Skip to content
CAI
Software that uses CAICheck a score

reactiveui/refit

57.3

Adequate · 23 September 2026

51.6k

lines of production code

C#

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Refit is a type-first REST library for .NET that generates HTTP clients from C\# interfaces using source generators and reflection. It supports modern .NET versions including Native AOT and trimming, while maintaining compatibility with legacy frameworks through polyfills. The system provides secure, configurable serialization for JSON and XML, integrates with dependency injection for scoped authentication, and includes comprehensive analyzers to enforce interface contract correctness.

Features

Add .NET DevContainer configuration

Developers can now open the project in a pre-configured VS Code DevContainer environment. This setup provides a .NET SDK container (defaulting to version 7.0 in the configuration, with the Dockerfile supporting 6.0 and 8.0 variants), installs essential VS Code extensions (C\#, PowerShell, IntelliCode), and includes GitHub CLI and common utilities. Upon creation, the container automatically restores .NET packages and builds the default solution.

.devcontainers · high confidence

Add Blazor WebAssembly example demonstrating Refit AOT and JSON serialization

A new sample application (BlazorWasmIssue2065) has been added to demonstrate Refit's compatibility with Blazor WebAssembly trimming and AOT compilation. The example includes two pages: one verifying that Refit works without blocking sync waits, and another proving that the default System.Text.Json enum converter correctly supports JsonStringEnumMemberName. The setup uses reflection-free source-generated request building and a custom JsonSerializerContext to ensure compatibility with aggressive linker settings.

src/examples/BlazorWasmIssue2065 · high confidence

Add Meow.Common example services and response models

The Meow.Common example library now includes a set of new service classes and data models to demonstrate HTTP client patterns. This adds response models for cat breed data (Breed, Weight, SearchResult) and a CatsService wrapper for The Cat API. It also introduces a suite of in-memory demo infrastructure, including a DemoBackendHandler for simulating API endpoints, a CustomerIdHeaderHandler for propagating request headers, and an Issue2056And2058Demo class that validates concurrent header handling and large async payload deserialization.

src/examples/Meow.Common/Services · high confidence

Add default site stylesheets

The stylesheets directory now includes pygment\_trac.css for syntax highlighting and styles.css for the main layout, typography, and reset rules, establishing the visual presentation for the site.

stylesheets · high confidence

Add local REST API example for testing Refit integration

The local API example now includes a complete ASP.NET Core web application (RestApiforTest) that serves as a mock backend for testing the Refit client. This example provides a ValuesController with standard CRUD endpoints (GET, POST, PUT, DELETE) and a corresponding IRestService interface in the LibraryWithSDKandRefitService project, allowing users to verify their Refit-based SDK implementations against a running local server.

src/examples/SampleUsingLocalApi/RestApiforTest · high confidence

Added polyfills for System.Index and System.Range to support older .NET targets

The InterfaceStubGenerator now includes minimal polyfill implementations for System.Index and System.Range. This enables the generator to compile and function correctly when targeting .NET Standard 2.0 and .NET Framework 4.6.2, where these types are not natively available in the base class library.

InterfaceStubGenerator.Roslyn48 · high confidence

Documentation examples now demonstrate AOT-compatible clients, body policies, and JSON context integration

The documentation examples have been expanded to include runnable samples for Native AOT scenarios, showing how to configure generated clients with \JsonTypeInfo\ and \SystemTextJsonContentSerializer\ to avoid reflection. New examples cover detailed request body policies, including serialization modes (JSON, text, streams, forms, JSON lines), compression options (GZip, Brotli, Zstandard), and per-call timeouts. The samples also illustrate how to use \JsonSerializerContext\ for property naming conventions (camelCase, snake\_case, kebab-case) and demonstrate dependency injection registration patterns for generated clients.

src/examples/Documentation · high confidence

Expanded DI registration with keyed clients, AOT-safe source generation, and scoped authorization

The HttpClientFactory extension methods now support registering Refit clients using keyed service resolution (AddKeyedRefitClient) for scenarios requiring multiple clients of the same interface type. For .NET 8+ environments, new AddRefitGeneratedClient methods allow binding clients to source-generated System.Text.Json contexts, enabling fully trim- and Native AOT-safe JSON serialization without reflection. Additionally, a new ScopedAuthorizationHeaderHandler ensures that authorization tokens are resolved from a fresh per-request DI scope, preventing token leakage across pooled HTTP client requests.

src/Refit.HttpClientFactory · high confidence

Native AOT compatibility verification and .NET Framework polyfills

This update introduces a Native AOT smoke test project to verify that Refit's source-generated clients and JSON serialization work correctly in trimmed, Native AOT environments, alongside a comprehensive set of polyfills in the \src/Polyfills\ directory that enable modern C\# features (such as \CallerArgumentExpression\, \Index\/\Range\, and nullable reference type attributes) on older target frameworks like .NET Framework.

src/Refit · high confidence

New HttpClientDiagnosticsHandler for request/response logging

A new HttpClientDiagnosticsHandler middleware has been added to the Meow.Common library. This delegating handler automatically logs detailed information about HTTP requests and responses, including the request/response objects, their content bodies, and the elapsed time for both the response phase and the total operation. This provides users with enhanced visibility into HTTP traffic for debugging and performance monitoring purposes.

src/examples/Meow.Common/Middleware · high confidence

New Newtonsoft.Json content serializer with secure default settings

The library now includes a dedicated \NewtonsoftJsonContentSerializer\ that implements \IHttpContentSerializer\ and \ISynchronousContentDeserializer\ for JSON serialization using Newtonsoft.Json. A key behavioral change is that when no explicit settings are provided, the serializer automatically forces \TypeNameHandling\ to \None\ on inherited global settings, preventing potential remote-code-execution vulnerabilities via polymorphic type resolution; users requiring polymorphic deserialization must now explicitly pass their own \JsonSerializerSettings\.

src/Refit.Newtonsoft.Json · high confidence

New XML content serialization support with secure defaults

Refit now includes an XmlContentSerializer that enables serializing and deserializing HTTP content as XML, configurable via XmlContentSerializerSettings. The implementation uses System.Xml.Serialization with a cache for performance and enforces security by default: DTD processing is prohibited and the XML resolver is cleared to prevent XXE and entity-expansion attacks. Users can opt out of these protections via the obsolete AllowDtdProcessing property, but this is strongly discouraged and intended only for fully trusted sources.

src/Refit.Xml · high confidence

New analyzer diagnostics for invalid Refit interface contracts

The Refit analyzer now reports warnings for common interface mistakes, including missing HTTP method attributes, invalid route backslashes, multiple cancellation tokens, unsupported HeaderCollection types, and conflicting Body/Authorize/HeaderCollection parameters. It also warns when a method uses features incompatible with source-generated request building, which would cause runtime failures under NativeAOT or with generated-only client registration.

src/Refit.Analyzers.Shared · high confidence

New shared utilities for scoped auth tokens, cancellation polyfills, and public unique type naming

The src/Shared area introduces three new components to support the broader reflection-free request generation and DI alignment. AuthenticatedHttpClientHandler is a new delegating handler that injects an authorization token into outgoing requests via a provided callback, allowing callers to opt into scoped authentication without reflection. HttpContentExtensions provides cancellation-aware polyfills for LoadIntoBufferAsync, ReadAsStreamAsync, and ReadAsStringAsync on older .NET frameworks, ensuring consistent cancellation behavior across target versions. UniqueName is a new public static class that reconstructs the exact generated type name for a Refit interface (including assembly scope and optional service key), enabling users to resolve or configure the corresponding named HttpClient in their DI container.

src/Shared · high confidence

Behavioural changes

Add custom Refit theme with dark mode support

A new SCSS stylesheet (assets/css/style.scss) has been added to define the Refit project's visual identity. This change introduces a consistent color palette for backgrounds, text, links, and code blocks, and includes a media query for prefers-color-scheme: dark to automatically switch to a dark theme when the user's system settings prefer it.

assets · high confidence

Modernized build infrastructure with centralized package management and AOT support

The build system has been restructured to adopt central package management (via Directory.Packages.props) and MinVer for versioning, replacing previous ad-hoc approaches. The solution now targets modern .NET versions (net8.0 through net11.0) alongside legacy .NET Framework, with explicit AOT and trimming compatibility flags enabled for modern targets. Additionally, the project integrates a suite of analyzers (StyleSharp, PerformanceSharp, SecuritySharp, SonarAnalyzer, and PublicApiSharp) to enforce code quality and track public API changes, while migrating test execution to the Microsoft.Testing.Platform.

src · high confidence

Refactor source generator models to reflection-free, cache-safe value types

The generator's internal data structures have been replaced with a comprehensive set of immutable records and enums (e.g., \InterfaceModel\, \MethodModel\, \QueryParameterModel\) that pre-resolve Roslyn symbols into display strings and compile-time metadata. This change eliminates reflection from the incremental generation pipeline, ensuring that cached model data is purely value-equatable and safe for AOT scenarios, while also enabling reflection-free formatting for URL parameters, form fields, and multipart parts.

src/InterfaceStubGenerator.Shared/Models · high confidence

Refactored example project structure and build configuration

The example projects have been reorganized into new solution files (Meow.sln and SampleUsingLocalApi.sln) with updated build properties. The examples now default to C\# 14 language version and are marked as non-packable. Console output warnings are suppressed for sample applications, and the README clarifies that examples target .NET 8 for runtime compatibility while using the newer C\# compiler.

src/examples · high confidence

Refactored source generator into modular emitter components with performance optimizations

The InterfaceStubGenerator.Shared module has been restructured into a set of focused, modular files (Emitter.Buffers, Emitter.Constraints, Emitter.Helpers, Emitter.Inline.\*) to improve maintainability and readability. This change introduces pre-sized character buffers and indentation caching to significantly reduce allocations during source generation, while also adding new diagnostic descriptors (RF002, RF007, RF013, RF014) to provide clearer error messages for common configuration issues like missing Refit references or invalid paged method setups.

src/InterfaceStubGenerator.Shared · high confidence

Reflection-based request builder performance and reliability improvements

The reflection-based request builder in Refit.Reflection has been optimized to reduce memory allocations and improve startup performance. Request building results are now cached per method signature using new key structs (MethodTableKey, CloseGenericMethodKey) and a CachedRequestBuilderImplementation wrapper, ensuring each method is analyzed only once. Attribute lookups, particularly for QueryAttribute, are cached via CachedAttributeProvider to avoid repeated metadata reads during formatting. Query property metadata is also cached per type. Additionally, the builder now supports building HttpRequestMessage instances without sending them (useful for inspection, signing, or logging), handles caller-supplied request streams without disposing them, and applies body compression when configured. Header application now includes CRLF-injection protection and optional validation via RefitSettings.ValidateHeaders.

src/Refit.Reflection · high confidence

Repository configuration and documentation overhaul

The repository has been restructured with the addition of several new configuration and documentation files, including a comprehensive \.editorconfig\ for C\# code style and analyzer rules, \AGENTS.md\ and \CLAUDE.md\ to define AI assistant and build/test instructions, and \SECURITY.md\ for vulnerability reporting. The \.gitignore\ and \.gitattributes\ files have been updated to standardize line endings to LF, explicitly handle binary files, and ignore modern IDE and build artifacts. Additionally, the \README.md\ has been completely rewritten to reflect the current state of the library, including its packages, features, and build requirements.

(repo-wide) · high confidence

Support for optional URL path segments

Refit now supports optional URL path segments using the \{name?}\ syntax. When a parameter bound to an optional placeholder is null, the segment and its preceding separator are omitted from the generated URL rather than formatting to an empty string. This behavior is implemented via new internal reflection helpers, including the \ParameterFragment\ record which tracks the \IsOptional\ flag, and dedicated query entry sinks (\QueryMapEntrySink\, \QueryParameterEntrySink\) to handle value appending.

Refit.Reflection · high confidence

Test coverage

Add .NET Framework smoke test to verify generated client resolution; Added Refit reflection request-builder micro-benchmarks; Added Refit.Benchmarks suite for performance validation; Expanded test infrastructure and coverage for analyzers, generators, and test utilities; New benchmark suite for Refit source generator performance.

Dependencies

Adopts central package management and modernizes MSBuild

The project has switched to Central Package Management (CPM) via a new Directory.Packages.props file, which now centrally defines versions for all dependencies including Microsoft.Extensions.Http (10.0.12), SonarAnalyzer.CSharp (10.34.0.3385), and ReactiveUI.Primitives (8.0.0). This change also introduces framework-specific versioning for .NET 11.0 (rc.1) and .NET 10.0, updates the Roslyn toolchain to version 4.14.0, and restructures the solution into dedicated projects for analyzers, code fixes, and the source generator to ensure a single analyzer slot is shipped.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 57 (-1.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 80 → 71 (-8.1)
  • Architecture 99 → 81 (-19.0)
  • Maturity 60 → 61 (+1.5)
  • Readiness 75 → 71 (-3.7)
  • Security 45 → 46 (+0.3)
  • Performance 79 → 77 (-2.4)

Resolved (23)

  • Bounded contexts not declared
  • Build status unknown
  • Coverage not measured — analyzer environment
  • Duplicated block (13 lines × 2) (src/Refit.HttpClientFactory/HttpClientFactoryCore.cs)
  • Duplicated block (14 lines × 2) (src/Refit.Reflection/RequestBuilderImplementation.QueryAndHeaders.Helpers.cs)
  • Duplicated block (15 lines × 2) (src/InterfaceStubGenerator.Shared/Emitter.ReflectionArguments.cs)
  • Duplicated block (16 lines × 2) (src/InterfaceStubGenerator.Shared/Parser.Request.Helpers.cs)
  • Duplicated block (8 lines × 3) (src/InterfaceStubGenerator.Shared/Emitter.Inline.Query.cs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not measured — analyzer environment
  • TooManyMethods: Emitter (src/InterfaceStubGenerator.Shared/Emitter.cs)
  • TooManyMethods: Parser (src/InterfaceStubGenerator.Shared/Parser.Request.Query.cs)
  • XML-doc coverage: ConsoleSampleUsingLocalApi (src/examples/SampleUsingLocalApi/ConsoleApplication/ConsoleSampleUsingLocalApi.csproj)
  • …and 3 more

New (148)

  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • BareSuppressMessage (src/Refit/SystemTextJsonContentSerializer.JsonContext.cs)
  • BareSuppressMessage (src/Refit/SystemTextJsonContentSerializer.JsonContext.cs)
  • Change coupling: ApiException.cs ↔ JsonContentSerializer.cs (src/Refit/ApiException.cs)
  • ClassTooLong: RequestExecutionHelpers (src/Refit/RequestExecutionHelpers.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Emitter.Buffers.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Emitter.Inline.Multipart.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Emitter.Inline.Query.Values.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Emitter.Inline.Query.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/InterfaceStubGeneratorV2.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Members.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Request.HttpMethod.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Request.HttpMethod.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Request.HttpMethod.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Request.ParameterKinds.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Request.Query.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Request.Query.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Request.Query.cs)
  • CoverageExclusion (src/InterfaceStubGenerator.Shared/Parser.Request.Query.cs)
  • …and 128 more

Changes since last survey

  • 35 commits — 29 feature/other, 6 fixes

By area

  • src/Directory.Packages.props — 10 commits
  • (root) — 5 commits
  • .github/workflows — 5 commits
  • src/tests — 4 commits
  • src/Refit — 3 commits
  • src/examples — 3 commits
  • src/InterfaceStubGenerator.Shared — 2 commits
  • .devcontainers/Dockerfile — 1 commit
  • src/Directory.Build.props — 1 commit
  • src/Refit.HttpClientFactory — 1 commit

Notable commits

  • fix: build: raise the analyzer rules to error and fix the reported code (#2299)
  • fix: fix(debugging): stop debugger displays rendering as a bare null (#2315)
  • fix: fix(generator): keep the analyzers loadable in Visual Studio (#2309)
  • fix: fix(generator): ship a single Roslyn analyzer slot (#2305)
  • fix: fix(headers): stop rewriting raw header values (#2310)
  • fix: fix: differentiate explicitly empty string delimiter from "no delimiter" (#2295)
  • change: Update copyright year in LICENSE file
  • change: Update sponsors section in README
  • change: chore(deps): pin github actions digests (#2323)
  • change: chore(deps): pin mcr.microsoft.com/dotnet/sdk docker tag to e622deb (#2324)
  • change: chore(deps): update dependency microsoft.testing.extensions.codecoverage to 18.11.2 (#2322)
  • change: chore(deps): update dependency minver to v8 (#2320)
  • change: chore(deps): update dependency publicapisharp.analyzers to v2 (#2328)
  • change: chore(deps): update dependency roslynator.analyzers to 4.16.0 (#2298)
  • change: chore(deps): update dependency roslynator.analyzers to 4.16.1 (#2312)
  • change: chore(deps): update dependency roslynator.analyzers to v5 (#2317)
  • change: chore(deps): update dependency sonaranalyzer.csharp to 10.32.0.713 (#2303)
  • change: chore(deps): update dependency sonaranalyzer.csharp to 10.33.0.1635 (#2316)
  • change: chore(deps): update dependency sonaranalyzer.csharp to 10.34.0.3385 (#2321)
  • change: chore(deps): update dependency verify.tunit to v32 (#2318)
  • …and 15 more

API surface

  • Unchanged — 5 HTTP endpoints

Architecture

  • Unchanged — 7 containers · 2 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

reactiveui/refit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bb98726d94195b8045dbdc9787da33ea87e28ba1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.