Skip to content
CAI
Software that uses CAICheck a score

loco-rs/loco

59.0

Adequate · 29 September 2026

45.1k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Loco framework, a Rust-based toolkit for building full-stack web applications, REST APIs, and SaaS platforms. It provides a comprehensive suite of features including JWT and magic link authentication, a unified background job queue, multi-tenant database support, and a pluggable caching and storage layer. The framework also includes a CLI for scaffolding projects, a code generator for boilerplate, and an evaluation harness for testing AI coding agents.

How it got here

2023 — Loco 1.2.0 release and demo modernization

33 changes.

This period centered on the Loco 1.2.0 release, introducing presigned storage URLs, multi-tenancy, and agent skills alongside a comprehensive overhaul of the demo application to align with the 1.0.0 stable API. The work involved migrating the demo to magic link authentication, refactoring controllers and models, and removing legacy code generation modules and deprecated CLI tools. Additionally, new xtask tooling was established to automate CI, versioning, and documentation maintenance.

2024 — Core infrastructure and CLI scaffolding

46 changes.

This period focused on building foundational framework components, including a new storage abstraction with OpenDAL, a generic caching layer, and a multi-tenancy system. Simultaneously, the Loco CLI was rewritten to support dynamic project scaffolding via Rhai scripts, introducing comprehensive templates for SaaS applications, React frontends, and background workers.

2025–2026 — Framework extensibility and tooling

11 changes.

This period focused on enhancing the Loco framework's developer experience through new controller extractors for authentication and validation, alongside build-time static asset embedding. It also expanded the ecosystem with a comprehensive reference SPA example, a migration of the documentation site to Astro, and an evaluation harness for coding agents.

Features

Added Docker and Nginx deployment templates for generated applications

The generator now includes new template files to produce Docker and Nginx configuration for deployed applications. Specifically, it generates a Dockerfile based on \rust:1.94.0-slim\ that supports both server-side and client-side rendering (installing Node.js and building the frontend when \is\_client\_side\_rendering\ is true), along with a corresponding \.dockerignore\ file. Additionally, it generates an Nginx \default.conf\ that handles proxying to the application on the specified domain and port, including support for subdomain-based routing.

loco-gen/src/templates/deployment/docker · high confidence

Added Loco agent evaluation harness and test corpus

Introduced a new \evals/\ directory containing an automated evaluation suite for measuring how well coding agents write idiomatic Loco code. This includes a \grade.py\ script for scoring greenfield app builds, a curated corpus of tasks (such as API-key endpoints, cached stats, and mailers) with reference solutions, and hidden behavioral tests that verify runtime correctness (like click counting and user scoping) after code generation. The suite is designed to track agent fluency and token efficiency against the Loco framework.

(repo-wide) · high confidence

Added database migrations for users and posts tables

The reference SPA example now includes database migration files that define the schema for 'users' and 'posts' tables. The 'users' table migration creates columns for id, pid, email, password, api\_key, name, and various authentication-related fields (reset\_token, email\_verification\_token, magic\_link\_token, etc.). The 'posts' table migration creates columns for id, title, content, status, price, and published\_at. These migrations are registered in the Migrator struct, enabling the application to initialize its database schema.

_examples/reference\spa/migration · high confidence

Added demo application assets and internationalization support

The demo application now includes static assets and internationalized content. This adds a 404 error page, shared translation strings, and locale-specific files for English (en-US) and German (de-DE) covering greetings and navigation labels. A home view template demonstrates rendering these translations dynamically based on the selected language.

examples/demo/assets · high confidence

Added mailer and task generation templates

The code generator now includes templates for creating mailers and background tasks. New files in loco-gen/src/templates/mailer provide the structure for mailer modules (including shared HTML/text bases and welcome email templates), while loco-gen/src/templates/task provides the Rust implementation and corresponding unit test template for new tasks. This enables users to generate these components via the CLI.

loco-gen/src/templates/mailer · high confidence

Added number formatting filters to Tera templates

Users can now format numeric values directly in Tera templates using three new filters: \number\_with\_delimiter\ adds thousands separators (e.g., 1,000), \number\_to\_human\_size\ converts byte counts into human-readable units (e.g., 70.69 MB), and \number\_to\_percentage\ formats numbers as percentages with an optional custom format string. These filters are registered in the \tera\_builtins\ module and handle invalid inputs gracefully by returning the original value.

_src/controller/views/tera\builtins · high confidence

Generated controller and API test templates for Loco

The code generator now includes templates for creating API controllers and their corresponding integration tests. When a new controller is generated, it produces a Rust module with an \index\ action and any additional defined actions, registering routes under a pluralized API prefix. Simultaneously, it generates integration tests in \tests/requests/\ that verify the endpoints return a 200 status for public routes or 401 for routes requiring JWT authentication, ensuring immediate test coverage for new API endpoints.

loco-gen/src/templates/controller · high confidence

Introduce generic cache module with Redis and in-memory drivers

The application now includes a new \src/cache\ module that provides a generic caching interface supporting multiple backends. Users can configure the cache via application settings to use either an in-memory store or Redis (enabled via the \cache\_redis\ feature), or disable caching entirely with a null provider. The module exposes standard operations such as inserting, retrieving, and checking for key existence, with automatic serialization and deserialization of values using Serde.

src/cache · high confidence

Introduce opt-in multi-tenancy support with explicit tenant scoping

The \src/model\ module now includes a new \tenant\ module (enabled via the \multi-tenancy\ feature flag) that provides traits for explicit tenant scoping in Sea-ORM entities. Users can implement \TenantEntity\ to mark an entity as tenant-owned, and use \TenantQueryExt\ to restrict queries (\Select\, \UpdateMany\, \DeleteMany\) to a specific tenant via \in\_tenant()\. Additionally, \TenantActiveModelExt\ allows safe assignment of the tenant key on active models, preventing tenant key changes after initial assignment by returning a \ModelError::TenantMismatch\ error. This change also introduces a \ModelError\ enum with variants for \TenantMismatch\ and \Jwt\ (the latter gated by the \auth\ feature), along with convenience methods for wrapping errors.

src/model · high confidence

Introduce pluggable cache driver architecture with in-memory and Redis support

The application now supports a configurable caching layer via a new \CacheDriver\ trait and specific implementations. Users can choose between an in-memory cache (using the \moka\ library) for development or lightweight scenarios, and a Redis cache (using \bb8-redis\) for production use, or rely on the default null driver which silently ignores cache operations. The API supports both standard key-value storage and entries with time-to-live (TTL) expiration, allowing developers to optimize performance by caching expensive computations or data lookups.

src/cache/drivers · high confidence

JWT module with custom claims support

The authentication module now includes a new JWT implementation that supports HMAC-based signing algorithms (HS256, HS384, HS512) and allows attaching arbitrary custom claims to user tokens via a flattened JSON map, enabling flexible payload extension while maintaining standard expiration and user ID fields.

src/auth · high confidence

Loco 1.2.0 release with presigned storage URLs, multi-tenancy, and agent skills

This release introduces presigned storage URLs for direct S3/Azure/GCS uploads and downloads, row-level multi-tenancy for scoped database queries, and a new \TeraView::render\_component\ method for rendering individual Tera 2 components. It also adds batch job enqueueing via \perform\_all\_later\, a Loco skill for coding agents to generate idiomatic code, and a \user:delete\ CLI task. Additionally, SQLite support is now opt-in via a feature flag to reduce build sizes, and \perform\_later\_with\_priority\ now returns an error if no queue provider is configured instead of silently succeeding.

(repo-wide) · high confidence

Loco CLI generator scaffolds new Rust applications with configurable features

The loco-new module now provides the template engine and setup scripts (setup.rhai) used by the Loco CLI to scaffold new Rust projects. Users can generate applications with optional database support, authentication, mailers, background workers, and either server-side or client-side asset handling. The generator also includes pre-configured CI workflows, test structures, and example code to help developers start building SaaS apps, REST APIs, or lightweight services quickly.

loco-new · high confidence

Mailer now supports CC, BCC, custom headers, multi-recipient sending, and shared templates

The mailer component has been expanded to support richer email features. Users can now send emails with CC and BCC recipients, and attach custom headers (References, In-Reply-To, Message-ID) to individual messages. A new \mail\_multi\ capability allows sending a single email to multiple recipients in one go. The template engine now supports shared template directories, enabling multiple mailers to inherit from common base layouts. Additionally, SMTP configuration has been refined to explicitly support STARTTLS, implicit TLS, and cleartext modes, and a \hello\_name\ option is now exposed for the SMTP client.

src/mailer · high confidence

New CLI generator for scaffolding Loco applications

The \loco-new\ crate introduces a new command-line interface for generating new Loco projects. Users can now scaffold applications using an interactive wizard or command-line arguments, selecting from templates such as SaaS (server-side or client-side rendering), REST API, lightweight service, or advanced configurations. The generator allows customization of database backends (SQLite, Postgres, or none), background worker modes (Async, Blocking, or Queues with Redis/Postgres/SQLite), and asset handling (Server, Client, or None). It also supports OS-specific defaults and ensures the generated application's \loco-rs\ dependency version matches the CLI release to prevent compatibility issues.

loco-new/src · high confidence

New CLI generator with Rhai scripting and Tera templates

The \loco-new\ CLI now uses a new generator module that executes project scaffolding via Rhai scripts. This allows for dynamic, scripted generation of files and directories, with support for Tera template rendering (using \.t\ extension) and random string generation for customizable project setup.

loco-new/src/generator · high confidence

New Loco CLI generator for creating applications

A new command-line interface has been introduced in loco-new/src/bin/main.rs, allowing users to scaffold new Loco applications via the 'loco new' command. This CLI accepts options to configure the database provider, background worker settings, asset serving, and OS-specific optimizations (defaulting to Linux on Unix systems and Windows on others). It also supports embedding static assets and includes safety checks to warn users if the target directory is already a Git repository.

loco-new/src/bin · high confidence

New SaaS starter template with React frontend and full authentication

The base template now includes a complete SaaS starter kit featuring a React frontend (Vite, React Router, TanStack Query) alongside the existing Rust backend. This addition provides out-of-the-box user authentication (JWT-based login, registration, email verification, password reset, and magic link login), internationalized server-side views, and TypeScript bindings generated from the backend DTOs. The template also introduces a new \ViewEngineInitializer\ for configuring the Tera view engine with Fluent i18n support, and updates the backend dependencies to include Axum 0.8, SeaORM 2.0, and Validator 0.20.

_loco-new/base\template · high confidence

New background job queue system with Postgres, SQLite, and Redis backends

The \src/bgworker\ module introduces a unified background job queue system supporting three storage backends: Postgres, SQLite, and Redis. This system provides a consistent API for enqueuing, processing, and managing background jobs, including features like job status tracking (queued, processing, completed, failed, cancelled), priority handling, and tag-based filtering. The implementation includes a shared SQL-based queue layer for Postgres and SQLite, with Redis offering a separate atomic job queue implementation. Workers can be configured with cancellation tokens for graceful shutdown, and the system includes a reaper mechanism to handle stale jobs. The module also provides snapshot tests verifying job lifecycle operations across all backends.

src/bgworker · high confidence

New date range query builder in the query DSL

The query DSL now includes a \DateRangeBuilder\ that allows users to filter records by a specific date range. By calling \condition().date\_range(column).from(date)\ or \.to(date)\, or both via \.dates(from, to)\, developers can easily construct SQL conditions for \\>\ (greater than), \\<\ (less than), or \BETWEEN\ operations on datetime columns, simplifying the creation of time-based filters.

src/model/query/dsl · high confidence

New diagnostic and infrastructure modules for application health and configuration

This release introduces several new internal modules to support application diagnostics and configuration management. The \doctor\ command now includes a \depcheck\ subsystem that validates dependency versions against minimum requirements by parsing \Cargo.lock\, and it can run health checks for specific initializers. A new \CargoConfig\ module allows reading database entity settings from \Cargo.toml\, while a \data\ module provides synchronous and asynchronous helpers for loading JSON files from a configurable data folder. Additionally, the \tera\ module now registers a \get\_env\ function to support environment variable access in templates, and the \hash\ module has been updated to use Argon2 for password hashing instead of the previous implementation.

src · high confidence

New file-system abstraction for the CLI generator

The CLI generator now uses a new \Executer\ trait in \loco-new/src/generator/executer\ to handle file operations, introducing \FileSystem\ (for real disk I/O) and \Inmem\ (for in-memory storage) implementations. This allows the generator to copy files, create content, and render templates using the Tera engine with configurable settings, providing a unified interface for how generated project files are written or stored.

loco-new/src/generator/executer · high confidence

New pagination query and response structures

The \src/model/query/paginate\ module now provides \PaginationQuery\ and \PageResponse\ types to standardize how API consumers request and receive paginated data. \PaginationQuery\ handles input parameters like \page\ and \page\_size\ with sensible defaults (page 1, size 25) and robust deserialization, while \PageResponse\ wraps the resulting data slice with metadata via \PagerMeta\. This change introduces the structural contract for pagination rather than altering existing runtime behavior, serving as the foundation for the \paginate\ and \fetch\_page\ helper functions defined in the same file.

src/model/query/paginate · high confidence

New reference SPA example with typed React frontend

Added a new \reference\_spa\ example application that serves as a golden reference for a full-stack Loco setup. This includes a Rust backend using Loco 1.0 with Sea-ORM 2.0 and JWT authentication, and a React 19 frontend built with Vite, React Router v8, and TanStack Query v5. The frontend is strictly typed against the Rust backend using \ts-rs\ bindings, eliminating the need for OpenAPI. The example demonstrates a complete CRUD workflow for 'Posts' with authentication flows (login, register, logout) and provides configuration for development, production, and test environments.

_examples/reference\_spa, examples/reference\spa/frontend · high confidence

New request extractors for authentication, validation, and shared store access

This change introduces a new \src/controller/extractor\ module containing Axum extractors that simplify common request handling patterns. The \auth\ module provides \JWT\ and \JWTWithUser\ extractors that automatically validate JWT tokens from configurable locations (header, cookie, or query) and, when the database feature is enabled, attach the corresponding user entity. The \validate\ module adds \JsonValidate\, \FormValidate\, and \QueryValidate\ extractors (with \WithMessage\ variants) to automatically validate request bodies and parameters using the \validator\ crate, returning structured error responses on failure. Additionally, the \shared\_store\ module provides a \SharedStore\<T\>\ extractor for retrieving services from the dependency injection container.

src/controller/extractor · high confidence

New storage module with strategy-based abstraction and streaming support

The \src/storage\ module introduces a generic storage abstraction (\Storage\) that delegates operations to pluggable strategies, including \SingleStrategy\ for direct access and \ReplicatedStrategy\ for primary/secondary replication with configurable failure policies. The module adds streaming capabilities for both uploads and downloads via \BytesStream\, enabling memory-efficient handling of large files and direct integration with \axum\ HTTP responses. It also adds presigned URL support (\presign\_get\/\presign\_put\) to the strategy interface and replaces the previous \object\_store\ dependency with \opendal\ for the underlying driver implementation.

src/storage · high confidence

New xtask CLI for release, testing, and evaluation workflows

A new command-line interface has been added to the xtask tool, providing developers with subcommands to manage the Loco project lifecycle. Users can now run \bump\ to update version numbers across the workspace, \test\ to execute CI checks on all resources or just the library, \docs-syntax\ to validate Rust code blocks in documentation, \agent-skill\ to regenerate and verify API indexes, and \eval\ to measure agent performance against idiomatic Loco patterns. This centralizes automation tasks previously handled by disparate scripts or manual processes.

xtask/src/bin · high confidence

New xtask tooling for CI, versioning, and agent-skill maintenance

The \xtask\ development tool is introduced to automate and enforce quality gates across the workspace. It adds a CI runner (\xtask ci\) that executes \cargo fmt\, \clippy\, and \cargo test\ on the library, examples, and starters. A version-bumping command (\xtask versions\) synchronizes crate versions across \Cargo.toml\ files and the \LOCO\_VERSION\ constant, ensuring generated apps use the correct dependency floor. Additionally, an agent-skill module (\xtask agent\_skill\) automatically regenerates API documentation indices from rustdoc JSON and mirrors them into the \loco new\ template, while a syntax checker (\xtask docs\_syntax\) validates Rust code blocks in documentation and skill files to prevent broken snippets.

xtask/src · high confidence

Support for embedding static assets at build time

The application now includes a build-time mechanism to embed static assets (such as templates and other files) directly into the binary. A new build script scans the \assets/\ directory, discovers all files recursively, and generates Rust code to embed them. This allows the application to serve these assets without requiring them to be present on the filesystem at runtime, while also providing clear warnings if the assets directory is missing or if environment variables like \CARGO\_TARGET\_DIR\ interfere with asset detection.

build · high confidence

Removals

Removal of generator templates for controllers, models, mailers, tasks, and workers

The template files used by the code generator to scaffold controllers, models, mailers, tasks, workers, and their associated tests have been removed from the project. This eliminates the ability to generate new boilerplate code for these components via the generator.

src/gen/templates · high confidence

Removal of legacy code generation modules

The \src/gen\ module, including \mod.rs\, \model.rs\, and \scaffold.rs\, has been removed. This eliminates the legacy code generation capabilities for Models, Scaffolds, Controllers, Tasks, Workers, and Mailers that were previously exposed via the \Component\ enum and \generate\ function.

src/gen · high confidence

Removal of the AdiDoks Zola theme

The AdiDoks theme, a Zola port of the Hugo Doks theme, has been completely removed from the documentation site. This change deletes the entire \docs-site/themes/adidoks\ directory, including all configuration files (\config.toml\), source code (Sass/Bootstrap), templates, and sample content (blog posts, documentation pages, and author profiles). Users will no longer have access to this specific theme or its default layout and styling options.

docs-site/themes · high confidence

Removal of the legacy Loco CLI binary

The \loco-cli/src/bin/main.rs\ file has been deleted, removing the legacy command-line interface that previously handled project generation via the \New\ subcommand. This change eliminates the old code path for scaffolding Loco applications, aligning with the removal of deprecated starter projects and the introduction of a new CLI generator.

loco-cli/src/bin · high confidence

Removal of the stateless example application

The \examples/stateless\ directory has been completely removed, deleting the example application's source code, configuration files, and associated tests. This eliminates the demo app that previously provided a starting point for building stateless applications with the framework.

examples/stateless · high confidence

Removed deprecated loco-cli source modules

The deprecated loco-cli library source files (generate.rs, lib.rs, and template.rs) have been removed from the codebase. This deletion eliminates the previous implementation for generating new projects from starter templates (such as SaaS and stateless options) and the associated CLI command exit handling logic, aligning with the project's decision to remove these legacy starter projects.

loco-cli/src · high confidence

Behavioural changes

The demo application now supports magic link authentication by introducing new email templates (subject, text, and HTML) for the magic link flow, alongside updates to the existing welcome and forgot-password templates. The email templates have been standardized to use a {{host}} variable instead of {{domain}} or hardcoded localhost URLs, ensuring consistent link generation across all auth emails. The Rust mailer implementation has been updated to include the new magic link sending method and to use .clone() for email addresses instead of .to\_string().

examples/demo/src/mailers · high confidence

Demo app adopts Loco 1.0.0 API and removes unused code

The demo application has been updated to align with the Loco 1.0.0 stable release, introducing several behavioral and structural changes. The app now exposes its version via the new \app\_version\ hook, which displays the crate version and build SHA. The background worker system has migrated from the legacy \AppWorker\ trait to the new \BackgroundWorker\ trait, requiring updates to worker registration and execution. Additionally, the \boot\ method now uses a standardized \create\_app\ flow with a migrator, and the \routes\ hook has been simplified to only register authentication routes, removing the previously included notes and user controllers. The \DownloadWorker\ implementation has been stripped of its actual database querying logic and sleep delays, leaving only a placeholder implementation. New modules for \data\ and \initializers\ have been added to support the new initialization system.

examples/demo/src · high confidence

The demo application's controller layer has been significantly restructured. The \notes\ and \user\ controller modules, along with their associated views, have been removed entirely. Authentication logic in \auth.rs\ has been expanded to support passwordless magic link login (including request and verification flows) and now uses a standardized \Response\ return type instead of \Json\<()\>\ for most endpoints, improving consistency. A new \CurrentResponse\ view was added to expose user details, and the \current\ endpoint now explicitly uses JWT authentication. Additionally, email validation for magic links was introduced using a regex pattern for allowed domains.

examples/demo/src/controllers · high confidence

Demo app entity model updates and notes removal

The demo application's entity models have been regenerated using sea-orm-codegen 1.0.0, replacing the previous 0.12.x generation. This update removes the 'notes' entity entirely and updates the 'users' entity to use 64-bit integers for the primary key (i64) and timezone-aware datetime types (DateTimeWithTimeZone) for all timestamp fields. Additionally, the users model now includes new fields for API key authentication (api\_key) and magic link login (magic\_link\_token, magic\_link\_expiration).

_examples/demo/src/models/\entities · high confidence

Demo app example structure updated for Loco 1.0.0

The \examples/demo\ directory has been restructured to align with the Loco 1.0.0 stable release. The previous entry points (\start.rs\, \task.rs\, and \workers.rs\) which relied on the \blo\ crate and manual environment variable handling have been removed. They are replaced by a new \playground.rs\ example that utilizes the \loco\_rs\ CLI playground feature, providing a simplified entry point for users to interact with the demo application.

examples/demo/examples · high confidence

Demo app now uses a dedicated view engine initializer with i18n support

The demo application now organizes its startup logic through a new \initializers\ module, specifically introducing a \ViewEngineInitializer\. This change configures the Tera template engine and integrates Fluent for internationalization (i18n) if locale assets are present in \assets/i18n\, while also handling shared translation resources to prevent bundle conflicts. For users of the demo, this represents a structural shift in how the view layer is bootstrapped, ensuring that template rendering and translation functions are correctly registered via the application's initializer pipeline rather than ad-hoc setup.

examples/demo/src/initializers · high confidence

Demo application renamed and updated to use Loco 1.0.0 error types

The demo application entry point has been updated to reflect the new crate name (importing from \demo\ instead of \blo\) and to align with the Loco 1.0.0 stable release by switching the main function's return type from \eyre::Result\ to \loco\_rs::Result\.

examples/demo/src/bin · high confidence

Introduction of modular query DSL and pagination components

The query module has been restructured to separate concerns by introducing dedicated modules for the domain-specific language (DSL) and pagination logic. This change exposes the DSL and pagination functionality publicly, allowing users to leverage these specific capabilities within the query system.

src/model/query · medium confidence

Redesigned middleware architecture with new and updated components

The middleware layer has been completely redesigned to use a unified \MiddlewareLayer\ trait, making all components configurable via application settings. New middleware has been added to handle panic recovery (\catch\_panic\), HTTP compression (\compression\), ETag-based caching (\etag\), and custom fallback responses for 404s (\fallback\). Existing functionality has been updated: CORS now supports explicit configuration for credentials and expose headers with validation; the remote IP extractor now relies on the \axum-client-ip\ crate with a simplified source configuration; and the logger now integrates request IDs and environment context into trace spans. Additionally, a \format\ extractor has been introduced to detect response content types from request headers, and a \powered\_by\ middleware allows customizing the \X-Powered-By\ header.

src/controller/middleware · high confidence

Refactor health monitoring and route registration API

The separate health and ping controllers have been consolidated into a single monitoring module that exposes /\_ping, /\_health, and /\_readiness endpoints, with the readiness check now verifying database, queue, and cache connections based on enabled features. The route registration API has been updated to use a verb-explicit builder (e.g., Routes::get/post/put/delete) that records HTTP methods directly instead of parsing debug strings, and AppRoutes now supports nested prefixes via nest\_prefix and nest\_route methods.

src/controller · high confidence

Replaced user report task with user creation task in demo app

The demo application's CLI task suite has been updated to replace the 'user\_report' task, which listed existing users, with a new 'user:create' task. This new task allows administrators to create a new user by providing email, name, and password arguments via the command line; it automatically handles password hashing, triggers the email verification process, and sends a welcome email to the new user.

examples/demo/src/tasks · high confidence

Rewritten generator engine with new DSL and migration inference

The code generator has been rebuilt from the ground up, replacing the previous JSON-based field-type mapping with a new Rust-based DSL parser in \column.rs\ that serves as the single source of truth for column types. This change introduces a new command syntax for defining columns (e.g., \!\ for required, \^\ for unique, \references?\ for nullable foreign keys) and adds automatic migration name inference in \infer.rs\ to determine migration types (create, add columns, rename, etc.) from command arguments. The generator now supports more granular control over generated code, including a \--without-tz\ flag for timestamps, support for nullable foreign keys, extra fields in join tables, and named/multiple references. Additionally, the scaffold generator now conditionally emits React-SPA frontend files only when the app has a client-side frontend, and controller generation now correctly maps action names to HTTP verbs (e.g., \create\ to \POST\).

loco-gen/src · high confidence

Simplified migration syntax and updated user schema in demo app

The demo application's database migration logic has been refactored to use a more concise, declarative API for defining tables, replacing the previous verbose SeaQuery builder pattern with helper functions like \create\_table\ and \drop\_table\. This change also updates the \users\ table schema to include new columns for API key authentication (\api\_key\) and magic link login (\magic\_link\_token\, \magic\_link\_expiration\), while removing the \notes\ table migration entirely.

examples/demo/migration · high confidence

Storage drivers now use OpenDAL and support presigned URLs

The storage driver implementations in \src/storage/drivers\ have been rewritten to use the OpenDAL library instead of the previous \object\_store\ crate, enabling support for AWS S3, Azure Blob, GCP Cloud Storage, local filesystem, and in-memory storage. This change introduces presigned URL capabilities (\presign\_get\ and \presign\_put\) for S3, allowing users to generate temporary, signed URLs for direct object access and uploads. The \StoreDriver\ trait and its adapters have been updated to reflect these new capabilities, and the null driver now explicitly errors on all operations to prevent silent failures.

src/storage/drivers · high confidence

Updated base template to use SeaORM migration v2 with expanded user schema

The base template's database migration module has been upgraded to use sea-orm-migration version 2.0, requiring the explicit selection of async runtime features (such as tokio-rustls) in the Cargo configuration. Additionally, the default user migration now creates a 'users' table that includes fields for magic link authentication (magic\_link\_token, magic\_link\_expiration) alongside existing authentication and verification fields, reflecting the addition of magic link support to the generated application structure.

_loco-new/base\template/migration · high confidence

The demo application's user model has been refactored to support new authentication flows and cleaner query construction. A new \find\_by\_magic\_token\ method allows users to authenticate via magic links with expiration checks, while the \ActiveModelBehavior\ now automatically generates an \api\_key\ for new users. Query logic across the model (email, reset token, magic token, PID lookups) has been standardized to use a new \model::query::condition\ builder. Additionally, the validation system was simplified by replacing the custom \ModelValidator\ struct with a \Validatable\ trait implementation, and the unused \notes\ model was removed from the module.

examples/demo/src/models · high confidence

View engine refactoring and pagination API fix

The view rendering system has been restructured to support both on-disk and embedded template sources via a feature flag, with the engine now handling post-processing (such as registering custom filters) before template loading to comply with Tera 2's requirements. In debug builds, the engine now supports hot-reloading of view files. Additionally, the pagination response structure has been fixed to allow proper round-trip serialization and deserialization, ensuring the \total\_items\ field is correctly exposed in the \pagination\ object of API responses.

src/controller/views · high confidence

Website migrated from Zola to Astro with Starlight

The documentation and marketing site has been rebuilt using Astro and the Starlight theme, replacing the previous Zola-based static site generator. This migration includes a custom warm-dark code theme, a reorganized sidebar structure that preserves all existing documentation URLs, and automated scripts to convert Zola TOML frontmatter to Starlight YAML and rewrite internal links. The site now features pre-fetching for faster navigation, a new SVG icon, and serves an AI agent skill at /skills/loco. Legacy URLs for docs, blog posts, and casts are maintained via redirects and parity checks to ensure no broken links.

website · high confidence

Test coverage

Add scheduler job configuration template; Added Cargo configuration template for Windows linker and OS-specific aliases; Added comprehensive integration and snapshot tests for the code generator; Added comprehensive test coverage for the application generator templates; Added end-to-end tests for the project wizard; Added integration tests for controller extractors; Added integration tests for controller response handling and middleware behavior; Added model tests for the user authentication module; Added playground example template for Loco CLI generators; Added request-level integration tests for the generated application; Added scaffold templates for API, DTOs, and React frontend pages; Added server infrastructure test utilities; Added snapshot tests for middleware behavior; Added test coverage for generated application configuration and test structure; Added test fixtures for email templates and background jobs; Added test module for workers; Added test module structure for the new CLI generator; Added test templates for database migration generation; Added test templates for generated models; Added test templates for generated workers; Added tests for Lambda deployment template and view rendering; Added tests for embedded assets build script; Added tests for the data subsystem templates; Added tests for the user creation task; Added tests for user management CLI tasks; New test configuration module for isolated integration testing; New testing utilities for database isolation, HTTP requests, and HTML assertions; Removed CLI snapshot tests for demo app commands; Removed deprecated CLI test suite; Snapshot tests added for app routes and response formatting; Snapshot tests added for generated application templates; Snapshot tests for scheduler display and worker queue configuration; Updated request tests for the demo app's authentication endpoints; Updated test module structure in demo application; Updated user model test snapshots to reflect new fields and validation changes; Updated user model tests to use simplified boot and seed helpers.

Dependencies

Add reference SPA example and update generator templates to React 19 and Axum 0.8

The \loco-new\ generator now scaffolds applications using React 19, Vite 8, and Axum 0.8, aligning the starter projects with current web and Rust ecosystem standards. A new \examples/reference\_spa\ directory provides a complete reference implementation of a Single Page Application using these updated dependencies, including SeaORM 2.0.0-rc and validator 0.20. The \loco-gen\ crate has been updated to version 1.2.0 to support these new template structures, and the website dependencies have been refreshed to Astro 7 and Starlight 0.41.7.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 59 → 59 (-0.5)
  • Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.

Lenses

  • Code Health 93 → 91 (-1.7)
  • Architecture 100 → 98 (-2.1)
  • Maturity 66 → 67 (+1.6)
  • Readiness 65 → 65 (-0.3)
  • Security 75 → 77 (+1.9)
  • Domain Modelling 72 → 63 (-9.0)
  • Accessibility 48 → 49 (+0.5)
  • Performance 100 (new)

Resolved (6)

  • Hotspot: build/embedded_assets.rs (build/embedded_assets.rs)
  • Hotspot: loco-gen/src/column.rs (loco-gen/src/column.rs)
  • Hotspot: src/bgworker/redis.rs (src/bgworker/redis.rs)
  • Hotspot: src/schema.rs (src/schema.rs)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (src/bgworker/redis.rs)
  • Off-boarding risk: anonymized user #1

New (43)

  • Conflicting JWT configuration models. There is a runtime JWT builder class (loco_rs.auth.jwt.JWT) that takes a secret in its constructor and expiration in its method, and a configuration struct (loco_rs.config.auth.JWT) that holds secret and expiration as properties. It is unclear if these are related or if the config struct is used to instantiate the runtime class, leading to potential duplication of JWT logic.
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Duplicate intent between QueueProvider and Queue. QueueProvider is a low-level driver interface, while Queue is a wrapper. However, they expose nearly identical public methods (enqueue, enqueue_batch, clear, etc.) with only minor type differences (JsonValue vs generic A). This forces users to understand which abstraction to use for simple queue operations, creating confusion.
  • Duplicated block (12 lines × 2) (src/bgworker/pg.rs)
  • Duplicated block (5 lines × 2) (src/bgworker/mod.rs)
  • Duplicated block (5 lines × 6) (evals/tasks/api-key-endpoint/wiring/src/app.rs)
  • Duplicated block (6 lines × 2) (src/bgworker/pg.rs)
  • Duplicated block (7 lines × 2) (evals/tasks/user-search/reference/src/views/user_search.rs)
  • Duplicated block (8 lines × 2) (src/bgworker/pg.rs)
  • Duplicated block (9 lines × 6) (evals/tasks/api-key-endpoint/wiring/src/app.rs)
  • FileTooLong: bgworker/mod.rs (src/bgworker/mod.rs)
  • FileTooLong: src/agent_skill.rs (xtask/src/agent_skill.rs)
  • FileTooLong: src/eval.rs (xtask/src/eval.rs)
  • Further sole-owners (lower concentration)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/controller/mod.rs (src/controller/mod.rs)
  • Medium: security finding (details withheld)
  • …and 23 more

Changes since last survey

  • 14 commits — 13 feature/other, 1 fixes

By area

  • website/src — 7 commits
  • src/bgworker — 2 commits
  • (root) — 1 commit
  • evals/tasks — 1 commit
  • src/controller — 1 commit
  • src/storage — 1 commit
  • website/package.json — 1 commit

Notable commits

  • fix: fix(bgworker/redis): survive a slow or dropped worker connection (#1831)
  • change: Add render_component to TeraView. (#1822)
  • change: Add tenant query scoping and a full-stack multitenancy example (#1824)
  • change: Loco 1.2.0
  • change: blog: Loco 1.2.0 announcement
  • change: blog: byline the agent series to Dotan Nahum
  • change: blog: date the agent series and 1.2.0 post for today's publish
  • change: blog: five-part series on teaching coding agents Loco
  • change: blog: link the agent series from the 1.2.0 post; redirect /skills/loco to SKILL.md
  • change: chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates (#1826)
  • change: docs: modernize "the tour" applying new code style (#1829)
  • change: feat(bgworker): perform_all_later batch job enqueueing (#1821)
  • change: feat(storage): add presign_get/presign_put to StoreDriver (#1827)
  • change: feat: optional db-sqlite feature for Postgres-only compile paths (#1828)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

loco-rs/loco was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9f7e021e9fe68275a9a7e1ab3e7dd25c483d2bd8 — the exact code this score is about.
  • Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-705631bb727e.