Skip to content
CAI
Software that uses CAICheck a score

palkan/action_policy

50.1

Adequate · 19 September 2026

6.2k

lines of production code

Ruby

with JavaScript, TypeScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the ActionPolicy library, a Ruby gem that provides a structured framework for defining and enforcing authorization rules within applications. It offers core capabilities for policy resolution, rule evaluation, and data scoping, with specific integrations for Rails controllers, channels, and ActiveRecord relations. The library also includes tooling for testing via RSpec matchers, performance optimization through memoization and caching, and developer aids like code generation and debugging utilities.

How it got here

2018 — ActionPolicy library initialization and core feature development

24 changes.

This period focused on initializing the ActionPolicy authorization library, establishing its core API, and implementing essential features such as policy lookup, namespacing, scoping, and memoization. Significant effort was dedicated to building first-class integrations for Rails and RSpec, alongside comprehensive test coverage and performance benchmarking to ensure stability and usability.

2019–2026 — Developer tooling and observability

10 changes.

This period focused on enhancing the developer experience by introducing Rails generators for scaffolding policies and tests, alongside an experimental Ruby LSP addon for better code navigation. It also expanded observability through instrumentation events and added utilities for monitoring SQL query performance. Additionally, the work included establishing a robust testing infrastructure with a dummy Rails app and creating a WebAssembly-based tutorial kit for interactive learning.

Features

Add Rails generator for creating policies with configurable parent class

A new \action\_policy:policy\ Rails generator has been added, allowing users to scaffold policy classes via \rails generate action\_policy:policy\. The generator automatically invokes the \action\_policy:install\ generator if the base \ApplicationPolicy\ does not yet exist, ensuring the necessary foundation is in place. It also supports a \--parent\ option, enabling users to specify a custom parent class (defaulting to \ApplicationPolicy\) for the generated policy, which facilitates inheritance hierarchies in larger applications.

_lib/generators/action\policy/policy · high confidence

Add Rails generator for installing base policy class

Users can now run the \rails generate action\_policy:install\ command to automatically create a base \ApplicationPolicy\ class in \app/policies/\. This generator scaffolds a standard policy structure inheriting from \ActionPolicy::Base\, including comments that guide configuration of authorization contexts and shared helper methods.

_lib/generators/action\policy/install · high confidence

Added Rails generators for Action Policy specs

Users can now generate RSpec and Test Unit policy specifications using the new \rails generate rspec:policy\ and \rails generate test\_unit:policy\ commands. The RSpec generator creates a spec file in \spec/policies\ with stubbed examples for \index?\, \create?\, and \manage?\ rules, while the Test Unit generator creates a corresponding test file in \test/policies\ with empty test methods for the same rules.

lib/generators/rspec · high confidence

Added Ruby refinements for string, hash, and module utilities

This change introduces a set of new refinement modules in lib/action\_policy/ext to provide standard utility methods for older Ruby versions and non-Rails environments. Specifically, it adds String\#safe\_constantize and String\#underscore, Symbol\#camelize, Hash\#transform\_keys, Module\#namespace, and Object\#\_policy\_cache\_key (along with refinements for NilClass, TrueClass, FalseClass, String, Symbol, Numeric, Time, and Module). These refinements ensure consistent behavior for naming conventions, constant lookup, and caching keys across different Ruby versions and frameworks.

_lib/action\policy/ext · high confidence

Adds instrumentation events for policy initialization and rule application

The library now emits ActiveSupport::Notifications events to allow monitoring of policy execution. Specifically, an \action\_policy.init\ event is fired whenever a policy is initialized, and an \action\_policy.apply\_rule\ event is fired for every rule application, including details such as the policy name, rule name, cache status, and result value in the payload.

_lib/action\policy/rails/policy · high confidence

Experimental Ruby LSP addon for ActionPolicy

An experimental Ruby LSP addon for ActionPolicy has been added, enabling definition navigation for authorization rules. When a user invokes 'go to definition' on an \authorize!\ call within a controller or channel, the addon locates the corresponding policy class, parses the policy file to identify rule definitions (including those aliased via \alias\_rule\), and provides a link to the specific line where that rule is defined.

_lib/ruby\lsp · high confidence

New RSpec DSL and Pundit-compatible syntax for policy testing

Users can now test ActionPolicy policies using a dedicated RSpec DSL. The new \dsl.rb\ module provides \describe\_rule\, \succeed\, and \failed\ helpers to define and assert policy rule outcomes, while \pundit\_syntax.rb\ adds Pundit-style \permit\ matchers and a \permissions\ block for testing authorization lists. These features are automatically included for specs located in \spec/policies\ with \type: :policy\, allowing for more expressive and concise policy tests.

_lib/action\policy/rspec · high confidence

New Rails integration for controllers, channels, and instrumentation

This release introduces the \action\_policy/rails\ gem, providing first-class integration with Rails applications. Controllers gain \verify\_authorized\ and \verify\_authorized\_scope\ callbacks to enforce that authorization checks are performed, along with \skip\_verify\_authorized!\ to opt out. The integration also adds \authorized\_scope\ helper methods, memoization for policy instances, and ActiveSupport instrumentation for the \authorize!\ method to support monitoring and debugging. Additionally, ActionCable channels are supported via a dedicated concern.

_lib/action\policy/rails · high confidence

New TutorialKit for Ruby on Rails: interactive WASM-based tutorials

This change introduces a new TutorialKit template for building interactive Ruby on Rails tutorials that run entirely in the browser via WebAssembly. It provides a scaffolded project structure (including \astro.config.ts\, \CLAUDE.md\, and VS Code settings), a \build-wasm\ script to compile Ruby and gems into a WASM module, and a suite of Claude skills (\rails-file-management\, \rails-lesson-recipes\, \rails-wasm-author-constraints\, \tutorial-content-structure\, \tutorial-lesson-config\, \tutorial-quickstart\) that guide authors in creating lessons, managing file templates, and understanding WASM constraints. The template includes a \rails-app\ base template, supports lesson types like terminal-only and code-editing, and configures a WebContainer environment with PGLite for in-browser database operations.

tutorial · high confidence

New authorization behavior modules for namespacing, scoping, and memoization

The \lib/action\_policy/behaviours\ directory now contains dedicated modules that extend the core authorization capabilities. The \Namespaced\ module enables automatic policy lookup within the current context's namespace (e.g., \Admin::UserPolicy\), supporting nested modules and custom namespace overrides. The \Scoping\ module introduces the \authorized\_scope\ method (aliased as \authorized\ for backward compatibility) to apply policy-based scopes to records, inferring the policy from the target or implicit authorization target. Two memoization modules, \Memoized\ and \ThreadMemoized\, optimize performance by caching policy instances; \Memoized\ caches per-instance, while \ThreadMemoized\ caches per-thread (enabled by default outside test environments). The \PolicyFor\ module centralizes the \policy\_for\ method, supporting explicit context, namespace, and default policy fallbacks, and provides hooks like \implicit\_authorization\_target\ for cases where no record is specified.

_lib/action\policy/behaviours · high confidence

New policy modules for aliases, authorization context, caching, and scoping

The policy library now includes several new modules that enhance how policies are defined and executed. The Aliases module allows defining rule aliases (e.g., \publish?\ mapping to \update?\) and a default fallback rule. The Authorization module enables declaring required context parameters (like \user\ or \account\) that must be passed during initialization. The Cache and CachedApply modules provide mechanisms for caching rule evaluation results to improve performance, with \CachedApply\ offering per-policy in-memory caching and \Cache\ supporting long-lived external cache stores. The Scoping module introduces the ability to modify the object under authorization (e.g., filtering a collection based on user permissions) using \scope\_for\ and \apply\_scope\. Additionally, the Defaults module provides standard rules (\index?\, \create?\, \manage?\) and aliases out of the box.

_lib/action\policy/policy · high confidence

New pre-checks, detailed failure reasons, and testing matchers

Action Policy now supports pre-checks, allowing common authorization logic to be extracted into reusable callbacks that run before specific rules. It also introduces detailed failure reasons, enabling developers to track and inspect why authorization was rejected, which is particularly useful when composing policies. Additionally, new RSpec matchers (\be\_authorized\_to\, \have\_authorized\_scope\, \be\_an\_alias\_of\) and test helpers (\assert\_authorized\_to\, \assert\_have\_authorized\_scope\) have been added to improve the testing experience for authorization and scoping.

_action\policy · high confidence

New scope matchers for ActiveRecord relations and ActionController params

Users can now use more intuitive methods for defining scope matchers in Rails applications. The library adds \relation\_scope\ as an alias for \scope\_for :active\_record\_relation\, allowing policies to match against ActiveRecord::Relation objects, and \params\_filter\ as an alias for \scope\_for :action\_controller\_params\, enabling policies to match against ActionController::Parameters. These additions simplify policy definitions by providing domain-specific method names that map directly to the underlying scope matcher registrations.

_lib/action\_policy/rails/scope\matchers · high confidence

New utility modules for pretty-printing policy rules and error suggestions

The library now includes two new utility modules in the \lib/action\_policy/utils\ directory. \PrettyPrint\ provides a way to format policy rule methods into readable, annotated source code that evaluates logical parts (like \&&\ and \\|\|\) and displays their results, supporting colorized output and the ability to ignore specific expressions (such as debugging hooks). \SuggestMessage\ integrates with Ruby's \did\_you\_mean\ library to provide helpful 'Did you mean?' suggestions when policy scope exceptions are raised, improving developer experience during debugging.

_lib/action\policy/utils · high confidence

Behavioural changes

ActionPolicy library initialization and core API exposure

The ActionPolicy library has been initialized with a new entry point that loads core components including the base policy class, lookup chain, and behavior modules. It introduces a \NotFound\ error class for better diagnostics when a policy class cannot be found, and exposes a \lookup\ method on the main module to resolve policy classes for targets. The library now supports optional I18n integration and includes configuration options for caching and enforcing predicate rule naming conventions.

lib · high confidence

ActionPolicy version bump to 0.7.7

The library version has been updated from 0.0.1 to 0.7.7. This release includes significant internal refactoring and new capabilities such as a configurable lookup chain for policy resolution, per-thread memoization for performance, namespace caching, and I18n integration for error messages. It also adds Rails-specific features like auto-injection into controllers and channels, instrumentation support, and RSpec matchers for testing.

_lib/action\policy · high confidence

Repository tooling and documentation overhaul

The project has replaced Travis CI with GitHub Actions and introduced a suite of local development tools to improve code quality and consistency. This includes configuring RuboCop with the Standard gem and Ruby Next for modern Ruby syntax, adding Markdown linting via mdl and link checking with lychee, and implementing pre-commit hooks through Lefthook. The README has been significantly expanded with usage examples, integration guides, and badges, while the CHANGELOG has been formalized to track version history.

(repo-wide) · high confidence

Fixes

Optimized caching for ActiveRecord relations and non-persisted records

The library now defines explicit \policy\_cache\_key\ methods for \ActiveRecord::Relation\ and \ActiveRecord::Base\ to improve performance and correctness. For relations, the new method returns the object ID to avoid unnecessary database queries and prevents side effects that could mutate the relation's internal state. For model instances, non-persisted records are now cached using their object ID rather than a shared key, ensuring that unsaved records are not incorrectly treated as identical.

_lib/action\policy/rails/ext · high confidence

Test coverage

Added RSpec test suite for DSL and matchers; Added Rails dummy application configuration for testing; Added benchmarks for catch/throw, namespaced lookup cache, and pre-checks; Added dummy Rails application for testing; Added test coverage for ActionPolicy core features; Added test coverage for core policy features; Added test coverage for install and policy generators; Added test helper for asserting ActiveRecord SQL query counts; Added test infrastructure and coverage configuration; Added test stubs for Account, User, and InMemoryCache; Added test suite for Rails integration features; Added tests for Memoized, Namespaced, and ThreadMemoized behaviors; Added tests for policy cache key generation and string/symbol transformation extensions; Updated test infrastructure and configuration.

Dependencies

Update documentation and tutorial dependencies

The \docs\ area now uses VitePress 2.0.0-alpha.16 for static site generation, while the \tutorial\ area has been upgraded to use Astro 4.15.0 and TutorialKit RB 0.1.6. Additionally, the default tutorial template now includes dependencies for running Ruby on WebAssembly via \@rails-tutorial/wasm\ 8.0.2-rc.1 and \@ruby/wasm-wasi\ 2.7.1.

(dependencies) · high confidence

Updated gemfiles for Rails 6–8 and JRuby compatibility

The gemfiles in the gemfiles/ directory have been updated to support testing against Rails 6.0, 7.0, 7.1, 8.0, and the Rails master branch, alongside a new configuration for JRuby. Specific dependencies have been adjusted for each environment: Rails 6–7.1 and Rails 8 use sqlite3 \~\> 1.4 or 2.1 respectively, while the Rails master gemfile points to the github source. The JRuby gemfile now targets Rails \~\> 7.1 with activerecord-jdbcsqlite3-adapter and pins rdoc to versions below 8. Additionally, the rubocop gemfile has been updated to use standard \~\> 1.0, rubocop-md \~\> 2.0, and ruby-next \>= 1.0.

gemfiles · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 50.

Lenses

  • Code Health 55
  • Architecture 89
  • Maturity 65
  • Readiness 43
  • Security 57
  • Domain Modelling 100
  • Accessibility 50

Changes since last survey

  • 300 commits — 239 feature/other, 61 fixes

By area

  • (root) — 97 commits
  • lib/action_policy — 58 commits
  • tutorial/src — 26 commits
  • test/action_policy — 19 commits
  • .github/workflows — 13 commits
  • docs/testing.md — 13 commits
  • docs/authorization_context.md — 6 commits
  • docs/graphql.md — 5 commits
  • docs/rails.md — 5 commits
  • (repo) — 4 commits
  • docs/assets — 4 commits
  • tutorial/ruby-wasm — 4 commits
  • docs/.vitepress — 3 commits
  • docs/scoping.md — 3 commits
  • gemfiles/jruby.gemfile — 3 commits
  • lib/generators — 3 commits
  • tutorial/.claude — 3 commits
  • .github/ISSUE_TEMPLATE.md — 2 commits
  • docs/README.md — 2 commits
  • docs/_sidebar.md — 2 commits

Notable commits

  • fix: - docs: fix logo
  • fix: - tutorialkit: fix rails path handler paths resolution
  • fix: - tutorialkit: fix ts errors
  • fix: - tutorialkitrb: fix minitest parallel issues
  • fix: Fix Ruby 2.7 kwargs warnings
  • fix: Fix aliases in policies with reasons
  • fix: Fix broken docs link in Alternatives section
  • fix: Fix cache storing policy found in parent namespace in strict mode
  • fix: Fix calling rules directly when allowed_to? present
  • fix: Fix copypasta
  • fix: Fix erb-syntax at quick_start.md's code snippet.
  • fix: Fix generators specs
  • fix: Fix global policies not being found with strict_namespace: true
  • fix: Fix initializer racing condition with Rails 8.1
  • fix: Fix links
  • fix: Fix rspec test with colorize
  • fix: Fix symbol lookup with namespaces
  • fix: Fix testing docs (stubbed models cannot access DB)
  • fix: Fix tests
  • fix: Lint fixes
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

palkan/action_policy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f5e5912fbd6aca518ea43b2dbf0fc099da245441 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.