence

Removed Bootstrap 3.3.4 CSS assets from the plugin editor

The minified CSS file for Bootstrap v3.3.4 has been deleted from the \bootstrap\_editor\ plugin assets. This removes the bundled grid, component, and utility styles that were previously included with the plugin, meaning the editor will no longer apply these specific Bootstrap styles unless they are provided by another source.

(repo-wide) · high confidence

Removed admin session views

The admin session views for login, registration, and password reset have been deleted from the application. This removes the user-facing templates for these authentication flows, meaning the admin login, user registration, and password recovery interfaces are no longer available via these view files.

app/views/admin/sessions · high confidence

Removed application scaffolding and configuration files

This change removes several default scaffolding and configuration files from the repository, including the HTML email templates (other.html.erb, sender.html.erb), environment-specific configuration files (development.rb, production.rb, test.rb), the database schema definition (schema.rb), the database seed file (seeds.rb), and placeholder keep files in the lib and vendor asset directories. This effectively strips the project of its initial boilerplate structure, leaving the codebase cleaner for custom development.

(repo-wide) · high confidence

Removed default theme view templates and assets

The default view templates for the 'my\_theme' theme generator have been removed, including the admin settings page, the main index layout, the site index content view, and the partials readme file. This change eliminates the pre-built UI structure and navigation components that were previously included in the generated theme, requiring users to provide their own view implementations.

_lib/generators/ctheme\_template/app/apps/themes/my\theme/views · high confidence

Removed empty model template from plugin generator

The placeholder model file for the 'my\_plugin' generator has been deleted. This file previously contained only commented-out examples for defining an ActiveRecord model and its associations, offering no functional code for users to inherit or modify.

_lib/generators/cplugin\_template/app/apps/plugins/my\plugin/models · high confidence

Removed legacy admin appearance views for menus, themes, and widgets

The admin interface views for managing navigation menus, theme selection/preview, and widget/sidebar assignments have been deleted. This removes the UI components that allowed administrators to configure external menu links, browse and activate themes, and assign widgets to sidebars, indicating these features are no longer supported or have been replaced by a different implementation.

app/views/admin/appearances · high confidence

Removed legacy plugin and theme generators

The \CpluginGenerator\ and \CthemeGenerator\ classes have been removed from the codebase. These generators previously created basic plugin and theme directory structures by copying template files and performing text substitutions for names and titles. Their removal indicates that the legacy plugin/theme generation workflow is no longer supported or has been replaced by a different mechanism.

lib/generators · high confidence

Removed legacy theme partials from the new theme location

The view partials located in app/apps/themes/new/views/partials have been deleted. This removal eliminates the UI components for the category carousel, comment forms and lists, flash messages, custom forms, post list items, search forms, and the sidebar (including categories, latest posts, and tags) from this specific theme area.

app/apps/themes/new/views/partials · high confidence

Removed legacy user roles admin views

The legacy ERB templates for the user roles administration interface have been removed. This includes the form view used for creating and editing role permissions (such as post type access and manager capabilities) and the index view that displayed the list of roles with pagination and action links. Users will no longer see these specific UI components in the admin panel.

_app/views/admin/user\roles · high confidence

Removed obsolete and unused frontend assets

The application no longer includes several frontend JavaScript files that were previously bundled: Bootstrap 3.3.4, jQuery 1.11.3, Gibberish-AES, and the custom elfinder file uploader integration. Removing these files reduces the asset footprint and eliminates dependencies on outdated libraries and custom encryption utilities that are no longer in use.

app/assets/javascripts · high confidence

Security

Admin controllers refactored with explicit authorization and security hardening

The admin controllers (Categories, Comments, Installers, Media, Plugins, PostTags, Posts, Sessions, Settings, UserRoles, and Users) have been rewritten to enforce strict authorization checks, prevent path traversal and mass-assignment vulnerabilities, and secure session management. Key changes include: adding explicit \authorize!\ calls for all admin actions (e.g., \:manage, :media\, \:manage, :users\), validating category parents to prevent cross-site reparenting, sanitizing private file downloads to block path traversal, requiring setup tokens for remote installer access, equalizing login timing to prevent username enumeration, throttling password-reset emails, and using explicit parameter whitelists instead of \permit!\ to prevent mass-assignment attacks.

_app/controllers/camaleon\cms/admin · high confidence

Hardened authorization and content security in CMS models

The CMS models now enforce stricter security and permission controls. The authorization system (Ability) uses a safe\_can helper to prevent crashes from malformed role metadata and supports decorator class names. Custom field management now gates dangerous 'select\_eval' field types behind explicit permissions. Content saving is hardened against XSS: post content and custom field values (editor, field\_attrs, URIs) are scanned and rejected if they contain untrusted markup or scripts, with an opt-out for trusted server-side pipelines. Media uploads now validate canonical paths to prevent directory traversal and reject NULL visibility states.

_app/models/camaleon\cms · high confidence

Hardened media upload security and improved asset precompilation

This release significantly strengthens the security of uploaded media and fixes asset compilation issues. A new parse-based SVG and markup scanner (SvgContentChecker) replaces regex-based checks, rejecting dangerous elements and event handlers by shape to prevent stored XSS. The upload gate now strictly enforces the \media\_unfiltered\_upload\ permission for executable scripts and compressed markup, and decompresses gzip files before scanning to prevent evasion. Additionally, a new \AssetsPrecompile\ module ensures plugin and theme assets are correctly declared for precompilation across host, gem-bundled, and gem\_mode layouts, preventing \AssetNotPrecompiledError\ on modern Sprockets. The installer is now gated by a cryptographically secure setup token, and sensitive configuration parameters (passwords, API keys) are filtered from Rails logs.

_lib/camaleon\cms · high confidence

Installer now generates and displays a unique admin password

The CMS installation flow has been updated to no longer use a static default password. Instead, the installer form now collects a setup token for remote installations, and upon successful site creation, the welcome screen displays a randomly generated admin password. This password is shown only once with a copy-to-clipboard utility, and users are explicitly instructed to change it upon their first sign-in, significantly improving the security of new installations.

_app/views/camaleon\cms/admin/installers · high confidence

Refactored CMS decorators to centralize locale handling and fix stored XSS vulnerabilities

The Camaleon CMS decorator layer has been restructured to improve security and internationalization consistency. A new ApplicationDecorator base class centralizes locale resolution, ensuring that frontend URLs and content render correctly regardless of the admin or frontend context. This refactor also addresses critical security issues by HTML-escaping interpolated values in post titles, taxonomy names, and status labels, preventing stored XSS attacks in admin views. Additionally, the PostCommentDecorator has been updated to safely handle anonymous comments and missing user associations, preventing runtime errors on orphaned data.

_app/decorators/camaleon\cms · high confidence

Secure draft autosave with authorization and input validation

The new DraftsController introduces strict security controls for the post draft autosave feature. It now requires explicit authorization for listing drafts, creating buffers, and updating existing drafts, ensuring users can only access their own data. Additionally, custom field options are confined to registered slugs to prevent mass-assignment vulnerabilities, and the post\_parent field is enforced as create-only to prevent client-side manipulation.

_app/controllers/camaleon\cms/admin/posts · high confidence

Security fix for HTML injection in attribute formatting

The \to\_attr\_format\ method in \lib/ext/hash.rb\ now properly escapes HTML attribute values using \CGI.escapeHTML\ and validates attribute names against a strict regex pattern. This prevents malicious scripts from executing via crafted attribute names or values in forms and contact submissions, addressing a previously identified HTML injection vulnerability.

lib/ext · high confidence

Security fix for widget assignment mass-assignment vulnerability

The widget assignment controller now strictly limits permitted parameters to title, content, and item\_order, preventing attackers from modifying the underlying sidebar\_id or widget\_id fields during an update. This change ensures that widget assignments remain scoped to the current site and cannot be redirected to another site's sidebar or widget, addressing a critical mass-assignment vulnerability.

_app/controllers/camaleon\cms/admin/appearances/widgets · high confidence

Security hardening and permission tightening in admin settings controllers

The admin settings controllers for Custom Fields, Post Types, and Sites have been refactored to address multiple security vulnerabilities and enforce stricter access controls. Custom Fields management now requires explicit authorization for list and write actions, restricts category updates to POST requests to prevent CSRF-based data loss, and validates that field group placements belong to the current site to prevent cross-site contamination. Post Type settings now restrict default template and layout options to an offered list to prevent unauthorized view injection. Site creation now generates a unique administrator password for non-shared setups and displays it securely once, removing the previous default password behavior.

_app/controllers/camaleon\cms/admin/settings · high confidence

Security hardening and private file access fixes in media uploaders

The local and AWS uploaders now enforce strict path validation to prevent directory traversal and arbitrary file deletion attacks, and the AWS uploader ensures private uploads are stored with an owner-only ACL to prevent world-readable exposure. Additionally, the system corrects the inverted visibility mapping for existing media records and provides a repair task to fix legacy private file ACLs and thumbnail URLs, ensuring private files are properly protected and accessible only to authenticated users.

app/uploaders · high confidence

Behavioural changes

2 commits (0 fixes) modifying app/apps/themes

A change to existing behaviour in app/apps/themes — 2 commits, 1 file.

app/apps/themes · medium confidence · unverified

Admin interface JavaScript assets migrated to plain JavaScript

The admin interface JavaScript files (including \_actions, \_bootstrap-datepicker, \_bootstrap-select, \_custom\_fields, \_data, and \_i18n) have been converted from CoffeeScript to plain JavaScript. This migration ensures compatibility with the project's updated build pipeline and jQuery 2.x requirements, while preserving all existing admin functionality such as form validations, custom field handling, date pickers, and TinyMCE editor integration.

_app/assets/javascripts/camaleon\cms/admin · high confidence

Admin interface helpers refactored into modular concerns

The monolithic admin helper has been split into distinct, modular concerns (ApplicationHelper, BreadcrumbHelper, CategoryHelper, CustomFieldsHelper, MenusHelper, and PostTypeHelper). This refactoring improves maintainability and code organization within the admin panel, introducing specific capabilities such as a new pagination helper, a dedicated breadcrumb title drawer, and a rebuilt menu generation system that respects user permissions and includes intro tour data.

_app/helpers/camaleon\cms/admin · high confidence

Admin interface layout and components restructured

The admin panel's visual structure has been rebuilt by introducing new layout partials (\_ajax, \_flash\_messages, \_footer, \_form\_error, \_header, \_sidebar) and a dedicated installer template. This change standardizes how flash messages are displayed (with specific styling for notice, info, error, alert, and warning types), updates the footer to reference camaleon.website, and ensures the header and sidebar use the correct helper methods (cama\_current\_user, cama\admin\\*) for navigation and user context. The installer template provides a standalone login/setup view with its own manifest and styling.

_app/views/layouts/camaleon\cms/admin · high confidence

Admin interface styles updated with new UI components and theme skins

The admin dashboard styles have been refreshed by adding comprehensive CSS for several UI libraries and components. This includes styles for the AdminLTE 2.3.11 framework (with black and blue skin variants), IntroJS 7.2.0 for guided tours, Bootstrap-select v1.10.0 for enhanced dropdowns, and jQuery UI v1.11.4 for interactive widgets. Additionally, new styles were added for the bootstrap-datetimepicker, colorpicker, and jquery.tagsinput, while manifest files were reorganized to correctly bundle these assets for the admin interface.

_app/assets/stylesheets/camaleon\cms/admin · high confidence

Admin panel layout refactored with modularized partials and standardized breadcrumbs

The admin interface layout has been restructured to improve modularity and consistency. The main admin template now renders the header, sidebar, and footer as separate partials, and integrates the \breadcrumbs\_on\_rails\ gem for standardized breadcrumb navigation. Additionally, the layout now supports content injection hooks (\:before\_content\, \:after\_content\, \:head\) to allow custom CSS or scripts to be injected into the admin panel, and includes specific JavaScript inclusions for localized jQuery validation messages and Moment.js locales.

_app/views/layouts/camaleon\cms · high confidence

Admin search authorization and draft visibility controls

The admin panel now enforces stricter access controls: the search function is scoped to only return content types (posts, categories, tags) that the logged-in user has permission to manage, preventing unauthorized enumeration of drafts or private items. Additionally, viewing draft posts on the frontend is now gated by role-based permissions, allowing site administrators to restrict draft visibility to specific user roles via hooks.

_app/controllers/camaleon\cms · high confidence

Admin security hardening and frontend route modularization

The admin interface routes have been hardened to prevent state-changing actions (such as logout, trash/restore posts, widget deletion, and menu item deletion) from being triggered via GET requests, requiring POST, PATCH, or DELETE verbs instead to mitigate CSRF risks. The frontend routing system has been refactored to support relative URL roots, dynamic locale prefixes, and eager-loaded post type slugs, replacing the previous static locale-based route definitions with a more flexible structure that handles hierarchical posts and custom post types more robustly.

config/routes · high confidence

Admin settings reorganized into dedicated tabs with new configuration options

The admin settings interface has been restructured into distinct tabs: Configuration, SEO, Email, Filesystem, and Media. The Configuration tab now allows administrators to set the home and 404 pages, manage site status (including maintenance and inactive modes), control pagination, and toggle features like anonymous comments, user registration, and captchas. A new Email tab provides SMTP configuration and a test-email button. The Filesystem tab introduces AWS S3 storage support with fields for access keys, bucket, region, endpoint, and Cloudfront URL. The Media tab adds controls for maximum upload file size, thumbnail dimensions, and file actions in modals. The SEO tab includes a new Canonical URL field. Additionally, the Shortcodes viewer settings have been moved from the plugins directory into the main admin settings area.

_app/views/camaleon\cms/admin/settings · high confidence

Admin site management UI moved to dedicated settings views

The admin interface for managing CMS sites has been restructured into dedicated view files under app/views/camaleon\_cms/admin/settings/sites. The previous form, which was repurposed from an ecommerce tax rate form, has been replaced with a new form specifically for site creation and editing, featuring fields for domain slug, name, and description. A new index view provides a table listing all sites with their ID, name, slug, description, default status, and status, along with actions to edit, delete, or visit the site and its admin dashboard.

_app/views/camaleon\cms/admin/settings/sites · high confidence

Admin theme settings view replaced with placeholder comment

The admin interface for configuring theme settings no longer renders the dynamic custom fields form. Instead, the view now contains only a static HTML comment, meaning users will not see the previous custom field configuration options in the admin panel for themes.

app/apps/themes/new/views/admin · high confidence

Admin user management UI and credential security restrictions

The admin interface for managing users has been updated with a new form and list view. The user creation and editing form now enforces security restrictions (H10) that prevent non-admins from changing an admin's password, email, or username, and restricts role changes to admins only. The user list view now displays the last login time and includes an impersonation link for authorized users, while preventing users from deleting their own accounts.

_app/views/camaleon\cms/admin/users · high confidence

Attack model inherits from CamaleonRecord and specifies Site class

The Attack model in the attack plugin now inherits from CamaleonRecord instead of ActiveRecord::Base, aligning it with the platform's base record class. Additionally, the belongs\_to association for the site is now explicitly typed to CamaleonCms::Site, ensuring correct polymorphic or class resolution when loading related site data.

app/apps/plugins/attack/models · high confidence

Attack plugin configuration updates

The Attack plugin's configuration has been updated to include a descriptive link to its documentation in the plugin settings. Additionally, the plugin's initialization hook has been changed from 'app\_before\_load' to 'front\_before\_load', altering when the plugin loads relative to the application lifecycle. A new custom model configuration file was also added to define a relationship between the CamaleonCms Site and the Attack model.

app/apps/plugins/attack/config · high confidence

Centralized authorization and modularized plugin/theme controllers

The CMS now uses dedicated controllers for managing plugins and themes in both the admin and frontend areas. The new PluginsAdminController enforces explicit authorization checks via \authorize! :manage, :plugins\ before allowing any plugin management actions, addressing broken access control vulnerabilities. Additionally, these controllers standardize how plugin and theme view paths are resolved by dynamically adjusting the lookup context prefixes, ensuring that theme and plugin views are rendered correctly without duplication or path errors.

_app/controllers/camaleon\cms/apps · high confidence

Clean up bundled theme settings and installation logic

The bundled 'new' theme no longer ships with pre-loaded sample posts, categories, tags, or custom field groups, as the \data.json\ seed file has been removed. Additionally, the theme's settings save hook has been refactored to prevent redundant database writes and erroneous redirects by relying on the existing permitted field options path, and the installation process now safely checks for existing navigation menus before creating the default 'Main Menu'.

app/apps/themes/new · high confidence

Configure Camaleon CMS asset manifest for installation

The asset manifest for Camaleon CMS has been updated to explicitly include theme images, JavaScript, and stylesheets, as well as specific plugin assets like the contact form editor and admin navigation menu. This ensures that built-in theme assets and plugin scripts are correctly compiled and available when the installation generator runs, resolving previous issues where default theme assets were not properly linked.

app/assets/config · high confidence

Database schema modernization and media management

This update modernizes the database structure to improve performance, compatibility, and data organization. Key changes include migrating user first and last names from a meta table to dedicated columns for easier access, introducing a new media table to store file metadata separately, and adding email confirmation tokens to the user model. The schema also supports post features via a new boolean flag, optimizes post queries by replacing comment counts with explicit ordering and taxonomy IDs, and refines navigation menu structures. Additionally, field lengths for titles, slugs, and content are adjusted to support longer text, and the system now safely handles migrations across different database prefixes and character sets.

db/migrate · high confidence

Default text fallbacks and simplified post layout in default theme

The default theme views now provide English fallback strings for untranslated keys (e.g., 'No contents found', 'Text searched: ') to prevent empty labels when translations are missing. The post and page templates have been simplified by removing the empty entry-meta footer and the explicit render\_fields call, resulting in a cleaner post display. Additionally, pagination has been standardized across category, tag, type, and search views to use the new cama\_do\_pagination helper instead of the previous will\_paginate configuration.

app/apps/themes/default/views · high confidence

Default theme partials refactored and expanded with JSON API support

The default theme's view partials have been significantly restructured to support both enhanced frontend rendering and JSON API consumption. New JBuilder templates (\_cama\_category\_entry, \_cama\_post\_entry, \_cama\_posts\_entries, etc.) provide structured JSON responses for categories, posts, tags, and users, enabling integration with JavaScript frontends. The comment system now supports anonymous submissions with optional CAPTCHA and offers two distinct visual styles (standard and 'style2'). The sidebar partials have been updated to include related articles and tags, with a fix for the 'skip\_tags' option. Additionally, the post list item partial has been moved from the ecommerce plugin to the default theme and stripped of ecommerce-specific fields (SKU, price, stock) to serve as a generic content display component.

_app/views/camaleon\_cms/default\theme/partials · high confidence

Enhanced comment system with anonymous support and improved localization

The default theme's comment functionality now supports anonymous comments when the 'permit\_anonimos\comment' site option is enabled, requiring name, email, and optional CAPTCHA verification for unauthenticated users. Comment content is now sanitized by removing raw HTML rendering, and all user-facing text strings (titles, placeholders, buttons) have been updated to use proper translation helpers with English defaults. The search form and flash message partials have been standardized to use the new \cama\\ prefixed path helpers and consistent partial namespaces.

app/apps/themes/default/views/partials · high confidence

The default theme's taxonomy helper now escapes URLs and relationship attributes when generating link tags, preventing potential cross-site scripting (XSS) vulnerabilities in breadcrumb, sitemap, and taxonomy displays.

app/apps/themes/default · high confidence

Front Cache plugin gains restart preservation, TTL expiration, and admin purge controls

The front\_cache plugin now supports preserving cached pages across server restarts via a new 'preserve\_cache\_on\_restart' setting, preventing unnecessary cache misses after deployments. Stored pages are automatically expired after one week to prevent unbounded cache growth. The admin 'Clean Cache' action now explicitly purges stored pages in addition to clearing the cache index, and the plugin fails safely if settings metadata is missing rather than crashing the site.

_app/apps/plugins/front\cache · high confidence

Front Cache plugin initializes with cache refresh enabled and updates metadata

The Front Cache plugin now includes an initializer that automatically sets the 'refresh\_cache' option to true for all existing sites upon startup, ensuring the cache is refreshed after a server restart. Additionally, the plugin's configuration metadata has been updated to version 0.2, with a description linking to the official documentation and the removal of a comment from the JSON structure.

_app/apps/plugins/front\cache/config · high confidence

Front Cache settings UI: new preserve option, post-type grouping, and UI fixes

The Front Cache admin settings page now includes a 'Preserve cache on restart' checkbox, allowing users to keep cached content across application restarts. The 'Pages' and 'Skip cache pages' selectors have been refactored to group options by post type using \option\_groups\_from\_collection\_for\_select\, improving navigation for sites with multiple content types. Additionally, the custom URL paths help text now uses a localized tooltip, the back button link uses the correct \cama\_admin\_plugins\_path\, and the JavaScript initialization for the select picker has been corrected to use jQuery's ready handler.

_app/apps/plugins/front\cache/views · high confidence

Generator now includes placeholder for plugin locale directory

The Camaleon CMS gem plugin template generator now creates an empty \.keep\ file within the \config/locales\ directory. This ensures that the locales folder is included in the generated plugin structure, allowing developers to easily add translation files without needing to manually create the directory.

_lib/generators/camaleon\_cms/gem\_plugin\template/config/locales · high confidence

Genericons font paths updated to absolute URLs

The CSS for the default theme's Genericons has been updated to use absolute paths (starting with /assets/...) for the font files (EOT, TTF, SVG) instead of relative paths. This ensures the icon fonts load correctly regardless of the current page's URL structure. The trailing whitespace in the CSS file was also removed.

app/apps/themes/default/assets/genericons · high confidence

Hardened custom field permitting and enforced template/layout allow-lists

Admin controllers now use new concerns to secure and validate post data. Custom field submissions are strictly filtered against registered slugs for the specific object class, preventing mass-assignment vulnerabilities and avoiding crashes or data loss when receiving malformed or empty payloads. Additionally, template and layout selections are validated against the list of options actually offered by the current theme; non-admin users attempting to save unoffered template or layout values will be rejected, ensuring the frontend only receives valid view choices.

_app/controllers/concerns/camaleon\cms/admin · high confidence

Improved navigation security and localization in the default theme layout

The default theme layout now uses the \cama\_\-prefixed URL helpers (e.g., \cama\_admin\_dashboard\_path\) instead of the previous generic helpers, ensuring consistent routing within the application. User-facing text in the navigation dropdowns (Dashboard, Profile, Logout, Login, Register) is now pulled from locale files via \I18n.t\, enabling proper translation support. Additionally, the Logout action has been changed from a GET link to a POST request using \button\_to\, preventing accidental execution via CSRF or link-following attacks. The layout also explicitly includes the main JavaScript file and ensures the main stylesheet path includes the \.css\ extension.

app/apps/themes/default/views/layouts · high confidence

Improved output safety and code structure in Camaleon First theme helper

The Camaleon First theme's main helper has been refactored to improve security and maintainability. The \camaleon\_first\_list\_select\ method now uses Rails' \safe\_join\ and \content\_tag\ helpers instead of manually constructing HTML strings, ensuring that output is properly escaped and safe by default. Additionally, the module structure has been updated to use nested modules, and error handling in the \included\ hook has been made more specific to \StandardError\.

_app/apps/themes/camaleon\first · high confidence

Improved post visibility controls and date picker in the post editor

The post editor's visibility settings now enforce required fields more strictly: selecting 'Private' visibility automatically marks the user group input as required, while selecting 'Password protection' marks the password field as required. Additionally, the date/time selection for post publication has been updated to use a custom format (YYYY-MM-DD HH:mm) via the bootstrap-datetimepicker library, replacing the previous generic datepicker implementation. The plugin's documentation page has been removed.

_app/apps/plugins/visibility\post/assets · high confidence

Introduces site-aware HTML email sending with SMTP and attachment support

The application now uses a dedicated \HtmlMailer\ to send emails, allowing each site to configure its own SMTP settings (server, port, credentials) and sender address via admin options. This change supports sending HTML or plain text emails with file attachments, CC recipients, and inline content, while also providing a hook (\email\_late\) to modify delivery options before sending.

_app/mailers/camaleon\cms · high confidence

Layout templates updated for security, routing, and asset consistency

The layout templates in the new theme app have been updated to improve security and consistency. The logout action now requires a POST request via a form button to prevent CSRF attacks, replacing the previous GET link. User session references have been standardized to use the \cama\_current\user\ helper, and all navigation links now point to the \cama\\ prefixed routes (e.g., \cama\_admin\_dashboard\_path\). Additionally, the header logo link now uses the site's configured URL instead of the root path, and the main stylesheet asset path has been corrected to include the \.css\ extension.

app/apps/themes/new/views/layouts · high confidence

Major overhaul of PluginRoutes and core library structure

The \lib/plugin\_routes.rb\ file has been significantly refactored to improve thread safety and error handling during route loading. The previous implementation, which used a global variable and fragile string concatenation with bare \rescue\ clauses, has been replaced with a class-based structure using \Monitor\ for thread safety and explicit \begin/rescue\ blocks that catch \StandardError\ to prevent persistent 500 errors. Additionally, the core library entry point (\lib/camaleon\_cms.rb\) has been restructured to explicitly require new security modules (\content\_security\, \svg\_content\_checker\, \media\_security\_headers\, \uploader\_content\_security\, \uploader\_path\_security\) and initialize a shortcode registry at boot time to enforce permission gates. Legacy files like \aes\_crypt.rb\ and \ca-bundle.crt\ have been removed, indicating a shift away from bundled cryptography and certificate bundles.

lib · high confidence

Media uploader now enforces CSRF protection and adds image cropping

The admin media uploader now requires a CSRF token on the server-side media\#upload endpoint, with the client-side JavaScript reading the token directly from the meta tag to ensure secure form submissions. Additionally, the uploader now includes the Cropper v2.3.4 library, enabling users to crop images to specific dimensions directly within the media manager interface.

_app/assets/javascripts/camaleon\cms/admin/uploader · high confidence

Migrate JavaScript dependencies and remove CoffeeScript support

The theme's JavaScript asset pipeline has been updated to drop support for CoffeeScript files, requiring all scripts to be written in plain JavaScript. The main.js manifest now replaces the previous local jQuery and Bootstrap includes with a global 'jquery2' requirement and the 'camaleon\_cms/bootstrap.min' plugin, while the dedicated 'modal\_elfinder' plugin file has been removed entirely.

app/apps/themes/new/assets/js · high confidence

Migrate theme JavaScript to jQuery 2 and plain JavaScript

The default theme's client-side code has been migrated from CoffeeScript to standard JavaScript and updated to depend on jQuery 2. This change replaces the previous jQuery version and CoffeeScript compilation step, ensuring the theme's interactive components now run on the newer jQuery API and standard JS syntax.

app/apps/themes/default/assets/js · high confidence

New installation templates for plugin routes and system configuration

The installation generator now includes a new \plugin\_routes.rb\ template that dynamically reads and joins Gemfile configurations from plugins and themes to avoid route conflicts, and a \system.json\ template that sets default configuration values such as \auto\_include\_migrations\ (defaulting to false) and \db\_prefix\.

_lib/generators/camaleon\_cms/install\template · high confidence

New theme generator template with updated assets and security hardening

The theme generator now provides a complete starter template (lib/generators/camaleon\_cms/theme\_template) that includes a layout using jQuery 2 and Bootstrap, a manifest-based asset structure for CSS and JavaScript, and a helper module with hooks for theme installation and settings. The layout template has been updated to use POST-based logout via button\_to for improved security, and the admin settings view has been simplified to remove auto-rendered custom fields, requiring explicit hook-based saving.

_lib/generators/camaleon\_cms/theme\template · high confidence

Password-protected posts now use secure session-based unlocking and hide excerpts

The Visibility Post plugin now requires users to submit passwords via a secure POST request to unlock content, replacing the previous method that exposed passwords in URLs and logs. Upon successful authentication, the post remains unlocked for the current session using a server-side marker, and the password is compared in constant time to prevent timing attacks. Additionally, password-protected posts now display a placeholder excerpt ('This content is password protected.') in listings and feeds, preventing the post body from leaking through derived content representations.

_app/apps/plugins/visibility\post · high confidence

Plugin generator templates now include secure settings handling

The gem plugin generator templates for the admin and front controllers have been updated to include a settings form and a secure save mechanism. The admin controller now incorporates \CamaleonCms::Admin::CustomFieldsConcern\ and uses \cama\_permitted\_field\_options\ to confine submitted field values to slugs registered by the plugin, preventing unauthorized modification of settings. This ensures that plugin developers generating new plugins via the template start with a secure baseline for managing plugin configuration.

_lib/generators/camaleon\_cms/gem\_plugin\_template/app/controllers/plugins/my\plugin · high confidence

Plugins page now uses tabs and secure toggle actions

The admin plugins interface has been restructured to separate active and disabled plugins into distinct tabs, improving navigation clarity. The mechanism for enabling or disabling plugins has been updated to use a PATCH request with a confirmation dialog, preventing accidental activation or deactivation via simple GET links. Additionally, the view now supports custom plugin-specific action links through a new 'plugin\_options' hook.

_app/views/camaleon\cms/admin/plugins · high confidence

Post type settings now use a tabbed interface with expanded configuration options

The admin interface for managing post types has been restructured to use a tabbed layout (Admin, Visitor, and Custom) within the settings form. This change introduces several new configuration capabilities: administrators can now define post type icons using FontAwesome v4.7.0, manage page hierarchies via a parent structure setting, and configure image handling including specific dimensions, thumbnail versions, and required image flags. Additionally, the form supports managing layouts, templates, categories (single or multiple), tags, content, summaries, comments, featured status, and SEO settings, with hooks available for extending the sidebar and form areas.

_app/views/camaleon\_cms/admin/settings/post\types · high confidence

Rails 7 compatibility and theme-scoped partial rendering isolation

This update ensures compatibility with Rails 7 by introducing a new ActionView initializer that re-implements the private \args\_for\_lookup\ method, which was removed in Rails 7, and adds logic to isolate theme-scoped partial lookups so that templates from one theme do not leak into another. It also replaces the legacy ElFinder image processing initializer with new Sass functions (\asset\_theme\_path\, \asset\_theme\_url\, etc.) that correctly resolve theme and plugin asset paths, and updates the \sort\_by\_field\ API to whitelist the sort direction (ASC/DESC) to prevent SQL injection. Additionally, the initializer now supports loading custom plugin/theme initializers and model aliases, and patches the asset pipeline to correctly render TinyMCE icons in development environments.

config/initializers · high confidence

Rails application structure modernization and configuration expansion

The Rails application entry point has been refactored from the custom WPRails module to the standard Rails.application, and legacy database configuration files (MySQL, SQLite, and the main database.yml) along with boot, environment, New Relic, and sitemap configuration files have been removed. Route definitions are now scoped under a configurable relative URL root, and the system configuration (system.json) has been expanded to support new features including custom admin paths, custom user models, media slug folder settings, automatic migration inclusion, and a default layout, while also updating the default plugin set and adding support for additional languages such as Arabic, Dutch, Chinese, Russian, and Ukrainian.

config · high confidence

Rebuilt admin media library with private file support and upload-from-URL capability

The admin media management interface has been replaced with a new implementation that supports browsing private media files (with URLs resolved via a dedicated download endpoint) and uploading files directly from external URLs. The new gallery view includes a search bar, folder navigation, and a side panel for uploading files or viewing file info, while file actions like editing and deletion are now gated by configurable hooks to verify permissions before allowing changes.

_app/views/camaleon\cms/admin/media · high confidence

Rebuilt admin posts and comments interfaces with AJAX and draft support

The admin interface for managing posts and comments has been rebuilt to use AJAX-driven interactions and improved draft handling. The new post list view includes status filtering, search, and direct links to edit or preview posts. The post creation and editing forms now support private draft autosaving, allowing users to save and recover their own drafts without affecting other users' work. The sidebar has been enhanced with options to manage templates, layouts, page hierarchy, categories, tags, and featured images. Additionally, a new modular comments system allows administrators to view, create, and reply to comments directly from the admin panel, with forms integrated into the AJAX workflow.

_app/views/camaleon\cms/admin/posts · high confidence

Redesigned admin authentication and session management views

The admin login, registration, password recovery, and logout flows have been completely rewritten with a new UI structure. The login page now includes a 'Remember me' checkbox and a 'Forgot Password' link, while the registration form collects first and last names alongside email and username, with optional CAPTCHA support. A new 'Back to Parent' view allows users impersonating an admin to securely re-authenticate with their own password without exposing the target admin's username. Logout is now protected by a confirmation step that requires a POST request, preventing accidental session termination via GET links or forged requests. All views use standardized translation keys and consistent form styling.

_app/views/camaleon\cms/admin/sessions · high confidence

Redesigned admin interface for managing widgets and sidebars

The admin panel for widget and sidebar management has been rebuilt with new views. Administrators can now create and edit widgets (including simple and complex types with custom fields) and sidebars via dedicated forms. The main index page displays available simple widgets in a card layout, while the sidebar management view lists sidebars and allows assigning widgets to them via an AJAX-driven form. All navigation links and form actions have been updated to use the new \cama\_\ URL helpers.

_app/views/camaleon\cms/admin/appearances/widgets · high confidence

Redesigned user role management with administrator safeguards and select\_eval confirmation

The admin interface for managing user roles has been updated to provide clearer permission controls and safety checks. Administrators are now explicitly informed that their role holds all permissions, with the corresponding checkboxes locked and disabled to prevent accidental changes. Additionally, enabling the 'select\_eval' permission now triggers a confirmation modal to prevent unintended actions. The role editing form also supports editing titles and descriptions for private roles, and the index view now correctly displays whether roles are editable or locked.

_app/views/camaleon\_cms/admin/user\roles · high confidence

Refactor helpers to use CurrentRequest and harden security

The helper modules in app/helpers/camaleon\_cms have been refactored to store request-scoped state in CurrentRequest instead of instance variables, improving reliability and testability. This change introduces several security hardening measures: captchas are now single-use and throttled per client IP to prevent brute-force attacks, session cookies are rotated on sign-in and logout to prevent impersonation residue, and open redirects are blocked by validating return\_to destinations against a host allowlist. Additionally, the comment moderation view now escapes commenter names to prevent stored XSS, and the email helper uses read\_attribute to safely access password reset tokens across Rails versions.

_app/helpers/camaleon\cms · high confidence

Refactor model base class and introduce request-scoped state

The \app/models\ directory has been restructured to improve isolation and thread safety. All CMS models now inherit from a new \CamaleonRecord\ base class instead of \ApplicationRecord\, preventing method and data pollution from the main Rails application. A new \CurrentRequest\ class using \ActiveSupport::CurrentAttributes\ has been added to manage per-request state (such as the current user and site) in a thread-safe manner, replacing the previous instance-variable-based approach. Additionally, the standalone \Ability\ model has been removed, with authorization logic now integrated directly into \CamaleonRecord\ to delegate to the central CanCan ability system.

app/models · high confidence

Refactored CMS model concerns for security, data integrity, and performance

This change introduces a suite of new model concerns in app/models/concerns/camaleon\_cms that fundamentally improve how the CMS handles content, relationships, and security. The new ContentShortcodeGate concern enforces a fail-closed security model, preventing non-administrator users from saving content containing shortcodes unless they hold the specific 'content\_shortcodes' permission, thereby mitigating stored XSS risks. Data integrity is strengthened by CategoriesTagsForPosts, which prevents duplicate category/tag assignments and ensures category counts are accurately updated, and by Metas, which now robustly handles JSON serialization, indifferent key access, and transaction-safe queuing of meta/option writes. CommonRelationships standardizes association scoping by demodulized class names to support Single Table Inheritance (STI) and custom user models, while NormalizeAttrs ensures consistent sanitization of translatable fields. Additionally, UserMethods now rotates authentication tokens on logout to invalidate stolen cookies and reassigns orphaned comments to an anonymous user upon deletion, and SiteDefaultSettings generates random admin passwords on first install instead of using a hardcoded default.

_app/models/concerns/camaleon\cms · high confidence

Refactored controller runtime concerns and hardened comment submission

The controller logic in app/controllers/concerns/camaleon\_cms has been reorganized into a set of focused runtime concerns (such as FrontendConcern, RequestContextConcern, and RuntimeStateConcern) to improve modularity and maintain a single source of truth for shared helpers. As part of this refactor, the frontend comment submission endpoint (save\_comment) has been hardened to prevent 500 errors from crafted requests, including validation of the post\_comment parameter shape, safe handling of missing parent comments, and secure redirect vetting. Additionally, anonymous comments are now supported when permitted by site settings, and the frontend visited state tracking has been migrated to use the CurrentRequest object with deprecation warnings for legacy instance variables.

_app/controllers/concerns/camaleon\cms · high confidence

Refactored frontend helpers to use CurrentRequest state and improved URL handling

The frontend helper module has been restructured into focused concerns (Application, ContentSelect, NavMenu, SEO, Site) that now rely on the \CurrentRequest\ object for state management instead of legacy instance variables. This change improves URL generation by automatically appending the current locale to links when multiple languages are configured, fixes the \the\_url\ method to return correct host information in console contexts, and enhances navigation menus with better current-item detection and support for custom link attributes. SEO attributes are now customizable via code without hooks, and post content rendering uses a scan-and-reject security policy to prevent stored XSS while preserving trusted HTML.

_app/helpers/camaleon\cms/frontend · high confidence

Removal of Draper-based view decorators

The application has removed the entire \app/decorators\ directory, deleting all Draper decorator classes (including \ApplicationDecorator\, \PostDecorator\, \SiteDecorator\, etc.) that previously handled view-level presentation logic such as URL generation, breadcrumb construction, and localized content formatting. This change eliminates the Draper dependency for these models, meaning the presentation methods previously provided by these decorators are no longer available in the view layer.

app/decorators · high confidence

Removal of TinyMCE Visual Blocks styles and flash message partial

The TinyMCE Visual Blocks plugin's CSS file has been removed, meaning the dashed borders and background icons that previously helped distinguish HTML elements in the editor will no longer appear. Additionally, the shared \\_flash\_messages.html.erb\ partial has been deleted, which removes the centralized rendering logic for notice, info, error, and alert flash messages across the application.

app/assets/javascripts/admin/tinymce/plugins/visualblocks, app/views · high confidence

Removal of custom field rendering from admin settings view

The admin settings view no longer renders the custom field groups for the current theme. The specific partial responsible for displaying these theme fields has been removed from the view template, meaning users will no longer see or be able to edit custom field groups directly within the theme settings interface.

app/apps/themes/default/views/admin · high confidence

Removal of custom public error pages and robots.txt

The custom static error pages (404, 422, 500) and the robots.txt file in the public directory have been deleted. Users will no longer see the branded error templates (such as the '500 bear' design) or the specific robots.txt directives; instead, the application will fall back to default error handling or framework-provided responses for these scenarios.

public · high confidence

Removal of default theme helper and settings logic

The \main\_helper.rb\ file, which previously provided default methods for saving theme settings, handling theme installation (including adding default field groups like 'Main Settings' with background color and image fields), and handling theme uninstallation, has been removed from the theme template. Users generating this theme will no longer have these default helper methods and installation behaviors available out of the box.

_lib/generators/ctheme\_template/app/apps/themes/my\theme · high confidence

Removal of default theme partials

The default theme's view layer has been significantly reduced by deleting ten partial templates, including those for breadcrumbs, category carousels, comments, flash messages, forms, post listings, custom fields, search, and the sidebar. This change removes the standard UI components and layout structures previously provided by the default theme, likely indicating a shift to a new theme implementation or a restructuring of the view hierarchy.

_app/views/default\theme/partials · high confidence

Removal of embedded Bootstrap v3.3.4 styles

The application no longer includes the embedded Bootstrap v3.3.4 CSS file (\bootstrap.min.css.scss\). This change removes the built-in grid, form, button, and component styles from the asset pipeline, meaning the application will no longer render with Bootstrap's default appearance unless these styles are provided by an external source or gem.

app/assets/stylesheets · high confidence

Removal of legacy Contact Form admin views

The admin interface for the Contact Form plugin has been refactored by deleting the previous view templates (\_form.html.erb, edit.html.erb, manual.html.erb, and responses.html.erb). This change removes the old form creation, editing, help documentation, and response listing UIs, indicating a migration to a new view structure or component system elsewhere in the application.

_app/apps/plugins/contact\_form/views/admin\forms · high confidence

Removal of legacy Elfinder-based media management views

The previous media administration interface, which relied on the Elfinder file manager for both the main listing and modal selection, has been removed. Specifically, the \app/views/admin/media/iframe.html.erb\ (used for modal file selection) and \app/views/admin/media/index.html.erb\ (the main media manager page) are deleted. This indicates a shift away from the Elfinder integration for media handling in the admin panel.

app/views/admin/media · high confidence

Removal of legacy HtmlMailer class

The custom HtmlMailer class, which previously handled email sending with hardcoded default sender addresses and manual attachment logic, has been removed from the application. This change eliminates the legacy mailer implementation, likely as part of a broader refactoring to standardize email delivery or migrate to a different mailer configuration.

app/mailers · high confidence

Removal of legacy admin helper modules

The admin interface no longer includes the legacy helper modules that previously managed the left-hand navigation menu, breadcrumb trails, and custom field type definitions. Specifically, the \Admin::ApiHelper\, \Admin::ApplicationHelper\, \Admin::BreadcrumbHelper\, \Admin::CategoryHelper\, \Admin::CustomFieldsHelper\, \Admin::MenusHelper\, and \Admin::PostTypeHelper\ files have been deleted. This change removes the underlying logic responsible for rendering the admin sidebar structure, generating breadcrumb paths, and defining the UI options for custom field inputs (such as text boxes, select lists, and color pickers).

app/helpers/admin · high confidence

Removal of legacy admin user management views

The admin interface for managing users has been refactored by removing the previous standalone view templates. Specifically, the old user creation/editing form (\form.html.erb\), the user listing page (\index.html.erb\), the user profile display (\profile.html.erb\), and the profile editing page (\profile\_edit.html.erb\) have been deleted from the application. This change eliminates the legacy UI components for user administration, including the associated modals for changing photos and passwords, and the static timeline placeholder previously found in the profile view.

app/views/admin/users · high confidence

Removal of shortcode template views

The \form.html.erb\ and \widget.html.erb\ views within the \shortcode\_templates\ directory have been removed. This eliminates the previous behavior where shortcode forms were rendered via a partial and widgets were displayed by looking up site-specific widget records or rendering plugin-specific partials (such as the visits counter).

_app/views/shortcode\templates · high confidence

Removed legacy custom field templates

The individual view templates for all custom field types (audio, checkbox, colorpicker, date, editor, email, file, image, numeric, phone, posts, radio, select, text\_area, text\_box, url, users, and video) have been deleted from the admin settings interface. This removes the previous inline rendering logic for these specific field inputs, indicating a shift to a different rendering mechanism or template structure elsewhere in the application.

_app/views/admin/settings/custom\fields/fields · high confidence

Removed placeholder .keep file from images directory

The .keep placeholder file in the app/assets/images directory has been deleted. This file was previously used to ensure the directory was tracked by version control when empty; its removal indicates the directory now contains actual assets or is managed differently.

app/assets/images · high confidence

Removed placeholder views and layout documentation from my\_plugin template

The my\_plugin generator template no longer includes the default admin and frontend index views (which previously displayed 'Plugin ready to use' messages) or the layout documentation file. Users generating this plugin will no longer receive these static placeholder pages or the instructions for custom layout loading, resulting in a cleaner, empty view structure that requires manual implementation.

_lib/generators/cplugin\_template/app/apps/plugins/my\plugin/views · high confidence

Removed unused theme assets from Camaleon CMS

The Camaleon CMS theme has been cleaned up by deleting a collection of unused static assets, including CSS files (animate.css, blue.css, bootstrap.css, dark.css, form.css, google-fonts.css, green.css, header.css, jquery.fancybox.css, main.css), a web font definition file (web-fonts.css), and the associated SVG web font (BEBAS\\\_-webfont.svg). This reduces the theme's footprint by removing styles and fonts that are no longer referenced.

_app/apps/themes/camaleon\cms, app/assets/javascripts/admin/tinymce/plugins/media · high confidence

Removes default plugin controller and helper templates

The plugin generator no longer includes the default AdminController, FrontController, and MainHelper template files. Users generating a new plugin will no longer receive these pre-scaffolded files, meaning they must manually create their own controller and helper structures if needed rather than inheriting from the previous default implementations.

_lib/generators/cplugin\_template/app/apps/plugins/my\plugin · high confidence

Shortcodes are now processed within widget descriptions

Widgets can now include shortcodes in their description content, which are automatically evaluated and rendered when the widget is displayed. This allows for more dynamic and flexible widget content without requiring custom rendering logic for every case.

_app/views/camaleon\_cms/shortcode\templates · high confidence

Standardize bin scripts with Bundler binstubs

The project has replaced legacy, manually maintained bin scripts with standard Bundler-generated binstubs for rake, rspec, rubocop, brakeman, and bundle-audit. This change ensures these tools run against the correct gem versions defined in the Gemfile, improves cross-platform compatibility by removing Windows-specific shebangs, and adds safety checks to verify the integrity of the bundle binstub. Additionally, the rails and rake scripts were updated to properly initialize the Rails engine environment, and the old bin/bundle file was removed.

bin · high confidence

Theme CSS refactored to use shared libraries and fix logout menu styling

The theme's CSS asset pipeline has been updated to replace the local Bootstrap copy with the shared \camaleon\_cms/bootstrap.min\ library and added a dependency on \font-awesome\. Additionally, custom styles were added to the logout menu button to ensure it visually matches standard dropdown links, addressing a styling inconsistency identified during a security audit.

app/apps/themes/new/assets/css · high confidence

Theme view updates: pagination, security, and UI adjustments

The new theme's views now use a custom pagination helper (\cama\_do\_pagination\) instead of the previous \will\_paginate\ with Bootstrap renderer, affecting category, post\_tag, post\_type, and search pages. To improve security and fix potential XSS issues, raw HTML output has been removed from the post title in \post.html.erb\ and the post type excerpt in \index.html.erb\. Additionally, image sources in the \index.html.erb\ carousel were updated from HTTP to HTTPS, a default fallback was added to the 'no contents found' translation key, and an edit link was added to post type captions.

app/apps/themes/new/views · high confidence

Update JavaScript dependencies and remove CoffeeScript support

The theme's JavaScript manifest now requires jQuery 2 instead of the previous jQuery version and loads the Bootstrap library from the Camaleon CMS vendor directory rather than the local assets. Additionally, the manifest comment has been updated to reflect that only JavaScript files are supported, indicating the removal of CoffeeScript compilation support in this asset pipeline.

_app/apps/themes/camaleon\first/assets/js · high confidence

Update admin settings view to use Camaleon CMS helpers and translations

The admin settings view for the attack plugin now uses the \cama\_admin\_plugins\_path\ helper for the back button link and the \camaleon\_cms\ translation scope for UI strings, ensuring consistent routing and localization within the Camaleon CMS environment. Additionally, the generic \readme.txt\ file in the views directory has been removed.

app/apps/plugins/attack/views · high confidence

Updated AdminLTE JavaScript to version 2.3.11

The main AdminLTE JavaScript file (app.js) has been updated to version 2.3.11. This update includes the latest layout options and plugin implementations for the admin interface, such as sidebar push menu, control sidebar, and box widget behaviors, ensuring the admin UI aligns with the current AdminLTE release.

_app/assets/javascripts/camaleon\cms/admin/lte · high confidence

Updated Moment.js library and added new locale files

The admin interface now uses Moment.js version 2.11.2, replacing the previous version. This update includes new locale configuration files for Arabic, Catalan, German, Spanish, French, Italian, Japanese, Dutch, Polish, Brazilian Portuguese, Portuguese, Russian, Ukrainian, and Simplified Chinese, enabling proper date and time formatting in these languages within the CMS admin area.

_app/assets/javascripts/camaleon\cms/admin/momentjs · high confidence

Updated gem plugin model template to use CamaleonRecord

The model template for generated gem plugins now inherits from \CamaleonRecord\ instead of \ApplicationRecord\. This change ensures that plugin models correctly integrate with the Camaleon CMS base class, aligning with the platform's internal architecture for record handling.

_lib/generators/camaleon\_cms/gem\_plugin\_template/app/models/plugins/my\plugin · medium confidence

Upgrade Bootstrap to v3.4.1 and add source maps

The Camaleon CMS frontend stylesheets have been updated to use Bootstrap v3.4.1, replacing the previous v3.3.4. This update brings the latest bug fixes and improvements from the Bootstrap 3.4.x series to the CMS interface. Additionally, a source map file (bootstrap.min.css.map) has been added to support debugging and development workflows.

_app/assets/stylesheets/camaleon\cms · high confidence

Widget system refactored to use STI and explicit associations

The widget management system has been restructured to use Single Table Inheritance (STI) and explicit model relationships. New models have been introduced: \CamaleonCms::Widget::Main\ (representing the widget definition), \CamaleonCms::Widget::Sidebar\ (representing container locations), and \CamaleonCms::Widget::Assigned\ (linking widgets to sidebars). This change replaces the previous implicit or generic post-based storage with a dedicated schema, allowing for type-safe relationships, proper inverse associations, and clearer separation between widget definitions, their placement in sidebars, and the assignment data itself.

_app/models/camaleon\cms/widget · high confidence

Fixes

Fixes for brute-force bypass and output safety in the Attack plugin

The Attack plugin now correctly throttles requests by client IP address instead of session ID, preventing attackers from bypassing rate limits by rotating cookies or using cookieless sessions. Additionally, the plugin has been updated to use safe HTML rendering for ban messages and standardized time handling, improving both security posture and output safety for administrators.

app/apps/plugins/attack · high confidence

Fixes for email templates, sample pages, and homepage content rendering

The camaleon\_first theme now includes dedicated mailer and sample page templates to support email notifications and custom post displays. The homepage view has been refactored to use a dedicated helper for determining the home page, and translation strings for 'latest articles' now include a default fallback. Additionally, a broken external image link in the portfolio section has been updated to a working HTTPS URL.

_app/apps/themes/camaleon\first/views · high confidence

Fixes to email template and theme layout assets

This change introduces a new email layout template for mailers, ensuring consistent branding with the site logo and a visit link. It also corrects the main theme layout by specifying the .css extension in the stylesheet link tag, adding dynamic CSS classes to the body element to distinguish between home and inner pages, and fixing a typo in the language list class name.

_app/apps/themes/camaleon\first/views/layouts · high confidence

Restored default theme stylesheets

The missing default theme CSS file (style.css.scss) has been added back to the repository, restoring the standard Twenty Thirteen theme styling for the application.

app/apps/themes/default/assets/css · high confidence

Updated theme asset dependencies and navigation styling

The Camaleon First theme now explicitly requires the Camaleon CMS-specific Bootstrap version and Font Awesome, ensuring consistent styling and icon rendering. The navigation menu has been enhanced with new CSS rules to support multi-level dropdowns, including specific positioning and color overrides for submenus. Additionally, image asset paths have been updated to use the application's asset pipeline helpers, and the language list items now display reduced opacity for non-active items to improve visual hierarchy.

_app/apps/themes/camaleon\first/assets/css · high confidence

Test coverage

Added dummy Rails application for testing; Added frontend regression tests for custom field i18n rendering and post visibility; Added test coverage for controller concerns, decorators, and dummy application; Added tests for attack plugin throttle and output safety; Added tests for front\_cache security and correctness fixes; Expanded feature test coverage for admin interface; Removal of legacy test infrastructure and stubs.

Dependencies

New development tooling and configuration files

The repository now includes configuration files for RuboCop (\.rubocop.yml\, \.rubocop\_todo.yml\), ESLint (\.eslintrc.js\), Bundler audit (\.bundler-audit.yml\), and RSpec (\.rspec\), along with a \.tool-versions\ file specifying Ruby 3.4.10 and Node.js 24.15.0. These files standardize code quality checks, security auditing, and development environment versions for contributors.

(repo-wide) · high confidence

Updated CI gemfiles for Rails 7.1, 7.2, 8.0, 8.1, and edge

The CI configuration now includes dedicated gemfiles for testing against Rails 7.1, 7.2, 8.0, and 8.1, as well as an edge file pointing to the upcoming 8.2 release. These updates ensure compatibility with the latest Rails versions, with the edge file specifically pinning sqlite3 to version 2.0 and allowing non-digest-assets 2.6.0.

gemfiles · high confidence

Updated bundled jQuery and Bootstrap JavaScript libraries

The theme's bundled client-side libraries have been upgraded: jQuery is updated from version 2.1.1 to 3.2.0, and Bootstrap is updated from version 3.2.0 to 3.3.7. This ensures the theme uses the latest bug fixes and features provided by these core dependencies.

app/apps/themes/new/assets/js/plugins/bootstrap, app/apps/themes/new/assets/js/plugins/jquery · high confidence

Upgrade to Rails 8.1 and modernize dependency stack

The application has been upgraded from Rails 4.2 to Rails 8.1, requiring a minimum Ruby version of 3.0. This change replaces legacy asset pipelines (sass-rails, uglifier, coffee-rails) with dartsass-sprockets and non-digest-assets, and updates core dependencies such as draper (\>= 4.0.2), cancancan (\>= 2.0), and cama\_contact\_form (\~\> 0.1.15). The gemspec now explicitly pins json to versions below 3 to ensure compatibility, and development tooling has been updated to include RuboCop, Brakeman, and RSpec configurations suitable for the new environment.

(dependencies) · high confidence

Housekeeping

Placeholder for plugin migration files

A .keep file has been added to the plugin template's migration directory to ensure the folder is tracked by version control, providing a standard location for future database schema changes in generated plugins.

_lib/generators/camaleon\_cms/gem\_plugin\template/db · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 46.

Lenses

  • Code Health 46
  • Architecture 93
  • Maturity 61
  • Readiness 74
  • Security 60
  • Domain Modelling 100
  • Accessibility 32

Changes since last survey

  • 300 commits — 276 feature/other, 24 fixes

By area

  • (root) — 51 commits
  • openspec/changes — 47 commits
  • app/models — 46 commits
  • (repo) — 29 commits
  • app/controllers — 20 commits
  • docs/ai — 13 commits
  • app/assets — 12 commits
  • spec/models — 11 commits
  • spec/requests — 9 commits
  • app/apps — 8 commits
  • app/uploaders — 7 commits
  • spec/apps — 6 commits
  • app/helpers — 5 commits
  • openspec/specs — 4 commits
  • spec/features — 4 commits
  • spec/shared_specs — 4 commits
  • docs/security — 3 commits
  • docs/upgrading-to-2.9.5.md — 3 commits
  • lib/tasks — 3 commits
  • spec/lib — 3 commits

Notable commits

  • fix: Add changelog entry for post published_at fix
  • fix: Add the changelog entry for the STI-root destroy fix
  • fix: Add the changelog entry for the current_site log advice fix
  • fix: Add the changelog entry for the data_options fix
  • fix: Add the changelog entry for the delete_meta fix
  • fix: Add the changelog entry for the dup and reload cache fix
  • fix: Archive the fix-same-instance-option-reads OpenSpec change
  • fix: Correct the write-rule docs for the broadened fix
  • fix: Fix NameError destroying an STI-root term taxonomy row
  • fix: Merge pull request #1276 from owen2345/fix/post-published-at-on-publish
  • fix: Merge pull request #1280 from owen2345/fix/host-app-factory-overrides
  • fix: Merge pull request #1285 from owen2345/fix/media-folder-self-recursion
  • fix: Merge pull request #1286 from owen2345/fix/media-is-public-visibility
  • fix: Merge pull request #1287 from owen2345/fix/term-taxonomy-base-class-destroy
  • fix: Merge pull request #1288 from owen2345/fix/custom-field-colorpicker-coercion
  • fix: Merge pull request #1296 from owen2345/fix/run-hook-handlers-once
  • fix: Merge pull request #1298 from owen2345/fix/delete-meta-in-memory-metas
  • fix: Merge pull request #1299 from owen2345/fix/save-data-options-once
  • fix: Merge pull request #1300 from owen2345/fix/current-site-log-advice
  • fix: Merge pull request #1301 from owen2345/fix/meta-cache-dup-and-reload
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

owen2345/camaleon-cms was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 47eec93bfae46258e5c7a827381b1aa87d159838 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.