Changelog for
python3-msal-1.16.0-2.2.noarch.rpm :
* Tue Nov 02 2021 adrian.glaubitzAATTsuse.com- Update to version 1.16.0 + New feature: Introducing a new http_cache parameter, whose documentation is available by searching http_cache (dict) from our API Reference Doc (Implementation #407). If an app utilizes this feature, it will also address #80 & #334. + Improvement: Prevent concurrent interactive flows listening on same port when running on Windows (#427) + Improvement: Detecting Regional Endpoint from env var. Also ensure the entire regional endpoint behavior needs to opt in. (#425)- from version 1.15.0 + New feature: Now both initiate_auth_code_flow() and acquire_token_interactive() accept a new optional parameter max_age which is the allowable elapsed time in seconds since the last time the End-User was actively authenticated. If the elapsed time is greater than this value, Microsoft identity platform will actively re-authenticate the End-User. (#381, #389) + Improvement: MSAL will now automatically utilize a backup authentication system, to provide better resiliency. (#376, #395, #409) + Improvement: Previously, acquire_token_interactive() was not able to be aborted by CTRL+C when running on Windows. It is now fixed. (#393, #404) + Bugfix: The http cache feature shipped in #379 came with an unexpected side effect to slow down the Device Code Flow. Now fixed. (#408, #410) + Change: Adopting cryptography 35.0.0 (#414)- from version 1.14.0 UPDATE: There was a bug in this version, being fixed in subsequent 1.15.0. We recommend everyone to upgrade to msal>=1.15.0,<2. There is no API-level change in this MSAL release. So, all existing apps do not need any code changes. Just upgrade, and your app will gain the following behaviors. + Behavior Change: By default, MSAL Python will launch Edge browser when running on Linux, when Edge is installed on current desktop. (#388) + Behavior Change: MSAL Python will use an in-memory http-level cache. This would improve the latency in normal cases, and improve responsiveness for invalid requests and outage. (#159, #379) + Behavior Change: MSAL Python will no longer use env var REGION_NAME as the Azure region name. (#394, #382) + Bugfix: MSAL Python will no longer throw exception when your app excludes the profile scope. (#387, #390)- from version 1.13.0 + New feature: MSAL supports a confidential client being authenticated by a pre-signed assertion. Usage: cca = ConfidentialClientApplication( ..., client_credential={\"client_assertion\": \"...a JWT with claims aud, exp, iss, jti, nbf, and sub...\"}, ...) This can be useful for where the signing takes place externally for example using Azure Key Vault (AKV). AKV sample included (#161, #271). + Improvement: Skip unnecessary and repetitive region detection. (#372, #373)
* Tue Jun 29 2021 adrian.glaubitzAATTsuse.com- Update to version 1.12.0 + New feature: MSAL Python supports ConfidentialClientApplication(..., azure_region=...). If your app is deployed in Azure, you can use this new feature to pin a region. (#295, #358) + New feature: Historically MSAL Python attempts to acquire a Refresh Token (RT) by default. Since this version, MSAL Python supports ConfidentialClientApplication(..., excluse_scopes=[\"offline_access\"]) to opt out of RT (#207, #361) + Improvement: acquire_token_interactive(...) can also trigger browser when running inside WSL (8d86917) + Adjustment: get_accounts(...) would automatically combine equivalent accounts, so that your account selector widget could be easier to use (#349) + Document: MSAL Python has long been accepting acquire_token_interactive(..., prompt=\"create\"), now we officially documented it. (#356, #360)- from version 1.11.0 + Enhancement: ConfidentialClientApplication also supports acquire_token_by_username_password() now. (#294, #344) + Enhancement: PublicClientApplication\'s acquire_token_interactive() also supports WSL Ubuntu 18.04 (#332, #333) + Enhancement: Enable a retry once behavior on connection error. (But this is only available from the default http client. If your app supplies your customized http_client via MSAL constructors, it is your http_client\'s job to decide whether retry.) (#326) + Enhancement: MSAL improves the internal telemetry mechanism. (#137, #175, #329, #345) + Bugfix: Better compatibility on handling SAML token when using acquire_token_by_username_password() with ADFS. (#336)
* Thu Mar 25 2021 adrian.glaubitzAATTsuse.com- Update to version 1.10.0 + Enhancement: Proactive access token (AT) refreshing. Previously, an AT is either valid or expired. If an AT expires and your network happens to have a glitch, your app wouldn\'t be able to auth. Now, MSAL Python attempts to refresh some AT (typically long-lived AT) half way towards their expiration, and silently ignores the error and retries next time, so that your app would be more resilient. All these happen automatically, without any code change to your app. (#176, #312, #320) + Adjustment: MSAL Python will keep RT in token cache even when its usage encounters an \"invalid_grant\" error, so that the RT would likely still be used by other requests. (#314, #315)- from version 1.9.0 + Enhancement: Starting from this version, MSAL will be compatible with both PyJWT 1.x and PyJWT 2.x (#293, #296) + Enhancement: Better support for upcoming Azure CLI\'s SSH extension (#300, #298) + Enhancement: Better deprecation message for get_authorization_request_url() and acquire_token_by_authorization_code(). (#301, #303) + Enhancement: Better exception message when using incorrect case in client_id. (#304, #307) + Other improvements.
* Mon Jan 11 2021 adrian.glaubitzAATTsuse.com- Update to version 1.8.0 + New feature: A new extra_scopes_to_consent parameter is introduced to the acquire_token_interactive(...) API (#212, #286) + Adjustment to previous version 1.7.0: Lazy import webbrowser module only when necessary (#287, #288)- from version 1.7.0 + New feature: A new initiate_auth_code_flow() & acquire_token_by_auth_code_flow() API, which automatically provides PKCE protection for you (#276, #255). (You are recommended to use these 2 new APIs to replace the previous get_authorization_request_url() and acquire_token_by_authorization_code().) + New feature: A new acquire_token_interactive() (#138, #260, #282), comes with a sample (#283) + Bugfix: Now MSAL Python can properly access those Refresh Tokens which were keyed slightly differently by different apps. (#279, #280)
* Thu Nov 26 2020 rjschweiAATTsuse.com- Only build Python3 flavors for distributions 15 and greater
* Fri Nov 13 2020 adrian.glaubitzAATTsuse.com- Update to version 1.6.0 + New Feature: ```ConfidentialClientApplication``` accepts private key encrypted by a passphrase. (#232, #270) + Enhancement: Provides different exception and messages while encountering transient error during tenant discovery (#263, #269)- from version 1.5.1 + Bugfix: We now cache tokens by specified environment, not by OIDC Discovery. This won\'t matter most of the time, but it can be needed when your tenant is in transitional state while migrating to a different cloud. (#247) + Bugfix: We now make sure one app\'s sign-out operation would be successful even when another app is acquiring token from cache at the same time. (#258, #262)- Update Requires from setup.py
* Tue Sep 08 2020 adrian.glaubitzAATTsuse.com- Update to version 1.5.0 + Added support for setting client capabilities to enable CAE(Continuous Access Evaluation) (#240, #174) + Device code endpoint is now fetched from open-id configuration, if available. (#245, #242) + Fixes in test cases (#239, #211)
* Fri Aug 28 2020 adrian.glaubitzAATTsuse.com- Update to version 1.4.3 + Bugfix: A side effect in previous release prevented reading some tokens from a different authority alias (#235, #236)- from version 1.4.2 + Bugfix: Changed case of messageID in WS-Trust Requests (#228 , #230 ) + Bugfix: Removed content-type header sent in request to Mex endpoint (#226 , #227 ) + Bugfix: Bypasses cache lookup for authority alias if no refresh token found (#223, #225 )- from version 1.4.1 + Reverts Application Initializer will not send network requests introduced in MSAL Python 1.4.0 (#205, #216, #187)- from version 1.4.0 + Enhancement: Application initializer will not send network requests. (#205, #187) + Enhancement: Improved handling of errors in ADAL to MSAL token migration scenario. (#209, #208) + Added changelog in PYPI (#203, #202) + Other readme and reference docs adjustments (#200, #197)
* Tue Jun 16 2020 adrian.glaubitzAATTsuse.com- Update to version 1.3.0 + New feature: class ```ClientApplication``` accepts a new optional parameter ```http_client```. You can provide your own HTTP client to have different behavior. (#169) Please refer to API Reference doc. + New feature: method ```get_authorization_request_url()``` accepts a new optional parameter ```domain_hint```. (#158, #181) Please refer to API Reference doc. + New feature: A new method ```acquire_token_by_refresh_token()``` to help migrating refresh tokens from elsewhere to MSAL Python. (#193) Its usage is demonstrated in this sample.- from version 1.2.0 + New ```nonce``` parameter is provided in ```both get_authorization_request_url(..., nonce=...)``` and ```acquire_token_by_authorization_code(..., nonce=...)``` method, so that you can use them to mitigate replay attacks, per OIDC specs. (#128, #173).- from version 1.1.0 + New ```acquire_token_silent_with_error(...)``` method to expose conditional access error classifications (#143, closes #57). + App developers can opt in to provide their app\'s name and version for Microsoft Telemetry, so that we can understand your usage pattern and serve you better. (#136 closes #130) + Internally,
* Collect anonymous telemetry data to help us improve MSAL Python (#103)
* Test cases cover ADFS 2019 on-premise scenarios (#142, closes #132)
* Switched to our latest lab apis for better test infrastructure (#108, #133, #134, #135)
* Tue Feb 18 2020 adrian.glaubitzAATTsuse.com- Initial build + Version 1.1.0