Skip to content
CAI
Software that uses CAICheck a score

salvo-rs/salvo

41.5

Weak · 30 September 2026

89.4k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Salvo is a modular Rust web framework designed for building high-performance HTTP servers and APIs. It provides core networking capabilities including routing, TLS management, and support for protocols like HTTP/3, WebSocket, and WebTransport. The system also offers middleware for security and performance, along with tooling for API documentation, observability, and static file serving.

How it got here

2019–2022 — Core framework rewrite and HTTP/3 support

85 changes.

The project underwent a major architectural overhaul, stripping legacy HTTP and routing abstractions to introduce a new core system featuring Depot-based state management, structured routing filters, and robust error handling. This period also expanded the framework's capabilities with the addition of HTTP/3 (QUIC) support, dynamic TLS certificate reloading, and a comprehensive suite of middleware for security, caching, and rate limiting.

2023–2024 — OpenAPI 3.2 and macro ecosystem expansion

53 changes.

This period focused on upgrading the OpenAPI generation system to support version 3.2 and JSON Schema draft 2020-12, alongside a major refactoring of the oapi-macros crate for better modularity and error handling. The team introduced the salvo-craft crate to enable ergonomic, struct-based handler definitions and expanded the framework's core capabilities with new middleware for static files, compression, and OpenTelemetry observability. These changes were accompanied by a comprehensive suite of new examples demonstrating authentication, real-time protocols, and advanced routing patterns.

2025–2026 — Example expansion and protocol support

26 changes.

This period focused on expanding the project's ecosystem by introducing comprehensive boilerplate examples for PostgreSQL integration using Diesel, SeaORM, and Toasty ORMs. It also added significant new capabilities, including full TUS resumable upload protocol support, enhanced ACME certificate management, and explicit OpenAPI schema registration for request parameters.

Features

Add CORS example demonstrating cross-origin request handling

The examples/cors directory now includes a Rust application that demonstrates how to configure and use CORS middleware in Salvo. The example runs two concurrent servers: a backend on port 5600 that serves a simple text response protected by CORS settings (allowing origins from localhost:8698, specific HTTP methods, and the authorization header), and a frontend on port 8698 that serves an HTML page with a button to trigger a POST request to the backend. This allows users to test and understand cross-origin resource sharing behavior in a local development environment.

examples/cors · high confidence

Add CatchPanic example demonstrating graceful panic handling

A new example at examples/catch-panic demonstrates how to use the CatchPanic middleware to prevent the server from crashing when a handler panics. The example configures a router with CatchPanic and binds the server to port 8698 on 0.0.0.0.

examples/catch-panic · high confidence

Add Clerk + React starter example with JWT authentication

The \examples/jwt-clerk/app\ directory now contains a complete starter application demonstrating how to integrate Clerk authentication with a React frontend. The app uses \@clerk/clerk-react\ to manage user sessions and provides a header component that conditionally renders sign-in/sign-up buttons or a user profile button. It includes a main view that fetches data from a backend by attaching a JWT token to the request headers, and it is configured to run on port 5801 via Vite.

examples/jwt-clerk/app · high confidence

Add Clerk authentication example application

The \examples/jwt-oidc-clerk/app\ directory now contains a complete React application demonstrating integration with Clerk for authentication. This includes the main entry point (\main.jsx\) which configures the \ClerkProvider\ and React Router, a layout component (\Layout.jsx\) with a header (\Header.jsx\) that renders sign-in/sign-up buttons for unauthenticated users and a user profile button for authenticated users, and an \App.jsx\ component that fetches data from a server endpoint using a Clerk-issued JWT. The example also provides the necessary static assets, styles, and a sample environment variable file (\.env.local.sample\) to configure the Clerk publishable key.

examples/jwt-oidc-clerk/app · high confidence

Add HTTP redirect example

A new example has been added at examples/redirect that demonstrates how to implement an HTTP redirect using the Salvo framework. The example runs on port 8698 and serves a handler that issues a 302 Found redirect to https://www.rust-lang.org/.

examples/redirect · high confidence

Add HTTP/3 (QUIC) example using Salvo and Quinn

The \examples/hello-h3\ directory now contains a working example that serves both HTTPS and HTTP/3 (QUIC) traffic. The implementation uses the Salvo web framework with Quinn for QUIC support, listening on port 8698 at \0.0.0.0\. It includes embedded self-signed TLS certificates (\cert.pem\ and \key.pem\) and configures Rustls to handle TLS for both the TCP and QUIC listeners, allowing users to test dual-stack HTTP/2 and HTTP/3 responses.

examples/hello-h3 · high confidence

Add JWT authentication example using query parameter token passing

The \examples/jwt-auth\ directory now contains a complete JWT authentication demo. It uses the \salvo\ framework with \jsonwebtoken\ v10 and the \time\ crate for expiration handling. The example server listens on port 8698 and authenticates users via a simple login form, passing the generated JWT token through a query parameter (\jwt\_token\) rather than headers or cookies, as configured by the \QueryFinder\.

examples/jwt-auth · high confidence

Add MongoDB user management example

Introduces a new example application in \examples/db-mongodb\ that demonstrates integrating the MongoDB Rust driver with the Salvo web framework. The example provides REST endpoints for managing users (create, list, and retrieve by username) and configures the server to listen on port 8698.

examples/db-mongodb · high confidence

Add MySQL example using Rbatis and Salvo

A new example application has been added that demonstrates how to use the Rbatis ORM with a MySQL database and the Salvo web framework. The example exposes a GET /users endpoint that retrieves user records by ID, initializes the database connection using a global lazy-initialized RBatis instance, and serves the API on port 8698.

examples/db-mysql-rbatis · high confidence

Add OpenAPI generics example with custom schema naming

The \examples/oapi-generics\ directory now includes a new Rust example demonstrating how to use generic types in OpenAPI schema generation. It shows how to apply custom schema names to generic wrappers (e.g., \ApiResponse\<T\>\) and how to configure global naming styles using \FlexNamer\ to shorten type names in the generated documentation.

examples/oapi-generics · high confidence

Add OpenTelemetry Jaeger tracing example

A new example demonstrating distributed tracing with OpenTelemetry and Jaeger has been added to the examples directory. It includes a client and two server components (server1 and server2) that propagate trace context via HTTP headers to Jaeger's OTLP collector on port 4317. Users can run the example to visualize the request flow across services in the Jaeger UI at localhost:16686.

examples/otel-jaeger · high confidence

Add Postgres Diesel model definitions for Users and Posts

The example application now includes Diesel ORM model definitions for the \users\ and \posts\ tables. This adds \User\ and \Post\ structs for querying, along with \NewUser\, \NewPost\, \UserCredentials\, \UserCreate\, \UserUpdate\, \PostCreate\, \Token\, and \ResUserBody\ structs to handle input validation, serialization, and API schema generation via Salvo and Salvo-OAPI.

examples/db-postgres-diesel/src/models · high confidence

Add Rust GraphQL example with in-memory database

Introduces a new Rust-based GraphQL example in the \examples/db-graphql\ directory, demonstrating a complete server setup using the \salvo\ web framework and \juniper\ GraphQL library. The example exposes a GraphQL endpoint at \/graphql\ on port 8698, bound to \0.0.0.0\ for external access, and implements a simple in-memory database with thread-safe read/write access via \parking\_lot::RwLock\. Users can now query for all users or a specific user by ID, and create new users through mutations, serving as a reference implementation for building GraphQL APIs in Rust.

examples/db-graphql · high confidence

Add Rust HTTP server example with bilingual greeting endpoints

A new Rust example application has been added to the examples/hello directory, demonstrating a basic HTTP server using the Salvo framework. The server listens on port 8698 and exposes two endpoints: the root path (/) returns an English greeting ('Hello World'), and the path /你好 returns a Chinese greeting ('你好,世界!'). The example includes logging initialization and prints the router structure for debugging purposes.

examples/hello · high confidence

Add Rust-based Todos example using the Salvo web framework

Introduces a new example application in \examples/todos\ that demonstrates a RESTful todo service built with the Salvo framework. The example includes a full implementation with routing for listing, creating, updating, and deleting todos, along with request body parsing, size limiting, and in-memory storage. It also includes integration tests to verify the create endpoint behavior.

examples/todos · high confidence

Add Salo-based SSE chat example

A new Server-Sent Events (SSE) chat example has been added to the repository, implemented using the Salo web framework. This example demonstrates a real-time chat application where users connect via an HTTP endpoint, receive unique IDs, and broadcast messages to other connected clients. The implementation includes a simple HTML/JavaScript frontend for sending and receiving messages, running on port 8698.

examples/sse-chat · high confidence

Add Salvo + PostgreSQL + SeaORM boilerplate example

This change introduces a new example project demonstrating how to integrate the Salvo web framework with PostgreSQL using SeaORM for database access. The included files provide the foundational boilerplate: database migration setup via SeaORM's migration crate, and entity models for 'users' and 'posts' that define the schema, relationships (one-to-many), and serialization logic.

examples/db-postgres-sea-orm/migration, examples/db-postgres-sea-orm/src/models, examples/db-postgres-sea-orm/src · high confidence

Add Salvo OpenTelemetry OTLP logging example

A new example demonstrating how to integrate the Salvo web framework with OpenTelemetry OTLP for distributed tracing and logging. The example configures a Rust application to send telemetry data to a Jaeger backend (running via Docker) on port 4317, while exposing the application itself on port 8698. It includes setup instructions for prerequisites and running the service to view traces in the Jaeger UI.

examples/logging-otlp · high confidence

Add Salvo Postgres Diesel boilerplate example

Introduces a new example application demonstrating a Salvo-based REST API with PostgreSQL and Diesel. The example includes JWT authentication, user and post management endpoints, and runs on port 8698 by default.

examples/db-postgres-diesel/src · high confidence

Add Sea-ORM blog example with CRUD operations

The \examples/db-sea-orm\ directory now contains a complete example application demonstrating a blog backend using Sea-ORM and the Salvo web framework. This includes a \post\ entity model with serialization support, database migration logic for creating the \posts\ table, and a \main.rs\ entry point that exposes handlers for creating, listing (with pagination), editing, updating, and deleting blog posts. The example uses an in-memory SQLite database and serves Tera templates for the user interface.

examples/db-sea-orm/src · high confidence

Add Unix socket example for static file serving

A new example has been added that demonstrates how to serve static files using a Unix domain socket. The example configures a router to serve files from the './static' directory and binds the server to '/tmp/salvo.sock', requiring the 'unix' feature and a Unix-based operating system to run.

examples/unix-socket · high confidence

Add WebTransport example with short-lived certificate generation

The \examples/webtransport\ directory now contains a complete WebTransport demo application. The server generates a short-lived, self-signed development certificate at startup and exposes its SHA-256 hash via a dedicated route, allowing the browser-based client to bypass HTTPS warnings by verifying the certificate hash directly. The example listens on port 8698, supports bidirectional and unidirectional streams as well as datagrams, and includes a static HTML/JS client for interactive testing.

examples/webtransport · high confidence

Add affix-state example demonstrating request context injection

A new example located at examples/affix-state has been added to demonstrate how to use the affix\_state crate for injecting configuration and shared state into the request context. The example shows a Salvo application that uses hoop middleware to inject a Config struct, a shared State struct protected by a Mutex, and custom string data, making them accessible to handlers via the depot.

examples/affix-state · high confidence

Add body-channel example demonstrating streaming responses

A new example at examples/body-channel has been added to demonstrate how to stream HTTP response bodies using a channel. The example shows a handler that creates a response channel, spawns an async task to send data through it, and serves the endpoint on port 8698.

examples/body-channel · high confidence

Add caching-headers example demonstrating middleware ordering

A new example application has been added to the examples/caching-headers directory that demonstrates how to configure caching headers and response compression in a Salvo server. The example shows a 'Hello World' handler protected by CachingHeaders and Compression middleware, specifically illustrating that CachingHeaders must be applied before Compression to ensure cache control headers are set correctly. The server binds to port 8698 on 0.0.0.0.

examples/caching-headers · high confidence

Add concurrency-limiter example demonstrating request limiting

A new example application has been added to the examples/concurrency-limiter directory that demonstrates how to use the salvo concurrency limiter middleware. The example serves a web page with two upload endpoints: one at /limited which restricts concurrent uploads to a single request using max\_concurrency(1), and another at /unlimit which allows unlimited concurrent uploads. The application listens on port 8698 at 0.0.0.0 and includes a simulated 10-second delay for file uploads to illustrate the concurrency control behavior.

examples/concurrency-limiter · high confidence

Add configurable HTTP client backends (Hyper, Reqwest, Unix Socket) to the proxy

The proxy crate now supports pluggable HTTP client implementations via a new \Client\ trait, allowing users to choose the backend that best fits their needs. By default, the proxy uses a Hyper-based client (\HyperClient\) which handles HTTPS connections with native or WebPKI root certificate fallback and explicit crypto provider selection. Users can alternatively opt into a Reqwest-based client (\ReqwestClient\) which disables redirect following by default for proxy safety, or a Unix socket client (\UnixSockClient\) that tunnels raw HTTP/1.1 requests to local Unix sockets. This change introduces new feature flags (\hyper-client\, \reqwest-client\, \unix-sock-client\) to control which clients are compiled, and updates the \Proxy\ API to accept these clients explicitly or via convenient constructors like \use\_hyper\_client\, \use\_reqwest\_client\, and \use\_unix\_sock\_tunnel\.

crates/proxy/src · high confidence

Add craft example demonstrating API generation with salvo

A new example application has been added to the examples/craft directory, showcasing the use of the \#\[craft\] macro for generating API endpoints in a Rust web server. The example implements a simple calculator service that adds two integers, demonstrating three different endpoint patterns: instance methods with shared state, Arc-wrapped instance methods, and static methods. It also includes OpenAPI documentation generation and Swagger UI integration, serving on localhost port 8698.

examples/craft · high confidence

Add custom error page example

A new example demonstrating how to implement custom error handling in a Salvo application. The example sets up a server on port 8698 with two routes: a standard 'Hello World' endpoint and an endpoint that triggers a 500 error. It specifically illustrates how to configure a custom catcher to intercept 404 Not Found errors and render a custom error page instead of the default response.

(repo-wide) · high confidence

Add db-postgres-toasty example with user management API

Introduces a new example application in examples/db-postgres-toasty that demonstrates a PostgreSQL-backed user management system using the toasty ORM and the salvo web framework. The example provides a REST API for creating, reading, updating, and deleting system users, including specific endpoints for updating user status and paginated list queries. It includes the full application structure with request/response value objects, service-layer business logic (such as uniqueness validation for usernames, mobile numbers, and emails), and HTTP client test files for local development.

examples/db-postgres-toasty · high confidence

Add example demonstrating craft macro usage with query parameters and OpenAPI docs

The \crates/craft-macros/examples\ directory now includes \example-add.rs\, which demonstrates how to use the \\#\[craft\]\ macro to define handlers and endpoints that accept \QueryParam\ arguments. The example shows how to expose these endpoints via a router, generate OpenAPI documentation, and serve Swagger UI, running on port 8698.

crates/craft-macros/examples · high confidence

Add example demonstrating lifetime-aware data extraction

Introduces a new example in \examples/extract-with-lifetimes\ that showcases the \Extractible\ macro with lifetime parameters. The example defines a \BadMan\ struct that extracts data from query, path, and body sources, including a borrowed string field (\&'a str\) to demonstrate lifetime handling in request extraction. It serves a form for user input and displays the extracted data, running on port 8698.

examples/extract-with-lifetimes · high confidence

Add file upload example application

A new example application has been added at examples/upload-files that demonstrates how to handle multipart file uploads using the Salvo web framework. The application serves an HTML form allowing users to select and upload multiple files, which are then saved to a local 'temp' directory. It listens on port 8698 at 0.0.0.0 and provides feedback on the uploaded file paths or errors.

examples/upload-files · high confidence

Add file upload examples with OpenAPI documentation

New example applications demonstrating single-file (FormFile) and multi-file (FormFiles) uploads have been added to the examples directory. These examples include HTML forms for uploading files and integrate with the OpenAPI specification generator, exposing the upload endpoints via Swagger UI at /swagger-ui and the OpenAPI JSON at /api-doc/openapi.json. The examples run on port 8698.

examples/oapi-upload-files · high confidence

Add flash message example using Salvo

A new example application has been added at examples/flash-session-store that demonstrates how to use the Salvo framework's flash message and session handling capabilities. The example runs on port 8698 and includes two routes: one to set flash messages (info and debug levels) and redirect to a retrieval page, and another to display any pending flash messages from the session.

examples/flash-session-store · high confidence

Add fuse-attack example demonstrating strict fuse configuration

A new example application has been added at examples/fuse-attack that showcases the use of \salvo::fuse::FuseConfig::strict()\. This demo runs a simple HTTP server on port 8698 and is designed to exercise idle, write-stall, and body timeouts, providing a practical reference for configuring strict fuse behavior in production-like scenarios.

examples/fuse-attack · high confidence

Add listenfd example for systemd socket activation

A new example application has been added to demonstrate how to integrate the server with systemd socket activation using the listenfd crate. The example checks for a pre-existing TCP listener from the environment and, if not found, falls back to binding to a configurable host and port (defaulting to 0.0.0.0:8080).

examples/with-listenfd · high confidence

Add middleware example demonstrating header injection

A new example application has been added at examples/middleware-add-header that demonstrates how to use Salvo's middleware capabilities. The example defines a handler that returns a static string and a middleware function that inserts a custom 'Server' header with the value 'Salvo' into the response. The application listens on port 8698 at 0.0.0.0.

examples/middleware-add-header · high confidence

Add native-tls TLS example listening on port 8698

A new example demonstrating how to configure TLS using the native-tls backend has been added. This example serves a simple "Hello World" response and binds to 0.0.0.0 on port 8698, using a PKCS12 certificate for secure connections.

examples/tls-native-tls · high confidence

Add oapi-hello example with OpenAPI documentation and Swagger UI

A new example application (examples/oapi-hello) is introduced that demonstrates how to integrate OpenAPI specification generation and Swagger UI into a Salvo service. The example exposes a simple 'hello' endpoint, serves the OpenAPI JSON document at /api-doc/openapi.json, and provides an interactive Swagger UI at /swagger-ui. The server listens on 0.0.0.0:8698.

examples/oapi-hello · high confidence

Add request and response schema definitions for the Salvo + PostgreSQL example

This change introduces the data models used for API interactions in the new Salvo + PostgreSQL + SeaORM boilerplate example. It defines request schemas for creating and updating posts and users (including credentials), as well as response models for user data and authentication tokens, enabling structured data validation and OpenAPI documentation generation within the example application.

examples/db-postgres-sea-orm/src/schemas · high confidence

Add request-id example demonstrating X-Request-ID header handling

A new example application has been added to the examples/request-id directory. It demonstrates how to use the RequestId middleware to extract and display the 'x-request-id' header from incoming HTTP requests. The example server listens on port 8698.

examples/request-id · high confidence

Add routing example demonstrating custom GUID path filtering

The examples/routing-guid directory now contains a new Rust example that demonstrates how to register a custom regular expression for path parameters using salvo's PathFilter. The example defines a 'guid' filter matching standard UUID formats and routes requests to a handler that echoes the captured ID, listening on port 8698 at 0.0.0.0.

examples/routing-guid · high confidence

Add session-based login example

The examples/session-login directory now contains a complete, runnable example demonstrating session management in Salvo. It implements a login/logout flow using cookie-based sessions, allowing users to authenticate via a POST request to /login, view a personalized greeting on the home page, and clear their session by visiting /logout. The example server listens on port 8698.

examples/session-login · high confidence

Add simple cache example using MokaStore

A new example application demonstrates how to implement response caching in a Salvo-based server. The example configures two distinct cache middleware instances using MokaStore: one with a 5-second time-to-live for short-lived responses and another with a 60-second time-to-live for long-lived responses. It serves a home page with links to these endpoints, illustrating how to attach cache handlers to specific routes and bind the server to port 8698 on all interfaces.

examples/cache-simple · high confidence

Add simple proxy example using Hyper client

A new example application has been added at examples/proxy-simple that demonstrates how to set up a basic reverse proxy using the Salvo framework. The example configures two routing rules: requests to 127.0.0.1:8698 are proxied to https://docs.rs, while requests to localhost:8698 are proxied to https://crates.io. It utilizes the Hyper client for proxying and listens on port 8698.

examples/proxy-simple, examples/proxy-websocket · high confidence

Add size-limiter and upload-file examples using the Salvo framework

New example applications have been added to demonstrate file upload handling with the Salvo web framework. The size-limiter example provides a web interface with two endpoints: one for unlimited uploads and another that enforces a 10 MiB size limit on incoming files, while the upload-file example demonstrates a basic single-endpoint upload flow. Both examples listen on port 8698 and save uploaded files to a local 'temp' directory.

examples/size-limiter · high confidence

Add static directory listing example with dot-file filtering

The \examples/static-dir-list\ example now demonstrates serving static files from multiple directories (\static-dir-list/static/boy\, \static-dir-list/static/girl\, etc.) using \salvo::serve\_static::StaticDir\. It configures the server to automatically generate directory listings (\auto\_list(true)\), serve \index.html\ as the default file for directories, and explicitly exclude hidden dot-files (\include\_dot\_files(false)\). The example application listens on port 8698.

examples/static-dir-list · high confidence

Add static rate-limiter example using Moka and Hyper

Introduces a new example application in \examples/rate-limiter-static\ that demonstrates how to implement a rate limiter using the \salvo\ framework. The example configures a \RateLimiter\ with a \MokaStore\ for state management, a \FixedGuard\, and a \RemoteIpIssuer\ to restrict requests to one per second per IP address. The server listens on \0.0.0.0:8698\ and serves a simple "Hello World" endpoint protected by this rate limiting logic.

examples/rate-limiter-static · high confidence

Add timeout example demonstrating request handling with duration limits

A new example located at examples/timeout has been added to demonstrate how to configure request timeouts using the salvo framework. The example runs a server on port 8698 and defines two routes: a 'fast' route that responds immediately and a 'slow' route that sleeps for 6 seconds. A Timeout middleware is applied with a 5-second duration, ensuring that requests to the 'slow' endpoint are terminated if they exceed this limit, while 'fast' requests complete normally.

examples/timeout · high confidence

Add use-depot example demonstrating state sharing via Depot

A new example located at examples/use-depot demonstrates how to use the Depot object to share state between handlers. The example defines a set\_user handler that inserts a user value into the Depot and a hello handler that retrieves this value to personalize the response, illustrating the use of the hoop middleware for pre-processing and the goal method for defining the final handler.

examples/use-depot · high confidence

Add with-sentry example for tracing and error reporting

A new example application has been added at examples/with-sentry that demonstrates how to integrate Sentry for error tracking and performance monitoring in a Salvo-based HTTP server. The example configures the tracing subscriber to send logs to Sentry, initializes the Sentry client using the SENTRY\_DSN environment variable with full transaction sampling, and applies Sentry middleware layers to capture HTTP requests and errors.

examples/with-sentry · high confidence

Added database migration scaffolding for the Sea-ORM example

The \examples/db-sea-orm/src/migration\ directory now includes the necessary files to manage database schema changes. This adds a \main.rs\ entry point for the migration CLI, a \README.md\ with usage instructions for applying and rolling back migrations, and an initial migration script (\m20220120\_000001\_create\_post\_table.rs\) that creates a \posts\ table with \id\, \title\, and \text\ columns.

examples/db-sea-orm/src/migration · high confidence

Added example Postgres/Sea-ORM router implementations for Posts and Users

The example application now includes concrete router implementations for managing Posts and Users using the Sea-ORM database library. The new \posts.rs\ file exposes endpoints to retrieve, create, update, and delete posts, enforcing ownership checks during updates. The \users.rs\ file provides endpoints for user registration (including password hashing), retrieving user lists, fetching current user details, and updating user profiles with permission validation. These files establish the HTTP interface layer for the example's data models.

examples/db-postgres-sea-orm/src/routers · high confidence

Added force-https example with self-signed certificates

The examples/force-https directory now includes a complete runnable example demonstrating how to enforce HTTPS using the Salvo framework. This addition provides self-signed TLS certificates (cert.pem and key.pem) and a Rust source file (main.rs) that configures a server to listen on port 8698 for HTTP and port 5443 for HTTPS, automatically redirecting HTTP requests to the secure port.

examples/force-https · high confidence

Added fuzzing targets for Salvo core and extra components

A new \cargo-fuzz\ workspace has been added to the \fuzz\ directory, introducing automated fuzzing targets for four key areas of the Salvo framework: \basic\_auth\ (parsing Basic and Proxy-Authorization headers), \path\_filter\ (validating route patterns and path matching), \tus\_options\ (extracting upload IDs and generating URLs from request headers), and \websocket\_upgrade\ (validating WebSocket handshake headers and subprotocol negotiation). The entry includes the target implementations, seed corpora, and helper utilities for generating safe, structured fuzz inputs.

fuzz · high confidence

Added initial database schema and migration files for the Salvo Postgres Diesel example

The \examples/db-postgres-diesel/migrations\ directory now contains the SQL migration files required to set up the example application's database. This includes an initial setup migration that creates helper functions for automatic \updated\_at\ timestamp management, a migration to create the \users\ and \posts\ tables with their relationships, and a subsequent migration to add \created\_at\ and \updated\_at\ columns to both tables. These files provide the foundational database structure for the Salvo Postgres Diesel boilerplate example.

examples/db-postgres-diesel/migrations · high confidence

HTTP/3 support via Quinn integration

The server now supports the HTTP/3 protocol using the Quinn QUIC library. This change introduces a new \quinn\ connection module containing a \Builder\ to configure HTTP/3 settings (such as WebTransport and Alt-Svc headers), a \QuinnListener\ to bind and accept connections, and a \QuinnAcceptor\ to handle incoming QUIC streams. Users can now serve HTTP/3 traffic alongside existing protocols.

crates/core/src/conn/quinn · high confidence

Introduce \#\[salvo(parameters)\] derive for struct-based parameter extraction

The \ToParameters\ derive macro is now available in \crates/oapi-macros/src/parameter/derive.rs\, allowing users to automatically generate OpenAPI parameter definitions and corresponding Salvo extractors from struct fields. This feature supports container-level configuration such as \DefaultStyle\, \DefaultParameterIn\, \ToParametersNames\, and \RenameAll\, as well as field-level attributes for serialization control (e.g., \skip\), renaming, and validation constraints. It enables declarative definition of query, header, path, and cookie parameters directly on Rust structs, integrating with Salvo's extraction metadata system.

crates/oapi-macros/src/parameter · high confidence

Introduce DiskStore for local file-based tus uploads

Added a new \DiskStore\ implementation in \crates/tus/src/stores\ that persists tus upload chunks and metadata to the local filesystem. This backend stores data files as \.bin\ and metadata as \.json\ within a configurable root directory (defaulting to \./tus-upload-files\). It includes path validation to ensure uploads remain within the designated root directory and integrates with the existing \DataStore\ trait to support standard tus operations like creation, chunk writing, and metadata retrieval.

crates/tus/src/stores · high confidence

Introduce OpenTelemetry middleware for metrics and distributed tracing

Adds the \salvo\_otel\ crate, providing \Metrics\ and \Tracing\ middleware for the Salvo web framework. The \Metrics\ middleware collects HTTP server metrics (request duration, active requests, body sizes) and the \Tracing\ middleware creates distributed tracing spans, both adhering to OpenTelemetry HTTP semantic conventions. Attributes like \http.route\ are derived from matched route templates to keep time series bounded, and sensitive query parameters are redacted in traces.

crates/otel/src · high confidence

Adds a new flash message system to the Salvo web framework, allowing temporary notifications (such as success or error messages) to persist across a single redirect. The implementation includes a \CookieStore\ for storing messages in signed cookies with configurable security policies (e.g., \Secure\, \HttpOnly\, \SameSite\) and a \SessionStore\ for storing messages in the application session. Users can now integrate flash handling via \FlashHandler\ and access messages through \Depot\ extensions (\incoming\_flash\, \outgoing\_flash\), supporting distinct message levels (Debug, Info, Success, Warning, Error) for appropriate UI styling.

crates/flash/src · high confidence

Introduce in-memory locking for TUS uploads

Added a new \MemoryLocker\ implementation for the TUS crate, providing an in-memory mechanism to serialize access to upload IDs using Tokio's \RwLock\. This change introduces the \Locker\ trait and \LockGuard\ RAII wrapper in the \lockers\ module, enabling concurrent read access and exclusive write access to upload resources within a single process. The implementation includes comprehensive unit tests to verify lock acquisition, release, and concurrency behavior.

crates/tus/src/lockers · high confidence

Introduce new rate-limiter crate with fixed and sliding window algorithms

The \crates/rate-limiter/src\ directory now contains the initial implementation of the \salvo-rate-limiter\ middleware. This adds support for rate limiting via two algorithms: \FixedGuard\ (fixed-window) and \SlidingGuard\ (sliding-window counter). It includes a \MokaStore\ for in-memory state persistence, \BasicQuota\ and \CelledQuota\ for defining limits, and issuers like \RemoteIpIssuer\ and \TrustedProxyIssuer\ to identify clients. The middleware returns \429 Too Many Requests\ when limits are exceeded and can optionally add \X-RateLimit-\*\ headers to responses.

crates/rate-limiter/src · high confidence

Introduce response caching middleware for Salvo

This change adds a new response caching middleware for the Salvo web framework, located in \crates/cache\. It intercepts HTTP responses to cache status codes, headers, and bodies (excluding streaming responses), reducing server load and improving response times. The middleware includes a \MokaStore\ backend for high-performance concurrent caching, a \RequestIssuer\ for generating cache keys from request URIs, and a \MethodSkipper\ to control which HTTP methods are cached. It also supports concurrent miss coalescing to prevent cache stampedes and allows customizing cache keys via the \CacheIssuer\ trait.

crates/cache/src · high confidence

Introduce salvo-craft-macros for ergonomic handler definition

The new \salvo-craft\ crate provides the \\#\[craft\]\ attribute macro, allowing developers to define handlers as methods on structs rather than standalone functions. This enables better code organization and state sharing via \self\, supporting \&self\, \Arc\<Self\>\, and static receivers. The library integrates with Salvo's router and OpenAPI documentation, as demonstrated by the included \openapi.rs\ example.

crates/craft/src · high confidence

Introduce salvo-craft-macros for procedural macro-based handler generation

The new \salvo-craft-macros\ crate provides a \\#\[craft\]\ procedural macro that transforms methods within an \impl\ block into Salvo handlers. By marking methods with \\#\[craft(handler)\]\ or \\#\[craft(endpoint(...))\]\, developers can generate handler factories that automatically manage receiver types (\&self\, \Arc\<Self\>\, or static) and forward documentation and deprecation attributes to the underlying Salvo implementation. This allows related handlers to be organized cleanly within service structs while maintaining full compatibility with Salvo's routing and OpenAPI generation.

crates/craft-macros/src · high confidence

Introduce salvo-serve-static crate for serving static files and directories

The new \salvo-serve-static\ crate provides three handlers for serving static content: \StaticFile\ for individual files, \StaticDir\ for directories with listing support, and \StaticEmbed\ for files embedded in the binary via \rust-embed\. \StaticDir\ supports directory listings in HTML, JSON, XML, and Text formats, automatic content-type detection, and serving pre-compressed variants (Brotli, Gzip, Deflate, Zstd) based on client \Accept-Encoding\. It also includes security hardening by blocking access to dot directories (e.g., \.git\, \.env\) and preventing path traversal. \StaticEmbed\ supports HTTP range requests and RFC-compliant ETags for embedded assets.

crates/serve-static/src · high confidence

Introduce tus protocol upload handlers

This change adds the core HTTP handlers for the tus resumable upload protocol within the \salvo-tus\ crate. It implements the standard protocol endpoints—POST (creation), PATCH (data upload), HEAD (metadata retrieval), GET (file download), DELETE (termination), and OPTIONS (capability discovery)—along with shared logic for CORS header application, TUS version validation, and metadata parsing. This provides the server-side request handling layer required to support resumable uploads.

crates/tus/src/handlers · high confidence

New ACME HTTP-01 example for automatic SSL certificate management

Added a new example demonstrating how to configure the Acme service for automatic SSL certificate management using the HTTP-01 challenge. The example sets up a server listening on both port 80 and 443, integrates with Let's Encrypt (with an option to switch to the staging server), caches certificates in a specified path, and registers a simple 'Hello World' handler while automatically adding the necessary routes to handle ACME challenge requests.

examples/acme-http01 · high confidence

New ACME TLS/ALPN example added

An example demonstrating how to configure a server with automatic SSL certificate management via ACME has been added. This example shows how to set up a TCP listener on port 443, enable ACME for a specific domain (test.salvo.rs), and serve a simple 'Hello World' response.

examples/acme-tls-alpn01 · high confidence

New CSRF CookieStore example with multiple protection methods

Added a new example application demonstrating CSRF protection using a cookie store. The example serves a home page with links to four distinct CSRF protection strategies: Bcrypt, HMAC, AES-GCM, and ChaCha20Poly1305. Each strategy is implemented as a separate route that validates incoming form submissions against the stored token, providing a practical reference for integrating these security mechanisms into a web application.

examples/csrf-cookie-store · high confidence

New CSRF session-store example with multiple protection algorithms

Added a new example application (\examples/csrf-session-store\) that demonstrates how to implement CSRF protection using a session store. The example serves a home page with links to four distinct CSRF protection methods: Bcrypt, HMAC, AES-GCM, and ChaCha20Poly1305. It configures a session handler with a memory store and secret key, then applies the specific CSRF middleware to respective routes (\/bcrypt\, \/hmac\, \/aes\_gcm\, \/ccp\). Each route handles GET requests to display a form with the current CSRF token and POST requests to validate the submitted token against the session. The server listens on port 8698 at 0.0.0.0.

examples/csrf-session-store · high confidence

New Clerk OIDC JWT authentication example

Added a new example application in \examples/jwt-oidc-clerk\ that demonstrates JWT authentication using Clerk's OpenID Connect (OIDC) provider. The example configures an \OidcDecoder\ to validate tokens against a specific issuer and audience, listens on port 8698, and uses a \JwtAuth\ handler to protect routes. It also includes a proxy component to forward requests to a backend service running on localhost:5801.

examples/jwt-oidc-clerk/src · high confidence

New HTTP core types and request body size limits

The \crates/core/src/http\ module now introduces dedicated types for HTTP bodies (\ReqBody\, \ResBody\, \BytesFrame\), form data parsing (\FormData\, \FilePart\), and range requests (\HttpRange\). It also adds a \SecureMaxSize\ middleware and a global \set\_global\_secure\_max\_size\ function to enforce configurable limits on request body reads and form parsing, protecting against denial-of-service attacks. Additionally, a \SecureCookiePolicy\ enum is provided to control the \Secure\ attribute on response cookies based on the request scheme.

crates/core/src/http · high confidence

New JWT authentication example with Clerk-style validation

A new example application has been added at examples/jwt-clerk/src/main.rs that demonstrates JWT authentication using the Salvo framework. The app listens on 0.0.0.0:8698, validates JWTs via a RSA PEM key using ConstDecoder and HeaderFinder, and serves a welcome message upon successful authentication. Unauthorized requests receive a 401 error, while other states return 403. The application also includes a proxy route that forwards unmatched paths to http://localhost:5801 using HyperClient.

examples/jwt-clerk/src · high confidence

New NamedFile component for HTTP file serving

The \crates/core/src/fs\ module now includes a new \NamedFile\ component that wraps file handles with HTTP-specific functionality, including automatic MIME type detection, ETag generation, Last-Modified header support, Content-Disposition handling, and HTTP Range request support for partial content. The component also implements chunked transfer for large files and includes security headers like X-Content-Type-Options: nosniff by default. XML-based files are served with attachment disposition by default for security reasons.

crates/core/src/fs · high confidence

New OpenAPI 3.2 object model and version-aware generation

The \oapi\ crate now includes a complete OpenAPI 3.2 object model and supports version-aware document generation. This update introduces new fields and types required by the 3.2 specification, including \media\_types\ in the Components object, \item\_schema\ and \prefix\_encoding\/\item\_encoding\ in Content and Encoding objects, and \data\_value\/\serialized\_value\ in Example objects. It also adds support for \path\_items\ in Components (referenced via \$ref\), \summary\ in Info, and \operation\_ref\ in Link objects. Existing types are marked \\#\[non\_exhaustive\]\ to allow for future extension, and the library now correctly handles OpenAPI 3.1 and 3.2 specific behaviors, such as nullable values in Map types and correct serialization of extensions.

crates/oapi/src/openapi · high confidence

New Post and User API endpoints in the Diesel example

The \examples/db-postgres-diesel\ example now includes dedicated router modules for managing posts and users. The new \posts.rs\ file exposes endpoints to list, create, update, and delete posts, enforcing ownership checks so users can only modify their own content. The \users.rs\ file adds endpoints to retrieve all users, create new accounts with hashed passwords, fetch the current user's profile, and update user details, also restricting updates to the authenticated user's own record.

examples/db-postgres-diesel/src/routers · high confidence

New PostgreSQL example using SQLx and OnceLock

Added a new example application in the db-postgres-sqlx directory that demonstrates connecting to a PostgreSQL database using the SQLx library. The example initializes a global connection pool using std::sync::OnceLock and exposes a GET /users endpoint that retrieves user records by ID. The server is configured to listen on port 8698 at 0.0.0.0.

examples/db-postgres-sqlx · high confidence

New Salvo with SeaORM example application

Adds a new example application demonstrating the integration of the Salvo web framework with SeaORM. The example includes a complete web interface for managing posts (create, edit, delete, list) using Tera templates and static CSS assets, and runs on port 8698 by default.

examples/db-sea-orm · high confidence

New Server-Sent Events example using Salvo

Added a new example in examples/sse that demonstrates Server-Sent Events (SSE) using the Salvo web framework. The example runs on port 8698, binds to 0.0.0.0, and serves a /ticks endpoint that streams incrementing counter events every second.

examples/sse · high confidence

New Swagger UI configuration and OAuth modules

The \crates/oapi/src/swagger\_ui\ module now includes dedicated \Config\ and \oauth::Config\ structs that allow users to programmatically configure Swagger UI settings. The \Config\ struct exposes options for managing API document URLs (including primary name selection for multiple docs), UI layout, deep linking, operation filtering, and request snippet display. The new \oauth::Config\ struct provides a builder API to set OAuth2 parameters such as client ID, secret, scopes, PKCE usage, and additional query string parameters, enabling secure and customizable authentication flows within the Swagger UI interface.

_crates/oapi/src/swagger\ui · high confidence

New TLS example using OpenSSL with updated configuration

A new TLS example has been added to the \examples/tls-openssl\ directory, demonstrating a server setup using the \salvo\ framework's OpenSSL integration. The example includes self-signed certificate and key files (\cert.pem\, \key.pem\) and a main application file that binds to \0.0.0.0:8698\. It serves a simple "Hello World" response over HTTPS, utilizing \OpensslConfig\ for certificate management and \TcpListener\ for network binding.

examples/tls-openssl · high confidence

New TUS resumable upload example for Salvo

The \examples/upload-files-tus\ directory now includes a complete demo for the TUS resumable upload protocol. The Rust server (\src/main.rs\) uses the \salvo-tus\ crate to handle uploads at \/files\ with a 2GB size limit and custom ID generation, while the browser client (\clients/browser/\) provides interactive demos for standard file uploads and live webcam video streaming, including features like pause/resume, chunk size configuration, and upload progress tracking.

examples/upload-files-tus · high confidence

New TUS resumable upload protocol support for Salvo

The \salvo-tus\ crate introduces a complete implementation of the TUS (Resumable Upload Protocol) for the Salvo web framework, enabling reliable large-file uploads with pause and resume capabilities. This feature provides a configurable router handling standard TUS endpoints (OPTIONS, POST, HEAD, PATCH, DELETE, GET), supports lifecycle hooks for upload events, and includes a built-in \DiskStore\ for file persistence alongside a \DataStore\ trait for custom backends. The implementation enforces protocol validation, manages upload locking to prevent conflicts, and includes security hardening such as upload ID and path validation to prevent path traversal attacks, as well as safe handling of \Location\ headers to mitigate host-injection risks.

crates/tus/src · high confidence

New WebSocket chat example using the Salvo framework

Added a new WebSocket chat example in the \examples/websocket-chat\ directory. This example demonstrates a real-time chat application built with the Salvo web framework, featuring a Rust backend that manages user connections and message broadcasting, along with an embedded HTML/JavaScript frontend for the chat interface. The server listens on port 8698 at 0.0.0.0.

examples/websocket-chat · high confidence

New WebSocket echo example with subprotocol support

Added a new WebSocket example in \examples/websocket\ that demonstrates subprotocol negotiation (specifically \echo.v1\) and basic echo functionality. The example listens on port 8698 at \0.0.0.0\ and includes a simple HTML client for testing.

examples/websocket · high confidence

New WebTransport example with ACME and HTTP/3 support

Added a new example application (\examples/webtransport-acme-http01\) that demonstrates WebTransport over HTTP/3. The server uses the Salvo framework to handle WebTransport sessions, including bidirectional and unidirectional streams, as well as datagrams, while automatically managing TLS certificates via ACME HTTP-01 challenges. The accompanying static client interface allows users to connect to the server, send data via datagrams or streams, and view event logs.

examples/webtransport-acme-http01 · high confidence

New basic-auth and trailing-slash examples added

The repository now includes two new example applications: a basic-auth example demonstrating how to implement custom username/password validation using the BasicAuth middleware, and a trailing-slash example showing how to automatically append slashes to routes. Both examples are configured to listen on port 8698 at 0.0.0.0 and include basic integration tests.

examples/basic-auth · high confidence

New catch-error example demonstrating custom and third-party error handling

Added a new example at examples/catch-error that demonstrates how to handle errors in the Salvo framework. The example shows how to implement the Writer trait for a custom error type to return a 500 status with a custom message, and how to handle errors from the anyhow and eyre libraries within handlers. The server binds to 0.0.0.0:8698 and exposes three endpoints (/anyhow, /eyre, /custom) to test these error handling strategies.

examples/catch-error · high confidence

New channel-backed response body with backpressure and timeout protection

The HTTP body module now includes a channel-based response body (\ResBody::Channel\) backed by \BodySender\ and \BodyReceiver\, allowing applications to stream response data with built-in backpressure. \BodySender\ implements both \futures\_util::AsyncWrite\ and \tokio::io::AsyncWrite\, enabling standard async write patterns. Incoming request bodies (\ReqBody\) now support configurable timeouts via \FuseConfig\, which automatically terminates slow or stalled request streams to prevent resource exhaustion.

crates/core/src/http/body · high confidence

New compression example demonstrating path-specific compression strategies

Added a new \examples/compression\ example that demonstrates how to apply different compression algorithms (Brotli, Zstd, Gzip) and force-priority compression to specific routes using the \Compression\ hoop, alongside static file serving via \StaticDir\ and \StaticFile\.

examples/compression · high confidence

New custom-filter example demonstrating host-based access control

Added a new example in \examples/custom-filter\ that shows how to restrict access to a Salvo server based on the HTTP Host header. The example configures a router with a custom filter that only allows requests where the Host header matches \localhost:8698\, returning a 'not found' response for other hosts, while the server itself listens on \0.0.0.0:8698\.

examples/custom-filter · high confidence

The \oapi-macros\ crate now provides \ToResponse\ and \ToResponses\ derive macros, allowing users to automatically generate OpenAPI response definitions from Rust structs and enums. This includes support for named, unnamed, and unit structs, as well as enum variants, mapping them to specific HTTP status codes and registering them in the OpenAPI components. Additionally, a new \Link\ attribute structure is introduced, enabling the definition of OpenAPI Links (operation references, parameters, request bodies, descriptions, and servers) within response definitions, enhancing the ability to document relationships between API operations.

crates/oapi-macros/src/response · high confidence

New dynamic per-user rate limiting example

Added a new example application in \examples/rate-limiter-dynamic\ that demonstrates how to implement dynamic, per-user rate limiting. The example uses a custom \RateIssuer\ to extract a user identifier from the request query string and a \QuotaGetter\ to look up specific rate limits (e.g., 1 request per second, 1 per 5 seconds) from a static map. It serves a simple HTML page with links to test these different limits on a protected route, listening on port 8698.

examples/rate-limiter-dynamic · high confidence

New example demonstrating ACME HTTP-01 challenge with QUIC/HTTP-3 support

Added a new example in \examples/acme-http01-quinn\ that shows how to configure a server to handle ACME HTTP-01 challenges for automatic SSL certificate management while simultaneously supporting QUIC/HTTP-3 on port 443. The example sets up a listener on port 443 with ACME enabled for the domain \test.salvo.rs\, caches certificates in \temp/letsencrypt\, and joins it with a standard TCP listener on port 80 to handle the HTTP-01 challenge requests.

examples/acme-http01-quinn · high confidence

New example demonstrating embedded static file serving

Added a new example in \examples/static-embed-file\ that shows how to serve static assets embedded directly into the binary using the \rust-embed\ crate with the Salvo web framework. The example defines a \Assets\ struct to embed files from the \static\ folder, sets up a router to catch all paths via \{\*\*rest}\, and serves the corresponding embedded file or returns a 404 if not found, listening on port 8698.

examples/static-embed-file · high confidence

New example demonstrating query parameter aliasing in Salvo

The \examples/extract-alias\ directory now includes a runnable example showing how to use the \\#\[serde(alias = ...)\]\ attribute with Salvo's \Extractible\ derive macro. This allows API consumers to pass query parameters under alternative names (such as \name\ or \location\ instead of \country\) while the server extracts them into a single struct field, with tests verifying that all alias variants resolve correctly.

examples/extract-alias · high confidence

New extra middleware crate for Salvo

The \salvo\_extra\ crate is introduced, providing a collection of opt-in middleware and utilities to complement the core framework. This release adds handlers for HTTP Basic Authentication (\basic\_auth\), shared state injection (\affix\_state\), and request caching (\caching\_headers\). It also includes security and reliability features such as \force\_https\ for protocol redirection, \catch\_panic\ to convert panics into 500 errors, and \concurrency\_limiter\ to prevent server overload. Additional utilities cover observability with \logging\ and \request\_id\, real-time communication via \sse\ and \websocket\, and request management through \size\_limiter\ and \timeout\.

crates/extra · high confidence

New extract-data example demonstrating multi-source data extraction and depot injection

Added a new example application that demonstrates how to extract data from multiple sources (query, path parameters, and request body) using the \Extractible\ derive macro, and how to inject and extract user context data via the depot middleware. The example runs on port 8698 at 0.0.0.0 and includes handlers for displaying a form and processing submitted data, illustrating the integration of authentication-like middleware with request data extraction.

examples/extract-data · high confidence

New join-listeners example demonstrating multi-port TCP binding

Added a new example that shows how to bind a server to multiple TCP ports simultaneously using the \join\ method on \TcpListener\. The example configures listeners on ports 8698 and 5801, binding to all interfaces (0.0.0.0), and serves a simple 'Hello World' response via a router.

examples/join-listeners · high confidence

New logging example using Salvo and Tracing

Added a new example in examples/logging that demonstrates how to integrate the Salvo web framework with the Tracing logging ecosystem. The example configures a router with hello and error handlers, applies a Logger hoop for request logging, and starts an HTTP server on 0.0.0.0:8698.

examples/logging · high confidence

New modular CSRF middleware with pluggable ciphers and stores

The \crates/csrf\ crate introduces a configurable CSRF protection system for the Salvo web framework. Users can now choose from multiple token-generation strategies—Bcrypt, HMAC, AES-GCM, and ChaCha20-Poly1305—via feature-gated modules (\bcrypt-cipher\, \hmac-cipher\, \aes-gcm-cipher\, \ccp-cipher\). Token storage is similarly decoupled into \CookieStore\ (with configurable TTL, path, domain, and secure-cookie policies) and \SessionStore\ (persisting tokens in the user's session). Token extraction is handled by pluggable finders (\HeaderFinder\, \FormFinder\, \JsonFinder\), and the middleware supports both per-session and per-request token rotation policies.

crates/csrf/src · high confidence

New nested data extraction example using Salvo

Added a new example demonstrating how to extract nested data structures in a Salvo application. The example shows a form that submits JSON data containing nested fields (such as pet preferences) and uses the \Extractible\ macro with \flatten\ and source mapping attributes to automatically parse parameters, query strings, and body content into a structured Rust type. It runs on port 8698 at 0.0.0.0.

examples/extract-nested · high confidence

New path filter composition and routing filter types

The routing filter system now supports composing filters with logical operators (And, Or, AndThen, OrElse) and introduces new filters for matching request methods, URI schemes, hosts, and ports. The path matching engine has been refactored to use a 'wisp'-based architecture, allowing for more flexible and performant path pattern matching with support for constant, named, character-based, regex, and combined wisps.

crates/core/src/routing/filters · high confidence

New request extractors for parameters and payloads

This change introduces a new set of request extractors in \crates/core/src/extract/parameter\ and \crates/core/src/extract/payload\. The parameter module adds \CookieParam\, \HeaderParam\, \PathParam\, and \QueryParam\ to extract data from cookies, headers, URI paths, and query strings respectively; notably, \CookieParam\ now supports JSON values, allowing structured types to be deserialized directly from cookie content. The payload module adds \FormFile\ and \FormFiles\ for handling file uploads, as well as \FormBody\ and \JsonBody\ for deserializing form and JSON request bodies into typed structs.

crates/core/src/extract/parameter · high confidence

New response writers for JSON, text, redirects, and range streaming

The \crates/core/src/writing\ module now provides dedicated response writers: \Json\<T\>\ serializes data with \serde\_json\ and replaces any previously buffered body to ensure valid JSON output; \Text\<C\>\ renders string content with appropriate content-type headers for plain text, HTML, XML, JSON, CSS, JS, CSV, Atom, RSS, and RDF; \Redirect\ constructs HTTP redirects with automatic percent-encoding of non-ASCII characters and includes security documentation warning against open redirects; and \ReadSeeker\ streams content from \AsyncRead\/\AsyncSeek\ sources, supporting HTTP range requests, conditional requests (If-Match, If-Modified-Since, etc.), and proper handling of partial content responses.

crates/core/src/writing · high confidence

New routing and remote-addr examples added

Added new example applications for routing and remote address handling. The routing example demonstrates how to define routes with path parameters (e.g., \{id:num}\), apply middleware (auth hoop), and conditionally include routes based on configuration flags (debug/admin modes). The remote-addr example shows how to retrieve and display the client's remote address in a response. Both examples listen on port 8698 at 0.0.0.0.

examples/routing · high confidence

New salvo\_oapi todos example with multiple OpenAPI UIs

Added a new \oapi-todos\ example that demonstrates building a RESTful API with Salvo and automatically generating OpenAPI documentation. The example serves the OpenAPI JSON spec at \/api-doc/openapi.json\ and provides four interactive documentation viewers: Swagger UI, Scalar, RapiDoc, and ReDoc, accessible at their respective root paths. The API listens on port 8698 and supports standard CRUD operations for todos.

examples/oapi-todos · high confidence

New serde-util crate for parsing serde attributes and case conversion

A new \serde-util\ crate has been added to the workspace, providing utilities for parsing \\#\[serde(...)\]\ attributes from Rust type definitions. It introduces a \SerdeValue\ struct to extract field-level attributes such as \skip\, \rename\, \alias\, \default\, \flatten\, and \double\_option\, and a \SerdeContainer\ struct to parse container-level attributes like \rename\_all\, \tag\, \content\, \untagged\, and \deny\_unknown\_fields\. The crate also includes a \RenameRule\ enum in \case.rs\ that supports converting Rust identifiers to various casing styles (e.g., camelCase, snake\_case, kebab-case) for use in serialization/deserialization.

crates/serde-util · high confidence

New todos-utoipa example with OpenAPI/Swagger support

Added a new example application (\examples/todos-utoipa\) demonstrating a Todo API built with Salvo and utoipa. This example includes automatic OpenAPI JSON generation and a Swagger UI interface, accessible at \/api-doc/openapi.json\ and \/swagger-ui/\ respectively. The service listens on port 8698 and implements standard CRUD operations for todos with path-based routing.

examples/todos-utoipa · high confidence

OpenAPI 3.2 example demonstrates version-specific features

A new example application in examples/oapi-3-2 shows how to opt into OpenAPI 3.2 generation using the \openapi\_version\ method. This example highlights 3.2-specific capabilities, including the registration of the HTTP \QUERY\ method via \Router::query\, the use of \self\_uri\ for stable base URIs, and the addition of \name\ on Server objects and \summary\/\kind\ on Tag objects. It also notes that while Swagger UI renders these documents, other viewers like Scalar, RapiDoc, and ReDoc may currently ignore the \query\ operation.

examples/oapi-3-2 · high confidence

OpenAPI documentation UIs hardened against XSS and schema generation expanded

The \crates/oapi\ module now includes dedicated HTML escaping utilities (\html.rs\) to prevent cross-site scripting (XSS) when rendering Swagger UI, Scalar, ReDoc, and RapiDoc pages, ensuring user-supplied titles, descriptions, and spec URLs are safely escaped. Additionally, the OpenAPI schema generation capabilities have been expanded: the \EndpointOutRegister\ trait now supports \StatusCode\ (emitting all standard HTTP status codes), \Result\<T, E\>\ (registering both success and error schemas), and \salvo\_core::Error\, while the \OpenApi\ struct now supports OpenAPI 3.2 features like the \$self\ URI and the \webhooks\ field.

crates/oapi/src · high confidence

Support for OpenAPI request body examples and field-level encoding

The macro now allows users to specify detailed examples and per-field encoding rules for multipart request bodies. You can define named examples with summaries, descriptions, and JSON values using the \example\ and \examples\ attributes on \request\_body\. Additionally, the new \encoding\ attribute lets you configure \content\_type\, \explode\, and \allow\_reserved\ for individual fields within a multipart body, ensuring the generated OpenAPI documentation accurately reflects complex serialization requirements.

crates/oapi-macros/src/operation · high confidence

Support for dynamic TLS certificate reloading via config streams

The native TLS listener now accepts a stream of configuration updates, allowing TLS certificates and keys to be reloaded at runtime without restarting the server. This is implemented through the new \NativeTlsConfig\ builder and \NativeTlsListener\, which spawn a background task to monitor the config stream and swap the active \TlsAcceptor\ when changes are detected, ensuring continuous availability during certificate rotations.

_crates/core/src/conn/native\tls · high confidence

Support for dynamic TLS configuration reloading

The OpenSSL connection layer now supports live reloading of TLS certificates and keys without restarting the server. By accepting a stream of \OpensslConfig\ objects, the \OpensslListener\ spawns a background task that monitors for configuration changes and atomically swaps the active \SslAcceptor\ when a new valid configuration is provided, ensuring continuous availability during certificate rotations.

crates/core/src/conn/openssl · high confidence

Removals

Removal of basic\_auth example

The basic\_auth example located in examples/basic\_auth has been removed from the repository. This deletion includes the main source file (main.rs) which demonstrated basic authentication using the novel and novel\_extra libraries, as well as the associated static test files (file2.txt, file4.txt) used to verify static file serving behind the auth handler.

_examples/basic\_auth, examples/file\_list, examples/hello\world · high confidence

Removal of core HTTP server and request handling components

The \core/src\ module has removed the foundational components for the HTTP server and request lifecycle, including the \Server\ and \ServerConfig\ structs, the \Context\ request context, the \Handler\ trait, the \Content\ rendering types, the \Catcher\ error handling mechanism, and the \State\ dependency container. This effectively strips the library of its ability to bind to network addresses, process incoming HTTP requests, route them to handlers, render responses, or manage application state.

core/src · high confidence

Removal of core routing implementation files

The files defining the routing logic, including \core/src/routing/method.rs\, \core/src/routing/router.rs\, and \core/src/routing/mod.rs\, have been deleted from the codebase. This removes the \Router\ struct, \Method\ bitflags, and associated segment parsing logic (such as \RegexSegment\, \RestSegment\, and \ConstSegment\) that were previously exposed via the \core/src/routing\ module.

core/src/routing · high confidence

Removal of legacy BasicAuthHandler module

The \extra/src/auth\ module, which previously provided a \BasicAuthHandler\ for HTTP Basic Authentication, has been removed. This change eliminates the built-in capability to validate credentials against a custom validator and inject the authenticated username into the request context, requiring users to implement authentication logic through other means if this functionality is still needed.

extra/src/auth · high confidence

Removal of legacy HTTP request and response abstractions

The legacy HTTP request and response types (\Request\, \Response\, \BodyWriter\) and their supporting modules (\headers\, \form\) have been removed from the \core/src/http\ module. This deletion eliminates the previous abstraction layer that wrapped \hyper\ and \cookie\ libraries, indicating a shift in the framework's internal HTTP handling strategy.

core/src/http · high confidence

Removal of legacy JWT and static file serving handlers

The \extra/src/serve\ module has removed the legacy \JwtHandler\ and \Static\ file-serving components. This eliminates the built-in ability to validate JWTs via header, form, query, or cookie extractors and removes the automatic directory listing and static file serving capabilities that previously relied on these handlers.

extra/src/serve · high confidence

Removal of legacy multipart form-data parsing implementation

The \core/src/http/form\ module has been completely removed, deleting the legacy synchronous implementation for parsing and generating \multipart/form-data\ requests. This includes the removal of the \FormData\ struct, \FilePart\ handling, and the \read\_form\_data\/\write\_form\_data\ APIs that previously relied on the old Hyper network stream abstractions and \httparse\ for header parsing. Users relying on this specific module for form handling will need to adopt the new asynchronous API introduced in the same change set.

core/src/http/form · high confidence

Architecture

Refactor oapi-macros feature attributes into modular components

The attribute parsing and validation logic in the \oapi-macros\ crate has been restructured into dedicated modules (\attributes\, \ext\, \macros\, \validation\, \validators\). This refactoring introduces a more modular architecture for handling schema features (such as \example\, \default\, \xml\, \format\, and validation constraints like \maximum\/\minimum\), improving code organization and maintainability without changing the external API surface.

crates/oapi-macros/src/feature · high confidence

Refactored schema generation into modular components

The schema generation logic in the \oapi-macros\ crate has been reorganized into distinct modules (\enum\_schemas\, \enum\_variant\, \struct\_schemas\, \flattened\_map\_schema\, \feature\, and \xml\). This refactoring separates the concerns of parsing schema features, handling different enum types (simple, repr, tagged, untagged, complex), processing struct fields (including flattened maps), and generating XML attributes, resulting in a more maintainable codebase without changing the external API.

crates/oapi-macros/src/schema · high confidence

Behavioural changes

ACME module replaced with certon for enhanced certificate management

The ACME module has been rewritten to use the certon library, replacing the previous salvo-acme implementation. This change introduces support for multiple certificate issuers (including Let's Encrypt and ZeroSSL), additional challenge types (HTTP-01, TLS-ALPN-01, DNS-01), on-demand TLS, OCSP stapling, and pluggable storage backends. The default key type for new certificates is now ECDSA P-256, and the module now explicitly handles rustls CryptoProvider selection to support both ring and aws-lc-rs backends without panicking.

crates/acme/src · high confidence

CORS middleware refactored with granular configuration and private network support

The CORS handler in \crates/cors\ has been completely rewritten to use a modular, builder-style API where each CORS header (Allow-Origin, Allow-Methods, Allow-Headers, Allow-Credentials, Expose-Headers, Max-Age, Vary) is configured via its own dedicated struct (e.g., \AllowOrigin\, \AllowCredentials\). This refactoring introduces support for dynamic and async closures to determine header values at runtime, adds a new \AllowPrivateNetwork\ configuration for the Access-Control-Allow-Private-Network header, and includes a \permissive()\ convenience method for development. The implementation also optimizes header value joining to reduce allocations and enforces that the CORS handler is attached to the \Service\ level rather than the \Router\ to correctly intercept preflight requests.

crates/cors/src · high confidence

Expanded and more flexible OpenAPI endpoint attribute parsing

The \\#\[oapi(endpoint)\]\ macro now supports a broader range of attribute syntaxes, allowing tags and descriptions/summaries to be specified as expressions rather than just string literals. It also introduces aliases for single \response\ and \parameter\ attributes (which can now accept struct paths or tuples) and adds a \status\_codes\ attribute to restrict allowed HTTP status codes. These changes make the macro's attribute parsing more robust and expressive for defining OpenAPI specifications directly on Rust functions.

crates/oapi-macros/src/endpoint · high confidence

Explicit OpenAPI schema registration for request parameters and bodies

The \crates/oapi/src/extract\ module now explicitly implements \EndpointArgRegister\ for request extractors (re-exported from \salvo\_core\), ensuring that OpenAPI documentation accurately reflects incoming data structures. Parameter extractors (\CookieParam\, \HeaderParam\, \PathParam\, \QueryParam\) now register their specific locations and required status in the operation schema, while payload extractors (\JsonBody\, \FormBody\, \FormFile\, \FormFiles\) define the corresponding request body content types (e.g., \application/json\, \multipart/form-data\) and schemas. This change guarantees that API endpoints using these extractors will have their input requirements correctly documented in the generated OpenAPI spec.

crates/oapi/src/extract · high confidence

Introduce dedicated compression encoder and streaming implementation

The compression middleware now uses a new internal architecture with separate \encoder.rs\ and \stream.rs\ modules to handle response body compression. This change introduces a \Writer\ struct for buffering data and an \Encoder\ enum that wraps specific compression libraries (Brotli, Deflate, Gzip, Zstd) based on feature flags. The \EncodeStream\ implementation manages the asynchronous compression of response bodies, supporting various body types like \BoxStream\, \HyperBody\, and \VecDeque\<Bytes\>\. This refactoring separates the low-level encoding logic from the middleware's HTTP handling, improving modularity and allowing for more efficient chunked compression with configurable levels and minimum lengths.

crates/compression/src · high confidence

JWT authentication crate restructured with new decoder and finder abstractions

The \jwt-auth\ crate has been refactored to provide a more modular authentication experience. It now introduces a \JwtAuthDecoder\ trait, implemented by \ConstDecoder\ (for static keys) and \OidcDecoder\ (for OpenID Connect discovery), allowing users to choose their validation strategy. Token extraction is handled by a new \JwtTokenFinder\ trait, with built-in implementations like \HeaderFinder\ and \FormFinder\ that support configurable HTTP methods and header names. The crate also enforces stricter security defaults, such as rejecting symmetric JWKs from OIDC discovery by default and requiring explicit crypto provider installation, while updating the underlying \jsonwebtoken\ dependency to version 11.

crates/jwt-auth/src · high confidence

Major core refactoring: new Depot, Catcher, and Fuse systems

The core library has been restructured with several significant behavioral changes. The request context storage is now handled by a new \Depot\ type, which replaces the previous \Piece\/\Scribe\ naming and introduces a split between string-keyed and type-keyed storage for better performance. Error handling is now managed by a dedicated \Catcher\ module that supports middleware-style chaining and content negotiation for error pages, controlled via the \SALVO\_STATUS\_ERROR\ environment variable. Connection protection is now provided by a new \Fuse\ system (\FuseConfig\, \FusePolicy\) that enforces timeouts against slow HTTP attacks. Additionally, the \Handler\ trait has been updated to use \goal\ and \hoop\ terminology, and the \Error\ enum now includes variants for \anyhow\ and \eyre\ when those features are enabled.

crates/core/src · high confidence

Multi-server example now listens on 0.0.0.0

The multi-servers example has been updated to bind its TCP listeners to 0.0.0.0 instead of 127.0.0.1, allowing external connections to reach the servers on ports 8698 and 5801. The example also includes two distinct handlers (hello1 and hello2) serving separate routes on these servers.

examples/multi-servers · high confidence

New connection-layer abstractions and protocol handling

The connection module introduces a set of new internal types to manage network I/O and protocol negotiation. A new \SocketAddr\ enum provides a unified representation for IPv4, IPv6, and Unix socket addresses, including display formatting and conversion helpers. Connection lifecycle is now controlled via \ConnCtrl\, which exposes methods for graceful shutdown, immediate abort, and relaxing idle/write-stall timeouts (useful for long-lived protocols like WebSockets). Protocol detection logic in \HttpBuilder\ has been updated to bound the initial read for HTTP/1 vs HTTP/2 distinction, sharing the timeout budget with Hyper's header-read timeout to prevent idle connection leaks. Additionally, \HandshakeStream\ and \StraightStream\ wrap transport streams to enforce TLS handshake timeouts, connection idle timeouts, and write-stall timeouts, while \JoinedListener\ and \JoinedAcceptor\ allow combining two listeners into a single acceptor.

crates/core/src/conn · high confidence

New request extraction metadata and case-renaming utilities

The \crates/core/src/extract\ module now includes new internal components to support request extraction: \case.rs\ provides a \RenameRule\ enum and logic for converting field names between formats like \snake\_case\, \camelCase\, and \PascalCase\, while \metadata.rs\ introduces \Metadata\ and \Field\ structs to track extraction sources (e.g., query, body, header) and rename configurations. These files lay the groundwork for the parameter and payload extractors defined in \parameter.rs\ and \payload.rs\.

crates/core/src/extract · medium confidence

OIDC JWKS caching and symmetric key rejection

The OIDC validation logic now includes a configurable cache for JSON Web Key Sets (JWKS) that respects Cache-Control headers (max-age, stale-while-revalidate, stale-if-error) with safe upper bounds to prevent indefinite staleness or overflow. Additionally, symmetric JWKs (e.g., HS\*) are rejected by default during OIDC discovery to enhance security, requiring explicit opt-in if needed.

crates/jwt-auth/src/oidc · high confidence

OpenAPI macro crate refactored with improved error handling and schema generation

The \oapi-macros\ crate has been restructured into a modular architecture (attribute, bound, component, diagnostic, doc\_comment, endpoint, feature, operation, parameter, etc.) to improve maintainability. This change introduces a dedicated \Diagnostic\ system that converts user-triggerable panics into compile-time errors, ensuring clearer feedback when macro attributes are misused. It also refines schema generation logic, specifically ensuring that \Option\<T\>\ in parameter contexts is treated as optional rather than nullable, and adds support for parsing negative values in schema validation attributes.

crates/oapi-macros/src · high confidence

Refactor OpenAPI schema types to support JSON Schema draft 2020-12 and OpenAPI 3.1

The schema definitions in \crates/oapi/src/openapi/schema\ have been rewritten to align with OpenAPI 3.1 (which adopts JSON Schema draft 2020-12). This introduces a new \Number\ type that correctly distinguishes between integers and floats during serialization (e.g., \1\ vs \1.0\), adds \prefix\_items\ support to \Array\ for tuple validation, and adds \property\_names\ support to \Object\ for typed map keys. Composite schemas (\AllOf\, \AnyOf\, \OneOf\) now explicitly support \examples\, \discriminator\, and \extensions\ fields, and the \Object\ schema now uses \IndexSet\ for required fields to preserve order when the \preserve-order\ feature is enabled.

crates/oapi/src/openapi/schema · high confidence

Refactored macro internals and improved extraction error handling

The \crates/macros\ crate has been restructured into dedicated modules (\attribute\, \extract\, \handler\, \shared\) to improve maintainability. A key behavioral change is that \\#\[serde(flatten)\]\ is now explicitly rejected on \Extractible\ fields in favor of \\#\[salvo(extract(flatten))\]\, preventing silent conflicts between serde's buffering and Salvo's metadata-driven flattening. Additionally, the \\#\[handler\]\ macro now correctly handles raw identifiers (e.g., \r\#type\) for extractor parameters by using parsed identifiers instead of string rewriting, and it ensures a 400 Bad Request status is set if extraction fails and no error status was previously defined.

crates/macros · high confidence

Refactored request deserialization with optimized depot extraction and new value types

The \crates/core/src/serde\ module has been rewritten to improve performance and robustness when deserializing request data. A new \get\_depot\_value\ helper extracts values from the Depot using a single map lookup and cheap downcasts, supporting \String\, \&str\, \Arc\<String\>\, \Arc\<str\>\, and numeric/boolean types. The JSON payload is now wrapped in an \Arc\ to make cloning cheap during flattened field processing. New internal deserializer types—\CowValue\, \FlatValue\, and \VecValue\—handle string-to-type conversion, URL query parsing (including list detection), and sequence deserialization respectively, replacing the previous implementation.

crates/core/src/serde · high confidence

Regenerated test certificates and added macOS compatibility script

The test certificate assets in the core crate have been regenerated, including new \cert.pem\, \key.pem\, and \chain.pem\ files for the \testserver.com\ domain. A new \generate.sh\ script was added to automate this process, featuring specific support for macOS by generating legacy PKCS\#12 files (\identity-legacy.p12\) via the \-legacy\ OpenSSL flag to ensure compatibility with older macOS keychain implementations.

crates/core/certs · high confidence

Reintroduce and expand HTTP error handling with RFC 9457 support

The HTTP error module has been reconstructed to provide a more robust and standards-compliant error handling experience. A new \StatusError\ type is introduced, featuring a \cause\ field that exposes the underlying error via the standard \Error::source\ trait method, alongside a separate \origin\ field for type-safe downcasting of the original error value. The module now includes comprehensive support for RFC 9457 Problem Details via a new \Problem\ struct, allowing developers to generate structured JSON error responses with standard fields like \type\, \title\, \detail\, and \instance\, as well as custom extensions. Additionally, a new \ParseError\ enum centralizes HTTP parsing failures (such as payload size limits, invalid content types, and deserialization errors) and implements the \Writer\ trait to automatically render appropriate HTTP status codes and error messages.

crates/core/src/http/errors · high confidence

Removal of extra/src/lib.rs module structure

The \extra/src/lib.rs\ file has been deleted, removing the public module declarations for \serve\, \auth\, and \jwt\ that were previously exposed from this crate. This change eliminates the direct re-export of these sub-modules from the \extra\ library's root, likely as part of a broader restructuring or cleanup of the extra features.

extra/src · high confidence

Reworked routing internals with structured filters and optimized path parameter handling

The routing module has been restructured to improve performance and maintainability. A new \filters.rs\ module introduces structured filter types (scheme, host, port, path, method) that expose typed metadata via \FilterInfo\, enabling better introspection for debugging and OpenAPI generation. The \FlowCtrl\ component now manages handler execution with explicit \call\_next\, \skip\_rest\, and \cease\ methods, allowing middleware to control flow more precisely. Path parameter handling in \path\_params.rs\ uses a snapshot-and-rollback mechanism to efficiently undo captures during failed route matches without cloning, and \path\_state.rs\ now uses copy-on-write strings for path parts to reduce allocations. The \Router\ struct has been marked \\#\[non\_exhaustive\]\ and its internal detection logic refactored to use a stack-based approach with explicit rollback frames.

crates/core/src/routing · high confidence

Session middleware now uses saysion and enforces stricter key security

The session implementation has been migrated from the unmaintained \async-session\ crate to \saysion\, updating the underlying storage and cookie handling mechanisms. To improve security, the minimum recommended secret key length has been increased to 64 bytes (512 bits), with the builder now panicking on shorter keys to prevent weak session signing. The module also introduces a \SecureCookiePolicy\ configuration option, allowing users to explicitly control whether session cookies are marked as secure based on the request scheme.

crates/session/src · high confidence

TLS certificate reloading example updated to use Salvo and bind to all interfaces

The \examples/tls-openssl-reload\ example has been rewritten to use the Salvo web framework instead of the previous implementation. It now listens on \0.0.0.0:8698\ (previously likely bound to localhost or a different port) and demonstrates dynamic TLS certificate reloading by periodically loading certificate and key files from \certs/cert.pem\ and \certs/key.pem\. The example serves a simple "Hello World" text response.

examples/tls-openssl-reload · high confidence

TLS configuration now supports hot-reloading via a config stream

The Rustls listener and acceptor have been refactored to accept a dynamic configuration stream instead of a static TLS config. This allows TLS certificates and settings to be reloaded in the background without restarting the server, with invalid updates safely ignored and the previous configuration retained. The implementation also ensures that HTTP/1.1 and HTTP/2 versions are automatically included in the listener's holdings when their respective features are enabled, and provides a method to convert the acceptor into a boxed dynamic TCP acceptor.

crates/core/src/conn/rustls · high confidence

TLS examples updated with new structure and port configuration

The TLS example applications have been reorganized and updated. The \tls-native-tls-reload\ example now uses the \native\_tls\ connector with automatic certificate reloading every 60 seconds, while the \tls-rustls\ example demonstrates static TLS configuration using \rustls\. Both examples now listen on port 8698 instead of the previous default, and bind to \0.0.0.0\ to accept connections from any interface. New certificate files (cert.pem and key.pem) have been added to the rustls example directory to support the TLS configuration.

examples/tls-native-tls-reload, examples/tls-rustls · high confidence

TLS reload example now listens on 0.0.0.0:8698 with embedded certificates

The TLS reload example has been updated to bind to all interfaces (0.0.0.0) on port 8698, replacing the previous localhost-only configuration. It now includes embedded certificate and key files (cert.pem and key.pem) directly in the source tree, which are loaded at runtime to configure Rustls. The server continuously reloads these TLS credentials every 60 seconds to support dynamic certificate updates without restarting the process.

examples/tls-rustls-reload · high confidence

Updated feature flag documentation and re-export structure

The \salvo\ crate's \lib.rs\ has been updated to reflect the current set of available feature flags, including the addition of \tus\ (resumable uploads), \rfc9457\ (Problem Details), and \jwt-auth-ring\ (JWT with RustCrypto provider), while removing \async-compression\ in favor of the new \compression\ feature. The documentation table now accurately lists default and optional features such as \aws-lc-rs\ and \ring\ for TLS providers. Additionally, the internal re-export structure has been adjusted to conditionally expose middleware modules from \salvo\_extra\ and other sub-crates based on these feature flags, ensuring that only enabled features are available in the public API.

crates/salvo · high confidence

Test coverage

Added RequestBuilder for constructing test HTTP requests; Added benchmarks for routing and service dispatch performance; Added end-to-end tests for OpenTelemetry HTTP semantic conventions; Added integration and unit tests for the Salvo + PostgreSQL + SeaORM example; Added integration and unit tests for the Salvo Postgres Diesel example; Added regression tests for doc comment propagation and generic impl handling; Added test client and response utilities; Added test coverage for OpenAPI macro schema composition and endpoint generation; Added test fixtures for precompressed file serving; Added tests for OpenAPI 3.2 serialization; Added tests for crypto provider feature interactions; Removed obsolete hello\_world integration test.

Dependencies

Adopt workspace dependency management and update MSRV to Rust 1.94

The project has migrated to a workspace-based dependency configuration, centralizing version management for crates such as \salvo\, \salvo-core\, and \salvo-oapi\ to ensure consistency across the monorepo. This change also updates the Minimum Supported Rust Version (MSRV) to 1.94 and adopts the Rust 2024 edition for the examples workspace. Additionally, several example dependencies have been updated, including \sea-orm\ pinned to \rc.42\ to resolve compatibility issues and \jsonwebtoken\ upgraded to version 10.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 39 → 41 (+2.8)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 86 → 86 (+0.0)
  • Architecture 96 → 95 (-0.6)
  • Maturity 66 → 67 (+0.2)
  • Readiness 63 → 66 (+3.2)
  • Security 53 → 63 (+10.1)
  • Event-Driven 10 → 10 (+0.0)
  • Performance 89 (new)

Resolved (23)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Documentation: no usage examples (crates/proxy/README.md)
  • Hotspot: crates/compression/src/lib.rs (crates/compression/src/lib.rs)
  • Hotspot: crates/core/src/conn/proto.rs (crates/core/src/conn/proto.rs)
  • Hotspot: crates/core/src/conn/quinn/builder.rs (crates/core/src/conn/quinn/builder.rs)
  • Hotspot: crates/core/src/http/body/res.rs (crates/core/src/http/body/res.rs)
  • Hotspot: crates/core/src/http/errors/status_error.rs (crates/core/src/http/errors/status_error.rs)
  • Hotspot: crates/core/src/http/range.rs (crates/core/src/http/range.rs)
  • Hotspot: crates/core/src/serde/request.rs (crates/core/src/serde/request.rs)
  • Hotspot: crates/core/src/server.rs (crates/core/src/server.rs)
  • Hotspot: crates/core/src/writing/seek.rs (crates/core/src/writing/seek.rs)
  • Hotspot: crates/macros/src/extract.rs (crates/macros/src/extract.rs)
  • Hotspot: crates/oapi-macros/src/component.rs (crates/oapi-macros/src/component.rs)
  • Hotspot: crates/oapi-macros/src/feature.rs (crates/oapi-macros/src/feature.rs)
  • Hotspot: crates/oapi-macros/src/schema_type.rs (crates/oapi-macros/src/schema_type.rs)
  • Hotspot: crates/oapi/src/openapi.rs (crates/oapi/src/openapi.rs)
  • Hotspot: crates/tus/src/handlers/patch.rs (crates/tus/src/handlers/patch.rs)
  • Repeated repair: crates/core/src/http/response.rs (crates/core/src/http/response.rs)
  • …and 3 more

New (15)

  • Ambiguous duplication. insert_typed and inject both take a value V and return Self. In many contexts, 'inject' is a synonym for 'insert'. Without seeing the implementation, it is unclear if they differ by key derivation or behavior, but the naming convention is inconsistent (one is explicit about type, one is generic verb).
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Documentation: no project overview (README.md)
  • Duplicate method names with identical signatures. directory and get_directory appear to perform the same configuration action (setting a directory URL), likely due to a copy-paste error or incomplete refactoring.
  • Duplicate method names with identical signatures. get_typed/obtain and get_typed_mut/obtain_mut appear to be synonyms for retrieving typed values from the depot.
  • Duplicate method signatures. Two methods named extension with identical parameters but different return types (Problem vs Self). This is a compile error in Rust unless they are in different traits or one is a typo in the API surface description. Assuming it's a valid surface, this is a severe inconsistency/error.
  • Inconsistent naming for removal operations. delete returns a bool (success/failure), while remove returns a Box (likely the removed value or a result). This is confusing because remove typically implies returning the value in Rust, while delete implies a void/bool action. However, the return types are vastly different, suggesting they might do different things, but the names are counter-intuitive relative to their signatures.
  • Low cohesion: Cors (LCOM4 4) (crates/cors/src/lib.rs)
  • Low cohesion: DynStream (LCOM4 4) (crates/core/src/conn.rs)
  • Low cohesion: EncodeStream (LCOM4 6) (crates/compression/src/stream.rs)
  • Low cohesion: OpenApi (LCOM4 7) (crates/oapi/src/openapi.rs)
  • Low cohesion: Router (LCOM4 6) (crates/core/src/routing/router.rs)
  • Off the main sequence: salvo-serde-util
  • Off the main sequence: salvo_core
  • Split crates/core

Changes since last survey

  • 4 commits — 2 feature/other, 2 fixes

By area

  • (root) — 2 commits
  • crates/serve-static — 1 commit
  • examples/otel-jaeger — 1 commit

Notable commits

  • fix: fix(examples): align OpenTelemetry examples with 0.33 (#1710)
  • fix: fix(serve-static): block paths beneath dot directories (#1708)
  • change: Release 1.0.0
  • change: build(deps): upgrade OpenTelemetry crates to 0.33 together (#1709)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

salvo-rs/salvo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e011f4d2e33091fec02a8e8246bbfd8a69ad878c — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.