Sourced from fastapi-sso's releases.
0.19.0
️⚠️ A critical OAuth login CSRF vulnerability caused by missing
statevalidation was reported by@davidbors-snyk(Snyk Security Labs) in #266 and has been resolved in version0.19.0.Starting with
fastapi-sso==1.0.0, OAuthstatewill be backed by a pluggable server-side store (in-memory by default, with support for external stores such asRedis).What's Changed
- chore(deps): bump the all group with 11 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#230- chore(deps): bump the all group with 3 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#231- chore(deps): bump the all group with 6 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#232- chore(deps): bump the all group with 4 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#233- chore(deps-dev): bump the all group with 3 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#234- chore(deps-dev): bump the all group with 2 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#235- chore(deps): bump the all group across 1 directory with 3 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#237- chore(deps): bump the all group across 1 directory with 3 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#239- chore(deps-dev): bump the all group across 1 directory with 4 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#241- chore(deps): bump the all group with 5 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#242- chore(deps): bump the all group across 1 directory with 10 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#247- chore(deps-dev): bump the all group with 3 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#248- chore(deps-dev): bump the all group across 1 directory with 3 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#251- chore(deps-dev): bump the all group with 3 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#252- chore(deps-dev): bump the all group with 2 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#253- chore(deps): bump the all group with 2 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#254- chore(deps): bump the all group across 1 directory with 12 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#259- fix: enforce state validation by
@davidbors-snykin tomasvotava/fastapi-sso#267- chore(deps): bump the all group across 1 directory with 7 updates by
@dependabot[bot] in tomasvotava/fastapi-sso#265- docs(#266): warn against using state as an arbitrary data transport by
@tomasvotavain tomasvotava/fastapi-sso#269New Contributors
@davidbors-snykmade their first contribution in tomasvotava/fastapi-sso#267Full Changelog: https://github.com/tomasvotava/fastapi-sso/compare/0.18.0...0.19.0
c905eaf
chore: 0.18.0 => 0.19.094343bf
docs(#266):
warn against using state as an arbitrary data transport (#269)d057c1d
chore(deps): bump the all group across 1 directory with 7 updates (#265)6117d1a
fix: enforce state validation (#267)da63c19
chore(deps): bump the all group across 1 directory with 12 updates (#259)0ccaedd
chore(deps): bump the all group with 2 updates (#254)a43e62e
chore(deps-dev): bump the all group with 2 updates (#253)8cd706d
chore(deps-dev): bump the all group with 3 updates (#252)ea769fa
chore(deps-dev): bump the all group across 1 directory with 3 updates
(#251)7aba1e6
chore(deps-dev): bump the all group with 3 updates (#248)