Skip to content

fix: allow oauthlib 4.x - #971

Merged
vuanhphung merged 3 commits into
mainfrom
vu-phung/allow-oauthlib-4
Oct 6, 2026
Merged

vuanhphung merged 3 commits into
mainfrom
vu-phung/allow-oauthlib-4

Conversation

@vuanhphung

Copy link
Copy Markdown
Collaborator

What type of PR is this?

  • Bug Fix

Description

Widens the oauthlib constraint from ^3.1.0 to >=3.1.0,<5.0.0 and locks 4.0.0, so downstream consumers can pick up the fixes for CVE-2026-49264 and CVE-2026-49265, which are only available in oauthlib 4.0.0. Both advisories are in oauthlib's provider-side code. The connector only uses WebApplicationClient and OAuth2Error, which behave the same in 4.0.0. The 3.1.0 floor stays so consumers whose other dependencies cap oauthlib below 4 don't hit resolver conflicts.

This carries @hannonpi1228's commits from #966, rebased onto main, so the checks that need repository secrets (DBR LTS Install) can run. Those checks can't run on fork PRs. The extra commit only reverts lock-file formatting churn from Poetry 2.3.2 back to the CI-pinned 2.2.1.

How is this tested?

  • Unit tests
  • Manually

The full unit suite passes with oauthlib 4.0.0 installed. I ran the four WebApplicationClient calls the connector makes under oauthlib 3.3.1 and 4.0.0, and they produce identical output. poetry check --lock passes with Poetry 2.2.1.

Related Tickets & Documents

Closes #964
Based on #966

This pull request and its description were written by Isaac.


This PR was created with GitHub MCP.

hannonpi1228 and others added 3 commits October 6, 2026 05:00
Signed-off-by: Paddy Hannon <pih@ehukai.com>
AOS-Session: 01a0f91e-4c76-7691-9cc7-acaa414b4a20
AOS-Session: pi-1790885871-80347-0ea3f429
AOS-Commit-Time: 2026-10-01T20:25:07Z
Signed-off-by: Vu Anh Phung <vu.phung@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: Paddy Hannon <pih@ehukai.com>
AOS-Session: pi-1790885871-80347-0ea3f429
AOS-Commit-Time: 2026-10-01T20:33:15Z
Signed-off-by: Vu Anh Phung <vu.phung@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Revert formatting-only churn from regenerating the lock with Poetry 2.3.2 so the lock matches the Poetry version CI pins. No dependency changes.

Signed-off-by: Vu Anh Phung <vu.phung@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>

@peco-review-bot peco-review-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No issues identified by the review bot.

@vuanhphung vuanhphung added integration-test Triggers proxy-based integration tests; auto-removed on new commits. kernel-e2e Trigger preview run of the Kernel E2E workflow on this PR labels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Integration tests triggered. View workflow runs. Result posts back here as the "Python Integration Tests" check.

1 similar comment
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Integration tests triggered. View workflow runs. Result posts back here as the "Python Integration Tests" check.

@vuanhphung
vuanhphung merged commit 21d288f into main Oct 6, 2026
92 of 96 checks passed
@vuanhphung
vuanhphung deleted the vu-phung/allow-oauthlib-4 branch October 6, 2026 16:47
@justin-castillo-snz

Copy link
Copy Markdown

Thanks for merging this fix. Our approved package mirror blocks OAuthlib 3.x due to the security advisories, so connector 4.6.0 cannot resolve. Is there an ETA for a PyPI release containing #971, or could this be shipped as a patch release?

This branch was successfully deployed

1 active deployment
azure-prod — 2131eef8 Deployed Oct 6, 2026 by vuanhphung via run-kernel-e2e #589
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-assisted integration-test Triggers proxy-based integration tests; auto-removed on new commits. kernel-e2e Trigger preview run of the Kernel E2E workflow on this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow oauthlib 4.x (fixes CVE-2026-49265 and CVE-2026-49264)

4 participants