Added
-
Association.cleanup_expired()removes expired OpenID associations and OIDC
nonces. Theclearsocialcommand now includes this cleanup independently of
its--ageoption. Existing undated OIDC nonces receive a 30-minute grace
period during migration. -
Strategy-based, opt-in synchronization of external memberships to existing
Django groups using backend-scopedGROUPS_MAPconfiguration. -
Render an overridable authentication error page with an appropriate HTTP status
when exception middleware is installed withoutSOCIAL_AUTH_LOGIN_ERROR_URL. -
Opt-in
SOCIAL_AUTH_ERROR_INCLUDE_METADATAfor safe code/source/stage/recovery
fields in error redirects, including message-storage fallback. -
Backend display metadata in the
backends.metadatatemplate context and
social_django.finders.SocialAuthIconFinderfor social-core's bundled SVGs.
Register the finder after Django's standard finders to collect the icons.
Breaking
- Use the structured exception contract from social-auth-core 6. Removed
specialized exception classes must be migrated. Only recognized identifier
uniqueness failures become account conflicts; other integrity failures propagate.
Detection uses cheap driver diagnostics and model metadata without database
introspection. - Require social-auth-core 6.x and migrate custom strategy overrides from
request_data()toget_request_data(). - Pipeline steps no longer receive a Django request argument. Use
strategy.requestfor the HTTP request andstrategy.request_data()for
effective pipeline parameters, including replayed external-link data. - Custom exception middleware overrides of
dispatch_error()and
append_query_params()must accept the keyword-onlymetadataargument.
Security
- Support upstream email-validation code expiry using the existing creation
timestamp, including deployments withUSE_TZ=False. No migration is needed. - Added identifier-key metadata and atomic identifier migration for social
associations, supporting migration away from mutable provider identifiers.
Fixed
- Explicitly package runtime modules, templates, and typing metadata in wheels;
retain tests only in source distributions for downstream testing. - Preserve email verification data when resuming a confirmed partial pipeline
while keeping the native HTTP request available to Django authentication. - Preserve concrete social-auth model types in inherited manager operations.
- Preserve hyphenated UUID usernames for user models with a
UUIDFieldusername,
including Cognito users. - Preserve tracebacks in logs for server errors rendered by the exception
middleware.