Security News
Maven Central Adds Sigstore Signature Validation
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Please note: This project was started by ThoughtBot. It was known by them as "Saucy". This project wasn't listed on their GitHub profile, thus I have taken it under wing.
Sassy is a Rails engine for monthly subscription-style SaaS apps.
Example scenarios covered by Saucy:
In your Gemfile:
gem "saasy"
After you bundle, run the generator:
rails generate saucy:install
You will want to include the ensure_active_account
before_filter
in any controller actions that you want to protect if the user is using an past due paid account.
You will want to customize the from email addresses.
Support email address for your application:
Saucy::Configuration.support_email_address = "support@example.com"
Personalizable emails such as trial expiration notice and activation encouragement are sent from a product manager personal address:
Saucy::Configuration.manager_email_address = "manager@example.com"
If you have an account with Braintree with multiple merchant accounts you'll want to configure the merchant account for this application:
Saucy::Configuration.merchant_account_id = 'your merchant account id'
In addition, there are a number of strings such as application name, support url, automated emails, etc. that are provided and customized with i18n translations. You can customize these in your app, and you can see what they are by looking at config/locales/en.yml in saucy.
There is a saucy:daily
rake task which should be run on a regular basis to send receipts and payment processing problem emails.
Saucy accounts become "activated" once an initial setup step is complete. This could be creating the first bug for a bug tracker, or setting up a client gem for a server API. Once the application detects that the account is activate, it should set "activated" to true on the account. This will prevent followup emails being sent to users that have already set up their accounts.
Plans need to exist for users to sign up for. In db/seeds.rb:
%w(free expensive mega-expensive).each do |plan_name|
Plan.find_or_create_by_name(plan_name)
end
Then run: rake db:seed
Generate the Braintree Fake for your specs:
rails generate saucy:specs
Generate feature coverage:
rails generate saucy:features
To use seed data in your Cucumber, add this to features/support/seed.rb:
require Rails.root.join('db','seeds')
By default Saucy uses and provides a saucy.html.erb
layout. To change the
layout for a controller inside of saucy, add a line like this to your
config/application.rb:
config.saucy.layouts.accounts.index = "custom"
In addition to just the normal yield, your layout should yield the following items in order to get everything from saucy views:
To extend the ProjectsController:
class ProjectsController < ApplicationController
include Saucy::ProjectsController
def edit
super
@deleters = @project.deleters
end
end
To define additional limit meters, or override existing limit meters, create the partials:
app/views/limits/_#{limitname}_meter.html.erb
You can override all the views by generating them into your app and customizing them there:
rails g saucy:views
Make sure you don't do this in ApplicationController:
before_filter :authenticate
Saucy's internal controllers don't skip any before filters.
FAQs
Unknown package
We found that saasy demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Security News
CISOs are racing to adopt AI for cybersecurity, but hurdles in budgets and governance may leave some falling behind in the fight against cyber threats.
Research
Security News
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.