[PR #6210] [MERGED] fix(organization): some endpoints missing requireHeaders #23422

Closed
opened 2026-04-15 21:42:33 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/better-auth/better-auth/pull/6210
Author: @ping-maxwell
Created: 11/22/2025
Status: Merged
Merged: 11/24/2025
Merged by: @himself65

Base: canaryHead: fix/organization-endpoints-missing-requireHeaders


📝 Commits (3)

  • fcf875b fix(organization): some endpoints missing requireHeaders
  • a9f2dd6 Merge branch 'canary' into fix/organization-endpoints-missing-requireHeaders
  • 9c0adbb Merge branch 'canary' into fix/organization-endpoints-missing-requireHeaders

📊 Changes

5 files changed (+20 additions, -1 deletions)

View changed files

📝 packages/better-auth/src/plugins/organization/routes/crud-access-control.ts (+3 -0)
📝 packages/better-auth/src/plugins/organization/routes/crud-invites.ts (+5 -0)
📝 packages/better-auth/src/plugins/organization/routes/crud-members.ts (+4 -0)
📝 packages/better-auth/src/plugins/organization/routes/crud-org.ts (+2 -0)
📝 packages/better-auth/src/plugins/organization/routes/crud-team.ts (+6 -1)

📄 Description

closes https://github.com/better-auth/better-auth/issues/6157


Summary by cubic

Adds requireHeaders: true to missing organization routes to enforce auth headers and block requests without them. Improves security and aligns all org endpoints with middleware expectations.

  • Bug Fixes
    • Enforced headers on: roles (list/get/update), invites (create/accept/reject/cancel/list), members (remove/updateRole/list/getActiveRole), organizations (setActive/list), teams (list org teams/setActive/list user teams/list members/add/remove).
    • Fixed requireHeaders placement in listOrganizationTeams.

Written for commit 9c0adbb953. Summary will update automatically on new commits.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/better-auth/better-auth/pull/6210 **Author:** [@ping-maxwell](https://github.com/ping-maxwell) **Created:** 11/22/2025 **Status:** ✅ Merged **Merged:** 11/24/2025 **Merged by:** [@himself65](https://github.com/himself65) **Base:** `canary` ← **Head:** `fix/organization-endpoints-missing-requireHeaders` --- ### 📝 Commits (3) - [`fcf875b`](https://github.com/better-auth/better-auth/commit/fcf875b7d1e392860608b4aeef4beaa3e3c3b14d) fix(organization): some endpoints missing `requireHeaders` - [`a9f2dd6`](https://github.com/better-auth/better-auth/commit/a9f2dd6173bc823a1d0a9ba830b5cdc0d29a9f77) Merge branch 'canary' into fix/organization-endpoints-missing-requireHeaders - [`9c0adbb`](https://github.com/better-auth/better-auth/commit/9c0adbb953abcc93f7041d1bdc87040b2e459a05) Merge branch 'canary' into fix/organization-endpoints-missing-requireHeaders ### 📊 Changes **5 files changed** (+20 additions, -1 deletions) <details> <summary>View changed files</summary> 📝 `packages/better-auth/src/plugins/organization/routes/crud-access-control.ts` (+3 -0) 📝 `packages/better-auth/src/plugins/organization/routes/crud-invites.ts` (+5 -0) 📝 `packages/better-auth/src/plugins/organization/routes/crud-members.ts` (+4 -0) 📝 `packages/better-auth/src/plugins/organization/routes/crud-org.ts` (+2 -0) 📝 `packages/better-auth/src/plugins/organization/routes/crud-team.ts` (+6 -1) </details> ### 📄 Description closes https://github.com/better-auth/better-auth/issues/6157 <!-- This is an auto-generated description by cubic. --> --- ## Summary by cubic Adds requireHeaders: true to missing organization routes to enforce auth headers and block requests without them. Improves security and aligns all org endpoints with middleware expectations. - **Bug Fixes** - Enforced headers on: roles (list/get/update), invites (create/accept/reject/cancel/list), members (remove/updateRole/list/getActiveRole), organizations (setActive/list), teams (list org teams/setActive/list user teams/list members/add/remove). - Fixed requireHeaders placement in listOrganizationTeams. <sup>Written for commit 9c0adbb953abcc93f7041d1bdc87040b2e459a05. Summary will update automatically on new commits.</sup> <!-- End of auto-generated description by cubic. --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-04-15 21:42:33 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/better-auth#23422