Gustavo Valverde 01f7e2b0a7 fix(two-factor): preserve enforcement on path-less endpoints
Restore the pre-patch semantics for the after-hook matcher: a missing
`context.path` must still match so virtual endpoints that mint a session
are not silently exempt from 2FA. The `/two-factor/` and
session-transition prefix checks now apply only when `path` is set.

Also trim the `shouldEnforce` JSDoc; the behavioral detail lives in the
Enforcement scope section of the 2FA docs.
2026-04-15 10:38:07 +01:00

Better Auth Logo

Better Auth

The most comprehensive authentication framework for TypeScript
Learn more »

Discord · Website · Issues

npm npm version GitHub stars

About the Project

Better Auth is framework-agnostic authentication (and authorization) library for TypeScript. It provides a comprehensive set of features out of the box and includes a plugin ecosystem that simplifies adding advanced functionalities with minimal code in a short amount of time. Whether you need 2FA, multi-tenant support, or other complex features. It lets you focus on building your actual application instead of reinventing the wheel.

Why Better Auth

Authentication in the TypeScript ecosystem is a half-solved problem. Other open-source libraries often require a lot of additional code for anything beyond basic authentication. Rather than just pushing third-party services as the solution, I believe we can do better as a community—hence, Better Auth.

Contribution

Better Auth is a free and open source project licensed under the MIT License. You are free to do whatever you want with it.

You could help continuing its development by:

Security

If you discover a security vulnerability within Better Auth, please send an e-mail to security@better-auth.com.

All reports will be promptly addressed, and you'll be credited accordingly.

S
Description
No description provided
Readme
253 MiB
Latest
2026-04-16 05:05:30 -05:00
Languages
TypeScript 99.4%
CSS 0.3%
MDX 0.2%