dingo/api
54.5
Adequate · 26 September 2026
8.8k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This release modernizes the framework's architecture by introducing a comprehensive set of new interfaces and contracts for authentication, routing, and HTTP handling, while removing legacy classes to streamline the codebase. Key features include a centralized API configuration, a new internal request dispatcher, and robust rate-limiting and authentication providers (Basic and JWT). The update also brings significant improvements to the transformer layer with runtime configurability and Fractal integration, alongside extensive test coverage and CI infrastructure updates for PHP 7.2+ and Laravel 7/8.
Features
Add Auth class with check() method for non-authenticating user verification
The src/Auth/Auth.php file introduces a new Auth class that manages authentication providers and user state. A key addition is the check() method, which allows verifying if a user is authenticated without triggering the full authentication process, addressing the need to check authentication status separately from enforcing it.
src/Auth · high confidence
Add Basic and JWT authentication providers
Introduced new authentication providers for the API: a Basic auth provider that validates credentials via the Laravel auth manager, and a JWT auth provider that handles token-based authentication using the Tymon JWT package. Both providers implement the Dingo API authentication contract, allowing users to secure their API endpoints with either basic or JWT-based security mechanisms.
src/Auth/Provider · high confidence
Add rate-limiting throttle classes for authenticated, unauthenticated, and route-specific requests
The package now includes a new rate-limiting subsystem under \src/Http/RateLimit/Throttle\. A base \Throttle\ abstract class defines default limits (60 requests, 60 minutes expiry) and methods to retrieve them. Three concrete throttle implementations are added: \Authenticated\ (matches when the request is authenticated), \Unauthenticated\ (matches when the request is not authenticated), and \Route\ (always matches). This allows the API to apply different rate-limiting rules depending on the user's authentication status.
src/Http/RateLimit/Throttle · high confidence
Added new API events for request matching and response morphing
The API now introduces three new event classes—RequestWasMatched, ResponseIsMorphing, and ResponseWasMorphed—to replace previous callback-based mechanisms. This change allows developers to hook into the request matching process and modify response content through event listeners, providing a more flexible way to handle API lifecycle events.
src/Event · medium confidence
Introduce API and Route facades for Dingo API
Users can now access the Dingo API functionality via the new \API\ facade, which provides convenient static methods for error handling, transformation, authentication, and routing. Additionally, the previous \Dingo\\Api\\Facades\\API\ class has been renamed and moved to \src/Facade/Route.php\ to improve namespace consistency and reflect its specific role as the route/router accessor.
src/Facade · high confidence
Introduce Fractal adapter for API response transformation
The Fractal adapter is now used to transform API responses, supporting eager loading of Eloquent collections and paginators, and allowing users to interact with the underlying Fractal instance via a callback.
src/Transformer/Adapter · medium confidence
Introduce HTTP rate limiting handler
Added a new rate limiting handler for HTTP requests, allowing developers to configure and enforce request throttling limits. The implementation supports route-specific rate limits, automatic selection of the most permissive matching throttle, and integration with the application's cache and container for flexible rate limiter configuration.
src/Http/RateLimit · high confidence
Introduce Routing Adapter contract for API route management
A new \Adapter\ interface has been added to the \Dingo\\Api\\Contract\\Routing\ namespace, defining the contract for API route adapters. This interface standardizes how routes are dispatched, their properties retrieved, and how they are stored and serialized. It includes methods for adding routes, fetching all routes or those for a specific version, and crucially, a \getIterableRoutes\ method to provide a normalized, iterable array of routes from each adapter, facilitating easier extension and integration of the package.
src/Contract/Routing · high confidence
Introduce centralized API configuration file
A new \config/api.php\ file has been added to centralize API settings, including standards tree, subtype, version, prefix, domain, name, conditional requests, strict mode, debug mode, error formatting, middleware, authentication providers, and throttling rules. This allows users to configure these aspects globally via environment variables or direct array values.
config · high confidence
Introduce internal request dispatcher and URL version helper
Added the \Dispatcher\ class in \src/Dispatcher.php\ to handle internal API requests, supporting features such as passing cookies, setting custom headers, submitting raw JSON data, and uploading files. The dispatcher manages request and route stacks, persists authentication state, and ensures proper header and prefix handling for internal requests. Additionally, a \version()\ helper function was added in \src/helpers.php\ to generate API URLs for a specified version.
src · high confidence
Introduce new exception classes and a dedicated exception handler
The package now includes a dedicated exception handler in src/Exception/Handler.php that manages API-specific error responses, including converting Eloquent's ModelNotFoundException to a 404, handling generic errors with a configurable format, and supporting custom exception handlers via a register method. New exception classes are introduced: InternalHttpException for internal server errors with response objects, ResourceException (and its subclasses StoreResourceFailedException, UpdateResourceFailedException, DeleteResourceFailedException) for resource-related errors with validation message bags, ValidationHttpException for validation failures, RateLimitExceededException for 429 rate limit errors, and UnknownVersionException for invalid API versions.
src/Exception · high confidence
Introduce optional JSON formatting and pretty-printing
The JSON response formatter now supports optional formatting via a new \JsonOptionalFormatting\ trait. Users can enable pretty-printed JSON output and customize indentation styles (tabs or spaces) and sizes through response options. This allows for more readable JSON responses when debugging or in development environments, while maintaining compact output by default.
src/Http/Response/Format · high confidence
New API console commands for caching, documentation, and route listing
Three new Artisan commands have been added to the \src/Console\ directory. The \api:cache\ command creates a cached route file for faster route registration. The \api:docs\ command generates API documentation from annotated controllers, supporting options for name, version, output file, and controller filtering. The \api:routes\ command lists all registered API routes, including details on protection, versions, scopes, and rate limiting, with support for sorting and filtering.
src/Console · high confidence
New HTTP middleware components for authentication, request handling, and rate limiting
The library introduces new middleware classes to handle core HTTP processing: \Auth\ performs authentication checks before requests are executed; \Request\ validates incoming requests, dispatches events, and manages the pipeline through the router; \RateLimit\ enforces rate limits by checking thresholds and adding standard headers to responses; and \PrepareController\ ensures the current route and controller are prepared. These components replace the previous internal handling of these concerns, providing a more modular and explicit middleware stack for API requests.
src/Http/Middleware · high confidence
New HTTP request and response classes for API handling
The package introduces new classes in the \src/Http\ directory to manage API-specific HTTP interactions. \FormRequest\ provides a base class for validating incoming requests using Laravel's validation components, handling both JSON and redirect responses. \InternalRequest\ ensures that parameters passed through internal requests are accessible via \$request-\>input()\. \Request\ extends Laravel's base request to parse the \Accept\ header for versioning, subtypes, and format types. \RequestValidator\ orchestrates the validation of incoming requests against domain, prefix, and accept headers. \Response\ handles the transformation and formatting of API responses into various formats (e.g., JSON, XML) and fires events during the morphing process.
src/Http · high confidence
New debug contracts for exception handling and validation errors
Two new interfaces have been added to the debug namespace to standardize how the API handles exceptions and validation errors. The \ExceptionHandler\ interface defines a \handle\ method for processing thrown exceptions, while the \MessageBagErrors\ interface provides methods (\getErrors\ and \hasErrors\) to interact with Laravel's message bag for retrieving validation error messages.
src/Contract/Debug · high confidence
New response factory with HTTP status code helpers
A new \Dingo\\Api\\Http\\Response\\Factory\ class has been introduced, providing dedicated methods for generating HTTP 201 (created), 202 (accepted), and 204 (no content) responses. The factory also includes methods for binding items, collections, arrays, and paginators to transformers, with the \array\ method now supporting direct array input without requiring a transformer.
src/Http/Response · high confidence
New routing components for API versioning and resource registration
Introduced new classes in the Routing namespace to support API versioning, resourceful controller routing, and URL generation. The Router class now manages versioned route groups and exposes helper methods for defining routes. The Route class encapsulates version, scope, authentication, and rate-limiting metadata, merging controller-level configurations into route definitions. A new ResourceRegistrar extends the base registrar to handle resourceful routes while excluding 'create' and 'edit' actions. Additionally, a Helpers trait provides convenient access to the API dispatcher, authentication, and response factory from controllers, while the UrlGenerator is updated to support version-specific route collections.
src/Routing · high confidence
Removals
Removal of legacy API routing classes
The \Dingo\\Api\\Routing\\Controller\ and \Dingo\\Api\\Routing\\Router\ classes have been removed from the codebase. This change eliminates the previous implementation of API-specific routing and request handling, indicating a shift in how API routes are registered and processed within the framework.
src/Dingo/Api/Routing · high confidence
Behavioural changes
Accept header parsing now supports hyphens and non-numeric versions
The Accept header parser has been updated to allow version strings that contain hyphens and are not strictly numeric. This change enables clients to use more flexible versioning schemes (e.g., 'v1.0-beta') in their Accept headers without triggering a 400 Bad Request error. The parser now correctly extracts the version, subtype, and format from the Accept header, falling back to default values if strict matching fails.
src/Http/Parser · medium confidence
Introduce Auth Provider contract
A new interface, Dingo\\Api\\Contract\\Auth\\Provider, has been added to define the contract for authentication providers. This interface specifies the authenticate method, which accepts an HTTP request and a route, and returns the authenticated user instance. This change establishes a standardized contract for authentication logic within the API framework.
src/Contract/Auth · medium confidence
Introduce a runtime-configurable transformer binding system
The transformer layer now supports dynamic, runtime configuration of transformers via a new \Binding\ and \Factory\ architecture. Developers can register transformer bindings for classes or collections, allowing the transformation logic to be resolved or customized at runtime rather than being statically bound. This enables more flexible transformer management and supports closure-based or instance-based resolver patterns.
src/Transformer · high confidence
New HTTP and Transformer contract interfaces for extensibility
The package introduces several new interfaces to allow deeper customization of the HTTP and transformation layers. In the HTTP layer, new contracts define how requests are parsed, validated, and converted from the underlying framework's request object, while the rate-limiting subsystem gains a \HasRateLimiter\ interface to support custom rate limiters. Additionally, a new \Adapter\ contract is added for the transformer layer, enabling custom response transformation logic. These changes provide extension points for developers to replace or extend core request handling and data formatting behaviors.
src/Contract/Http · high confidence
New HTTP request validators for Accept, Domain, and Prefix
The codebase introduces three new validation classes—Accept, Domain, and Prefix—located in src/Http/Validation. The Accept validator now allows OPTIONS requests to bypass strict Accept header checking, preventing validation errors for preflight requests. The Domain validator has been updated to ignore port numbers when matching the configured domain, resolving issue \#754. The Prefix validator validates that the request path matches the configured API prefix. These changes refine how the API handles HTTP headers, domain routing, and URL prefixes.
src/Http/Validation · medium confidence
Refactored routing adapters for Laravel and Lumen
The routing adapters for Laravel and Lumen have been refactored to improve how routes are managed and dispatched. For Laravel, the adapter now injects a dedicated router instance, merges existing application routes with API routes, and updates internal lookups to ensure the route helper functions work correctly. For Lumen, the adapter now removes global middleware to prevent double execution, normalizes request URIs for proper dispatching, and breaks down URIs into multiple routes to fix issues with route name generation and method handling. These changes ensure that both adapters correctly integrate with their respective frameworks' routing systems.
src/Routing/Adapter · medium confidence
Refactored service providers for improved Laravel and Lumen compatibility
The service provider architecture has been split into specialized components: DingoServiceProvider handles core registrations, HttpServiceProvider manages HTTP-related bindings (rate limiting, validation, parsers, middleware), and RoutingServiceProvider handles router and URL generation. LaravelServiceProvider and LumenServiceProvider now extend DingoServiceProvider to handle framework-specific wiring, such as middleware registration, route dispatcher replacement, and request rebinding. This separation allows each framework to maintain its own adapter and middleware setup while sharing common logic, improving maintainability and compatibility with Laravel 5+ and Lumen.
src/Provider · high confidence
Removal of default API configuration file
The default configuration file for the API, which previously defined the API vendor and default version, has been removed. Users will no longer have these specific default settings available in the package's configuration.
src/config · high confidence
Removed automatic 422 response conversion and internal request class
The \InternalRequest\ class has been removed, and the \Response\ class no longer automatically converts specific error arrays into HTTP 422 (Unprocessable Entity) responses. Previously, the \Response::process()\ method would detect an indexed array containing an error message and a \MessageBag\ instance, then rewrite the status code to 422. This automatic 'unprocessable entity' handling has been removed, meaning API errors will no longer be implicitly mapped to 422 status codes by the framework's response processor.
src/Dingo/Api/Http · high confidence
Removed legacy API exception and service provider classes
The \ApiException\ class, which previously handled HTTP error states and status code checks, has been removed from the codebase. Additionally, the \ApiServiceProvider\ and \Dispatcher\ classes have been deleted, indicating a significant refactoring of the API layer's core infrastructure and request handling mechanisms.
src/Dingo/Api · medium confidence
Updated CI configuration and test suite setup
The project's continuous integration and testing infrastructure has been modernized. The \.travis.yml\ file was updated to test against PHP 7.2, 7.3, and 7.4, replacing the previous support for PHP 5.3–5.6 and HHVM. The PHPUnit configuration was renamed from \phpunit.xml\ to \phpunit.xml.dist\ and updated to enforce stricter test standards, including failing on risky or warning conditions, excluding specific Lumen tests, and adding code coverage filtering. Additionally, new configuration files \.editorconfig\ and \.styleci.yml\ were added to enforce consistent coding styles and editor settings across the project.
(repo-wide) · high confidence
Test coverage
Add tests for JSON and JSONP response formatting; Add tests for the API exception handler; Added test coverage for HTTP validation components; Added test coverage for authentication providers; Added test coverage for the Dingo API routing layer; Added test coverage for the internal request dispatcher; Added test stubs for multiple Laravel versions; Added tests for Fractal adapter; Added tests for HTTP request validation and response handling; Added tests for the HTTP Accept header parser; Added unit tests for HTTP middleware; Added unit tests for routing adapters; Added unit tests for the Auth module; Added unit tests for the HTTP Response Factory; Added unit tests for the rate limiting handler and throttle matchers.
Dependencies
Upgrade to Laravel 7/8 and PHP 7.2.5+ support
The package now requires PHP 7.2.5 or 8.0, and supports Laravel 7 and 8 (via illuminate/routing, illuminate/support, and lumen-framework). It also updates the league/fractal dependency to ^0.19, adds dingo/blueprint as a required dependency, and migrates the autoloading to PSR-4. Development dependencies are updated to include phpunit 8.5/9.0, mockery, and various illuminate packages for testing.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 53 → 55 (+1.0)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 97 (-2.8)
- Architecture 94 → 75 (-18.6)
- Maturity 57 → 48 (-9.8)
- Readiness 27 → 41 (+13.7)
- Security 100 → 100 (+0.0)
Resolved (5)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- No exposed public API
- No tests found
- Test reliability not included
New (19)
- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Dormant codebase
- Duplicated block (12 lines × 2) (src/Http/Response/Factory.php)
- Duplicated block (23 lines × 2) (src/Provider/LaravelServiceProvider.php)
- Duplicated block (7 lines × 2) (src/Provider/LaravelServiceProvider.php)
- Lumen.getIterableRoutes (cognitive 21) (src/Routing/Adapter/Lumen.php)
- Most significant orphaned file (src/Routing/Router.php)
- No dependency advisory monitoring
- Skipped (documented): testRoutesWithDomains (tests/Routing/Adapter/LumenTest.php)
- TodoComment (tests/Stubs/Application58Stub.php)
- TodoComment (tests/Stubs/Application6Stub.php)
- TodoComment (tests/Stubs/Application7Stub.php)
- TodoComment (tests/Stubs/Application8Stub.php)
- TodoComment (tests/Stubs/ApplicationStub.php)
- TooManyMethods: Dispatcher (src/Dispatcher.php)
- TooManyMethods: Route (src/Routing/Route.php)
- TooManyMethods: Router (src/Routing/Router.php)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
dingo/api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 42b6afa6e20a27f938a45e676665e57d26422cea — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.