Skip to content

Releases: descope/python-sdk

1.6.3

26 Feb 12:24
3b5e69f
Compare
Choose a tag to compare

Breaking changes

  • Set an active password for a user: You can set a new active password for a user, with the set_active_password function , which they can then use to sign in. It will be applied with the project's password expiration settings, after which the user will have to update it to their own.
    Notice that we deprecated the set_password function, and now offer a set_temporary_password function instead. The functionality is the same as before (automatically expires the password, making the user reset it upon first authentication) - we just wanted to make sure it's clearer!

Enhancements

  • Tenant-level roles: Tenants can require having their own set of roles on top of the default roles provided in your application. For that, we enhanced existing roles function (create, update, delete) to support association with a specific tenant_id.
  • User impersonation: Using the impersonate function, you can decide which user you would want to temporarily sign in on behalf of. Please make sure to read our SDK's README on impersonation, as well as our KB article on the topic to fully understand this feature and how to securely use it.

1.6.2

05 Feb 10:59
f5f85b7
Compare
Choose a tag to compare

Enhancements

  • Support Bcrypt and Firebase encoding: Some systems encode passwords with the Bcrypt hashing mechanism, so we added support for importing those hashes into Descope using the InviteBatch function. We also added support for the Firebase hashing mechanism.
  • User authentication activity log: Using the new history command, you can find out more information (such as IP address, country, etc) on your users' authentications. Read more about this in the SDK's README.
  • Associate an access key with a specific user: We've added the user_id parameter to the access key create function, so that upon creation that key will be associated with the user. This means that if the user's status is change (for example - the user is disabled) - then the access key's status changes accordingly (gets deactivated).

1.6.1

28 Jan 15:34
9a402e9
Compare
Choose a tag to compare

Enhancements

  • 😮 Tenant SSO - supporting SAML and OIDC: We've recently expanded our tenant SSO support to both SAML and OIDC configurations, so we created a set of generic SSO commands that replace the existing SAML ones.
    Using the dedicated SSOSAMLSettings, SSOSAMLSettingsByMetadata and SSOOIDCSettings objects, along with their matching functions, you can define a tenant's SSO configuration settings.
    This also means that dedicated SAML authentication commands are now deprecated, and we encourage you to update your code to use the new commands:
    • saml.exchange_token >> sso.exchange_token
    • saml.start >> sso.start
  • Use external information in email/text message templates: Just like custom flow inputs, you can now provide custom template inputs that can be added to the email/text message template upon runtime. For example, you can choose to pass the user's IP into the template, to present upon verification.
  • Applications management: Applications, also known as SSO Applications, are used to integrate with an application using SAML or OIDC. Under the sso_application object, you can find an option to create, load, update and delete applications in a specific project. Find out more about applications in our documentation.
  • Associate an application to a user: You can decide to associate one or more application to a user, thus controlling which of your users has access to those apps. If the user doesn't have access - no JWT will be generated and the authentication to that application will fail.
  • Delete a flow: Using the delete_flows function, you can delete one or more flows.
  • Free search and sorting in users: Two new parameters were added to the search_all users function: text will allow searching any text value in all user attributes; sort will allow sorting the returned values alphabetically by attribute name.
  • Get recent changes in Authz schema definition: We added the get_modified authz function, to be able to understand which new targets and resources were created or updated since a certain time.

1.6.0

01 Jan 07:46
2dda1d2
Compare
Choose a tag to compare

Breaking changes

  • Support multiple domains for tenant: There's an option to automatically associated a user to a tenant based on the user's email domain. Sometimes the same tenant can 'accept' multiple domains - so that's supported now!
    Please notice that this breaks compilation - considering this value is now an array and not a string.

Enhancements

  • Appending user login IDs: We've added the option to assign multiple login IDs to a user, using the additional_login_ids parameter, upon creation and/or invitation of the user.
  • First, middle and last names of a user: We added system attributes for first (given_name), middle (middle_name) and last (family_name) of a user.
  • Control audience claim in access keys: With the new audience parameter in the exchange_access_key function - you can control the aud claim in the JWT that's created for the access key.
  • Set the user's roles: We now support the option to set an existing user's roles. Instead of fetching existing roles, removing all of them and adding new ones 'from scratch' - use the set_roles user function.
  • Check roles or permissions of a user: Check if the user has at least one of the roles in a provided list, using the get_matched_roles function. This also applies for checking permissions (get_matched_permissions), and also for checking the existence on a project level and a specific tenant level (get_matched_tenant_roles , get_matched_tenant_permissions).
  • Batch user invitation: You can now use the invite_batch function to add multiple users to your project.
  • Remove a user's passkey login IDs: Using the remove_all_passkeys management function, the Descoper can decide to remove all passkeys associated with a specific user.
  • Delete a user by its user ID: Support to delete a user by its userId property, using the new delete_by_user_id function.

Bug fixes

  • Support embedded delivery method and login options in test users: Some functionalities were left out from the test users' support, so we made sure those are quickly added.

1.5.9

29 Nov 16:06
05b5a5d
Compare
Choose a tag to compare

Enhancements

  • ReBAC support: Descope now supports an advanced and more elaborate concept of authorization, known as ReBAC. ReBAC, Relation-Based Access Control, allows defining the user's permissions based on its relationship to various objects, using a directed graph of connections between them. Read more in our README.
  • Search users by email or phone: We enabled the option to search over the user email and phone attributes - regardless if those are used as Login IDs or not.
  • Flask decorators as extra package: We've added Flask as an extra package to the SDK. This means that it is not installed by default, but only when setting the relevant flag appropriately, and installing all relevant Flask dependencies.
  • Search over tenants: Using the search_all tenants command, you can now search for all tenants based on their attribute values, such as name, self-provisioning domains, custom attributes and more.
  • Logout all user sessions: Descopers can now decide to terminate a specific user's sessions across existing devices, using the management SDK. You can do so by providing the user's Login ID (logout_user_by_user_id) or their User ID (logout_user).
  • Invitation of users using their phone number: If needed, upon inviting a user - you can configure that the invitation is sent via SMS using the sendSMS boolean flag.
  • Cloning a project: Projects can be programmatically cloned using the new clone project command. Note that this action is supported for pro and enterprise licensed customers.
  • README enhancements: Making our README more informative and full of examples for better explainability!

Bug fixes

  • Improved exception type catches: To provide as much information as we can on token validation exceptions, we've changed our existing encapsulated errors to be more specific.

1.5.8

18 Sep 11:44
7e54658
Compare
Choose a tag to compare

Enhancements

  • Setting email and phone verification status upon creation: When creating a new user, you can now control whether the email and/or phone of that user are verified or not.
  • Setting the Invitation URL via SDK: Using the new invite_url parameter, you can define a specific invitation URL when inviting a new user, that will override the default invitation URL set in your project's settings.

1.5.7

28 Aug 12:37
b3899b5
Compare
Choose a tag to compare

Enhancements

  • Password Replace return value: We're now returning the JWT's response in the password.replace function, so that the session and refresh JWTs can be utilized (for example, in flows).
  • OIDC JWT validation support: For OIDC JWT validation, we've added the option to pass the audience value to all validation functions (such as validation_session). That value will be compared to the aud claim in the JWT, so to make sure those are aligned. This is a must when using OIDC.

1.5.6

10 Aug 13:50
0d70d74
Compare
Choose a tag to compare

Enhancements

  • Embedded links: We now support the option of generating an embedded link. Using the generate_embedded_link function, the Descoper can now generate a link that contains a user's token, thus requiring only verification to finalize the authentication.
    ⚠️ Please notice that this feature needs to be turned on in the console, as it's considered an advanced feature that requires extra planning and attention when used. Make sure only permitted personnel use it, and that it is audited appropriately in the relevant places.
  • Search by user status: We've added the option to search over user statuses using the search_all function.

1.5.5

19 Jul 14:59
24a1b03
Compare
Choose a tag to compare

Breaking changes

  • Update of the configure_via_metadata and configure SSO functions: We've added two new parameters to the configure_via_metadata function - redirect_url, domain. This is to complete the SSO configuration options when using the metadata URL option.
    We've also made these parameters mandatory in the configure function (used for configuring SSO using connection details).
    Please notice that this breaks function signatures for both the configure_via_metadata and configure functions.

Enhancements

  • Load tenant by ID: We added an option to load a specific tenant, using the load tenant function.

1.5.4

05 Jul 14:52
2bbc9c0
Compare
Choose a tag to compare

Bug fixes

  • Return full error message: We fixed our errors so that more information will be provided when returned.