Update boxsdk to use requests-toolbelt >= 1.0.0.
envgap__box__box-python-sdk-869
01 / FAILURE SIGNATURE
Captured in a clean container
ImportError: cannot import name 'appengine' from 'requests.packages.urllib3.contrib' (/usr/local/lib/python3.10/dist-packages/urllib3/contrib/__init__.py)
02 / ENVIRONMENT RECIPE
- Base commit
8e0d6406f26be87799838b0aa57acd62c79d59a2- Manifest
setup.py- Reproduce
cd /tmp && python3 -c 'from boxsdk import OAuth2,Client,BoxAPIException; from boxsdk.util.multipart_stream import MultipartStream; body=MultipartStream({'"'"'attributes'"'"':'"'"'{\"name\":\"example.txt\"}'"'"'},{'"'"'file'"'"':('"'"'example.txt'"'"',b'"'"'hello'"'"','"'"'text/plain'"'"')}).to_string(); assert b'"'"'hello'"'"' in body and b'"'"'example.txt'"'"' in body; print('"'"'encoded multipart bytes'"'"',len(body))'- Run under trace
cd /tmp && python3 -c 'from boxsdk import OAuth2,Client,BoxAPIException; from boxsdk.util.multipart_stream import MultipartStream; body=MultipartStream({'"'"'attributes'"'"':'"'"'{\"name\":\"example.txt\"}'"'"'},{'"'"'file'"'"':('"'"'example.txt'"'"',b'"'"'hello'"'"','"'"'text/plain'"'"')}).to_string(); assert b'"'"'hello'"'"' in body and b'"'"'example.txt'"'"' in body; print('"'"'encoded multipart bytes'"'"',len(body))'
Reference environment fix used for admission
diff --git a/setup.py b/setup.py
index 5aa00f5..9df99a1 100644
--- a/setup.py
+++ b/setup.py
@@ -56,7 +56,7 @@ def main():
'attrs>=17.3.0',
'urllib3',
'requests>=2.4.3,<3',
- 'requests-toolbelt>=0.4.0',
+ 'requests-toolbelt==1.0.0',
'python-dateutil', # To be removed after dropping Python 3.6
]
redis_requires = ['redis>=2.10.3']03 / ORIGINAL ISSUE TEXT
box/box-python-sdk #869 · read the original issue
Now when I install ```$ pip install -U 'requests-toolbelt>=1'``` I get the following:
- [x] I have checked that the [SDK documentation][sdk-docs] doesn't solve my issue.
- [x] I have checked that the [API documentation][api-docs] doesn't solve my issue.
- [x] I have searched the [Box Developer Forums][dev-forums] and my issue isn't already reported (or if it has been reported, I have attached a link to it, for reference).
- [x] I have searched [Issues in this repo][github-repo] and my issue isn't already reported.
### Description of the Issue
Currently boxsdk uses ```requests-toolbelt>=0.4.0```. During an upgrade of requests-toolbelt to 1.0.0, they removed Google's Engine 'appengine' that was part of their pkg [requests-toolbelt HISTORY](https://github.com/requests/toolbelt/blob/master/HISTORY.rst#100----2023-05-01) and ```urllib3``` also [removed](https://github.com/urllib3/urllib3/issues/2065) ```appengine``` from their package. When this happened it broke a few dependencies.
### Steps to Reproduce
1. Install a ```venv``` and install requests and boxsdk via pip: ```pip install requests boxsdk```. Doing this installs ```urllib3 2.2.1``` and ```requests 2.31.0```, and ```requests-toolbelt 0.10.1```.
2. Once that happens and I use my script that uses ```boxsdk 2.10.0``` I get the following error:
```
$ python ./box_upload.py -h
Traceback (most recent call last):
File "/dev/venv/lib/python3.11/site-packages/requests_toolbelt/_compat.py", line 48, in <module>
from requests.packages.urllib3.contrib import appengine as gaecontrib
ImportError: cannot import name 'appengine' from 'requests.packages.urllib3.contrib' (/dev/venv/lib/python3.11/site-packages/urllib3/contrib/__init__.py)
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "/dev/box_upload/./box_upload.py", line 10, in <module>
from boxsdk import OAuth2, Client, BoxAPIException
File "/dev/venv/lib/python3.11/site-packages/boxsdk/__init__.py", line 5, in <module>
from .auth import JWTAuth, OAuth2
File "/dev/venv/lib/python3.11/site-packages/boxsdk/auth/__init__.py", line 5, in <module>
from .cooperatively_managed_oauth2 import CooperativelyManagedOAuth2
File "/dev/venv/lib/python3.11/site-packages/boxsdk/auth/cooperatively_managed_oauth2.py", line 4, in <module>
from .oauth2 import OAuth2
File "/dev/venv/lib/python3.11/site-packages/boxsdk/auth/oauth2.py", line 20, in <module>
from ..session.session import Session
File "/dev/venv/lib/python3.11/site-packages/boxsdk/session/session.py", line 18, in <module>
from ..util.multipart_stream import MultipartStream
File "/dev/venv/lib/python3.11/site-packages/boxsdk/util/multipart_stream.py", line 7, in <module>
from requests_toolbelt.multipart.encoder import MultipartEncoder
File "/dev/venv/lib/python3.11/site-packages/requests_toolbelt/__init__.py", line 12, in <module>
from .adapters import SSLAdap04 / LABELS
Labels checked by running the task · assistant reviewed
misspecificationsecurityLabel rules and the text that matched
[
{
"category": "misspecification",
"rule": "diff.changes_existing_manifest_line",
"source": "manifest_diff:setup.py",
"excerpt": "- 'requests-toolbelt>=0.4.0',\n+ 'requests-toolbelt==1.0.0',"
},
{
"category": "security",
"rule": "issue.security_keyword",
"source": "issue_body",
"excerpt": "belt>=0.4.0```. During an upgrade of requests-toolbelt to 1.0.0, they removed Google's Engine 'appengine' that was part of their pkg [requests-toolbelt HISTORY](https://github.c"
}
]Historical install-only results are not EnvGap validation.
The issue reports boxsdk2.10.0; this instance executes the required dated default-branch source, preserving the same permissive requests-toolbelt requirement and import path rather than replacing it with an older release.
Explicit old toolbelt/requests/urllib3 versions reproduce the reported installed environment; the unchanged permissive manifest retains old toolbelt at baseline.
No Box API calls or credentials are required; the existing MultipartStream encoder processes a real multipart body.
Preparation uses current registries. Historical package availability is not enforced here; execution metadata records this limitation separately from the oracle's date-bounding policy.