Security
- Reject missing provider user identifiers before converting them to strings,
preventing absent identifiers from being stored and matched as the shared UID
"None". - Use documented stable identifiers for HubSpot (
hub_idanduser_id), Monzo
(user_id), WLCG (sub), Asana (data.gid), and Dropbox (account_id).
HubSpot identities are scoped to both the portal and installing user. - MineID and the legacy Upwork OAuth1 backend now fail closed because their
profile responses do not expose a documented immutable account identifier.
Custom MineID deployments can configureID_KEYafter adding such a field to
their profile response.
Existing social-auth rows whose UID is "None" cannot be attributed to a
specific provider account. Administrators should review and remove those rows,
then require affected users to authenticate again; they are not migrated
automatically.