OSS Tanbou

centralize Rails authorization rules in Ability objects and reuse the same access policy across controllers, views, and queries

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
5,681
Primary language
Ruby
License
MIT
Repository last updated
Sep 8, 2026
On this page

Overview

CanCanCan is an authorization library for Ruby and Ruby on Rails. It defines which actions a user may perform on resources through Ability rules and reuses those rules across controllers, views, and database queries. Rails helpers can also combine resource loading with authorization checks.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Centralize authorization rules in Ability objects

Include CanCan::Ability in an Ability class and define can rules so controllers and views do not duplicate the same permission conditions.

Sources: [1]

Check access with can? and enforce it with authorize!

Views and controllers can use can? or cannot?, while authorize! raises when the current user is not allowed to perform the requested action.

Sources: [1]

Filter records with accessible_by

accessible_by(current_ability) applies Ability rules to model queries so the returned records are limited to objects the user is allowed to access.

Sources: [1]

Best fit

Fits Rails applications that need consistent authorization across layers

It is useful when role, ownership, or resource attributes should drive the same authorization policy in UI rendering, controller actions, and database access.

Sources: [1]

Before adoption

Keep authentication separate from authorization

CanCanCan manages permissions on resources. Login and identity verification belong to a separate authentication mechanism whose user context is then passed into Ability rules.

Sources: [1]

Test automatic loading and authorization for custom controllers

load_and_authorize_resource automates loading and checks for RESTful controllers. Custom actions and complex associations should be tested to ensure the intended record and rule are selected.

Sources: [1]

Distinguish the 3.5.0 release from ongoing development

As of October 3, 2026, GitHub's latest release is 3.5.0, while the develop branch contains later commits. Production usage should pin a released version rather than depend on unreleased changes.

Sources: [3][4][2]

Official sources

  1. [1]CanCanCan 3.5.0 README(2026-10-03)
  2. [2]CanCanCan 3.5.0 gemspec(2026-10-03)
  3. [3]CanCanCan 3.5.0 release(2026-10-03)
  4. [4]CanCanCommunity/cancancan repository(2026-10-03)
  5. [5]CanCanCan MIT license(2026-10-03)
Supplemental curator note

CanCanCan fits Rails applications that need a single place to decide what an authenticated user may do. As policies grow, split Ability responsibilities by domain and add focused authorization tests to keep rule interactions maintainable.

Try it in 3 steps

  1. 1

    Add CanCanCan 3.5.0 to the Gemfile

    Pin the stable release in the Rails application's Gemfile and run bundle install.

    gem 'cancancan', '3.5.0'
  2. 2

    Generate the Ability class

    Create the Ability class that will hold authorization rules.

    bin/rails generate cancan:ability
  3. 3

    Check permission in a view or controller

    Define rules such as can :read, Post, ... in Ability, then reuse the same policy through can?, authorize!, and related helpers.

    can? :read, @post
Check the official README

Growth

Growth trends · Last 30 days

5,681 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
1
Open PRs
31

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • authorization
  • cancancan
  • rails
Stars
5,681
Forks
630
Watchers
94
Open issues
61
Contributors
199
Owner type
Organization
Primary language
Ruby
License
MIT
Repository last updated
Sep 8, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?