palkan/action_policy
50.1
Adequate · 19 September 2026
6.2k
lines of production code
Ruby
with JavaScript, TypeScript
1
measurement over time
What this system is
This system is the ActionPolicy library, a Ruby gem that provides a structured framework for defining and enforcing authorization rules within applications. It offers core capabilities for policy resolution, rule evaluation, and data scoping, with specific integrations for Rails controllers, channels, and ActiveRecord relations. The library also includes tooling for testing via RSpec matchers, performance optimization through memoization and caching, and developer aids like code generation and debugging utilities.
How it got here
2018 — ActionPolicy library initialization and core feature development
24 changes.
This period focused on initializing the ActionPolicy authorization library, establishing its core API, and implementing essential features such as policy lookup, namespacing, scoping, and memoization. Significant effort was dedicated to building first-class integrations for Rails and RSpec, alongside comprehensive test coverage and performance benchmarking to ensure stability and usability.
2019–2026 — Developer tooling and observability
10 changes.
This period focused on enhancing the developer experience by introducing Rails generators for scaffolding policies and tests, alongside an experimental Ruby LSP addon for better code navigation. It also expanded observability through instrumentation events and added utilities for monitoring SQL query performance. Additionally, the work included establishing a robust testing infrastructure with a dummy Rails app and creating a WebAssembly-based tutorial kit for interactive learning.
Features
Add Rails generator for creating policies with configurable parent class
A new \action\_policy:policy\ Rails generator has been added, allowing users to scaffold policy classes via \rails generate action\_policy:policy\. The generator automatically invokes the \action\_policy:install\ generator if the base \ApplicationPolicy\ does not yet exist, ensuring the necessary foundation is in place. It also supports a \--parent\ option, enabling users to specify a custom parent class (defaulting to \ApplicationPolicy\) for the generated policy, which facilitates inheritance hierarchies in larger applications.
_lib/generators/action\policy/policy · high confidence
Add Rails generator for installing base policy class
Users can now run the \rails generate action\_policy:install\ command to automatically create a base \ApplicationPolicy\ class in \app/policies/\. This generator scaffolds a standard policy structure inheriting from \ActionPolicy::Base\, including comments that guide configuration of authorization contexts and shared helper methods.
_lib/generators/action\policy/install · high confidence
Added Rails generators for Action Policy specs
Users can now generate RSpec and Test Unit policy specifications using the new \rails generate rspec:policy\ and \rails generate test\_unit:policy\ commands. The RSpec generator creates a spec file in \spec/policies\ with stubbed examples for \index?\, \create?\, and \manage?\ rules, while the Test Unit generator creates a corresponding test file in \test/policies\ with empty test methods for the same rules.
lib/generators/rspec · high confidence
Added Ruby refinements for string, hash, and module utilities
This change introduces a set of new refinement modules in lib/action\_policy/ext to provide standard utility methods for older Ruby versions and non-Rails environments. Specifically, it adds String\#safe\_constantize and String\#underscore, Symbol\#camelize, Hash\#transform\_keys, Module\#namespace, and Object\#\_policy\_cache\_key (along with refinements for NilClass, TrueClass, FalseClass, String, Symbol, Numeric, Time, and Module). These refinements ensure consistent behavior for naming conventions, constant lookup, and caching keys across different Ruby versions and frameworks.
_lib/action\policy/ext · high confidence
Adds instrumentation events for policy initialization and rule application
The library now emits ActiveSupport::Notifications events to allow monitoring of policy execution. Specifically, an \action\_policy.init\ event is fired whenever a policy is initialized, and an \action\_policy.apply\_rule\ event is fired for every rule application, including details such as the policy name, rule name, cache status, and result value in the payload.
_lib/action\policy/rails/policy · high confidence
Experimental Ruby LSP addon for ActionPolicy
An experimental Ruby LSP addon for ActionPolicy has been added, enabling definition navigation for authorization rules. When a user invokes 'go to definition' on an \authorize!\ call within a controller or channel, the addon locates the corresponding policy class, parses the policy file to identify rule definitions (including those aliased via \alias\_rule\), and provides a link to the specific line where that rule is defined.
_lib/ruby\lsp · high confidence
New RSpec DSL and Pundit-compatible syntax for policy testing
Users can now test ActionPolicy policies using a dedicated RSpec DSL. The new \dsl.rb\ module provides \describe\_rule\, \succeed\, and \failed\ helpers to define and assert policy rule outcomes, while \pundit\_syntax.rb\ adds Pundit-style \permit\ matchers and a \permissions\ block for testing authorization lists. These features are automatically included for specs located in \spec/policies\ with \type: :policy\, allowing for more expressive and concise policy tests.
_lib/action\policy/rspec · high confidence
New Rails integration for controllers, channels, and instrumentation
This release introduces the \action\_policy/rails\ gem, providing first-class integration with Rails applications. Controllers gain \verify\_authorized\ and \verify\_authorized\_scope\ callbacks to enforce that authorization checks are performed, along with \skip\_verify\_authorized!\ to opt out. The integration also adds \authorized\_scope\ helper methods, memoization for policy instances, and ActiveSupport instrumentation for the \authorize!\ method to support monitoring and debugging. Additionally, ActionCable channels are supported via a dedicated concern.
_lib/action\policy/rails · high confidence
New TutorialKit for Ruby on Rails: interactive WASM-based tutorials
This change introduces a new TutorialKit template for building interactive Ruby on Rails tutorials that run entirely in the browser via WebAssembly. It provides a scaffolded project structure (including \astro.config.ts\, \CLAUDE.md\, and VS Code settings), a \build-wasm\ script to compile Ruby and gems into a WASM module, and a suite of Claude skills (\rails-file-management\, \rails-lesson-recipes\, \rails-wasm-author-constraints\, \tutorial-content-structure\, \tutorial-lesson-config\, \tutorial-quickstart\) that guide authors in creating lessons, managing file templates, and understanding WASM constraints. The template includes a \rails-app\ base template, supports lesson types like terminal-only and code-editing, and configures a WebContainer environment with PGLite for in-browser database operations.
tutorial · high confidence
New authorization behavior modules for namespacing, scoping, and memoization
The \lib/action\_policy/behaviours\ directory now contains dedicated modules that extend the core authorization capabilities. The \Namespaced\ module enables automatic policy lookup within the current context's namespace (e.g., \Admin::UserPolicy\), supporting nested modules and custom namespace overrides. The \Scoping\ module introduces the \authorized\_scope\ method (aliased as \authorized\ for backward compatibility) to apply policy-based scopes to records, inferring the policy from the target or implicit authorization target. Two memoization modules, \Memoized\ and \ThreadMemoized\, optimize performance by caching policy instances; \Memoized\ caches per-instance, while \ThreadMemoized\ caches per-thread (enabled by default outside test environments). The \PolicyFor\ module centralizes the \policy\_for\ method, supporting explicit context, namespace, and default policy fallbacks, and provides hooks like \implicit\_authorization\_target\ for cases where no record is specified.
_lib/action\policy/behaviours · high confidence
New policy modules for aliases, authorization context, caching, and scoping
The policy library now includes several new modules that enhance how policies are defined and executed. The Aliases module allows defining rule aliases (e.g., \publish?\ mapping to \update?\) and a default fallback rule. The Authorization module enables declaring required context parameters (like \user\ or \account\) that must be passed during initialization. The Cache and CachedApply modules provide mechanisms for caching rule evaluation results to improve performance, with \CachedApply\ offering per-policy in-memory caching and \Cache\ supporting long-lived external cache stores. The Scoping module introduces the ability to modify the object under authorization (e.g., filtering a collection based on user permissions) using \scope\_for\ and \apply\_scope\. Additionally, the Defaults module provides standard rules (\index?\, \create?\, \manage?\) and aliases out of the box.
_lib/action\policy/policy · high confidence
New pre-checks, detailed failure reasons, and testing matchers
Action Policy now supports pre-checks, allowing common authorization logic to be extracted into reusable callbacks that run before specific rules. It also introduces detailed failure reasons, enabling developers to track and inspect why authorization was rejected, which is particularly useful when composing policies. Additionally, new RSpec matchers (\be\_authorized\_to\, \have\_authorized\_scope\, \be\_an\_alias\_of\) and test helpers (\assert\_authorized\_to\, \assert\_have\_authorized\_scope\) have been added to improve the testing experience for authorization and scoping.
_action\policy · high confidence
New scope matchers for ActiveRecord relations and ActionController params
Users can now use more intuitive methods for defining scope matchers in Rails applications. The library adds \relation\_scope\ as an alias for \scope\_for :active\_record\_relation\, allowing policies to match against ActiveRecord::Relation objects, and \params\_filter\ as an alias for \scope\_for :action\_controller\_params\, enabling policies to match against ActionController::Parameters. These additions simplify policy definitions by providing domain-specific method names that map directly to the underlying scope matcher registrations.
_lib/action\_policy/rails/scope\matchers · high confidence
New utility modules for pretty-printing policy rules and error suggestions
The library now includes two new utility modules in the \lib/action\_policy/utils\ directory. \PrettyPrint\ provides a way to format policy rule methods into readable, annotated source code that evaluates logical parts (like \&&\ and \\|\|\) and displays their results, supporting colorized output and the ability to ignore specific expressions (such as debugging hooks). \SuggestMessage\ integrates with Ruby's \did\_you\_mean\ library to provide helpful 'Did you mean?' suggestions when policy scope exceptions are raised, improving developer experience during debugging.
_lib/action\policy/utils · high confidence
Behavioural changes
ActionPolicy library initialization and core API exposure
The ActionPolicy library has been initialized with a new entry point that loads core components including the base policy class, lookup chain, and behavior modules. It introduces a \NotFound\ error class for better diagnostics when a policy class cannot be found, and exposes a \lookup\ method on the main module to resolve policy classes for targets. The library now supports optional I18n integration and includes configuration options for caching and enforcing predicate rule naming conventions.
lib · high confidence
ActionPolicy version bump to 0.7.7
The library version has been updated from 0.0.1 to 0.7.7. This release includes significant internal refactoring and new capabilities such as a configurable lookup chain for policy resolution, per-thread memoization for performance, namespace caching, and I18n integration for error messages. It also adds Rails-specific features like auto-injection into controllers and channels, instrumentation support, and RSpec matchers for testing.
_lib/action\policy · high confidence
Repository tooling and documentation overhaul
The project has replaced Travis CI with GitHub Actions and introduced a suite of local development tools to improve code quality and consistency. This includes configuring RuboCop with the Standard gem and Ruby Next for modern Ruby syntax, adding Markdown linting via mdl and link checking with lychee, and implementing pre-commit hooks through Lefthook. The README has been significantly expanded with usage examples, integration guides, and badges, while the CHANGELOG has been formalized to track version history.
(repo-wide) · high confidence
Fixes
Optimized caching for ActiveRecord relations and non-persisted records
The library now defines explicit \policy\_cache\_key\ methods for \ActiveRecord::Relation\ and \ActiveRecord::Base\ to improve performance and correctness. For relations, the new method returns the object ID to avoid unnecessary database queries and prevents side effects that could mutate the relation's internal state. For model instances, non-persisted records are now cached using their object ID rather than a shared key, ensuring that unsaved records are not incorrectly treated as identical.
_lib/action\policy/rails/ext · high confidence
Test coverage
Added RSpec test suite for DSL and matchers; Added Rails dummy application configuration for testing; Added benchmarks for catch/throw, namespaced lookup cache, and pre-checks; Added dummy Rails application for testing; Added test coverage for ActionPolicy core features; Added test coverage for core policy features; Added test coverage for install and policy generators; Added test helper for asserting ActiveRecord SQL query counts; Added test infrastructure and coverage configuration; Added test stubs for Account, User, and InMemoryCache; Added test suite for Rails integration features; Added tests for Memoized, Namespaced, and ThreadMemoized behaviors; Added tests for policy cache key generation and string/symbol transformation extensions; Updated test infrastructure and configuration.
Dependencies
Update documentation and tutorial dependencies
The \docs\ area now uses VitePress 2.0.0-alpha.16 for static site generation, while the \tutorial\ area has been upgraded to use Astro 4.15.0 and TutorialKit RB 0.1.6. Additionally, the default tutorial template now includes dependencies for running Ruby on WebAssembly via \@rails-tutorial/wasm\ 8.0.2-rc.1 and \@ruby/wasm-wasi\ 2.7.1.
(dependencies) · high confidence
Updated gemfiles for Rails 6–8 and JRuby compatibility
The gemfiles in the gemfiles/ directory have been updated to support testing against Rails 6.0, 7.0, 7.1, 8.0, and the Rails master branch, alongside a new configuration for JRuby. Specific dependencies have been adjusted for each environment: Rails 6–7.1 and Rails 8 use sqlite3 \~\> 1.4 or 2.1 respectively, while the Rails master gemfile points to the github source. The JRuby gemfile now targets Rails \~\> 7.1 with activerecord-jdbcsqlite3-adapter and pins rdoc to versions below 8. Additionally, the rubocop gemfile has been updated to use standard \~\> 1.0, rubocop-md \~\> 2.0, and ruby-next \>= 1.0.
gemfiles · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 50.
Lenses
- Code Health 55
- Architecture 89
- Maturity 65
- Readiness 43
- Security 57
- Domain Modelling 100
- Accessibility 50
Changes since last survey
- 300 commits — 239 feature/other, 61 fixes
By area
- (root) — 97 commits
- lib/action_policy — 58 commits
- tutorial/src — 26 commits
- test/action_policy — 19 commits
- .github/workflows — 13 commits
- docs/testing.md — 13 commits
- docs/authorization_context.md — 6 commits
- docs/graphql.md — 5 commits
- docs/rails.md — 5 commits
- (repo) — 4 commits
- docs/assets — 4 commits
- tutorial/ruby-wasm — 4 commits
- docs/.vitepress — 3 commits
- docs/scoping.md — 3 commits
- gemfiles/jruby.gemfile — 3 commits
- lib/generators — 3 commits
- tutorial/.claude — 3 commits
- .github/ISSUE_TEMPLATE.md — 2 commits
- docs/README.md — 2 commits
- docs/_sidebar.md — 2 commits
Notable commits
- fix: - docs: fix logo
- fix: - tutorialkit: fix rails path handler paths resolution
- fix: - tutorialkit: fix ts errors
- fix: - tutorialkitrb: fix minitest parallel issues
- fix: Fix Ruby 2.7 kwargs warnings
- fix: Fix aliases in policies with reasons
- fix: Fix broken docs link in Alternatives section
- fix: Fix cache storing policy found in parent namespace in strict mode
- fix: Fix calling rules directly when allowed_to? present
- fix: Fix copypasta
- fix: Fix erb-syntax at quick_start.md's code snippet.
- fix: Fix generators specs
- fix: Fix global policies not being found with strict_namespace: true
- fix: Fix initializer racing condition with Rails 8.1
- fix: Fix links
- fix: Fix rspec test with colorize
- fix: Fix symbol lookup with namespaces
- fix: Fix testing docs (stubbed models cannot access DB)
- fix: Fix tests
- fix: Lint fixes
- …and 280 more
Architecture
- 0 containers · 1 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
palkan/action_policy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f5e5912fbd6aca518ea43b2dbf0fc099da245441 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.