pow-auth/assent
66.0
Adequate · 3 October 2026
4.1k
lines of production code
Elixir
primary language
2
measurements over time
What this system is
Assent is an Elixir library that provides a unified interface for implementing OpenID Connect and OAuth 2.0 authentication flows. It supports a wide range of identity providers through standardized strategies and allows for flexible configuration of HTTP and JWT backends. The system emphasizes extensibility by enabling developers to swap underlying adapters and define custom providers using shared base modules.
Features
Added integration test server for provider validation
A new Plug-based server has been added to the integration directory to facilitate testing the Assent library against all configured OAuth providers. This server dynamically discovers available strategy modules, exposes authentication and callback endpoints for each, and handles the authorization flow by redirecting users and displaying the resulting user and token data. It requires CLIENT\_ID and CLIENT\_SECRET environment variables to function and is intended for use by developers to verify integration correctness locally.
integration · high confidence
Introduce OIDC base strategy for custom OpenID Connect providers
A new \Assent.Strategy.OIDC.Base\ module has been added, providing a foundation for implementing custom OpenID Connect strategies. This base module handles common OIDC flows such as authorization URL generation and callback processing, while allowing developers to define provider-specific configuration via \default\_config/1\ and user data normalization via \normalize/2\. By using this base, custom strategies can inherit standard OIDC behavior without reimplementing core logic.
lib/assent/strategies/oidc · high confidence
Native JWT adapter added alongside JOSE adapter
Users can now choose between two JWT adapters: the existing JOSE-based adapter and a new native \AssentJWT\ adapter that implements signing and verification using Erlang's built-in \:crypto\ and \:public\_key\ modules. The native adapter supports HMAC (HS256/384/512), ECDSA (ES256/384/512), and EdDSA algorithms, providing a dependency-free alternative for JWT operations without requiring the external JOSE library.
_lib/assent/jwt\adapter · high confidence
New OIDC and OAuth 2.0 strategies added; existing strategies migrated to OIDC/OAuth2 base
This release introduces new authentication strategies for Apple Sign In, Azure AD, Bitbucket, DigitalOcean, LINE, LinkedIn, Spotify, Strava, Stripe, Telegram, Twitch, and Zitadel. Additionally, existing strategies for Auth0, GitLab, Google, and Azure (AzureOAuth2) have been migrated from the legacy OAuth2 implementation to the new OpenID Connect (OIDC) or OAuth2 base strategies, standardizing configuration and behavior across the library.
lib/assent/strategies · high confidence
Behavioural changes
Enhanced error reporting with structured exceptions and detailed messages
The library now uses structured exception types (e.g., MissingConfigError, CallbackCSRFError, RequestError) that include specific context fields like config keys, parameter keys, and HTTP response details. This change improves debugging by providing more informative error messages that include relevant data such as expected vs. actual keys and formatted HTTP response bodies, rather than generic error strings.
lib · high confidence
Introduces pluggable HTTP and JWT adapters with normalized response handling
Assent now supports configurable HTTP and JWT backends via new \Assent.HTTPAdapter\ and \Assent.JWTAdapter\ modules, allowing users to swap in libraries like \Req\ or custom implementations instead of relying on hardcoded defaults. The HTTP adapter normalizes response header names to lowercase and automatically decodes JSON or URL-encoded bodies based on content type, while the JWT adapter provides a unified interface for signing and verifying tokens using configurable JSON libraries. Additionally, the legacy \Assent.Config\ module has been removed, with configuration handling migrated to direct keyword list operations and application environment settings.
lib/assent · high confidence
OAuth 1.0a strategy base refactored to use base\_url and conform to OpenID Connect claims
The OAuth 1.0a strategy base now requires the \base\_url\ configuration key instead of the previous \site\ key. Additionally, the \normalize\ callback has been updated to return user data conforming to OpenID Connect Core 1.0 standard claims, mapping the user identifier to the \sub\ field rather than \uid\. The strategy interface has also been adjusted: the \get\_user\ callback has been renamed to \fetch\_user\, and the \normalize\ callback now supports returning provider-specific data alongside the standard claims.
lib/assent/strategies/oauth · high confidence
OAuth2 strategy API and response normalization updates
The OAuth2 base strategy now uses \base\_url\ instead of the deprecated \site\ configuration key. The \normalize\ callback has been updated to return a map conforming to OpenID Connect Core 1.0 standard claims (using \sub\ instead of \uid\), and its return type now supports returning additional provider-specific data alongside the standard claims. Additionally, the \get\_user\ function has been renamed to \fetch\_user\ to better reflect its purpose, and the strategy now implements the \Assent.Strategy\ behaviour for consistent interface compliance.
lib/assent/strategies/oauth2 · high confidence
Removal of explicit JSON library configuration
The explicit configuration setting the JSON library to Jason has been removed from the application config. This change means the application will no longer explicitly enforce Jason as the JSON parser via this configuration file, likely reverting to the default behavior or relying on other configuration mechanisms.
config · high confidence
Replace Mint HTTP adapter with Req and enhance Httpc SSL handling
The Mint HTTP adapter has been removed and replaced by a new Req adapter, allowing users to switch their HTTP backend by configuring \http\_adapter: {Assent.HTTPAdapter.Req, \[...\]}\. The existing Httpc adapter has been updated to automatically enable SSL verification when \:certifi\ and \:ssl\_verify\_fun\ are present, and it now correctly handles wildcard certificates using \:public\_key.pkix\_verify\_hostname\_match\_fun\ for OTP 22+. Additionally, the Httpc adapter now automatically sets the \Content-Length\ header for requests with a body.
_lib/assent/http\adapter · high confidence
Upgrade to Elixir 1.15 and OTP 26 with breaking API changes
The framework now requires Elixir 1.15 and OTP 26, dropping support for older versions. This release introduces several breaking changes: the \Assent.HTTPAdapter.Finch\ and \Assent.HTTPAdapter.Mint\ adapters have been removed, and the \Assent.Config\ module is deprecated. Configuration options have shifted, with \:site\ replaced by \:base\_url\ and \:domain\ removed from Auth0 in favor of \:base\_url\. Several strategies (Auth0, Gitlab, Google) now use the OIDC base strategy, and user claims are cast to correct types per the OpenID specification (e.g., \sub\ is now a binary, \email\_verified\ is a boolean). Additionally, \:inets\ is started automatically, and the JWT adapter now supports EdDSA and EC JWKs.
(repo-wide) · high confidence
Test coverage
Added test coverage for JWT adapters; Added tests for Assent configuration and parameter fetching; Added tests for HTTP, JWT, and Strategy adapters; Expanded test coverage for new and refactored authentication strategies; Migrate test helpers from Bypass to TestServer and standardize JSON library usage; Refactor HTTP adapter tests to use local test servers.
Dependencies
Upgrade to Elixir 1.15 and modernize HTTP client dependencies
The library now requires Elixir 1.15 and has updated its HTTP client dependencies, replacing the legacy \mint\ adapter with \req\ and adding support for the \jose\ library for JWT operations. This change also removes the deprecated \oauther\ dependency and updates the test suite to use \bandit\ and \test\_server\ instead of \bypass\, ensuring compatibility with modern Elixir standards and improved HTTP handling.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 70 → 66 (-3.9)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 98 → 98 (-0.1)
- Architecture 100 → 100 (+0.0)
- Maturity 64 → 64 (+0.0)
- Readiness 64 → 55 (-9.1)
- Security 76 → 79 (+3.2)
Resolved (4)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (6 lines × 2) (lib/assent/strategies/discord.ex)
- Duplicated block (6 lines × 2) (lib/assent/strategies/strava.ex)
- Medium CVE: EEF-[CVE redacted] (integration/mix.lock)
New (4)
- Duplicated block (8 lines × 2) (lib/assent/strategies/discord.ex)
- Duplicated block (8 lines × 2) (lib/assent/strategies/strava.ex)
- Duplicated block (9 lines × 2) (lib/assent/strategies/bitbucket.ex)
- High CVE: [GHSA redacted] (integration/mix.lock)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
pow-auth/assent was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 17070852974fd4d39a56d81576802fb05510fb35 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-8fe32cd45d00.