ruby-china/homeland
27.7
Weak · 28 September 2026
7.8k
lines of production code
Ruby
with JavaScript
2
measurements over time
What this system is
Homeland is a community discussion platform built on Rails 8 that facilitates topic-based conversations, user interactions, and content moderation. It supports real-time updates via ActionCable, role-based access control, and extensibility through a plugin architecture and Single Sign-On capabilities. The system manages user profiles, teams, and OAuth integrations while providing a comprehensive admin panel for site configuration and content oversight.
How it got here
2010 — Homeland rebrand and Rails 8 upgrade
29 changes.
The project was rebranded to Homeland and upgraded to Rails 8.0, involving a comprehensive modernization of the development environment, database schema, and frontend stack. This period focused on replacing legacy scaffolding and JavaScript libraries with a modern API-centric architecture, Tailwind CSS styling, and new organizational features like teams and push notifications.
2011–2016 — Authentication, real-time, and API overhaul
49 changes.
This period focused on modernizing the application's core infrastructure by integrating Devise for authentication, ActionCable for real-time updates, and ActiveJob for background processing. It also involved a comprehensive redesign of the user interface using Bootstrap and Tailwind CSS, alongside a major refactor of the API v3 to use Jbuilder and the introduction of a plugin system with SSO support.
2017–2020 — frontend modernization and architectural refactoring
38 changes.
This period focused on modernizing the frontend stack by migrating to Webpacker, Tailwind CSS, and ViewComponents, while introducing dark mode and improved admin styling. Concurrently, the backend underwent significant structural refactoring, breaking down large models and controllers into modular concerns and expanding comprehensive test coverage across the application.
Features
Add ERB scaffold generator
A new ERB-based scaffold generator has been added to the library, enabling users to generate standard MVC view templates (index, edit, show, new, \_form, and \_base) for controllers. This provides a dedicated code-generation path for ERB templates, distinct from other template engines.
lib/rails · high confidence
Add Markdown tutorial page with live preview
A new Markdown tutorial page has been added to the application, providing users with a side-by-side view of Markdown source code and its rendered HTML output. The page displays localized example content via the Homeland::Markdown helper and includes a cached view to improve performance. The layout utilizes Tailwind CSS utility classes for responsive design, replacing previous Bootstrap-based structures for this specific view.
app/views/home · high confidence
Add OAuth authorization UI views
The application now includes user-facing views for the OAuth 2 authorization flow. Users will see a new authorization screen to review and approve or deny requested scopes for third-party applications, an error page to display authorization failures, and a success page that displays the authorization code when no redirect URL is configured.
app/views/doorkeeper/authorizations · high confidence
Add Rails scaffold controller template
A new scaffold controller template has been added to the Rails template library. This template generates a standard RESTful controller with actions for index, show, new, edit, create, update, and destroy. It includes a before\_action callback to set the resource, uses pagination for the index action, and implements standard create/update/destroy logic with redirects and notices.
lib/templates/rails · high confidence
Add admin views for comments and locations management
The admin panel now includes dedicated views for managing comments and locations. Administrators can view a paginated list of comments (showing target, creator, body, and time) and locations (showing ID, name, and user count), as well as edit these records via forms with validation error display. Comment deletion is supported via a remote AJAX request that removes the row and displays a success notice.
app/views/admin/comments · high confidence
Add legacy JavaScript libraries to asset pipeline
The lib/assets directory now includes several standalone JavaScript libraries to support frontend functionality. These additions include Backbone.js (v1.1.2) for model-view-controller patterns, jQuery plugins for auto-growing textareas, hotkey handling, infinite scrolling, and a fluidbox lightbox effect, along with an autocomplete library (at.js) and a Google Analytics snippet.
lib/assets · high confidence
Add mention notification templates for comments, replies, and topics
New view templates have been added to the mentions notification partials to render notifications for comments, replies, and topics. These templates display the relevant content (comment body, reply body, or topic body) and provide links to the source (post, page, or topic) when available, handling cases where the source has been deleted by showing a 'source deleted' message.
app/views/notifications/mentions · high confidence
Add vendor assets for social sharing, Bootstrap, and tooltips
This change introduces several new vendor files to support frontend features. It adds a social share button implementation with support for Twitter, Facebook, Weibo, and WeChat (including QR code generation), along with their associated SVG icons and SCSS styles. It also adds Bootstrap JavaScript integration with Turbolinks event handling for bootstrap-select, the atwho CSS for autocomplete suggestions, jQuery Fluidbox CSS for image lightboxes, and the Tooltipster bundle SCSS for tooltip animations.
app/javascript/vendor · high confidence
Add welcome email template for new user registration
A new welcome email template has been added for newly registered users. The email greets the user by their full name, confirms their successful account registration, and provides a prominent button to log in to the application.
_app/views/user\mailer · high confidence
Added SSO controller supporting login and provider modes
A new SSO controller has been added to handle Single Sign-On flows, allowing users to log in via an external SSO provider or act as an SSO provider for other services. The controller includes endpoints to initiate the SSO process, handle the callback by creating or finding users and signing them in, and generate SSO payloads for authenticated users to share their identity with other applications.
app/controllers/auth · high confidence
Added resend confirmation email view
A new view for the 'Resend confirmation instructions' page has been added, allowing users to request a new confirmation email. The interface uses a centered card layout with a form field for the user's email address and a submit button to trigger the resend action.
app/views/devise/confirmations · high confidence
Admin OAuth application management UI with search and level configuration
The admin panel now includes a dedicated interface for managing OAuth applications, featuring a searchable list view that filters by application name and access token level, as well as edit and show views that allow administrators to modify application details and configure the application level, which controls the validity period of issued access tokens.
app/views/admin/applications · high confidence
Admin interface for installing and managing plugins
Administrators can now install, view, and uninstall plugins directly from the admin panel. The new Plugins section lists all active plugins with their versions and provides an 'Install' button to upload plugin zip files, as well as 'Uninstall' links for uninstallable plugins. A dedicated view displays plugin details, including source path, description, and associated links (navbar, user menu, admin panel).
app/views/admin/plugins · high confidence
Admin panel now supports managing and searching replies
Administrators can now view, search, edit, delete, and revert replies directly from the admin interface. The new replies index page includes search fields for title and username, displays reply details in a table, and provides actions to edit, delete, or revert deleted replies. A dedicated form allows editing reply content, and the interface integrates with the existing admin navigation and styling.
app/views/admin/topics · high confidence
Automated background jobs for data cleanup and user statistics
New scheduled jobs have been added to automatically manage data retention and update user metrics. The system now periodically removes expired Doorkeeper access tokens and grants, deletes notifications older than one year, and purges banned topics that are over a month old. Additionally, a new job updates users' monthly and yearly reply counts, and another job cleans up inactive online user statistics from Redis.
app/jobs/scheduler · high confidence
Introduce CanCanCan-based role system and new organizational features
The application now uses the CanCanCan gem to manage permissions, replacing the previous authorization logic with a structured \Ability\ class that defines roles for anonymous users, members, VIPs, maintainers, and admins. This change introduces support for new organizational structures, including \Team\ and \TeamUser\ models that allow users to create and manage groups with specific roles (owner, member). Additionally, a new \Device\ model is added to track user devices for push notifications, and the \Profile\ model is updated to support social contact fields and theme preferences. The \User\ model is also enhanced with new scopes and methods to support these organizational and tracking features.
app/models · high confidence
Introduce plugin system and SSO support
The application now supports a plugin architecture, allowing plugins to register themselves and appear in the main navigation, admin sidebar, and user menus. Additionally, Single Sign-On (SSO) functionality has been added, enabling the application to act as both an SSO client and provider for external authentication services.
lib · high confidence
Introduce team user management views
Adds the view layer for managing team members, including a new user form, an edit form, a list view with pagination, and a show view for accepting or rejecting pending invitations. The implementation uses Bootstrap 5 utility classes (e.g., flex, form-control) and integrates with the existing team header and error message partials.
_app/views/team\users · high confidence
Introduces new helpers for likes, topics, users, and teams while refactoring application helpers
This change introduces several new helper modules and significantly expands the application helper. New modules include LikesHelper (providing likeable\_tag for displaying like counts and states), LocationsHelper (for location name tags), TeamsHelper (for team member count displays), and TopicsHelper (adding tags for topic favoriting, following, titles, excellence status, closure status, and node names). UsersHelper is expanded with new tags for user names, avatars, levels, blocking nodes/users, following users, and rewarding users. ApplicationHelper gains a cached markdown rendering method, sanitization, admin/wiki/owner checks, timeago formatting, title tagging, mobile detection, code insertion menus, icon rendering, list rendering, search highlighting, social sharing configuration, and form group/error handling helpers. The old SectionsHelper is removed.
app/helpers · high confidence
Introduction of Dark Mode and modernized frontend asset pipeline
Users can now toggle a Dark Mode theme, which applies a comprehensive set of CSS variable overrides to the application's UI components including the navbar, cards, and forms. This capability is supported by a refactored frontend architecture that consolidates styles into a new SCSS variable system, integrates Tailwind CSS utilities alongside Bootstrap 5, and migrates JavaScript assets to Webpacker 6 with Turbolinks prefetching enabled.
app/javascript/homeland · high confidence
Like feature UI and interaction updates
The application now supports a 'Like' interaction on topics and user profiles. When a user likes an item, the interface updates to show a 'liked' state (changing the icon class to 'small\_liked' and setting the action to 'delete'). Conversely, unliking reverts the icon to 'small\_like' and sets the action to 'post'. Additionally, a popover view has been added to display avatars of users who have liked content.
app/views/likes · high confidence
Localized system event notifications for topic lifecycle actions
Users now see localized, structured notifications in reply threads for specific topic events, including bans (with optional reasons), closures, reopenings, excellent/unexcellent status changes, and mentions. These system replies are rendered via new partials in app/views/replies/system\_events that pull text from I18n keys, ensuring consistent and translatable messaging for topic state changes and interactions.
_app/views/replies/system\events · high confidence
New HTML pipeline filters for video embedding, image proxying, and mention handling
The application now includes a new set of HTML pipeline filters in lib/homeland/pipeline. The EmbedVideoFilter automatically converts URLs from YouTube, Vimeo, Youku, and Bilibili into embedded iframes. The ImageProxyFilter rewrites image sources through a configurable proxy URL. The MentionFilter and NormalizeMentionFilter handle user mentions (@user) by linking them and processing them in code blocks. The MarkdownFilter is updated to disable footnotes, support image dimensions, add rel=nofollow to external links, and fix autolinking issues with Chinese characters. The FloorFilter adds support for linking to specific post floors (e.g., \#1楼). The TwemojiFilter replaces emoji shortcodes with emoji images.
lib/homeland/pipeline · high confidence
New OAuth application management and revocation interfaces
Users can now manage their OAuth applications through a dedicated interface that lists their applications, authorized apps, and devices. The new ApplicationsController allows users to view, create, edit, and delete their own OAuth applications, while the AuthorizedApplicationsController enables them to revoke access tokens for specific authorized applications.
app/controllers/oauth · high confidence
New OAuth application management interface with user-facing controls
This change introduces a new set of views for managing OAuth applications within the user settings area. Users can now create and edit their own applications via a form that supports name, confidentiality, and redirect URI configuration. The main index page displays a table of the user's applications, including their client ID, assigned level, and the count of associated access tokens, alongside a list of authorized third-party apps that can be revoked. Additionally, the interface now includes a section for managing connected devices, allowing users to view platform details and delete active device tokens.
app/views/doorkeeper/applications · high confidence
New Rake tasks for version release and search reindexing
Two new Rake tasks have been added to the application's task library. The \release\ task (in \lib/tasks/release.rake\) automates the versioning process by creating a git tag based on \Homeland.version\ and pushing commits and tags to the origin remote, but is restricted to development and test environments. The \reindex\ task (in \lib/tasks/search.rake\) allows administrators to manually trigger a full reindexing of Topics, Users, and optionally Pages by calling their respective \reindex!\ methods.
lib/tasks · high confidence
New Reply modules for notifications and vote-based likes
The Reply model now includes two new concerns: Notify and Voteable. The Notify module triggers an asynchronous job to send notifications to topic followers, the reply author's followers, and the topic creator when a new reply is created, while also broadcasting the event via ActionCable. The Voteable module automatically likes the associated topic if the reply body starts with specific upvote characters (e.g., +1, 👍).
app/models/reply · high confidence
New admin interface for managing site configuration settings
Administrators can now manage site settings through a new dedicated interface in the admin panel. The settings are organized into groups with a list view that displays configuration keys, descriptions, and current values (such as the active timezone). The edit form supports various data types including text, numbers, booleans, and hashes, and provides specific dropdowns for timezones and mailer providers. A key feature is the ability to modify settings that require a server restart, which are clearly marked with a 'reboot required' badge to inform the user that the change will only take effect after a restart.
_app/views/admin/site\configs · high confidence
New model concerns for core functionality and compatibility
This change introduces a suite of new model concerns in app/models/concerns to support core application features and ensure backward compatibility. Key additions include Closeable for managing topic closure states, Mentionable and MentionTopic for handling user and topic mentions with associated notifications, and Countable/RedisCountable for tracking storage and view metrics. It also adds SoftDelete for non-destructive record deletion, Searchable for indexing, TopicReference for linking topics, and ScopedSetting for backward compatibility with RailsSettingsCached 0.x. Additionally, FakeSecondCache is provided to maintain plugin compatibility, while MarkdownBody, UserAvatarDelegate, and ScopedSetting support content rendering and user profile data.
app/models/concerns · high confidence
New scaffold templates for ERB views
Added new scaffold view templates for ERB-based Rails applications, including a form partial, index, show, new, and edit views. The index view now displays a table with attributes, creation time, and action links for editing and deleting records, while the form uses standard Bootstrap form-control classes. These templates provide a consistent structure for generating CRUD interfaces.
lib/templates/erb · high confidence
New shared UI partials for navigation, comments, and editor tools
The application now includes a set of new shared view templates in app/views/shared that standardize the user interface for key interactive areas. The main navigation (\_navbar) and user menu (\_usernav) have been restructured to support responsive layouts and integrate plugin-driven menu items. A new comment system (\_comment, \_comments) provides a consistent card-based layout for displaying and submitting comments. Additionally, a shared editor toolbar (\_editor\_toolbar) is now available to provide consistent formatting options (such as emoji, code insertion, and image upload) across different content types, and utility partials for error messages (\_error\_messages), hot locations (\_hot\_locations), and CAPTCHA input (\_captcha\_input) have been added to improve consistency and configuration flexibility.
app/views/shared · high confidence
New topic list action endpoints for popular, recent, and filtered views
A new \Topics::ListActions\ concern has been introduced to handle topic listing logic, adding dedicated endpoints for popular topics, topics with no replies, the most recently replied-to topics, user favorites, banned topics, and excellent topics. These actions allow users to browse topic lists filtered by specific criteria such as activity level, user preferences, or moderation status, with each view paginated and rendered via a shared index template.
app/controllers/topics · high confidence
Real-time notification and reply updates via ActionCable
Users now receive real-time updates for new replies on topics and changes to their notification counts without refreshing the page. This is enabled by two new ActionCable channels: \RepliesChannel\, which streams updates for specific topics, and \NotificationsChannel\, which streams the global notification count for the current user.
app/channels · high confidence
Support sub/sup tags and allow embedded videos in topics
The topic scrubber now permits the sub and sup HTML tags in post content, resolving the limitation that previously stripped these elements. Additionally, it allows iframes from specific video providers (YouTube, Vimeo, Youku, and Bilibili) by validating their source URLs, enabling users to embed videos directly in topic posts.
lib/homeland/sanitize · high confidence
Removals
Removed legacy application README template
The doc/README\_FOR\_APP file, which previously served as a template for introducing the application and pointing to API documentation generation instructions, has been deleted.
doc · high confidence
Architecture
Introduce ViewComponent-based UI architecture for core elements
The application replaces inline view templates with a new set of ViewComponents to standardize and modularize the user interface. This change introduces AlertComponent for flash messages, ProfileCardComponent for user profiles (including online status indicators), ReplyComponent and ReplyToComponent for thread discussions, and TopicComponent for topic listings. These components encapsulate rendering logic, helper delegation, and TailwindCSS styling, providing a consistent and maintainable structure for these key UI areas.
app/components · high confidence
Refactors Topic model into modular concerns
The Topic model has been reorganized into distinct concern modules (Actions, AutoCorrect, Notify, RateLimit, Search) to improve code structure and maintainability. This change introduces automatic title formatting via the AutoCorrect module, enforces topic creation rate limits using Redis caching, and streamlines notification logic for node changes and topic creation. It also consolidates moderation actions (ban, excellent) and search indexing logic into dedicated files, making the core Topic class cleaner and easier to extend.
app/models/topic · high confidence
Behavioural changes
API v3 serialization migrated to Jbuilder with updated response structures
The API v3 endpoints now use Jbuilder templates instead of the previous serialization approach, introducing several structural changes to the JSON responses. The user object no longer includes the 'bio' field (it is now returned as an empty string) to prevent spam misuse, and the topic object now includes a 'hits' count. Reply objects have gained an 'action' field and now include 'mention\_topic' details when the reply is a mention. Notification objects have been expanded to include 'mention\_type' and 'mention' details for mention-type notifications, and node objects now explicitly include 'section\_id' and 'section\_name'. Additionally, all topic, reply, and user objects now include an 'abilities' object indicating the current user's permissions (update, destroy, and topic-specific actions like ban/close).
app/views/api · high confidence
ActionCable connection authentication and base channel setup
The application now uses ActionCable for real-time communication, replacing the previous MessageBus implementation. A new base channel class (ApplicationCable::Channel) and connection class (ApplicationCable::Connection) have been introduced. The connection logic authenticates users by extracting their ID from signed cookies; if no valid user ID is found, the connection is rejected. This ensures that only authenticated users can establish WebSocket connections, while also providing basic logging for active connections upon disconnection.
_app/channels/application\cable · high confidence
Added localized Devise email templates for account confirmation, password reset, and unlock
The application now includes custom HTML email templates for Devise authentication events, written in Chinese. Users will receive specific notifications for account confirmation (with an activation link), password reset requests (with a link to edit the password), and account lockouts due to failed login attempts (with an unlock link). These templates replace any default Devise mailers, ensuring the messaging is consistent with the application's language and branding.
app/views/devise/mailer · high confidence
Added unlock request page with Bootstrap 4 styling
Users can now request a new unlock email via a dedicated page that uses Bootstrap 4 classes (flexbox, card components) for layout and styling. The form collects the user's email address and submits it to the unlock path, displaying localized text for the title, placeholder, and submit button.
app/views/devise/unlocks · high confidence
Added user-facing error pages for 403 and 404 responses
Users will now see dedicated, styled error pages when encountering access denied (403) or page not found (404) scenarios. The 403 page explains the lack of authority and encourages users to post questions in the community, while the 404 page provides a simple notification that the page was not found. Both pages are implemented as new ERB templates in the app/views/errors directory.
app/views/errors · high confidence
Admin dashboard now displays user online status and deprecated config warnings
The admin dashboard view has been updated to include a real-time count of currently online users alongside existing statistics for topics, replies, notifications, comments, and photos. It also now warns administrators if deprecated configuration environment variables are detected, suggesting the correct replacements. Additionally, the reboot action button has been restyled to float to the right, and the boot time display now respects the configured timezone.
app/views/admin/dashboards · high confidence
Admin panel node management UI updated to Bootstrap 5
The admin panel's node management views (index, new, edit) have been rewritten to use Bootstrap 5 styling classes, replacing the previous Bootstrap 4 implementation. This includes updated form controls, table styling, and button classes to align with the new framework version, ensuring consistent visual presentation and improved usability for administrators managing nodes.
app/views/admin/nodes · high confidence
Admin panel restructured with new controllers and enhanced moderation capabilities
The admin panel has been reorganized into a dedicated \Admin\ namespace with a base controller enforcing admin authentication and layout. This change introduces granular controllers for managing applications (including OAuth/Doorkeeper settings), plugins (install/uninstall with reboot), and site configurations (grouped by scope, with restart requirements). Moderation capabilities are expanded: admins can now revert soft-deleted topics and replies, suggest/unpin topics, and perform batch deletions of a user's recent 10 items (replies, topics, photos, notes) via the user edit page. User management now supports searching by tagline and differentiating between user and team types. The dashboard includes a reboot feature, and stats are exposed via JSON API.
app/controllers/admin · high confidence
Admin panel styling overhaul with Tailwind and dark mode support
The admin interface has been restyled to improve visual consistency and usability. The new styles integrate Tailwind CSS utilities and enable dark mode support for the admin area. Specific improvements include refined table layouts with distinct styling for deleted and banned users, updated navigation bar spacing and active states, and adjusted typography for headers, stats, and plugin items. These changes enhance the readability and modern appearance of the admin dashboard.
app/javascript/admin · high confidence
Admin photos list view with search and card layout
The admin photos interface now displays photos in a card-based layout with a username search filter. Users can search for photos by entering a username in the provided input field, and the results are paginated. Each photo card shows a thumbnail, links to the user's edit page, and includes a delete button that removes the photo via an AJAX request without reloading the page.
app/views/admin/photos · high confidence
Admin user management interface restructured with new editing and search capabilities
The admin panel's user management section has been reorganized into a new set of view templates (\_form, \_user, index, edit, new, destroy). Administrators can now edit user profiles via a dedicated form that supports conditional fields based on settings (location, github, twitter, company, tagline, website) and displays read-only sign-in metadata. The user list view includes a toolbar for searching by username, email, name, or tagline, filtering by type (All/Team) and state, and pagination. The edit page adds specific bulk-cleanup actions to delete a user's recent 10 photos, topics, replies, or notes. User rows in the list display avatar, name, bio, tagline, topic/reply counts, and allow inline banning or editing.
app/views/admin/users · high confidence
Database schema modernization and structural cleanup
This update overhauls the database schema to support modern application features and improve data integrity. Key changes include enabling email confirmation for user accounts via Devise, replacing the legacy notification system with the \notifications\ gem, and migrating user profile data (contacts, rewards, preferences) to a dedicated \profiles\ table using JSONB storage. The schema also introduces support for team-based content organization, device tokens for push notifications, and PostgreSQL full-text search via \search\_documents\. Additionally, legacy fields and tables such as \sections\, \body\_html\, and various array-based action fields have been removed or consolidated, and strict uniqueness constraints are now enforced on user login and email addresses.
db/migrate · high confidence
Database schema modernized with new tables and Rails 8.0 compatibility
The database schema has been significantly updated to support new features and align with Rails 8.0. New tables include \actions\ to replace legacy array-based fields for likes, follows, and blocks; \devices\ to store push notification tokens; \notes\ for the standalone notebook feature; and \notifications\ to replace previous notification logic. The schema also introduces \authorizations\ for OAuth/SSO, \comments\ for general commenting, \exception\_tracks\ for error logging, and \locations\ for user geography. Legacy structures like \sections\ and \replies\ have been removed or refactored, and the \counters\ table now uses polymorphic associations. Seed data has been simplified to initialize default nodes.
db · high confidence
Front-end JavaScript bundled with Webpack and restructured
The front-end JavaScript application has been migrated to use Webpack for module bundling, introducing a new entry point in app/javascript/front/app.js that initializes the main application view, comment editor, and real-time notification channels. This change restructures the client-side codebase to support modern asset pipelines and includes updates to the emoji data library and editor components to improve image handling and user interface interactions.
app/javascript/front · high confidence
Homeland version 3.11.0 release
This update releases Homeland version 3.11.0. The diff introduces several core library components including a new plugin management system (supporting install/uninstall via zip and admin navigation links), a refactored Markdown pipeline with auto-correction and video embedding, a PostgreSQL-based search implementation replacing previous engines, and Single Sign-On (SSO) capabilities. It also adds utilities for image thumbnail generation, HTML sanitization, and username handling.
lib/homeland · high confidence
Introduce ActionMailer-based email system with dynamic settings and welcome notifications
The application now uses ActionMailer for sending emails, replacing the previous implementation. A new ApplicationMailer base class overrides the mail method to dynamically apply sender, provider, and delivery options from the application settings at runtime, and includes error handling for inactive recipients. A new UserMailer provides a welcome email feature that sends a notification to newly registered users, utilizing the application's configured mailer settings.
app/mailers · high confidence
Introduce ActiveJob-based asynchronous processing for notifications and references
The application now uses ActiveJob to handle background tasks asynchronously, replacing previous synchronous or ad-hoc mechanisms. Lightweight jobs, such as updating topic read status and processing topic references, run in-process using the AsyncAdapter for lower latency, while notification and push jobs (including APNs support) are queued to dedicated channels. This change ensures that actions like mentioning topics, notifying followers, and sending push notifications do not block the main request thread, improving responsiveness and reliability for users interacting with topics and replies.
app/jobs · high confidence
Migrate frontend asset pipeline to Webpacker 6 and Tailwind CSS
The frontend build system has been upgraded to Webpacker 6, introducing a new JavaScript entry point (application.js) that explicitly loads vendor dependencies like Bootstrap alongside application modules. The styling architecture is shifting towards Tailwind CSS, evidenced by the new SCSS entry points (admin.scss, front.scss, turbolinks-app.scss) which import modular index files and the Tailwind application configuration. A jsconfig.json file has also been added to support IDE navigation within the new module structure.
app/javascript · high confidence
Migrate image uploaders to Carrierwave with cloud provider thumbnail support
The application has replaced the previous image upload implementation with Carrierwave, introducing new \AvatarUploader\, \PhotoUploader\, and \BaseUploader\ classes. This change enables automatic image resizing into multiple versions (xs, sm, md, lg, large) and integrates native thumbnail processing for Aliyun OSS, Qiniu, and Upyun storage providers, while enforcing strict allowlists for image extensions (jpg, jpeg, gif, png) and content types to prevent invalid uploads.
app/uploaders · high confidence
Migrate to Shakapacker with custom Webpack configuration
The project has migrated from webpacker to Shakapacker (v8.4.0), introducing a new Webpack configuration structure. This includes custom environment settings that merge provider plugins for jQuery, enable ERB template loading via rails-erb-loader, and configure chunk splitting for vendor assets. The setup also defines custom module resolution extensions to support TypeScript and ERB-embedded JavaScript files.
config/webpack · high confidence
New comment display and submission UI
The application now uses a new partial for rendering comments, displaying the user's avatar, name, and timestamp alongside the pre-rendered HTML body. Additionally, a new JavaScript view handles comment creation via AJAX, appending the new comment to the relevant container, clearing the input field, and handling success or failure states.
app/views/comments · high confidence
New notification templates for comments, replies, follows, and team invites
The notification view layer has been updated with new partials to render specific notification types more clearly. Users will now see dedicated templates for comment notifications (including support for Posts and Pages via homeland\_press and homeland\_wiki), topic replies, user follows, node changes, and team invites. These templates handle cases where the source content has been deleted by displaying a 'source deleted' message, and they provide structured headings and summaries for active notifications.
app/views/notifications · high confidence
New notifications controller with daily grouping and pagination
A new NotificationsController has been added to handle the display and management of user notifications. The index action now groups notifications by the date they were created, orders them by ID, and implements pagination using the Kaminari gem (replacing the previous WillPaginate implementation). It also preloads the associated actor data to optimize queries. The controller exposes endpoints to mark specific notifications as read and to delete all notifications for the current user.
app/controllers/notifications · high confidence
New user registration view with OAuth pre-fill and captcha support
The registration page now supports pre-filling user details (email, name, login) from OAuth providers during sign-up, displays a specific alert for users completing their profile via OAuth, and includes a captcha input field to enhance security during account creation.
app/views/devise/registrations · high confidence
Nginx configuration is now generated from ERB templates
The Nginx setup has been refactored to use ERB templates (nginx.conf.erb and homeland.conf.erb) instead of static configuration files. A new build script (config/nginx/build) generates the final configuration files at runtime, allowing environment variables like NGINX\_WORKER\_CONNECTIONS and client\_max\_body\_size to be injected directly into the Nginx settings. This change also introduces a start script that ensures necessary directories exist before launching Nginx with the generated configuration.
config/nginx · high confidence
Pagination UI updated to use Kaminari with Bootstrap 4 styling
The pagination component has been replaced with Kaminari and restyled for Bootstrap 4. Users will now see pagination controls rendered as standard Bootstrap list items (using classes like \page-item\ and \page-link\) with Font Awesome icons for the previous and next buttons. This change ensures the pagination bar displays correctly on mobile devices and within plugins, fixing issues where buttons were previously missing or broken.
app/views/kaminari · high confidence
Project rebranding to Homeland and modernization of development environment
The project has been rebranded from Ruby China to Homeland, introducing a new Docker-based development workflow with docker-compose and a Makefile, and adopting Tailwind CSS for styling. The setup now requires Ruby 3.1+ and includes updated configuration files (.env, .rubocop.yml) and documentation (CONTRIBUTE.md, README.md) to reflect these changes.
(repo-wide) · high confidence
Rails 8.0 environment configuration defaults
The development, production, and test environment configurations have been updated to align with Rails 8.0 defaults. Key changes include replacing \cache\_classes\ with \enable\_reloading\ and \eager\_load\, enabling server timing and verbose query logging in development, configuring Action Cable origins via the \Setting\ model in production, and switching the test cache store to \:memory\_store\. Additionally, the application class has been updated from \Homeland::Application\ to \Rails.application\ across all environment files.
config/environments · high confidence
Rails 8.0 upgrade and configuration overhaul
The application has been upgraded to Rails 8.0, bringing significant changes to the configuration landscape. The database adapter has switched from MySQL/SQLite to PostgreSQL, and the caching system now uses Redis with a defined namespace and expiration. The asset pipeline has moved to Shakapacker (Webpacker), and the web server configuration now supports Puma with Solid Queue integration and PumaWorkerKiller for memory management. Additionally, the application now uses Sidekiq for background jobs with a defined queue priority system, and the routing structure has been completely rewritten to support new features like OAuth (Doorkeeper), SSO, and an expanded admin panel.
config · high confidence
Rails asset pipeline configuration file relocated
The asset manifest configuration file has been moved from the internal tasks directory to the standard assets config directory, aligning the project structure with current Rails conventions for asset pipeline management.
app/assets · medium confidence
Redesign of password reset and update views with modern UI and security enhancements
The password reset (new) and password update (edit) views have been completely rewritten to use a modern, responsive card-based layout. The password reset form now includes a CAPTCHA challenge to prevent abuse and provides helpful text for users. Both forms utilize Bootstrap styling for improved aesthetics and usability. Additionally, the submit buttons now include a 'disable-with' attribute to prevent duplicate submissions during network latency, enhancing the user experience and preventing potential data integrity issues.
app/views/devise/passwords · high confidence
Redesign of topic listing and detail pages with new moderation and reference features
The topic views have been completely redesigned to modernize the user interface and introduce new community management capabilities. The topic list and detail pages now use a card-based layout with a dedicated sidebar, replacing the previous table and simple list structures. A new moderation workflow allows administrators to ban topics via a modal dialog that supports predefined reasons or custom text, with the ban reason displayed prominently on the topic page. Additionally, a new 'References' section on the topic detail page allows users to view topics that cite the current one and those cited by it. The topic creation and editing forms have been streamlined with a new node selector and team support, while the reply form now includes an integrated editor toolbar and keyboard shortcuts. The topic index page also features a new sidebar with active users and statistics, and the topic detail page now displays a 'References' tab and a ban alert if the topic is banned.
app/views/topics · high confidence
Redesign user profile and list pages with new layout and features
The user profile and list views have been completely redesigned. The profile page now features a sidebar with user details (avatar, stats, social links, online status) and a main content area with tabbed navigation for topics, replies, favorites, and followers. New partials support displaying user contacts, recent topics, and GitHub repositories. The user list page now displays active users in a card-based layout with filtering by yearly or monthly activity. The old CRUD-style forms and index pages have been removed.
app/views/users · high confidence
Redesigned admin panel layout and new email template
The admin panel now uses a dedicated layout (admin.html.erb) featuring a responsive navbar with plugin support and a prominent alert banner that prompts administrators to reboot the application when configuration changes require it. A new email layout (mailer.html.erb) provides a consistent, styled template for system notifications. The main application layout (application.html.erb) has been significantly expanded to include PWA support (manifest, theme colors), improved SEO meta tags, and a more robust JavaScript configuration block.
app/views/layouts · high confidence
Redesigned login page with Tailwind CSS and OAuth integration
The login view has been completely rewritten to use a modern, responsive layout based on Tailwind CSS classes (e.g., flexbox, card components) instead of the previous styling. The page now features a split layout with the login form on the left and navigation links on the right. It includes a 'Remember me' checkbox and a submit button with duplicate-submission protection via the 'data-disable-with' attribute. Additionally, if any OAuth providers are configured in the application settings, the page dynamically renders a section with buttons for third-party login services (such as GitHub, Twitter, etc.), allowing users to authenticate via those providers directly from the login screen.
app/views/devise/sessions · high confidence
Redesigned notifications page with daily grouping and caching
The notifications interface has been updated to group notifications by day, displaying a date header for each group, and now includes a 'Clean All' button to bulk-delete notifications. The rendering logic uses fragment caching keyed by the notification's read status and actor to improve performance, and the view automatically marks unread notifications as read upon page load via a background AJAX request.
app/views/notifications/notifications · high confidence
Redesigned search results page with unified result cards
The search interface has been updated to display results using a new card-based layout. The main index page now shows a total record count and renders specific partials for different content types: topics display their title, URL, creation date, and highlighted content; users show their avatar, name, level, bio, and activity stats; teams display their avatar, name, and bio; and wiki pages (if the homeland\_wiki plugin is active) show the page title, URL, update date, and content snippet. This change replaces the previous search view structure with a consistent, styled presentation for all searchable entities.
app/views/search · high confidence
Redesigned team pages with new layout and components
The team pages (show, index, new, edit) have been completely rewritten to use a modern layout structure. The show page now features a dedicated header partial displaying team details and social links, alongside a sidebar showing recent members and repositories, while the main content area renders topics via a ViewComponent. The index page utilizes a new team list partial for displaying active teams, and the new/edit forms have been restructured with updated styling and layout classes to improve responsiveness and visual consistency.
app/views/teams · high confidence
Refactor ApplicationController into modular concerns
The application controller logic has been reorganized into five distinct modules (CurrentInfo, Deviseable, Localize, Turbolinks, UserNotifications) to improve maintainability. This change introduces automatic tracking of request IDs and current users, enhances authentication handling for OAuth and Devise (including specific parameter permitting for sign-up/sign-in), refines locale detection to support HTTP header-based auto-detection, adds helper methods for identifying Turbolinks app versions, and exposes unread notification counts to views.
_app/controllers/application\controller · high confidence
Refactor controllers to modernize API responses and remove legacy scaffolding
The controllers in app/controllers have been significantly refactored to remove legacy scaffold-style code (such as XML format support and generic CRUD actions) and adopt a more modern, API-centric approach. Key changes include: replacing generic index/show actions with specific, optimized logic (e.g., TopicsController now uses \topics\_scope\ and includes association loading for performance); converting Node and User controllers to return JSON responses for list and block/unblock actions; introducing new controllers for Comments, Devices, Likes, Photos, Search, Settings, and Teams to handle specific user features like account management, team membership, and media uploads; and updating ApplicationController to include new modules for localization, user notifications, and ETag caching, while also standardizing error handling with \rescue\_from\ for 404 and 403 errors. The SectionsController has been removed entirely.
app/controllers · high confidence
Refactored user authentication, registration, and profile interaction logic
The user management controllers and shared behaviors have been restructured to support OAuth account binding and improved security. The new OmniauthCallbacksController handles social login flows, allowing users to sign up or bind existing accounts via OAuth providers. Registration and session controllers now enforce IP-based sign-up limits and require CAPTCHA verification, while sessions automatically link OAuth credentials to local accounts upon successful login. Additionally, user profile interactions (follow, block, topic viewing) and team topic listings are now managed through dedicated concern modules (UserActions, TeamActions), separating concerns for individual users versus team entities.
app/controllers/users · high confidence
Removal of default scaffold CSS styles
The default scaffold stylesheet (scaffold.css) has been removed from the public stylesheets directory. This means the application will no longer automatically apply the generic default styling for forms, error messages, and layout elements that were previously provided by this file, likely requiring custom styles or a different stylesheet to maintain the visual presentation of these UI components.
public/stylesheets · high confidence
Removal of legacy Node and Section view templates
The default Rails scaffold views for Nodes and Sections have been removed. This includes the index, show, new, edit, and partial form templates for both resources, eliminating the standard CRUD interface for managing nodes and sections through these specific view files.
app/views/nodes, app/views/sections · high confidence
Removal of legacy script/rails entry point
The legacy \script/rails\ executable has been removed from the project. This file previously served as the entry point for running Rails commands from the application root when using Rails 3 gems; its removal indicates a shift to standard Rails 3 conventions where commands are typically invoked via the \rails\ binary directly or through \bin/rails\.
script · high confidence
Removal of vendor/plugins directory
The vendor/plugins directory has been removed from the project. This indicates that the application is no longer using the legacy Rails plugin system for third-party extensions, likely as part of a migration to modern dependency management or bundler-based gem inclusion.
vendor · high confidence
Removed legacy Prototype and script.aculo.us JavaScript libraries
The application has removed the legacy client-side JavaScript dependencies, specifically Prototype (v1.7\_rc2) and script.aculo.us (v1.8.3), along with the associated \rails.js\ UJS helper. This cleanup eliminates the autocompletion, drag-and-drop, and visual effects capabilities previously provided by these libraries, as well as the AJAX form handling and remote link support implemented in \rails.js\. Users will no longer have access to these interactive UI features in the public-facing application.
public/javascripts · high confidence
Replies are now edited and created via AJAX with a modern UI
The reply editing interface has been completely redesigned: the previous scaffold-style form is replaced by a card-based layout with an integrated editor toolbar, and submissions are now handled via AJAX (remote forms) instead of full page reloads. Creating a new reply also uses AJAX, appending the new reply to the topic view and updating reply counts without navigating away. Additionally, the standalone reply listing page has been removed, as replies are now managed exclusively within the context of their topics.
app/views/replies · high confidence
Rewrite of API v3 controllers to use Rails API and jbuilder
The API v3 controllers (including endpoints for topics, users, replies, notifications, likes, nodes, photos, and devices) have been rewritten to inherit from a new \Api::V3::ApplicationController\. This base controller now extends \ActionController::Base\ instead of \ActionController::API\ to resolve jbuilder compatibility issues, while still providing API-specific features like CSRF token skipping and OAuth authorization. The change also introduces custom error handling for parameter validation and access denial, and standardizes the response format across all v3 endpoints.
app/controllers/api · high confidence
Session expiration extended to 90 days
The application now keeps users logged in for 90 days by default, up from the previous 30-day limit. This change is implemented in the session store initializer by setting the cookie expiration to 7,776,000 seconds (90 days), ensuring that returning users do not need to re-authenticate as frequently.
config/initializers · high confidence
Settings page restructured into dedicated sub-pages
The settings interface has been reorganized from a single page into distinct sub-pages for Profile, Account, Password, and Rewards, accessible via a new sidebar navigation menu. This change introduces specific views for managing user profile details (including location, company, and social links), account deletion and OAuth authorization bindings, password updates, and reward QR code uploads, while also adding a theme selector (auto/light/dark) and login change options to the main profile section.
app/views/settings · high confidence
Standardized authentication navigation links with Bootstrap styling
The shared authentication navigation partial now renders login, registration, password recovery, email confirmation, and account unlock links using a consistent Bootstrap list-group layout. This change ensures that the user-facing navigation for signing in, registering, and managing account access is visually aligned with the Bootstrap v4 design system and dynamically displays only the relevant options based on the current Devise configuration.
app/views/devise/shared · high confidence
Standardized development and deployment bin scripts
The application now ships with a comprehensive set of standardized bin scripts to streamline local development and deployment. This includes updated Rails binstubs (rails, rake, bundle) and new tools for asset management (shakapacker, shakapacker-dev-server) and process management (dev, spring, thrust). A new provision.sh script automates the installation of system dependencies like PostgreSQL and Redis, while setup and update scripts handle dependency installation, database configuration, and migrations, providing a consistent entry point for developers to get the environment running.
bin · high confidence
Update authentication menu to use Devise and display user login name
The application's navigation menu has been updated to support the new Devise authentication system. Logged-in users now see their login name (instead of full name) in the header, along with links to settings and the admin panel (if they have admin privileges). The menu also provides clear links for logging out, logging in, and registering for a new account.
app/views/devise/menu · high confidence
Updated error pages and robots.txt configuration
The public error pages (400, 404, 406, 422, 500) have been redesigned with a modern, responsive layout and updated content, including Chinese text for the 404 and 500 errors. A new 406 'Unsupported Browser' page has been added. The default Rails welcome page (index.html) has been removed, and a new SVG icon has been added. Additionally, the robots.txt file has been updated to disallow crawling of the /cable path.
public · high confidence
User model refactored into modular concerns with new online tracking and GitHub repository features
The User model has been restructured into separate concern modules (avatar, blockable, deviseable, followable, github\_repository, likeable, profile\_fields, redis\_online\_trackable, reward\_fields, roles, soft\_delete, topic\_actions) to improve maintainability. This change introduces several new capabilities: users can now track their online status via Redis, fetch and display up to 10 GitHub repositories on their profile, and manage social contact information and reward settings (Alipay, WeChat) through a new profile system. Authentication is enhanced with Devise's confirmable and omniauthable modules, supporting GitHub OAuth login and registration. Avatar handling is improved with automatic removal on soft-delete and a fallback to letter avatars. User roles and permissions are now managed through a state enum and helper methods (admin?, wiki\_editor?, etc.). Topic reading status is tracked with caching for performance.
app/models/user · high confidence
Test coverage
Add test plugin for i18n verification; Added FactoryBot definitions for core domain models; Added controller tests for core application features; Added controller tests for user authentication flows; Added integration tests for OAuth2 flows and user login scenarios; Added test coverage for API V3 controllers; Added test coverage for admin controller endpoints; Added test coverage for application, likes, locations, topics, and users helpers; Added test coverage for job execution and cleanup logic; Added test coverage for model concerns; Added test coverage for new ViewComponent-based UI components; Added test coverage for user avatar, online status, and profile features; Added test fixtures for file upload testing; Added test support helpers for API integration and database setup; Added tests for SSO authentication controller; Added tests for avatar and photo uploader validation; Added tests for plugin loading, registration, and settings; Added unit tests for lib utilities; Initial model test suite with Minitest; Migrate test suite to Minitest and enable parallel execution; Removed legacy Test::Unit functional tests for core controllers; Removed placeholder unit tests during RSpec migration; Updated test fixtures for HTML/text rendering and removed obsolete YAML fixtures.
Dependencies
Major platform upgrade to Rails 8 and Bootstrap 5
The application has been upgraded from Rails 3.0 to Rails 8, bringing significant performance improvements, modern security defaults, and updated API behaviors. The frontend stack has been modernized by upgrading Bootstrap from version 2 to 5.3 and migrating the asset pipeline to use Shakapacker (Webpacker) with TailwindCSS support. Additionally, the database driver has switched from SQLite to PostgreSQL, and the web server has been updated from Unicorn to Puma.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 31 → 28 (-3.3)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 44 → 44 (-0.1)
- Architecture 100 → 75 (-24.5)
- Maturity 33 → 33 (+0.0)
- Readiness 18 → 17 (-1.3)
- Security 43 → 57 (+13.7)
- Domain Modelling 54 → 54 (+0.0)
- Accessibility 64 → 30 (-34.2)
Resolved (62)
- Change coupling: production.rb ↔ test.rb (config/environments/production.rb)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- …and 42 more
New (10)
- FileTooLong: javascripts/jquery.mobile-events.js (lib/assets/javascripts/jquery.mobile-events.js)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High vulnerability: [GHSA redacted] (yarn.lock)
- Medium: security finding (details withheld)
- No ADRs found
- Outdated: rails-settings-cached
- Projects may be oversized for their cohesion
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ruby-china/homeland was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0bad08a46d205544af189fa53d1b70a2b32a1e20 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.