Skip to content
CAI
Software that uses CAICheck a score

smpallen99/coherence

51.8

Adequate · 23 September 2026

8.2k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an authentication library for Elixir and Phoenix applications, providing a comprehensive suite of user management features including registration, login, password recovery, account confirmation, and session tracking. It offers a modular architecture with overridable controllers, configurable services, and in-memory or database-backed credential stores. The library includes Mix tasks for code generation and cleanup, along with templates and localization support for the authentication flow.

How it got here

2016 — Coherence framework modernization and test coverage

13 changes.

This period focused on modernizing the Coherence authentication library to support Elixir 1.11 and Phoenix 1.3, including a configuration system refactor and the addition of new routing and responder modules. Significant effort was also dedicated to comprehensive test coverage, adding extensive tests for controllers, models, plugs, and services to ensure the reliability of the authentication features.

2017–2018 — Authentication and developer experience improvements

8 changes.

This period focused on enhancing the Coherence authentication system by introducing persistent login capabilities, service modules for account management, and in-memory credential stores. It also expanded the developer experience with new Mix tasks for code generation and cleanup, supported by comprehensive test coverage.

Features

Add Coherence authentication templates and message translations

The Coherence authentication system now includes a complete set of generated templates and message files. This adds EEx templates for all authentication controllers (confirmation, invitation, password, registration, session, and unlock), email templates for account confirmation, password reset, invitation, and unlock notifications, and a comprehensive set of gettext message strings for user-facing text. These files provide the default UI and localization support for the authentication flow.

priv · high confidence

Add Elixir code formatter configuration and tooling files

The repository now includes a \.formatter.exs\ file that configures the Elixir code formatter with local function names for Phoenix, Phoenix.Controller, Phoenix.Endpoint, and various test helpers, ensuring consistent code style across the project. Additionally, \.tool-versions\ specifies Erlang 25.3.2.5 and Elixir 1.14.5-otp-25, while \.travis.yml\ is added to configure the CI environment for Elixir 1.4–1.6 and OTP 20.0.

(repo-wide) · high confidence

Added Mix utility module for migration and argument validation

A new \Coherence.Mix.Utils\ module was added to \lib/mix/mix\_utils.ex\. This module provides helper functions for generating database migration fields for various authentication features (such as recoverable, trackable, lockable, and confirmable), managing controller file templates, and validating Mix task arguments. It also includes a compatibility shim for the \Code.format\_string!/1\ function introduced in later Elixir versions.

lib/mix · high confidence

Added Rememberable schema for persistent login tokens

A new Rememberable schema has been introduced to support persistent login functionality. This addition enables the system to generate, store, and validate remember-me tokens, allowing users to remain logged in across browser sessions. The implementation includes logic for creating and updating login states, querying valid and invalid login attempts, and automatically cleaning up expired tokens.

lib/coherence/schemas · high confidence

Added RequireLogin and ValidateOption plugs

Two new plugs have been introduced to the Coherence library: RequireLogin, which restricts controller access to authenticated users, and ValidateOption, which ensures specific project configuration options are enabled before allowing access. These changes provide a more granular way to enforce authentication and configuration requirements across the application.

lib/coherence/plugs · high confidence

Added new service modules for account confirmation, locking, password recovery, remember-me, session, and login tracking

The \lib/coherence/services\ directory now includes new Elixir modules (\ConfirmableService\, \LockableService\, \PasswordService\, \RememberableService\, \SessionService\, and \TrackableService\) that implement core authentication behaviors. These services handle user account confirmation, account locking after failed attempts, password reset token generation, remember-me cookie management, signed user token verification, and login activity tracking. Users can now configure and utilize these features for enhanced security and audit capabilities.

lib/coherence/services · high confidence

New coh.clean and coh.gen.controllers mix tasks

The Coherence package introduces two new Mix tasks to improve the developer experience. The \mix coh.clean\ task allows users to cleanly remove files generated by the installer, supporting granular removal of views, templates, models, controllers, and other components. Additionally, the \mix coh.gen.controllers\ task enables developers to generate customizable Coherence controllers, providing greater control over authentication flows. These additions streamline the lifecycle management of Coherence-generated code.

lib/mix/tasks · high confidence

New in-memory and database-backed credential stores for authentication

The authentication plugs (Basic, Session, Token, and IP address) now use a new credential storage system. A new \Coherence.CredentialStore.Server\ provides an in-memory GenServer for caching user data, while \Coherence.CredentialStore.Session\ adds database persistence via the \Coherence.DbStore\ protocol. This allows session data to survive application restarts when configured, and provides a consistent interface for storing and retrieving user credentials across different authentication methods.

lib/coherence/plugs/authentication · high confidence

Behavioural changes

Add comprehensive documentation for Coherence features and configuration

The main module now includes extensive @moduledoc text detailing all authentication features (Authenticatable, Invitable, Registerable, Confirmable, Recoverable, Trackable, Lockable, Unlockable, Rememberable) and their configuration options, as well as Mix task usage. This provides users with a complete reference for setting up and customizing the library.

lib · high confidence

Coherence authentication framework restructured with new configuration and responder modules

The Coherence library has been refactored to support configurable authentication features. A new \Coherence.Config\ module centralizes all configuration options, including password hashing algorithms, token generation, and redirect URLs. The framework now provides \Coherence.Responders\ behaviors with default HTML and JSON implementations for consistent response handling across sessions, registrations, passwords, and invitations. Routing is managed via \Coherence.Router\ macros that dynamically generate public and protected routes based on enabled features. Additionally, a \Coherence.Schema\ module simplifies user model setup with helper functions for various authentication modes (e.g., lockable, trackable, invitable).

lib/coherence · high confidence

Migrate configuration system to modern Elixir/Phoenix standards

The application's configuration has been modernized to use the current Elixir \import Config\ syntax, replacing the legacy \Mix.Config\ approach. Environment variables are now supported for sensitive settings like database credentials, and the configuration structure has been updated to align with Phoenix 1.3+ project layouts, including explicit definitions for user schemas, permitted attributes for registration and invitations, and mailer adapters.

config · high confidence

Split all controllers into thin public modules and overridable base modules

The controllers in lib/coherence/controllers have been refactored into a two-part structure: lightweight public controllers (e.g., Coherence.ConfirmationController) that use the framework's :controller plug, and corresponding \*Base modules (e.g., Coherence.ConfirmationControllerBase) that contain the actual action logic. This change makes every controller action overridable, allowing users to customize behavior by overriding specific functions in their own controller modules. The base modules implement the core logic for confirmation, invitation, password, registration, session, and unlock flows, while the public controllers handle routing, layout, and validation plugs.

lib/coherence/controllers · high confidence

Test coverage

Add comprehensive test coverage for Coherence configuration, schema, and view helpers; Added comprehensive controller tests for authentication and account management; Added comprehensive test coverage for authentication plugs; Added test support infrastructure for the Coherence authentication system; Added tests for Mix tasks; Added tests for lockable, password, and trackable services; Added tests for the Rememberable model; Added tests for the credential store server.

Dependencies

Upgrade to Elixir 1.11 and Phoenix 1.3 support

The project has been updated to require Elixir 1.11 and support Phoenix 1.3, reflecting a significant framework upgrade. The \mix.exs\ configuration now specifies \elixir: "\~\> 1.11"\ and includes \phoenix\ version \\~\> 1.3\ in the dependencies. This change ensures compatibility with newer Elixir and Phoenix versions, potentially bringing performance improvements and access to newer language features, while also updating the application's OTP configuration to include \:ecto\, \:tzdata\, \:crypto\, and \:eex\ as extra applications.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 54 → 52 (-2.5)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 98 (+1.0)
  • Architecture 100 → 85 (-15.5)
  • Maturity 51 → 51 (+0.0)
  • Readiness 34 → 36 (+1.8)
  • Security 90 → 74 (-15.9)
  • Accessibility 78 (new)

Resolved (15)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (12 lines × 2) (lib/mix/tasks/coh.gen.controllers.ex)
  • Duplicated block (9 lines × 2) (lib/mix/tasks/coh.gen.controllers.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: [GHSA redacted] (mix.lock)
  • No exposed public API
  • Test reliability not included
  • TooManyMethods: Install (lib/mix/tasks/coh.install.ex)
  • dormant codebase — no living knowledge left to concentrate

New (28)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (16 lines × 2) (lib/mix/tasks/coh.gen.controllers.ex)
  • Duplicated block (8 lines × 2) (lib/mix/tasks/coh.gen.controllers.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • Leaked secret: signing-key (config/test.exs)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: [GHSA redacted] (mix.lock)
  • No SBOM
  • No artifact signing
  • No build provenance
  • No dependency advisory monitoring
  • Outdated: credo
  • Outdated: dialyxir
  • Outdated: ecto_sql
  • Outdated: floki
  • …and 8 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

smpallen99/coherence was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ede75598de6b01ce896d6ec67f0aeac6047ddbd9 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.