← All tasks
pythonjpadilla/pyjwt #804Not a task: already works

`crypto` extra requires outdated `types-cryptography` type annotation stubs

envgap__jpadilla__pyjwt-804

01 / FAILURE SIGNATURE

As reported upstream

error: Module "cryptography.hazmat.primitives.ciphers.aead" has no attribute "AESOCB3"
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
1ef6dcfa67744ff69ef1a771465179e31282d5b5
Manifest
setup.cfg
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

jpadilla/pyjwt #804 · read the original issue
Type annotation stub packages are usually only needed for static type analyzers like `mypy`. Type annotations of dependencies might not be useful in any way for the user of this library if it's not necessary to use the dependency directly. Thus, type annotations of dependencies should be always optional, and definitely not included in the `crypto` extra. Also, annotations in `types-cryptography` are outdated or incomplete for the latest version of `cryptography`. This dependency was added in #784.



`cryptography` package has included type annotations which are usable by `mypy` and other tools since [version 3.4.4](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst#344---2021-02-09). [Metadata in the `typeshed` repository](https://github.com/python/typeshed/blob/master/stubs/cryptography/METADATA.toml) also suggests that those annotations are obsolete for `cryptography` versions 3.4.4 and later. For some reason, `mypy` prefers the external stubs over the type information from the source code and gives incorrect output for later versions of `cryptography` when `types-cryptography` is installed. For example, a project could use `cryptography`, and also depend on `pyjwt[crypto]`, in which case `mypy` could give incorrect errors for direct use `cryptography`. Thus, I'd suggest not installing `types-cryptography` unless you're running tests and static type analysis against the oldest supported version of `cryptography`.



## Expected Result



`pip install 'pyjwt[crypto]'` should not install `types-cryptography` and `mypy` should not print any errors for the included code snippet.



## Actual Result

`pip install 'pyjwt[crypto]'` installs `types-cryptography` and prints the following error for the code snippet.

```

error: Module "cryptography.hazmat.primitives.ciphers.aead" has no attribute "AESOCB3"

```



## Reproduction Steps



Install `pyjwt` with `crypto` extra, e.g. `pip install 'pyjwt[crypto]'`, the output should show that `types-cryptography` was installed. Run `mypy` on the following code snippet, which simply imports a cipher that was added in `cryptography` version 36.0:

```python

from cryptography.hazmat.primitives.ciphers.aead import AESOCB3

```



## System Information

```json

{

  "cryptography": {

    "version": "38.0.1"

  },

  "implementation": {

    "name": "CPython",

    "version": "3.10.6"

  },

  "platform": {

    "release": "5.19.7-arch1-1",

    "system": "Linux"

  },

  "pyjwt": {

    "version": "2.5.0"

  }

}

```

Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]