You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Removed the Docker Hub OAuth2 backend (docker) because its authorization,
token, and profile endpoints are no longer available. Remove social_core.backends.docker.DockerOAuth2 from backend configuration.
See #1176.
Removed obsolete authentication backends: Microsoft Live Connect (live),
Evernote Sandbox (evernote-sandbox), PixelPin (pixelpin-openidconnect),
Behance (behance), and NGP VAN ActionID OpenID (actionid-openid). Their
authentication endpoints have been retired or are no longer available; see #1176.
Remove social_core.backends.live.LiveOAuth2, social_core.backends.evernote.EvernoteSandboxOAuth, social_core.backends.pixelpin.PixelPinOpenIDConnect, social_core.backends.behance.BehanceOAuth2, and social_core.backends.ngpvan.ActionIDOpenID from backend configuration.
Live Connect users can configure social_core.backends.microsoft.MicrosoftOAuth2
(microsoft-graph), but identifiers are not compatible and existing account
associations are not migrated automatically. Production Evernote remains
supported. This removes the old ActionID OpenID integration, not the ActionID
service. Existing stored account associations are not deleted.
Security
OpenID session state uses explicit JSON-compatible serialization instead of
pickle. In-progress OpenID logins with old session state must restart; existing
linked accounts, provider associations, and authenticated sessions are unchanged.
Fixed
Resolve historical identifiers through indexed (provider, id_key, uid)
lookups instead of scanning stored JSON during authentication. Configure
backend-scoped LEGACY_ID_KEYS for explicit identifier changes.
Require matching stored identifier evidence for migration by default, except
for audited built-in transitions that lacked evidence in social-core 5.2.0.
Conflicting evidence always stops authentication, including when ALLOW_UNVERIFIED_LEGACY_UID_MIGRATION is explicitly enabled. Missing evidence
stops authentication unless the transition's compatibility policy allows it.
Preserve historical OIDC subject aliases and atomic Vend shop-scoped migration.
Backends return None for unavailable names instead of invented empty
strings, preventing logins and account associations from clearing existing
names. Name normalization still fills missing or blank fields from available
names, but preserves unavailable components when derivation produces nothing.
Explicit provider-supplied empty strings remain valid profile updates.
New-user creation omits unavailable configured name fields so user model
defaults apply instead of inserting null values into non-null columns,
including when only name fields are configured.
OpenID keeps usable names from earlier response schemas when a later
alias is blank, while preserving blanks when no usable name is supplied.
Required Auth0, Fence, SAML, and Twitch validation remains active when Python
runs with optimization enabled.
Okta reuses the validated, cached OpenID Connect discovery loader.
Cached methods retain argument and return type checking, including their invalidate() and refresh() controls.
Breaking
Storage implementations must accept the optional keyword-only evidence_key
argument to migrate_social_auth() and revalidate supplied evidence atomically.
The pipeline now passes keyed legacy_identifiers; legacy_uids and get_legacy_user_ids() remain available for compatibility.
Changed
Allowed newer Google Auth versions for the Google One Tap backend.
Updated development dependencies, lint configuration, and CI actions.