9.1.2 (2026-10-05)
Fixes
Backward incompatibilities
Check if you have changed any of the following allauth settings (usually in cms/settings.py or similar file) :
-
ACCOUNT_EMAIL_REQUIRED, ACCOUNT_USERNAME_REQUIRED and ACCOUNT_SIGNUP_PASSWORD_ENTER_TWICE are replaced by ACCOUNT_SIGNUP_FIELDS. Because settings.py now sets the new option, deployments that override any of the three old ones in local_settings.py lose that override silently and must switch to ACCOUNT_SIGNUP_FIELDS.
-
The new ALLAUTH_TRUSTED_PROXY_COUNT = 1: deployments with another reverse proxy in front of nginx should set it to 2. Otherwise all visitors share one login rate-limit bucket.
-
Login redirects (next=) to other hosts are now ignored unless that host is listed in ALLOWED_HOSTS or CSRF_TRUSTED_ORIGINS.
REST_FRAMEWORK authentication classes are now the cms.authentication.* wrappers. Any local_settings.py that redefines REST_FRAMEWORK must keep them, or approval checks and GLOBAL_LOGIN_REQUIRED no longer apply to the API.