Gustavo Valverde 51a122fa6d test(oidc-provider): align concurrent-redemption test to next's callback path (#9533)
The concurrent authorization-code redemption test (added on main for
GHSA-7w99-5wm4-3g79) exchanged the code against `/api/auth/oauth2/callback/test`,
but next renamed that callback path to `/api/auth/callback/test`. The merge
kept next's code-minting helper while preserving main's exchange path, so the
race winner failed redirect_uri validation and no caller minted a token,
tripping the "exactly one success" assertion.

Because that test threw before closing its listener on port 3000, the leaked
server poisoned the later EdDSA and HS256 oidc-jwt tests (stale server, code
not found on consume). Aligning the exchange path to next fixes all three.
2026-05-31 07:40:40 +01:00
2026-05-31 00:10:16 +01:00
2026-05-31 00:10:16 +01:00
2026-04-23 19:50:25 +00:00
2026-04-23 19:50:25 +00:00
2025-12-08 16:58:23 -08:00
2026-04-23 19:50:25 +00:00
2026-01-21 04:08:09 +00:00
2026-04-18 23:04:27 -07:00

Better Auth

Better Auth is a framework-agnostic authentication (and authorization) framework for TypeScript. It provides a comprehensive set of features out of the box and includes a plugin ecosystem that simplifies adding advanced functionalities with minimal code in a short amount of time. Whether you need 2FA, multi-tenant support, or other complex features, it lets you focus on building your actual application instead of reinventing the wheel.

Why Better Auth

Authentication in the TypeScript ecosystem is a half-solved problem. Other open-source libraries often require a lot of additional code for anything beyond basic authentication. Rather than just pushing third-party services as the solution, I believe we can do better as a community—hence, Better Auth.

Contribution

Better Auth is a free and open source project licensed under the MIT License. You are free to do whatever you want with it.

You could help continuing its development by:

Security

If you discover a security vulnerability within Better Auth, please send an e-mail to security@better-auth.com.

All reports will be promptly addressed, and you'll be credited accordingly.

S
Description
No description provided
Readme
258 MiB
Latest
2026-04-16 05:05:30 -05:00
Languages
TypeScript 99.4%
CSS 0.3%
MDX 0.2%