Added
- Added a CESID AAI OpenID Connect backend.
- Added an optional
userargument todo_auth()and aBaseAuth.prepare_auth()
hook for backend-specific authentication initiation.
Security
- Twilio Connect is now association-only: starting and completing a connection
requires the same authenticated local user. Twilio callback data can no
longer create or authenticate users. - Facebook App authentication now binds access-token and signed-request
callbacks to the browser session, preventing login CSRF and unauthorized
account linking. Custom Facebook App templates must preserve the query string
inFACEBOOK_COMPLETE_URIwhen submitting the callback. - Weixin app authentication now validates OAuth state before exchanging codes,
preventing login CSRF and unauthorized account linking. - Last.fm authentication now binds callbacks to the browser session that
initiated the login, preventing login CSRF and unauthorized account linking. - GitHub App authentication now validates OAuth state before exchanging codes.
Stateless installation callbacks restart a state-protected OAuth flow,
preventing forged installation parameters from enabling login CSRF. - VK OpenAPI authentication now uses the signed session's user ID instead of
trusting the ID supplied in callback data.
Changed
- Updated development dependencies and CI actions.
- Allowed newer Google Auth versions for the Google One Tap backend.