Skip to content

fix: allow oauthlib 4.x - #971

Merged
vuanhphung merged 3 commits into
mainfrom
vu-phung/allow-oauthlib-4
Oct 6, 2026
Merged

vuanhphung merged 3 commits into
mainfrom
vu-phung/allow-oauthlib-4

Conversation

@vuanhphung

Copy link
Copy Markdown
Collaborator

What type of PR is this?

  • Bug Fix

Description

Widens the oauthlib constraint from ^3.1.0 to >=3.1.0,<5.0.0 and locks 4.0.0, so downstream consumers can pick up the fixes for CVE-2026-49264 and CVE-2026-49265, which are only available in oauthlib 4.0.0. Both advisories are in oauthlib's provider-side code. The connector only uses WebApplicationClient and OAuth2Error, which behave the same in 4.0.0. The 3.1.0 floor stays so consumers whose other dependencies cap oauthlib below 4 don't hit resolver conflicts.

This carries @hannonpi1228's commits from #966, rebased onto main, so the checks that need repository secrets (DBR LTS Install) can run. Those checks can't run on fork PRs. The extra commit only reverts lock-file formatting churn from Poetry 2.3.2 back to the CI-pinned 2.2.1.

How is this tested?

  • Unit tests
  • Manually

The full unit suite passes with oauthlib 4.0.0 installed. I ran the four WebApplicationClient calls the connector makes under oauthlib 3.3.1 and 4.0.0, and they produce identical output. poetry check --lock passes with Poetry 2.2.1.

Related Tickets & Documents

Closes #964
Based on #966

This pull request and its description were written by Isaac.


This PR was created with GitHub MCP.

hannonpi1228 and others added 3 commits October 6, 2026 05:00
Signed-off-by: Paddy Hannon <pih@ehukai.com>
AOS-Session: 01a0f91e-4c76-7691-9cc7-acaa414b4a20
AOS-Session: pi-1790885871-80347-0ea3f429
AOS-Commit-Time: 2026-10-01T20:25:07Z
Signed-off-by: Vu Anh Phung <vu.phung@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: Paddy Hannon <pih@ehukai.com>
AOS-Session: pi-1790885871-80347-0ea3f429
AOS-Commit-Time: 2026-10-01T20:33:15Z
Signed-off-by: Vu Anh Phung <vu.phung@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Revert formatting-only churn from regenerating the lock with Poetry 2.3.2 so the lock matches the Poetry version CI pins. No dependency changes.

Signed-off-by: Vu Anh Phung <vu.phung@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>

@peco-review-bot peco-review-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No issues identified by the review bot.

@vuanhphung vuanhphung added integration-test Triggers proxy-based integration tests; auto-removed on new commits. kernel-e2e Trigger preview run of the Kernel E2E workflow on this PR labels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Integration tests triggered. View workflow runs. Result posts back here as the "Python Integration Tests" check.

1 similar comment
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Integration tests triggered. View workflow runs. Result posts back here as the "Python Integration Tests" check.

@vuanhphung
vuanhphung merged commit 21d288f into main Oct 6, 2026
92 of 96 checks passed
@vuanhphung
vuanhphung deleted the vu-phung/allow-oauthlib-4 branch October 6, 2026 16:47

This branch was successfully deployed

1 active deployment
azure-prod — 2131eef8 Deployed Oct 6, 2026 by vuanhphung via run-kernel-e2e #589
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-assisted integration-test Triggers proxy-based integration tests; auto-removed on new commits. kernel-e2e Trigger preview run of the Kernel E2E workflow on this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow oauthlib 4.x (fixes CVE-2026-49265 and CVE-2026-49264)

3 participants