You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Added an optional user argument to do_auth() and a BaseAuth.prepare_auth()
hook for backend-specific authentication initiation.
Security
Twilio Connect is now association-only: starting and completing a connection
requires the same authenticated local user. Twilio callback data can no
longer create or authenticate users.
Facebook App authentication now binds access-token and signed-request
callbacks to the browser session, preventing login CSRF and unauthorized
account linking. Custom Facebook App templates must preserve the query string
in FACEBOOK_COMPLETE_URI when submitting the callback.
Weixin app authentication now validates OAuth state before exchanging codes,
preventing login CSRF and unauthorized account linking.
Last.fm authentication now binds callbacks to the browser session that
initiated the login, preventing login CSRF and unauthorized account linking.
GitHub App authentication now validates OAuth state before exchanging codes.
Stateless installation callbacks restart a state-protected OAuth flow,
preventing forged installation parameters from enabling login CSRF.
VK OpenAPI authentication now uses the signed session's user ID instead of
trusting the ID supplied in callback data.
Changed
Updated development dependencies and CI actions.
Allowed newer Google Auth versions for the Google One Tap backend.