Skip to content

Bump fastapi-sso from 0.21.0 to 0.22.0 in /backend - #1860

Merged
github-actions[bot] merged 1 commit into
masterfrom
dependabot/uv/backend/fastapi-sso-0.22.0
Oct 6, 2026
Merged

github-actions[bot] merged 1 commit into
masterfrom
dependabot/uv/backend/fastapi-sso-0.22.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps fastapi-sso from 0.21.0 to 0.22.0.

Release notes

Sourced from fastapi-sso's releases.

0.22.0

⚠️ Security fix and breaking change

This release fixes an OAuth login CSRF vulnerability (GHSA-wgrh-7h2j-rg46, CWE-352), reported by @​mohammedix88 (cystack.ps redteam).

SSOBase.requires_state defaulted to False, so the state validation added in 0.19.0 never ran unless you opted in. Any application on the default configuration accepted a callback with nothing bound to the caller's session. Upgrading is recommended for all users.

requires_state now defaults to True. A login flow that does not carry the sso_state cookie back to your callback will now fail with 401 State cookie not found. This affects you if:

  • you do not use the SSO instance as a context manager (async with sso:), so no state is generated
  • your login and callback endpoints are served from different hosts, so the browser does not return the cookie
  • you build the redirect yourself from get_login_url, which returns a URL and sets no cookie. This now emits a SecurityWarning at login time, so you will see it before your users do

If you cannot carry the cookie, you can opt out per instance and keep the old behaviour, at the cost of losing CSRF protection:

sso = GoogleSSO(client_id, client_secret, redirect_uri)
sso.requires_state = False

The sso_state cookie is now also set HttpOnly, SameSite=lax, and Secure unless allow_insecure_http is enabled.

What's Changed

New Contributors

Full Changelog: tomasvotava/fastapi-sso@0.21.1...0.22.0

0.21.1

Dependencies-only release

... (truncated)

Commits
  • 2aa5389 bump: => v0.22.0
  • bbb1ace fix!: enforce OAuth state validation by default (#307)
  • 60838d6 chore(deps-dev): bump the all group with 2 updates (#306)
  • 797cc66 chore(deps-dev): bump the all group with 3 updates (#305)
  • 8bb74dc chore(deps-dev): bump the all group with 3 updates (#303)
  • e29bf01 chore(deps-dev): bump uvicorn from 0.52.0 to 0.52.1 in the all group (#302)
  • c2e4310 chore(deps): bump the all group with 3 updates (#301)
  • 3a7af3c chore(deps): bump the all group with 3 updates (#300)
  • 88b4d55 chore(deps): bump the all group with 4 updates (#299)
  • cd52f19 chore(deps-dev): bump the all group with 4 updates (#298)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [fastapi-sso](https://github.com/tomasvotava/fastapi-sso) from 0.21.0 to 0.22.0.
- [Release notes](https://github.com/tomasvotava/fastapi-sso/releases)
- [Commits](tomasvotava/fastapi-sso@0.21.0...0.22.0)

---
updated-dependencies:
- dependency-name: fastapi-sso
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 6, 2026
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying bracket-demo with  Cloudflare Pages  Cloudflare Pages

Latest commit: 0bce33b
Status:⚡️  Build in progress...

View logs

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 6, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) October 6, 2026 04:09
@github-actions
github-actions Bot merged commit 9fabbd7 into master Oct 6, 2026
5 of 6 checks passed
@github-actions
github-actions Bot deleted the dependabot/uv/backend/fastapi-sso-0.22.0 branch October 6, 2026 04:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants