← All tasks
pythonbox/box-python-sdk #869Reported task

Update boxsdk to use requests-toolbelt >= 1.0.0.

envgap__box__box-python-sdk-869

01 / FAILURE SIGNATURE

Captured in a clean container

ImportError: cannot import name 'appengine' from 'requests.packages.urllib3.contrib' (/usr/local/lib/python3.10/dist-packages/urllib3/contrib/__init__.py)

02 / ENVIRONMENT RECIPE

Base commit
8e0d6406f26be87799838b0aa57acd62c79d59a2
Manifest
setup.py
Reproduce
cd /tmp && python3 -c 'from boxsdk import OAuth2,Client,BoxAPIException; from boxsdk.util.multipart_stream import MultipartStream; body=MultipartStream({'"'"'attributes'"'"':'"'"'{\"name\":\"example.txt\"}'"'"'},{'"'"'file'"'"':('"'"'example.txt'"'"',b'"'"'hello'"'"','"'"'text/plain'"'"')}).to_string(); assert b'"'"'hello'"'"' in body and b'"'"'example.txt'"'"' in body; print('"'"'encoded multipart bytes'"'"',len(body))'
Run under trace
cd /tmp && python3 -c 'from boxsdk import OAuth2,Client,BoxAPIException; from boxsdk.util.multipart_stream import MultipartStream; body=MultipartStream({'"'"'attributes'"'"':'"'"'{\"name\":\"example.txt\"}'"'"'},{'"'"'file'"'"':('"'"'example.txt'"'"',b'"'"'hello'"'"','"'"'text/plain'"'"')}).to_string(); assert b'"'"'hello'"'"' in body and b'"'"'example.txt'"'"' in body; print('"'"'encoded multipart bytes'"'"',len(body))'
Reference environment fix used for admission
diff --git a/setup.py b/setup.py
index 5aa00f5..9df99a1 100644
--- a/setup.py
+++ b/setup.py
@@ -56,7 +56,7 @@ def main():
         'attrs>=17.3.0',
         'urllib3',
         'requests>=2.4.3,<3',
-        'requests-toolbelt>=0.4.0',
+        'requests-toolbelt==1.0.0',
         'python-dateutil',  # To be removed after dropping Python 3.6
     ]
     redis_requires = ['redis>=2.10.3']

03 / ORIGINAL ISSUE TEXT

box/box-python-sdk #869 · read the original issue
 Now when I install ```$ pip install -U 'requests-toolbelt>=1'``` I get the following:



- [x] I have checked that the [SDK documentation][sdk-docs] doesn't solve my issue.

- [x] I have checked that the [API documentation][api-docs] doesn't solve my issue.

- [x] I have searched the [Box Developer Forums][dev-forums] and my issue isn't already reported (or if it has been reported, I have attached a link to it, for reference).

- [x] I have searched [Issues in this repo][github-repo] and my issue isn't already reported.



### Description of the Issue

Currently boxsdk uses ```requests-toolbelt>=0.4.0```. During an upgrade of requests-toolbelt to 1.0.0, they removed Google's Engine 'appengine' that was part of their pkg [requests-toolbelt HISTORY](https://github.com/requests/toolbelt/blob/master/HISTORY.rst#100----2023-05-01) and ```urllib3``` also [removed](https://github.com/urllib3/urllib3/issues/2065) ```appengine``` from their package.  When this happened it broke a few dependencies.



### Steps to Reproduce

1. Install a ```venv``` and install requests and boxsdk via pip: ```pip install requests boxsdk```. Doing this installs ```urllib3 2.2.1``` and ```requests 2.31.0```, and ```requests-toolbelt 0.10.1```. 

2. Once that happens and I use my script that uses ```boxsdk 2.10.0``` I get the following error:

```

$ python ./box_upload.py -h 

  Traceback (most recent call last):

    File "/dev/venv/lib/python3.11/site-packages/requests_toolbelt/_compat.py", line 48, in <module>

  from requests.packages.urllib3.contrib import appengine as gaecontrib

  ImportError: cannot import name 'appengine' from 'requests.packages.urllib3.contrib' (/dev/venv/lib/python3.11/site-packages/urllib3/contrib/__init__.py)

  

  During handling of the above exception, another exception occurred:

  

  Traceback (most recent call last):

  File "/dev/box_upload/./box_upload.py", line 10, in <module>

  from boxsdk import OAuth2, Client, BoxAPIException

  File "/dev/venv/lib/python3.11/site-packages/boxsdk/__init__.py", line 5, in <module>

  from .auth import JWTAuth, OAuth2

  File "/dev/venv/lib/python3.11/site-packages/boxsdk/auth/__init__.py", line 5, in <module>

  from .cooperatively_managed_oauth2 import CooperativelyManagedOAuth2

  File "/dev/venv/lib/python3.11/site-packages/boxsdk/auth/cooperatively_managed_oauth2.py", line 4, in <module>

  from .oauth2 import OAuth2

  File "/dev/venv/lib/python3.11/site-packages/boxsdk/auth/oauth2.py", line 20, in <module>

  from ..session.session import Session

  File "/dev/venv/lib/python3.11/site-packages/boxsdk/session/session.py", line 18, in <module>

  from ..util.multipart_stream import MultipartStream

  File "/dev/venv/lib/python3.11/site-packages/boxsdk/util/multipart_stream.py", line 7, in <module>

  from requests_toolbelt.multipart.encoder import MultipartEncoder

  File "/dev/venv/lib/python3.11/site-packages/requests_toolbelt/__init__.py", line 12, in <module>

  from .adapters import SSLAdap
Continue on GitHub ↗

04 / LABELS

Labels checked by running the task · assistant reviewed

misspecificationsecurity
Label rules and the text that matched
[
  {
    "category": "misspecification",
    "rule": "diff.changes_existing_manifest_line",
    "source": "manifest_diff:setup.py",
    "excerpt": "-        'requests-toolbelt>=0.4.0',\n+        'requests-toolbelt==1.0.0',"
  },
  {
    "category": "security",
    "rule": "issue.security_keyword",
    "source": "issue_body",
    "excerpt": "belt>=0.4.0```. During an upgrade of requests-toolbelt to 1.0.0, they removed Google's Engine 'appengine' that was part of their pkg [requests-toolbelt HISTORY](https://github.c"
  }
]

Historical install-only results are not EnvGap validation.

The issue reports boxsdk2.10.0; this instance executes the required dated default-branch source, preserving the same permissive requests-toolbelt requirement and import path rather than replacing it with an older release.

Explicit old toolbelt/requests/urllib3 versions reproduce the reported installed environment; the unchanged permissive manifest retains old toolbelt at baseline.

No Box API calls or credentials are required; the existing MultipartStream encoder processes a real multipart body.

Preparation uses current registries. Historical package availability is not enforced here; execution metadata records this limitation separately from the oracle's date-bounding policy.