RolifyCommunity/rolify
61.7
Adequate · 28 September 2026
1k
lines of production code
Ruby
primary language
2
measurements over time
What this system is
This system is the Rolify gem, a Ruby library that implements role-based access control for ActiveRecord and Mongoid models. It provides APIs for assigning roles to users, querying roles with strict or inherited scoping, and managing polymorphic resource associations. The codebase includes generators for scaffolding role structures and adapters that handle database interactions for both SQL and NoSQL backends.
How it got here
2011 — Rolify 6.0.1 release and API restructuring
9 changes.
This period focused on the Rolify 6.0.1 release, introducing strict role checking modes and deprecating legacy generators and Ruby versions. The core API was restructured to support explicit configuration and factory patterns, while the test infrastructure was significantly expanded to cover both ActiveRecord and Mongoid adapters.
2012 — Adapter architecture and Mongoid support
5 changes.
This period focused on establishing a robust adapter base class structure to standardize ORM integration, notably introducing a new Mongoid adapter alongside the existing ActiveRecord implementation. The work included significant refactoring of the ActiveRecord adapter to enforce stricter role scoping and improve query performance, supported by comprehensive test coverage across both backends.
2013 — Generator refactoring and Rails 5 support
6 changes.
This period focused on refactoring the Rolify generators to support namespaced models and separate Role/User generation for both ActiveRecord and Mongoid. The work included updating templates for Rails 5+ compatibility, adding validation for resource types, and introducing new configuration options like remove\_role\_if\_empty. Comprehensive test coverage was added to verify the correct behavior of the updated generators.
Features
Add Mongoid adapter for role management
Introduces a new Mongoid adapter (ResourceAdapter, RoleAdapter, and Scopes) that enables the Rolify gem to manage roles and permissions for models using the Mongoid ODM. This change allows users to define and query roles on Mongoid documents with the same API used for ActiveRecord, including support for strict role checking, resource-scoped roles, and role caching.
lib/rolify/adapters/mongoid · high confidence
New ActiveRecord generator for Rolify scaffolding
A new \RolifyGenerator\ class has been added to the \lib/generators/active\_record\ directory, enabling users to automatically scaffold Role models and associated migrations for ActiveRecord. The generator accepts a user class name (defaulting to 'User'), validates that the specified user model exists before proceeding, and generates the necessary migration file with version-specific naming conventions for Rails 5 and above. It also handles the injection of the Rolify module into the user model, supporting both standard applications and engines with Devise integration.
_lib/generators/active\record · high confidence
Removals
Removed legacy RoleGenerator class
The \RoleGenerator\ class located in \lib/generators/rolify/role/\ has been removed from the codebase. This generator previously handled the creation of the Role model and the associated migration file using a simple \has\_and\_belongs\_to\_many\ association. Its removal indicates that the library has moved away from this specific generator implementation, likely in favor of a different approach for setting up role-based access control.
lib/generators/rolify/role · high confidence
Architecture
Introduction of a new adapter base class structure
A new base class \Rolify::Adapter::Base\ has been added to define the core interface for ORM adapters. This class establishes the foundational methods and structure required for adapter implementations, serving as the parent for specific adapter types like \RoleAdapterBase\ and \ResourceAdapterBase\.
lib/rolify/adapters · high confidence
Behavioural changes
Active Record adapter refactoring for stricter role scoping and performance
The Active Record adapters (Resource, Role, and Scopes) have been rewritten to support strict role queries, allowing users to check for roles bound to specific resources without inheriting super-roles. This change introduces \where\_strict\ and \find\_cached\_strict\ methods to enforce precise resource binding, optimizes role existence checks by using subqueries and \LIMIT 1\ to avoid large result sets, and fixes several SQL issues including ambiguous column errors and MySQL quoting problems. Users benefit from more predictable role resolution and improved query performance when filtering resources by role.
_lib/rolify/adapters/active\record · high confidence
Mongoid generator now uses collection\_name and adds resource\_type validation
The Mongoid rolify generator has been updated to correctly use the Mongoid model's collection\_name instead of the ActiveRecord table\_name when generating the association, ensuring compatibility with Mongoid's naming conventions. Additionally, the generated Role model now includes a validation on the resource\_type field to ensure it is included in the allowed Rolify resource types, improving data integrity for polymorphic associations.
lib/generators/mongoid · high confidence
Redesigned role assignment and resource configuration APIs
The library's core API has been restructured to support more explicit configuration and stricter role checking. The \rolify\ method now accepts a \strict\ option to enable strict role validation, allowing users to check roles without super-role inheritance. Configuration options such as \role\_cname\, \role\_join\_table\_name\, and \role\_table\_name\ are now explicitly managed via accessor methods on the \Rolify\ module, replacing previous implicit defaults. Additionally, the \resourcify\ method has been updated to allow customization of the association name (defaulting to \:roles\) and supports dependent destroy behavior, while the underlying adapter creation logic has been refactored to use a factory pattern for better separation of concerns between user and resource adapters.
lib · high confidence
Refactored generators to support namespaced models and separate Role/User generation
The Rolify generator structure has been reorganized to handle namespaced models and separate the generation of the Role model from the modification of the User model. The new \RolifyGenerator\ now invokes a dedicated \UserGenerator\ to inject the \rolify\ method into the user class, allowing for better support of custom user class names and namespaced paths. This change also introduces specific logic to detect and inject the rolify association correctly for both ActiveRecord and Mongoid ORMs, ensuring compatibility with namespaced model structures.
lib/generators/rolify · high confidence
Removal of legacy Role generator templates
The migration and Role model templates previously located in the generator directory have been deleted. This change removes the legacy ERB-based templates that defined the Role model structure and its associated database migration, aligning with the reorganization of the generator logic to use Rails generator conventions instead of manual file references.
lib/generators/rolify/role/templates · high confidence
Restructured generator templates and added new configuration options
The generator templates have been reorganized to provide separate files for Role models based on the ORM (ActiveRecord or Mongoid) and a new README explaining the generated files. The initializer template now includes a commented-out \remove\_role\_if\_empty\ configuration option, allowing users to control whether roles are deleted from the database when they no longer have any resources assigned.
lib/generators/rolify/templates · high confidence
Rolify 6.0.1 release with strict role query support and Ruby 2.3/2.4 deprecation
This entry covers the changes introduced in the Rolify 6.0.1 release (as documented in the new CHANGELOG.rdoc). The primary behavioral change is the introduction of strict \with\_role\ queries, which alters the behavior of \with\_role\ in strict mode to align with previous documentation, addressing issue \#543. Additionally, support for Ruby 2.3 and 2.4 has been dropped. The release also includes an improvement to the ActiveRecord adapter's \in\ method, which now utilizes a subquery instead of two separate queries for better performance. The Appraisals file confirms support for Mongoid 5, 6, and 7, as well as ActiveRecord 4, 5, and 6.
(repo-wide) · high confidence
Rolify version 6.0.1 release with strict role checking and dynamic shortcut defaults
This release updates the Rolify gem to version 6.0.1. It introduces a strict role-checking mode that allows verifying roles without relying on super-roles, configurable via the new \strict\_rolify\ setting. The default behavior for dynamic shortcut methods (like \is\_admin?\) is now disabled to improve performance and avoid potential conflicts, though this can be re-enabled via \use\_dynamic\_shortuts\. The configuration module also includes a sanity check to warn if the roles table is missing during initialization, and the \has\_no\_role\ method is deprecated in favor of \remove\_role\.
lib/rolify · high confidence
Fixes
Updated ActiveRecord migration and model templates for Rails 5+ compatibility
The generator templates for the Role model and its migration have been updated to support Rails 5.x. The migration template now conditionally adds an index on the role name only for non-PostgreSQL databases, addressing a specific regression for PostgreSQL users. The model template now uses the \:optional =\> true\ option for the polymorphic \resource\ association in Rails 5 and later, ensuring correct validation behavior. Additionally, a README file was added to clarify the usage of the \resourcify\ method.
_lib/generators/active\record/templates · high confidence
Test coverage
Added comprehensive test suite for Rolify configuration and role management; Added generator specs for ActiveRecord and Mongoid; Added shared test suites for role assignment, removal, and querying; Added test adapter fixtures for ActiveRecord and Mongoid; Added test support infrastructure for spec execution; Updated test infrastructure and added documentation for running specs.
Dependencies
Update gemspec and Gemfile for modern Ruby and test tooling
The gemspec now requires Ruby 2.5 or higher and lists development dependencies for RSpec, Ammeter, Appraisal, and Bundler 2. The Gemfile has been refactored to move test dependencies (such as database\_cleaner, byebug, and codeclimate-test-reporter) into a dedicated test group, and the RubyGems source URL has been updated to use HTTPS.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 61 → 62 (+0.3)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 46 → 46 (+0.0)
- Readiness 74 → 74 (+0.0)
- Security 84 → 88 (+4.0)
Resolved (3)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1
New (4)
- Ambiguity between global configuration methods and specific adapter instances. Rolify.adapter() and Rolify.resource_adapter() are methods on the main module, but there are also distinct RoleAdapter and ResourceAdapter types. It is unclear if the module methods return the global singleton or if they are meant to be overridden by the specific adapter types. The naming adapter vs resource_adapter is also slightly inconsistent with the class names RoleAdapter vs ResourceAdapter.
- Off-boarding risk: anonymized user #1
- Proliferation of similar boolean check methods with subtle behavioral differences (strict vs cached) that are not immediately obvious from the signature alone. While distinct, the naming convention is verbose and error-prone for users.
- Redundant user class injection logic across multiple generator types. RolifyGenerator.ensure_user_class_defined and inject_user_class appear to handle the same concern (ensuring the User model exists/configured), while UserGenerator.inject_user_content likely performs the actual file modification. This creates confusion about which generator method is responsible for the final state of the User class.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
RolifyCommunity/rolify was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3d5234d9cbb98b8d8903b44931b37d65a6c5634f — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.