Re-applies three main fixes onto next's rewritten OAuth callback, which now routes generic-oauth through the shared callback route. - #9702/#9788: a before-callback hook that rejects sign-in (the banned-user guard is the flagship case) now redirects to the per-flow errorURL carrying the hook's machine-readable code and message, instead of surfacing a raw error response. handleOAuthUserInfo is wrapped in try/catch; the hook's APIError code is forwarded verbatim (it is app-defined, not a member of OAUTH_CALLBACK_ERROR_CODES) via next's local redirectOnError closure. The admin plugin's stale inline /callback redirect is removed so the banned-user path flows through that single forwarder and emits BANNED_USER with a URL-encoded description. - #8758: accountLinking.updateUserInfoOnLink now applies on the explicit OAuth link path, not only id-token linking. The regression tests (banned social sign-in emits error=BANNED_USER, the cross-origin errorCallbackURL case, and the 403-JSON id-token case) arrived via the merge and were red on the baseline; these source changes make them pass. (cherry picked from commit 1d893ae572277447025e29462946a7aeb11443ac)
Better Auth
Better Auth is a framework-agnostic authentication (and authorization) framework for TypeScript. It provides a comprehensive set of features out of the box and includes a plugin ecosystem that simplifies adding advanced functionalities with minimal code in a short amount of time. Whether you need 2FA, multi-tenant support, or other complex features, it lets you focus on building your actual application instead of reinventing the wheel.
Why Better Auth
Authentication in the TypeScript ecosystem is a half-solved problem. Other open-source libraries often require a lot of additional code for anything beyond basic authentication. Rather than just pushing third-party services as the solution, I believe we can do better as a community—hence, Better Auth.
Contribution
Better Auth is a free and open source project licensed under the MIT License. You are free to do whatever you want with it.
You could help continuing its development by:
Security
If you discover a security vulnerability within Better Auth, please send an e-mail to security@better-auth.com.
All reports will be promptly addressed, and you'll be credited accordingly.
