pypi social-auth-core 6.1.0

4 hours ago

Removed

  • Removed the Docker Hub OAuth2 backend (docker) because its authorization,
    token, and profile endpoints are no longer available. Remove
    social_core.backends.docker.DockerOAuth2 from backend configuration.
    See #1176.
  • Removed obsolete authentication backends: Microsoft Live Connect (live),
    Evernote Sandbox (evernote-sandbox), PixelPin (pixelpin-openidconnect),
    Behance (behance), and NGP VAN ActionID OpenID (actionid-openid). Their
    authentication endpoints have been retired or are no longer available; see
    #1176.
    Remove social_core.backends.live.LiveOAuth2,
    social_core.backends.evernote.EvernoteSandboxOAuth,
    social_core.backends.pixelpin.PixelPinOpenIDConnect,
    social_core.backends.behance.BehanceOAuth2, and
    social_core.backends.ngpvan.ActionIDOpenID from backend configuration.
    Live Connect users can configure social_core.backends.microsoft.MicrosoftOAuth2
    (microsoft-graph), but identifiers are not compatible and existing account
    associations are not migrated automatically. Production Evernote remains
    supported. This removes the old ActionID OpenID integration, not the ActionID
    service. Existing stored account associations are not deleted.

Security

  • OpenID session state uses explicit JSON-compatible serialization instead of
    pickle. In-progress OpenID logins with old session state must restart; existing
    linked accounts, provider associations, and authenticated sessions are unchanged.

Fixed

  • Resolve historical identifiers through indexed (provider, id_key, uid)
    lookups instead of scanning stored JSON during authentication. Configure
    backend-scoped LEGACY_ID_KEYS for explicit identifier changes.
  • Require matching stored identifier evidence for migration by default, except
    for audited built-in transitions that lacked evidence in social-core 5.2.0.
    Conflicting evidence always stops authentication, including when
    ALLOW_UNVERIFIED_LEGACY_UID_MIGRATION is explicitly enabled. Missing evidence
    stops authentication unless the transition's compatibility policy allows it.
  • Preserve historical OIDC subject aliases and atomic Vend shop-scoped migration.
  • Backends return None for unavailable names instead of invented empty
    strings, preventing logins and account associations from clearing existing
    names. Name normalization still fills missing or blank fields from available
    names, but preserves unavailable components when derivation produces nothing.
    Explicit provider-supplied empty strings remain valid profile updates.
  • New-user creation omits unavailable configured name fields so user model
    defaults apply instead of inserting null values into non-null columns,
    including when only name fields are configured.
  • OpenID keeps usable names from earlier response schemas when a later
    alias is blank, while preserving blanks when no usable name is supplied.
  • Required Auth0, Fence, SAML, and Twitch validation remains active when Python
    runs with optimization enabled.
  • Okta reuses the validated, cached OpenID Connect discovery loader.
  • Cached methods retain argument and return type checking, including their
    invalidate() and refresh() controls.

Breaking

  • Storage implementations must accept the optional keyword-only evidence_key
    argument to migrate_social_auth() and revalidate supplied evidence atomically.
    The pipeline now passes keyed legacy_identifiers; legacy_uids and
    get_legacy_user_ids() remain available for compatibility.

Changed

  • Allowed newer Google Auth versions for the Google One Tap backend.
  • Updated development dependencies, lint configuration, and CI actions.

Don't miss a new social-auth-core release

NewReleases is sending notifications on new releases.