From adb56bc39a66e09971a4ae0ed9de496ffaf974d6 Mon Sep 17 00:00:00 2001 From: nejdetkadir Date: Tue, 25 Aug 2026 19:47:57 +0300 Subject: [PATCH] chore: upgrade dependencies to latest stable versions Resolves the open Dependabot alerts by moving the development/test dependency tree off the Rails 7.0.4-era lockfile: - Rails 7.0.4 -> 8.1.3.1 (rack 3.2.7, nokogiri 1.19.4, loofah 2.25.2, rails-html-sanitizer 1.7.1, rexml dropped from the tree) - devise 4.8.1 -> 5.0.4, bcrypt 3.1.22, concurrent-ruby 1.3.8 - puma ~> 5.0 -> ~> 7.0 (7.2.1), sqlite3 ~> 1.4 -> ~> 2.0 (2.9.6) - rspec-rails ~> 6.0 -> ~> 8.0, rubocop 1.42 -> 1.90 (3 layout autocorrections in dummy initializers) - add ostruct gem (no longer a default gem since Ruby 3.5) Dummy app now boots with Rails 8.1 framework defaults. CI matrix updated from Ruby 2.7.7/3.0.5/3.1.3/3.2.0 to 3.2/3.3/3.4/4.0 (Rails 8 needs Ruby >= 3.2) with actions/checkout@v4; gemspec constraints for host apps are unchanged (Ruby >= 2.7, Rails >= 6.0). Docs updated to match. Full suite green (321 examples, 100% line/branch coverage, rubocop clean) on Ruby 3.2.6 and 4.0.3. Co-Authored-By: Claude Fable 5 --- .github/workflows/rubocop.yml | 10 +- .github/workflows/test.yml | 10 +- Gemfile | 9 +- Gemfile.lock | 431 ++++++++++-------- docs/architecture.md | 2 +- docs/development.md | 2 +- docs/testing.md | 4 +- spec/dummy/config/application.rb | 2 +- .../initializers/content_security_policy.rb | 1 + spec/dummy/config/initializers/inflections.rb | 1 + .../config/initializers/permissions_policy.rb | 1 + 11 files changed, 271 insertions(+), 202 deletions(-) diff --git a/.github/workflows/rubocop.yml b/.github/workflows/rubocop.yml index da345ac..fe3fdfc 100644 --- a/.github/workflows/rubocop.yml +++ b/.github/workflows/rubocop.yml @@ -9,13 +9,13 @@ jobs: strategy: matrix: ruby: - - '2.7.7' - - '3.0.5' - - '3.1.3' - - '3.2.0' + - '3.2' + - '3.3' + - '3.4' + - '4.0' steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v4 - name: Set up Ruby uses: ruby/setup-ruby@v1 with: diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 4d5cc5e..541cf80 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -9,13 +9,13 @@ jobs: strategy: matrix: ruby: - - '2.7.7' - - '3.0.5' - - '3.1.3' - - '3.2.0' + - '3.2' + - '3.3' + - '3.4' + - '4.0' steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v4 - name: Set up Ruby uses: ruby/setup-ruby@v1 with: diff --git a/Gemfile b/Gemfile index 0ba5130..67e34fa 100644 --- a/Gemfile +++ b/Gemfile @@ -25,10 +25,10 @@ gem 'pry', '~> 0.14.1' gem 'sprockets-rails' # Use sqlite3 as the database for Active Record -gem 'sqlite3', '~> 1.4' +gem 'sqlite3', '~> 2.0' # Use the Puma web server [https://github.com/puma/puma] -gem 'puma', '~> 5.0' +gem 'puma', '~> 7.0', '>= 7.2.1' # A library for setting up Ruby objects as test data [https://github.com/thoughtbot/factory_bot] gem 'factory_bot', '~> 6.2', '>= 6.2.1' @@ -40,7 +40,7 @@ gem 'faker', '~> 3.1' gem 'database_cleaner', '~> 2.0', '>= 2.0.1' # RSpec for Rails 5+ [https://github.com/rspec/rspec-rails] -gem 'rspec-rails', '~> 6.0', '>= 6.0.1' +gem 'rspec-rails', '~> 8.0' # RSpec runner and formatters [https://github.com/rspec/rspec-core] gem 'rspec-core' @@ -50,3 +50,6 @@ gem 'rspec-support' # Code coverage analysis tool for Ruby [https://github.com/simplecov-ruby/simplecov] gem 'simplecov', '~> 0.22', require: false + +# OpenStruct implementation, no longer a default gem since Ruby 3.5 [https://github.com/ruby/ostruct] +gem 'ostruct' diff --git a/Gemfile.lock b/Gemfile.lock index 843f1d0..326c394 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -12,256 +12,318 @@ PATH GEM remote: https://rubygems.org/ specs: - actioncable (7.0.4) - actionpack (= 7.0.4) - activesupport (= 7.0.4) + action_text-trix (2.1.19) + railties + actioncable (8.1.3.1) + actionpack (= 8.1.3.1) + activesupport (= 8.1.3.1) nio4r (~> 2.0) websocket-driver (>= 0.6.1) - actionmailbox (7.0.4) - actionpack (= 7.0.4) - activejob (= 7.0.4) - activerecord (= 7.0.4) - activestorage (= 7.0.4) - activesupport (= 7.0.4) - mail (>= 2.7.1) - net-imap - net-pop - net-smtp - actionmailer (7.0.4) - actionpack (= 7.0.4) - actionview (= 7.0.4) - activejob (= 7.0.4) - activesupport (= 7.0.4) - mail (~> 2.5, >= 2.5.4) - net-imap - net-pop - net-smtp - rails-dom-testing (~> 2.0) - actionpack (7.0.4) - actionview (= 7.0.4) - activesupport (= 7.0.4) - rack (~> 2.0, >= 2.2.0) + zeitwerk (~> 2.6) + actionmailbox (8.1.3.1) + actionpack (= 8.1.3.1) + activejob (= 8.1.3.1) + activerecord (= 8.1.3.1) + activestorage (= 8.1.3.1) + activesupport (= 8.1.3.1) + mail (>= 2.8.0) + actionmailer (8.1.3.1) + actionpack (= 8.1.3.1) + actionview (= 8.1.3.1) + activejob (= 8.1.3.1) + activesupport (= 8.1.3.1) + mail (>= 2.8.0) + rails-dom-testing (~> 2.2) + actionpack (8.1.3.1) + actionview (= 8.1.3.1) + activesupport (= 8.1.3.1) + nokogiri (>= 1.8.5) + rack (>= 2.2.4) + rack-session (>= 1.0.1) rack-test (>= 0.6.3) - rails-dom-testing (~> 2.0) - rails-html-sanitizer (~> 1.0, >= 1.2.0) - actiontext (7.0.4) - actionpack (= 7.0.4) - activerecord (= 7.0.4) - activestorage (= 7.0.4) - activesupport (= 7.0.4) + rails-dom-testing (~> 2.2) + rails-html-sanitizer (~> 1.6) + useragent (~> 0.16) + actiontext (8.1.3.1) + action_text-trix (~> 2.1.15) + actionpack (= 8.1.3.1) + activerecord (= 8.1.3.1) + activestorage (= 8.1.3.1) + activesupport (= 8.1.3.1) globalid (>= 0.6.0) nokogiri (>= 1.8.5) - actionview (7.0.4) - activesupport (= 7.0.4) + actionview (8.1.3.1) + activesupport (= 8.1.3.1) builder (~> 3.1) - erubi (~> 1.4) - rails-dom-testing (~> 2.0) - rails-html-sanitizer (~> 1.1, >= 1.2.0) - activejob (7.0.4) - activesupport (= 7.0.4) + erubi (~> 1.11) + rails-dom-testing (~> 2.2) + rails-html-sanitizer (~> 1.6) + activejob (8.1.3.1) + activesupport (= 8.1.3.1) globalid (>= 0.3.6) - activemodel (7.0.4) - activesupport (= 7.0.4) - activerecord (7.0.4) - activemodel (= 7.0.4) - activesupport (= 7.0.4) - activestorage (7.0.4) - actionpack (= 7.0.4) - activejob (= 7.0.4) - activerecord (= 7.0.4) - activesupport (= 7.0.4) + activemodel (8.1.3.1) + activesupport (= 8.1.3.1) + activerecord (8.1.3.1) + activemodel (= 8.1.3.1) + activesupport (= 8.1.3.1) + timeout (>= 0.4.0) + activestorage (8.1.3.1) + actionpack (= 8.1.3.1) + activejob (= 8.1.3.1) + activerecord (= 8.1.3.1) + activesupport (= 8.1.3.1) marcel (~> 1.0) - mini_mime (>= 1.1.0) - activesupport (7.0.4) - concurrent-ruby (~> 1.0, >= 1.0.2) + activesupport (8.1.3.1) + base64 + bigdecimal + concurrent-ruby (~> 1.0, >= 1.3.1) + connection_pool (>= 2.2.5) + drb i18n (>= 1.6, < 2) + json + logger (>= 1.4.2) minitest (>= 5.1) - tzinfo (~> 2.0) - ast (2.4.2) + securerandom (>= 0.3) + tzinfo (~> 2.0, >= 2.0.5) + uri (>= 0.13.1) + ast (2.4.3) awesome_print (1.9.2) - bcrypt (3.1.18) - builder (3.2.4) + base64 (0.3.0) + bcrypt (3.1.22) + bigdecimal (4.1.2) + builder (3.3.0) coderay (1.1.3) - concurrent-ruby (1.1.10) - crass (1.0.6) - database_cleaner (2.0.1) - database_cleaner-active_record (~> 2.0.0) - database_cleaner-active_record (2.0.1) + concurrent-ruby (1.3.8) + connection_pool (3.0.2) + crass (1.0.7) + database_cleaner (2.1.0) + database_cleaner-active_record (>= 2, < 3) + database_cleaner-active_record (2.2.2) activerecord (>= 5.a) - database_cleaner-core (~> 2.0.0) - database_cleaner-core (2.0.1) - date (3.3.3) - devise (4.8.1) + database_cleaner-core (~> 2.0) + database_cleaner-core (2.1.0) + date (3.5.1) + devise (5.0.4) bcrypt (~> 3.0) orm_adapter (~> 0.1) - railties (>= 4.1.0) + railties (>= 7.0) responders warden (~> 1.2.3) - diff-lcs (1.5.0) + diff-lcs (1.6.2) docile (1.4.1) - dry-configurable (1.0.1) - dry-core (~> 1.0, < 2) + drb (2.2.3) + dry-configurable (1.3.0) + dry-core (~> 1.1) zeitwerk (~> 2.6) - dry-core (1.0.0) + dry-core (1.2.0) concurrent-ruby (~> 1.0) + logger zeitwerk (~> 2.6) - dry-inflector (1.0.0) - dry-initializer (3.1.1) - dry-logic (1.5.0) + dry-inflector (1.3.1) + dry-initializer (3.2.0) + dry-logic (1.6.0) + bigdecimal concurrent-ruby (~> 1.0) - dry-core (~> 1.0, < 2) + dry-core (~> 1.1) zeitwerk (~> 2.6) - dry-monads (1.6.0) + dry-monads (1.10.0) concurrent-ruby (~> 1.0) - dry-core (~> 1.0, < 2) + dry-core (~> 1.1) zeitwerk (~> 2.6) - dry-types (1.7.0) + dry-types (1.9.1) + bigdecimal (>= 3.0) concurrent-ruby (~> 1.0) - dry-core (~> 1.0, < 2) - dry-inflector (~> 1.0, < 2) - dry-logic (>= 1.4, < 2) + dry-core (~> 1.0) + dry-inflector (~> 1.0) + dry-logic (~> 1.4) zeitwerk (~> 2.6) - erubi (1.12.0) - factory_bot (6.2.1) - activesupport (>= 5.0.0) - faker (3.1.0) + erb (6.0.7) + erubi (1.13.1) + factory_bot (6.6.0) + activesupport (>= 6.1.0) + faker (3.8.0) i18n (>= 1.8.11, < 2) - globalid (1.0.0) - activesupport (>= 5.0) - i18n (1.12.0) + globalid (1.4.0) + activesupport (>= 6.1) + i18n (1.15.2) concurrent-ruby (~> 1.0) - json (2.6.3) - loofah (2.19.1) + io-console (0.9.2) + irb (1.18.0) + pp (>= 0.6.0) + prism (>= 1.3.0) + rdoc (>= 4.0.0) + reline (>= 0.4.2) + json (2.21.2) + language_server-protocol (3.17.0.6) + lint_roller (1.1.0) + logger (1.7.0) + loofah (2.25.2) crass (~> 1.0.2) - nokogiri (>= 1.5.9) - mail (2.8.0) + nokogiri (>= 1.12.0) + mail (2.9.1) + logger mini_mime (>= 0.1.1) net-imap net-pop net-smtp - marcel (1.0.2) - method_source (1.0.0) - mini_mime (1.1.2) - mini_portile2 (2.8.1) - minitest (5.17.0) - net-imap (0.3.4) + marcel (1.2.1) + method_source (1.1.0) + mini_mime (1.1.5) + minitest (6.0.6) + drb (~> 2.0) + prism (~> 1.5) + net-imap (0.6.6) date net-protocol net-pop (0.1.2) net-protocol - net-protocol (0.2.1) + net-protocol (0.2.2) timeout - net-smtp (0.3.3) + net-smtp (0.5.1) net-protocol - nio4r (2.5.8) - nokogiri (1.13.10) - mini_portile2 (~> 2.8.0) + nio4r (2.7.5) + nokogiri (1.19.4-arm64-darwin) racc (~> 1.4) orm_adapter (0.5.0) - parallel (1.22.1) - parser (3.2.0.0) + ostruct (0.6.3) + parallel (1.28.0) + parser (3.3.12.0) ast (~> 2.4.1) + racc + pp (0.6.4) + prettyprint + prettyprint (0.2.0) + prism (1.9.0) pry (0.14.2) coderay (~> 1.1) method_source (~> 1.0) - puma (5.6.5) + puma (7.2.1) nio4r (~> 2.0) - racc (1.6.2) - rack (2.2.5) - rack-test (2.0.2) + racc (1.8.1) + rack (3.2.7) + rack-session (2.1.2) + base64 (>= 0.1.0) + rack (>= 3.0.0) + rack-test (2.2.0) rack (>= 1.3) - rails (7.0.4) - actioncable (= 7.0.4) - actionmailbox (= 7.0.4) - actionmailer (= 7.0.4) - actionpack (= 7.0.4) - actiontext (= 7.0.4) - actionview (= 7.0.4) - activejob (= 7.0.4) - activemodel (= 7.0.4) - activerecord (= 7.0.4) - activestorage (= 7.0.4) - activesupport (= 7.0.4) + rackup (2.3.1) + rack (>= 3) + rails (8.1.3.1) + actioncable (= 8.1.3.1) + actionmailbox (= 8.1.3.1) + actionmailer (= 8.1.3.1) + actionpack (= 8.1.3.1) + actiontext (= 8.1.3.1) + actionview (= 8.1.3.1) + activejob (= 8.1.3.1) + activemodel (= 8.1.3.1) + activerecord (= 8.1.3.1) + activestorage (= 8.1.3.1) + activesupport (= 8.1.3.1) bundler (>= 1.15.0) - railties (= 7.0.4) - rails-dom-testing (2.0.3) - activesupport (>= 4.2.0) + railties (= 8.1.3.1) + rails-dom-testing (2.3.0) + activesupport (>= 5.0.0) + minitest nokogiri (>= 1.6) - rails-html-sanitizer (1.4.4) - loofah (~> 2.19, >= 2.19.1) - railties (7.0.4) - actionpack (= 7.0.4) - activesupport (= 7.0.4) - method_source + rails-html-sanitizer (1.7.1) + loofah (~> 2.25, >= 2.25.2) + nokogiri (>= 1.15.7, != 1.16.7, != 1.16.6, != 1.16.5, != 1.16.4, != 1.16.3, != 1.16.2, != 1.16.1, != 1.16.0.rc1, != 1.16.0) + railties (8.1.3.1) + actionpack (= 8.1.3.1) + activesupport (= 8.1.3.1) + irb (~> 1.13) + rackup (>= 1.0.0) rake (>= 12.2) - thor (~> 1.0) - zeitwerk (~> 2.5) + thor (~> 1.0, >= 1.2.2) + tsort (>= 0.2) + zeitwerk (~> 2.6) rainbow (3.1.1) - rake (13.0.6) - regexp_parser (2.6.1) - responders (3.0.1) - actionpack (>= 5.0) - railties (>= 5.0) - rexml (3.2.5) - rspec (3.12.0) - rspec-core (~> 3.12.0) - rspec-expectations (~> 3.12.0) - rspec-mocks (~> 3.12.0) - rspec-core (3.12.0) - rspec-support (~> 3.12.0) - rspec-expectations (3.12.2) + rake (13.4.2) + rbs (4.1.3) + logger + prism (>= 1.6.0) + tsort + rdoc (8.0.0) + erb + prism (>= 1.6.0) + rbs (>= 4.0.0) + tsort + regexp_parser (2.12.0) + reline (0.7.0) + io-console (~> 0.5) + responders (3.2.0) + actionpack (>= 7.0) + railties (>= 7.0) + rspec (3.13.2) + rspec-core (~> 3.13.0) + rspec-expectations (~> 3.13.0) + rspec-mocks (~> 3.13.0) + rspec-core (3.13.6) + rspec-support (~> 3.13.0) + rspec-expectations (3.13.5) diff-lcs (>= 1.2.0, < 2.0) - rspec-support (~> 3.12.0) - rspec-mocks (3.12.2) + rspec-support (~> 3.13.0) + rspec-mocks (3.13.8) diff-lcs (>= 1.2.0, < 2.0) - rspec-support (~> 3.12.0) - rspec-rails (6.0.1) - actionpack (>= 6.1) - activesupport (>= 6.1) - railties (>= 6.1) - rspec-core (~> 3.11) - rspec-expectations (~> 3.11) - rspec-mocks (~> 3.11) - rspec-support (~> 3.11) - rspec-support (3.12.0) - rubocop (1.42.0) - json (~> 2.3) - parallel (~> 1.10) - parser (>= 3.1.2.1) + rspec-support (~> 3.13.0) + rspec-rails (8.0.4) + actionpack (>= 7.2) + activesupport (>= 7.2) + railties (>= 7.2) + rspec-core (>= 3.13.0, < 5.0.0) + rspec-expectations (>= 3.13.0, < 5.0.0) + rspec-mocks (>= 3.13.0, < 5.0.0) + rspec-support (>= 3.13.0, < 5.0.0) + rspec-support (3.13.7) + rubocop (1.90.0) + json (>= 2.3) + language_server-protocol (~> 3.17.0.2) + lint_roller (~> 1.1.0) + parallel (>= 1.10) + parser (>= 3.3.0.2) rainbow (>= 2.2.2, < 4.0) - regexp_parser (>= 1.8, < 3.0) - rexml (>= 3.2.5, < 4.0) - rubocop-ast (>= 1.24.1, < 2.0) + regexp_parser (>= 2.9.3, < 3.0) + rubocop-ast (>= 1.49.0, < 2.0) ruby-progressbar (~> 1.7) - unicode-display_width (>= 1.4.0, < 3.0) - rubocop-ast (1.24.1) - parser (>= 3.1.1.0) - ruby-progressbar (1.11.0) + unicode-display_width (>= 2.4.0, < 4.0) + rubocop-ast (1.50.0) + parser (>= 3.3.7.2) + prism (~> 1.7) + ruby-progressbar (1.13.0) + securerandom (0.4.1) simplecov (0.22.0) docile (~> 1.1) simplecov-html (~> 0.11) simplecov_json_formatter (~> 0.1) simplecov-html (0.13.2) simplecov_json_formatter (0.1.4) - sprockets (4.2.0) - concurrent-ruby (~> 1.0) + sprockets (4.4.1) + concurrent-ruby (~> 1.1) + logger rack (>= 2.2.4, < 4) - sprockets-rails (3.4.2) - actionpack (>= 5.2) - activesupport (>= 5.2) + sprockets-rails (3.5.2) + actionpack (>= 6.1) + activesupport (>= 6.1) sprockets (>= 3.0.0) - sqlite3 (1.6.0-arm64-darwin) - thor (1.2.1) - timeout (0.3.1) - tzinfo (2.0.5) + sqlite3 (2.9.6-arm64-darwin) + thor (1.5.0) + timeout (0.6.1) + tsort (0.2.0) + tzinfo (2.0.6) concurrent-ruby (~> 1.0) - unicode-display_width (2.4.2) + unicode-display_width (3.2.0) + unicode-emoji (~> 4.1) + unicode-emoji (4.2.0) + uri (1.1.1) + useragent (0.16.11) warden (1.2.9) rack (>= 2.0.9) - websocket-driver (0.7.5) + websocket-driver (0.8.2) + base64 websocket-extensions (>= 0.1.0) websocket-extensions (0.1.5) - zeitwerk (2.6.6) + zeitwerk (2.8.3) PLATFORMS arm64-darwin-21 @@ -275,17 +337,18 @@ DEPENDENCIES devise-api! factory_bot (~> 6.2, >= 6.2.1) faker (~> 3.1) + ostruct pry (~> 0.14.1) - puma (~> 5.0) + puma (~> 7.0, >= 7.2.1) rake (~> 13.0) rspec (~> 3.0) rspec-core - rspec-rails (~> 6.0, >= 6.0.1) + rspec-rails (~> 8.0) rspec-support rubocop (~> 1.21) simplecov (~> 0.22) sprockets-rails - sqlite3 (~> 1.4) + sqlite3 (~> 2.0) BUNDLED WITH 2.4.3 diff --git a/docs/architecture.md b/docs/architecture.md index 319799f..8561236 100644 --- a/docs/architecture.md +++ b/docs/architecture.md @@ -135,7 +135,7 @@ lib/devise/api/ generators/install_generator.rb # rails g devise_api:install generators/templates/migration.rb.erb config/locales/en.yml # all user-facing strings (devise.api.error_response.*) -spec/dummy/ # full Rails 7 host app used by the test suite +spec/dummy/ # full Rails 8 host app used by the test suite ``` ## Dependency notes diff --git a/docs/development.md b/docs/development.md index 0c76462..82d912d 100644 --- a/docs/development.md +++ b/docs/development.md @@ -35,7 +35,7 @@ Style highlights (`.rubocop.yml`): target Ruby 2.7, single quotes, 120-char line ## CI -Two workflows on every push, matrix over Ruby 2.7.7 / 3.0.5 / 3.1.3 / 3.2.0: +Two workflows on every push, matrix over Ruby 3.2 / 3.3 / 3.4 / 4.0 (the development `Gemfile.lock` resolves to Rails 8.x, which needs Ruby >= 3.2; the gemspec still allows Ruby >= 2.7 for host apps): - `test.yml` — `bundle install` + `bundle exec rake rspec` - `rubocop.yml` — `bundle exec rubocop --config .rubocop.yml --parallel` diff --git a/docs/testing.md b/docs/testing.md index 0fb0b6b..c3c9934 100644 --- a/docs/testing.md +++ b/docs/testing.md @@ -10,7 +10,7 @@ bundle exec rspec spec/requests/tokens_spec.rb:95 # one example/context by bundle exec rspec --only-failures # uses .rspec_status ``` -CI (`.github/workflows/test.yml`, `rubocop.yml`) runs on push across Ruby 2.7 / 3.0 / 3.1 / 3.2. +CI (`.github/workflows/test.yml`, `rubocop.yml`) runs on push across Ruby 3.2 / 3.3 / 3.4 / 4.0. ## Coverage @@ -23,7 +23,7 @@ enforced. `lib/devise/api/version.rb` is filtered because the gemspec loads it b ## How the suite is wired -- `spec/spec_helper.rb` sets `RAILS_ENV=test`, starts SimpleCov, requires the gem, then boots the **dummy Rails app** at `spec/dummy` (`require 'dummy/config/environment'`) — a real Rails 7 app with sqlite3 whose `User` model enables `database_authenticatable, registerable, recoverable, rememberable, validatable, confirmable, lockable, trackable, :api` (schema: `spec/dummy/db/schema.rb`). A second bare model, `AdminUser` (`database_authenticatable, registerable, validatable, :api` only), exists to exercise the "optional Devise module not enabled" branches (non-trackable sign-in, error/token responses without `lockable`/`confirmable` info); it has its own `devise_for :admin_users` routes. +- `spec/spec_helper.rb` sets `RAILS_ENV=test`, starts SimpleCov, requires the gem, then boots the **dummy Rails app** at `spec/dummy` (`require 'dummy/config/environment'`) — a real Rails 8 app with sqlite3 whose `User` model enables `database_authenticatable, registerable, recoverable, rememberable, validatable, confirmable, lockable, trackable, :api` (schema: `spec/dummy/db/schema.rb`). A second bare model, `AdminUser` (`database_authenticatable, registerable, validatable, :api` only), exists to exercise the "optional Devise module not enabled" branches (non-trackable sign-in, error/token responses without `lockable`/`confirmable` info); it has its own `devise_for :admin_users` routes. - `DatabaseCleaner` wraps every example; spec types are inferred from file location; monkey-patching is disabled (`RSpec.describe` only). - `spec/supports/` is auto-required: FactoryBot setup, ActiveRecord config, and two request-spec helpers: - `authentication_headers_for(owner, token = nil, token_type = :access_token)` → `{ Authorization: "Bearer …" }` (creates a token via FactoryBot when none given; pass `:refresh_token` to authenticate refresh calls) diff --git a/spec/dummy/config/application.rb b/spec/dummy/config/application.rb index 5a62533..18fb48d 100644 --- a/spec/dummy/config/application.rb +++ b/spec/dummy/config/application.rb @@ -11,7 +11,7 @@ module Dummy class Application < Rails::Application # Initialize configuration defaults for originally generated Rails version. - config.load_defaults 7.0 + config.load_defaults 8.1 # Configuration for the application, engines, and railties goes here. # diff --git a/spec/dummy/config/initializers/content_security_policy.rb b/spec/dummy/config/initializers/content_security_policy.rb index 691cfa1..53538c1 100644 --- a/spec/dummy/config/initializers/content_security_policy.rb +++ b/spec/dummy/config/initializers/content_security_policy.rb @@ -1,4 +1,5 @@ # frozen_string_literal: true + # Be sure to restart your server when you modify this file. # Define an application-wide content security policy. diff --git a/spec/dummy/config/initializers/inflections.rb b/spec/dummy/config/initializers/inflections.rb index 6c78420..9e049dc 100644 --- a/spec/dummy/config/initializers/inflections.rb +++ b/spec/dummy/config/initializers/inflections.rb @@ -1,4 +1,5 @@ # frozen_string_literal: true + # Be sure to restart your server when you modify this file. # Add new inflection rules using the following format. Inflections diff --git a/spec/dummy/config/initializers/permissions_policy.rb b/spec/dummy/config/initializers/permissions_policy.rb index 50bcf4e..810aade 100644 --- a/spec/dummy/config/initializers/permissions_policy.rb +++ b/spec/dummy/config/initializers/permissions_policy.rb @@ -1,4 +1,5 @@ # frozen_string_literal: true + # Define an application-wide HTTP permissions policy. For further # information see https://developers.google.com/web/updates/2018/06/feature-policy #