Skip to content
CAI
Software that uses CAICheck a score

tornadoweb/tornado

65.7

Adequate · 19 September 2026

43.9k

lines of production code

Python

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the Tornado asynchronous web framework, providing a high-performance HTTP server and client with support for long-polling, WebSockets, and TCP connections. It includes a suite of demonstration applications that illustrate core features such as authentication, file uploads, and real-time messaging using modern Python async patterns. The project also maintains extensive tooling for development, testing, and cross-platform compatibility, including Docker deployments, Vagrant environments, and automated linting and type-checking workflows.

How it got here

2009 — Demo modernization and tooling overhaul

11 changes.

This period focused on modernizing the project's development infrastructure by standardizing tooling, linting, and CI/CD configurations. Concurrently, all demo applications were updated to use HTML5, async/await patterns, and modern APIs, while also addressing security vulnerabilities and adding static assets.

2010–2012 — asyncio integration and testing infrastructure

12 changes.

This period focused on integrating Tornado with Python's standard asyncio library and external ecosystems like Twisted and c-ares, while expanding the project's test coverage. Significant effort was dedicated to establishing robust local development environments through Vagrant configurations and adding comprehensive conformance tests for WebSocket and HTTP protocols.

2013–2023 — Testing infrastructure and demo expansion

10 changes.

This period focused on enhancing development workflows by adding Vagrant environments for Windows and Ubuntu, alongside comprehensive test suites for Cython compatibility and mypy type checking. The project also expanded its educational resources with new demos for asyncio queues, TCP echo, file uploads, and Google OAuth, while reorganizing benchmarking tools for better maintenance.

Features

Add Google OAuth demo application

A new demo application has been added to the demos/google\_auth directory to demonstrate the usage of Tornado's GoogleOAuth2Mixin. This example app implements a complete authentication flow, including login, logout, and user info retrieval via Google's OAuth2 API, and can be run locally on port 8888 with appropriate OAuth credentials.

_demos/google\auth · high confidence

Add TCP echo demo

A new demo has been added to the \demos/tcpecho\ directory that demonstrates Tornado's asynchronous TCP client and server capabilities. The package includes a server (\server.py\) that listens on a configurable TCP port (default 9888) and echoes back received data, and a client (\client.py\) that connects to the server, sends a message, and prints the response. The demo also includes a README with instructions for running the server and client, as well as connecting via telnet.

demos/tcpecho · high confidence

Add Ubuntu 12.04 development environment configuration

A new Vagrant configuration for Ubuntu 12.04 (Precise Pangolin) has been added to the maint/vm directory, allowing developers to spin up a consistent virtual machine for testing. The setup script installs Python 2.7 and 3.5 via the deadsnakes PPA, along with necessary system libraries (libcurl4-openssl-dev) and Python packages (futures, pycurl, tox, twisted, virtualenv). A corresponding tox.ini file defines test environments for Python 2.7, including configurations for standard, select-based, and Twisted-based I/O loops.

maint/vm/ubuntu12.04 · high confidence

Add Vagrant VM setup scripts and documentation for local testing

New scripts and documentation have been added to the maint/vm directory to facilitate testing Tornado using Vagrant and VirtualBox. The setup includes a shared provisioning script that links the tox configuration into the user's home directory for immediate use after SSH, and a README explaining the requirements and usage, including a note about using NFS shared folders to support hard links.

maint/vm · high confidence

Add Vagrant-managed FreeBSD VM configuration for testing

Developers can now spin up a FreeBSD 10.0 virtual machine using Vagrant to run the project's test suite. The new configuration in maint/vm/freebsd sets up a private network, shares the project directory via NFS, and provisions the environment with Python 2.7 and 3.4, along with necessary dependencies like futures, pycurl, and tox, enabling local FreeBSD-specific testing.

maint/vm/freebsd · high confidence

Add WebSocket chat demo with HTML5 templates and jQuery 3.1.0

A new WebSocket chat demonstration is introduced, featuring HTML5-based templates for the chat interface and message rendering. The demo utilizes jQuery 3.1.0 for client-side interactions and includes CSRF protection via the XSRF form helper. Users can now test real-time messaging capabilities through this new sample application.

demos/websocket/templates · high confidence

Add WebSocket chat demo with static assets

The WebSocket chat demo now includes its necessary static frontend assets, specifically the CSS styles (chat.css) and the client-side JavaScript logic (chat.js). These files provide the user interface and the WebSocket connection handling for the demo, enabling users to test real-time messaging functionality directly in the browser.

demos/websocket/static · high confidence

Add Windows VM bootstrap script and tox configuration

A new bootstrap script and tox configuration have been added to the maint/vm/windows directory to simplify setting up a Windows environment for testing. The bootstrap script automates the installation of Python 2.7 and Python 3.6, along with necessary testing dependencies like tox and virtualenv, on Windows VMs. The tox.ini file defines test environments for Python 2.7 and 3.6, allowing developers to run the full test suite or specific configurations (such as monotonic time tests) consistently across Windows setups.

maint/vm/windows · high confidence

Add asyncio-based Hello World demo

A new Hello World demo has been added to the demos directory, demonstrating how to run a Tornado web server using the modern asyncio.run pattern instead of the traditional IOLoop.start approach.

demos/helloworld · high confidence

Add chat demo static assets

The chat demo now includes its client-side styling and logic, provided by the new chat.css and chat.js files in the static directory. These assets define the visual layout for the chat interface and implement the client-side behavior for sending messages, polling for updates, and displaying new messages in the inbox.

demos/chat/static · high confidence

Add file upload and receive demo scripts

Added two new Python scripts to the demos/file\_upload directory: file\_uploader.py, which demonstrates uploading files via multipart-form-encoded POST or raw PUT requests using Tornado's async HTTP client, and file\_receiver.py, which provides a corresponding server implementation to handle these uploads. The demo uses modern asyncio patterns (async/await, asyncio.run) and supports streaming large files efficiently.

_demos/file\upload · high confidence

Add web spider demo to demonstrate asyncio queues

A new webspider demo has been added to the demos directory. It demonstrates how to use asyncio queues to concurrently fetch and parse links from a website, handling dead links and unicode errors gracefully. The script uses Tornado's HTTP client and queue primitives to manage concurrent URL fetching.

demos/webspider · high confidence

Added Ubuntu 14.04 Vagrant development environment

A new Vagrant configuration for Ubuntu 14.04 (Trusty) has been added to the maint/vm directory, providing a ready-to-use virtual machine for development and testing. The setup includes a Vagrantfile that provisions the ubuntu/trusty64 box with NFS sharing, a shell script that installs necessary system dependencies (such as Python 2.7/3.4, pycurl, and libcurl4-openssl-dev to avoid known deadlock bugs), and a tox.ini file defining test environments for Python 2.7 and 3.4 with specific IOLoop configurations (select, twisted) and pinned dependencies like Twisted 14.0.0.

maint/vm/ubuntu14.04 · high confidence

Added static assets for blog and Facebook demo applications

The blog and Facebook demo applications now include their respective static style sheets (blog.css and facebook.css) to define the visual presentation of the user interfaces. Additionally, a JavaScript file (facebook.js) has been added to the Facebook demo's static directory, replacing a previous README file in that location.

demos/blog/static, demos/facebook/static · high confidence

Blog demo now supports Docker-based deployment

The blog demo now includes a Dockerfile and docker-compose.yml, allowing users to run the application and its PostgreSQL database dependency with a single docker-compose up command. This addition simplifies the setup process by containerizing the Python 3.7 environment and the database service, removing the need for manual local installation of prerequisites beyond Docker itself.

demos/blog · high confidence

New asyncio-based WebSocket chat demo

A new simplified WebSocket chat demo has been added to the demos/websocket directory. It demonstrates modern Tornado usage with asyncio.run, including WebSocket compression support via permessage-deflate, XSRF protection, and template rendering. The demo includes a chat socket handler that maintains a message cache and broadcasts updates to connected clients.

demos/websocket · high confidence

New maintenance scripts for code style, version automation, and resolver testing

Added four new scripts to the maint/scripts directory to support development workflows: run\_autopep8.sh applies code formatting while ignoring specific style rules (W602, E501, E301, E309) to avoid incorrect or ugly fixes; run\_fixers.py provides a 2to3-style interface for running custom Python 2-to-3 fixers; runcog.sh automates the annual update of supported Python versions (11–15) in documentation and build files using the cog tool; and test\_resolvers.py allows developers to manually test DNS resolution across different resolver implementations against real domain names, serving as a temporary tool until the pluggable resolver system is removed in Tornado 7.0.

maint/scripts · high confidence

New platform integration modules for asyncio, c-ares, and Twisted

The tornado.platform package now includes dedicated modules for integrating with external async ecosystems. The new asyncio.py module bridges Tornado with Python's standard asyncio library, automatically managing the event loop and selector thread (particularly for Windows ProactorEventLoop compatibility) while deprecating direct usage of this module as integration is now automatic. A new caresresolver.py module provides a non-blocking, non-threaded DNS resolver using the pycares (c-ares) library, though it is deprecated in favor of the default thread-based resolver. Additionally, twisted.py restores the install() function to configure the AsyncioSelectorReactor for Twisted compatibility and registers a converter for Twisted Deferreds, ensuring seamless interoperability between Tornado Futures and Twisted Deferreds.

tornado/platform · high confidence

Behavioural changes

Blog demo templates migrated to HTML5 with improved security

The blog demo's HTML templates have been rewritten to use HTML5 standards, including a proper DOCTYPE and charset declaration in the base layout. This change also introduces explicit escaping for user-controlled data (such as the blog title) and implements XSRF protection on all forms (login, create author, compose), addressing previous escaping errors and open redirect vulnerabilities in the demo application.

demos/blog/templates · high confidence

Chat demo rewritten for asyncio and modern Tornado patterns

The chat demo has been updated to use Python's asyncio and Tornado's coroutine-based API instead of the older callback style. It now uses a Condition variable for efficient long-polling message updates and includes an on\_connection\_close hook to properly clean up waiting tasks when clients disconnect. The demo also fixes an open redirect vulnerability in the message posting handler, removes authentication for simplicity, and uses distinct cookie names to avoid conflicts with other demos.

demos/chat · high confidence

Chat demo updated to HTML5 and jQuery 3.1 with improved template rendering

The chat demo templates have been migrated to HTML5, replacing the previous XHTML structure. The main index template now loads jQuery 3.1.0 from Google's CDN and utilizes the new {% module Template %} syntax to render individual messages, passing message data via keyword arguments rather than inheriting the caller's namespace. Additionally, message content is processed through a new linkify() function to automatically convert URLs into clickable links, and the input form is configured to clear upon submission for a smoother user experience.

demos/chat/templates · high confidence

Facebook demo updated to use Graph API and HTML5

The Facebook demo templates have been rewritten to use the Facebook Graph API instead of the legacy API, including specific checks for the presence of 'actions' and 'message' fields in the post data to handle missing information gracefully. The templates also adopt HTML5 standards and utilize the new Post module to render individual stream items.

demos/facebook/templates · high confidence

Facebook demo updated to use the Graph API and async patterns

The Facebook demo application has been migrated from the deprecated legacy API to the Facebook Graph API, requiring users to request the 'user\_posts' scope during authentication. The implementation has also been updated to use modern Python async/await patterns, including the use of \asyncio.run\ for the entry point and asynchronous handlers for login, logout, and stream retrieval.

demos/facebook · high confidence

New benchmarking suite moved to maint/benchmark

The Tornado benchmarking scripts (benchmark.py, chunk\_benchmark.py, gen\_benchmark.py, parsing\_benchmark.py, and template\_benchmark.py) have been relocated from the demos directory to the maint/benchmark directory. This change organizes these performance-testing tools under the maintenance directory, separating them from user-facing demo applications while preserving their functionality for measuring HTTP stack, header parsing, coroutine, and template rendering performance.

maint/benchmark · high confidence

New custom fixers for normalizing future imports and unicode literals

Added new maintenance scripts to automatically standardize Python source code: a fixer that ensures all files import \absolute\_import\, \division\, and \print\function\ from \\\future\\_\, and another that removes redundant \u\ prefixes from unicode string literals.

_maint/scripts/custom\fixers · high confidence

Project infrastructure and development tooling overhaul

This change introduces a comprehensive set of configuration files to standardize the development environment and CI/CD pipeline. It adds \.coveragerc\ for test coverage reporting, \.flake8\ for code linting, and \.gitattributes\ to enforce consistent line endings in test data. The project now uses \tox.ini\ to manage test environments across multiple Python versions (3.11–3.15) and platforms, including specific configurations for documentation builds (\docs\) and linting (\lint\). A new \requirements.in\ file lists development dependencies like \black\, \mypy\, and \sphinx\. Additionally, \setup.py\ is updated to enforce Python 3.11+ support, build wheels with the stable ABI (limited API), and include necessary data files via \MANIFEST.in\. The repository also gains a \SECURITY.md\ policy, a \CONTRIBUTING.md\ guide detailing the use of \black\ and \tox\, and a \runtests.sh\ script for executing the test suite.

(repo-wide) · high confidence

Test coverage

Added Autobahn WebSocket conformance test suite; Added HTTP validation tests using Redbot; Added mypy type-checking tests for Tornado request handlers; Added tests for Cython-compiled coroutines and ArgReplacer compatibility; Extensive test suite updates and maintenance.

Dependencies

Updated build and development dependencies

The project's dependency manifests have been updated to newer versions of key tools. The main requirements.txt now includes black 26.5.1, mypy 2.3.1, flake8 7.3.0, tox 4.61.4, and sphinx 9.0.4, alongside updated transitive dependencies like requests 2.34.2 and urllib3 2.8.0. Additionally, a new requirements.txt for the blog demo specifies aiopg, bcrypt, markdown, psycopg2, and tornado, while pyproject.toml configures cibuildwheel to build wheels for Python 3.11 through 3.15 (including experimental 3.14t).

(dependencies) · high confidence

Housekeeping

Tornado framework version bump to 4.3.dev1

The Tornado web framework version has been updated to 4.3.dev1. This change primarily reflects the internal versioning state of the library and does not introduce new user-facing features or behavioral changes in the provided diff excerpt.

tornado · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 66.

Lenses

  • Code Health 86
  • Architecture 92
  • Maturity 59
  • Readiness 58
  • Security 84

Changes since last survey

  • 300 commits — 268 feature/other, 32 fixes

By area

  • (repo) — 112 commits
  • tornado/test — 53 commits
  • (root) — 30 commits
  • docs/releases — 22 commits
  • tornado/httputil.py — 19 commits
  • .github/workflows — 11 commits
  • tornado/curl_httpclient.py — 7 commits
  • tornado/web.py — 5 commits
  • tornado/auth.py — 4 commits
  • tornado/http1connection.py — 4 commits
  • tornado/gen.py — 3 commits
  • tornado/platform — 3 commits
  • demos/README.rst — 2 commits
  • docs/guide — 2 commits
  • tornado/init.py — 2 commits
  • tornado/concurrent.py — 2 commits
  • tornado/ioloop.py — 2 commits
  • tornado/locks.py — 2 commits
  • .github/zizmor.yml — 1 commit
  • demos/blog — 1 commit

Notable commits

  • fix: *: Remaining pyupgrade 3.8 fixes
  • fix: Fix ValueError in file_uploader.py by converting @gen.coroutine to async/await
  • fix: Fix mypy union-attr error on python 3.13 and newer
  • fix: Fix test_strip_headers_on_redirect's URL-embedded-credentials cases
  • fix: Fix two sources of unexpected log output seen on windows
  • fix: Merge pull request #3474 from bdarnell/fix-build
  • fix: Merge pull request #3519 from bdarnell/fix-host-argument
  • fix: Merge pull request #3523 from killerdevildog/fix-file-uploader-coroutine-issue-3182
  • fix: Merge pull request #3528 from bdarnell/ping-interval-fix
  • fix: Merge pull request #3563 from arnaudsjs/issue/fix-case-insensitivity-in-operator
  • fix: Merge pull request #3582 from charles2910/fix-tests-with-curl-8-19-0
  • fix: Merge pull request #3610 from joegasewicz/fix/Improve-and-update-the-tornado-branding
  • fix: Merge pull request #3620 from mokashang/docs/fix-typos-in-comments-and-docs
  • fix: Merge pull request #3621 from SAY-5/fix-zero-timeout
  • fix: Merge pull request #3624 from mokashang/fix/test-multi-process-thread-leak
  • fix: Merge pull request #3686 from maxtaran2010/fix-typo-afe-in-ioloop
  • fix: Merge pull request #3696 from kobihikri/fix-classifier-commas
  • fix: Revert "ci: Temporarily pin 3.14-alpha.4"
  • fix: build: Fix free-threaded build, mark speedups module as no-GIL
  • fix: curl_httpclient: Fix a streaming stall on older libcurl, and test more
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tornadoweb/tornado was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 85b6917d05a84a6d26b7488b2b56d0b52c107a0f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.