Commit Graph
7446 Commits
Author SHA1 Message Date
Taesu 17ce1a909f docs: refine 1.7 release guidance 2026-08-18 04:03:38 +09:00
Taesu e3007954fb docs: simplify 1.7 release title 2026-08-18 03:35:50 +09:00
Gustavo ValverdeandCursor 8c0bc6e535 docs: clarify 1.7 OAuth section heading
Use an audience-focused heading instead of subjective provider praise.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-17 12:53:45 -04:00
Gustavo ValverdeandCursor 96ac240e89 docs: improve 1.7 release introduction
Lead with audience-focused outcomes and surface migration guidance before the detailed highlights.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-17 09:32:17 -04:00
Gustavo ValverdeandCursor c32465e741 docs: fix prerelease guidance link
Point prerelease adopters to the release candidate post instead of a removed upgrade-guide section.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-17 09:09:39 -04:00
Gustavo ValverdeandCursor 437033c662 docs: announce Better Auth 1.7
Publish the stable release overview and remove release-candidate CLI guidance from the upgrade path.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-17 08:55:49 -04:00
better-release[bot]andGitHub bc93b27542 chore: release v1.7.0-rc.6 (#10772) v1.7.0-rc.6 2026-08-14 14:15:16 -04:00
Gustavo ValverdeandGitHub 14975fbf4b chore: sync main to next
chore: sync main to next
2026-08-14 14:13:30 -04:00
Gustavo ValverdeandGitHub f451d1c758 fix(oauth-provider): complete RP-initiated logout flow (#10812) 2026-08-14 17:35:54 +00:00
Gustavo ValverdeandGitHub 801968e354 fix(oauth-provider): accept issuer audience for client assertions (#10811) 2026-08-14 17:35:53 +00:00
Taesu 80799e6931 chore: sync main to next 2026-08-14 09:19:43 +09:00
better-release[bot]GitHubgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
86faaee69b chore: release v1.6.28 (#10796)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
v1.6.28
2026-08-13 22:29:39 +00:00
TaesuandGitHub 773de54b18 fix(client): deduplicate settled session requests during Suspense retries (#10769) 2026-08-13 22:04:08 +00:00
TaesuandGitHub 396120120f fix(oauth-provider): require openid for claims requests (#10791) 2026-08-13 19:10:37 +00:00
TaesuandGitHub a966815b13 fix(oauth-provider): handle voluntary and essential ACR requests (#10790) 2026-08-13 19:10:36 +00:00
TaesuandGitHub 8e85b12a62 docs(core): clarify dynamic base URL proxy trust (#10779) 2026-08-13 15:16:04 -04:00
TaesuandGitHub 80592e6d17 docs(sso): align SAML release notes with final behavior (#10797) 2026-08-13 15:15:24 -04:00
TaesuandGitHub 588c87d8b6 docs(scim): align release notes with final model (#10795) 2026-08-13 15:15:09 -04:00
TaesuandGitHub 2ad2928f96 fix(build): restore declaration compatibility (#10794) 2026-08-13 18:21:53 +00:00
TaesuandGitHub c92a1ca27b chore: upgrade next to 16.3 (#10787) 2026-08-13 18:06:00 +00:00
TaesuandGitHub df1163a3d5 docs(oauth): qualify transaction rollback guarantee (#10777) 2026-08-13 17:58:16 +00:00
TaesuandGitHub 4d1e04a2af docs(db): clarify unique column migrations (#10778) 2026-08-13 17:41:00 +00:00
TaesuandGitHub 3e485bf730 docs(username): fix displayUsername release notes (#10776) 2026-08-13 17:40:34 +00:00
65fc17c755 fix(deps): align drizzle-orm peer range with drizzle-adapter (#10501)
Co-authored-by: Taesu <bytaesu@gmail.com>
2026-08-13 16:12:15 +00:00
Toms SokolovsandGitHub d9b3e3d17b docs: add Mailtrap as an email provider example (#10765) 2026-08-12 18:34:56 +00:00
Hussein AhmadandGitHub c8e047a10a docs: add better-auth-azure-cosmos to community adapters (#10768) 2026-08-12 18:30:20 +00:00
Fabian HillerandGitHub 11b91e27c3 docs: fix validator JSDoc to mention Standard Schema (#10761) 2026-08-12 18:29:40 +00:00
TaesuandGitHub c35c41ef2a docs: rewrite Hono integration guide (#10763) 2026-08-12 18:25:44 +00:00
692b22c517 fix(drizzle): export generated pgSchema for drizzle-kit (#10770)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-12 16:25:58 +00:00
better-release[bot]andGitHub acbe42128f chore: release v1.7.0-rc.5 (#10704) v1.7.0-rc.5 2026-08-11 18:12:57 -04:00
Gustavo ValverdeandGitHub 3ca2c08dc3 fix(device-authorization): enforce RFC device flow requirements (#10752) 2026-08-11 18:05:25 -04:00
6782647d7c refactor(oauth-provider)!: separate device grant ownership (#10746)
Co-authored-by: Taesu <166604494+bytaesu@users.noreply.github.com>
2026-08-11 19:45:23 +00:00
Gustavo ValverdeandGitHub 26e05cdecd chore: sync main to next
chore: sync main to next
2026-08-11 15:30:36 -04:00
Gustavo Valverde 4052cfea74 refactor(cli): derive upgrade packages from release config 2026-08-11 15:15:10 -04:00
Gustavo Valverde ebf5ae2145 test(cli): enforce release-train upgrade coverage 2026-08-11 15:11:37 -04:00
Gustavo Valverde 1fa55595e8 test(sso): exercise provider pagination boundary 2026-08-11 15:11:30 -04:00
Gustavo Valverde 74270029c7 fix(docs): classify AI rate limits contextually 2026-08-11 14:53:18 -04:00
Gustavo Valverde dfa95cf560 fix(cli): limit version alignment to release train 2026-08-11 14:53:12 -04:00
Gustavo Valverde 5071415398 fix(sso): harden domain organization assignment 2026-08-11 14:53:03 -04:00
Gustavo Valverde 970fd0cc9f test(sso): align legacy provider fixture 2026-08-11 14:15:27 -04:00
Gustavo Valverde 73d6f80e5b chore(sync): merge main into next 2026-08-11 14:14:49 -04:00
better-release[bot]andGitHub be47e9418b chore: release v1.6.27 (#10686) v1.6.27 2026-08-11 13:56:17 -04:00
999acbd41d Merge commit from fork
* fix(sso): bind domain verification to provider state

Complete domain verification with an atomic guarded transition keyed by the provider row, exact domain snapshot, and unverified state. Concurrent provider mutations now return a retryable conflict instead of applying stale DNS proof.

Document the conflict behavior and cover provider mutation, replacement, deletion, simultaneous verification, memory-adapter, and downstream trust cases.

* fix(sso): allow domain verification when the stored bit is null

* test(sso): assert the resolved DNS hostname outside the mock callback

* fix(sso): require verified domains for organization assignment

Use verified persisted provider domains and canonical verified user emails for domain-derived routing and organization membership. Keep explicit organization-bound SSO provisioning separate from domain trust.

* fix(sso): scope domain verification to organization assignment

* fix(sso): keep verified provider lookup internal

---------

Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com>
2026-08-11 13:50:45 -04:00
TaesuandGitHub b8077b74ef fix(cli): align packages with running CLI version (#10743) 2026-08-10 16:47:54 +00:00
TaesuandGitHub d79740cb9c docs(two-factor): align enrollment guidance with current behavior (#10745) 2026-08-10 12:45:03 -04:00
TaesuandGitHub 6e227c42c5 docs: clarify remaining 1.7 migration details (#10744) 2026-08-10 12:44:18 -04:00
81ef812251 docs: align the 1.7 migration guide with current behavior (#10742)
Co-authored-by: Taesu <bytaesu@gmail.com>
2026-08-10 11:56:27 -04:00
8a3fa826e1 docs: make AI chat failures recoverable (#10737)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-10 15:11:39 +00:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
95e248eb88 chore(deps): bump mermaid from 11.15.0 to 11.16.1 (#10715)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-07 12:30:18 +00:00
TaesuandGitHub 2ae491eac3 fix(types): align auth endpoints with better-call (#10657) 2026-08-07 11:33:52 +00:00