ImportError: cannot import name 'safe_str_cmp' from 'werkzeug.security'
Fixes ImportError: cannot import name 'safe_str_cmp' from 'werkzeug.security' Use when werkzeug>=2.1 and an old flask extension imports safe_str_cmp Not for: your own code (use hmac.compare_digest directly)
How to fix ImportError: cannot import name 'safestrcmp' from 'werkzeug.security'
Werkzeug 2.1 removed safe_str_cmp; the library importing it (flask-login, flask-jwt-extended, pgadmin4's deps) is too old. Upgrade that library (pip install -U flask-login etc.). Stopgap: pip install "werkzeug<2.1", but that just postpones the upgrade.
The exact error
ImportError: cannot import name 'safe_str_cmp' from 'werkzeug.security'Fix it
- Find the importer from the traceback (e.g. flask_login/utils.py).
Expected: you know which package is stale
pip install -U [that package](flask-login>=0.6.2 fixed it).
Expected: it uses hmac.compare_digest now
- Re-run your app.
Expected: no ImportError
When this applies
werkzeug>=2.1 and an old flask extension imports safestrcmp
When this does NOT apply
your own code (use hmac.compare_digest directly)
Versions
werkzeug >= 2.1 with old flask extensions
Why it happens
Werkzeug removed the helper; its own docs point at hmac.compare_digest.
Edge cases
Pinning werkzeug[2.1 can conflict with Flask]=2.2 requirements; upgrade the extension instead.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.