You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OpenID Connect nonces expire after 30 minutes by default. Configure SOCIAL_AUTH_<BACKEND>_NONCE_LIFETIME to change the duration. Storage
integrations must persist issued and lifetime; stored nonces without
a valid lifetime are rejected.
LinkedIn OpenID Connect no longer stores unused nonces.
Backend signatures, hashes, and CSRF tokens use constant-time comparisons.
Malformed signatures, including non-ASCII Discourse signatures, raise
authentication errors instead of type errors.
Facebook Limited Login reuses validated claims only during a saved partial
pipeline resume, preventing forged resumes from authenticating a previous user.
Google OAuth2 and Google OpenID Connect now reject UserInfo responses that do
not explicitly confirm email verification. Google One Tap requires the same
confirmation in its ID token.
Email validation codes expire after seven days by default. Configure SOCIAL_AUTH_EMAIL_VALIDATION_EXPIRED_THRESHOLD to change their lifetime.
Storage integrations must persist each code's creation timestamp; undated
codes are rejected when expiry is enabled.
Tumblr, Deezer, Discourse, SciStarter, Okta, Google, Trello, Qiita, Keycloak,
Fence, CAS, Cognito, Dailymotion, Mail.ru, ArcGIS, Ubuntu, openSUSE, Yandex,
and affected Microsoft Entra ID backends now bind accounts to stable provider
or protocol identifiers. Existing associations record their identifier key
and migrate on authentication; strict deployments can disable unverified
legacy-identifier migration with SOCIAL_AUTH_<BACKEND>_ALLOW_UNVERIFIED_LEGACY_UID_MIGRATION.
Drip, Last.fm, and Mixcloud are now association-only: connecting requires the
same authenticated local user at initiation, callback, and partial resumption.
Mutable provider identifiers can no longer create or authenticate local users,
and connecting preserves local profile fields.
Breaking
Name normalization now runs in the shared authentication pipeline. Custom
pipelines must add social_core.pipeline.social_auth.social_names immediately
after social_core.pipeline.social_auth.social_details to retain automatic
conversion between full names and first/last names.
Storage integrations must persist association id_key values, accept id_key
in get_social_auth() and create_social_auth(), and implement get_social_auth_by_extra_data() and atomic migrate_social_auth().
Existing associations use an empty identifier key until migration.
Token renewal raises AuthCredentialError with reauthentication_required
when a stored access token is expired and no renewal credential is available.
Custom backends that exchange access tokens must override get_refresh_token().
MediaWiki and Discourse groups are exposed separately from profile details.
Enable group extraction and update custom pipeline consumers to use groups
instead of details["groups"]. MediaWiki identity retrieval now runs in user_data() rather than get_user_details().
Authentication exceptions now expose stable reason codes, failure sources,
operation stages, and suggested recovery. Only SocialAuthBaseException and AuthException retain broad catch compatibility; migrate removed specialized
classes using the exception reference in social-docs.
HTTP failures no longer infer cancellation from HTTP 400 or token expiry from
HTTP 401. Provider diagnostics are separate from safe exception messages.
Strategies must implement get_request_data() instead of overriding request_data(). The latter now returns effective data for the active partial
pipeline, including confirmed external-link data.
Pipeline steps no longer receive an automatic request argument. Use strategy.request_data() for parameters and the framework strategy's request attribute for its native request object.
Legacy disconnect partials without a pipeline type must restart the disconnect
flow. Legacy authentication partials remain resumable.
Added
Configurable external group extraction and login allow lists for Azure, OIDC,
Keycloak, Okta OAuth2, SAML, GitLab, MediaWiki, and Discourse, with a strategy
hook and optional pipeline step for local group synchronization. Existing CAS
allow lists continue to work without pipeline changes.
Human-readable title and optional icon metadata for authentication
backends, with packaged icons shared with Django applications. Backend
identifiers remain unchanged; display labels follow current service branding.
VK ID OAuth2 backend (vk-id) with mandatory S256 PKCE, payload callbacks,
server-side profiles, and device-bound refresh tokens with automatic renewal.
Azure AD backends support an explicit AUTHORITY_URL and opt-in PKCE through USE_PKCE. Azure AD B2C exposes a logout_url() helper using policy discovery.
Reusable BaseAuth.ASSOCIATION_ONLY capability for user-bound connections,
shared by Drip, Last.fm, Mixcloud, and Twilio Connect.
Scoped pipeline request data, stored separately from pipeline arguments.
Existing partials with request data in their arguments remain readable.
Life Science EOSC OpenID Connect backend (life_science_eosc) with temporary
configuration for the EOSC federation.
Name normalization controls SOCIAL_AUTH_<BACKEND>_FIRSTLAST_FROM_FULL and SOCIAL_AUTH_<BACKEND>_FULL_FROM_FIRSTLAST, both enabled by default.
Changed
Updated development dependencies and CI actions.
Allowed newer Google Auth versions for the Google One Tap backend.
Deprecated
BaseAuth.get_user_names() is deprecated. Backends should return
provider-supplied names from get_user_details() and leave normalization
to the social_names pipeline step.
Fixed
Facebook Graph API quota errors are classified as rate_limited, including
responses with HTTP 400 or 403, so callers receive retry guidance.
Facebook Limited Login partial pipelines preserve validated claims across
repeated resumes, including after the original ID token expires.
OAuth2 renewal no longer substitutes access tokens for missing refresh tokens.
Facebook retains its access-token exchange, and Zoom and PayPal now store
refresh tokens by default. Existing accounts without a refresh token need
another provider login to obtain one.
Auth0 caches signing keys by JWKS URL for 24 hours and refreshes them when
a token references an unknown key ID or a token without a key ID fails
signature verification. Refreshes preserve other domains' cached keys and
retain existing keys if fetching or parsing replacements fails.
Exclude tests and their key fixtures from wheels while retaining them in
source distributions for downstream testing.
VK OAuth2 accepts aliased and conditional EXTRA_DATA entries when requesting
profile fields, and requests the supported photo_50 field while preserving
the legacy photo and user_photo response keys.
Azure tenant and B2C backends honor OPENID_CONFIGURATION_URL overrides.
Azure's get_auth_token() uses stored refresh tokens and persists refreshed
credentials instead of sending an access token as a refresh token.
Resumed authentication and disconnect pipelines consistently expose their
effective request data without replacing the native framework request.
Saved request data is deserialized before use, including strategies that
encode mappings as strings or bytes.
Partial pipelines are bound to authentication or disconnect so an unrelated
saved step cannot skip disconnect permission checks.
OpenID Connect partial pipelines now preserve validated ID token claims when
resuming with a new backend instance, fixing login failures since 5.1.0.
Shopify partial pipelines now use the saved shop instead of resume request
parameters, and Apple preserves callback names across early pipeline pauses.
Legacy OpenID partial pipelines now preserve verified responses and signed
extension data instead of repeating callback verification on resume.