Skip to content
CAI
Software that uses CAICheck a score

scambra/devise_invitable

69.4

Adequate · 19 September 2026

858

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Ruby gem that extends the Devise authentication library to support user invitation workflows. It provides controllers, models, and views to handle sending, accepting, and managing invitations, including configurable expiration, limits, and auto-sign-in behaviors. The gem supports multiple ORM backends like ActiveRecord and Mongoid, and includes generators to streamline integration into Rails applications.

How it got here

2009 — Devise Invitable release and CI migration

11 changes.

This period focused on the initial release of the Devise Invitable module, establishing its core configuration, architecture, and comprehensive test suite. Concurrently, the project modernized its build infrastructure by migrating to GitLab CI and updating gem management tools.

2010 — Devise Invitations feature implementation

13 changes.

This period focused on implementing the core invitation workflow for Devise, including the creation of controllers, views, and generators to streamline integration. The work established the foundational logic for sending, accepting, and managing invitations, supported by comprehensive test coverage for mailers, ORM compatibility, and integration flows.

2011–2022 — Rails 8.0 support and security hardening

11 changes.

This period focused on extending compatibility to Rails 8.0 and adding Mongoid generator support, while significantly expanding test coverage for controllers and views. Security was addressed by hiding sensitive invitation attributes from serialization, and user experience was improved by automatically confirming invited users during registration.

Features

Add Mongoid generator for Devise Invitable

A new generator class for Devise Invitable has been added to support Mongoid. This file defines the \Mongoid::Generators::DeviseInvitableGenerator\ which inherits from \Rails::Generators::NamedBase\ and includes the necessary ORM helpers, enabling users to generate Devise Invitable components specifically tailored for Mongoid-backed applications.

lib/generators/mongoid · high confidence

Add invitation acceptance and creation views with configurable password requirements

The invitation workflow now includes dedicated views for accepting an invitation (edit.html.erb) and creating a new invitation (new.html.erb). The acceptance view conditionally renders password and password confirmation fields based on the require\_password\_on\_accepting configuration, and sets the invitation token field to readonly to prevent browser autofill issues. The creation view supports multiple invite key fields by iterating over invite\_key\_fields, allowing flexible identification of invitees.

app/views/devise/invitations · high confidence

Initial release of Devise Invitable module

This change introduces the core configuration and module structure for the new Devise Invitable feature. It adds a set of configurable options to the Devise initializer, including \invite\_for\ (token validity period), \validate\_on\_invite\ (whether to validate the record before sending), \invitation\_limit\, \invite\_key\ (the field used to identify users, defaulting to email), \resend\_invitation\, \invited\_by\_class\_name\ (to support non-polymorphic inviting models), \invited\_by\_foreign\_key\, \invited\_by\_counter\_cache\, \allow\_insecure\_sign\_in\_after\_accept\ (auto-login behavior), and \require\_password\_on\_accepting\. It also registers the \:invitable\ module with Devise, defining the associated controllers, models, and routes for invitation management.

lib · high confidence

New Devise Invitations Controller Implementation

This change introduces the \Devise::InvitationsController\ to handle user invitation workflows, including sending, accepting, and removing invitations. The controller enforces authentication for senders via \authenticate\_inviter!\, checks invitation limits, and manages the acceptance flow with support for secure sign-in after acceptance. It integrates with Devise's parameter sanitization for security and provides customizable redirect paths after inviting, accepting, or signing out.

app/controllers/devise · high confidence

New Rails generators for installation, model setup, and views

The gem now provides dedicated Rails generators to streamline integration: the install generator adds commented configuration options (such as invite expiration, invitation limits, and auto-sign-in settings) to the Devise initializer and copies locale files; the model generator injects the :invitable directive into existing models and triggers ORM-specific migrations; and the views generator copies invitation and mailer templates to the application, supporting both SimpleForm and standard FormBuilder. These tools replace manual setup steps, ensuring consistent configuration and view scaffolding for new installations.

_lib/generators/devise\invitable · high confidence

Behavioural changes

Devise Invitable updated to version 2.0.12

The gem has been upgraded to version 2.0.12, introducing a refactored architecture that separates concerns into dedicated modules for the inviter logic, mailer, and parameter sanitization. This update ensures compatibility with modern Devise versions by using \Devise.mailer\ instead of \Devise::Mailer\, integrating with Devise's parameter sanitizer for strong parameters support, and adjusting the Rails engine initialization to use \to\_prepare\ hooks for reliable mailer inclusion during development and reloading.

_lib/devise\invitable · high confidence

Hide invitable attributes from serialization and inspection

The \invitation\_token\, \invitation\_created\_at\, \invitation\_sent\_at\, \invitation\_accepted\_at\, \invitation\_limit\, \invited\_by\_type\, \invited\_by\_id\, and \invitations\_count\ attributes are now explicitly added to the serialization blacklist (either \UNSAFE\_ATTRIBUTES\_FOR\_SERIALIZATION\ or \BLACKLIST\_FOR\_SERIALIZATION\, depending on availability). This ensures these sensitive invitation-related fields are excluded from object serialization and inspection outputs, addressing security and privacy concerns raised in issue \#735.

_lib/devise\invitable/models · high confidence

Invitation email templates now display expiration due dates

The invitation email templates (HTML and plain text) have been updated to include a message indicating when an invitation expires. If the invited resource has an \invitation\_due\_at\ date set, the email will now display a localized 'accept until' message showing that specific due date, ensuring users are aware of the invitation's validity period.

app/views/devise/mailer · high confidence

Invited users are now confirmed and accepted during registration

The new DeviseInvitable::RegistrationsController overrides the build\_resource method to automatically accept invitations and send confirmation instructions when an invited user registers. This ensures that invited users are fully activated and receive their confirmation email immediately upon completing the registration process, rather than requiring a separate confirmation step.

_app/controllers/devise\invitable · high confidence

Migrate CI to GitLab Dependency Scanning and update build infrastructure

The project replaces its previous CI configuration with a new GitLab CI pipeline (.gitlab-ci.yml) that runs dependency scanning using the official GitLab security products image. The build infrastructure is modernized by removing the Jeweler gem in favor of Bundler for gem management, updating test file patterns to \*\_test.rb, and adding a Rake task to run tests across all configured ORMs. Documentation is consolidated by replacing the Rdoc README with a Markdown version, and the .gitignore is updated to exclude generated test artifacts and lock files.

(repo-wide) · high confidence

Migration template now includes Rails version for Rails 5+

The ActiveRecord generator for devise\_invitable now appends the current Rails version (e.g., \[5.0\]) to the generated migration filename when running on Rails 5 or later. This ensures migration files are correctly versioned and avoids conflicts with other migrations, addressing issues where the extension or naming might otherwise be ambiguous in newer Rails versions.

_lib/generators/active\record · high confidence

Standardize invitation acceptance paths and authentication

The controller helpers now define default behavior for post-invitation and post-acceptance redirects, sending users to the signed-in root path in both cases. A new helper method allows customizing the path displayed when an invitation token is invalid, defaulting to the sign-out path. Additionally, the internal authentication method for the inviter has been renamed to authenticate\_inviter! to better reflect its purpose and align with Devise core conventions.

_lib/devise\invitable/controllers · high confidence

Updated migration template for Devise Invitable

The ActiveRecord migration generator template has been updated to include new columns for tracking invitation lifecycle and limits. Users generating migrations will now see \invitation\_created\_at\, \invitation\_sent\_at\, \invitation\_accepted\_at\, \invitation\_limit\, and \invitations\_count\ columns added to their tables, along with a polymorphic \invited\_by\ reference. The template also ensures proper indexing on \invitation\_token\ and \invited\_by\_id\, and provides a corresponding \down\ migration to remove these fields cleanly.

_lib/generators/active\record/templates · high confidence

Updated simple\_form templates for invitation views

The simple\_form templates for the invitation edit and new views have been updated to use \f.button :submit\ instead of the previous implementation. This change ensures that the generated submit buttons include the standard \btn\ CSS class when used with simple\_form, providing consistent styling for the invitation acceptance and creation forms.

_lib/generators/devise\invitable/templates · high confidence

Test coverage

Add ORM test configuration for ActiveRecord and Mongoid; Added ApplicationHelper stub in test app; Added environment configuration files for the test Rails application; Added functional tests for controller helpers and registration flows; Added integration tests for invitation removal and acceptance flows; Added layout template for the Rails test application; Added model tests for invitation lifecycle and token management; Added test application configuration for Rails 5 and Devise integration; Added test application controllers for Devise integration scenarios; Added test application initializer configuration files; Added test application models for Devise integration testing; Added test coverage for user invitation view; Added test database schema for Rails 5.1 compatibility; Added test infrastructure for Rails 3.2 and Mongoid; Added test suite for generators, models, and routes; Added test view for admin invitation form; Added test view for free invitation form; Added test view template for Devise sessions; Added tests for the invitation mailer.

Dependencies

Add test dependency files for Rails 6.1 through 8.0

New Gemfile variants have been added to the gemfiles directory to support testing against Rails versions 6.1, 7.0, 7.1, 7.2, and 8.0, as well as the Rails main branch. These files configure the necessary test dependencies, including specific versions of ActiveRecord, ActionMailer, and Devise, and address compatibility requirements such as pinning concurrent-ruby for earlier versions and updating sqlite3 for Rails 8.0.

gemfiles · high confidence

Housekeeping

Added placeholder file in tmp directory

A .gitkeep file was added to the tmp directory to ensure the directory is tracked by version control.

tmp · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 69.

Lenses

  • Code Health 100
  • Architecture 69
  • Maturity 61
  • Readiness 77
  • Security 93

Changes since last survey

  • 300 commits — 242 feature/other, 58 fixes

By area

  • (root) — 151 commits
  • lib/devise_invitable — 33 commits
  • (repo) — 27 commits
  • config/locales — 20 commits
  • .github/workflows — 12 commits
  • app/controllers — 11 commits
  • test/test_helper.rb — 10 commits
  • test/models — 6 commits
  • test/rails_app — 5 commits
  • app/views — 4 commits
  • lib/generators — 4 commits
  • test/integration — 4 commits
  • gemfiles/Gemfile.devise-4.0 — 2 commits
  • gemfiles/Gemfile.rails-6.1 — 2 commits
  • test/orm — 2 commits
  • .github/dependabot.yml — 1 commit
  • gemfiles/Gemfile.devise-4.4 — 1 commit
  • gemfiles/Gemfile.rails-5.0.lock — 1 commit
  • gemfiles/Gemfile.rails-master — 1 commit
  • lib/devise_invitable.rb — 1 commit

Notable commits

  • fix: Allow to set invited_by_* options on model, fixes #677
  • fix: Fix NoMethodError in random_password
  • fix: Fix Rails 5 deprecated method call on attributes
  • fix: Fix after_{invite,accept}_path_for per issue #733
  • fix: Fix broken CI caused by dependency conflict between Rails and concurrent-ruby
  • fix: Fix changelog
  • fix: Fix changelog
  • fix: Fix invitation_due_at
  • fix: Fix invitation_period_valid? with no timestamp
  • fix: Fix obsolete symbols in German translation
  • fix: Fix vulnerability report
  • fix: Fixes a minor deprecation warning
  • fix: Fixes no locale, because it's converting to a boolean and brake tests
  • fix: Fixes top key locale from et.yml and ua.yml files
  • fix: Merge pull request #758 from bradleypriest/bugfix/accept
  • fix: [Fix issue #810] Fix Ruby 2.7.0 deprecation warning "Using the last argument as keyword parameters is deprecated; maybe ** should be added to the call"
  • fix: fix active record testing
  • fix: fix bundler issues in travis
  • fix: fix deprecation testing with rails 5
  • fix: fix es.yml i18n
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

scambra/devise_invitable was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 81bfce9d6142c8728671b469a422d0e76c0b0356 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.