Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package python-django-allauth for
openSUSE:Factory checked in at 2026-09-28 10:46:17
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-django-allauth (Old)
and /work/SRC/openSUSE:Factory/.python-django-allauth.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-django-allauth"
Mon Sep 28 10:46:17 2026 rev:22 rq:1380824 version:65.19.4
Changes:
--------
---
/work/SRC/openSUSE:Factory/python-django-allauth/python-django-allauth.changes
2026-08-21 17:00:12.685665200 +0200
+++
/work/SRC/openSUSE:Factory/.python-django-allauth.new.383539/python-django-allauth.changes
2026-09-28 10:46:54.480097248 +0200
@@ -1,0 +2,43 @@
+Sat Sep 26 17:42:18 UTC 2026 - Dirk Müller <[email protected]>
+
+- update to 65.19.4 (bsc#1282668, CVE-2026-97764):
+ * Account: On databases with broad Unicode collations (e.g.
+ common MySQL/MariaDB configurations), usernames such as admin
+ and ádmin, or email addresses containing compatibility
+ characters, could authenticate the same account while
+ consuming different rate limit keys. This resulted in a
+ larger than intended per account rate limit. To mitigate,
+ matching rows are now checked against the submitted username
+ or email address before the password is verified. On these
+ configurations, projects using username authentication must
+ remove Django's ModelBackend from AUTHENTICATION_BACKENDS, as
+ it does not perform this additional check. Thanks to Yuji
+ Egami for reporting.
+ * Account: The email address data migrations (0006 and 0008)
+ did not honor the database selected using migrate --database,
+ potentially querying or updating the default database
+ instead. Fixed.
+ * MFA: Fixed various race conditions involving TOTP and
+ recovery codes.
+ * Headless: When HEADLESS_JWT_STATEFUL_VALIDATION_ENABLED is
+ on, JWT access tokens are now rejected after the password
+ changes outside of the allauth password-change flow (for
+ example via set_password() in a shell). Stateful validation
+ now uses the same session auth hash check that refresh tokens
+ already used.
+ * A known flaw in the built-in rate limiting was that the
+ configured limits could be exceeded under a high volume of
+ concurrent requests. This was documented as an acceptably
+ small margin of error. However, as Kaya Emre Arikan (kemrec)
+ demonstrated, the limits could be substantially exceeded
+ under a sufficiently high volume of concurrent requests. This
+ is now fixed by serializing rate limit updates.
+ * Headless: Posting a well-formed JSON payload that was not an
+ object (e.g. a list or a string) to the headless endpoints
+ resulted in a server error.
+ * MFA: TOTP enrollment code verification was not rate limited.
+ Impact is limited, as to exploit this you would need to be
+ already fully authenticated, pass (rate-limited)
+ reauthentication, and brute force within a 30s TOTP window.
+
+-------------------------------------------------------------------
Old:
----
django_allauth-65.19.1.tar.gz
New:
----
django_allauth-65.19.4.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ python-django-allauth.spec ++++++
--- /var/tmp/diff_new_pack.DmJYGY/_old 2026-09-28 10:46:55.617144886 +0200
+++ /var/tmp/diff_new_pack.DmJYGY/_new 2026-09-28 10:46:55.621145054 +0200
@@ -38,7 +38,7 @@
%{?sle15_python_module_pythons}
Name: python-django-allauth
-Version: 65.19.1
+Version: 65.19.4
Release: 0
Summary: Django authentication, registration, account management
License: MIT
@@ -65,7 +65,6 @@
BuildRequires: %{python_module pytest-django >= %{pytest_django_min_version}}
BuildRequires: %{python_module python3-openid >=
%{python3_openid_min_version}}
BuildRequires: %{python_module python3-saml >= %{python3_saml_min_version}}
-BuildRequires: %{python_module python3-saml >= %{python3_saml_min_version}}
BuildRequires: %{python_module qrcode >= %{qrcode_min_version}}
BuildRequires: %{python_module requests >= %{requests_min_version}}
# /SECTION
++++++ django_allauth-65.19.1.tar.gz -> django_allauth-65.19.4.tar.gz ++++++
++++ 1987 lines of diff (skipped)
++++++ missing-template-in-test.patch ++++++
--- /var/tmp/diff_new_pack.DmJYGY/_old 2026-09-28 10:46:56.692189927 +0200
+++ /var/tmp/diff_new_pack.DmJYGY/_new 2026-09-28 10:46:56.696190094 +0200
@@ -1,7 +1,7 @@
-Index: django_allauth-65.14.3/tests/apps/account/test_ratelimit.py
+Index: django_allauth-65.19.4/tests/apps/account/test_ratelimit.py
===================================================================
---- django_allauth-65.14.3.orig/tests/apps/account/test_ratelimit.py
2026-01-17 13:07:19.000000000 +0100
-+++ django_allauth-65.14.3/tests/apps/account/test_ratelimit.py
2026-03-03 12:29:39.635505574 +0100
+--- django_allauth-65.19.4.orig/tests/apps/account/test_ratelimit.py
++++ django_allauth-65.19.4/tests/apps/account/test_ratelimit.py
@@ -8,5 +8,5 @@ def test_case_insensitive_password_reset
user_factory(email="[email protected]")
resp = client.post(reverse("account_reset_password"), data={"email":
"[email protected]"})