Skip to content

Comments

Bump authlib from 0.15.5 to 1.5.2#4200

Closed
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/pip/develop/authlib-1.5.2
Closed

Bump authlib from 0.15.5 to 1.5.2#4200
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/pip/develop/authlib-1.5.2

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 1, 2025

Bumps authlib from 0.15.5 to 1.5.2.

Release notes

Sourced from authlib's releases.

Version 1.5.2

Released on Apr 1, 2025

  • Forbid fragments in redirect_uris. #714
  • Fix invalid characters in error_description. #720
  • Add claims_cls parameter for client's parse_id_token method. #725

Version 1.5.1

Released on Feb 28, 2025

  • Fix RFC9207 iss parameter. #715

Version 1.5.0

  • Fix token introspection auth method for clients. #662
  • Optional typ claim in JWT tokens. #696
  • JWT validation leeway. #689
  • Implement server-side RFC9207. #700 #701
  • generate_id_token can take a kid parameter. #702
  • More detailed InvalidClientError. #706
  • OpenID Connect Dynamic Client Registration implementation. #707

Version 1.4.1

  • Improve garbage collection on OAuth clients. #698
  • Fix client parameters for httpx. #694

Version 1.4.0

Bugfixes

  • Fix id_token decoding when kid is null. #659
  • Support for Python 3.13. #682
  • Force login if the prompt parameter value is login. #637
  • Support for httpx 0.28. #695

Breaking changes

  • Stop support for Python 3.8. #682

Version 1.3.2

  • Prevent ever-growing session size for OAuth clients.
  • Revert quote client id and secret.
  • unquote basic auth header for authorization server.

Version 1.3.1

Prevent OctKey to import ssh and PEM strings.

Version 1.3.0

Bug fixes

  • Restore AuthorizationServer.create_authorization_response behavior, via #558 by @​TurnrDev

... (truncated)

Changelog

Sourced from authlib's changelog.

Version 1.5.2

Released on Apr 1, 2025

  • Forbid fragments in redirect_uris. :issue:714
  • Fix invalid characters in error_description. :issue:720
  • Add claims_cls``` parameter for client's parse_id_token`` method. :issue:725

Version 1.5.1

Released on Feb 28, 2025

  • Fix RFC9207 iss parameter. :pr:715

Version 1.5.0

Released on Feb 25, 2025

  • Fix token introspection auth method for clients. :pr:662
  • Optional typ claim in JWT tokens. :pr:696
  • JWT validation leeway. :pr:689
  • Implement server-side :rfc:RFC9207 <9207>. :issue:700 :pr:701
  • generate_id_token can take a kid parameter. :pr:702
  • More detailed InvalidClientError. :pr:706
  • OpenID Connect Dynamic Client Registration implementation. :pr:707

Version 1.4.1

Released on Jan 28, 2025

  • Improve garbage collection on OAuth clients. :issue:698
  • Fix client parameters for httpx. :issue:694

Version 1.4.0

Released on Dec 20, 2024

  • Fix id_token decoding when kid is null. :pr:659
  • Support for Python 3.13. :pr:682
  • Force login if the prompt parameter value is login. :pr:637
  • Support for httpx 0.28, :pr:695

Breaking changes:

... (truncated)

Commits
  • fb698d7 chore: release version 1.5.2
  • 29fbe66 Merge pull request #729 from azmeuk/714-redirect-uri-fragments
  • 2f1f971 Merge pull request #732 from azmeuk/731-request-discovery
  • c68daba Merge branch 'main' into 714-redirect-uri-fragments
  • c1f237d Merge pull request #728 from azmeuk/720-error-description
  • 35e210b Merge branch 'main' into 720-error-description
  • 80737a5 Merge pull request #727 from lepture/fix-725
  • 50960f7 docs: add changelog for claims_cls parameter
  • ca468d8 fix: request_object_signing_alg_values_supported 'none' and 'RS256'
  • 5394bc0 fix: forbid fragments in redirect_uris
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [authlib](https://github.com/lepture/authlib) from 0.15.5 to 1.5.2.
- [Release notes](https://github.com/lepture/authlib/releases)
- [Changelog](https://github.com/authlib/authlib/blob/main/docs/changelog.rst)
- [Commits](authlib/authlib@v0.15.5...v1.5.2)

---
updated-dependencies:
- dependency-name: authlib
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file Major issue that requires attention python Pull requests that update Python code labels May 1, 2025
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jun 1, 2025

Superseded by #4234.

@dependabot dependabot bot closed this Jun 1, 2025
@dependabot dependabot bot deleted the dependabot/pip/develop/authlib-1.5.2 branch June 1, 2025 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file Major issue that requires attention python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants