seanmonstar/warp
67.2
Adequate · 29 September 2026
9.8k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is a Rust-based HTTP web framework that provides a composable filter system for building asynchronous web services. It handles core web operations such as routing, request body parsing, static file serving, and response generation, while supporting advanced protocols like WebSockets and Server-Sent Events. The architecture is built on modern async primitives and the Hyper 1.0 stack, enabling integration with middleware and secure TLS configurations.
Features
Added ECC and RSA certificate/key examples for TLS configuration
The examples/tls directory now includes sample certificate and private key files supporting both Elliptic Curve (ECC) and RSA algorithms. Specifically, cert.ecc.pem and key.ecc provide an ECC pair, while cert.pem and key.rsa provide an RSA pair, allowing users to choose their preferred cryptographic algorithm when configuring TLS in the example setup.
examples/tls · high confidence
New examples directory with comprehensive usage guides
The \examples\ directory now includes a \README.md\ and a wide range of new example files demonstrating core and advanced \warp\ features. These include basic routing (\hello.rs\, \routing.rs\), body and header parsing (\body.rs\, \headers.rs\), static file serving (\file.rs\, \dir.rs\), and compression (\compression.rs\). New examples also cover WebSockets (\websockets.rs\, \websockets\_chat.rs\), Server-Sent Events (\sse.rs\, \sse\_chat.rs\), TLS configuration (\tls.rs\), and custom HTTP methods (\custom\_methods.rs\). Additional examples show how to handle rejections (\rejections.rs\), integrate with Handlebars templates (\handlebars\_template.rs\), use Unix sockets (\unix\_socket.rs\), implement tracing diagnostics (\tracing.rs\), and build a full CRUD application (\todos.rs\).
examples · high confidence
Behavioural changes
Filter system refactored to use async futures and a new Rejection model
The \src/filter\ module has been completely rewritten to replace the synchronous \Filter\ trait with an asynchronous, \std::future::Future\-based architecture. This change introduces a new \Rejection\ system for handling errors, replacing the previous \FilterResult\ mechanism, and adds new combinators such as \and\_then\, \then\, \or\_else\, \recover\, and \boxed\ to support the new async flow. Additionally, the module now provides \warp::service()\ to convert a \Filter\ into a Tower \Service\, enabling integration with broader middleware ecosystems.
src/filter · high confidence
Major internal refactor to support hyper 1.0 and async body handling
The internal architecture has been significantly restructured to support the hyper 1.0 upgrade. This includes a new \bodyt\ module that wraps \http\_body\_util\ types to manage request and response bodies, replacing the previous \WarpBody\ wrapper. The \handler\ and \router\ modules have been removed in favor of a direct \Filter\-to-\Service\ conversion via the new \service\ module. Additionally, the \route\ module now uses scoped thread-locals to manage request state, and the \tls\ module has been updated to use \tokio\_rustls\ for TLS configuration.
src · high confidence
Major rewrite of the filter system for warp v0.4
The \src/filters\ module has been completely rewritten to support the new warp v0.4 architecture. This change introduces a new set of built-in filters including \addr::remote\, \any\, \body\ (with \json\, \bytes\, \stream\, \aggregate\, and \content\_length\_limit\), \compression\ (gzip, deflate, brotli), \cookie\, \cors\, \ext\, \fs\ (file and dir with path sanitization), \header\, \host\, \log\, \method\, \multipart\, \path\, \query\, \reply\, \sse\, \trace\, and \ws\. The implementation shifts to using \futures-util\ and \http-body-util\, and introduces a new \Filter\ trait structure with \FilterBase\ and \WrapSealed\ for wrapping filters. The \fs\ filters now include path sanitization to prevent directory traversal attacks by rejecting paths with backslashes or colons on Windows. The \body\ filters now use \http\_body\_util::BodyDataStream\ and \BodyExt\ for body extraction. The \cors\ filter has been reworked to use a builder pattern. The \log\ filter now uses the \log\ crate instead of \tracing\ for default logging. The \method\ filters now return \Infallible\ errors for the \method()\ filter. The \multipart\ filter now uses the \multer\ crate. The \path\ filter has been reworked to use a new \path!\ macro. The \query\ filter has been reworked to use the \serde\_urlencoded\ crate. The \reply\ filter has been reworked to use the \http\ crate's \Response\ type. The \sse\ filter has been reworked to use the \tokio\_util\ crate. The \trace\ filter has been reworked to use the \tracing\ crate. The \ws\ filter has been reworked to use the \tokio-tungstenite\ crate.
src/filters · high confidence
Test coverage
Added comprehensive test coverage for core Warp filters and utilities
Added new test files in the \tests/\ directory to verify the behavior of key Warp components. These tests cover request address extraction (\tests/addr.rs\), body parsing including JSON, form, and stream handling with content-length limits (\tests/body.rs\), cookie extraction (\tests/cookie.rs\), CORS policy enforcement (\tests/cors.rs\), request extensions (\tests/ext.rs\), filter composition and tuple flattening (\tests/filter.rs\), static file serving and directory indexing (\tests/fs.rs\), header matching (\tests/header.rs\), host authority matching (\tests/host.rs\), HTTP method routing (\tests/method.rs\), multipart form data (\tests/multipart.rs\), path segment matching and parameters (\tests/path.rs\), query string parsing (\tests/query.rs\), HTTP redirects (\tests/redirect.rs\), reply header manipulation (\tests/reply\_with.rs\), tracing integration (\tests/tracing.rs\), and WebSocket handshake and message handling (\tests/ws.rs\).
tests · high confidence
Dependencies
Warp 0.4.3: Major dependency overhaul and feature unification
This release updates the warp crate to version 0.4.3, performing a comprehensive migration of its underlying dependencies. The HTTP stack has been upgraded from hyper 0.11 to hyper 1, accompanied by the adoption of hyper-util 0.1.12 and the http 1.0 crate, replacing the older http 0.1 types. Asynchronous primitives have shifted from the legacy futures 0.1 crate to futures-util 0.3 and futures-channel 0.3.17. The TLS implementation has been standardized on tokio-rustls (commented out in the diff but referenced in commit history as the target), and multipart handling now uses the multer crate. Additionally, the dependency structure has been significantly refactored: hyper, hyper-util, tokio-tungstenite, multer, and futures-channel are now optional dependencies controlled by specific features (server, websocket, multipart, test), allowing users to reduce binary size by disabling unused capabilities. Dev-dependencies have also been updated, including pretty\_env\_logger to 0.5 and the addition of tracing-subscriber and tracing-log.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 69 → 67 (-1.9)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.
Lenses
- Code Health 98 → 98 (+0.0)
- Architecture 100 → 84 (-16.3)
- Maturity 57 → 57 (+0.0)
- Readiness 63 → 62 (-1.1)
- Security 90 → 90 (+0.0)
- Performance 100 (new)
Resolved (4)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1
New (6)
- Ambiguous naming for HTTP 302 Found. redirect.found is the specific HTTP status code name, while redirect.redirect is a generic verb. In many web frameworks, redirect is the generic action, but having both redirect and found as top-level functions with identical signatures suggests redirect might be an alias or a legacy name. It is unclear if redirect defaults to 302 or if it is a generic builder. Given see_other, temporary, and permanent are explicit, redirect is redundant and confusingly named.
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Duplicate intent for adding a single header. The warp.reply module provides a standalone function with_header that takes a reply and header details, while warp.filters.reply provides a method header on the filter/reply context. While one is a function and one is a method, they represent the same logical operation (attaching a header to a response). In a fluent API, methods are preferred; having a standalone function with the same name and signature logic creates confusion about which entry point to use.
- Inverted test pyramid
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
seanmonstar/warp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ff34d7213ed55ec342304aa7ff6ac4b351da9e66 — the exact code this score is about.
- Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fbec9b1e08c2.