ea06c5a71f
feat(drizzle-adapter): support Drizzle Relations v2 ( #9489 )
...
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com >
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
Co-authored-by: Taesu <bytaesu@gmail.com >
Co-authored-by: Taesu <166604494+bytaesu@users.noreply.github.com >
2026-06-26 11:01:48 +00:00
Gustavo Valverde and GitHub
50d15280b1
chore: sync main to next
...
chore: sync main to next
2026-06-26 08:44:45 +01:00
Gustavo Valverde
7cae0f2a77
fix: keep siwe reservation fallback best-effort
2026-06-26 08:26:53 +01:00
Gustavo Valverde
f291e5ba74
fix: address sync review fallout
2026-06-26 08:09:34 +01:00
Gustavo Valverde
d46b8bee4f
fix: tighten remaining sync review fixes
2026-06-26 07:45:19 +01:00
Gustavo Valverde
cc1aed88d3
fix: address sync review feedback
2026-06-26 07:42:55 +01:00
Gustavo Valverde
4bcda56649
chore: resolve 10178 main-to-next sync conflicts
...
Merges origin/main into origin/next for the replacement sync PR and records the hand-resolved package metadata, changelog, OAuth/social provider, admin, SIWE, SCIM, SSO, username, rate-limiter, and next-owned MCP/OIDC provider conflicts.
2026-06-26 06:33:24 +01:00
better-release[bot] and GitHub
414169d95a
chore: release v1.6.21 ( #10184 )
v1.6.21
2026-06-26 05:52:50 +01:00
f52e1ab50b
fix(device-authorization): make schema option optional under Zod v4 ( #9939 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
Co-authored-by: ping-maxwell <maxwell.multinite@gmail.com >
2026-06-26 05:48:15 +01:00
Gustavo Valverde and GitHub
f395c30e95
ci(release): skip pre-commit hooks for the release bot commit ( #10233 )
2026-06-26 05:33:13 +01:00
882cf9e592
fix(admin): use authoritative session reads for authorization ( #10187 )
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-26 04:09:16 +00:00
b5bec193a5
fix(oauth): apply user input rules to provider profiles ( #10196 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-26 04:06:54 +00:00
Taesu and GitHub
471f81c1ab
refactor: centralize request IP resolver in core ( #10216 )
2026-06-26 05:05:00 +01:00
90d509e0b9
fix(adapter): fail closed on update misses ( #10180 )
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-26 03:56:39 +00:00
816d7f9252
fix(one-tap): apply configured Google hosted domain (hd) on the callback ( #10197 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-26 03:56:20 +00:00
Gustavo Valverde and GitHub
5838df2f41
feat(oauth-provider): add refresh token reuse interval ( #10145 )
2026-06-26 03:49:27 +00:00
fa1e036ae7
fix(sso): validate SAML response binding against the Service Provider ( #10226 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-26 03:07:43 +00:00
7a7a7b311a
fix(sso): delete linked account rows when an SSO provider is deleted ( #10224 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-26 03:07:21 +00:00
fcabaaffcb
fix(sso): require DNS proof for every domain listed on a provider ( #10227 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-26 02:49:15 +00:00
1a8b7ccc83
fix(sso): restrict SAML SLO POST form action to http(s) schemes ( #10225 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-06-26 02:27:12 +00:00
Gustavo Valverde and GitHub
1bc370aef5
fix(siwe): reject sign-in when the provided email already belongs to another account ( #10228 )
2026-06-26 02:21:45 +00:00
Taesu and GitHub
5f86c3bed7
docs: restore lubiah community adapter ( #10230 )
2026-06-25 13:44:27 -07:00
Taesu and GitHub
29fbcb5732
Merge commit from fork
...
Organization subscription actions re-derived the reference id in the handler
instead of consuming the value the middleware resolved, so an action could run
against a different organization than the one resolved for the request. The
middleware now resolves the reference id once and exposes it on the context, and
the handlers read it from there.
2026-06-25 11:21:12 -07:00
Maxwell and GitHub
82cbbd6f1d
docs: add missing disable-implicit-linking docs ( #10218 )
2026-06-25 10:59:14 +00:00
Gustavo Valverde and GitHub
ae647b4abe
fix(two-factor): cap verification attempts on TOTP and backup codes ( #10210 )
2026-06-25 06:49:09 +00:00
5953157acf
fix: harden forwarded client IP resolution ( #10203 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-25 04:55:10 +00:00
Taesu and GitHub
5af69e4b50
test: cover base path leading-prefix enforcement ( #10211 )
2026-06-25 00:51:21 +00:00
Taesu and GitHub
e0762a127c
chore: bump better-call to 1.3.7 ( #10212 )
2026-06-25 00:30:07 +00:00
452bd03f74
fix(cli): increase generated BETTER_AUTH_SECRET length from 16 to 32 … ( #10186 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-24 21:52:53 +00:00
Taesu and GitHub
88409b0078
fix(oauth-proxy): reject profile callbacks with missing or expired OAuth state ( #10183 )
2026-06-24 19:41:43 +00:00
b046f9ec11
fix: apply rate limits before plugin requests ( #10191 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-06-24 11:51:11 +00:00
Rachit mittal and GitHub
570267cd5e
fix: honor disableMigration on plugin schema tables ( #10198 )
2026-06-24 00:19:25 +00:00
Taesu and GitHub
239bcc836c
fix(paypal): bind userinfo subject to verified id token subject ( #10192 )
2026-06-23 00:23:56 +00:00
Taesu and GitHub
e7c8066cf1
docs: refine warning guidance across plugin docs ( #10185 )
2026-06-21 22:39:30 -07:00
Taesu and GitHub
461ca6fd24
fix(username): only store valid displayUsername fallbacks as usernames ( #10182 )
2026-06-22 05:16:44 +00:00
moonevm and GitHub
6e5f7e656b
docs: fix the code block format on the Stripe plugin page ( #10181 )
2026-06-21 02:31:43 -07:00
bdda5162f9
docs: remove extra spaces in documentation ( #10174 )
...
Co-authored-by: Taesu <166604494+bytaesu@users.noreply.github.com >
2026-06-20 22:48:59 -07:00
Gustavo Valverde and GitHub
6ddb5554c0
chore(deps)!: upgrade dependencies to latest ( #10170 )
2026-06-20 10:15:37 -07:00
Gustavo Valverde and GitHub
324db9c322
chore: sync main to next
...
chore: sync main to next
2026-06-20 09:23:28 -07:00
Gustavo Valverde
3b170f2f40
chore: sync main to next
2026-06-20 09:15:00 -07:00
better-release[bot] and GitHub
c342f42fff
chore: release v1.6.20 ( #10108 )
v1.6.20
2026-06-19 19:42:38 -07:00
Taesu and GitHub
6909ddfdf6
ci(cspell): add custom words for tracked files ( #10168 )
2026-06-19 19:39:22 -07:00
Taesu and GitHub
0017ec0186
ci: check spelling on tracked files ( #10167 )
2026-06-19 19:18:54 -07:00
Roman Sirokov and GitHub
58549652dd
docs: fix open in markdown url ( #10162 )
2026-06-20 02:06:21 +00:00
better-release[bot] and GitHub
4218161c53
chore: release v1.7.0-beta.9 ( #10141 )
v1.7.0-beta.9
2026-06-19 18:12:18 -07:00
Gustavo Valverde and GitHub
e3125e872d
feat(oauth-provider): honor requested UserInfo claims via a claim registry ( #10156 )
2026-06-19 18:08:35 -07:00
Gustavo Valverde and GitHub
7d1288e7c5
fix(oauth-provider): make redirect_uri conditional at the token endpoint ( #10159 )
2026-06-19 15:03:25 -07:00
Taesu and GitHub
40138db6ed
chore: add coverage script to adapter packages ( #10158 )
2026-06-19 13:48:34 -07:00
Gustavo Valverde and GitHub
5ac62493ef
fix(oauth-provider): accept UserInfo form-body tokens ( #10155 )
2026-06-19 11:57:22 -07:00
Gustavo Valverde and GitHub
6f9a188bbb
fix(oauth-provider): return invalid_grant for cross-client refresh tokens ( #10154 )
2026-06-19 11:32:12 -07:00