Security
- OpenID Connect nonces expire after 30 minutes by default. Configure
SOCIAL_AUTH_<BACKEND>_NONCE_LIFETIMEto change the duration. Storage
integrations must persistissuedandlifetime; stored nonces without
a valid lifetime are rejected. - LinkedIn OpenID Connect no longer stores unused nonces.
- Backend signatures, hashes, and CSRF tokens use constant-time comparisons.
Malformed signatures, including non-ASCII Discourse signatures, raise
authentication errors instead of type errors. - Facebook Limited Login reuses validated claims only during a saved partial
pipeline resume, preventing forged resumes from authenticating a previous user. - Google OAuth2 and Google OpenID Connect now reject UserInfo responses that do
not explicitly confirm email verification. Google One Tap requires the same
confirmation in its ID token. - Email validation codes expire after seven days by default. Configure
SOCIAL_AUTH_EMAIL_VALIDATION_EXPIRED_THRESHOLDto change their lifetime.
Storage integrations must persist each code's creationtimestamp; undated
codes are rejected when expiry is enabled. - Tumblr, Deezer, Discourse, SciStarter, Okta, Google, Trello, Qiita, Keycloak,
Fence, CAS, Cognito, Dailymotion, Mail.ru, ArcGIS, Ubuntu, openSUSE, Yandex,
and affected Microsoft Entra ID backends now bind accounts to stable provider
or protocol identifiers. Existing associations record their identifier key
and migrate on authentication; strict deployments can disable unverified
legacy-identifier migration with
SOCIAL_AUTH_<BACKEND>_ALLOW_UNVERIFIED_LEGACY_UID_MIGRATION. - Drip, Last.fm, and Mixcloud are now association-only: connecting requires the
same authenticated local user at initiation, callback, and partial resumption.
Mutable provider identifiers can no longer create or authenticate local users,
and connecting preserves local profile fields.
Breaking
- Name normalization now runs in the shared authentication pipeline. Custom
pipelines must addsocial_core.pipeline.social_auth.social_namesimmediately
aftersocial_core.pipeline.social_auth.social_detailsto retain automatic
conversion between full names and first/last names. - Storage integrations must persist association
id_keyvalues, acceptid_key
inget_social_auth()andcreate_social_auth(), and implement
get_social_auth_by_extra_data()and atomicmigrate_social_auth().
Existing associations use an empty identifier key until migration. - Token renewal raises
AuthCredentialErrorwithreauthentication_required
when a stored access token is expired and no renewal credential is available.
Custom backends that exchange access tokens must overrideget_refresh_token(). - MediaWiki and Discourse groups are exposed separately from profile details.
Enable group extraction and update custom pipeline consumers to usegroups
instead ofdetails["groups"]. MediaWiki identity retrieval now runs in
user_data()rather thanget_user_details(). - Authentication exceptions now expose stable reason codes, failure sources,
operation stages, and suggested recovery. OnlySocialAuthBaseExceptionand
AuthExceptionretain broad catch compatibility; migrate removed specialized
classes using the exception reference in social-docs. - HTTP failures no longer infer cancellation from HTTP 400 or token expiry from
HTTP 401. Provider diagnostics are separate from safe exception messages. - Strategies must implement
get_request_data()instead of overriding
request_data(). The latter now returns effective data for the active partial
pipeline, including confirmed external-link data. - Pipeline steps no longer receive an automatic
requestargument. Use
strategy.request_data()for parameters and the framework strategy's
requestattribute for its native request object. - Legacy disconnect partials without a pipeline type must restart the disconnect
flow. Legacy authentication partials remain resumable.
Added
- Configurable external group extraction and login allow lists for Azure, OIDC,
Keycloak, Okta OAuth2, SAML, GitLab, MediaWiki, and Discourse, with a strategy
hook and optional pipeline step for local group synchronization. Existing CAS
allow lists continue to work without pipeline changes. - Human-readable
titleand optionaliconmetadata for authentication
backends, with packaged icons shared with Django applications. Backend
identifiers remain unchanged; display labels follow current service branding. - VK ID OAuth2 backend (
vk-id) with mandatory S256 PKCE, payload callbacks,
server-side profiles, and device-bound refresh tokens with automatic renewal. - Azure AD backends support an explicit
AUTHORITY_URLand opt-in PKCE through
USE_PKCE. Azure AD B2C exposes alogout_url()helper using policy discovery. - Reusable
BaseAuth.ASSOCIATION_ONLYcapability for user-bound connections,
shared by Drip, Last.fm, Mixcloud, and Twilio Connect. - Scoped pipeline request data, stored separately from pipeline arguments.
Existing partials with request data in their arguments remain readable. - Life Science EOSC OpenID Connect backend (
life_science_eosc) with temporary
configuration for the EOSC federation. - Name normalization controls
SOCIAL_AUTH_<BACKEND>_FIRSTLAST_FROM_FULLand
SOCIAL_AUTH_<BACKEND>_FULL_FROM_FIRSTLAST, both enabled by default.
Changed
- Updated development dependencies and CI actions.
- Allowed newer Google Auth versions for the Google One Tap backend.
Deprecated
BaseAuth.get_user_names()is deprecated. Backends should return
provider-supplied names fromget_user_details()and leave normalization
to thesocial_namespipeline step.
Fixed
- Facebook Graph API quota errors are classified as
rate_limited, including
responses with HTTP 400 or 403, so callers receive retry guidance. - Facebook Limited Login partial pipelines preserve validated claims across
repeated resumes, including after the original ID token expires. - OAuth2 renewal no longer substitutes access tokens for missing refresh tokens.
Facebook retains its access-token exchange, and Zoom and PayPal now store
refresh tokens by default. Existing accounts without a refresh token need
another provider login to obtain one. - Auth0 caches signing keys by JWKS URL for 24 hours and refreshes them when
a token references an unknown key ID or a token without a key ID fails
signature verification. Refreshes preserve other domains' cached keys and
retain existing keys if fetching or parsing replacements fails. - Exclude tests and their key fixtures from wheels while retaining them in
source distributions for downstream testing. - VK OAuth2 accepts aliased and conditional
EXTRA_DATAentries when requesting
profile fields, and requests the supportedphoto_50field while preserving
the legacyphotoanduser_photoresponse keys. - Azure tenant and B2C backends honor
OPENID_CONFIGURATION_URLoverrides. - Azure's
get_auth_token()uses stored refresh tokens and persists refreshed
credentials instead of sending an access token as a refresh token. - Resumed authentication and disconnect pipelines consistently expose their
effective request data without replacing the native framework request. - Saved request data is deserialized before use, including strategies that
encode mappings as strings or bytes. - Partial pipelines are bound to authentication or disconnect so an unrelated
saved step cannot skip disconnect permission checks. - OpenID Connect partial pipelines now preserve validated ID token claims when
resuming with a new backend instance, fixing login failures since 5.1.0. - Shopify partial pipelines now use the saved shop instead of resume request
parameters, and Apple preserves callback names across early pipeline pauses. - Legacy OpenID partial pipelines now preserve verified responses and signed
extension data instead of repeating callback verification on resume.