Gustavo Valverde 3fbc2f3405 test(generic-oauth): port regression suites onto the social-provider rewrite (#9799, #9792, #9702, #9578)
next's #9069 rewrote generic-oauth to flow through the core social provider
and callback. The #9799 accessTokenExpiresIn source fix merged in cleanly
(its config field and the applyDefaultAccessTokenExpiry wiring land on the
three token paths); main's regression tests still targeted the old
signIn.oauth2 plugin API. This ports them onto signIn.social so they keep
guarding the behavior:

- #9799: getAccessToken refreshes once the accessTokenExpiresIn window passes
  when the provider omits expires_in, does not refresh when it is unset, and
  applies it to a custom getToken result.
- #9792: the verify-email link preserves the encoded callbackURL.
- #9702: a session hook throwing an APIError redirects to the cross-origin
  errorCallbackURL with the hook's code (proves the rewritten callback's
  hook-error forwarding).
- #9578: implicit-link tests mark the local user verified so linking is
  allowed under the default-on requireLocalEmailVerified gate.

A stale IDP-bounce assertion is updated to next's state-error vocabulary.
All 71 tests pass.

(cherry picked from commit 52adab0db3f463295a0c4e3152d770f4ce40b2d2)
2026-05-31 00:10:36 +01:00
2026-05-31 00:10:16 +01:00
2026-05-31 00:10:16 +01:00
2026-05-31 00:10:16 +01:00
2026-04-23 19:50:25 +00:00
2026-04-23 19:50:25 +00:00
2026-04-23 19:50:25 +00:00
2026-04-18 23:04:27 -07:00

Better Auth

Better Auth is a framework-agnostic authentication (and authorization) framework for TypeScript. It provides a comprehensive set of features out of the box and includes a plugin ecosystem that simplifies adding advanced functionalities with minimal code in a short amount of time. Whether you need 2FA, multi-tenant support, or other complex features, it lets you focus on building your actual application instead of reinventing the wheel.

Why Better Auth

Authentication in the TypeScript ecosystem is a half-solved problem. Other open-source libraries often require a lot of additional code for anything beyond basic authentication. Rather than just pushing third-party services as the solution, I believe we can do better as a community—hence, Better Auth.

Contribution

Better Auth is a free and open source project licensed under the MIT License. You are free to do whatever you want with it.

You could help continuing its development by:

Security

If you discover a security vulnerability within Better Auth, please send an e-mail to security@better-auth.com.

All reports will be promptly addressed, and you'll be credited accordingly.

S
Description
No description provided
Readme
247 MiB
Latest
2026-04-16 05:05:30 -05:00
Languages
TypeScript 99.4%
CSS 0.3%
MDX 0.2%