# Changelog

## Score

- CAI 61 → 62 (+0.3)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 99 → 99 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 46 → 46 (+0.0)
- Readiness 74 → 74 (+0.0)
- Security 84 → 88 (+4.0)

## Resolved (3)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1

## New (4)

- Ambiguity between global configuration methods and specific adapter instances. `Rolify.adapter()` and `Rolify.resource_adapter()` are methods on the main module, but there are also distinct `RoleAdapter` and `ResourceAdapter` types. It is unclear if the module methods return the global singleton or if they are meant to be overridden by the specific adapter types. The naming `adapter` vs `resource_adapter` is also slightly inconsistent with the class names `RoleAdapter` vs `ResourceAdapter`.
- Off-boarding risk: anonymized user #1
- Proliferation of similar boolean check methods with subtle behavioral differences (strict vs cached) that are not immediately obvious from the signature alone. While distinct, the naming convention is verbose and error-prone for users.
- Redundant user class injection logic across multiple generator types. `RolifyGenerator.ensure_user_class_defined` and `inject_user_class` appear to handle the same concern (ensuring the User model exists/configured), while `UserGenerator.inject_user_content` likely performs the actual file modification. This creates confusion about which generator method is responsible for the final state of the User class.
