Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-django-allauth for 
openSUSE:Factory checked in at 2026-09-28 10:46:17
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-django-allauth (Old)
 and      /work/SRC/openSUSE:Factory/.python-django-allauth.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-django-allauth"

Mon Sep 28 10:46:17 2026 rev:22 rq:1380824 version:65.19.4

Changes:
--------
--- 
/work/SRC/openSUSE:Factory/python-django-allauth/python-django-allauth.changes  
    2026-08-21 17:00:12.685665200 +0200
+++ 
/work/SRC/openSUSE:Factory/.python-django-allauth.new.383539/python-django-allauth.changes
  2026-09-28 10:46:54.480097248 +0200
@@ -1,0 +2,43 @@
+Sat Sep 26 17:42:18 UTC 2026 - Dirk Müller <[email protected]>
+
+- update to 65.19.4 (bsc#1282668, CVE-2026-97764):
+  * Account: On databases with broad Unicode collations (e.g.
+    common MySQL/MariaDB configurations), usernames such as admin
+    and ádmin, or email addresses containing compatibility
+    characters, could authenticate the same account while
+    consuming different rate limit keys. This resulted in a
+    larger than intended per account rate limit. To mitigate,
+    matching rows are now checked against the submitted username
+    or email address before the password is verified. On these
+    configurations, projects using username authentication must
+    remove Django's ModelBackend from AUTHENTICATION_BACKENDS, as
+    it does not perform this additional check.  Thanks to Yuji
+    Egami for reporting.
+  * Account: The email address data migrations (0006 and 0008)
+    did not honor the database selected using migrate --database,
+    potentially querying or updating the default database
+    instead. Fixed.
+  * MFA: Fixed various race conditions involving TOTP and
+    recovery codes.
+  * Headless: When HEADLESS_JWT_STATEFUL_VALIDATION_ENABLED is
+    on, JWT access tokens are now rejected after the password
+    changes outside of the allauth password-change flow (for
+    example via set_password() in a shell). Stateful validation
+    now uses the same session auth hash check that refresh tokens
+    already used.
+  * A known flaw in the built-in rate limiting was that the
+    configured limits could be exceeded under a high volume of
+    concurrent requests. This was documented as an acceptably
+    small margin of error. However, as Kaya Emre Arikan (kemrec)
+    demonstrated, the limits could be substantially exceeded
+    under a sufficiently high volume of concurrent requests. This
+    is now fixed by serializing rate limit updates.
+  * Headless: Posting a well-formed JSON payload that was not an
+    object (e.g. a list or a string) to the headless endpoints
+    resulted in a server error.
+  * MFA: TOTP enrollment code verification was not rate limited.
+    Impact is limited, as to exploit this you would need to be
+    already fully authenticated, pass (rate-limited)
+    reauthentication, and brute force within a 30s TOTP window.
+
+-------------------------------------------------------------------

Old:
----
  django_allauth-65.19.1.tar.gz

New:
----
  django_allauth-65.19.4.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-django-allauth.spec ++++++
--- /var/tmp/diff_new_pack.DmJYGY/_old  2026-09-28 10:46:55.617144886 +0200
+++ /var/tmp/diff_new_pack.DmJYGY/_new  2026-09-28 10:46:55.621145054 +0200
@@ -38,7 +38,7 @@
 
 %{?sle15_python_module_pythons}
 Name:           python-django-allauth
-Version:        65.19.1
+Version:        65.19.4
 Release:        0
 Summary:        Django authentication, registration, account management
 License:        MIT
@@ -65,7 +65,6 @@
 BuildRequires:  %{python_module pytest-django >= %{pytest_django_min_version}}
 BuildRequires:  %{python_module python3-openid >= 
%{python3_openid_min_version}}
 BuildRequires:  %{python_module python3-saml >= %{python3_saml_min_version}}
-BuildRequires:  %{python_module python3-saml >= %{python3_saml_min_version}}
 BuildRequires:  %{python_module qrcode >= %{qrcode_min_version}}
 BuildRequires:  %{python_module requests >= %{requests_min_version}}
 # /SECTION

++++++ django_allauth-65.19.1.tar.gz -> django_allauth-65.19.4.tar.gz ++++++
++++ 1987 lines of diff (skipped)

++++++ missing-template-in-test.patch ++++++
--- /var/tmp/diff_new_pack.DmJYGY/_old  2026-09-28 10:46:56.692189927 +0200
+++ /var/tmp/diff_new_pack.DmJYGY/_new  2026-09-28 10:46:56.696190094 +0200
@@ -1,7 +1,7 @@
-Index: django_allauth-65.14.3/tests/apps/account/test_ratelimit.py
+Index: django_allauth-65.19.4/tests/apps/account/test_ratelimit.py
 ===================================================================
---- django_allauth-65.14.3.orig/tests/apps/account/test_ratelimit.py   
2026-01-17 13:07:19.000000000 +0100
-+++ django_allauth-65.14.3/tests/apps/account/test_ratelimit.py        
2026-03-03 12:29:39.635505574 +0100
+--- django_allauth-65.19.4.orig/tests/apps/account/test_ratelimit.py
++++ django_allauth-65.19.4/tests/apps/account/test_ratelimit.py
 @@ -8,5 +8,5 @@ def test_case_insensitive_password_reset
      user_factory(email="[email protected]")
      resp = client.post(reverse("account_reset_password"), data={"email": 
"[email protected]"})

Reply via email to