Where: src/dispatch.rs:350, 598, 1295, 1592.
Registering CORS via apply_cors installs a request middleware, which unconditionally disables try_rsgi_sync_short_circuit for every request on the app (dispatch.rs:350 bails to the full async path whenever request_middleware is non-empty), even for routes that don't need it. On top of that, every response header merge for CORS/security-headers calls back into Python (response_header_pairs) and copies the body through into_vec.
Fix direction: compile CORSConfig/SecurityHeadersConfig into native Rust structs at set_cors/set_security_headers time so header merging and CORS preflight can happen without a Python call, and stop routing all requests through the async path just because middleware exists — only requests actually needing middleware should skip the fast path.
Where:
src/dispatch.rs:350,598,1295,1592.Registering CORS via
apply_corsinstalls a request middleware, which unconditionally disablestry_rsgi_sync_short_circuitfor every request on the app (dispatch.rs:350bails to the full async path wheneverrequest_middlewareis non-empty), even for routes that don't need it. On top of that, every response header merge for CORS/security-headers calls back into Python (response_header_pairs) and copies the body throughinto_vec.Fix direction: compile
CORSConfig/SecurityHeadersConfiginto native Rust structs atset_cors/set_security_headerstime so header merging and CORS preflight can happen without a Python call, and stop routing all requests through the async path just because middleware exists — only requests actually needing middleware should skip the fast path.