pypi social-auth-core 4.8.7

9 hours ago

Added

  • OpenID Connect backends can now opt in to PKCE support

Changed

  • PKCE defaults now match RFC 7636 requirements

Security

  • Tightened redirect URL validation
  • Tightened OAuth state handling for Clever, Eventbrite, GoClio, MailChimp, SurveyMonkey and Untappd backends
  • SAML authentication now restores saved sessions only after response validation

Don't miss a new social-auth-core release

NewReleases is sending notifications on new releases.