1.31.5 — Account save and realtime write hardening
Editorial identity incomplete
2026-10-01
Closes account-save and realtime paths that could overwrite authentication secrets, sign-in identities, API keys, and protected account metadata.
Security
- A stored one-time code can no longer be written through an account save. A signed-in user could set their own phone or email verification code, and an administrator with
manage_userscould set a sign-in code on another account. - An account save can no longer replace or switch off an authenticator through a nested
totprecord. - The undocumented
permanent_passwordkey no longer sets a password. A user's own change still needs the current password, and an administrator's reset throughnew_passwordis unchanged. - A field a model declares unwritable can no longer be written through its column alias, such as
user_idforuser. An administrator could move a personal API key or a sign-in connection to another account and then sign in as that account. - An administrator can no longer change the provider identity of a sign-in connection.
- A personal API key's signing secret, and the stored tokens of sign-in connections and group API keys, can no longer be written through a save.
- The realtime
set_metamessage is removed. Any signed-in socket could overwrite account metadata, including the protected section.
Changed
- Releases publish a wheel only. No source archive is uploaded.
Upgrade notes
- A client that sent
set_metaover the websocket now gets a plain acknowledgement and nothing is written. Save account metadata through the REST API. - Posting a blocked key is ignored without an error:
secrets,permanent_password, a nestedtotp, or a sign-in connection'sprovider,provider_uid,emailoruser_id. - In your own models, a foreign key listed in
NO_SAVE_FIELDSnow also refuses its_idalias.