Commit Graph
7059 Commits
Author SHA1 Message Date
Gustavo Valverde 381fc6cfaf chore: sync main to next 2026-06-11 18:18:13 -07:00
TaesuandGitHub 24a6b01463 chore(deps): update hono and shell-quote (#10010) 2026-06-11 17:23:05 -07:00
TaesuandGitHub ac69e81a29 fix(cli): skip Unsupported() fields when regenerating prisma schema (#10011) 2026-06-11 17:19:17 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2edeb33228 chore(deps): bump the github-actions group across 1 directory with 12 updates (#9827)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 17:13:18 -07:00
Gautam ManchandaniandGitHub e0a768c973 refactor(access): flatten access plugin role authorization logic (#9677) 2026-06-11 17:04:07 -07:00
Gautam ManchandaniandGitHub 3310ebc4a0 fix(open-api): mark model ids as required (#9704) 2026-06-11 17:01:24 -07:00
108aadd251 fix(cli): update existing prisma field types (#9729)
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com>
2026-06-11 16:59:14 -07:00
Gautam ManchandaniandGitHub bf39cbf13f feat(phone-number): add server-side OTP consumption API (#9766) 2026-06-11 16:58:16 -07:00
59e0ccbedc fix(client): updateSession should infer session additional fields (#9777)
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com>
2026-06-11 16:56:45 -07:00
Gautam ManchandaniandBereket Engida 96c78c3e98 fix(logger): downgrade validation logs level to warn 2026-06-11 16:50:14 -07:00
TaesuandGitHub b36c38f984 feat(captcha)!: support wildcard endpoint matching (#10004) 2026-06-11 23:47:25 +00:00
Arnav SharmaandGitHub d3758fb2a3 fix(expo): on /linkSocial include cookie for id token (#9953) 2026-06-11 16:45:19 -07:00
5c289b52bc fix(account): resolve stateless account cookies across instances (#9979)
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com>
2026-06-11 16:44:11 -07:00
Gustavo ValverdeandGitHub 8960f5f3bd fix(client): restructure session fetch architecture (#8760) 2026-06-11 22:49:34 +00:00
TaesuandGitHub e246ac0929 ci: scope semantic-pull-request app token to pull requests (#10006) 2026-06-11 22:15:57 +00:00
Gustavo ValverdeandGitHub 7faddd4a1d refactor(core): prevent accidental HTTP exposure of server-only endpoints (#9835) 2026-06-11 20:37:51 +00:00
Gustavo ValverdeandGitHub ed7b6c9ac0 fix: enforce team capacity, constant-time SCIM tokens, and org-admin SSO domain verification (#10002) 2026-06-11 19:21:34 +00:00
Gustavo ValverdeandGitHub fdef997eb9 fix: harden provider identity validation (One Tap, Microsoft, SSO, WeChat, Reddit) (#10003) 2026-06-11 19:10:55 +00:00
7343284149 fix: jwks caching, oauth id mapping, team invitations, account cookie, and scim deprovision bugs (#9987)
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com>
2026-06-11 08:25:19 -07:00
Gustavo ValverdeandGitHub 0c3856f098 fix: harden session authority against stale cookie cache and unverified selectors (#9991) 2026-06-11 13:31:13 +00:00
Damien MasperoandGitHub e468ff37ce docs: update Node.js built-in SQLite status to Release Candidate (#9914) 2026-06-10 23:13:39 -07:00
TaesuandGitHub d9c526b2a5 feat(oauth-popup): add popup-based OAuth sign-in (#9890) 2026-06-11 05:38:22 +00:00
TaesuandGitHub 3e99e6c77e fix(admin): create credential account in setUserPassword when missing (#9482) 2026-06-11 05:36:55 +00:00
Gustavo ValverdeandGitHub baeaa00bc2 fix: make single-use credentials, counters, and replay markers atomic (#9993) 2026-06-11 05:11:26 +00:00
Gustavo ValverdeandGitHub 1dbf5bb59d fix: harden trusted request context (#9990) 2026-06-11 03:50:35 +00:00
TaesuandGitHub 9484a77805 chore: bump @better-fetch/fetch (#9989) 2026-06-11 01:09:05 +00:00
6987c628f1 fix(cli): resolve SvelteKit, Vite asset, and Cloudflare virtual-module imports (#9834)
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com>
2026-06-11 01:06:43 +00:00
Bereket EngidaGitHubcubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>Copilot Autofix powered by AI
b803c61fdc fix(organization): reject setting unknown or empty roles on updateMemberRole (#9962)
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-06-10 16:57:24 -07:00
better-release[bot]andGitHub 8b1e759c07 chore: release v1.7.0-beta.5 (#9905) @better-auth/api-key@1.7.0-beta.5 @better-auth/cimd@1.7.0-beta.5 @better-auth/core@1.7.0-beta.5 @better-auth/drizzle-adapter@1.7.0-beta.5 @better-auth/electron@1.7.0-beta.5 @better-auth/expo@1.7.0-beta.5 @better-auth/i18n@1.7.0-beta.5 @better-auth/kysely-adapter@1.7.0-beta.5 @better-auth/memory-adapter@1.7.0-beta.5 @better-auth/mongo-adapter@1.7.0-beta.5 @better-auth/oauth-provider@1.7.0-beta.5 @better-auth/passkey@1.7.0-beta.5 @better-auth/prisma-adapter@1.7.0-beta.5 @better-auth/redis-storage@1.7.0-beta.5 @better-auth/scim@1.7.0-beta.5 @better-auth/sso@1.7.0-beta.5 @better-auth/stripe@1.7.0-beta.5 @better-auth/telemetry@1.7.0-beta.5 @better-auth/test-utils@1.7.0-beta.5 auth@1.7.0-beta.5 better-auth@1.7.0-beta.5 v1.7.0-beta.5 2026-06-10 12:34:04 -07:00
Gustavo ValverdeandGitHub c20ebaf06d chore: sync main to next
chore: sync main to next
2026-06-10 12:16:54 -07:00
TaesuandGitHub a11a706ff2 fix(stripe): correct subscription handling and customer linking (#9971) 2026-06-10 18:58:40 +00:00
Gustavo Valverde d7bba8ee33 Merge origin/next into chore/sync-main-to-next 2026-06-10 11:34:38 -07:00
Gustavo Valverde bf7f2c5b4e chore: sync main to next 2026-06-10 11:30:38 -07:00
Eric LuceandGitHub 82dbc9b8bf docs: add ProofKit FileMaker adapter (#9980) 2026-06-10 11:26:02 -07:00
Prakash KumarandGitHub 128bc34572 docs: add horizontal scrolling to landing page code block (#9975) 2026-06-09 23:22:24 -07:00
better-release[bot]andGitHub 1a3c8c478a chore: release v1.6.16 (#9958) @better-auth/api-key@1.6.16 @better-auth/core@1.6.16 @better-auth/drizzle-adapter@1.6.16 @better-auth/electron@1.6.16 @better-auth/expo@1.6.16 @better-auth/i18n@1.6.16 @better-auth/kysely-adapter@1.6.16 @better-auth/memory-adapter@1.6.16 @better-auth/oauth-provider@1.6.16 @better-auth/prisma-adapter@1.6.16 @better-auth/redis-storage@1.6.16 @better-auth/scim@1.6.16 @better-auth/sso@1.6.16 @better-auth/stripe@1.6.16 @better-auth/telemetry@1.6.16 @better-auth/test-utils@1.6.16 auth@1.6.16 better-auth@1.6.16 v1.6.16 @better-auth/passkey@1.6.16 @better-auth/mongo-adapter@1.6.16 2026-06-09 22:32:25 -07:00
Bereket EngidaandGitHub cb1cbfa4cc fix: address bug findings across packages (#9974) 2026-06-09 19:46:12 -07:00
Gustavo ValverdeandGitHub 0e1770ac75 feat(oauth-provider)!: enforce max_age (#9936) 2026-06-09 19:36:30 -07:00
Gustavo ValverdeandGitHub a6b0295df3 fix(sso): consume SAML AuthnRequest atomically (#9972) 2026-06-10 01:58:45 +00:00
Gustavo ValverdeandGitHub 87e7aa5e0f fix(api): validate Origin/Referer on cookieless email sign-in and sign-up (#9973) 2026-06-10 01:43:41 +00:00
Gustavo ValverdeandGitHub 893cf6cb3f fix(session): honor server-side session deletion in update-session and token routes (#9967) 2026-06-10 00:42:45 +00:00
Gustavo ValverdeandGitHub 76a33429fc fix(session): fire session-delete hooks for preserved sessions on secondaryStorage (#9969) 2026-06-10 00:40:56 +00:00
Gustavo ValverdeandGitHub 3e852a2650 fix(oauth-provider): report unsupported_token_type for JWT access-token revocation (#9970) 2026-06-10 00:39:26 +00:00
Gustavo ValverdeandGitHub 7abaaed53f fix(oauth-provider): make private_key_jwt jti single-use atomic across processes (#9964) 2026-06-10 00:36:06 +00:00
Gustavo ValverdeandGitHub ec8a38c08f feat(generic-oauth): verify discovery id_tokens and enable id_token sign-in (#9966) 2026-06-10 00:34:26 +00:00
Gustavo ValverdeandGitHub 5e49c56a9e fix(auth): mark plugin-owned session fields as non-input (#9965) 2026-06-09 23:59:09 +00:00
TaesuandGitHub 2ac00fe421 chore: bump better-call and @better-fetch/fetch (#9955) 2026-06-09 21:34:16 +00:00
TaesuandGitHub 2545b7bb13 chore: drop two-factor-newsession-null.md changeset (#9960) 2026-06-09 14:24:28 -07:00
Paola Estefanía de CamposandGitHub afcb4dd7f3 docs(two-factor): document newSession is null during 2FA challenge (#9957) 2026-06-09 13:15:00 -07:00
TaesuandGitHub 6a8dfa4f3e docs(changelog): show contributor avatars with proper size and styling (#9956) 2026-06-09 19:44:32 +00:00