wardencommunity/warden
54.1
Adequate · 19 September 2026
1.1k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is the Warden authentication middleware for Rack-based Ruby applications, providing a flexible framework for managing user sessions and authentication strategies. It replaces the legacy Rack::Auth implementation with a structured architecture that supports scoped sessions, customizable hooks, and multiple authentication strategies. The library includes comprehensive test helpers to facilitate integration testing and ensures compatibility with modern Rack versions through explicit dependency management.
Removals
Removal of legacy Rack::Auth implementation
The \lib/rack-auth\ directory has been completely removed, deleting the \Manager\, \Proxy\, and \Common\ mixin classes that previously handled authentication via the \Rack::Auth\ namespace. This change eliminates the middleware logic that injected authentication objects into the Rack environment and managed user sessions through specific session keys, effectively stripping this authentication layer from the application.
lib/rack-auth · high confidence
Removal of legacy Rack::Auth strategy classes
The \Rack::Auth::Strategies\ module and its \Base\ class have been removed from the library. This eliminates the previous mechanism for defining and managing custom authentication strategies within the \Rack::Auth\ namespace, requiring users to adopt the new authentication architecture (such as Warden) for strategy registration and execution.
lib/rack-auth/authentication · high confidence
Removal of legacy Rubigen script generators
The \script/generate\ and \script/destroy\ files, which previously provided scaffolding capabilities via the Rubigen library, have been removed. Users can no longer use these scripts to generate new components or destroy existing ones using the legacy Rubigen tooling.
script · high confidence
Behavioural changes
Introduce Warden::Mixins::Common with session and cookie helpers
A new Common mixin module is added to lib/warden/mixins, providing standard accessors for the Rack session (session/raw\_session), request, and params, along with a reset\_session! method. It also introduces a warden\_cookies accessor that is explicitly deprecated with a warning, indicating it was non-functional and will be removed in future versions.
lib/warden/mixins · high confidence
Migration from Rack::Auth to Warden
The library has switched its core authentication implementation from the Rack::Auth module to Warden. This change removes the previous lib/rack-auth.rb entry point and introduces lib/warden.rb, which loads the Warden manager, proxy, and session serializer. For users, this means the authentication strategy and configuration must now align with Warden's API rather than the previous Rack-based approach.
lib · high confidence
New base strategy class with explicit halt and fail modes
The authentication strategy base class now includes explicit \halt!\ and \fail!\ methods to control strategy execution flow. \halt!\ stops further strategy processing, while \fail!\ halts execution and marks the attempt as failed. A new \fail\ method (without exclamation) allows strategies to fail without halting, enabling cascading checks across multiple strategies. The class also introduces \successful?\ to verify if a strategy resulted in a successful user assignment, and \store?\ to indicate whether the login should be permanent. These changes provide finer control over authentication logic and error handling within the Warden middleware.
lib/warden/strategies · high confidence
Warden authentication library restructured and upgraded to v1.2.9
The Warden authentication middleware has been reorganized into a cleaner module structure (lib/warden) and upgraded to version 1.2.9. This release introduces a dedicated SessionSerializer to handle user serialization and deserialization, allowing for more robust session management and support for different scopes. It also adds a comprehensive hooks system (after\_set\_user, before\_failure, before\_logout, on\_request) to allow plugins and applications to inject custom logic at key authentication events. Configuration is now centralized in a new Config class, supporting features like intercepting 401 responses, silencing missing strategies, and setting default strategies per scope. The library also includes performance improvements, such as caching strategies and using raw accessors for config, and fixes several bugs related to session handling and strategy execution.
lib/warden · high confidence
Test coverage
Added Warden test helpers and mock infrastructure; Added test coverage for Warden authentication components; Added test coverage for Warden test helpers and test mode; Added test helper strategies for Warden authentication; Migrate test suite from Rack::Auth to Warden and update RSpec configuration; Removed spec/rack-auth test suite; Removed test strategy definitions for Rack::Auth; Updated test helpers to align with Warden API changes; Updated tests for Warden::Strategies::Base.
Dependencies
Add support for testing with multiple versions of Rack
The project now includes dedicated Gemfiles to facilitate testing against different major versions of the Rack library. Specifically, \gemfiles/rack\_2.gemfile\ pins Rack to version 2.2, and \gemfiles/rack\_3.gemfile\ pins Rack to version 3.0, allowing the gemspec to be evaluated in both environments.
gemfiles · high confidence
Initial gemspec and Gemfile setup with Rack 2.2.3+ requirement
The project now includes a Gemfile and a warden.gemspec that define the package structure and dependencies. The gemspec specifies a runtime dependency on Rack version 2.2.3 or higher, ensuring compatibility with modern Rack-based frameworks. Development dependencies include Rake, RSpec (\~\> 3), rack-test, and rack-session, while the Gemfile adds Pry for interactive debugging. The gem is configured to exclude test, spec, feature, and .github directories from the published package.
(dependencies) · high confidence
Update to Warden 1.2.9 with Rack 2.2.3 and security fixes
This release updates the Warden authentication middleware to version 1.2.9, bumping the Rack dependency to 2.2.3 to address multiple CVEs and resolving warnings on uninitialized instance variables. It also removes the Gemfile.lock, updates the CHANGELOG to Markdown format, and migrates the build system from Jeweler to Bundler, while cleaning up documentation by replacing README.textile with README.md.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 54.
Lenses
- Code Health 100
- Architecture 69
- Maturity 33
- Readiness 65
- Security 91
Changes since last survey
- 300 commits — 276 feature/other, 24 fixes
By area
- (root) — 99 commits
- (repo) — 97 commits
- lib/warden — 71 commits
- spec/warden — 20 commits
- .github/workflows — 10 commits
- spec/helpers — 2 commits
- script/destroy — 1 commit
Notable commits
- fix: Actually release 0.10.5, since 0.10.4 did not include some fixes from 0.10.3.
- fix: Bump to 1.1.0. fixes #11
- fix: Do not throw exception on logout if session is nil. Fixes #78
- fix: English fix
- fix: Fix 2 failing tests.
- fix: Fix a bug in strategies error handling
- fix: Fix an issue where winning_strategy was not cleaned, allowing multiple scopes to sign in, even when the second one should not.
- fix: Fix document comment[ci skip]
- fix: Fix failing test
- fix: Fix issue with attempting to write to a nil session store
- fix: Fixed issue with rake tasks failing (rake build, etc.) on Ruby 1.9. "require" only is not enough on Ruby 1.9 if gem is not loaded. To build the gem from edge this needs to work for sure.
- fix: Fixes specs that broke under rack 1.3
- fix: Merge fix
- fix: Merge pull request #129 from acaron/fix-test-helpers
- fix: Merge pull request #149 from hassox/fix-bundle-on-travis
- fix: Merge pull request #162 from godfat/fix-catching-on-request
- fix: Merge pull request #215 from chubchenko/fix-build
- fix: Tiny fixes to get specs to run on Ruby 1.9. Issues related to how 1.9 treats Blocks and Arrays. Closes #7.
- fix: fix flakey specs
- fix: fix specs failing when run with --order rand
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
wardencommunity/warden was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ffee6ac52099fd32404ca66cfc897fffde5919de — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.