Skip to content

fix: allow oauthlib 4.x - #966

Open
hannonpi1228 wants to merge 2 commits into
databricks:mainfrom
hannonpi1228:fix/964-allow-oauthlib-4
Open

hannonpi1228 wants to merge 2 commits into
databricks:mainfrom
hannonpi1228:fix/964-allow-oauthlib-4

Conversation

@hannonpi1228

@hannonpi1228 hannonpi1228 commented Oct 1, 2026 •

Copy link
Copy Markdown

Closes #964

Summary

  • Widen the oauthlib constraint from ^3.1.0 to >=3.1.0,<5.0.0 so the 4.x line can be resolved.
  • Bump the locked oauthlib to 4.0.0, so this project no longer resolves a version flagged by CVE-2026-49264 / CVE-2026-49265.

Why widen rather than require >=4.0.0?

Both advisories are provider-side (RevocationEndpoint JSONP injection, and the PKCE code-verifier comparison in server-side token handling). This connector is a pure OAuth client: src/databricks/sql/auth/oauth.py only uses WebApplicationClient (prepare_authorization_request, parse_request_uri_response, prepare_request_body, prepare_refresh_body) plus OAuth2Error, none of which are affected.

So a hard >=4.0.0 floor would force-upgrade consumers and risk resolver conflicts for anyone whose other dependencies still cap oauthlib <4, with no security benefit. Keeping the 3.1.0 floor preserves compatibility, while the lock bump means the connector itself ships on the patched release and stops showing up in pip-audit output.

Validation

  • poetry run python -m pytest tests/unit with oauthlib 4.0.0 actually installed: 583 passed, 237 skipped.
  • Auth-specific suites (test_auth.py, test_oauth_persistence.py, test_token_federation.py) pass against 4.0.0, confirming the client-side API surface is unchanged.

Signed-off-by: Paddy Hannon pih@ehukai.com

Signed-off-by: Paddy Hannon <pih@ehukai.com>
AOS-Session: 01a0f91e-4c76-7691-9cc7-acaa414b4a20
AOS-Session: pi-1790885871-80347-0ea3f429
AOS-Commit-Time: 2026-10-01T20:25:07Z
Signed-off-by: Paddy Hannon <pih@ehukai.com>
AOS-Session: pi-1790885871-80347-0ea3f429
AOS-Commit-Time: 2026-10-01T20:33:15Z

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow oauthlib 4.x (fixes CVE-2026-49265 and CVE-2026-49264)

1 participant