Skip to content
CAI
Software that uses CAICheck a score

pow-auth/pow

61.1

Adequate · 23 September 2026

9.7k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Pow is an authentication library for Elixir and Phoenix applications, providing a modular framework for managing user sessions, credentials, and account workflows. It offers a suite of extensions including email confirmation, password resets, persistent sessions, and user invitations, each with dedicated Ecto schemas and Phoenix controllers. The system also includes Mix tasks to automate the generation of migrations, templates, and configuration, streamlining the integration of authentication features into web applications.

How it got here

2018 — Pow rebranding and Phoenix 1.7 modernization

82 changes.

The project underwent a major rebranding from Authex to Pow, accompanied by a comprehensive architectural overhaul to support Phoenix 1.7 and Ecto 3. This period focused on modernizing the codebase by introducing dedicated Ecto contexts, Phoenix controllers, and Mix tasks for each extension, while removing legacy authentication plugs and in-memory caching mechanisms.

2019–2021 — invitation extension and infrastructure

14 changes.

This period focused on introducing the PowInvitation extension, which enables user invitation workflows across Ecto and Phoenix layers. The work also included adding test support infrastructure for extensions and comprehensive test coverage for various components, including password hashing and session caching.

Features

Add Ecto 3 support and new migration generation utilities

Introduces a new \Mix.Pow.Ecto.Migration\ module that provides utilities for generating Ecto migration files, including a \create\_migration\_file/3\ function that handles timestamping, path resolution, and uniqueness checks. The implementation adds explicit support for Ecto 3.0 (while maintaining backward compatibility with Ecto 2.x via conditional loading), addressing previous compile warnings and ensuring compatibility with the latest Ecto versions.

lib/mix/pow/ecto · medium confidence

Add Mnesia cluster auto-initialization and network split recovery

A new \Pow.Store.Backend.MnesiaCache.Unsplit\ GenServer is introduced to handle Mnesia cluster auto-initialization and network split recovery. The module subscribes to Mnesia system events to detect inconsistent databases and restore data from the oldest node, with an optional \:flush\_tables\ configuration to control data loss risks. Additionally, it supports automatic cluster initialization when new nodes connect, resetting the Mnesia schema if the local node is older than the remote one.

_lib/pow/store/backend/mnesia\cache · high confidence

Add Phoenix 1.7+ compatible HTML helpers and templates

The library now provides new HTML helper modules (Bootstrap, CoreComponents, ErrorHelpers, FormTemplate, Minimalist) that support both legacy Phoenix versions and the new component-based approach introduced in Phoenix 1.7. For users on Phoenix 1.7+, the \core\_components.ex\ file enables the use of Phoenix's built-in \simple\_form\, \input\, and \button\ components, which offer a more modern, declarative way to build forms. For older Phoenix versions, the \bootstrap.ex\ and \minimalist.ex\ modules provide traditional EEx-based form templates. This change allows the library to adapt its HTML generation strategy based on the Phoenix version, ensuring compatibility and leveraging new features where available.

lib/pow/phoenix/html · high confidence

Add Phoenix controller callbacks for persistent session management

A new module, PowPersistentSession.Phoenix.ControllerCallbacks, has been added to handle session lifecycle events within the Phoenix framework. This implementation intercepts the \create\ and \delete\ actions on the \Pow.Phoenix.SessionController\ to manage persistent session storage. Specifically, it ensures that persistent sessions are stored upon successful login and are properly cleaned up when a user logs out.

_lib/extensions/persistent\session/phoenix · high confidence

Add Phoenix integration for password reset messages and routing

The library now provides Phoenix-specific implementations for the password reset flow. A new \PowResetPassword.Phoenix.Messages\ module defines user-facing flash messages for scenarios such as sending reset emails, handling invalid tokens, and confirming password updates. Additionally, \PowResetPassword.Phoenix.Router\ is introduced to define the \/reset-password\ routes, mapping the new and create actions for the reset password controller.

_lib/extensions/reset\password/phoenix · high confidence

Add Pow Ecto extension migration generation task

A new Mix task, \pow.extension.ecto.gen.migrations\, has been added to generate user migration files for Pow extensions. The task supports the \--extension\ flag to specify extensions, a \--binary-id\ flag to use binary IDs for primary keys, and provides warnings when no migration file is generated for an extension that does not require one.

lib/mix/tasks/extension/ecto · high confidence

Add Pow Mix task utilities

A new \Mix.Pow\ module is introduced to provide utilities for Mix tasks, including dependency checks for Ecto, Phoenix, and generic dependencies, as well as argument parsing and validation for schema generation.

lib/mix · high confidence

Add Pow.Ecto generator tasks for schema, migration, and installation

Users can now generate Ecto schemas, migrations, and perform initial setup via new mix tasks: \mix pow.ecto.gen.schema\ to create schema modules, \mix pow.ecto.gen.migration\ to create migration files, and \mix pow.ecto.install\ to run both. These tasks support the \--binary-id\ flag for binary primary keys and allow skipping specific generation steps with \--no-migrations\ or \--no-schema\.

lib/mix/tasks/ecto · high confidence

Add PowEmailConfirmation extension for email verification

Introduces the PowEmailConfirmation extension, which requires users to verify their email address before signing in. The extension prevents user enumeration by hiding whether an email is already registered, and ensures the session is regenerated upon successful confirmation.

_lib/extensions/email\confirmation · high confidence

Add PowInvitation Phoenix extension

The PowInvitation extension for Phoenix is introduced, providing a new router that mounts an InvitationController with new, edit, show, and update routes at /invitations, and a Messages module that defines flash messages for invalid/expired invitations and successful email invitations.

lib/extensions/invitation/phoenix · high confidence

Add PowInvitation extension for user invitation workflows

Introduces the PowInvitation extension, enabling users to invite others to join the application. The extension provides plug functions to create and update invited users, sign and verify invitation tokens, and handle acceptance flows. It includes a README with configuration examples for limiting invitations by role, restricting registration to invites only, and expiring invitations. The implementation prevents user enumeration by hiding unique constraint errors and supports integration with PowEmailConfirmation.

lib/extensions/invitation · high confidence

Add base module and migration generation for Ecto schema extensions

The Pow Ecto extension now provides a reusable base module (Pow.Extension.Ecto.Schema.Base) that allows extensions to define custom attributes, associations, indexes, and changesets for user schemas. Additionally, a new migration generator (Pow.Extension.Ecto.Schema.Migration) automatically creates database migrations that include these custom fields and associations, supporting :binary\_id types for foreign keys.

lib/pow/extension/ecto/schema · high confidence

Add base module for Phoenix controller callbacks in Pow extensions

A new base module, Pow.Extension.Phoenix.ControllerCallbacks.Base, has been introduced to standardize how Pow extensions implement Phoenix controller callbacks. This module provides a reusable structure with default implementations for before\_process and before\_respond hooks, allowing extensions to easily integrate with the new callback system.

_lib/pow/extension/phoenix/controllers/controller\callbacks · high confidence

Add controller callbacks for Pow extensions

A new module, Pow.Extension.Phoenix.ControllerCallbacks, has been added to automatically trigger before\_process and before\_respond hooks for all configured extensions. This allows extension modules to intercept and modify controller actions and responses within the Phoenix framework.

lib/pow/extension/phoenix/controllers · high confidence

Add invitation handling for user registration

Introduces a new PowInvitation extension that allows existing users to invite others to join the application. The change adds an \InvitationController\ to manage invitation flows, including creating and updating user accounts via signed tokens. It includes HTML templates for the invitation, edit, and show pages, as well as mailer components to send invitation emails containing the unique access link. This enables a workflow where invited users can register and set their credentials using the provided token.

lib/extensions/invitation/phoenix/controllers · high confidence

Add mix tasks to generate Phoenix templates and mailers for extensions

Users can now generate Phoenix view templates and mailer templates for Pow extensions using the new \mix pow.extension.phoenix.gen.templates\ and \mix pow.extension.phoenix.mailer.gen.templates\ mix tasks. These tasks accept an \--extension\ flag to specify which extensions to generate templates for, and a \--context-app\ flag to control path and module naming. The mailer task also automatically injects the \web\_mailer\_module\ configuration and updates the Phoenix web module to include the necessary mailer components.

lib/mix/tasks/extension/phoenix · high confidence

Add new mix tasks for Pow help and installation

The Pow library introduces two new Mix tasks: \mix pow\ to display help information about the library, and \mix pow.install\ to run installation tasks for Ecto and Phoenix. The install task validates that it is not run inside an umbrella project, providing specific instructions for each sub-task if that condition is met.

lib/mix/tasks · high confidence

Add persistent session extension for long-lived authentication

Introduces the PowPersistentSession extension, which allows users to maintain their authenticated state across browser sessions by setting a persistent cookie that expires after 30 days. To use this feature, developers must add \PowPersistentSession.Plug.Cookie\ to their endpoint configuration and optionally include a \persistent\_session\ checkbox in the login form to let users manage the setting.

_lib/extensions/persistent\session · high confidence

Introduces a new \PowPersistentSession.Plug.Cookie\ plug that enables persistent user sessions using signed tokens stored in cookies. The implementation uses a \before\_send\ callback to write to the backend store and client, ensuring proper ordering. It supports custom session metadata (including fingerprints) and allows configuration of the cookie key, TTL, and store backend. The token is signed to prevent timing attacks, and the plug handles creation, authentication, and deletion of persistent sessions.

_lib/extensions/persistent\session/plug · high confidence

Introduce Pow.Ecto.Context and Pow.Ecto.Schema modules for user authentication and schema handling

The Pow library now provides dedicated Ecto modules for handling user context and schema definitions. The new \Pow.Ecto.Context\ module manages authentication, creation, update, deletion, and retrieval of user records, including protection against timing attacks during password verification. The \Pow.Ecto.Schema\ module provides a macro to automatically generate Ecto schema fields, associations, and changeset functions for user models, with compile-time validation and customizable password hashing and length requirements.

lib/pow/ecto · high confidence

Introduce Pow.Ecto.Schema module for Ecto schema extensions

A new \Pow.Ecto.Schema\ module has been added to manage Ecto schema extensions. This module provides macros to register extension fields, associations, and indexes, and ensures that all extension modules are properly integrated into the user schema. It also adds a compilation-time validation to verify that all required fields are defined, improving the reliability of schema configurations.

lib/pow/extension/ecto · high confidence

Introduce PowInvitation Ecto extension for user invitations

Added the PowInvitation Ecto extension, providing new modules (Context and Schema) that enable inviting users, generating invitation tokens, and accepting invitations. The schema adds fields for invitation status and associations, while the context exposes methods for creating and updating invited users. The changeset functions are made overridable, allowing users to customize the invitation flow.

lib/extensions/invitation/ecto · high confidence

Introduce PowResetPassword extension for password reset functionality

Users can now reset their passwords via an email link. This new extension provides the core logic for generating and verifying reset tokens, securely storing them in a cache, and updating the user's password. It includes protections against user enumeration and timing attacks, and supports custom cache backends for token storage.

_lib/extensions/reset\password · high confidence

Introduce structured extension routing and messaging for Phoenix

The Pow Phoenix extension now provides dedicated modules for handling extension routes and messages. The new \Pow.Extension.Phoenix.Router\ module allows developers to declare extension routes via a \pow\_extension\_routes/0\ macro, which automatically wraps each extension's routes in a scoped namespace. Similarly, \Pow.Extension.Phoenix.Messages\ enables consistent message handling across extensions, allowing users to override messages by defining functions named after the extension. This change simplifies the integration of Pow extensions into Phoenix applications by providing a standardized way to manage routes and messages.

lib/pow/extension/phoenix · high confidence

Introduced Mix task for generating Phoenix mailer templates

A new module, Mix.Pow.Phoenix.Mailer, has been added to provide utilities for generating mailer templates in Phoenix applications. This change introduces the ability to create mail template files via a Mix task, allowing users to generate mailer modules with specified templates. The module includes functions to create mail modules and generate template functions for each mail, enhancing the developer experience when setting up email functionality.

lib/mix/pow/phoenix · high confidence

New Mix utilities for Phoenix web app scaffolding

Added new Mix task utilities in lib/mix/pow/extension.ex and lib/mix/pow/phoenix.ex to support Phoenix web application generation. The Extension module provides a centralized way to resolve and fetch extension configurations, while the Phoenix module handles parsing structure configurations and creating HTML templates for web modules. These utilities enable the mix tasks to properly handle context apps and web module generation for Phoenix applications.

lib/mix/pow · high confidence

New base store and credentials cache implementation

The \lib/pow/store\ directory now includes a new \Pow.Store.Base\ module that provides a standardized API for key-value stores, including a \\_\using\\_\ macro to simplify custom store implementations. A new \Pow.Store.CredentialsCache\ module has been added to handle session storage, supporting user and session listing, credential storage with metadata, and automatic invalidation of duplicate sessions based on fingerprints. The implementation includes a deprecation path for binary keys in backend stores and warns about excessive TTL values.

lib/pow/store · high confidence

New cache backends for session storage

The library now provides new cache store backends for session management. A new \Pow.Store.Backend.Base\ module defines the interface for key-value cache stores. Two implementations are added: \Pow.Store.Backend.EtsCache\, an in-memory ETS-based cache with optional async writes, and \Pow.Store.Backend.MnesiaCache\, a distributed Mnesia-based cache that supports multi-node clusters, automatic node discovery, and split-brain recovery. These modules implement the \Base\ behaviour, allowing users to switch between in-memory and distributed persistent caching strategies for the store backend.

lib/pow/store/backend · high confidence

New email confirmation controller and callbacks

The email confirmation feature now includes a dedicated Phoenix controller (ConfirmationController) and controller callbacks that manage the email verification flow. Users will receive flash messages for successful or failed confirmations, and the system prevents information leakage during registration by handling unique constraint errors gracefully. The controller handles token loading, redirects to appropriate paths based on user state, and sends confirmation emails with signed tokens.

_lib/extensions/email\confirmation/phoenix/controllers · medium confidence

New mix tasks to install and configure Pow in Phoenix apps

The library introduces two new Mix tasks, \pow.phoenix.install\ and \pow.phoenix.gen.templates\, to streamline setting up the Pow authentication library in Phoenix applications. The \install\ task automatically injects the necessary configuration into \config.exs\, adds the \Pow.Plug.Session\ plug to the endpoint, and inserts the Pow router scope into the router. It also supports generating templates and extension templates via the \--templates\ and \--extension\ flags, providing clear shell instructions for any manual steps required.

lib/mix/tasks/phoenix · high confidence

Removals

Removal of Authex.Config module

The Authex.Config module, which previously handled configuration retrieval and default value resolution for user assigns keys, has been removed from the codebase.

lib/authex · high confidence

Removed Authex.Authorization.Plug module

The Authex.Authorization.Plug module, which previously provided helper functions for handling the current user and configuration within Plug-based applications, has been removed from the codebase.

lib/authex/authorization · high confidence

Removed legacy authorization plugs and ETS-based store

The \Authex.Authorization.Plug.RequireAuthenticated\, \Authex.Authorization.Plug.RequireNotAuthenticated\, and \Authex.Authorization.Plug.Session\ plugs have been removed, along with the \Authex.Authorization.Store.CredentialsCache\ GenServer that managed credentials in an ETS table. This change eliminates the previous session-based authentication and in-memory caching mechanism, indicating a shift in how user sessions and credentials are managed within the application.

lib/authex/authorization/plug · high confidence

Behavioural changes

Add email confirmation messaging and routing for Phoenix

The extension now provides user-facing flash messages for email confirmation states, including success, failure, invalid token, and required confirmation for both sign-in and email updates. Additionally, a new router module registers the '/confirm-email' route to handle confirmation requests.

_lib/extensions/email\confirmation/phoenix · high confidence

Centralized test configuration for Pow extensions

Test environment configuration for Pow extensions (including Ecto, Mnesia, Email Confirmation, Invitation, Persistent Session, and Reset Password) has been moved from the main config file to a dedicated test.exs file, ensuring that test-specific settings like database connections and endpoint configurations are isolated from production or development environments.

config · high confidence

Deprecate Pow.Extension.Ecto.Context.Base

The base context module for the Ecto extension is now deprecated. Using \use Pow.Extension.Ecto.Context.Base\ will emit a warning directing users to use the functions in \Pow.Ecto.Context\ instead.

lib/pow/extension/ecto/context · high confidence

Introduce base controller for message handling in Phoenix extensions

A new base controller, \Pow.Extension.Phoenix.Controller.Base\, has been added to standardize how messages and routes are handled in Phoenix controllers. This change introduces a \extension\_messages/1\ function that allows extensions to define their own message modules, with a fallback mechanism to a default messages module. The implementation also includes a deprecation warning for the \:messages\_backend\_fallback\ config option, which will be removed in a future version.

lib/pow/extension/phoenix/controllers/controller · medium confidence

Introduce base module and configuration helpers for extension auto-discovery

A new \Pow.Extension.Base\ module is added to provide a standard interface for extensions to declare their capabilities (e.g., \ecto\_schema?\, \phoenix\_templates?\) and enable auto-discovery. The \Pow.Extension.Config\ module is introduced to manage extension configuration, including a new \extension\_modules/2\ function that filters and returns existing extension modules based on the base module's declarations. This refactors how extensions are discovered and validated, moving away from previous methods that relied on \Code.ensure\_compiled?/1\.

lib/pow/extension · medium confidence

Introduce new core modules for configuration, context, and operations

The library now includes new modules: \Pow.Application\ for managing the EtsCache supervisor, \Pow.Config\ for parsing and modifying configurations with environment fallbacks, \Pow.Context\ defining the user schema interface, \Pow.Operations\ to glue operation calls to the context module, and \Pow.UUID\ for generating UUID binaries. These changes restructure how configuration is handled, provide explicit methods for user operations (authenticate, create, update, delete), and ensure the module exists and is loaded before accessing primary keys.

lib/pow · high confidence

Modernize reset password UI with Phoenix 1.7+ components

The reset password pages have been updated to use Phoenix 1.7+ CoreComponents (e.g., \\<.simple\_form\>\, \\<.header\>\, \\<.link\>\) for the user interface. For older Phoenix versions, the legacy \render\_form\ approach is retained. This change improves the visual consistency of the password reset flow with modern Phoenix templates.

_lib/extensions/reset\password/phoenix/controllers · medium confidence

Persistent session cache now supports automatic user reloading

The persistent session cache has been refactored to include a \:reload\ configuration option that allows the cache to automatically fetch the latest user data from the database on each session lookup. This ensures that session data remains up-to-date without requiring the user to log in again. The implementation includes a backwards compatibility layer that warns if the new \:pow\_config\ argument is not provided, indicating a breaking change in the API for older configurations.

_lib/extensions/persistent\session/store · medium confidence

Rebuilt Phoenix controllers and templates for Phoenix 1.7 compatibility

The Pow library's Phoenix integration has been completely rebuilt to support Phoenix 1.7. This includes new controller implementations for session and registration flows, updated HTML templates using CoreComponents and Tailwind CSS, and a compatibility layer in \ViewHelpers\ that conditionally applies Phoenix 1.7 features (like \layouts\ in controllers) while maintaining support for older versions. Users on Phoenix 1.7 will see modernized, component-based templates, while older Phoenix versions continue to use the legacy template structure.

lib/pow/phoenix/controllers · high confidence

Refactor PowResetPassword Ecto context and schema

The reset password extension now uses a dedicated Ecto context and schema modules to decouple the changeset logic from the main context. The context module provides \get\_by\_email\ and \update\_password\ methods, while the schema module defines the \reset\_password\_changeset\ function, which validates the password and required fields. The old \password\_changeset\ in the context is deprecated in favor of the new schema-based approach.

_lib/extensions/reset\password/ecto · medium confidence

Refactor email templates into dedicated Phoenix components

The email templates for account confirmation and password reset have been restructured into dedicated Phoenix mailer components. This change updates how the application sends confirmation and reset password emails, ensuring that the HTML and plain-text versions are managed through the new mailer modules.

_lib/extensions/email\_confirmation/phoenix/mailers, lib/extensions/reset\password/phoenix/mailers · medium confidence

Refactored Ecto schema generation and validation logic

The Ecto schema generation and validation logic has been refactored into dedicated modules: \Pow.Ecto.Schema.Changeset\ handles all changeset validations (user ID, password, email, and current password) using compile-time configuration and Ecto's built-in validators. Password hashing is now handled by \Pow.Ecto.Schema.Password\ using PBKDF2-SHA512, replacing the previous \password\_hash\_methods\ configuration. The schema generation now uses \Pow.Ecto.Schema.Module\ and \Pow.Ecto.Schema.Fields\ to produce the user schema and migration files, with the user ID field being case-insensitive and unique. Password fields are redacted in logs and memory.

lib/pow/ecto/schema · high confidence

Refactored Pow.Phoenix routing and message handling

The library has been restructured to improve customization and maintainability. A new \Pow.Phoenix.Messages\ module provides a dedicated backend for all user-facing text, allowing developers to easily override default strings for authentication, registration, and account management. The \Pow.Phoenix.Router\ module now uses explicit macro definitions (\pow\_routes/0\, \pow\_session\_routes/0\, \pow\_registration\_routes/0\) to generate routes, which simplifies the process of overriding or filtering specific actions. Additionally, the \Pow.Phoenix.Routes\ module was introduced to centralize path and URL generation, supporting both standard and verified routes for Phoenix 1.7+ while maintaining backward compatibility with older versions.

lib/pow/phoenix · high confidence

Refactored email confirmation logic into dedicated Ecto context and schema modules

The email confirmation functionality has been restructured into new \PowEmailConfirmation.Ecto.Context\ and \PowEmailConfirmation.Ecto.Schema\ modules. This change introduces a dedicated context for handling email confirmation operations, such as \get\_by\_confirmation\_token\ and \confirm\_email\, and a schema module that manages the \email\_confirmation\_token\, \email\_confirmed\_at\, and \unconfirmed\_email\ fields. The schema's \changeset\ function now explicitly handles the logic for tracking unconfirmed email changes and generating confirmation tokens, while the context provides a cleaner API for confirming emails. This refactoring decouples the Ecto-specific implementation from the broader Pow extension system, making the email confirmation process more modular and maintainable.

_lib/extensions/email\confirmation/ecto · high confidence

Refactored mailer to use Phoenix components and templates

The mailer implementation has been refactored to use Phoenix components and templates, moving away from the previous \Phoenix.View\-based approach. This change introduces new modules (\Component\, \Mail\, and \Template\) that handle email rendering using modern Phoenix template syntax (\\~H\ and \\~P\ sigils) and support for custom email layouts. Users will now interact with a more flexible and modern templating system for generating HTML and text email content.

lib/pow/phoenix/mailer · high confidence

Refactored session handling and introduced extensible plug base

The \Pow.Plug\ module has been refactored to use a new \Pow.Plug.Base\ macro that standardizes session management via the \:before\_send\ callback. This change introduces \Pow.Plug.MessageVerifier\ for secure token signing and verification, and adds support for custom session metadata (e.g., IP, user-agent) stored in the credentials cache. The \:session\_store\ configuration option has been renamed to \:credentials\_cache\_store\ to better reflect its purpose, and session IDs are now signed to prevent timing attacks. Additionally, new plugs \Pow.Plug.RequireAuthenticated\ and \Pow.Plug.RequireNotAuthenticated\ provide standardized ways to enforce authentication states with custom error handlers.

lib/pow/plug · high confidence

Rename library from Authex to Pow

The library has been renamed from Authex to Pow. The Authex module and its config method have been removed, and a new Pow module has been added to handle dependency version matching, reflecting the library's rebranding.

lib · high confidence

Replaced external password hashing dependency with a custom PBKDF2 implementation

The password hashing logic for Ecto schemas has been refactored to use a custom \Pow.Ecto.Schema.Password.Pbkdf2\ module instead of the previous \Comeonin\ library. This change removes the external \Comeonin\ dependency and implements PBKDF2 hashing directly within the \pow\ library, utilizing \:crypto.mac\ and \:crypto.hmac\ from the Erlang \:crypto\ module. The implementation includes a constant-time comparison function to mitigate timing attacks and supports configurable iterations, salt, and digest algorithms. This is a behavioral change for users relying on the previous hashing mechanism, as the underlying cryptographic implementation and dependencies have changed.

lib/pow/ecto/schema/password · high confidence

Fixes

The \lib/ex\_doc\ directory now includes a custom markdown parser (\ExDoc.Pow.Markdown\) that intercepts markdown processing to correctly resolve relative links. This ensures that internal documentation links and source code links to GitHub work as expected in the generated HTML output.

_lib/ex\doc · medium confidence

Test coverage

Add Ecto test support infrastructure; Add centralized test helper for Mix task testing; Add tests for mix Pow and Pow.Install tasks; Added Ecto and Phoenix test infrastructure; Added Ecto migration test fixtures; Added Ecto-specific tests for the password reset extension; Added Phoenix test support files; Added comprehensive Ecto tests for email confirmation; Added comprehensive test coverage for Phoenix controllers; Added comprehensive test coverage for Phoenix reset password controller; Added comprehensive test coverage for Pow.Ecto Context and Schema modules; Added comprehensive tests for Pow Phoenix install and template generation tasks; Added comprehensive tests for Pow.Store.Base and Pow.Store.CredentialsCache; Added test coverage for PersistentSessionCache; Added test fixtures for Ecto user schemas; Added test infrastructure for the PersistentSession extension; Added test mocks for PowInvitation; Added test mocks for the PowResetPassword extension; Added test support for email confirmation extension; Added test support infrastructure for extensions; Added tests for Ecto schema migration generation; Added tests for Ecto-related Mix tasks; Added tests for EtsCache and MnesiaCache backends; Added tests for PBKDF2 password hashing; Added tests for Phoenix controller callbacks in the persistent session extension; Added tests for Phoenix extension messages and router; Added tests for Phoenix extension template generation; Added tests for Pow.Ecto.Schema components; Added tests for PowInvitation Ecto context and schema; Added tests for email confirmation flow in Phoenix controllers; Added tests for mail template rendering and layout configuration; Added tests for the Ecto schema extension; Added tests for the Pow Ecto extension mix tasks; Added tests for the PowPersistentSession plug cookie handling; Added tests for the invitation controller; Added tests for the reset password plug; Added unit tests for Pow configuration, operations, and plug modules; Added unit tests for Pow.Phoenix mailer, messages, router, and routes; Expanded test coverage for Pow.Plug session and authentication plugs; Refactored test support modules for session and context mocking; Removed Authex configuration tests; Removed obsolete authorization plug tests; Removed obsolete test files for session and credentials cache.

Dependencies

Updated dependencies and raised minimum Elixir version

The project has been updated to require Elixir 1.14 or higher and upgraded to support Phoenix 1.7 and Phoenix Live View 1.0. The dependency list now includes explicit support for Ecto 3.12, Plug 1.16, and Elixir 1.14, while removing older constraints on packages like Comeonin and Coherence. This ensures compatibility with the latest versions of the Phoenix and Ecto ecosystems.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 61 (+3.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 87 (-10.9)
  • Architecture 100 → 91 (-8.9)
  • Maturity 54 → 50 (-3.8)
  • Readiness 50 → 62 (+12.1)
  • Security 54 → 73 (+18.9)

Resolved (15)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included

New (87)

  • Duplicated block (12 lines × 2) (lib/mix/tasks/extension/phoenix/pow.extension.phoenix.mailer.gen.templates.ex)
  • Duplicated block (6 lines × 2) (lib/pow/store/backend/ets_cache.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No dependency advisory monitoring
  • Outdated: credo
  • Outdated: ecto
  • Outdated: ecto_sql
  • …and 67 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

pow-auth/pow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fe092233f7c85589e90761a761fb290dcc8cf706 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.