Skip to content

Python dependency: Update flask-security-too requirement from <5.9,>=5.8.2 to >=5.9.1,<5.10 - #10516

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/flask-security-too-gte-5.9.1-and-lt-5.10
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/flask-security-too-gte-5.9.1-and-lt-5.10

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on flask-security-too to permit the latest version.

Release notes

Sourced from flask-security-too's releases.

Release 5.9.1

This is a patch release to fix an open-redirect vulnerability - GHSA-ccgp-pv8r-95wm

Changelog

Sourced from flask-security-too's changelog.

Version 5.9.1

Released September 30, 2026

Fixes +++++ -(:pr:1293) Fix for open-redirect GHSA-ccgp-pv8r-95wm

Version 5.9.0

Released September 24, 2026

This release adds support for refresh tokens (finally!). In addition there are several configuration changes that try to align Flask-Security with latest best-practices.

Please read these notes carefully - in particular the change to the default auth token lifetime might severely impact some applications.

Features & Improvements +++++++++++++++++++++++

  • (:issue:1206) Add support for refresh tokens. See :ref:token_topic
  • (:pr:1233) Change :py:data:SECURITY_TOKEN_MAX_AGE from an int to a timedelta. Also - change default from never expire to 15 minutes.
  • (:pr:1235) Change default :py:data:SECURITY_LOGOUT_METHODS to be just "POST"
  • (:issue:1228) Change default csrf and tf_validity cookie config to secure=True
  • (:issue:1228) The tf_validity cookie name is now configurable via :py:data:SECURITY_TWO_FACTOR_VALIDITY_COOKIE_NAME
  • (:issue:1237) Add support for CSRF on logout (default False)
  • (:pr:1241) Convert all _WITHIN configuration variables to use timedelta
  • (:issue:1153) Enable localization of %(within)s variables using humanize
  • (:pr:1249) Add link expiration to confirmation and reset password email templates.
  • (:issue:536 Add template path configuration variables for all email templates.
  • (:issue:1254) Webauthn/passkey name input value is now sanitized and normalized. A new utility method :py:meth:flask_security.input_svn is now used and is available for applications to use.
  • (:pr:1271) Username validation and normalization now uses the new :py:meth:flask_security.input_svn utility. This has some backwards compatibility concerns - see below.
  • (:pr:1259) Allow redirects to exactly :py:data:SECURITY_REDIRECT_BASE_DOMAIN by adding '.' to :py:data:SECURITY_REDIRECT_ALLOWED_SUBDOMAINS.

Fixes +++++

  • (:issue:1108) /verify and /us-verify forms now include the optional next field so form-posted redirect URLs are validated and preserved. (DSeaStar)
  • (:issue:1212) Newly introduced :py:meth:.UserMixin.is_locked logic is inverted.
  • (:pr:1234) Fix for GHSA-f66q-9rf6-8795 - WebAuthn reauthentication freshness bypass. (tonghuaroot)
  • (:issue:1244) Fix login form remember me checkbox.
  • (:pr:1258) A JSON request body can set a form field (email, password, username, identity, name, phone, refresh token, recovery/2FA code, ...) to a non-string value (e.g. a dict), which used to crash with an unhandled

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [flask-security-too](https://github.com/pallets-eco/flask-security) to permit the latest version.
- [Release notes](https://github.com/pallets-eco/flask-security/releases)
- [Changelog](https://github.com/pallets-eco/flask-security/blob/main/CHANGES.rst)
- [Commits](pallets-eco/flask-security@5.8.2...5.9.1)

---
updated-dependencies:
- dependency-name: flask-security-too
  dependency-version: 5.9.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the Dependencies Pull requests that update a dependency file label Oct 9, 2026
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: pgadmin-org/pgadmin4/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: fe95e63e-8650-4c8f-b935-f899e06e2574

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dpage

dpage commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Flask-Security-Too 5.9 requires Python 3.11+ (our > '3.9' marker covers 3.10, so install fails) and removes flask_security.utils.get_post_login_redirect, which web/pgadmin/utils/__init__.py imports; taking it needs a split pin and code changes. The open-redirect fix (GHSA-ccgp-pv8r-95wm) is also in 5.8.3, which the existing pin already allows.

@dpage dpage closed this Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/flask-security-too-gte-5.9.1-and-lt-5.10 branch October 9, 2026 23:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant