Gustavo Valverde
b7850f90a4
fix: address merge follow-ups from PR #9172 review
...
- packages/oauth-provider/src/types/zod.ts: make `state` optional in
`verificationValueSchema`. Main's PR #9118 hardened authorization code
validation with a required `state`, but CIMD (next, PR #9159 ) doesn't send
state in test flows. Per OAuth 2.0 §4.1.1 state is RECOMMENDED, not
REQUIRED. Fixes CIMD token exchange (`401 !== 200`) in ci test and smoke.
- docs/content/docs/plugins/sso.mdx: replace remaining `/sso/saml2/callback/`
references with `/sso/saml2/sp/acs/` to match the endpoint rename from
next's PR #9117 . The merge took main verbatim here, regressing docs that
next had already updated.
2026-04-14 11:54:29 +01:00
Gustavo Valverde
3fbab44068
chore: sync main to next
...
Resolves conflicts in PR #9115 which the release bot cannot auto-merge.
Conflict resolutions:
- .github/workflows/release.yml: take main's hardened grep fallback (92256a2d0 )
- docs/content/docs/plugins/sso.mdx: take main's named-exports refactor verbatim (#9144 )
- packages/oauth-provider/src/token.ts: keep next's at_hash sequencing (#9079 ),
add main's customTokenResponseFields spread and credential helper rename (#9118 )
- packages/oauth-provider/src/token.test.ts: keep both new describe blocks
(at_hash in id tokens from next, customTokenResponseFields from main)
Semantic fixes on auto-merged files where git silently dropped main's changes
around next's discriminated-response refactor:
- two-factor/index.ts: restore skipVerificationOnEnable handling in the totp
enablement path
- two-factor/types.ts: restore the skipVerificationOnEnable type field
- two-factor/two-factor.test.ts: narrow the discriminated enable response via
method === "totp" guard
2026-04-14 11:30:13 +01:00
Gustavo Valverde and GitHub
92256a2d0d
chore: minor review followups on recent main commits ( #9163 )
2026-04-14 07:22:10 +00:00
Jaden Stanton and GitHub
2514c3d970
docs: correct wording for invocable endpoints in integration guides ( #9160 )
2026-04-14 05:59:29 +00:00
Sean Filimon and GitHub
a1f619969d
docs: update Convex Labs link in documentation ( #9161 )
2026-04-14 05:55:27 +00:00
cd8313ba00
feat(cimd): add Client ID Metadata Document plugin ( #9159 )
...
Co-authored-by: Dylan Vanmali <dylanvanmali@yahoo.com >
2026-04-13 20:52:34 +00:00
Taesu and GitHub
8dcb98873e
docs: update not-found page ( #9158 )
2026-04-13 19:54:32 +00:00
Gustavo Valverde and GitHub
c7d22539ec
refactor(generic-oauth)!: rewrite as first-class social provider with RFC compliance ( #9069 )
2026-04-13 12:02:16 +00:00
Taesu and GitHub
6c946a3e0c
docs(sso): extract inline fields to named exports ( #9144 )
2026-04-13 03:01:29 +00:00
Taesu and GitHub
daf7ab7aaa
docs: fix fk references in schema tables to match actual plugin schemas ( #9143 )
2026-04-13 02:37:17 +00:00
Taesu and GitHub
a6f31972ca
docs(landing): polish sentinel section ( #9142 )
2026-04-13 01:19:15 +00:00
ed2c18df31
chore(deps): bump next from 16.2.2 to 16.2.3 in /docs ( #9112 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Taesu <bytaesu@gmail.com >
Co-authored-by: Taesu <166604494+bytaesu@users.noreply.github.com >
2026-04-12 08:47:53 +00:00
Taesu and GitHub
a6e9b94318
docs: improve enterprise contact form ( #9128 )
2026-04-12 08:30:35 +00:00
Gustavo Valverde and GitHub
b70f025bfa
refactor(sso)!: remove callbackUrl, consolidate ACS endpoint, fix SLO ( #9117 )
2026-04-11 10:03:56 +00:00
Gustavo Valverde and GitHub
314e06f0fd
feat(oauth-provider): add customTokenResponseFields and harden authorization code validation ( #9118 )
2026-04-11 09:54:48 +00:00
Gustavo Valverde
28ccc8cda9
chore: resolve main-to-next sync conflicts
...
Conflicts resolved:
- docs/content/docs/plugins/2fa.mdx: kept next's OTP feature, applied main's exported const pattern
- docs/content/docs/plugins/oauth-provider.mdx: kept main's formatting, added back private_key_jwt docs
- docs/content/docs/plugins/sso.mdx: kept next's version with private_key_jwt and SAML options
- packages/sso/src/routes/sso.ts: kept next's version (has security fixes and private_key_jwt)
2026-04-10 19:11:05 +01:00
Gustavo Valverde and GitHub
52c47517a2
fix(sso): unify SAML response processing and fix bugs ( #9097 )
2026-04-10 15:00:26 +00:00
Gustavo Valverde and GitHub
544f1c63c9
feat(two-factor)!: add OTP enablement and discriminated response ( #9057 )
2026-04-10 14:23:20 +00:00
Gustavo Valverde and GitHub
93d3871bd2
feat(oauth): add private_key_jwt client authentication (RFC 7523) ( #8836 )
2026-04-10 08:22:05 +00:00
5f84335815
feat(stripe): support Stripe SDK v21 and v22 ( #9084 )
...
Co-authored-by: leonardo2204 <1509421+leonardo2204@users.noreply.github.com >
Co-authored-by: better-release[bot] <273320539+better-release[bot]@users.noreply.github.com>
2026-04-10 06:19:34 +00:00
Tony and GitHub
d141a3b190
docs: fix PostgreSQL Prisma native type typo ( #9090 )
2026-04-10 05:21:45 +00:00
Taesu and GitHub
099ee48c41
chore(docs): format markdown including mdx files ( #9085 )
2026-04-10 05:09:33 +00:00
41679fa817
docs: add database table names ( #9062 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-04-09 19:17:40 +00:00
809da03968
docs: add paragraph specifying need for cookie passage for server methods ( #6546 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-04-09 13:26:13 +00:00
31fd092896
docs: clarify that the redirectURI must include providerId parameter in generic oauth ( #6021 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-04-09 13:23:33 +00:00
cf25761bc1
docs: clarify credential account requirement for phone number plugin ( #6401 )
...
Signed-off-by: GautamBytes <manchandanigautam@gmail.com >
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-04-09 13:19:50 +00:00
b834782e2b
docs: add 'better-auth-audit-logs' plugin to community table ( #9051 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-04-09 13:14:25 +00:00
84098432ad
feat(two-factor): include enabled 2fa methods in sign-in redirect response ( #8772 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-04-09 09:25:49 +00:00
e78a7b120d
fix(two-factor): prevent unverified TOTP enrollment from gating sign-in ( #8711 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-04-09 08:48:10 +00:00
Taesu and GitHub
438d10d22e
docs: scale inline code size inside changelog headings ( #9047 )
2026-04-08 22:50:40 +00:00
Taesu and GitHub
54713e2fad
docs: fix sidebar SVG icon colors and clean up New tags ( #9041 )
2026-04-08 17:14:40 +00:00
Taesu and GitHub
538e949eb3
docs: switch npm download stats to weekly ( #9035 )
2026-04-08 07:16:13 +00:00
Taesu and GitHub
b24fd23790
docs: remove commet plugin from sidebar ( #9034 )
2026-04-08 07:11:21 +00:00
e2df67cf0d
docs: add v1.6 release blog post ( #9009 )
...
Co-authored-by: Gustavo Valverde <g.valverde02@gmail.com >
2026-04-08 06:50:50 +00:00
c665898953
docs(email): document beforeEmailVerification and onExistingUserSignUp callbacks ( #8914 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-04-08 02:15:29 +00:00
Allan Delmare and GitHub
fcd25d5057
docs: move @delmaredigital/payload-better-auth from plugins to adapters ( #9027 )
2026-04-08 02:04:00 +00:00
Maxwell and GitHub
fe6b72b675
docs: improve state-mismatch documentation ( #9026 )
2026-04-08 09:29:13 +10:00
a7e359d870
docs: add expo sentinel docs ( #9025 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-04-07 23:08:15 +00:00
5e7fd61da0
docs: hide fumadocs toc scroll indicator dot ( #9021 )
...
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com >
2026-04-08 08:49:35 +10:00
Jonathan Samines and GitHub
2e537df5f7
fix: endpoint instrumentation to always use route template ( #9023 )
2026-04-08 08:41:31 +10:00
47dc887d58
docs: add @delmaredigital/payload-better-auth to community plugins ( #8375 )
...
Co-authored-by: Taesu <bytaesu@gmail.com >
2026-04-07 16:39:03 +00:00
Sandy and GitHub
3b95d70d04
docs: change community plugin name ( #8961 )
2026-04-07 16:26:55 +00:00
Taesu and GitHub
374985e340
docs: update community adapters and plugins pages ( #9014 )
2026-04-07 15:43:55 +00:00
Taesu and GitHub
3baf0294c2
chore(docs): add remark-frontmatter ( #9015 )
2026-04-07 15:35:57 +00:00
60123da09c
docs: add missing secret to getSignedCookie and remove misleading comments ( #9008 )
...
Co-authored-by: Taesu <166604494+bytaesu@users.noreply.github.com >
2026-04-07 15:26:25 +00:00
Gustavo Valverde and GitHub
bd9bd58f87
fix(security): enforce authorization on SCIM management endpoints and normalize passkey ownership ( #8843 )
2026-04-06 13:47:24 +00:00
ee8b40d502
fix(deps): patch Dependabot security issues ( #8838 )
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-04-06 13:16:45 +00:00
Taesu and GitHub
91a838fdb7
docs: remove openfort plugin ( #8940 )
2026-04-04 07:09:24 +09:00
Taesu and GitHub
4c8a5f41b5
docs: update landing footer cta ( #8936 )
2026-04-03 20:36:47 +00:00
5970053e6a
docs: improve descriptions for appName, trustedOrigins, useSecureCookies ( #8935 )
...
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
2026-04-03 18:31:00 +00:00