Revisions of python-django-allauth
Ana Guerrero (anag+factory)
accepted
request 1140111
from
Dirk Mueller (dirkmueller)
(revision 13)
- update to 0.60.1: * User sessions: after changing your password in case of ACCOUNT_LOGOUT_ON_PASSWORD_CHANGE = False, the list of sessions woud be empty instead of showing your current session. * SAML: accessing the SLS/ACS views using a GET request would result in a crash (500). * SAML: the login view did not obey the SOCIALACCOUNT_LOGIN_ON_GET = False setting.
Ana Guerrero (anag+factory)
accepted
request 1137633
from
Dirk Mueller (dirkmueller)
(revision 12)
- update to 0.60.0: * Google One Tap Sign-In is now supported. * You can now more easily change the URL to redirect to after a successful password change/set via the newly introduced get_password_change_redirect_url() adapter method. * You can now configure the primary key of all models by configuring ALLAUTH_DEFAULT_AUTO_FIELD, for example to: "hashid_field.HashidAutoField". * You can now specify the URL path prefix that is used for all OpenID Connect providers using SOCIALACCOUNT_OPENID_CONNECT_URL_PREFIX. By default, it is set to "oidc", meaning, an OpenID Connect provider with provider ID foo uses /accounts/oidc/foo/login/ as its login URL. Set it to empty ("") to keep the previous URL structure (/accounts/foo/login/). * The SAML default attribute mapping for uid has been changed to only include urn:oasis:names:tc:SAML:attribute:subject-id. If the SAML response does not contain that, it will fallback to use NameID.
Ana Guerrero (anag+factory)
accepted
request 1133055
from
Dirk Mueller (dirkmueller)
(revision 11)
- update to 0.59.0: * The MFA authenticator model now features "created at" an "last used "at" timestamps. * The MFA authenticator model is now registered with the Django admin. * Added MFA signals emitted when authenticators are added, removed or (in case of recovery codes) reset. * There is now an MFA adapter method ``can_delete_authenticator(authenticator)`` available that can be used to prevent users from deactivating e.g. their TOTP authenticator. * Added a new app, user sessions, allowing users to view a list of all their active sessions, as well as offering a means to end these sessions. * A configurable timeout (``SOCIALACCOUNT_REQUESTS_TIMEOUT``) is now applied to all upstream requests. * Added a setting ``ACCOUNT_EMAIL_UNKNOWN_ACCOUNTS`` to disable sending of emails to unknown accounts. * You can now override the MFA forms via the ``MFA_FORMS`` setting.
Ana Guerrero (anag+factory)
accepted
request 1124871
from
Dirk Mueller (dirkmueller)
(revision 10)
- update to 0.58.2: * Added rate limiting to the MFA login form. * Fixed Twitch get_avatar_url()
Dominique Leuenberger (dimstar_suse)
accepted
request 1095440
from
Dirk Mueller (dirkmueller)
(revision 7)
Dominique Leuenberger (dimstar_suse)
accepted
request 942392
from
John Vandenberg (jayvdb)
(revision 6)
Dominique Leuenberger (dimstar_suse)
accepted
request 814882
from
Factory Maintainer (factory-maintainer)
(revision 5)
Automatic submission by obs-autosubmit
Dominique Leuenberger (dimstar_suse)
accepted
request 761502
from
Tomáš Chvátal (scarabeus_iv)
(revision 4)
- Update to 0.41.0: * Fixes CVE-2019-19844: Potential account hijack via password reset form bsc#1159447 * Dropped Python 2 and Django 1 compatibility. - Do not bother with the lang subpkg as it is needed to have languages to be present always anyway
Yuchen Lin (maxlin_factory)
accepted
request 731237
from
Tomáš Chvátal (scarabeus_iv)
(revision 3)
- Update to 0.40.0: * The instagram provider now extracts the user's full name. * New provider: NextCloud (OAuth2) * Added an SDK_URL setting for customizing the loading of the Facebook JavaScript SDK. * Updated Twitch provider to use new authentication endpoints (https://id.twitch.tv) over deprecated v5 endpoints (https://api.twitch.tv/kraken) * Added support for Patreon API v2, with API v1 set as default for backwards compatibility. - Use %ifpython2/3 to allow building only one flavour
Dominique Leuenberger (dimstar_suse)
accepted
request 683727
from
Tomáš Chvátal (scarabeus_iv)
(revision 2)
- Update to 0.39.1: * The linkedin_oauth2 provider now gracefully deals with old V1 data that might still be present in SocialAccount.extra_data. * New providers: JupyterHub (OAuth2), Steam (OpenID) * Refactor translations: Portuguese (Portugal). * Add testing for Django 2.2 (no code changes required) * linkedin_oauth2: As the LinkedIn V1 API is deprecated, the user info endpoint has been moved over to use the API V2. The format of the user extra_data is different and the profile picture is absent by default.
Dominique Leuenberger (dimstar_suse)
accepted
request 679779
from
Tomáš Chvátal (scarabeus_iv)
(revision 1)
- Skip five failing tests - Initial spec for v0.38.0
Displaying all 13 revisions