NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #973 most downloaded on crates.io
Actix Web is a powerful, pragmatic, and extremely fast web framework for Rust
Last release 1 months ago
21 Aug 2026
Release timing varies
gaps range from 1 weeks to 7 months
Most releases are documented
notes for 44 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
9 years old
158 releases · first in 2017
Add Error::add_response_mapper() to allow middleware to modify error-generated responses before they are sent.
Error::add_response_mapper() to allow middleware to modify error-generated responses before they are sent.experimental-io-uring crate feature.Close idle HTTP/1 keep-alive connections during graceful shutdown and let active connections finish only their current request before closing.
One column per quarter.
Add HttpRequest::{cookies_raw,cookie_raw} and ServiceRequest::{cookies_raw,cookie_raw} for reading request cookies without percent-decoding names and
HttpRequest::{cookies_raw,cookie_raw} and ServiceRequest::{cookies_raw,cookie_raw} for reading request cookies without percent-decoding names and values. #3542[::] also accept IPv4 connections.Route::to() or Route::service() after Route::wrap() to prevent silently dropping route middleware. #3944HttpRequest::{match_pattern,match_name} reporting path-only matches when route guards disambiguate overlapping resources. #3346Readlines handling of lines split across payload chunks so combined line limits are enforced and complete lines are yielded.foldhash dependency to 0.2.rand dependency to 0.10.impl-more dependency to 0.3.HttpServer::h1_write_buffer_size().Minimum supported Rust version (MSRV) is now 1.88.
HttpServer::{h2_initial_window_size, h2_initial_connection_window_size} methods for tuning. #3638HttpRequest::url_for_map and HttpRequest::url_for_iter methods for named URL parameters. #3895Cookie request header.experimental-introspection feature to report configured routes #3594TCP_NODELAY. #3918NormalizePath rewrites a scoped dynamic path before extraction (e.g., scope("{tail:.*}") + Path<String>). #3562Correct actix-http dependency requirement.
actix-http dependency requirement.actix_web::builder::HttpResponseBuilder::streaming() now sets Content-Type to application/octet-stream if Content-Type does not exist.
actix_web::response::builder::HttpResponseBuilder::streaming() now sets Content-Type to application/octet-stream if Content-Type does not exist.actix_web::response::builder::HttpResponseBuilder::streaming() now calls actix_web::response::builder::HttpResponseBuilder::no_chunking() and returns SizedStream if Content-Length is set by user.ws crate feature (on-by-default) which forwards to actix-http and guards some of its ResponseError impls.EitherExtractError in error module.Add Logger::log_level() method.
Logger::log_level() method.Logger middleware.HttpServer::shutdown_signal() method.HttpServer as #[must_use].Compress middleware.Host header in Host guard when connection protocol is HTTP/2.mime dependency.brotli dependency to 8.No significant changes since 4.10.1.
4.10.1.No significant changes since 4.10.0.
4.10.0.Implement Responder for Result<(), E: Into >. Returning Ok(()) responds with HTTP 204 No Content.
Responder for Result<(), E: Into<Error>>. Returning Ok(()) responds with HTTP 204 No Content.HttpServer::bind() (or TLS variants) when binding to a socket that's already in use.brotli dependency to 7.Add middleware::from_fn() helper.
middleware::from_fn() helper.web::ThinData extractor.Add HttpRequest::full_url() method to get the complete URL of the request.
web::Html responder.HttpRequest::full_url() method to get the complete URL of the request.ConnectionInfo::realip_remote_addr() when handling IPv6 addresses. from the Forwarded header.UrlencodedError::ContentType variant (relevant to the Form extractor) now uses the 415 (Media Type Unsupported) status code in it's ResponseError implementation.HttpServer::max_connection_rate() setting when using rustls v0.22 or v0.23.Add compat crate feature group (on-by-default) which, when disabled, helps with transitioning to some planned v5.0 breaking changes, starting only wit…
#[scope] macro.middleware::Identity type.CustomizeResponder::add_cookie() method.guard::GuardContext::app_data() method.compat-routing-macros-force-pub crate feature which (on-by-default) which, when disabled, causes handlers to inherit their attached function's visibility.compat crate feature group (on-by-default) which, when disabled, helps with transitioning to some planned v5.0 breaking changes, starting only with compat-routing-macros-force-pub.From<Box<dyn ResponseError>> for Error.Add unicode crate feature (on-by-default) to switch between regex and regex-lite as a trade-off between full unicode support and binary size.
unicode crate feature (on-by-default) to switch between regex and regex-lite as a trade-off between full unicode support and binary size.rustls-0_23 crate feature.HttpServer::{bind_rustls_0_23, listen_rustls_0_23}() builder methods.HttpServer::tls_handshake_timeout() builder method for rustls-0_22 and rustls-0_23.brotli dependency to 6.rustls in some circumstances.Fix missing import when using enabling Rustls v0.22 support.
Add HttpServer::{bind_rustls_0_22, listen_rustls_0_22}() builder methods.
rustls-0_22 crate feature.HttpServer::{bind_rustls_0_22, listen_rustls_0_22}() builder methods.Updated zstd dependency to 0.13.
zstd dependency to 0.13.Json extractor when JsonConfig::validate_content_type() is set to false.Minimum supported Rust version (MSRV) is now 1.88.
syn dependency to 3.HttpServer::{bind, listen}_auto_h2c() methods behind new http2 crate feature.HttpServer::{bind, listen}_rustls_021() methods for Rustls v0.21 support behind new rustls-0_21 crate feature.Resource::{get, post, etc...} methods for more concisely adding routes that don't need additional guards.web::Payload::to_bytes[_limited]() helper methods.HttpResponse for several status codes.http::header::ContentLength typed header.Default for web::Data.serde::Deserialize for web::Data.rustls-0_20 crate feature, which the existing rustls feature now aliases.Compress middleware no longer compresses image or video content.HttpRequest's Debug output.time dependency.Add support for custom methods with the #[route] macro. [#2969]
#[route] macro. #2969Add ContentDisposition::attachment() constructor. [#2867]
ContentDisposition::attachment() constructor. #2867ErrorHandlers::default_handler() (as well as default_handler_{server, client}()) to make registering handlers for groups of response statuses easier. #2784Logger::custom_response_replace(). #2631web::redirect() / web::Redirect. #1961guard::Acceptable for matching against Accept header MIME types. #2265test helpers: try_call_service(), try_call_and_read_body_json(), try_read_body(), and try_read_body_json(). #2961Allow header to Resource's default responses when no routes are matched. #2949Bump minimum version of actix-http dependency to fix compatibility issue. [#2871]
actix-http dependency to fix compatibility issue. #2871Add #[routes] macro to support multiple paths for one handler. [#2718]
#[routes] macro to support multiple paths for one handler. #2718ServiceRequest::{parts, request}() getter methods. #2786HttpServer::{rustls, openssl}_with_config methods. #2752time dependency.Add ServiceRequest::extract() to make it easier to use extractors when writing middlewares. [#2647]
ServiceRequest::extract() to make it easier to use extractors when writing middlewares. #2647Route::wrap() to allow individual routes to use middleware. #2725ServiceConfig::default_service(). #2338 #2743ResponseError for std::convert::Infalliblehashbrown dependency.HttpRequest drop. #2742Use stable version in readme example.
Rename test::{default_service => status_service}(). Old name is deprecated. [#2518]
actix-* to Tokio v1-based versions. #1813actix-web-codegen to 4.0.0.cookie to 0.16. #2555language-tags to 0.3.rand to 0.8.rustls to 0.20. #2414tokio to 1.CustomizeResponder for customizing response. #2510dev::ServerHandle re-export from actix-server. #2442dev::ServiceFactory re-export from actix-service. #2325guard::GuardContext for use with the Guard trait. #2552http::header::AcceptEncoding typed header. #2482http::header::Range typed header. #2485http::KeepAlive re-export from actix-http. #2625middleware::Compat that boxes middleware types like Logger and Compress to be used with constrained type bounds. #1865web::Header extractor for extracting typed HTTP headers in handlers. #2094dev::ServiceRequest::guard_ctx() for obtaining a guard context. #2552dev::ServiceRequest::parts_mut(). #2177dev::ServiceResponse::map_into_{left,right}_body() and HttpResponse::map_into_boxed_body(). #2468Either<web::Json<T>, web::Form<T>>::into_inner() which returns the inner type for whichever variant was created. Also works for Either<web::Form<T>, web::Json<T>>. #1894http::header::AcceptLanguage::{ranked, preference}(). #2480HttpResponse::add_removal_cookie(). #2586HttpResponse::map_into_{left,right}_body() and HttpResponse::map_into_boxed_body(). #2468HttpServer::worker_max_blocking_threads for setting block thread pool. #2200middleware::Logger::log_target() to allow customize. #2594Responder::customize() trait method that wraps responder in CustomizeResponder. #2510Route::service() for using hand-written services as handlers. #2262ServiceResponse::into_parts(). #2499TestServer::client_headers() method. #2097web::ServiceConfig::configure() to allow easy nesting of configuration functions. #1988#[actix_web::test] macro for setting up tests with a runtime. #2409App #1933services! macro for helping register multiple services to App. #1933Json extractor to work without a Content-Type header present. #2362HttpServer::on_connect callback is now accessible only from the new HttpRequest::conn_data() and ServiceRequest::conn_data() methods. #2491guard::fn_guard functions now receives a &GuardContext. #2552guard::Not is now generic over the type of guard it wraps. #2552test::{call_service, read_response, read_response_json, send_request}() now receive a &Service. #1905impl Guard and their concrete types are made private: guard::Header and all the method guards. #2552test::{default_service => status_service}(). Old name is deprecated. #2518test::{read_response_json => call_and_read_body_json}(). Old name is deprecated. #2518test::{read_response => call_and_read_body}(). Old name is deprecated. #2518App's B (body) type parameter been removed. As a result, Apps can be returned from functions now. #2493Compress middleware's response type is now EitherBody<Encoder<B>>. #2448error::BlockingError is now a unit struct. It's now only triggered when blocking thread pool has shutdown. #1957ErrorHandlerResponse's response variants now use ServiceResponse<EitherBody<B>>. #2515ErrorHandlers middleware's response types now use ServiceResponse<EitherBody<B>>. #2515http::header::Encoding now only represents Content-Encoding types. #2501middleware::Condition gained a broader middleware compatibility. #2635Resource no longer require service body type to be boxed. #2526Scope no longer require service body type to be boxed. #2523web::Paths inner field is now private. #1894web::Payload's inner field is now private. #2384#[non_exhaustive]. #2148App::data() is deprecated; App::app_data() should be preferred. #2271dev::JsonBody::new() returns a default limit of 32kB to be consistent with JsonConfig and the default behaviour of the web::Json<T> extractor. #2010dev::ServiceRequest::{into_parts, from_parts}() can no longer fail. #1893dev::ServiceRequest::from_request can no longer fail. #1893dev::ServiceResponse::error_response() now uses body type of BoxBody. #2201dev::ServiceResponse::map_body() closure receives and returns B instead of ResponseBody<B>. #2201http::header::ContentType::html() now produces text/html; charset=utf-8 instead of text/html. #2423HttpRequest::url_for's constructed URLs no longer contain query or fragment. #2430HttpResponseBuilder::json() can now receive data by value and reference. #1903HttpServer::{listen_rustls, bind_rustls}() now honor the ALPN protocols in the configuration parameter. [#2226]middleware::NormalizePath() now will not try to normalize URIs with no valid path #2246test::TestRequest::param() now accepts more than just static strings. #2172web::Data::into_inner() and Data::get_ref() no longer require T: Sized. #2403HttpServer::{client_timeout => client_request_timeout}(). #2611HttpServer::{client_shutdown => client_disconnect_timeout}(). #2611http::header::Accept::{mime_precedence => ranked}(). #2480http::header::Accept::{mime_preference => preference}(). #2480middleware::DefaultHeaders::{content_type => add_content_type}(). #1875dev::ConnectionInfo::{remote_addr => peer_addr}, deprecating the old name. #2554HttpResponse can now be used as a Responder with any body type. #2567TrailingSlash behavior is now Trim, in line with existing documentation. See migration guide for implications. #1875Result extractor wrapper can now convert error types. #2581406 Not Acceptable when no content encoding is acceptable to the client. #2344Into<Error> to Into<Response<BoxBody>>. #2253Into<Error> to Into<Box<dyn std::error::Error>>. #2253dev::ConnectionInfo extractor. #2282FromRequest implementation for Option and Result have changed. #2581error to debug for the log line that is emitted when a 500 Internal Server Error is built using HttpResponse::from_error. #2201Compress middleware. #2501App::data() with the same type now keeps the latest call's data. #1906dev::ConnectionInfo::peer_addr will no longer return the port number. #2554dev::ConnectionInfo::realip_remote_addr will no longer return the port number if sourcing the IP from the peer's socket address. #2554* items in AcceptLanguage. #2480Unpin bound on S (stream) parameter of HttpResponseBuilder::streaming. #2448http::header::AcceptEncoding typed header. #2344middleware::Logger format is escaped correctly. #2067test::read_body_json's panic message. #1812cookie upgrade addresses RUSTSEC-2020-0071.compress feature. #2065BodyEncoding; signalling content encoding is now only done via the Content-Encoding header. #2565dev::{BodySize, MessageBody, SizedStream} re-exports; they are exposed through the body module. #2468EitherExtractError direct export. #2510rt::{Arbiter, ArbiterHandle} re-exports. #2619test::TestServer; moved to new actix-test crate. #2112test::TestServerConfig; moved to new actix-test crate. #2112web::HttpRequest re-export. #2663web::HttpResponse re-export. #2663AppService::set_service_data; for custom HTTP service factories adding application data, use the layered data model by calling ServiceRequest::add_data_container when handling requests instead. #1906dev::ConnectionInfo::get. #2487dev::ServiceResponse::checked_expr. #2401HttpRequestBuilder::del_cookie. #2591HttpResponse::take_body and old HttpResponse::into_body method that casted body type. #2201HttpResponseBuilder::json2(). #1903middleware::Compress::new; restricting compression algorithm is done through feature flags. #2501test::TestRequest::with_header(); use test::TestRequest::default().insert_header(). #1869client module was removed; use the awc crate directly. 871ca5e4middleware::{normalize, err_handlers} modules; all necessary middleware types are now exposed in the middleware module.<details> <summary>4.0.0 Pre-Releases</summary>
middleware::Condition gained a broader compatibility; Compat is needed in fewer cases. [#2635]
On-by-default macros feature flag to enable routing and runtime macros. [#2619]
Rename HttpServer::{client_timeout => client_request_timeout}. [#2611]
HttpResponse::add_removal_cookie. [#2586]
ServiceConfig::configure to allow easy nesting of configuration functions. [#1988]
GuardContext::header #2569ServiceConfig::configure to allow easy nesting of configuration functions. #1988HttpResponse can now be used as a Responder with any body type. #2567Result extractor wrapper can now convert error types. #2581FromRequest impl for Option and Result has changed. #2581<B as MessageBody>::Error: Debug in test utility functions in order to support returning opaque apps. #2584impl Hash for http::Encoding. [#2501]
AcceptEncoding::preference now returns Option<Preference<Encoding>>. #2501BodyEncoding::{encoding => encode_with, get_encoding => preferred_encoding}. #2501http::header::Encoding now only represents Content-Encoding types. #2501Compress middleware. #2501Update cookie dependency (re-exported) to 0.16. [#2555]
cookie dependency (re-exported) to 0.16. #2555cookie upgrade addresses RUSTSEC-2020-0071.Rename ConnectionInfo::{remote_addr => peer_addr}, deprecating the old name. [#2554]
guard::GuardContext for use with the Guard trait. #2552ServiceRequest::guard_ctx for obtaining a guard context. #2552Guard trait now receives a &GuardContext. #2552guard::fn_guard functions now receives a &GuardContext. #2552impl Guard and their concrete types are made private: guard::Header and all the method guards. #2552Not guard is now generic over the type of guard it wraps. #2552No longer require Scope service body type to be boxed. [#2523]
Align DefaultHeader method terminology, deprecating previous methods. [#2510]
Responder trait (customize) for customizing responders and CustomizeResponder struct. #2510Debug for DefaultHeaders. #2510DefaultHeader method terminology, deprecating previous methods. #2510ErrorHandlers middleware now use ServiceResponse<EitherBody<B>> to allow changing the body type. #2515ErrorHandlerResponse now use ServiceResponse<EitherBody<B>>. #2515test::{default_service => simple_service}. Old name is deprecated. #2518test::{read_response_json => call_and_read_body_json}. Old name is deprecated. #2518test::{read_response => call_and_read_body}. Old name is deprecated. #2518Un-deprecate App::data_factory. [#2484]
AcceptLanguage: ranked and preference. #2480AcceptEncoding typed header. #2482Range typed header. #2485HttpResponse::map_into_{left,right}_body and HttpResponse::map_into_boxed_body. #2468ServiceResponse::map_into_{left,right}_body and HttpResponse::map_into_boxed_body. #2468HttpServer::on_connect callback is now accessible only from the new HttpRequest::conn_data() and ServiceRequest::conn_data() methods. #2491HttpRequest::{req_data,req_data_mut}. #2487ServiceResponse::into_parts. #2499Accept::{mime_precedence => ranked}. #2480Accept::{mime_preference => preference}. #2480App::data_factory. #2484HttpRequest::url_for no longer constructs URLs with query or fragment components. #2430B (body) type parameter on App. #2493B (body) type parameter on Scope. #2492RequestHead. Instead it is a distinct part of a Request. #2487* items in AcceptLanguage. #2480dev::{BodySize, MessageBody, SizedStream}. They are exposed through the body module. #2468ConnectionInfo::get. #2487Update actix-tls to 3.0.0-rc.1. [#2474]
actix-tls to 3.0.0-rc.1. #2474Compress middleware's response type is now AnyBody >. [#2448]
Re-export dev::ServerHandle from actix-server. [#2442]
Option to allow Json extractor to work without a Content-Type header present. [#2362]
Json extractor to work without a Content-Type header present. #2362#[actix_web::test] macro for setting up tests with a runtime. #2409FromRequest::Config was removed. #2233web::Payload. #2384Data::into_inner and Data::get_ref no longer requires T: Sized. #2403ServiceResponse::checked_expr method. #2401Re-export actix-service ServiceFactory in dev module. [#2325]
ServiceFactory in dev module. #2325BaseHttpResponse to dev::Response. #2379TestRequest::param to accept more than just static strings. #2172Deprecate App::data and App::data_factory. [#2271]
ServiceRequest::parts_mut. #2177Uri and Method. #2263ConnectionInfo and PeerAddr. #2263Route::service for using hand-written services as handlers. #2262App::data and App::data_factory. #2271ConnectionInfo parts. #2282HttpServer::worker_max_blocking_threads for setting block thread pool. [#2200]
HttpServer::worker_max_blocking_threads for setting block thread pool. #2200JsonPayloadError::Overflow error variant. #2162ServiceResponse::error_response now uses body type of Body. #2201ServiceResponse::checked_expr now returns a Result. #2201language-tags to 0.3.ServiceResponse::take_body. #2201ServiceResponse::map_body closure receives and returns B instead of ResponseBody<B> types. #2201Into<Error> to Into<Response<AnyBody>>. #2253Into<Error> to Into<Box<dyn std::error::Error>>. #2253HttpServer::{listen_rustls(), bind_rustls()} now honor the ALPN protocols in the configuration parameter. [#2226]middleware::normalize now will not try to normalize URIs with no valid path #2246HttpResponse::take_body and old HttpResponse::into_body method that casted body type. #2201HttpResponse and HttpResponseBuilder types. [#2065]
Header extractor for extracting common HTTP headers in handlers. [#2094]
Header extractor for extracting common HTTP headers in handlers. #2094TestServer::client_headers method. #2097CustomResponder would return error as HttpResponse when CustomResponder::with_header failed instead of skipping. (Only the first error is kept when multiple error occur) #2093Feature cookies is now optional and enabled by default. [#1981]
Update actix-web-codegen to 0.5.0-beta.1.
actix-web-codegen to 0.5.0-beta.1.The method Either , web::Form >::into_inner() which returns the inner type for whichever variant was created. Also works for Either , web::Json >. [#1
Either<web::Json<T>, web::Form<T>>::into_inner() which returns the inner type for whichever variant was created. Also works for Either<web::Form<T>, web::Json<T>>. #1894services! macro for helping register multiple services to App. #1933App #1933Responder trait to be sync and returns Response/HttpResponse directly. Making it simpler and more performant. #1891ServiceRequest::into_parts and ServiceRequest::from_parts can no longer fail. #1893ServiceRequest::from_request can no longer fail. #1893Either type now uses Left/Right variants (instead of A/B) #1894test::{call_service, read_response, read_response_json, send_request} take &Service in argument #1905App::wrap_fn, Resource::wrap_fn and Scope::wrap_fn provide &Service in closure argument. #1905web::block no longer requires the output is a Result. #1957App::data with the same type now keeps the latest call's data. #1906web::Path has been made private. #1894web::Query has been made private. #1894TestRequest::with_header; use TestRequest::default().insert_header(). #1869AppService::set_service_data; for custom HTTP service factories adding application data, use the layered data model by calling ServiceRequest::add_data_container when handling requests instead. #1906Compat middleware enabling generic response body/error type of middlewares like Logger and Compress to be used in middleware::Condition and Resource,
Compat middleware enabling generic response body/error type of middlewares like Logger and Compress to be used in middleware::Condition and Resource, Scope services. #1865actix-* dependencies to tokio 1.0 based versions. #1813rand to 0.8.rust-tls to 0.19. #1813Handler to HandlerService and rename Factory to Handler. #1852TrailingSlash is now Trim, in line with existing documentation. See migration guide for implications. #1875DefaultHeaders::{content_type => add_content_type}. #1875test::read_body_json's panic message. #1812middleware::{normalize, err_handlers}. All necessary middleware types are now exposed directly by the middleware module.actix-threadpool as dependency. actix_threadpool::BlockingError error type can be imported from actix_web::error module. #1878</details>
Soft-deprecate NormalizePath::default(), noting upcoming behavior change in v4. [#2529]
NormalizePath::default(), noting upcoming behavior change in v4. #2529Removed an occasional unwrap on None panic in NormalizePathNormalization. [#1762]
Ensure actix-http dependency uses same serde_urlencoded.
actix-http dependency uses same serde_urlencoded.Remove unused direct actix-tls dependency.
actix-tls dependency.Implement exclude_regex for Logger middleware. [#1723]
exclude_regex for Logger middleware. #1723web::ReqData. #1748app_data to ServiceConfig. #1757on_connect for access to the connection stream before request is handled. #1754time dependency.Add TrailingSlash::MergeOnly behaviour to NormalizePath, which allows NormalizePath to retain any trailing slashes. [#1695]
TrailingSlash::MergeOnly behaviour to NormalizePath, which allows NormalizePath to retain any trailing slashes. #1695std::marker::Sized from web::Data to support storing Arc<dyn Trait> via web::Data::from #1710ResourceMap debug printing is no longer infinitely recursive. #1708NormalizePath when used with TrailingSlash::Trim no longer trims the root path "/". [#1678]
NormalizePath when used with TrailingSlash::Trim no longer trims the root path "/". #1678middleware::TrailingSlash enum is now accessible. [#1673]
middleware::normalize::TrailingSlash enum is now accessible. #1673No significant changes from 3.0.0-beta.4.
3.0.0-beta.4.TestServer::stop is now async and will wait for the server and system to shutdown. #2442TestServer::client_headers method. #2097actix-server dependency to 2.actix-tls dependency to 3.bytes to 1.0. #1813<details> <summary>3.0.0 Pre-Releases</summary>
middleware::NormalizePath now has configurable behavior for either always having a trailing slash, or as the new addition, always trimming trailing sl
middleware::NormalizePath now has configurable behavior for either always having a trailing slash, or as the new addition, always trimming trailing slashes. #1639FormConfig and JsonConfig configurations are now also considered when set using App::data. #1641HttpServer::maxconn is renamed to the more expressive HttpServer::max_connections. #1655HttpServer::maxconnrate is renamed to the more expressive HttpServer::max_connection_rate. #1655### Changed - Update rustls to 0.18
Your coding agent can read these notes before it upgrades. Set up the MCP server →