Skip to content
CAI
Software that uses CAICheck a score

ueberauth/ueberauth

61.2

Adequate · 23 September 2026

1.2k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Ueberauth is an Elixir authentication framework that manages two-phase OAuth-style flows via Plug interceptors. It provides a standardized strategy behavior for implementing providers, along with structured data models for handling successful credentials and authentication failures. The system supports flexible configuration of request and callback paths, allowing applications to integrate multiple authentication services through a unified interface.

Features

Initial Ueberauth provider configuration

The application now includes a configuration file defining a set of Ueberauth authentication providers. These providers include simple callbacks, redirectors with custom request and callback paths, and options for handling errors or specific HTTP methods, allowing users to authenticate via these predefined strategies.

config · high confidence

Initial project scaffolding and documentation

This release establishes the foundational structure for the Ueberauth library, introducing essential developer tooling such as \.formatter.exs\ for code formatting, \.gitignore\ for build artifacts, and \.tool-versions\ specifying Elixir 1.19.5 and Erlang 28.4.1. It also includes a comprehensive \CHANGELOG.md\ documenting versions from 0.1.0 through 0.10.5, a \CONTRIBUTING.md\ guide, and a \Makefile\ for CI tasks. The \README.md\ has been significantly expanded to provide detailed integration instructions for Phoenix applications, including setup steps, controller examples, and explanations of the request and callback phases.

(repo-wide) · high confidence

Initial release of Ueberauth authentication framework

Introduces the Ueberauth library, a two-phase authentication framework for Elixir inspired by Omniauth. The core module provides a plug that intercepts requests for 'request' and 'callback' phases, allowing applications to configure multiple authentication strategies (providers) via application configuration. Users can define providers, customize base paths (defaulting to /auth), select specific providers per plug instance, and configure OTP app namespaces for multi-app setups.

lib · high confidence

Introduction of core authentication structs and strategy behavior

This change introduces the foundational data structures and behavior contracts for the Ueberauth library. It adds \Ueberauth.Auth\ to represent successful authentication results (including UID, provider, credentials, and extra info) and \Ueberauth.Failure\ (along with \Ueberauth.Failure.Error\) to represent authentication errors. Additionally, it defines the \Ueberauth.Strategy\ behavior, which establishes the standard request, callback, and cleanup phases that all authentication strategies must implement, providing default implementations for callbacks to simplify strategy development.

lib/ueberauth · high confidence

New strategy helper module for URL construction and error handling

A new \Ueberauth.Strategy.Helpers\ module has been added to provide convenience methods for strategy implementations. This includes functions to construct request and callback URLs (respecting configured schemes, ports, and paths), handle callback parameters (filtering out the provider and nil values), manage HTTP method validation for callbacks, and process authentication failures by attaching error structures to the connection.

lib/ueberauth/strategies · high confidence

Behavioural changes

Introduction of Auth sub-structs for credentials, extra data, and user info

The library now exposes dedicated structs for handling authentication details: \Ueberauth.Auth.Credentials\ stores token and scope information, \Ueberauth.Auth.Extra\ holds raw provider data, and \Ueberauth.Auth.Info\ contains user profile fields including a newly added \birthday\ field. These changes provide a structured way to access and validate authentication results within the Ueberauth framework.

lib/ueberauth/auth · high confidence

Test coverage

Added test support infrastructure for Ueberauth strategies; Initial test suite for core authentication flows.

Dependencies

Initial project setup with Elixir 1.14 and Plug 1.5

The project is initialized with version 0.10.8, requiring Elixir \~\> 1.14 and depending on Plug \~\> 1.5. Development tooling includes Credo, Dialyxir, ExCoveralls, ExDoc, and InchEx, with the dependency lock file pinning specific versions for these tools and their transitive dependencies like Plug 1.20.3 and Telemetry 1.4.2.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 53 → 61 (+7.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.2)
  • Architecture 69 → 69 (+0.0)
  • Maturity 53 → 53 (+0.0)
  • Readiness 46 → 59 (+13.6)
  • Security 57 → 80 (+22.6)

Resolved (13)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (7 lines × 2) (lib/ueberauth.ex)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included

New (13)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (8 lines × 2) (lib/ueberauth.ex)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No dependency advisory monitoring
  • Outdated: dialyxir
  • Outdated: ex_doc

Changes since last survey

  • 1 commits — 0 feature/other, 1 fixes

By area

  • lib/ueberauth — 1 commit

Notable commits

  • fix: fix: exclude the provider param from callback_url params (#216)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ueberauth/ueberauth was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a9fe6cf95b10797eae60cca0ff2cef7fca326c6d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.