Skip to content
CAI
Software that uses CAICheck a score

refinery/refinerycms

55.6

Adequate · 28 September 2026

6.4k

lines of production code

Ruby

with JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Refinery CMS, a modular Ruby on Rails content management system structured as a mountable engine. It provides core functionality for managing pages, images, and resources, featuring a modernized admin interface with AJAX interactions and a visual editor. The platform supports multi-language content through the Mobility gem and offers extensibility via a generator system for creating custom plugins and engines.

How it got here

2009 — Rails 3 migration and plugin cleanup

61 changes.

The project underwent a major migration from Rails 2 to Rails 3, removing the vendored framework and legacy configuration files in favor of system gems. This period involved stripping out deprecated vendor plugins, replacing Prototype with jQuery, and decoupling internal features like news and authentication into external dependencies.

2010–2011 — Mountable engine architecture and i18n migration

84 changes.

Refinery CMS was restructured into a modular, mountable engine architecture, centralizing core logic and establishing dedicated entry points for individual components like pages, images, and resources. The project simultaneously migrated its internationalization backend from Globalize to Mobility, updating database schemas and models to support translated content across all engines. This period also involved modernizing the admin interface, upgrading to Ruby 3.1+, and expanding the test suite with comprehensive specs and generator utilities.

2012–2017 — Testing infrastructure and generator modernization

54 changes.

This period focused on establishing a robust testing foundation by centralizing RSpec configurations, introducing a dedicated testing generator, and expanding test coverage across core, pages, and image modules. Simultaneously, the engine generator templates were modernized to support namespacing, Zeitwerk autoloading, and the Mobility gem for localization, while replacing legacy components like Globalize and FactoryGirl.

2018–2026 — Zeitwerk migration and test expansion

6 changes.

The project modernized its core architecture by adopting the Zeitwerk autoloader to replace manual require strategies, ensuring consistent class loading across components. Concurrently, extensive system tests were added to cover admin interfaces for images, resources, and pages, while new presenter classes and helpers were introduced to enhance the display and management of assets in the admin UI.

Features

Add TranslatedFieldPresenter for fallback field resolution

A new TranslatedFieldPresenter class has been introduced in the core app presenters to handle field value resolution with fallback logic. When a specific field is requested on a record, it first attempts to retrieve the value directly; if that value is empty or nil, it automatically searches through associated translations to find the first available value for that field. This simplifies how localized content is accessed by centralizing the fallback mechanism.

core/app/presenters · high confidence

Add resource management routes for Dragonfly integration

The application now exposes specific routing rules for managing resources via the Dragonfly middleware. Users can access resource files through the '/system/resources' path, and the admin interface includes new collection actions for resources, such as an 'insert' endpoint, facilitating media and file management within the backend.

resources/config · high confidence

Add resources library entry point

The resources engine now includes a dedicated library file (refinerycms-resources.rb) that serves as the primary entry point, requiring the core Refinery::Resources module to initialize the engine.

resources/lib · high confidence

Added Rake task template for extensions

A new Rake task template file has been added to the engine generator templates, providing a scaffold for defining namespaced tasks within extensions. This template allows developers to easily create custom rake tasks for their extensions by following the provided structure.

core/lib/generators/refinery/engine/templates/lib/tasks · high confidence

Added Rake tasks for isolated extension testing

The generator now includes support files for creating and testing isolated extensions using a dummy application. Specifically, it adds an \rspec.rake\ task to run specs and a \refinery:testing:setup\_extension\ task to handle setup logic, enabling developers to test their extensions in an isolated environment.

core/lib/generators/refinery/engine/templates/tasks · high confidence

Added Refinery::PagePresenter to expose menu title type

A new presenter class, Refinery::PagePresenter, has been introduced to wrap the Page model. This class exposes the menu\_title\_type attribute, allowing the presentation layer to access this specific property without directly interacting with the underlying model.

pages/app/presenters/refinery · high confidence

Added image cropping and browser compatibility vendor libraries

The application now includes vendor JavaScript and CSS libraries to support image cropping and improve browser compatibility. Specifically, Cropper.js v1.4.0 is added to enable image cropping functionality, accompanied by its required styles. A polyfill for the Canvas \toBlob\ method is included to ensure older browsers and Edge can handle canvas-to-blob conversions. Additionally, jQuery plugins for browser detection (\jquery.browser\), HTML5 placeholder shimming, text truncation, and timer abstractions are added to the vendor assets to support legacy browser features and UI utilities.

core/vendor · high confidence

Added placeholder for PID file storage

A new \tmp/pids\ directory has been created with a \.gitkeep\ file to ensure the folder is tracked in version control. This allows the application to store process ID files in a consistent, version-controlled location.

tmp · high confidence

Added script/rails helper for running Rails commands in extensions

A new executable script at core/lib/generators/refinery/engine/templates/script/rails has been added to allow Rails commands to function correctly within Refinery CMS extensions. This script attempts to load the rails command from the dummy application's script directory if it exists; otherwise, it instructs the user to run 'rake refinery:testing:dummy\_app' to generate the necessary dummy application structure.

core/lib/generators/refinery/engine/templates/script · high confidence

Introduce RefineryCMS Dragonfly extension for image management

This change introduces the \dragonfly\ extension as a standalone component within RefineryCMS, separating it from the core Images and Resources modules. It provides a new Rails engine (\Refinery::Dragonfly::Engine\) that registers the plugin, sets up the necessary middleware stack, and exposes a generator (\refinery:dragonfly\) to scaffold the initializer configuration. The extension supports configurable datastores, including a new capability to use Amazon S3 for storage by reading credentials from the application's encrypted credentials file, while maintaining the default local filesystem storage.

dragonfly · high confidence

Introduce main library entry point for the Images engine

The images engine now includes a primary library file (refinerycms-images.rb) that serves as the single entry point for loading the component. This file requires the core 'refinery/images' module, establishing the standard initialization path for the engine within the application.

images/lib · high confidence

New Rake tasks for whitespace cleanup, spec execution, and gem packaging

The project introduces three new Rake task files to streamline development and release workflows. The \whitespace\ task automatically removes trailing whitespace and converts tabs to spaces in Ruby files, handling platform-specific \sed\ syntax for Linux and macOS. The \spec\ task provides a standardized way to run RSpec tests across all extensions using a consistent file pattern. Additionally, the \build\ task (and its sub-tasks for individual extensions) automates the creation of gem packages, ensuring the output directory exists and building gems for all defined extensions (core, images, pages, resources, testing) as well as the main refinerycms application.

tasks · high confidence

New admin presenter classes and resource helper for image listing

This change introduces new presenter classes (\GroupPresenter\, \GridPresenter\, \ListPresenter\) and a \ResourceHelper\ within the Refinery CMS admin interface. The presenters provide structured ways to display grouped records (such as images) in grid or list formats, handling grouping logic, headers, and HTML tag generation. The \ResourceHelper\ adds a method to display file size metadata for resources. These components support the admin UI's ability to organize and present image assets with specific formatting and metadata.

images/app/presenters, resources/app/helpers · high confidence

New image management routes for Refinery CMS

The images engine now defines its own routing configuration, exposing a public endpoint for serving images via Dragonfly and an admin namespace for managing image resources. Users can now access image-specific actions such as inserting images and cropping them through the Refinery admin interface, with the crop functionality supporting both PATCH and DELETE HTTP verbs.

images/config · high confidence

New installation templates for Refinery CMS 4.0

The installer now provides three distinct Rails application templates to streamline setup: a stable 'installer' template targeting Refinery CMS 4.0 with released gems (including acts-as-indexed, wymeditor, and authentication-devise); an 'edge' template for the latest development versions via git; and a 'demo' template that pre-configures common extensions like blog, news, and portfolio. All templates automatically verify the presence of an ExecJS runtime (installing therubyracer if needed) and handle database creation, migration, and seeding in a single workflow.

templates · high confidence

New resources initializer template with Dragonfly and S3 configuration options

The generator now creates a dedicated initializer template at config/initializers/refinery/resources.rb.erb. This template exposes configuration options for the resource manager, including Dragonfly settings (such as URL verification, secrets, and host configuration) and S3 storage backend settings (including bucket names, credentials, and region). It also includes commented-out options for custom datastores and MIME type whitelisting, allowing users to easily customize how resources are stored and validated.

resources/lib/generators/refinery/resources/templates · high confidence

Refinery CMS generator now supports Heroku deployment with Puma and configurable stacks

The CMS generator now includes a \--heroku\ option that automates deployment to Heroku. When this flag is used, the generator installs the Puma web server, configures a Procfile, adds necessary production gems (including \pg\ for PostgreSQL or \sqlite3\ for development/test), and sets the default Heroku stack to \cedar-14\. It also handles database migrations and seeding on the remote host. Users can specify a custom Heroku app name and stack version via the \--heroku\ and \--stack\ options respectively.

core/lib/generators/refinery/cms · high confidence

Refinery engine generator adds --skip-frontend option

The \refinery:engine\ generator now supports a \--skip-frontend\ flag, allowing users to generate an extension that includes only backend components (admin, models, mailers) while omitting frontend views and assets. This is useful for creating backend-only plugins or APIs without the overhead of a public-facing interface.

core/lib/generators/refinery/engine · high confidence

Repository initialization with core configuration and documentation files

The repository has been initialized with essential configuration and documentation files to support development and deployment. A comprehensive .gitignore file is added to exclude build artifacts, logs, and IDE-specific files. Project configuration is established via .rspec for test execution, .yardopts for documentation generation, and a .pullreview.yml for code review rules. A SECURITY.md file is introduced to define the vulnerability reporting process. Documentation is standardized with a new markdown README.md (replacing the old README), a detailed changelog.md, a contributing.md guide, and a license.md file. Additionally, a config.ru file is provided to allow the application to run as a Rack app, and the Rakefile is updated to manage gem tasks for the core and its sub-gems.

(repo-wide) · high confidence

Removals

Admin page editing and listing views removed

The admin interface views for managing pages have been deleted, including the form for editing pages, the list and sortable list partials for displaying page trees, and the index and new page templates. This removes the previous UI for creating, editing, reordering, and listing pages within the Refinery admin panel.

vendor/plugins/pages/app/views/admin/pages · high confidence

Inquiries plugin views removed

The view templates for the inquiries plugin (new.html.erb and thank\_you.html.erb) have been deleted from the codebase. This removes the default HTML structure for the inquiry submission form and the subsequent thank-you page, indicating that the plugin's frontend presentation is no longer served by these specific view files.

vendor/plugins/inquiries/app/views/inquiries, vendor/plugins/news/app/views/admin, vendor/plugins/resources · high confidence

Removal of InquiriesController

The InquiriesController, which previously handled the creation of new inquiries, displayed the thank-you page, and managed email notifications for both administrators and users, has been removed from the application. This change eliminates the legacy inquiry submission workflow and associated mailer integration defined in this controller.

vendor/plugins/inquiries/app/controllers · high confidence

Removal of InquiriesHelper module

The InquiriesHelper module, which previously provided the open\_close\_link helper method for toggling inquiry status in the view layer, has been removed from the codebase.

vendor/plugins/inquiries/app/helpers · high confidence

Removal of News plugin view templates

The view templates for the news items feature have been deleted from the application. Specifically, the partial for displaying recent posts (\_recent\_posts.html.erb), the main listing page (index.html.erb), and the individual news item display page (show.html.erb) are no longer present. This change removes the frontend rendering logic for news items, likely as part of decoupling the news functionality into an external plugin or removing the feature entirely from this codebase.

_vendor/plugins/news/app/views/news\items · high confidence

Removal of Page and PagePart models

The \Page\ and \PagePart\ model files have been deleted from the \vendor/plugins/pages/app/models\ directory. This removes the core data structures for managing pages and their associated content parts within this plugin location.

vendor/plugins/pages/app/models · high confidence

Removal of WYMeditor hovertools, resizable, and tidy plugins

The WYMeditor hovertools, resizable, and tidy plugins have been removed from the application. This eliminates the hover-based status updates, the ability to resize the editor area via jQuery UI, and the client-side HTML cleanup functionality provided by the tidy plugin, simplifying the editor's feature set.

public/wymeditor/plugins/hovertools, public/wymeditor/plugins/resizable, public/wymeditor/plugins/tidy · high confidence

Removal of WYMeditor source files and licenses

The WYMeditor library files, including the main JavaScript implementation (jquery.refinery.wymeditor.js), license texts (GPL and MIT), and documentation (README), have been removed from the public/wymeditor directory. This indicates that the WYMeditor editor is no longer bundled with the application in this location, likely because it has been replaced by a different editor or moved to a different package management system.

public/wymeditor · high confidence

Removal of admin news items controller

The Admin::NewsItemsController has been deleted from the codebase. This change removes the administrative interface for managing news items, effectively stripping the news plugin of its ability to create, edit, or delete news content through the admin panel.

vendor/plugins/news/app/controllers/admin · high confidence

Removal of attachment\_fu plugin

The attachment\_fu plugin has been completely removed from the codebase. This deletion eliminates the legacy file attachment and image processing capabilities, including support for file system, database, Amazon S3, and Rackspace Cloud Files storage backends, as well as image resizing processors like RMagick, ImageScience, and MiniMagick.

_vendor/plugins/attachment\fu · high confidence

Removal of database setup rake task

The \db:setup\ rake task, which previously loaded initial data from \db/seeds.rb\, has been removed from the application. Users can no longer use this specific command to initialize the database with seed data.

lib/tasks · high confidence

Removal of internal News plugin controller

The \NewsItemsController\ has been removed from the codebase, effectively deleting the internal implementation of the news plugin. This change aligns with the decision to decouple the news functionality, allowing it to be maintained and distributed as an external plugin rather than being bundled within the core application.

vendor/plugins/news/app/controllers · high confidence

Removal of legacy Image model and attachment logic

The \Image\ model file has been deleted from the codebase. This removes the legacy implementation that relied on \attachment\_fu\ for file system storage, RMagick processing, and direct associations with \Page\ records. Users will no longer have access to this specific model class or its associated validation and thumbnail generation logic defined in this file.

vendor/plugins/images/app/models · high confidence

Removal of legacy PagesController

The legacy PagesController, which previously handled home page lookups and page rendering via direct model queries, has been removed from the application. This change eliminates the old implementation in favor of the current pages handling logic, ensuring that users are no longer served through this deprecated controller path.

vendor/plugins/pages/app/controllers · high confidence

Removal of legacy Refinery Dialogs plugin

The \refinery\_dialogs\ plugin has been completely removed from the codebase. This deletes the \Admin::DialogsController\, its associated views and layout, the plugin's route definitions, and its initialization file. This change eliminates the legacy dialog infrastructure that previously relied on Prototype, Scriptaculous, and Thickbox, aligning with the broader migration to jQuery UI and the removal of older plugin architectures.

(repo-wide) · high confidence

Removal of legacy Refinery plugin core files

The legacy Refinery plugin core files have been removed from the vendor directory. This includes the base admin controller, application controller, helpers, and associated views (layouts, menus, and shared partials). The removal eliminates the old Prototype/Scriptaculous-based admin interface and the legacy generator templates, effectively stripping out the deprecated plugin architecture and its associated UI components.

vendor/plugins/refinery · high confidence

Removal of legacy Restful Authentication models

The authentication plugin has removed the \User\, \UserMailer\, and \UserObserver\ model files that were part of the previous Restful Authentication implementation. This cleanup eliminates the state machine logic, manual password encryption, and automatic email notifications for account activation and signup, reflecting the migration to the Authlogic library.

vendor/plugins/authentication/app/models · high confidence

Removal of legacy admin controllers for page dialogs, parts, and listing

The legacy admin controllers for managing page dialogs (URL/email validation), page parts, and the main page listing have been removed from the application. This change eliminates the server-side validation logic for links and emails, as well as the specific controllers handling page part creation and the paginated root page index, indicating a shift in how these administrative interactions are handled (likely moving to client-side validation or different controller structures).

vendor/plugins/pages/app/controllers/admin · high confidence

Removal of legacy admin inquiry controllers

The \Admin::InquiriesController\ and \Admin::InquirySettingsController\ files have been deleted from the inquiries plugin. This removes the legacy admin interface components that previously handled inquiry status toggling (open/closed) and inquiry settings management via the \crudify\ helper, indicating these functionalities have been migrated or removed in favor of a different implementation.

vendor/plugins/inquiries/app/controllers/admin · high confidence

Removal of legacy authentication controllers

The \SessionsController\ and \UsersController\ files in the authentication plugin have been deleted. This removes the legacy RESTful authentication logic for handling user sign-in, sign-up, activation, suspension, and deletion, which is no longer part of the application's codebase.

vendor/plugins/authentication/app/controllers · high confidence

Removal of legacy dashboard controller

The legacy Admin::DashboardController has been removed from the codebase. This change eliminates the previous implementation that aggregated recent activity from all registered plugins using a global variable and manual sorting, effectively stripping out the old dashboard logic in favor of the new plugin architecture.

vendor/plugins/dashboard/app/controllers · high confidence

Removal of legacy frontend stylesheets

The public stylesheets directory has been cleaned up by deleting several legacy CSS files: formatting.css.example, home.css.example, lightbox.css, overlabel.css, thickbox.css, and tooltips.css. This removes the styling support for the deprecated lightbox image viewer, the thickbox dialog framework, and various older UI components, indicating a shift away from these specific frontend features in the application's public assets.

public/stylesheets · high confidence

Removal of legacy image dialog and admin controllers

The \Admin::ImageDialogsController\ and \Admin::ImagesController\ files have been deleted from the images plugin. This removes the legacy server-side logic that handled image insertion via dialogs and the basic admin CRUD interface, indicating a shift in how image management and insertion are implemented within the Refinery core.

vendor/plugins/images/app/controllers · high confidence

The admin page-dialogs views for creating links (\link\_to.html.erb\) and the associated page tree partial (\\_link\_list\_tree.html.erb\) have been removed. This eliminates the previous interface that allowed users to link to internal pages, web addresses, or email addresses using the Prototype/Scriptaculous JavaScript library and WYMeditor integration.

_vendor/plugins/pages/app/views/admin/page\dialogs · high confidence

Removal of legacy script/\* helper scripts

The legacy executable scripts located in the script/ directory (such as script/console, script/server, script/generate, and script/runner) have been removed. These files, which previously served as entry points for common development and maintenance tasks by requiring corresponding command modules, are no longer present in the codebase.

script · high confidence

Removal of the NewsItem model from the news plugin

The NewsItem model class has been deleted from the news plugin, removing the model's validation rules, friendly ID slug generation, and custom content accessor methods. This change aligns with the effort to decouple the news plugin so it can function as an external dependency rather than a bundled component.

vendor/plugins/news/app/models · high confidence

Removal of the images:regenerate rake task

The \images:regenerate\ rake task, previously used to delete and recreate all image thumbnails after size or cropping changes, has been removed from the codebase. Users can no longer rely on this specific command to bulk-regenerate thumbnails via the command line.

vendor/plugins/images/lib · high confidence

Removal of vendored acts\_as\_state\_machine and friendly\_id plugins

The \acts\_as\_state\_machine\ and \friendly\_id\ plugins have been removed from the \vendor/plugins\ directory. This deletion eliminates the local implementations for finite state machine behavior on ActiveRecord models and human-friendly URL slugging, respectively, along with their associated tests, generators, and documentation. Users relying on these plugins for state management or pretty URLs will need to migrate to alternative solutions, such as installing them as gems or using different libraries.

_vendor/plugins/friendly\id · high confidence

Removal of vendored will\_paginate plugin

The vendored will\_paginate pagination library (version 2.3.8) has been removed from the application. This eliminates the local copy of the plugin, including its source code, documentation, and example styles, which will no longer be shipped with the application.

_vendor/plugins/will\paginate · high confidence

Security

Removal of Dashboard Helper with Unsafe Code Execution

The \Admin::DashboardHelper\ module has been removed from the dashboard plugin. This helper previously generated activity messages for records by dynamically executing code via \eval\ to retrieve titles, URLs, and image paths. Its removal eliminates the potential for XSS vulnerabilities and runtime errors associated with dynamic code evaluation in the dashboard's recent activity list.

vendor/plugins/dashboard/app/helpers · high confidence

Architecture

Pages engine entry point established

The pages engine now includes a dedicated library file (refinerycms-pages.rb) that serves as the primary entry point, requiring the core pages module. This change consolidates the initialization logic for the pages component, ensuring it is loaded correctly within the Refinery CMS application structure.

pages/lib · high confidence

Refinery CMS core library restructured with new entry point

The core library has been reorganized to improve modularity and maintainability. A new \refinery.rb\ file serves as the central entry point, explicitly requiring essential dependencies like \rails\, \active\_record\, \action\_controller\, \font-awesome-sass\, and \jquery-rails\. It defines the \Refinery\ module with autoload paths for key components such as \Engine\, \Menu\, \Plugin\, and various generators. The file also introduces methods for managing extensions (engines), handling deprecation warnings, and determining root paths for the CMS and its extensions. A separate \refinerycms-core.rb\ file now simply requires \refinery/core\, streamlining the loading process.

core/lib · high confidence

Behavioural changes

Add Bundler binstubs for rake and rspec

The project now includes binstubs for rake and rspec in the bin directory. These scripts ensure that rake and rspec commands are executed using the specific gem versions defined in the project's Gemfile, providing consistent and isolated execution environments for development and testing tasks.

bin · high confidence

Admin 404 error handling now returns false to halt execution

The admin interface's 404 error handling method has been updated to explicitly return false when a custom 404 page is found and rendered. This change allows the method to be used effectively in before\_filters, automatically halting further controller execution without requiring an explicit return statement in the calling code.

pages/lib/refinery/pages/admin · high confidence

Admin JavaScripts moved to assets pipeline with configurable visual editor options

The admin JavaScript files have been relocated from the public directory to the core assets folder to better support the asset pipeline. This change introduces a new mechanism for customizing the visual editor's boot process: developers can now define a \custom\_visual\_editor\_boot\_options\ object to override specific configuration keys (such as the skin) before the editor initializes, providing a cleaner way to adjust editor behavior without modifying core files.

core/app/assets/javascripts · high confidence

Admin authentication and authorization logic moved to a shared module

The core admin security logic (SSL enforcement, user authentication, and controller access restrictions) has been extracted from individual controllers into a new \Refinery::Admin::BaseController\ module. This change centralizes the \before\_action\ hooks for \force\_ssl!\, \authenticate\_refinery\_user!\, and \restrict\_controller\, ensuring consistent security behavior across all admin interfaces while simplifying the inheritance chain for admin controllers.

core/lib/refinery/admin · high confidence

Admin images controller rewritten for Rails 8.1 and modern parameter handling

The admin images controller has been completely rewritten to support Rails 8.1 and Ruby 3.x. This update introduces strong parameters for image uploads, replacing the previous protected\_attributes approach, and implements AJAX-based image uploading with proper dialog redirection. The controller now supports multiple image uploads, image cropping functionality, and improved error handling for flash messages in modal windows. Additionally, it includes better support for image titles, alt attributes, and view mode preferences.

images/app/controllers · high confidence

Admin page management helper enhancements

The admin interface for managing pages now includes improved helper logic for the page tree and metadata display. Parent page selection in nested sets is optimized to avoid N+1 queries by manually preloading translations, ensuring faster rendering of page hierarchies. The page list now displays visual labels indicating specific page states, such as whether a page is hidden, a redirect, a draft, or set to skip to its first child. Additionally, the helper standardizes template option handling and provides icon-based indicators for pages with or without children, improving the clarity and usability of the page administration view.

pages/app/helpers/refinery/admin · high confidence

Adopt Zeitwerk autoloader for core components

Refinery CMS now complies with the Zeitwerk autoloader by introducing new entry-point files in the core, images, pages, and resources libraries. These files serve as the specific loading hooks that enable the modern autoloading mechanism, replacing previous manual require strategies and ensuring consistent, predictable class loading across the application.

(repo-wide) · high confidence

Centralized configuration and validation for the Images engine

The Images engine now exposes a dedicated configuration module (Refinery::Images) that allows users to customize image handling settings such as maximum file size, pagination limits, user-defined image sizes and ratios, allowed MIME types, and preferred view modes. It also registers specific validators (ImageSizeValidator and ImageUpdateValidator) to enforce these constraints during image uploads and updates, providing finer control over image management within Refinery CMS.

images/lib/refinery/images · high confidence

Configurable page generation initializer template

The generator for the Refinery Pages initializer now includes a comprehensive set of commented configuration options, allowing users to customize page behavior out of the box. New configurable features include reserved paths to prevent route conflicts, the ability to hide the page title in the body, and options to disable slug scoping by parent. The template also exposes settings for HTML sanitization whitelists (elements and attributes), custom layout and view template patterns, and the ability to set a custom path for the home page.

pages/lib/generators/refinery/pages/templates · high confidence

Consolidate application stylesheets into a single entry point

The application's stylesheet structure has been reorganized to consolidate imports into a new \application.scss\ file. This file now explicitly imports \refinery/formatting.scss\ and \refinery/theme.scss\, centralizing the styling logic. Additionally, the \public/favicon.ico\ file has been moved to \core/app/assets/stylesheets/.gitkeep\ to maintain the directory structure within the assets folder.

core/app/assets/stylesheets · high confidence

Database seeding now creates pages and sets localized slugs

The database seeding process has been updated to explicitly create core pages (Home, Page not found, and About) with their content parts if they do not already exist, rather than relying on previous implicit creation methods. Additionally, the seed script now iterates through configured frontend locales to update the URL slugs for these pages (e.g., setting 'home', 'page-not-found', 'about') and ensures the internationalization locale is reset to the default after execution.

pages/db · high confidence

Decouple visual editor assets from the admin helper

The admin visual editor helper no longer hardcodes JavaScript and stylesheet paths. Instead, it delegates to Refinery::Core to retrieve the required visual editor assets, allowing the underlying editor implementation (such as WYMeditor) to be replaced or updated without modifying the admin helper logic.

core/app/helpers/refinery/admin · high confidence

Dedicated controller for page preview functionality

Page previewing is now handled by a new \Refinery::Pages::Admin::PreviewController\ instead of the main pages controller. This change allows the preview mode to correctly render pages using inherited templates and custom view templates by explicitly permitting the \view\_template\ and \layout\_template\ attributes. Users will experience more reliable previews for pages that rely on specific template inheritance or custom layouts.

pages/app/controllers/refinery/pages · high confidence

Enforces image size limits and prevents filename changes during updates

The Images engine now includes two new validators to enforce stricter rules on image handling. The \ImageSizeValidator\ checks uploaded images against a configurable maximum size limit and rejects files that exceed it. Additionally, the \ImageUpdateValidator\ prevents users from changing the filename of an image when updating an existing record, ensuring the uploaded file name matches the one being replaced.

images/lib/refinery/images/validators · high confidence

Executable relocated to exe/ directory

The refinerycms command-line executable has been moved into the exe/ directory. This change reorganizes the project structure to align with standard conventions for executable scripts, ensuring the entry point is located in the expected path without altering the tool's functionality or command-line interface.

exe · low confidence

Extracted page rendering logic into a dedicated helper

The logic for rendering Refinery CMS pages has been moved from the \_content\_page template into a new ContentPagesHelper. This helper now provides methods to render page content via a presenter pattern and to compile the default menu, centralizing these behaviors for easier maintenance and testing.

pages/app/helpers/refinery/pages · high confidence

File size validation now uses configurable max\_file\_size in bytes

The Resources engine now validates uploaded file sizes against a new configurable limit, max\_file\_size, which is defined in bytes rather than megabytes. This change replaces the previous max\_client\_body\_size configuration and ensures that file uploads exceeding the specified byte limit are rejected with a clear error message, improving consistency across the codebase's configuration access patterns.

resources/lib/refinery/resources/validators · high confidence

Fix sitemap generation for multi-locale sites

The sitemap index view has been updated to correctly handle sites with multiple frontend locales. It now iterates through configured locales, setting the I18n context for each, and generates distinct URL entries for pages in their respective languages. The logic also ensures that external URLs are excluded and that relative URLs are correctly prefixed with the appropriate locale path, preventing duplicate locale segments in the generated sitemap URLs.

core/app/views/refinery/sitemap · high confidence

Generated engine controllers now use strong parameters and include public-facing templates

The generator templates for Refinery engine controllers have been updated to improve security and completeness. Admin controllers now explicitly define a strong parameters method (e.g., \resource\_params\) that permits only specific column names, replacing the previous approach of passing all parameters. Additionally, new public-facing controller templates have been added for engine resources, providing standard \index\ and \show\ actions that handle page presentation and resource lookup.

core/lib/generators/refinery/engine/templates/app/controllers · high confidence

Generated engine views now use content\_for blocks for proper layout integration

The index and show view templates generated for Refinery CMS engines have been updated to wrap their main content in \content\_for :body\ and \content\_for :side\_body\ blocks. This change ensures that generated engine pages correctly integrate with the Refinery CMS layout system, allowing for proper rendering of sidebars and page titles within the admin interface.

_core/lib/generators/refinery/engine/templates/app/views/refinery/namespace/plural\name · high confidence

Generators now automatically pull in migrations and seed data

When running Refinery CMS extension generators, the system now automatically invokes the migration installation rake task and appends the engine's seed loading logic to db/seeds.rb, ensuring that database schema and initial data are integrated without manual intervention.

core/lib/generators/refinery/engine/templates/lib/generators · high confidence

Images engine now supports translated image\_title and image\_alt fields

The Images engine now allows image titles and alt text to be translated into multiple languages. This capability is enabled by switching the underlying internationalization library from Globalize to Mobility, which is loaded via ActiveSupport hooks when ActiveRecord is initialized.

images/lib/refinery · high confidence

Migration from Prototype/Script.aculo.us to jQuery

The application's client-side JavaScript library has been switched from Prototype and Script.aculo.us to jQuery. This change removes the previous libraries (including \admin.js\, \boot\_wym.js\, \builder.js\, \controls.js\, \dialog.js\, \dragdrop.js\, \effects.js\, and \fastinit.js\) and replaces them with jQuery, which updates the underlying framework used for DOM manipulation, event handling, and UI interactions.

public/javascripts · high confidence

Model templates now use Mobility for localized attributes

The generated model templates for Refinery engines have been updated to use the Mobility gem for handling localized attributes, replacing the previous Globalize implementation. The template now includes \extend Mobility\ and \translates\ directives for any localized fields, while also adding a comment explaining how to enable admin searching via \acts\_as\_indexed\.

core/lib/generators/refinery/engine/templates/app/models · high confidence

New image helper for generating thumbnail URLs and view options

A new \Refinery::Admin::ImagesHelper\ module has been introduced to centralize image-related view logic. It provides the \thumbnail\_urls\ method, which generates a structured hash of image URLs for various sizes (original, grid, and user-defined sizes) using the \image\_path\ helper, and the \other\_image\_views\ method, which returns a list of available image views excluding the currently preferred one. This change also includes a placeholder \locale\_text\_icon\ method.

images/app/helpers · high confidence

Placeholder for visual editor dialog view

The admin dialog view at core/app/views/refinery/admin/dialogs/show.html.erb has been replaced with a placeholder instructing users that the visual editor should override this file, reflecting the migration of WYMeditor-specific functionality to the refinerycms-wymeditor engine.

core/app/views/refinery/admin/dialogs · medium confidence

Rails framework removed from vendor directory

The entire \vendor/rails\ directory, including Action Mailer and other Rails components, has been deleted. The application no longer bundles the Rails framework directly in the repository; instead, it relies on the Rails gem installed via the system package manager, allowing for easier version management and faster repository cloning.

(repo-wide) · high confidence

Refactor admin pages controller to use strong parameters and Mobility

The admin pages controller now uses strong parameters for page and page part attributes, replacing the previous protected\_attributes approach. It also integrates Mobility for locale handling, ensuring proper locale switching during page management and dialog interactions.

pages/app/controllers/refinery/admin · high confidence

Refactored admin UI into modular partials and updated form submission behavior

The admin interface has been restructured into a set of reusable partials (including \_form\_actions, \_image\_picker, \_resource\_picker, \_locale\_picker, and \_menu) to improve maintainability and consistency. A key behavioral change is the default disabling of the 'disable\_with' option on submit buttons (e.g., Save, Delete), which prevents the browser from automatically disabling the button and changing its text during AJAX requests, allowing for custom loading states. Additionally, the 'Continue Editing' functionality is now handled via a dedicated partial that conditionally renders a save button only for persisted objects, and the admin layout now explicitly includes CSRF meta tags and standardizes JavaScript/CSS asset loading.

core/app/views/refinery/admin · high confidence

Refactored admin image views to support cropping and multiple views

The admin image management interface has been restructured to support image cropping and flexible display layouts. The image editing form now includes a dedicated section for defining aspect-ratio-based crops, utilizing a JavaScript cropper and canvas polyfill for browser compatibility. Additionally, the image index page now supports switching between grid and list views, with the list view grouping images by date and displaying localized title translations via the Mobility gem.

images/app/views · high confidence

Refactored admin interface into modular JavaScript components

The admin interface JavaScript has been reorganized from a monolithic structure into distinct, modular files (admin, core, interface, modal\_dialogs, sortable\_list, tree, etc.) to improve maintainability and performance. This change introduces a centralized initialization flow in admin.js that explicitly loads and configures these modules, including new dedicated logic for image cropping (image\_crop.js), AJAX-based pagination (ajaxy\_pagination.js), and tree expansion (tree.js). Users benefit from a more responsive and stable admin experience, with specific improvements to dialog handling, sortable list interactions, and flash message management.

core/app/assets/javascripts/refinery · high confidence

Refactored admin layout structure and AJAX dialog handling

The admin interface now uses a new layout hierarchy under the refinery namespace, introducing dedicated templates for the main admin page, AJAX dialogs, and flash message rendering. This change restructures how the admin UI is assembled, specifically improving the handling of flash notices in partial responses and supporting a more AJAX-centric callback approach for dialogs, which affects the visual presentation and interaction flow within the admin panel.

core/app/views/layouts/refinery · high confidence

Refactored admin page editing interface and form structure

The admin pages interface has been restructured to improve usability and maintainability. The page editing form is now consolidated into a shared \\_form.html.erb\ partial, used by both the new and edit views, which standardizes the layout for page titles, content parts, and advanced options. A new dedicated \\_actions.html.erb\ partial manages the top-level admin actions, including search, creating new pages, and reordering. The page list view now renders a hierarchical tree using a recursive \\_page\ partial, enabling nested page display and AJAX-based child loading. Additionally, the page content editing experience is enhanced with a tabbed interface for managing multiple page parts, allowing users to reorder, add, and delete content sections directly within the editor.

pages/app/views/refinery/admin/pages · high confidence

Refactored admin resources views to use new partials and search integration

The admin resources interface has been restructured to improve modularity and add search capabilities. The main index page now renders a dedicated \\_records\ partial that includes a search header and pagination, while the list of files is displayed via a new \\_resources\ partial that groups items by date. A new \\_actions\ partial provides a consistent upload button. The insert dialog has been updated to use a new \\_existing\_resource\ partial for browsing and selecting files, which includes its own search functionality and pagination. The resource form (\\_form\) and individual resource item (\\_resource\) have also been refactored into reusable partials, with the form now correctly handling file size hints and the item view using helper methods for icons and translations.

resources/app/views · high confidence

Refactored application layout to use Refinery namespace and semantic HTML5 structure

The main application layout has been reorganized to use the /refinery/ namespace for shared partials (html\_tag, head, javascripts, site\_bar, header, footer) and updated to use semantic HTML5 elements (header, main, footer) with ARIA roles. The body tag now includes a canonical ID based on the current page and a class derived from the view template, allowing for more specific styling and identification of the current page context.

core/app/views/layouts · high confidence

Refactored page rendering with new presenters and HTML sanitization

The page rendering logic has been restructured into a new set of presenters: \ContentPresenter\ and \ContentPagePresenter\ now orchestrate the assembly of page sections, while \SectionPresenter\, \PagePartSectionPresenter\, and \TitleSectionPresenter\ handle the individual rendering of content blocks. A significant behavioral change is the introduction of HTML sanitization in \SectionPresenter\ and \TitleSectionPresenter\, which uses a custom scrubber to whitelist specific elements and attributes (including all \data-\*\ attributes) and logs warnings when content is sanitized. Additionally, \MenuPresenter\ replaces the previous menu partials, providing a configurable, object-oriented way to render navigation menus with support for custom CSS classes, roles, and depth limits.

pages/app/presenters/refinery/pages · high confidence

Refined page routing and HTTP method usage in the admin interface

The page management routes have been restructured to support nested page hierarchies and align with modern Rails conventions. Admin operations for pages now use the PATCH HTTP method for updates and deletions instead of PUT, and the preview functionality is exposed via specific PATCH and POST routes under the admin namespace. Additionally, dedicated routes for editing pages by path, retrieving children, and managing page parts and dialogs have been defined to improve navigation and API consistency within the backend.

pages/config · high confidence

Refined resource upload handling with distinct parameter permissions for create and update

The resources controller now enforces stricter parameter validation by using strong parameters, allowing multiple file uploads during resource creation while restricting updates to a single file. It also supports rendering specific dialog views based on the visual editor context and ensures proper AJAX callback handling for resource dialogs without relying on client-side JavaScript for redirects.

resources/app/controllers · high confidence

Refinery CLI tasks moved to Refinery::Cli

The Rake tasks for overriding files, listing overrides, and un-crudifying controllers now delegate to the Refinery::Cli class. This change centralizes the command-line interface logic, ensuring that these operations are handled consistently through the new CLI implementation rather than inline Rake code.

core/lib/tasks · high confidence

Refinery CMS 4.1.0 core engine restructure and Ruby 3.1+ support

Refinery CMS has been upgraded to version 4.1.0, requiring Ruby 3.1 or higher. The core library has been restructured into a modular engine architecture, introducing new files such as \application\_controller.rb\, \cli.rb\, \crud.rb\, \engine.rb\, \menu.rb\, and \menu\_item.rb\ to handle base controller logic, command-line overrides, CRUD operations, engine hooks, and navigation. This update also includes a new \Version\ class that explicitly enforces the Ruby 3.1+ requirement and defines the 4.1.0 version number.

core/lib/refinery · high confidence

Refinery CMS Pages generator now loads seed data via engine method

The Pages generator has been updated to use the Rails-standard approach for loading seed data. Instead of manually defining seed content, the generator now appends a call to \Refinery::Pages::Engine.load\_seed\ in \db/seeds.rb\, ensuring that page seeds are loaded correctly when the application boots or seeds are run.

pages/lib/generators/refinery/pages · high confidence

Refinery CMS core controllers reorganized and namespaced for mountable engine

The core application controllers have been restructured to support Refinery CMS as a mountable engine. This includes introducing a base \ApplicationController\, renaming the core admin controller to \Refinery::Admin::CoreController\ (which redirects to the admin root), and refactoring \Refinery::Admin::DialogsController\ to use explicit \before\_action\ filters for finding dialog types and iframe sources, returning 404 errors for unknown dialog types instead of rendering blank iframes. Additionally, new controllers for admin base functionality (\Refinery::AdminController\), fast responses (\Refinery::FastController\), and sitemaps (\Refinery::SitemapController\) have been added, with the sitemap controller now correctly handling locale information via \Refinery::I18n.frontend\_locales\.

core/app/controllers · high confidence

Refinery CMS core engine restructured with new authorization and configuration APIs

The core library has been refactored to align with modern Rails engine patterns and the Zilch authorization system. This introduces a new \Refinery::Core::Engine\ that isolates the namespace and manages autoload paths, decorators, and initializers (including Mobility for i18n and WillPaginate defaults). Authorization is now handled via \Refinery::Core::AuthorisationAdapter\ and \NilUser\, replacing previous mechanisms. Configuration is centralized in \Refinery::Core::Configuration\ using \ActiveSupport::Configurable\, exposing settings like \backend\_route\, \force\_ssl\, and analytics codes. The backend route logic has been hardened to prevent double slashes, and the dashboard extension has been removed.

core/lib/refinery/core · high confidence

Refinery CMS core routing restructured for mountable engine

The core application now uses a dedicated routes file to define paths within the Refinery::Core::Engine namespace. This change introduces a configurable backend route (Refinery::Core.backend\_route) for admin resources, specifically exposing dialog index and show actions, and establishes the admin root. It also retains the sitemap.xml endpoint and optional i18n locale filtering, aligning the routing structure with Rails mountable engine conventions.

core/config · high confidence

Refinery CMS engine initialization and asset configuration

This change introduces three new initializers to configure the Refinery CMS mountable engine. It adds a Zeitwerk inflector to correctly handle 'refinerycms-' prefixed gems, ensures the 'refinery\_core\_manifest.js' asset is precompiled for the assets pipeline, and implements a custom will\_paginate link renderer that prefixes URLs with 'refinery.url\_for' only when the request originates from a Refinery controller, allowing will\_paginate to function correctly both inside and outside the engine.

core/config/initializers · high confidence

Refinery CMS frontend view templates restructured and modernized

The frontend view templates in core/app/views/refinery have been reorganized and updated to improve structure, security, and analytics support. Key changes include the addition of Matomo analytics support alongside existing Google Analytics, the implementation of a draft page message for unpublished content, and the introduction of a 'skip to first child page' accessibility feature. The site bar now includes an 'edit this page' button and uses SVG logos, while the header and footer have been refined with better HTML markup and schema.org support. Additionally, the head partial now conditionally includes CSRF meta tags based on configuration, and the HTML tag partial has been updated to remove legacy IE6/7/8/9 conditional classes in favor of a simpler no-js class approach.

core/app/views/refinery · high confidence

Refinery CMS helpers refactored into modular components

The helper methods in core/app/helpers/refinery have been reorganized into distinct, single-responsibility modules (ActionHelper, AdminHelper, CustomAssetsHelper, HtmlTruncationHelper, IconHelper, ImageHelper, MetaHelper, PaginationHelper, SiteBarHelper, TagHelper, and TranslationHelper). This structural change improves code maintainability and clarity. Specific behavioral updates include deprecating the legacy refinery\_icon\_tag helper in favor of action\_icon, disabling Turbolinks on site bar navigation links to prevent navigation issues, and updating the image\_fu helper to handle Dragonfly job deserialization more robustly.

core/app/helpers/refinery · high confidence

Refinery CMS image and resource generators now create dedicated initializers

The generators for the images and resources engines have been updated to automatically create specific initializer files (config/initializers/refinery/images.rb and config/initializers/refinery/resources.rb) during installation. These generators also support a --skip-migrations option to bypass database migration steps, allowing users to control the setup process more granularly.

images/lib/generators/refinery/images, resources/lib/generators/refinery/resources · high confidence

Refinery CMS page schema migration updates

The database migration files for the Refinery CMS pages module have been updated to reflect the current schema state. This includes the addition of a \children\_count\ column to the \refinery\_pages\ table to track nested set children, the removal of legacy \custom\_slug\ and \slug\ columns from \refinery\_pages\ (which are now handled via translations), and the removal of the \body\ column from \refinery\_page\_parts\ (also moved to translations). Additionally, migrations ensure that \refinery\_page\_parts\ have a dedicated \slug\ column with normalized formatting (lowercase, spaces replaced by underscores) and a \title\ column, replacing the previous single-column approach.

pages/db/migrate · high confidence

Refinery CMS pages controller implements 301 redirects and scoped slug resolution

The new \Refinery::PagesController\ introduces explicit 301 redirects for legacy slugs, link URLs, and when skipping to the first live child of a page. It also adds support for scoping slugs to parent pages via the \Refinery::Pages.scope\_slug\_by\_parent\ setting, allowing nested pages to share slug names without conflict. The controller initializes page finding logic into a \before\_action\, supports custom page finders per action, and respects template settings for rendering.

pages/app/controllers/refinery · high confidence

Refinery Pages engine refactored with centralized configuration and new page type system

The Pages engine has been restructured to use a centralized configuration class (Refinery::Pages.configuration) for managing settings such as slugs, templates, and HTML whitelists, replacing scattered config access. A new 'page types' system (Refinery::Pages::Type) allows defining custom page structures with specific parts and templates, including a deprecation notice for the old string-based part syntax. The engine now uses a dedicated Finder class (Refinery::Pages::Finder) to handle page lookups with improved support for Mobility-based i18n and configurable slug scoping. Additionally, the engine isolates its namespace, registers itself as a plugin with specific menu matching, and ensures helpers are included via before\_inclusion blocks for proper decorator loading.

pages/lib/refinery/pages · high confidence

Refinery Pages engine restructured with Mobility integration

The Refinery Pages engine has been reorganized to centralize configuration and initialization logic within the main \pages.rb\ module, replacing previous scattered settings with a unified approach using \ActiveSupport::Configurable\. This change introduces support for 'page types' and integrates the Mobility gem for internationalization, replacing the older Globalize dependency. The update also improves autoloading compliance with Rails conventions and ensures database dependencies are loaded only when necessary to support asset precompilation.

pages/lib/refinery · high confidence

Refinery Resources engine configuration and validation

The Refinery Resources engine now includes a dedicated configuration class that exposes settings for max file size, pagination, content disposition, and a whitelist of allowed MIME types (including audio, video, images, text, and office documents). It also registers a FileSizeValidator to enforce the max\_file\_size limit on resource uploads, ensuring that uploaded files are validated against the configured byte limit.

resources/lib/refinery/resources · high confidence

Refinery Resources schema updated to support translated titles

The database schema for Refinery Resources has been updated to support localized content. A new migration creates the \refinery\_resources\ table to store file metadata (mime type, name, size, UID, extension), and a second migration introduces a \refinery\_resource\_translations\ table. This translation table links resource IDs to specific locales, allowing the \resource\_title\ to be stored and retrieved per language, enabling multi-language support for resource titles.

resources/db · high confidence

Refinery admin interface receives a comprehensive visual overhaul

The Refinery admin interface has been restyled to modernize its appearance and improve usability. The update introduces a new icon system using FontAwesome for consistent visual cues across menus and actions, and implements a new color palette for better distinction of states (errors, success, warnings). Layouts for dialogs, tooltips, and the site bar have been refined, including fixes for z-index overlaps and improved responsiveness for the top site bar. Additionally, legacy styles have been migrated to SCSS, and specific browser hacks (notably for Internet Explorer 7/8) have been cleaned up or removed.

core/app/assets/stylesheets/refinery · high confidence

Refinery core generator now places initializers in a dedicated directory

The Refinery core generator has been updated to store its generated initializer files within a dedicated \config/initializers/refinery/\ directory (e.g., \config/initializers/refinery/core.rb\) instead of the root initializers folder. This change organizes generated configuration files into a specific namespace, keeping the main initializers directory cleaner and making Refinery-specific settings easier to locate and manage.

core/lib/generators/refinery/core · high confidence

Refinery engine generator now uses dedicated routes file and explicit backend route configuration

The engine generator template has been restructured to use a dedicated \config/routes.rb.erb\ file that explicitly defines frontend and admin namespaces, replacing the previous approach of appending to routes. The admin namespace now utilizes a configurable \backend\_route\ (referenced as \Refinery::Core.backend\_route\) instead of a hardcoded path, and the generator now uses \routes.draw\ instead of \routes.append\ for cleaner route definition. Additionally, template files containing ERB have been renamed from \.rb\ to \.rb.erb\ to correctly indicate their templated nature.

core/lib/generators/refinery/engine/templates/config · high confidence

Refinery images database schema updates

The images database schema has been updated to support new capabilities and structural changes. Image title and alt text are now translatable via a dedicated \refinery\_image\_translations\ table, replacing the previous single-column approach. A \parent\_id\ column has been added to the \refinery\_images\ table to support hierarchical image relationships. Additionally, the \image\_ext\ column has been removed from the schema.

images/db · high confidence

Refinery now loads core extensions via a centralized all.rb file

The lib/refinery/all.rb file has been introduced to explicitly require the core Refinery extensions (core, images, resources, and pages) in a single location. This change centralizes the loading of these foundational components, ensuring they are available when the library is initialized, which supports the broader effort to restructure how Refinery manages its internal modules and extensions.

lib/refinery · high confidence

RefineryCMS core and engines migrated to Mobility for internationalization

The application has replaced the Globalize3 gem with Mobility for handling translations across core models (Page, PagePart, Image, Resource). This change introduces a new \Refinery::Core::BaseModel\ base class and updates the \Refinery::Page\ model to use Mobility's \translates\ macro for fields like title, slug, and menu\_title. The \Refinery::Image\ and \Refinery::Resource\ models now support translated \image\_title\, \image\_alt\, and \resource\_title\ fields. Additionally, the \Refinery::Page\ slug generation now supports scoping slugs to the parent page via FriendlyId, and the \Refinery::Plugins\ class has been refactored to use \Enumerable\ instead of inheriting from \Array\.

refinerycms · high confidence

Removal of Rails environment configuration files

The dedicated configuration files for development, production, and test environments (config/environments/development.rb, production.rb, and test.rb) have been removed from the project. This eliminates the previous per-environment settings for caching, logging, error reporting, and mailer delivery, likely as part of a broader migration or restructuring of how the application manages its runtime configuration.

config/environments · high confidence

Removal of WYMeditor language localization files

The localized string files for the WYMeditor rich-text editor have been removed from the public assets. This affects translations for Catalan, Czech, German, English, Spanish, Persian, French, Hebrew, Hungarian, Italian, Norwegian Bokmål, Dutch, Norwegian Nynorsk, Polish, Brazilian Portuguese, European Portuguese, Russian, Swedish, Turkish, and Simplified Chinese. Users relying on these specific language interfaces for the editor will no longer have access to these localized UI strings.

public/wymeditor/lang · high confidence

Removal of default database seed file

The default database seed file (db/seeds.rb) has been removed from the core application. This file previously defined the initial site configuration, including settings like site name and analytics codes, as well as default pages such as Home, About Us, News, Contact Us, and a 404 page. Users relying on this single file to bootstrap their database structure and initial content will need to adjust their setup process, as these default records are no longer automatically created via this specific seed script.

db · high confidence

Removal of default email templates for inquiry notifications

The default email templates for inquiry confirmations and notifications have been removed from the application. Users will no longer receive the standard HTML-formatted emails containing inquiry details (such as name, email, phone, and message) or confirmation messages via these specific view files, as the \confirmation.html.erb\ and \notification.html.erb\ files in the inquiry mailer views have been deleted.

_vendor/plugins/inquiries/app/views/inquiry\mailer · high confidence

Removal of default initializer templates

The default \inflections.rb\ and \mime\_types.rb\ initializer files have been removed from the application. These files previously contained commented-out examples for configuring custom pluralization/singularization rules and registering new MIME types. Their removal means the application no longer includes these specific configuration scaffolds by default, requiring users to create these files manually if they wish to customize inflection rules or register additional MIME types.

config/initializers · high confidence

Removal of empty helper modules in authentication and pages plugins

The empty helper modules SessionsHelper, UsersHelper, and PagesHelper have been removed from the authentication and pages plugins. This cleanup eliminates unused code artifacts from the application's helper directory structure.

vendor/plugins/authentication/app/helpers, vendor/plugins/pages/app/helpers · high confidence

Removal of internal news plugin routing configuration

The routing configuration for the internal news plugin has been removed from the application's codebase. Specifically, the file defining routes for public and admin news items has been deleted, indicating that the news functionality is no longer managed as an internal plugin within this repository and is likely being moved to an external dependency or handled differently.

vendor/plugins/news/config · high confidence

Removal of legacy Rails 2 configuration files

The application has removed several configuration files that were specific to the Rails 2 framework, including \config/boot.rb\, \config/environment.rb\, \config/routes.rb\, and cloud storage configuration files (\config/amazon\_s3.yml\, \config/rackspace\_cloudfiles.yml\, \config/database.yml.example\). This change reflects the migration away from the Rails 2 initialization and routing mechanisms, requiring users to update their configuration setup to align with the newer Rails version.

config · high confidence

Removal of legacy Rails 2 image routing configuration

The legacy routing configuration for the images plugin, which defined admin namespace routes for images and image dialogs using the deprecated ActionController::Routing API, has been removed. This change reflects the migration to the Rails 3 Router API, where these routes are likely managed elsewhere or via a different mechanism, eliminating the old route definitions that previously handled image resource and dialog insertion paths.

vendor/plugins/images/config · high confidence

Removal of legacy Rails 2 routing configuration

The legacy \config/routes.rb\ file for the Inquiries plugin has been removed. This file previously defined routes using the deprecated \ActionController::Routing::Routes.draw\ DSL, including resource definitions for inquiries and admin settings. Its removal indicates a migration to a newer routing mechanism (likely the Rails 3 API mentioned in commit history), meaning the old route definitions are no longer active or supported in this location.

vendor/plugins/inquiries/config, vendor/plugins/pages/config · high confidence

Removal of legacy admin dashboard routing configuration

The legacy routing configuration for the admin dashboard, previously defined in \vendor/plugins/dashboard/config/routes.rb\, has been removed. This file contained the namespace and resource definitions for the admin dashboard using the older Rails routing syntax. Its deletion indicates that the dashboard routing is now managed elsewhere, likely as part of a broader migration to a newer routing structure or framework version.

vendor/plugins/dashboard/config · high confidence

Removal of legacy admin inquiry views

The legacy admin views for listing and displaying individual inquiries (\index.html.erb\ and \show.html.erb\) have been removed from the inquiries plugin. This deletion eliminates the previous UI for managing open/closed statuses and viewing inquiry details, indicating that the backend interface for inquiries has been replaced or refactored elsewhere.

vendor/plugins/inquiries/app/views/admin/inquiries · high confidence

Removal of legacy authentication routing configuration

The legacy authentication plugin's route definitions have been removed. This eliminates the hardcoded routes for user resources, session management, and explicit login/logout paths (/login and /logout) that were previously defined in the plugin's configuration, indicating a shift away from this specific authentication mechanism or its integration into a broader routing strategy.

vendor/plugins/authentication/config · high confidence

Removal of legacy dashboard index view

The legacy admin dashboard index view (\vendor/plugins/dashboard/app/views/admin/dashboard/index.html.erb\) has been removed. This file previously rendered the 'Latest Activity' feed and 'Common Tasks' links (such as adding pages or uploading files/images) directly in the template. Its deletion indicates that the dashboard UI is now generated or managed through a different mechanism, likely involving the newly integrated user manager, plugin architecture, or updated i18n/localization structures mentioned in the commit history.

vendor/plugins/dashboard/app/views · medium confidence

Removal of legacy image dialog and form views

The legacy view templates for the image management interface have been removed, including the insert dialog (insert.html.erb), the new image upload dialog (new.html.erb), the shared image form partial (\_form.html.erb), and the standard edit and index pages. This cleanup eliminates the old Thickbox-based dialog structure and the previous form rendering logic, indicating a migration to a new image picker or dialog implementation elsewhere in the application.

vendor/plugins/images/app/views · high confidence

Removal of legacy inquiry settings views

The admin interface for managing inquiry settings has been refactored by removing the previous view templates. Specifically, the dedicated forms for configuring the confirmation email body and notification recipients, along with the main index and edit pages for these settings, have been deleted. This change removes the old server-rendered form structure in favor of the updated UI approach mentioned in the commit history.

_vendor/plugins/inquiries/app/views/admin/inquiry\settings · high confidence

Removal of legacy page part creation form

The traditional server-rendered form for creating new page parts in the admin interface has been removed. This change indicates a shift away from the previous page-part addition workflow, likely replacing it with a different mechanism (such as the dialog-based approach mentioned in commit history) to handle page part creation more gracefully.

_vendor/plugins/pages/app/views/admin/page\parts · high confidence

Removal of legacy page view templates

The \home.html.erb\ and \show.html.erb\ view templates in the pages plugin have been deleted. These files previously rendered page content using a two-column layout with left and right body sections. Their removal indicates that the rendering logic for these pages has been migrated to a different location or approach, likely aligning with the broader refactoring of content page partials and layout structures mentioned in the commit history.

vendor/plugins/pages/app/views/pages · medium confidence

Removal of legacy plugin initialization files

The legacy \init.rb\ files for the authentication, dashboard, and pages plugins have been removed. This cleanup eliminates the old plugin registration mechanism, aligning the codebase with the updated plugin architecture where these components are likely managed differently or integrated directly into the core.

vendor/plugins/authentication, vendor/plugins/images, vendor/plugins/news · high confidence

Removal of legacy plugin registration file

The \init.rb\ file for the Inquiries plugin has been removed. This file previously handled the plugin's registration with the Refinery CMS engine, defining its title, description, version, and menu match rules. Its deletion indicates a migration away from the legacy plugin initialization pattern (likely towards the Engines structure mentioned in commit history), meaning the plugin's configuration is now managed through a different mechanism.

vendor/plugins/inquiries · high confidence

Removal of legacy public directory assets and Apache configuration

The public directory's .htaccess file and robots.txt have been removed. This eliminates the legacy Apache rewrite rules that previously routed requests to dispatch.cgi and the static file serving logic, as well as the search engine directive that blocked crawling of the /admin/ path. Users relying on this specific Apache configuration for request routing or robots.txt directives will need to adjust their server setup.

public · high confidence

Removal of legacy user registration view

The \new.html.erb\ template for user registration has been removed from the authentication plugin. This view previously provided a form for new users to sign up by entering a login, email, and password, and conditionally included hidden fields for plugin selection during initial installation. Its deletion indicates that the user creation flow has been refactored or moved to a different location within the application.

vendor/plugins/authentication/app/views/users · high confidence

Removed legacy session login view

The previous session login form (new.html.erb) has been removed from the authentication plugin. This view, which previously rendered fields for login credentials and a remember-me checkbox using the old form structure, is no longer present, indicating a shift in how the login interface is handled or rendered.

vendor/plugins/authentication/app/views/sessions · high confidence

Removed obsolete user activation and signup notification email templates

The email templates for account activation (activation.html.erb) and signup notifications (signup\_notification.html.erb) have been removed from the authentication plugin. This eliminates the legacy workflow where users received an activation link and their password via email upon registration, aligning with the plugin's updated authentication flow.

_vendor/plugins/authentication/app/views/user\mailer · high confidence

Resources engine now uses Mobility for translations

The Resources engine has switched its internationalization backend from Globalize to Mobility. This change is implemented by requiring the Mobility library when ActiveRecord loads, enabling the system to handle resource name customization and translations using the new Mobility framework.

resources/lib/refinery · high confidence

Restructured admin engine generator templates to follow namespacing conventions

The admin view templates for generated Refinery engines have been restructured to align with new namespacing conventions. This change updates the generated CRUD interfaces (index, new, edit) and their supporting partials (actions, form, records, sortable list) to correctly use the engine's namespace in path helpers and controller checks. It also introduces support for localized content via the Mobility gem, adds a locale picker to the form, and updates the record list to display translation flags. Additionally, the generator now includes a \--skip-frontend\ option to control whether frontend preview links are generated in the admin interface.

core/lib/generators/refinery/engine/templates/app/views/refinery/namespace/admin · high confidence

Simplified library entry point

The main library file lib/refinerycms.rb has been simplified to a single line that requires 'refinery/all'. This change delegates the loading of all components to the 'refinery/all' module, streamlining the entry point for the Refinery CMS library.

lib · high confidence

Simplified page view templates to use shared content rendering

The home and show page views have been replaced with single-line templates that delegate rendering to the shared '/refinery/content\_page' partial. This change removes the previous view-specific logic, ensuring that both the home page and standard page displays are now generated through a unified content rendering path.

pages/app/views/refinery/pages · high confidence

Standardized error pages and updated robots.txt in core/public

The 404, 422, and 500 error pages have been moved from the application root to core/public and updated to use HTML5 syntax instead of XHTML Transitional, while the robots.txt file has been added to core/public to explicitly disallow the /refinery/ path for all crawlers.

core/public · high confidence

Support for Refinery-specific attribute types in generators

The generator system now recognizes and correctly handles Refinery-specific attribute types such as image, resource, radio, select, and checkbox. These custom types are mapped to appropriate database column types (e.g., integer for references, string for form inputs) and Rails attribute types, ensuring that generated migrations and models work correctly with Refinery's custom UI components.

core/lib/refinery/generators · high confidence

Updated asset manifest to include image cropping and polyfill dependencies

The core asset manifest has been updated to explicitly link new files required for the image cropping feature, specifically cropper.css, cropper.js, and refinery/image\_crop.js. Additionally, the manifest now includes canvas-to-blob.js to provide a polyfill for older browsers and Edge, ensuring compatibility for image manipulation features.

core/app/assets/config · high confidence

Updated core initializer template with Matomo analytics and configuration options

The generated core initializer template now includes commented-out configuration options for Matomo open web analytics (server and site ID), alongside existing settings for Google Analytics, SSL forcing, backend route customization, mounted path, and plugin priority. It also notes that Dragonfly and S3 configurations have moved to a separate initializer.

core/lib/generators/refinery/core/templates · high confidence

Updated database migration and seed templates for generated engines

The database migration and seed templates used when generating new Refinery engines have been updated. The migration template now explicitly specifies the ActiveRecord version in the migration class definition (e.g., \ActiveRecord::Migration\[7.0\]\) to ensure compatibility with modern Rails versions. Additionally, the seed template has been enhanced to automatically create localized page parts with slugs and assign engine plugins to users, ensuring that generated engines are properly initialized with their default content and permissions upon first run.

core/lib/generators/refinery/engine/templates/db · high confidence

Updated dummy application generator to skip unnecessary Rails components

The dummy application generator now explicitly skips Action Cable, Action Mailer, Action Mailbox, Action Text, Active Job, Active Storage, Hotwire, and JavaScript when creating the test environment. This results in a lighter, faster-to-generate dummy app that excludes features not required for Refinery CMS testing, while still providing necessary configuration files and placeholder assets like the apple-touch-icon.

core/lib/generators/refinery/dummy · high confidence

Updated dummy application templates for Rails 6.1+ compatibility

The dummy application generator templates have been updated to support Rails 6.1 and later versions. This includes migrating the application configuration to use \config.load\_defaults 6.1\, adopting the Zeitwerk-compatible autoloader structure, and updating database configuration to support modern MySQL (utf8mb4) and PostgreSQL adapters with appropriate environment variable handling. The generator now also includes updated asset pipeline configurations (manifest.js, application.js) and storage settings to align with current Rails conventions, ensuring the dummy app functions correctly for testing and development purposes.

core/lib/generators/refinery/dummy/templates · high confidence

Updated engine generator templates to use before\_inclusion hooks and comply with Zeitwerk

The engine generator templates have been updated to comply with the Zeitwerk autoloader by renaming .rb templates containing ERB to .rb.erb and replacing Concerns with pure Ruby modules. Additionally, plugin registration now utilizes before\_inclusion hooks within the engine definition, ensuring proper initialization order for new extensions.

core/lib/generators/refinery/engine/templates/lib/refinery · high confidence

Updated gem signing certificate

The gem signing certificate for the 'parndt' identity has been replaced with a new version. This change ensures that future gem releases are signed with the updated key, which is valid from May 10, 2020, to May 10, 2021, and includes updated contact information ([e-mail redacted]). Users installing gems signed with this certificate will need to trust the new public key to verify authenticity.

certs · high confidence

Updated generator templates for database configuration and repository hygiene

The CMS generator templates now include dedicated database configuration files for MySQL, PostgreSQL, and SQLite3, allowing users to scaffold applications with pre-configured settings for their preferred database engine. Additionally, a .gitignore file has been added to the generator output to automatically exclude common development artifacts, local configuration files, and vendor extension dummy applications, while legacy CSS files in the public stylesheets directory have been removed to clean up the generated project structure.

core/lib/generators/refinery/cms/templates · high confidence

Updated image initializer template with new Dragonfly configuration options

The generated initializer for Refinery Images now includes commented-out configuration options for the underlying Dragonfly image processing library. Users can now explicitly configure Dragonfly-specific settings such as URL verification, secret keys, URL hosts, and datastore roots directly within the images initializer, alongside existing options for allowed MIME types and image sizes.

images/lib/generators/refinery/images/templates · high confidence

The admin page link dialog now respects the Refinery::Pages.absolute\_page\_links setting, generating full URLs with the request host when enabled, and uses the Mobility gem to correctly resolve page URLs for the selected locale. This ensures that inserted page links are accurate whether the site uses relative or absolute paths and handles multi-language content correctly.

_pages/app/views/refinery/admin/pages\dialogs · high confidence

WYMeditor iframe and skin assets removed

The static WYMeditor iframe HTML/CSS files (default and refinery themes) and the refinery skin assets (skin.css, skin.js) have been deleted from the public directory. This removes the local, hardcoded styling and layout definitions for the editor's content area and toolbar, indicating that the editor's appearance and structure are now managed through other mechanisms (such as dynamic Rails actions or external asset pipelines) rather than these static files.

public/wymeditor/iframe · high confidence

Test coverage

Add Refinery::Testing::ControllerMacros for authentication and routing in specs; Add default spec helper template for generated tests; Added Guardfile template for extension-aware test watching; Added comprehensive tests for the Refinery engine generator; Added controller specs for Refinery PagesController; Added controller specs for the Refinery admin dummy controller; Added empty authentication macro stub for testing extensions; Added factory definition for Refinery::Resource; Added factory definitions for Refinery images; Added generator specs for Pages and Resources initializers; Added model specs for Page, PageFinder, PageMenu, PageMetaData, PagePart, and PageUrl; Added model tests for Refinery Resource; Added shared test contexts for image management specs; Added shared test examples for image management; Added spec helper with Capybara extensions and RSpec configuration; Added spec support helpers for page caching and UI selectors; Added spec\_helper template for generated engines; Added specs for Image model validation and thumbnail dimension logic; Added specs for pages admin helper methods; Added specs for pages presenters; Added system tests for Refinery CMS admin and core features; Added system tests for Refinery CMS page administration and frontend rendering; Added system tests for admin image and resource management; Added test coverage for Dragonfly generator and configuration; Added test coverage for Refinery Pages core components; Added test coverage for Refinery core components; Added test coverage for core configuration, NilUser, and UsersManager; Added test coverage for core helper and presenter modules; Added test coverage for the Sitemap controller; Added test factories for pages and page parts; Added test fixture for Refinery CMS security check; Added test fixtures for engine validation and asset precompilation; Added test support utilities for system specs and generators; Added testing generator with default setup; Added tests for CMS generator behavior; Added tests for ContentPagesHelper; Added tests for Pages library methods; Added tests for Refinery Resources engine configuration; Added tests for configurable view template patterns; Added tests for images generator and engine behavior; Added tests for the Refinery Core generator output; Centralized RSpec configuration for Refinery testing; Configured RSpec for instant feedback with Fuubar; Extract core testing functionality into a new testing engine; Initial RSpec test infrastructure setup; New testing library for Refinery CMS; New testing rake tasks for generating and managing dummy applications; Refactor testing infrastructure into a Railtie with autoloaded macros; Removal of Rails vendor test fixtures; Removed legacy authentication test suite; Updated generated admin feature specs for Refinery CMS modules; Updated test templates to use FactoryBot and modern RSpec syntax.

Dependencies

Updated dependencies and added Ruby 3.4 compatibility

The project's Gemfile has been updated to include explicit dependencies for \net-imap\, \net-pop\, and \net-smtp\, which are required for modern Ruby versions. Additionally, a conditional dependency on the \mutex\_m\ gem has been added to support Ruby 3.4+ when running on older Rails versions (6.x and 7.x), ensuring compatibility with the standard library changes in newer Ruby releases.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 56 (-5.7)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 61 → 60 (-0.8)
  • Architecture 89 → 80 (-8.6)
  • Maturity 69 → 69 (+0.0)
  • Readiness 53 → 52 (-0.6)
  • Security 71 → 73 (+1.6)
  • Domain Modelling 100 → 100 (+0.0)
  • Accessibility 50 (new)

Resolved (2)

  • Documentation: no project overview (README.md)
  • The body is a perfect copy-paste of the guide itself (bootstrap commands, gemspec dependencies) with no context/problem and no consequences/trade-offs (doc/guides/4 - Refinery Extensions/10 - Using a Refinery CMS extension as a standalone extension in your Rails Application.md)

New (13)

  • Ambiguous naming for root path resolution. Refinery.root() and Core.root() appear to serve the same purpose (getting the base path of the application/core), while Refinery.roots() (plural) suggests returning multiple paths or paths for specific extensions. The distinction between singular root and plural roots is not immediately clear in intent, and having root on both Refinery and Core modules suggests potential duplication or unclear ownership of the 'base path' concept.
  • Controller method naming inconsistency with routing intent. home and show are standard RESTful-ish names, but home is often a special case of show (showing the root page). Having distinct methods suggests different logic, but the naming doesn't clearly indicate if home is a redirect, a specific template render, or a different finder logic compared to show.
  • Duplicate registration mechanisms. Refinery.register_extension is a global API for registering extensions, while Plugin.register is an instance/class method on the Plugin model itself. It is unclear if these are complementary (one for global registry, one for local config) or redundant ways to achieve the same result, leading to confusion for developers on which API to use.
  • Inconsistent abstraction levels for image processing. Image.thumbnail is a high-level convenience method, while ThumbnailDimensions exposes low-level geometry processing methods like process, resize_geometry, and crop. This exposes internal implementation details of the thumbnailing engine directly on the public API, which can be confusing for users who just want a thumbnail.
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Projects may be oversized for their cohesion
  • The decision is an empty boilerplate guide (bootstrap a Rails app with just a Refinery extension like refinerycms-blog), with no context/problem and no consequences/trade-offs (doc/guides/4 - Refinery Extensions/10 - Using a Refinery CMS extension as a standalone extension in your Rails Application.md)

Architecture

  • Unchanged — 0 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

refinery/refinerycms was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 34438aae76d087246039cd24755187844d796737 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.