[PR #8121] [MERGED] fix(multi-session): allow setActive with multi-session cookies only #33358

Closed
opened 2026-04-17 23:59:22 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/better-auth/better-auth/pull/8121
Author: @Oluwatobi-Mustapha
Created: 2/23/2026
Status: Merged
Merged: 2/24/2026
Merged by: @Bekacru

Base: canaryHead: fix/multi-session-set-active-cookies


📝 Commits (2)

  • 3db98db fix(multi-session): allow setActive with multi-session cookies only
  • 903d10e Merge branch 'canary' into fix/multi-session-set-active-cookies

📊 Changes

2 files changed (+22 additions, -1 deletions)

View changed files

📝 packages/better-auth/src/plugins/multi-session/index.ts (+0 -1)
📝 packages/better-auth/src/plugins/multi-session/multi-session.test.ts (+22 -0)

📄 Description

Fixes #8114.

  • remove sessionMiddleware from multi-session/set-active
  • add regression test for setActive when better-auth.session_token is missing but valid _multi-* cookies are present

Summary by cubic

Allow setActive to authenticate with only signed _multi-* cookies, without better-auth.session_token. Fixes activation failures for apps using multi-session cookie storage.

  • Bug Fixes
    • Dropped sessionMiddleware from multiSession.setActive so _multi-* cookies alone are accepted.
    • Added regression test verifying setActive works with only multi-session cookies.

Written for commit 903d10e56b. Summary will update on new commits.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/better-auth/better-auth/pull/8121 **Author:** [@Oluwatobi-Mustapha](https://github.com/Oluwatobi-Mustapha) **Created:** 2/23/2026 **Status:** ✅ Merged **Merged:** 2/24/2026 **Merged by:** [@Bekacru](https://github.com/Bekacru) **Base:** `canary` ← **Head:** `fix/multi-session-set-active-cookies` --- ### 📝 Commits (2) - [`3db98db`](https://github.com/better-auth/better-auth/commit/3db98db6d50625eee7f9e188839590e8925a13a7) fix(multi-session): allow setActive with multi-session cookies only - [`903d10e`](https://github.com/better-auth/better-auth/commit/903d10e56b171dffabc319845ae3eb4af96663d0) Merge branch 'canary' into fix/multi-session-set-active-cookies ### 📊 Changes **2 files changed** (+22 additions, -1 deletions) <details> <summary>View changed files</summary> 📝 `packages/better-auth/src/plugins/multi-session/index.ts` (+0 -1) 📝 `packages/better-auth/src/plugins/multi-session/multi-session.test.ts` (+22 -0) </details> ### 📄 Description Fixes #8114. - remove `sessionMiddleware` from `multi-session/set-active` - add regression test for `setActive` when `better-auth.session_token` is missing but valid `_multi-*` cookies are present <!-- This is an auto-generated description by cubic. --> --- ## Summary by cubic Allow setActive to authenticate with only signed _multi-* cookies, without better-auth.session_token. Fixes activation failures for apps using multi-session cookie storage. - **Bug Fixes** - Dropped sessionMiddleware from multiSession.setActive so _multi-* cookies alone are accepted. - Added regression test verifying setActive works with only multi-session cookies. <sup>Written for commit 903d10e56b171dffabc319845ae3eb4af96663d0. Summary will update on new commits.</sup> <!-- End of auto-generated description by cubic. --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-04-17 23:59:22 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/better-auth#33358