pypi social-auth-core 6.0.0

3 hours ago

Security

  • OpenID Connect nonces expire after 30 minutes by default. Configure
    SOCIAL_AUTH_<BACKEND>_NONCE_LIFETIME to change the duration. Storage
    integrations must persist issued and lifetime; stored nonces without
    a valid lifetime are rejected.
  • LinkedIn OpenID Connect no longer stores unused nonces.
  • Backend signatures, hashes, and CSRF tokens use constant-time comparisons.
    Malformed signatures, including non-ASCII Discourse signatures, raise
    authentication errors instead of type errors.
  • Facebook Limited Login reuses validated claims only during a saved partial
    pipeline resume, preventing forged resumes from authenticating a previous user.
  • Google OAuth2 and Google OpenID Connect now reject UserInfo responses that do
    not explicitly confirm email verification. Google One Tap requires the same
    confirmation in its ID token.
  • Email validation codes expire after seven days by default. Configure
    SOCIAL_AUTH_EMAIL_VALIDATION_EXPIRED_THRESHOLD to change their lifetime.
    Storage integrations must persist each code's creation timestamp; undated
    codes are rejected when expiry is enabled.
  • Tumblr, Deezer, Discourse, SciStarter, Okta, Google, Trello, Qiita, Keycloak,
    Fence, CAS, Cognito, Dailymotion, Mail.ru, ArcGIS, Ubuntu, openSUSE, Yandex,
    and affected Microsoft Entra ID backends now bind accounts to stable provider
    or protocol identifiers. Existing associations record their identifier key
    and migrate on authentication; strict deployments can disable unverified
    legacy-identifier migration with
    SOCIAL_AUTH_<BACKEND>_ALLOW_UNVERIFIED_LEGACY_UID_MIGRATION.
  • Drip, Last.fm, and Mixcloud are now association-only: connecting requires the
    same authenticated local user at initiation, callback, and partial resumption.
    Mutable provider identifiers can no longer create or authenticate local users,
    and connecting preserves local profile fields.

Breaking

  • Name normalization now runs in the shared authentication pipeline. Custom
    pipelines must add social_core.pipeline.social_auth.social_names immediately
    after social_core.pipeline.social_auth.social_details to retain automatic
    conversion between full names and first/last names.
  • Storage integrations must persist association id_key values, accept id_key
    in get_social_auth() and create_social_auth(), and implement
    get_social_auth_by_extra_data() and atomic migrate_social_auth().
    Existing associations use an empty identifier key until migration.
  • Token renewal raises AuthCredentialError with reauthentication_required
    when a stored access token is expired and no renewal credential is available.
    Custom backends that exchange access tokens must override get_refresh_token().
  • MediaWiki and Discourse groups are exposed separately from profile details.
    Enable group extraction and update custom pipeline consumers to use groups
    instead of details["groups"]. MediaWiki identity retrieval now runs in
    user_data() rather than get_user_details().
  • Authentication exceptions now expose stable reason codes, failure sources,
    operation stages, and suggested recovery. Only SocialAuthBaseException and
    AuthException retain broad catch compatibility; migrate removed specialized
    classes using the exception reference in social-docs.
  • HTTP failures no longer infer cancellation from HTTP 400 or token expiry from
    HTTP 401. Provider diagnostics are separate from safe exception messages.
  • Strategies must implement get_request_data() instead of overriding
    request_data(). The latter now returns effective data for the active partial
    pipeline, including confirmed external-link data.
  • Pipeline steps no longer receive an automatic request argument. Use
    strategy.request_data() for parameters and the framework strategy's
    request attribute for its native request object.
  • Legacy disconnect partials without a pipeline type must restart the disconnect
    flow. Legacy authentication partials remain resumable.

Added

  • Configurable external group extraction and login allow lists for Azure, OIDC,
    Keycloak, Okta OAuth2, SAML, GitLab, MediaWiki, and Discourse, with a strategy
    hook and optional pipeline step for local group synchronization. Existing CAS
    allow lists continue to work without pipeline changes.
  • Human-readable title and optional icon metadata for authentication
    backends, with packaged icons shared with Django applications. Backend
    identifiers remain unchanged; display labels follow current service branding.
  • VK ID OAuth2 backend (vk-id) with mandatory S256 PKCE, payload callbacks,
    server-side profiles, and device-bound refresh tokens with automatic renewal.
  • Azure AD backends support an explicit AUTHORITY_URL and opt-in PKCE through
    USE_PKCE. Azure AD B2C exposes a logout_url() helper using policy discovery.
  • Reusable BaseAuth.ASSOCIATION_ONLY capability for user-bound connections,
    shared by Drip, Last.fm, Mixcloud, and Twilio Connect.
  • Scoped pipeline request data, stored separately from pipeline arguments.
    Existing partials with request data in their arguments remain readable.
  • Life Science EOSC OpenID Connect backend (life_science_eosc) with temporary
    configuration for the EOSC federation.
  • Name normalization controls SOCIAL_AUTH_<BACKEND>_FIRSTLAST_FROM_FULL and
    SOCIAL_AUTH_<BACKEND>_FULL_FROM_FIRSTLAST, both enabled by default.

Changed

  • Updated development dependencies and CI actions.
  • Allowed newer Google Auth versions for the Google One Tap backend.

Deprecated

  • BaseAuth.get_user_names() is deprecated. Backends should return
    provider-supplied names from get_user_details() and leave normalization
    to the social_names pipeline step.

Fixed

  • Facebook Graph API quota errors are classified as rate_limited, including
    responses with HTTP 400 or 403, so callers receive retry guidance.
  • Facebook Limited Login partial pipelines preserve validated claims across
    repeated resumes, including after the original ID token expires.
  • OAuth2 renewal no longer substitutes access tokens for missing refresh tokens.
    Facebook retains its access-token exchange, and Zoom and PayPal now store
    refresh tokens by default. Existing accounts without a refresh token need
    another provider login to obtain one.
  • Auth0 caches signing keys by JWKS URL for 24 hours and refreshes them when
    a token references an unknown key ID or a token without a key ID fails
    signature verification. Refreshes preserve other domains' cached keys and
    retain existing keys if fetching or parsing replacements fails.
  • Exclude tests and their key fixtures from wheels while retaining them in
    source distributions for downstream testing.
  • VK OAuth2 accepts aliased and conditional EXTRA_DATA entries when requesting
    profile fields, and requests the supported photo_50 field while preserving
    the legacy photo and user_photo response keys.
  • Azure tenant and B2C backends honor OPENID_CONFIGURATION_URL overrides.
  • Azure's get_auth_token() uses stored refresh tokens and persists refreshed
    credentials instead of sending an access token as a refresh token.
  • Resumed authentication and disconnect pipelines consistently expose their
    effective request data without replacing the native framework request.
  • Saved request data is deserialized before use, including strategies that
    encode mappings as strings or bytes.
  • Partial pipelines are bound to authentication or disconnect so an unrelated
    saved step cannot skip disconnect permission checks.
  • OpenID Connect partial pipelines now preserve validated ID token claims when
    resuming with a new backend instance, fixing login failures since 5.1.0.
  • Shopify partial pipelines now use the saved shop instead of resume request
    parameters, and Apple preserves callback names across early pipeline pauses.
  • Legacy OpenID partial pipelines now preserve verified responses and signed
    extension data instead of repeating callback verification on resume.

Don't miss a new social-auth-core release

NewReleases is sending notifications on new releases.