pypi social-auth-core 5.2.0

4 hours ago

Added

  • Added a CESID AAI OpenID Connect backend.
  • Added an optional user argument to do_auth() and a BaseAuth.prepare_auth()
    hook for backend-specific authentication initiation.

Security

  • Twilio Connect is now association-only: starting and completing a connection
    requires the same authenticated local user. Twilio callback data can no
    longer create or authenticate users.
  • Facebook App authentication now binds access-token and signed-request
    callbacks to the browser session, preventing login CSRF and unauthorized
    account linking. Custom Facebook App templates must preserve the query string
    in FACEBOOK_COMPLETE_URI when submitting the callback.
  • Weixin app authentication now validates OAuth state before exchanging codes,
    preventing login CSRF and unauthorized account linking.
  • Last.fm authentication now binds callbacks to the browser session that
    initiated the login, preventing login CSRF and unauthorized account linking.
  • GitHub App authentication now validates OAuth state before exchanging codes.
    Stateless installation callbacks restart a state-protected OAuth flow,
    preventing forged installation parameters from enabling login CSRF.
  • VK OpenAPI authentication now uses the signed session's user ID instead of
    trusting the ID supplied in callback data.

Changed

  • Updated development dependencies and CI actions.
  • Allowed newer Google Auth versions for the Google One Tap backend.

Don't miss a new social-auth-core release

NewReleases is sending notifications on new releases.