# Changelog

## Score

- CAI 54 → 63 (+8.6)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 95 → 95 (-0.1)
- Architecture 94 → 89 (-5.8)
- Maturity 50 → 50 (+0.0)
- Readiness 43 → 65 (+21.3)
- Security 61 → 75 (+13.8)

## Resolved (50)

- AuthClient.getClaims (cognitive 19) (Sources/Auth/AuthClient.swift)
- Change coupling: PushV2.swift ↔ RealtimeClientV2.swift (Sources/RealtimeV2/PushV2.swift)
- ClassTooLong: RealtimeChannelV2 (Sources/RealtimeV2/RealtimeChannelV2.swift)
- ClassTooLong: RealtimeClientV2 (Sources/RealtimeV2/RealtimeClientV2.swift)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (12 lines × 2) (Sources/RealtimeV2/RealtimeChannelV2.swift)
- Duplicated block (12–13 lines × 2) (Sources/Auth/AuthAdmin.swift)
- Duplicated block (13 lines × 2) (Examples/Examples/Storage/FileUploadView.swift)
- Duplicated block (13 lines × 2) (Sources/RealtimeV2/RealtimeChannelV2.swift)
- Duplicated block (14 lines × 2) (Sources/RealtimeV2/RealtimeChannel+Status.swift)
- Duplicated block (16–17 lines × 2) (Sources/PostgREST/Legacy/PostgrestQueryBuilder.swift)
- Duplicated block (24 lines × 2) (Sources/Auth/AuthAdmin.swift)
- Duplicated block (33 lines × 2) (Sources/RealtimeV2/RealtimeClientV2.swift)
- Duplicated block (9 lines × 2) (Sources/RealtimeV2/Types.swift)
- Duplicated block (9 lines × 4) (Sources/PostgREST/Legacy/PostgrestQueryBuilder.swift)
- FileTooLong: RealtimeV2/RealtimeChannelV2.swift (Sources/RealtimeV2/RealtimeChannelV2.swift)
- FileTooLong: RealtimeV2/RealtimeClientV2.swift (Sources/RealtimeV2/RealtimeClientV2.swift)
- …and 30 more

## New (98)

- APIClient.error (cognitive 17) (Sources/Auth/Internal/APIClient.swift)
- AuthClient.claims (cognitive 18) (Sources/Auth/AuthClient.swift)
- Change coupling: PushV2.swift ↔ RealtimeClientV2.swift (Sources/Realtime/PushV2.swift)
- ClassTooLong: AuthClient (Sources/Auth/AuthClient.swift)
- ClassTooLong: RealtimeChannelV2 (Sources/Realtime/RealtimeChannelV2.swift)
- ClassTooLong: RealtimeClientV2 (Sources/Realtime/RealtimeClientV2.swift)
- Coverage not measured — Swift suite
- Documentation: no project overview (README.md)
- Duplicate intent for listing users. AuthAdmin exposes both 'listUsers' (returning a paginated response object) and 'users' (returning a sequence). This forces the user to choose between two different APIs for the same logical operation, with different return types and parameter structures.
- Duplicated block (10 lines × 4) (Examples/Examples/Auth/AuthWithMagicLink.swift)
- Duplicated block (10 lines × 6) (Examples/Examples/Auth/AuthWithEmailAndPassword.swift)
- Duplicated block (11 lines × 2) (Examples/Examples/Auth/AuthWithMagicLink.swift)
- Duplicated block (12 lines × 2) (Examples/Examples/Profile/ProfileView.swift)
- Duplicated block (12 lines × 2) (Sources/PostgREST/Legacy/PostgrestQueryBuilder.swift)
- Duplicated block (12 lines × 2) (Sources/Realtime/RealtimeChannelV2.swift)
- Duplicated block (12 lines × 3) (Examples/Examples/Auth/AuthWithEmailAndPassword.swift)
- Duplicated block (12 lines × 3) (Examples/Examples/Auth/AuthWithMagicLink.swift)
- Duplicated block (12 lines × 3) (Examples/Examples/Profile/UpdateProfileView.swift)
- Duplicated block (13 lines × 2) (Examples/Examples/Auth/SignInWithPhone.swift)
- Duplicated block (13 lines × 2) (Examples/Examples/Storage/FileUploadView.swift)
- …and 78 more

## Changes since last survey

- 49 commits — 37 feature/other, 12 fixes

## By area

- (root) — 15 commits
- Sources/Auth — 12 commits
- Sources/PostgREST — 4 commits
- Sources/Helpers — 3 commits
- Sources/RealtimeV2 — 3 commits
- Sources/Storage — 3 commits
- .github/workflows — 2 commits
- Tests/AuthTests — 2 commits
- Tests/IntegrationTests — 2 commits
- Tests/RealtimeTests — 2 commits
- Tests/PostgRESTTests — 1 commit

## Notable commits

- fix: fix(auth)!: decode OAuth clients that omit redirect URIs, grant types or response types (#1349)
- fix: fix(auth)!: decode OAuth server responses that omit optional fields (#1347)
- fix: fix(auth): discard a token refresh that outlived its session (#1374)
- fix: fix(auth): encode confirmsEmail and confirmsPhone as email_confirm and phone_confirm (#1388)
- fix: fix(auth): fall back to the JWT header alg when the JWK omits one (#1348)
- fix: fix(auth): keep a fixed Keychain service for every KeychainLocalStorage (#1394)
- fix: fix(auth): listen on the callback scheme the provider redirects to (#1363)
- fix: fix(auth): parse the admin pagination Link header without trapping (#1379)
- fix: fix(auth): preserve status context for non-JSON 5xx errors (#1392)
- fix: fix(postgrest): quote array elements in rpc GET/HEAD params (#1383)
- fix: fix(postgrest): strip nulls through the Accept media type, not Prefer (#1382)
- fix: fix: split Package.swift by tools-version for the swift-issue-reporting migration (#1393)
- change: chore(ci): swift-format lint gate, pinned Linux Swift, visionOS platform (#1340)
- change: chore(deps): bump github.com/apple/swift-crypto from 4.5.2 to 5.0.0 (#1376)
- change: chore(deps): bump github.com/pointfreeco/swift-snapshot-testing (#1387)
- change: chore(deps): bump github.com/swiftlang/swift-syntax (#1377)
- change: chore(deps): bump supabase/setup-cli from 3.0.0 to 3.0.1 (#1386)
- change: chore: add SwiftLint 0.65.0 with pinned CI version (#1043)
- change: chore: add a privacy manifest (#1354)
- change: chore: declare Clocks where it is used and drop XCTestDynamicOverlay (#1353)
- …and 29 more
