pglombardo/PasswordPusher
41.3
Weak · 28 September 2026
7k
lines of production code
Ruby
with JavaScript
2
measurements over time
What this system is
Password Pusher is a secure, self-hosted web application designed for sharing secrets such as passwords, files, URLs, and QR codes via expiring links. It provides a unified interface for creating and managing these 'pushes' with features like passphrase protection, view limits, and automatic expiration, alongside comprehensive audit logging and email notifications. The system supports both web and JSON API interactions, includes robust administrative controls for user and content management, and offers extensive customization through themes and custom CSS.
How it got here
2011 — Rails 8 upgrade and v2.14.1 foundation
23 changes.
This period established the foundational structure for Password Pusher v2.14.1, centered on a major upgrade to Rails 8.0 and the migration from the legacy Password model to a unified Push model. The work involved a comprehensive modernization of the codebase, including replacing HAML with ERB, shifting to Bootstrap 5 with dark mode support, and implementing robust security features like TOTP and rate limiting.
2012–2023 — Security hardening and UI modernization
27 changes.
This period focused on significantly enhancing security by implementing two-factor authentication, custom session management, and comprehensive background jobs for data cleanup. The project also modernized its user interface with Bootstrap 5, migrated JavaScript to Stimulus, and expanded deployment options with Docker and Kubernetes support.
2024–2025 — Admin center and API v1 expansion
26 changes.
This period focused on establishing a comprehensive administration center with user management, database exploration, and dark mode support, while simultaneously introducing a new JSON API v1 for push operations. Significant enhancements were made to security and observability through mandatory MFA enforcement, centralized audit logging, and detailed email diagnostic tools. The work was solidified by extensive test coverage for the new API endpoints, authentication flows, and administrative interfaces.
2026 — API v2 and security hardening
13 changes.
This period focused on introducing API v2 endpoints for push management and password generation, alongside a secure first-run setup flow with boot code validation. Significant enhancements included multi-language password and passphrase generation, two-factor authentication, and automated email notifications for shared pushes. The work was supported by comprehensive integration tests and Docker-friendly configuration options for secrets and UI themes.
Features
Add Google Analytics, Plausible, IP address display, push expiration countdown, and multi-column language selector
The application view layout now includes several new partials to enhance analytics, security auditing, and user experience. Google Analytics tracking is added via a new partial (\_ga.html.erb), conditionally enabled in production and respecting Content Security Policy via nonces. Plausible Analytics support is also introduced (\_plausible.html.erb) with similar CSP-safe script loading. IP addresses in audit logs are now rendered via a dedicated partial (\_ip\_address.html.erb) that formats private/loopback addresses differently and links public IPs to an external lookup service. Push expiration notifications (\_push\_expiration.html.erb) display a countdown timer for file download links, excluding local storage environments. Finally, the secret URL bar (\_secret\_url\_bar.html.erb) now features a multi-column dropdown for selecting the recipient's language, improving usability for international users.
app/views/application · high confidence
Add localization files for new languages and Devise authentication strings
This change introduces localization support for several new languages (including Catalan, Czech, Welsh, Danish, German, British English, Spanish, Basque, Finnish, French, Irish, Hindi, Hungarian, Indonesian, Icelandic, Italian, Japanese, Korean, Latvian, Dutch, Norwegian, Polish, Brazilian Portuguese, European Portuguese, and Romanian) by adding dedicated \localization.\<lang\>.yml\ files that define language-specific date, number, and time formats. It also adds \devise.en.yml\ to provide English translations for authentication-related messages such as sign-in, password reset, and account confirmation, and creates a \.translation\_io\ metadata file to support the translation workflow.
config/locales · high confidence
Add user-facing views for account confirmation
Added new views for the account confirmation flow: a page allowing users to request a new confirmation email via an email input form, and a page displaying a link to complete the account confirmation process.
app/views/devise/confirmations · high confidence
Added password reset and account unlock views
The application now includes user-facing views for resetting forgotten passwords and unlocking accounts. Specifically, new templates have been added for the password reset request (new), password reset confirmation (edit), and account unlock request (new). These views provide the necessary forms for users to enter their email addresses or new passwords, utilizing internationalization for labels and messages.
app/views/devise/passwords, app/views/devise/unlocks · high confidence
Background jobs for push lifecycle, cache, and email notifications
This change introduces a suite of new background jobs to manage the application's data lifecycle and notification system. The \CleanUpPushesJob\ and \PurgeExpiredPushesJob\ handle the deletion of anonymous expired pushes and pushes older than a configurable duration, respectively, while \ExpirePushesJob\ proactively marks pushes as expired. Additionally, \CleanupCacheJob\ removes stale files from the Rails and Rack::Attack cache directories, \PurgeUnattachedBlobsJob\ cleans up orphaned Active Storage files, and \SendNotifyByEmailJob\ handles the asynchronous delivery of email notifications for new pushes.
app/jobs · high confidence
First-run setup and two-factor authentication UI
Users are now presented with a dedicated First Run Setup page to create their initial admin account, which can optionally require a boot code for secure initialization. Additionally, the application introduces a two-factor authentication (TOTP) workflow, providing views for scanning QR codes, verifying authenticator codes, managing backup recovery codes, and displaying a mandatory MFA banner when the require\_mfa setting is enabled.
app/views/users · high confidence
First-run setup flow with boot code validation
A new first-run boot code mechanism has been introduced to secure the initial application setup. When the application starts for the first time (no existing users), a unique 32-character hex code is generated and stored in a file, which users must provide to complete the initial configuration. This flow is automatically skipped if both logins and signups are disabled, preventing setup blocks in anonymous-only or ephemeral deployments. The service also handles legacy code formats and ensures secure comparison of the provided code.
app/services · high confidence
Initial Helm chart for Kubernetes deployment
This change introduces the initial Helm chart templates for deploying the application on Kubernetes. It includes a Deployment manifest configured to run as a non-root user (UID/GID 1000) with support for environment variables, secrets, and volume mounts; a Service manifest to expose the application; an Ingress manifest for HTTP routing with TLS support; and a shared helpers template for consistent naming and labeling. This provides the foundational infrastructure-as-code for containerized deployment.
containers/helm/templates · high confidence
Initial Helm chart release for Password Pusher
This change introduces a new Helm chart (version 0.4.2) for deploying Password Pusher (app version 2.0.1) on Kubernetes. The chart includes standard configuration files (Chart.yaml, values.yaml, README.md) and sets the default container image tag to 'stable'. It provides a basic deployment with a ClusterIP service on port 5100, configurable environment variables, and optional ingress support. The values file also includes specific warnings and examples for volume mounts, advising users to mount storage at /opt/PasswordPusher/storage but explicitly warning against mounting over /opt/PasswordPusher/db to prevent upgrade issues.
containers/helm · high confidence
Initial repository structure and configuration for Password Pusher v2.14.1
This change introduces the foundational configuration files and deployment manifests for the Password Pusher project, establishing the baseline for version 2.14.1. It includes the Ruby version specification (4.0.7), development tooling configurations (RuboCop, ERBLint, Overcommit, pre-commit hooks), and deployment definitions for Docker Compose, Heroku, Fly.io, and Railway. The entry also adds essential documentation files such as the Apache 2.0 License, Security policy, Code of Conduct, and a comprehensive upgrade guide for migrating from version 1.x to 2.0, which details new defaults for authentication, file storage, and configuration strategies.
(repo-wide) · high confidence
Introduce API v2 endpoints for push management, password generation, and versioning
This change introduces the initial set of controllers for the new API v2, providing dedicated endpoints for managing pushes, generating passwords, and checking API versioning. The new Api::V2::PushesController allows users to create, view, audit, and manage email notifications for pushes, with specific handling for file and URL push types. The Api::V2::GenerateController adds a new capability for generating passwords and other secrets via a rate-limited endpoint. Additionally, the Api::V2::VersionController exposes API version details and a features hash that reflects current application settings, such as anonymous access, file push support, and available password generation languages.
app/controllers/api/v2 · high confidence
Introduce JSON API v1 for Pushes and Versioning
This change introduces the new \app/controllers/api/v1\ directory, establishing the foundation for the JSON API v1. It adds \Api::V1::PushesController\ to handle creating, viewing, and managing secret pushes (including passphrase protection and view limiting) via JSON endpoints, and \Api::V1::VersionController\ to expose application and API version details. This represents a structural shift in how API interactions are routed and processed, moving towards a unified JSON-based interface for core push functionality.
app/controllers/api/v1 · high confidence
New Administrator Management interface
A new Administration Center view has been added for managing user roles. Administrators can now view a list of current administrators and regular users, with options to promote regular users to administrator status or revoke administrator privileges from existing admins. The interface displays user email addresses, creation dates, and last sign-in times, and includes a confirmation step before changing roles.
app/views/admin/users · high confidence
New Custom CSS admin page for interface styling
Admins now have a dedicated page to inject custom CSS styles that override the default appearance of the Password Pusher instance. The interface includes a warning about potential layout breakage, an informational alert directing users to built-in themes for common branding needs, and a text area for entering styles that are applied immediately upon saving. The page also provides several copy-paste examples for common customizations, such as adjusting button styles, form fields, and sliders.
_app/views/admin/custom\css · high confidence
New Database Explorer dashboard in Admin Center
The Admin Center now includes a Database Explorer view that displays the current database connection status (Connected/Disconnected), adapter type, database name, and environment. It provides direct links to manage Users, Pushes, and Audit Logs, accompanied by a critical warning about the irreversible nature of direct database modifications and recommendations to backup data before changes.
app/views/madmin/dashboard · high confidence
New JavaScript entry point, local time localization, and spoiler alert functionality
The application now initializes via a new \app/javascript/application.js\ entry point that loads Turbo Rails, Active Storage, Bootstrap, and Stimulus controllers. It introduces a mechanism to disable Turbo Drive via an environment variable and integrates the \local-time\ library to display dates and times in the user's timezone, supported by a new \local\_time\_locales.js\ file providing i18n definitions for multiple languages. Additionally, a new \spoiler\_alert.js\ module is added to handle content blurring, including a feature that automatically re-blurs revealed content after a configurable timeout.
app/javascript · high confidence
New Madmin administration center layout with theme support
A new layout file for the Madmin administration center has been introduced, providing a structured interface with a sidebar navigation and main content area. This layout integrates theme toggle functionality, allowing users to switch between light and dark modes, and includes specific meta tags for search engine indexing control and Turbo Drive configuration. It also displays a warning banner in staging environments to distinguish them from production.
app/views/layouts/madmin · high confidence
New Madmin administration center with user management and queue monitoring
This change introduces the Madmin administration center, providing a new set of controllers for managing application resources. The \UsersController\ adds the ability to create users with auto-generated secure passwords and supports user deletion, including logic to skip email confirmation when \enable\_user\_account\_emails\ is disabled. Additionally, controllers are added for monitoring Active Storage assets and Solid Queue background job statuses (including jobs, processes, and various execution states), while the \ApplicationController\ enforces admin authentication and locale settings.
app/controllers/madmin · high confidence
New Madmin administration resources for Active Storage, Solid Queue, and core entities
The administration center now includes dedicated resource definitions for managing Active Storage attachments and blobs, Solid Queue job processing (including jobs, executions, processes, and tasks), and core application entities like Users, Push notifications, Audit Logs, and Data Migration Status. This allows administrators to view, filter, and inspect these records directly within the Madmin interface, with specific customizations such as displaying User records by email and Push records by URL token.
app/madmin · high confidence
New admin controls for user management and custom CSS
Administrators can now manage user roles and appearance directly from the admin panel. A new Users controller allows admins to promote regular users to administrators, revoke administrator privileges (with protection against self-revocation), and delete user accounts. Additionally, a new Custom CSS controller enables admins to edit and apply custom CSS styles to the site.
app/controllers/admin · high confidence
New administrative and operational management scripts
This release introduces a suite of new command-line tools in the bin directory to streamline administration and development workflows. Administrators can now easily manage user roles and security via \bin/create\_admin\, \bin/promote\_to\_admin\, \bin/demote\_admin\, and \bin/list\_admins\ for user management, as well as \bin/disable\_two\_factor\ to handle Two-Factor Authentication (TOTP) recovery. Operational tasks are supported by \bin/jobs\ for the Solid Queue background job processor, \bin/importmap\ for JavaScript/CSS bundling, and \bin/dev\ for simplified local development server startup. Additionally, \bin/move\_up\_stable\_tag.sh\ automates the Docker image tagging process for releases.
bin · high confidence
New email infrastructure and diagnostic tools
The application now includes a base ApplicationMailer and a PushCreatedMailer that sends localized notifications for new password pushes, respecting locale settings and environment variables like FORCE\_SSL. Additionally, a new TestMailer has been added to help diagnose SMTP configuration issues by printing detailed configuration summaries and validation checks to the console before attempting to send a test email.
app/mailers · high confidence
New example setup for running Password Pusher with Nginx
A new example configuration has been added to the containers/examples directory that demonstrates how to deploy Password Pusher behind an Nginx reverse proxy. This includes a docker-compose.yml file defining the proxy and application services, a custom nginx.conf for header forwarding and proxying, an environment file with example settings for features, authentication, and branding, and a README pointing to official documentation. Users can now use this as a reference for setting up a production-like environment with Nginx handling incoming traffic.
containers/examples · high confidence
New maintenance tasks and OSS-to-Pro migration export
This change introduces several new Rake tasks in lib/tasks to improve maintenance and enable migration. The daily\_expiration task now proactively checks and expires pushes to reduce live-request overhead, while delete\_expired\_and\_anonymous removes metadata for expired anonymous pushes to enhance privacy. A new generate\_robots\_txt task creates the robots.txt file, and active\_storage:purge\_unattached cleans up orphaned storage blobs. Additionally, a new pwpush:export task allows users to export all data (users, pushes, audit logs, and storage attachments) into a JSON file, providing clear instructions for migrating to the Pro version.
lib/tasks · high confidence
New user management interface in the Madmin admin panel
The Madmin admin section now includes a dedicated interface for managing user accounts, featuring a searchable and paginated list view, a detailed user profile view, and a custom form for creating new users. The creation form allows administrators to set the user's email and, when the \enable\_user\_account\_emails\ setting is active, choose to auto-confirm the account; it also informs users that a secure password will be generated automatically. In the list and detail views, the ability to edit existing users has been removed, leaving only the option to delete non-current-user accounts or view their details.
app/views/madmin/users · high confidence
Removals
Removal of application documentation template
The file doc/README\_FOR\_APP, which previously served as a template for introducing the application and pointing to API documentation generation instructions, has been removed from the repository.
doc · high confidence
Security
Security hardening and configuration modernization
This update introduces several security and configuration improvements across the application. Cookie serialization has been switched from :hybrid to :json to mitigate potential Remote Code Execution (RCE) vulnerabilities associated with Marshal, and session cookies are now optionally secured with httponly, secure, and same-site flags based on the secure\_cookies setting. The Content Security Policy has been hardened with strict-dynamic and base-uri directives, and browser feature restrictions are enforced via Permissions-Policy headers. Additionally, sensitive data (passwords, tokens, keys) is now filtered from logs, Rack::Attack is configured to throttle login attempts by IP and email, and the Devise initializer enforces a minimum password length of 10 characters and a 2-hour session timeout.
config/initializers · high confidence
Behavioural changes
Administration Center UI overhaul with dark mode support
The Administration Center views have been completely redesigned to use a modern, card-based layout with Bootstrap 5 styling. The interface now features a dedicated sidebar navigation for database records (Users, Pushes, Audit Logs, etc.) and file storage (Blobs, Attachments), along with organized form sections for Basic Information, Security, and Activity. A key addition is robust dark theme support, which correctly remaps background and text colors for dark mode, and the UI now respects the user's theme toggle preference.
app/views/madmin/application · high confidence
Audit log views now display detailed context and email notification status
The audit log interface has been updated to provide richer details for each event. Users can now see the IP address, user agent, and referrer for actions such as views, edits, and failed attempts. Additionally, admin and owner views are explicitly marked with a badge indicating they do not count towards view limits. A new view type has been added to track email notification status, showing whether notifications are pending, completed, or failed, along with recipient counts and error messages.
_app/views/audit\logs · high confidence
Automated email notifications for new push shares
Users now receive an automatic email notification when someone shares a push with them. The new \push\_created\_mailer\ includes both HTML and text templates that display the sender's name, the secret access link, and key details such as the link's expiration (time or view count) and security requirements like potential passphrase prompts. Additionally, a new \MultipleEmailsValidator\ has been introduced to ensure that any comma-separated lists of email addresses are correctly formatted, contain no duplicates, and do not exceed the allowed count, improving data integrity for multi-recipient scenarios.
_app/validators, app/views/push\_created\mailer · high confidence
Background Jobs page now supports dark mode
The Background Jobs section of the Administration Center now respects the user's theme preference, including a fully styled dark mode. This change introduces a dedicated layout and theme toggle for the jobs interface, ensuring that headers, tables, buttons, and notifications render correctly in both light and dark themes via inline styles and a self-contained JavaScript toggle.
_app/views/layouts/mission\control · high confidence
Branded and Internationalized Devise Email Templates
The system now uses custom, branded email templates for Devise authentication events (account confirmation, password change, password reset, and account unlock). These templates feature internationalized text, include a shared footer, and display the application's brand title in notification messages, replacing the previous default styling and content.
app/views/devise/mailer · high confidence
Custom authentication controllers for 2FA, first-run setup, and session management
The application now uses custom controllers in the users namespace to extend Devise's default behavior. Sign-in now requires a two-factor authentication (TOTP) step if enabled, and administrators can disable all logins globally. A new first-run wizard allows initial admin account creation using a boot code, bypassing spam protection and confirmation emails. Session handling has been updated to explicitly clear session data and delete the session cookie upon logout. Additionally, users can manage their TOTP settings, view backup codes, and regenerate API tokens through dedicated endpoints.
app/controllers/users · high confidence
Database schema overhaul: unified push model, background jobs, and 2FA
The database schema has been significantly restructured to support new capabilities and improve performance. A unified 'push' model consolidates passwords, URLs, and file pushes into a single table, with legacy tables dropped after data migration. Two-factor authentication (TOTP) is now supported on user accounts, and background job processing has been upgraded to Solid Queue with batch support. Additional features include audit logging, email notification tracking, site settings, and user language preferences.
db/migrate · high confidence
Database schema upgraded to Rails 8.1 with Solid Queue and Active Storage support
The database schema has been updated to version 2026\_09\_28\_110942, reflecting a major framework upgrade to Rails 8.1. This change introduces new tables for Active Storage (active\_storage\_attachments, active\_storage\_blobs, active\_storage\_variant\_records) to manage file attachments, and a comprehensive set of tables for Solid Queue (solid\_queue\_batches, solid\_queue\_jobs, solid\_queue\_blocked\_executions, etc.) to handle background job processing. Existing application tables such as pushes, audit\_logs, and notify\_by\_emails have been retained with their current structures, while the schema definition format and seeds file have been updated to align with the new Rails version standards.
db · high confidence
Date and time fields now display in local time in Madmin
The Madmin Data Explorer now renders date and datetime values in the user's local timezone rather than UTC. This change introduces new view templates for the date and date\_time fields, utilizing the local\_date helper for short and long date formats, and the local\_time helper for short and long datetime formats, ensuring that timestamps shown in index and show views reflect the local time of the viewer.
app/views/madmin/fields · high confidence
Docker containers upgraded to Ruby 4.0.7 with new multi-stage build and entrypoint logic
The Docker images now use the Ruby 4.0.7-alpine base image, replacing previous versions. The build process has been restructured into a multi-stage build to optimize caching and reduce final image size, while the entrypoint scripts have been updated to support Docker secrets-style file loading for SECRET\_KEY\BASE, enforce persistent storage at /opt/PasswordPusher/storage, and default the application port to 5100. Additionally, the main container now includes a background worker by default (configurable via PWP\\_NO\_WORKER), and the worker-specific container explicitly requires PostgreSQL, MySQL, or MariaDB, excluding SQLite.
containers/docker · high confidence
Enforce MFA, standardize push logging, and unify locale handling
This change introduces several new controller concerns to improve security, observability, and internationalization. The \EnforceRequiredMfa\ concern now enforces two-factor authentication for signed-in users when the \require\_mfa\ setting is enabled, blocking access via JSON errors or redirects if MFA is not configured. The \LogEvents\ concern centralizes audit logging for push activities (views, creations, updates, etc.), recording IP addresses, user agents, and referrers while enforcing a maximum limit of 2000 logs per push. The \SetLocale\ concern standardizes language selection by checking URL parameters, user preferences, and HTTP headers. Additionally, \SetPushAttributes\ handles the assignment of \deletable\_by\_viewer\ and \retrieval\_step\ properties for pushes, correctly distinguishing between HTML form submissions and JSON API requests.
app/controllers/concerns · high confidence
Enforce first-run setup and add email notification tracking
The application now requires a first-run setup wizard to create the initial administrator account, displaying a boot code in the logs and redirecting unauthenticated users to the setup page until a user exists. Additionally, a new concern for assigning email notification fields ensures that the creator of a password share is automatically recorded when email notifications are enabled.
app/controllers/concerns/pwpush · high confidence
Introduce Push model with audit logging, email notifications, and TOTP authentication
The legacy Password model has been replaced by a new Push model that supports multiple content types (text, file, URL, QR code) and includes built-in audit logging for creation, views, and edits. Users can now configure automatic email notifications for push creation, subject to daily limits and recipient validation. User accounts have been enhanced with Time-based One-Time Password (TOTP) two-factor authentication and backup recovery codes, alongside token-based API authentication. The system also enforces a maximum of 2000 audit logs per push and restricts URL push payloads to HTTP/HTTPS schemes.
app/models · high confidence
Migrate frontend JavaScript to Stimulus controllers
The application's client-side behavior has been rewritten using the Stimulus framework, replacing previous inline scripts and other libraries. This change introduces dedicated controllers for key user interactions: \theme\_controller\ manages light/dark/system theme switching with instance-level locking; \payload\_visibility\_controller\ adds an eye-toggle to hide passwords while typing; \knobs\_controller\ persists user preferences for push settings (days, views, checkboxes) in cookies; \pwgen\_controller\ handles the password and passphrase generator UI; \multi\_upload\_controller\ manages ActiveStorage file uploads with progress bars; \countdown\_controller\ handles push expiration timers; \copy\_controller\ improves clipboard copying with visual feedback; \form\_controller\ prevents double-submits by disabling buttons; \gdpr\_controller\ manages the cookie consent banner; and \passwords\_controller\ handles character counting. This migration also supports the new Import Maps-based asset loading strategy.
app/javascript/controllers · high confidence
Migrate layout templates from HAML to ERB with unified theme support
The application layout templates have been converted from HAML to ERB, replacing the previous single HAML layout with a set of dedicated ERB layouts for the main application, administration, login, bare, naked, and mailer views. This change introduces consistent light/dark theme support across all public-facing layouts via a shared theme controller and settings, while the login layout specifically handles Turbo navigation to ensure password managers can correctly detect authentication forms on GET requests.
app/views/layouts · high confidence
Migration to esbuild for JavaScript packaging
The application has switched its JavaScript build system to esbuild. This change is reflected in the asset configuration, which now points to a new \app/assets/builds\ directory for compiled assets, replacing the previous structure. This shift supports a more modern and efficient build process for the application's frontend resources.
app/assets/config · high confidence
Modernized theming and UI styling with Bootstrap 5 and dark mode support
The application's styling has been completely overhauled to use Bootstrap 5 with explicit light/dark theme support via the \data-bs-theme\ attribute, replacing the previous SASS-based scaffolding and global styles. This change introduces a new \application.bootstrap.scss\ entry point that integrates Bootstrap, Bootstrap Icons, and Flag Icons, while removing the old \application.css\, \passwords.css.scss\, and \scaffolds.css.scss\ files. New styles in \standard.css\ handle theme-aware brand logos (switching between light and dark variants), payload visibility toggles (eye icon to hide passwords while typing), and reveal zones. Additionally, \pwgen.css\ provides specific styling for the password generator modal, and a new \custom.css\ file is provided as a user-overridable hook for custom styles.
app/assets/stylesheets · high confidence
New API base controller with pagination headers and token authentication
The API now includes a new base controller that enforces authentication via Bearer tokens or legacy X-User-Token headers, while allowing anonymous access only when explicitly permitted by settings or for specific public endpoints like version checks. It also adds RFC 5988-compliant pagination metadata headers (X-Page, X-Per-Page, X-Total, X-Total-Pages, and Link) to paginated list responses, and validates page parameters to prevent excessive OFFSET costs.
app/controllers/api · high confidence
New login page navigation and error display components
The application now uses dedicated shared partials for the login interface: \_error\_messages.html.erb renders validation errors as dismissible Bootstrap alerts, and \_links.html.erb provides the navigation footer. This footer dynamically shows links for login, sign-up, password recovery, and confirmation based on Devise mappings, and introduces a new setting (Settings.disable\_signups) that allows administrators to hide the sign-up link entirely.
app/views/devise/shared · high confidence
New password, passphrase, and PIN generators with multi-language support
The password generation logic in lib/pwpush has been replaced with a new system that supports generating passwords, passphrases, and PINs. Users can now configure passwords with specific character classes (uppercase, lowercase, digits, symbols), ambiguous character avoidance, and custom character sets (ASCII, Latin, Cyrillic, Greek). Passphrase generation is now available in five languages (English, Spanish, French, German, Italian) using EFF, BIP-0039, and diceware wordlists, with options for separators, capitalization, and appending numbers or symbols. PINs are generated as numeric strings with configurable length.
lib/pwpush · high confidence
Rails 7.1 environment configuration upgrade
The development, production, and test environment configurations have been upgraded to align with Rails 7.1 standards. This replaces legacy settings (such as \cache\_classes\ and \whiny\_nils\) with modern equivalents like \enable\_reloading\ and \disallowed\_deprecation\. Key behavioral changes include switching the background job adapter to \solid\_queue\, updating the mailer delivery method in development to \mailbin\ for easier debugging, and implementing configurable trusted proxy lists that now support custom environment variables alongside expanded default private IP ranges. Additionally, production logging now supports STDOUT output via environment variables, and asset compilation uses the \terser\ compressor.
config/environments · high confidence
Rails 8.0 upgrade and modernized configuration defaults
The application has been upgraded to Rails 8.0, bringing updated defaults for Active Storage (5-minute URL expiration, custom route prefix), Action Cable (Redis adapter in production), and Solid Queue (background job processing with recurring schedules for push expiration and cleanup). Configuration is now centralized in \config/settings.yml\ with environment variable overrides, and the asset pipeline has shifted to Import Maps with esbuild for CSS. The database defaults to SQLite3 in the \storage/db\ directory, and the Puma web server is configured with dynamic thread and worker counts. Security hardening includes a Brakeman ignore file for intentional redirects and a Content Security Policy report endpoint.
config · high confidence
Redesigned Administration Center with dark mode and custom CSS support
The Administration Center has been completely redesigned with a new sidebar navigation, updated dashboard stats, and full dark theme support that respects user toggle preferences. Admins can now view the application version in the sidebar and inject custom CSS styles directly from the admin interface.
app/views/admin · high confidence
Redesigned account management and authentication views
The application now features a completely redesigned user interface for account management and authentication. The Edit Profile page allows users to update their email, preferred language, and password, manage two-factor authentication (TOTP) settings, and delete their account. The registration form has been updated with improved styling and includes invisible CAPTCHA protection to prevent spam. A new API Token management page enables users to view, copy, and regenerate their authentication tokens securely. Additionally, the login view has been refreshed with modern form styling.
app/views/devise/registrations · high confidence
Redesigned error and maintenance pages with dark mode and multilingual support
The static error pages (404, 422, 500, 406) and the maintenance page have been completely redesigned to match the application's modern branding, replacing the previous generic Rails defaults. These pages now feature a consistent layout with the Inter font, a unified brand header, and support for dark mode via the system color scheme. Additionally, they include a language selector allowing users to switch between English, French, German, Dutch, Spanish, and Italian, with translations applied via client-side JavaScript. A new 406 'Browser not supported' page has also been added to handle unsupported browser scenarios, and a symlink for flag icons has been introduced to support the language selector UI.
public · high confidence
Redesigned shared UI components and layout
The shared view templates have been completely rewritten to modernize the user interface. This includes a new header with a responsive account dropdown and theme toggle, a redesigned dashboard header with push filtering, and a new footer with configurable branding and version display. A collapsible 'Additional Options' section has been added to forms, and a new password generator modal supports passphrases, passwords, and PINs with a confirmation step. Other updates include a new cookie consent banner, improved alert handling, and a copy-to-clipboard feature for share messages.
app/views/shared · high confidence
Redesigned static pages with modern UI and updated content
The About, API, Generate Key, and Slack integration pages have been completely rewritten using Bootstrap 5 components and Bootstrap Icons, replacing the previous HAML-based layouts. The About page now features a modern, responsive design with updated organizational history (mentioning Apnotic, LLC) and clearer calls to action. The API v2 documentation page has been enhanced to include a detailed features hash in the version endpoint response, explicitly documenting instance capabilities such as email auto-dispatch, file attachments, and QR code support. The Generate Key page now provides a dedicated interface for creating and copying master encryption keys using the Lockbox library, including environment variable formatting and command-line alternatives. The Slack integration pages have been updated with new branding assets and clearer usage examples.
app/views/pages · high confidence
Refactor helpers and introduce language selection for share messages
The application now supports selecting a language for the share message text on preview pages, allowing recipients to view the secret link instructions in their preferred locale. This is enabled by a new LanguageHelper that maps available locales to display names, and a ShareMessageHelper that constructs the share text using the selected locale. Additionally, the PushesHelper now formats expiration and file size information for display, while the ApplicationHelper manages brand logos (supporting light/dark mode), constructs secret URLs with optional locale parameters, and generates QR codes. The legacy PasswordsHelper has been removed.
app/helpers · high confidence
Removal of HAML password views
The HAML template files for the password resource (edit, index, new, and show) have been deleted from the application. This change removes the HAML-based user interface components for creating, listing, editing, and viewing passwords, likely as part of a migration to a different templating engine or view structure.
app/views/passwords · high confidence
Removal of legacy JavaScript manifest and CoffeeScript file
The legacy \application.js\ manifest file and the \passwords.js.coffee\ source file have been removed from the application assets. This eliminates the old Sprockets-style dependency management (which previously required jQuery, jquery\_ujs, and a tree of assets) and removes the CoffeeScript-based behavior hooks for the passwords controller, indicating a shift away from this older JavaScript bundling and language approach.
app/assets/javascripts · high confidence
Removal of legacy Rails 3 script/rails entry point
The legacy \script/rails\ executable, which was used to boot the application in older Rails versions, has been removed. This change aligns with the upgrade to Rails 5.2, where the application is now bootstrapped via the standard \bin/rails\ command or the Rails executable directly, eliminating the need for the deprecated script location.
script · high confidence
Restructured routing with legacy redirects and new admin tools
The application's URL structure has been reorganized to support a unified push model and a new administration center. Legacy localized paths for user authentication (sign-in, password reset, confirmation, unlock) and static pages are now automatically redirected to their English equivalents with the appropriate locale preserved. Old file and URL push shortcuts (f/ and r/) are redirected to the new unified p/ path. Administrators now have access to a new admin dashboard for user management (including promotion, revocation, and deletion) and a separate database exploration area (madmin) for viewing audit logs, pushes, and storage attachments. Additionally, a first-run setup wizard and two-factor authentication (TOTP) routes have been added to the user account flow.
config/routes · high confidence
Support for Docker-style secret files and configurable UI themes
Users can now provide encryption secrets via companion \_FILE environment variables (e.g., NAME\FILE) for better Docker integration, and customize the application's appearance by setting the PWP\\_THEME environment variable to select from available Bootswatch themes.
_lib/password\pusher · high confidence
Unified controller architecture with enhanced security and error handling
The application has refactored its controller layer to improve security, maintainability, and user experience. The legacy \PasswordsController\ has been removed and replaced by a new \PushesController\ which handles the core password push functionality, including passphrase protection, view limiting, and expiration logic. A new \BaseController\ centralizes error handling for missing parameters, unsupported formats, and bad requests, ensuring consistent HTTP status codes and user-facing messages. Security has been hardened by implementing rate limiting on passphrase attempts and email notifications, enforcing CSRF protection for non-JSON requests, and adding Content Security Policy (CSP) report handling via a dedicated \CspReportsController\. Additionally, the \AdminController\ now enforces strict admin-only access, and the \ApplicationController\ integrates multi-factor authentication (MFA) enforcement and configurable robots headers.
app/controllers · high confidence
Unified push creation forms and enhanced viewing experience
The push creation interface has been restructured into distinct, kind-specific forms (text, file, URL, and QR code) that share a common layout for expiration, passphrase, and notification settings. Text and QR pushes now include a payload visibility toggle to hide content while typing, and text pushes support an optional blur effect that auto-reveals on click. File pushes introduce a dedicated multi-file upload interface with progress tracking and per-file deletion. The JSON API response for pushes has been expanded to include payload and file details (filename, content type, URL) when viewing a push, and a new audit log view displays push settings, status, and reference notes.
app/views/pushes · high confidence
Updated bundled Bootswatch themes to v5.3.7 and added Brite theme
The bundled Bootswatch themes in app/assets/stylesheets/themes have been updated to version 5.3.7, bringing new color palettes, font imports, and dark-mode support to themes like Brite, Cerulean, Cosmo, Cyborg, Darkly, Flatly, Journal, and Litera. A new Brite theme has been added to the selection. The default theme's dark mode has been refined to use a custom surface-ladder approach for better depth and contrast, and a BOOTSWATCH\_LICENSE file has been included to document the upstream licensing.
app/assets/stylesheets/themes · high confidence
Updated gettext localization files for multiple languages
The gettext localization files in config/locales/gettext have been updated to include translations for Catalan, Czech, Welsh, Danish, German, English, and British English. These .po files contain the translated strings for application messages, including error notifications, push status updates, and authentication prompts, ensuring that users see interface text in their preferred language.
config/locales/gettext · high confidence
Test coverage
Added controller tests for CSP reports, file/QR/URL/text pushes, first run, and email notifications; Added integration tests for API v2 endpoints; Added integration tests for About and Generate Key pages; Added integration tests for QR code push functionality; Added integration tests for admin user deletion and custom CSS management; Added integration tests for admin, authentication, and security features; Added integration tests for locale availability; Added integration tests for password push functionality; Added model tests for push types, notifications, and security features; Added test coverage for Devise and PushCreated mailers; Added test coverage for application, language, push, and share message helpers; Added tests for API authentication and MFA enforcement; Added tests for flag-icons asset integration and EnvOrFile secret handling; Added tests for session store and settings validation initializers; Added tests for the LogEvents controller concern; Added tests for the NotifiableByEmail model concern; Added tests for user account deletion and password reset 2FA behavior; Added unit tests for push lifecycle and notification jobs; Enhanced test infrastructure with parallel execution and system test stability; Expanded system test coverage for core user and admin workflows; Integration tests added for file push functionality; Integration tests for QR and URL push editing; Removed generated RSpec test suite for Passwords resource.
Dependencies
Routine dependency updates across Ruby and JavaScript ecosystems
This release updates a wide range of Ruby gems and JavaScript packages to their latest versions. Key updates include the AWS SDK partitions data, Rails framework components (such as activestorage and turbo-rails), authentication libraries (Devise, googleauth), and various utility gems (nokogiri, json, puma). JavaScript dependencies like @hotwired/turbo, esbuild, and autoprefixer have also been upgraded. These changes ensure the application uses the latest stable versions of its dependencies for improved security, performance, and compatibility.
(dependencies) · high confidence
Updated vendor JavaScript libraries and fonts
The vendor JavaScript dependencies have been updated to newer versions: Bootstrap is now at 5.3.8, @popperjs/core at 2.11.8, and @rails/actioncable and @rails/activestorage are both at 8.1.300. Additionally, the @fontsource/roboto family of fonts has been updated, with Roboto at 5.2.10, Roboto Mono at 5.2.9, and Roboto Slab at 5.2.8, ensuring the application uses the latest font files and library fixes.
vendor · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 46 → 41 (-4.5)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 61 → 67 (+6.3)
- Architecture 100 → 66 (-33.3)
- Maturity 61 → 61 (+0.0)
- Readiness 31 → 31 (+0.8)
- Security 66 → 72 (+5.7)
- Domain Modelling 53 → 53 (+0.0)
- Accessibility 68 → 39 (-28.8)
Resolved (38)
- Documentation: no architecture or design documentation (containers/docker/README.md)
- Documentation: no architecture or design documentation (containers/kubernetes/README.md)
- High IaC: KSV-0014 (containers/kubernetes/persistent_deploy.yaml)
- High IaC: KSV-0014 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0003 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0011 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0011 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0015 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0015 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0016 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0016 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0018 (containers/kubernetes/persistent_deploy.yaml)
- Low IaC: KSV-0018 (containers/kubernetes/persistent_deploy.yaml)
- Medium IaC: CKV2_K8S_6 (containers/kubernetes/persistent_deploy.yaml)
- Medium IaC: CKV_K8S_11 (containers/kubernetes/persistent_deploy.yaml)
- Medium IaC: CKV_K8S_13 (containers/kubernetes/persistent_deploy.yaml)
- Medium IaC: CKV_K8S_14 (containers/kubernetes/persistent_deploy.yaml)
- Medium IaC: CKV_K8S_20 (containers/kubernetes/persistent_deploy.yaml)
- Medium IaC: CKV_K8S_22 (containers/kubernetes/persistent_deploy.yaml)
- Medium IaC: CKV_K8S_23 (containers/kubernetes/persistent_deploy.yaml)
- …and 18 more
New (3)
- BaseController.require_api_authentication (cyclomatic 16) (app/controllers/api/base_controller.rb)
- No ADRs found
- Projects may be oversized for their cohesion
Changes since last survey
- 64 commits — 62 feature/other, 2 fixes
By area
- (root) — 51 commits
- .github/workflows — 3 commits
- (repo) — 2 commits
- containers/docker — 2 commits
- lib/pwpush — 2 commits
- app/assets — 1 commit
- app/controllers — 1 commit
- app/views — 1 commit
- db/migrate — 1 commit
Notable commits
- fix: Fix flag-icons asset precompile warnings (#4884)
- fix: Rubocop fixes
- change: :arrow_up: Bump actiontext from 8.1.3.1 to 8.1.4 (#4883)
- change: :arrow_up: Bump activestorage from 8.1.3.1 to 8.1.4 (#4880)
- change: :arrow_up: Bump activesupport from 8.1.3.1 to 8.1.4 (#4878)
- change: :arrow_up: Bump autoprefixer from 10.5.5 to 10.5.6 (#4819)
- change: :arrow_up: Bump autoprefixer from 10.5.6 to 10.6.0 (#4834)
- change: :arrow_up: Bump autoprefixer from 10.6.0 to 10.6.1 (#4851)
- change: :arrow_up: Bump aws-partitions from 1.1287.0 to 1.1290.0 (#4882)
- change: :arrow_up: Bump aws-sdk-s3 from 1.229.0 to 1.231.0 (#4828)
- change: :arrow_up: Bump aws-sdk-s3 from 1.231.0 to 1.232.0 (#4831)
- change: :arrow_up: Bump aws-sdk-s3 from 1.232.0 to 1.232.1 (#4852)
- change: :arrow_up: Bump baseline-browser-mapping from 2.11.21 to 2.11.23 (#4818)
- change: :arrow_up: Bump baseline-browser-mapping from 2.11.23 to 2.11.25 (#4848)
- change: :arrow_up: Bump baseline-browser-mapping from 2.11.25 to 2.11.26 (#4866)
- change: :arrow_up: Bump brace-expansion from 5.0.9 to 5.0.12 (#4838)
- change: :arrow_up: Bump browserslist from 4.28.9 to 4.29.0 (#4846)
- change: :arrow_up: Bump browserslist from 4.29.0 to 4.29.1 (#4865)
- change: :arrow_up: Bump caniuse-lite from 1.0.30001810 to 1.0.30001812 (#4868)
- change: :arrow_up: Bump devise-i18n from 1.16.0 to 1.16.1 (#4843)
- …and 44 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
pglombardo/PasswordPusher was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 71febb58410b8393f5ca86507b5e340133e98522 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.