pow-auth/pow
61.1
Adequate · 23 September 2026
9.7k
lines of production code
Elixir
primary language
5
measurements over time
What this system is
Pow is an authentication library for Elixir and Phoenix applications, providing a modular framework for managing user sessions, credentials, and account workflows. It offers a suite of extensions including email confirmation, password resets, persistent sessions, and user invitations, each with dedicated Ecto schemas and Phoenix controllers. The system also includes Mix tasks to automate the generation of migrations, templates, and configuration, streamlining the integration of authentication features into web applications.
How it got here
2018 — Pow rebranding and Phoenix 1.7 modernization
82 changes.
The project underwent a major rebranding from Authex to Pow, accompanied by a comprehensive architectural overhaul to support Phoenix 1.7 and Ecto 3. This period focused on modernizing the codebase by introducing dedicated Ecto contexts, Phoenix controllers, and Mix tasks for each extension, while removing legacy authentication plugs and in-memory caching mechanisms.
2019–2021 — invitation extension and infrastructure
14 changes.
This period focused on introducing the PowInvitation extension, which enables user invitation workflows across Ecto and Phoenix layers. The work also included adding test support infrastructure for extensions and comprehensive test coverage for various components, including password hashing and session caching.
Features
Add Ecto 3 support and new migration generation utilities
Introduces a new \Mix.Pow.Ecto.Migration\ module that provides utilities for generating Ecto migration files, including a \create\_migration\_file/3\ function that handles timestamping, path resolution, and uniqueness checks. The implementation adds explicit support for Ecto 3.0 (while maintaining backward compatibility with Ecto 2.x via conditional loading), addressing previous compile warnings and ensuring compatibility with the latest Ecto versions.
lib/mix/pow/ecto · medium confidence
Add Mnesia cluster auto-initialization and network split recovery
A new \Pow.Store.Backend.MnesiaCache.Unsplit\ GenServer is introduced to handle Mnesia cluster auto-initialization and network split recovery. The module subscribes to Mnesia system events to detect inconsistent databases and restore data from the oldest node, with an optional \:flush\_tables\ configuration to control data loss risks. Additionally, it supports automatic cluster initialization when new nodes connect, resetting the Mnesia schema if the local node is older than the remote one.
_lib/pow/store/backend/mnesia\cache · high confidence
Add Phoenix 1.7+ compatible HTML helpers and templates
The library now provides new HTML helper modules (Bootstrap, CoreComponents, ErrorHelpers, FormTemplate, Minimalist) that support both legacy Phoenix versions and the new component-based approach introduced in Phoenix 1.7. For users on Phoenix 1.7+, the \core\_components.ex\ file enables the use of Phoenix's built-in \simple\_form\, \input\, and \button\ components, which offer a more modern, declarative way to build forms. For older Phoenix versions, the \bootstrap.ex\ and \minimalist.ex\ modules provide traditional EEx-based form templates. This change allows the library to adapt its HTML generation strategy based on the Phoenix version, ensuring compatibility and leveraging new features where available.
lib/pow/phoenix/html · high confidence
Add Phoenix controller callbacks for persistent session management
A new module, PowPersistentSession.Phoenix.ControllerCallbacks, has been added to handle session lifecycle events within the Phoenix framework. This implementation intercepts the \create\ and \delete\ actions on the \Pow.Phoenix.SessionController\ to manage persistent session storage. Specifically, it ensures that persistent sessions are stored upon successful login and are properly cleaned up when a user logs out.
_lib/extensions/persistent\session/phoenix · high confidence
Add Phoenix integration for password reset messages and routing
The library now provides Phoenix-specific implementations for the password reset flow. A new \PowResetPassword.Phoenix.Messages\ module defines user-facing flash messages for scenarios such as sending reset emails, handling invalid tokens, and confirming password updates. Additionally, \PowResetPassword.Phoenix.Router\ is introduced to define the \/reset-password\ routes, mapping the new and create actions for the reset password controller.
_lib/extensions/reset\password/phoenix · high confidence
Add Pow Ecto extension migration generation task
A new Mix task, \pow.extension.ecto.gen.migrations\, has been added to generate user migration files for Pow extensions. The task supports the \--extension\ flag to specify extensions, a \--binary-id\ flag to use binary IDs for primary keys, and provides warnings when no migration file is generated for an extension that does not require one.
lib/mix/tasks/extension/ecto · high confidence
Add Pow Mix task utilities
A new \Mix.Pow\ module is introduced to provide utilities for Mix tasks, including dependency checks for Ecto, Phoenix, and generic dependencies, as well as argument parsing and validation for schema generation.
lib/mix · high confidence
Add Pow.Ecto generator tasks for schema, migration, and installation
Users can now generate Ecto schemas, migrations, and perform initial setup via new mix tasks: \mix pow.ecto.gen.schema\ to create schema modules, \mix pow.ecto.gen.migration\ to create migration files, and \mix pow.ecto.install\ to run both. These tasks support the \--binary-id\ flag for binary primary keys and allow skipping specific generation steps with \--no-migrations\ or \--no-schema\.
lib/mix/tasks/ecto · high confidence
Add PowEmailConfirmation extension for email verification
Introduces the PowEmailConfirmation extension, which requires users to verify their email address before signing in. The extension prevents user enumeration by hiding whether an email is already registered, and ensures the session is regenerated upon successful confirmation.
_lib/extensions/email\confirmation · high confidence
Add PowInvitation Phoenix extension
The PowInvitation extension for Phoenix is introduced, providing a new router that mounts an InvitationController with new, edit, show, and update routes at /invitations, and a Messages module that defines flash messages for invalid/expired invitations and successful email invitations.
lib/extensions/invitation/phoenix · high confidence
Add PowInvitation extension for user invitation workflows
Introduces the PowInvitation extension, enabling users to invite others to join the application. The extension provides plug functions to create and update invited users, sign and verify invitation tokens, and handle acceptance flows. It includes a README with configuration examples for limiting invitations by role, restricting registration to invites only, and expiring invitations. The implementation prevents user enumeration by hiding unique constraint errors and supports integration with PowEmailConfirmation.
lib/extensions/invitation · high confidence
Add base module and migration generation for Ecto schema extensions
The Pow Ecto extension now provides a reusable base module (Pow.Extension.Ecto.Schema.Base) that allows extensions to define custom attributes, associations, indexes, and changesets for user schemas. Additionally, a new migration generator (Pow.Extension.Ecto.Schema.Migration) automatically creates database migrations that include these custom fields and associations, supporting :binary\_id types for foreign keys.
lib/pow/extension/ecto/schema · high confidence
Add base module for Phoenix controller callbacks in Pow extensions
A new base module, Pow.Extension.Phoenix.ControllerCallbacks.Base, has been introduced to standardize how Pow extensions implement Phoenix controller callbacks. This module provides a reusable structure with default implementations for before\_process and before\_respond hooks, allowing extensions to easily integrate with the new callback system.
_lib/pow/extension/phoenix/controllers/controller\callbacks · high confidence
Add controller callbacks for Pow extensions
A new module, Pow.Extension.Phoenix.ControllerCallbacks, has been added to automatically trigger before\_process and before\_respond hooks for all configured extensions. This allows extension modules to intercept and modify controller actions and responses within the Phoenix framework.
lib/pow/extension/phoenix/controllers · high confidence
Add invitation handling for user registration
Introduces a new PowInvitation extension that allows existing users to invite others to join the application. The change adds an \InvitationController\ to manage invitation flows, including creating and updating user accounts via signed tokens. It includes HTML templates for the invitation, edit, and show pages, as well as mailer components to send invitation emails containing the unique access link. This enables a workflow where invited users can register and set their credentials using the provided token.
lib/extensions/invitation/phoenix/controllers · high confidence
Add mix tasks to generate Phoenix templates and mailers for extensions
Users can now generate Phoenix view templates and mailer templates for Pow extensions using the new \mix pow.extension.phoenix.gen.templates\ and \mix pow.extension.phoenix.mailer.gen.templates\ mix tasks. These tasks accept an \--extension\ flag to specify which extensions to generate templates for, and a \--context-app\ flag to control path and module naming. The mailer task also automatically injects the \web\_mailer\_module\ configuration and updates the Phoenix web module to include the necessary mailer components.
lib/mix/tasks/extension/phoenix · high confidence
Add new mix tasks for Pow help and installation
The Pow library introduces two new Mix tasks: \mix pow\ to display help information about the library, and \mix pow.install\ to run installation tasks for Ecto and Phoenix. The install task validates that it is not run inside an umbrella project, providing specific instructions for each sub-task if that condition is met.
lib/mix/tasks · high confidence
Add persistent session extension for long-lived authentication
Introduces the PowPersistentSession extension, which allows users to maintain their authenticated state across browser sessions by setting a persistent cookie that expires after 30 days. To use this feature, developers must add \PowPersistentSession.Plug.Cookie\ to their endpoint configuration and optionally include a \persistent\_session\ checkbox in the login form to let users manage the setting.
_lib/extensions/persistent\session · high confidence
Add persistent session support via new PowPersistentSession.Plug.Cookie
Introduces a new \PowPersistentSession.Plug.Cookie\ plug that enables persistent user sessions using signed tokens stored in cookies. The implementation uses a \before\_send\ callback to write to the backend store and client, ensuring proper ordering. It supports custom session metadata (including fingerprints) and allows configuration of the cookie key, TTL, and store backend. The token is signed to prevent timing attacks, and the plug handles creation, authentication, and deletion of persistent sessions.
_lib/extensions/persistent\session/plug · high confidence
Introduce Pow.Ecto.Context and Pow.Ecto.Schema modules for user authentication and schema handling
The Pow library now provides dedicated Ecto modules for handling user context and schema definitions. The new \Pow.Ecto.Context\ module manages authentication, creation, update, deletion, and retrieval of user records, including protection against timing attacks during password verification. The \Pow.Ecto.Schema\ module provides a macro to automatically generate Ecto schema fields, associations, and changeset functions for user models, with compile-time validation and customizable password hashing and length requirements.
lib/pow/ecto · high confidence
Introduce Pow.Ecto.Schema module for Ecto schema extensions
A new \Pow.Ecto.Schema\ module has been added to manage Ecto schema extensions. This module provides macros to register extension fields, associations, and indexes, and ensures that all extension modules are properly integrated into the user schema. It also adds a compilation-time validation to verify that all required fields are defined, improving the reliability of schema configurations.
lib/pow/extension/ecto · high confidence
Introduce PowInvitation Ecto extension for user invitations
Added the PowInvitation Ecto extension, providing new modules (Context and Schema) that enable inviting users, generating invitation tokens, and accepting invitations. The schema adds fields for invitation status and associations, while the context exposes methods for creating and updating invited users. The changeset functions are made overridable, allowing users to customize the invitation flow.
lib/extensions/invitation/ecto · high confidence
Introduce PowResetPassword extension for password reset functionality
Users can now reset their passwords via an email link. This new extension provides the core logic for generating and verifying reset tokens, securely storing them in a cache, and updating the user's password. It includes protections against user enumeration and timing attacks, and supports custom cache backends for token storage.
_lib/extensions/reset\password · high confidence
Introduce structured extension routing and messaging for Phoenix
The Pow Phoenix extension now provides dedicated modules for handling extension routes and messages. The new \Pow.Extension.Phoenix.Router\ module allows developers to declare extension routes via a \pow\_extension\_routes/0\ macro, which automatically wraps each extension's routes in a scoped namespace. Similarly, \Pow.Extension.Phoenix.Messages\ enables consistent message handling across extensions, allowing users to override messages by defining functions named after the extension. This change simplifies the integration of Pow extensions into Phoenix applications by providing a standardized way to manage routes and messages.
lib/pow/extension/phoenix · high confidence
Introduced Mix task for generating Phoenix mailer templates
A new module, Mix.Pow.Phoenix.Mailer, has been added to provide utilities for generating mailer templates in Phoenix applications. This change introduces the ability to create mail template files via a Mix task, allowing users to generate mailer modules with specified templates. The module includes functions to create mail modules and generate template functions for each mail, enhancing the developer experience when setting up email functionality.
lib/mix/pow/phoenix · high confidence
New Mix utilities for Phoenix web app scaffolding
Added new Mix task utilities in lib/mix/pow/extension.ex and lib/mix/pow/phoenix.ex to support Phoenix web application generation. The Extension module provides a centralized way to resolve and fetch extension configurations, while the Phoenix module handles parsing structure configurations and creating HTML templates for web modules. These utilities enable the mix tasks to properly handle context apps and web module generation for Phoenix applications.
lib/mix/pow · high confidence
New base store and credentials cache implementation
The \lib/pow/store\ directory now includes a new \Pow.Store.Base\ module that provides a standardized API for key-value stores, including a \\_\using\\_\ macro to simplify custom store implementations. A new \Pow.Store.CredentialsCache\ module has been added to handle session storage, supporting user and session listing, credential storage with metadata, and automatic invalidation of duplicate sessions based on fingerprints. The implementation includes a deprecation path for binary keys in backend stores and warns about excessive TTL values.
lib/pow/store · high confidence
New cache backends for session storage
The library now provides new cache store backends for session management. A new \Pow.Store.Backend.Base\ module defines the interface for key-value cache stores. Two implementations are added: \Pow.Store.Backend.EtsCache\, an in-memory ETS-based cache with optional async writes, and \Pow.Store.Backend.MnesiaCache\, a distributed Mnesia-based cache that supports multi-node clusters, automatic node discovery, and split-brain recovery. These modules implement the \Base\ behaviour, allowing users to switch between in-memory and distributed persistent caching strategies for the store backend.
lib/pow/store/backend · high confidence
New email confirmation controller and callbacks
The email confirmation feature now includes a dedicated Phoenix controller (ConfirmationController) and controller callbacks that manage the email verification flow. Users will receive flash messages for successful or failed confirmations, and the system prevents information leakage during registration by handling unique constraint errors gracefully. The controller handles token loading, redirects to appropriate paths based on user state, and sends confirmation emails with signed tokens.
_lib/extensions/email\confirmation/phoenix/controllers · medium confidence
New mix tasks to install and configure Pow in Phoenix apps
The library introduces two new Mix tasks, \pow.phoenix.install\ and \pow.phoenix.gen.templates\, to streamline setting up the Pow authentication library in Phoenix applications. The \install\ task automatically injects the necessary configuration into \config.exs\, adds the \Pow.Plug.Session\ plug to the endpoint, and inserts the Pow router scope into the router. It also supports generating templates and extension templates via the \--templates\ and \--extension\ flags, providing clear shell instructions for any manual steps required.
lib/mix/tasks/phoenix · high confidence
Removals
Removal of Authex.Config module
The Authex.Config module, which previously handled configuration retrieval and default value resolution for user assigns keys, has been removed from the codebase.
lib/authex · high confidence
Removed Authex.Authorization.Plug module
The Authex.Authorization.Plug module, which previously provided helper functions for handling the current user and configuration within Plug-based applications, has been removed from the codebase.
lib/authex/authorization · high confidence
Removed legacy authorization plugs and ETS-based store
The \Authex.Authorization.Plug.RequireAuthenticated\, \Authex.Authorization.Plug.RequireNotAuthenticated\, and \Authex.Authorization.Plug.Session\ plugs have been removed, along with the \Authex.Authorization.Store.CredentialsCache\ GenServer that managed credentials in an ETS table. This change eliminates the previous session-based authentication and in-memory caching mechanism, indicating a shift in how user sessions and credentials are managed within the application.
lib/authex/authorization/plug · high confidence
Behavioural changes
Add email confirmation messaging and routing for Phoenix
The extension now provides user-facing flash messages for email confirmation states, including success, failure, invalid token, and required confirmation for both sign-in and email updates. Additionally, a new router module registers the '/confirm-email' route to handle confirmation requests.
_lib/extensions/email\confirmation/phoenix · high confidence
Centralized test configuration for Pow extensions
Test environment configuration for Pow extensions (including Ecto, Mnesia, Email Confirmation, Invitation, Persistent Session, and Reset Password) has been moved from the main config file to a dedicated test.exs file, ensuring that test-specific settings like database connections and endpoint configurations are isolated from production or development environments.
config · high confidence
Deprecate Pow.Extension.Ecto.Context.Base
The base context module for the Ecto extension is now deprecated. Using \use Pow.Extension.Ecto.Context.Base\ will emit a warning directing users to use the functions in \Pow.Ecto.Context\ instead.
lib/pow/extension/ecto/context · high confidence
Introduce base controller for message handling in Phoenix extensions
A new base controller, \Pow.Extension.Phoenix.Controller.Base\, has been added to standardize how messages and routes are handled in Phoenix controllers. This change introduces a \extension\_messages/1\ function that allows extensions to define their own message modules, with a fallback mechanism to a default messages module. The implementation also includes a deprecation warning for the \:messages\_backend\_fallback\ config option, which will be removed in a future version.
lib/pow/extension/phoenix/controllers/controller · medium confidence
Introduce base module and configuration helpers for extension auto-discovery
A new \Pow.Extension.Base\ module is added to provide a standard interface for extensions to declare their capabilities (e.g., \ecto\_schema?\, \phoenix\_templates?\) and enable auto-discovery. The \Pow.Extension.Config\ module is introduced to manage extension configuration, including a new \extension\_modules/2\ function that filters and returns existing extension modules based on the base module's declarations. This refactors how extensions are discovered and validated, moving away from previous methods that relied on \Code.ensure\_compiled?/1\.
lib/pow/extension · medium confidence
Introduce new core modules for configuration, context, and operations
The library now includes new modules: \Pow.Application\ for managing the EtsCache supervisor, \Pow.Config\ for parsing and modifying configurations with environment fallbacks, \Pow.Context\ defining the user schema interface, \Pow.Operations\ to glue operation calls to the context module, and \Pow.UUID\ for generating UUID binaries. These changes restructure how configuration is handled, provide explicit methods for user operations (authenticate, create, update, delete), and ensure the module exists and is loaded before accessing primary keys.
lib/pow · high confidence
Modernize reset password UI with Phoenix 1.7+ components
The reset password pages have been updated to use Phoenix 1.7+ CoreComponents (e.g., \\<.simple\_form\>\, \\<.header\>\, \\<.link\>\) for the user interface. For older Phoenix versions, the legacy \render\_form\ approach is retained. This change improves the visual consistency of the password reset flow with modern Phoenix templates.
_lib/extensions/reset\password/phoenix/controllers · medium confidence
Persistent session cache now supports automatic user reloading
The persistent session cache has been refactored to include a \:reload\ configuration option that allows the cache to automatically fetch the latest user data from the database on each session lookup. This ensures that session data remains up-to-date without requiring the user to log in again. The implementation includes a backwards compatibility layer that warns if the new \:pow\_config\ argument is not provided, indicating a breaking change in the API for older configurations.
_lib/extensions/persistent\session/store · medium confidence
Rebuilt Phoenix controllers and templates for Phoenix 1.7 compatibility
The Pow library's Phoenix integration has been completely rebuilt to support Phoenix 1.7. This includes new controller implementations for session and registration flows, updated HTML templates using CoreComponents and Tailwind CSS, and a compatibility layer in \ViewHelpers\ that conditionally applies Phoenix 1.7 features (like \layouts\ in controllers) while maintaining support for older versions. Users on Phoenix 1.7 will see modernized, component-based templates, while older Phoenix versions continue to use the legacy template structure.
lib/pow/phoenix/controllers · high confidence
Refactor PowResetPassword Ecto context and schema
The reset password extension now uses a dedicated Ecto context and schema modules to decouple the changeset logic from the main context. The context module provides \get\_by\_email\ and \update\_password\ methods, while the schema module defines the \reset\_password\_changeset\ function, which validates the password and required fields. The old \password\_changeset\ in the context is deprecated in favor of the new schema-based approach.
_lib/extensions/reset\password/ecto · medium confidence
Refactor email templates into dedicated Phoenix components
The email templates for account confirmation and password reset have been restructured into dedicated Phoenix mailer components. This change updates how the application sends confirmation and reset password emails, ensuring that the HTML and plain-text versions are managed through the new mailer modules.
_lib/extensions/email\_confirmation/phoenix/mailers, lib/extensions/reset\password/phoenix/mailers · medium confidence
Refactored Ecto schema generation and validation logic
The Ecto schema generation and validation logic has been refactored into dedicated modules: \Pow.Ecto.Schema.Changeset\ handles all changeset validations (user ID, password, email, and current password) using compile-time configuration and Ecto's built-in validators. Password hashing is now handled by \Pow.Ecto.Schema.Password\ using PBKDF2-SHA512, replacing the previous \password\_hash\_methods\ configuration. The schema generation now uses \Pow.Ecto.Schema.Module\ and \Pow.Ecto.Schema.Fields\ to produce the user schema and migration files, with the user ID field being case-insensitive and unique. Password fields are redacted in logs and memory.
lib/pow/ecto/schema · high confidence
Refactored Pow.Phoenix routing and message handling
The library has been restructured to improve customization and maintainability. A new \Pow.Phoenix.Messages\ module provides a dedicated backend for all user-facing text, allowing developers to easily override default strings for authentication, registration, and account management. The \Pow.Phoenix.Router\ module now uses explicit macro definitions (\pow\_routes/0\, \pow\_session\_routes/0\, \pow\_registration\_routes/0\) to generate routes, which simplifies the process of overriding or filtering specific actions. Additionally, the \Pow.Phoenix.Routes\ module was introduced to centralize path and URL generation, supporting both standard and verified routes for Phoenix 1.7+ while maintaining backward compatibility with older versions.
lib/pow/phoenix · high confidence
Refactored email confirmation logic into dedicated Ecto context and schema modules
The email confirmation functionality has been restructured into new \PowEmailConfirmation.Ecto.Context\ and \PowEmailConfirmation.Ecto.Schema\ modules. This change introduces a dedicated context for handling email confirmation operations, such as \get\_by\_confirmation\_token\ and \confirm\_email\, and a schema module that manages the \email\_confirmation\_token\, \email\_confirmed\_at\, and \unconfirmed\_email\ fields. The schema's \changeset\ function now explicitly handles the logic for tracking unconfirmed email changes and generating confirmation tokens, while the context provides a cleaner API for confirming emails. This refactoring decouples the Ecto-specific implementation from the broader Pow extension system, making the email confirmation process more modular and maintainable.
_lib/extensions/email\confirmation/ecto · high confidence
Refactored mailer to use Phoenix components and templates
The mailer implementation has been refactored to use Phoenix components and templates, moving away from the previous \Phoenix.View\-based approach. This change introduces new modules (\Component\, \Mail\, and \Template\) that handle email rendering using modern Phoenix template syntax (\\~H\ and \\~P\ sigils) and support for custom email layouts. Users will now interact with a more flexible and modern templating system for generating HTML and text email content.
lib/pow/phoenix/mailer · high confidence
Refactored session handling and introduced extensible plug base
The \Pow.Plug\ module has been refactored to use a new \Pow.Plug.Base\ macro that standardizes session management via the \:before\_send\ callback. This change introduces \Pow.Plug.MessageVerifier\ for secure token signing and verification, and adds support for custom session metadata (e.g., IP, user-agent) stored in the credentials cache. The \:session\_store\ configuration option has been renamed to \:credentials\_cache\_store\ to better reflect its purpose, and session IDs are now signed to prevent timing attacks. Additionally, new plugs \Pow.Plug.RequireAuthenticated\ and \Pow.Plug.RequireNotAuthenticated\ provide standardized ways to enforce authentication states with custom error handlers.
lib/pow/plug · high confidence
Rename library from Authex to Pow
The library has been renamed from Authex to Pow. The Authex module and its config method have been removed, and a new Pow module has been added to handle dependency version matching, reflecting the library's rebranding.
lib · high confidence
Replaced external password hashing dependency with a custom PBKDF2 implementation
The password hashing logic for Ecto schemas has been refactored to use a custom \Pow.Ecto.Schema.Password.Pbkdf2\ module instead of the previous \Comeonin\ library. This change removes the external \Comeonin\ dependency and implements PBKDF2 hashing directly within the \pow\ library, utilizing \:crypto.mac\ and \:crypto.hmac\ from the Erlang \:crypto\ module. The implementation includes a constant-time comparison function to mitigate timing attacks and supports configurable iterations, salt, and digest algorithms. This is a behavioral change for users relying on the previous hashing mechanism, as the underlying cryptographic implementation and dependencies have changed.
lib/pow/ecto/schema/password · high confidence
Fixes
Fix relative links in generated documentation
The \lib/ex\_doc\ directory now includes a custom markdown parser (\ExDoc.Pow.Markdown\) that intercepts markdown processing to correctly resolve relative links. This ensures that internal documentation links and source code links to GitHub work as expected in the generated HTML output.
_lib/ex\doc · medium confidence
Test coverage
Add Ecto test support infrastructure; Add centralized test helper for Mix task testing; Add tests for mix Pow and Pow.Install tasks; Added Ecto and Phoenix test infrastructure; Added Ecto migration test fixtures; Added Ecto-specific tests for the password reset extension; Added Phoenix test support files; Added comprehensive Ecto tests for email confirmation; Added comprehensive test coverage for Phoenix controllers; Added comprehensive test coverage for Phoenix reset password controller; Added comprehensive test coverage for Pow.Ecto Context and Schema modules; Added comprehensive tests for Pow Phoenix install and template generation tasks; Added comprehensive tests for Pow.Store.Base and Pow.Store.CredentialsCache; Added test coverage for PersistentSessionCache; Added test fixtures for Ecto user schemas; Added test infrastructure for the PersistentSession extension; Added test mocks for PowInvitation; Added test mocks for the PowResetPassword extension; Added test support for email confirmation extension; Added test support infrastructure for extensions; Added tests for Ecto schema migration generation; Added tests for Ecto-related Mix tasks; Added tests for EtsCache and MnesiaCache backends; Added tests for PBKDF2 password hashing; Added tests for Phoenix controller callbacks in the persistent session extension; Added tests for Phoenix extension messages and router; Added tests for Phoenix extension template generation; Added tests for Pow.Ecto.Schema components; Added tests for PowInvitation Ecto context and schema; Added tests for email confirmation flow in Phoenix controllers; Added tests for mail template rendering and layout configuration; Added tests for the Ecto schema extension; Added tests for the Pow Ecto extension mix tasks; Added tests for the PowPersistentSession plug cookie handling; Added tests for the invitation controller; Added tests for the reset password plug; Added unit tests for Pow configuration, operations, and plug modules; Added unit tests for Pow.Phoenix mailer, messages, router, and routes; Expanded test coverage for Pow.Plug session and authentication plugs; Refactored test support modules for session and context mocking; Removed Authex configuration tests; Removed obsolete authorization plug tests; Removed obsolete test files for session and credentials cache.
Dependencies
Updated dependencies and raised minimum Elixir version
The project has been updated to require Elixir 1.14 or higher and upgraded to support Phoenix 1.7 and Phoenix Live View 1.0. The dependency list now includes explicit support for Ecto 3.12, Plug 1.16, and Elixir 1.14, while removing older constraints on packages like Comeonin and Coherence. This ensures compatibility with the latest versions of the Phoenix and Ecto ecosystems.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 57 → 61 (+3.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 98 → 87 (-10.9)
- Architecture 100 → 91 (-8.9)
- Maturity 54 → 50 (-3.8)
- Readiness 50 → 62 (+12.1)
- Security 54 → 73 (+18.9)
Resolved (15)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
New (87)
- Duplicated block (12 lines × 2) (lib/mix/tasks/extension/phoenix/pow.extension.phoenix.mailer.gen.templates.ex)
- Duplicated block (6 lines × 2) (lib/pow/store/backend/ets_cache.ex)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No dependency advisory monitoring
- Outdated: credo
- Outdated: ecto
- Outdated: ecto_sql
- …and 67 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
pow-auth/pow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fe092233f7c85589e90761a761fb290dcc8cf706 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.