Zum Inhalt springen

Better Auth Release Notes

30 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.7: Kritische Magic-Link-Sicherheitslücke behoben

Better Auth v1.7.7 behebt eine kritische Magic-Link-Sicherheitslücke zur Kontoübernahme, die Ignorierung von disableSignUp bei ID-Token-Anmeldungen, die Annahme von Sign-in-State als Provider-Profil im OAuth Proxy sowie mehrere Fehler bei JSON-Content-Type-Headern und der Aktualisierung der aktiven Organisation; Server mit gemeinsamem Verification-Speicher müssen gemeinsam aktualisiert werden, neue Magic Links angefordert und ausstehende OAuth/SAML-Anmeldungen neu gestartet werden.

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.6: bannedUserMessage, Vercel BotID und Fixes

Better Auth v1.7.6 ergänzt eine bannedUserMessage-Funktion und Vercel BotID als Captcha-Anbieter und behebt unter anderem zu lange Passwörter (jetzt PASSWORD_TOO_LONG), React-Hydration-Probleme, überlappende Auth-Query-Antworten, Cloudflare-D1-Schemavalidierung und Social-Account-Linking über den OAuth Proxy.

better-auth

Features

  • Added support for a bannedUserMessage function that receives the banned user, allowing sign-in errors to include details such as the ban reason. (#11325)
  • Added Vercel BotID as a captcha provider for protected authentication routes. (#11016)

Bug Fixes

  • Passwords over maxPasswordLength are now rejected with PASSWORD_TOO_LONG before hashing or verification. (#11324)
  • Fixed React hydration mismatches when session or plugin auth queries resolve before streamed components hydrate. (#11316)
  • Prevented older auth-query responses from overwriting newer results when requests overlap. (#11376)
  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)
  • Fixed social account linking through the OAuth Proxy plugin. (#11268) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.5: database.schemaName für PostgreSQL

Better Auth v1.7.5 unterstützt database.schemaName für direkte PostgreSQL-Verbindungen, verbessert das Logging bei Cloudflare-Turnstile-Fehlern und behebt PostgreSQL-Migrationen über mehrere Schemas, die MySQL-Indexvalidierung sowie die Typableitung der Datenbankoptionen und entfernt die ungenutzte optionale Peer-Dependency better-sqlite3.

better-auth

Features

  • Added database.schemaName support for direct PostgreSQL connections. (#11203)

Bug Fixes

  • Improved server-side logging for Cloudflare Turnstile verification failures. (#11283)
  • Fixed PostgreSQL migrations incorrectly identifying tables and views across schemas. (#11270)
  • Fixed MySQL index validation for existing string columns. (#11272)
  • Removed the unused optional better-sqlite3 peer dependency to prevent installation conflicts. (#11209)

For detailed changes, see CHANGELOG

@better-auth/core

Features

  • Added database.schemaName support for direct PostgreSQL connections. (#11203)

Bug Fixes

  • Fixed database option type inference outside Cloudflare Workers. (#11290)

For detailed changes, see CHANGELOG

@better-auth/cimd

Bug Fixes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.33: Typableitung der Datenbankoptionen korrigiert

Better Auth v1.6.33 behebt die Typableitung der Datenbankoptionen in @better-auth/core für Projekte ohne Cloudflare Workers.

@better-auth/core

Bug Fixes

  • Fixed database option type inference for projects that do not use Cloudflare Workers. (#11291)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@better-release[bot]

Full changelog: v1.6.32...v1.6.33

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.32: Bessere Turnstile-Diagnose

Better Auth v1.6.32 verbessert die Diagnose bei fehlgeschlagener Cloudflare-Turnstile-Verifizierung.

better-auth

Bug Fixes

  • Improved diagnostics for Cloudflare Turnstile verification failures (#11286)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@better-release[bot]

Full changelog: v1.6.31...v1.6.32

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.4: OpenTelemetry abschaltbar, Vitest 5

Better Auth v1.7.4 ergänzt experimental.instrumentation.enabled zum Deaktivieren der OpenTelemetry-Span-Erzeugung, zusätzliche Session-Felder in testUtils sowie Vitest-5-Unterstützung und behebt Metro-Bundling ohne OpenTelemetry-API sowie Probleme mit Expo SecureStore.

better-auth

Features

  • Added experimental.instrumentation.enabled to disable OpenTelemetry span creation per auth instance. (#11224)
  • Added support for additional session fields in testUtils auth helpers. (#11217)
  • Added Vitest 5 support to the testing utilities. (#11205)

For detailed changes, see CHANGELOG

@better-auth/core

Features

  • Added experimental.instrumentation.enabled to disable OpenTelemetry span creation per auth instance. (#11224)

Bug Fixes

  • Fixed Metro bundling when the optional OpenTelemetry API is not installed. (#11210)

For detailed changes, see CHANGELOG

@better-auth/expo

Bug Fixes

  • Fixed multibyte session data storage in Expo SecureStore. (#11238)
  • Fixed stale Expo secure-storage session data and corrupted cookies during concurrent updates. (#11200) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.31: OpenTelemetry-Spans pro Auth-Instanz deaktivierbar

Better Auth v1.6.31 ergänzt eine Option, die OpenTelemetry-Span-Erzeugung für einzelne Auth-Instanzen zu deaktivieren.

better-auth

Features

  • Added an option to disable OpenTelemetry span creation for individual auth instances (#11228)

For detailed changes, see CHANGELOG

@better-auth/core

Features

  • Added an option to disable OpenTelemetry span creation for individual auth instances (#11228)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@better-release[bot]

Full changelog: v1.6.30...v1.6.31

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.3: Account-Schema von 1.6 wiederhergestellt, Cloudflare-Provider

Better Auth v1.7.3 stellt das Account-Core-Schema von 1.6 wieder her (Bereinigung nötig bei bereits angewendetem 1.7-Issuer-Schema), fügt Cloudflare als Social Provider und isPasswordCompromised hinzu, aktiviert die Schemavalidierung standardmäßig und enthält mehrere Fehlerbehebungen.

Upgrading from 1.7.0–1.7.2:

We restored the 1.6 account core schema to avoid requiring a disruptive backfill for existing users. We recognize the cost to users who already migrated and are committed to keeping the core schema stable throughout v1.

If you applied the 1.7 issuer schema, follow the upgrade guide for the required cleanup. No backfill is needed.

better-auth

Features

  • Added Cloudflare as a built-in social provider with client-secret and PKCE support. (#9908)
  • Enabled schema validation during initialization by default, including in production, and rejected authentication requests on detected mismatches. (#11178)
  • Added isPasswordCompromised for checking passwords against Have I Been Pwned in custom server-side flows. (#11147)

Bug Fixes

  • Aligned generated OpenAPI required fields with runtime validation. (#11066)
  • Handled malformed custom-scheme callback URLs without excessive processing. (#11060)
  • Improved Auth0 domain normalization to avoid slow trailing-slash processing. (#11188) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.2: Fixes für Sperren, Client-Typen, Migrationen und Callback-URLs

Better Auth v1.7.2 behebt unter anderem das Löschen von Ablaufdaten bei dauerhaften Sperren, Client-Typen bei mehreren Plugins, MyISAM- und Cloudflare-D1-Migrationen sowie die Validierung relativer Callback-URLs und verbessert die Performance von getTestInstance.

better-auth

Bug Fixes

  • Fixed permanent user bans to clear expiration dates from previous temporary bans. (#10823)
  • Fixed client types with more plugins being assignable to types declaring fewer plugins. (#10907)
  • Added warnings for invalid signed session data in the cookie cache. (#10934)
  • Fixed disabled MyISAM indexes from satisfying migration index checks. (#10877)
  • Fixed programmatic migrations on Cloudflare D1 while preserving existing-index validation. (#10875)
  • Allowed ~ in relative callback URLs validated by trusted-origin checks. (#10041)
  • Improved validation of relative callback and redirect URLs with paths, queries, and fragments. (#10979)
  • Allowed same-origin form submissions with Referrer-Policy: no-referrer while continuing to reject untrusted origins. (#10959)
  • Improved getTestInstance performance with a faster default password hasher. (#10879) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.1: Test-Transaktionen und bessere SCIM-Entra-Kompatibilität

Better Auth v1.7.1 ergänzt native Datenbanktransaktionen für Test-Instanzen, aktualisiert gebündelte Abhängigkeiten und verbessert in @better-auth/scim die Microsoft-Entra-Kompatibilität sowie managedConnections für Laufzeit-Tenant-Verbindungen und Bearer-Credentials.

better-auth

Bug Fixes

  • Added native database transaction support to test instances for PostgreSQL and MySQL.
  • Updated bundled dependencies (jose, nanostores, noble crypto packages, SimpleWebAuthn) to their latest compatible releases, with no changes required to existing projects.

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed case-insensitive parsing of string Boolean values for SCIM User active and the primary sub-attribute of emails, phoneNumbers, addresses, roles, and entitlements at the HTTP ingress, improving Microsoft Entra interoperability.
  • Added an optional SCIM-owned connection and credential catalog: configure managedConnections to allow trusted server code to create runtime tenant connections and issue, rotate, and revoke bearer credentials through server-only auth.api methods, without a code-defined connection or an application-owned verifier.
  • Fixed an issue where trusted server code could not retain a terminal connection binding before a dynamic SCIM connection's first authenticated request when supplying a provisioning domain during decommissioning.

For detailed changes, see CHANGELOG

@better-auth/sso

Bug Fixes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.0: Breaking Changes bei Joins, Konto-Schlüsseln und MCP-Paket

Better Auth v1.7.0 bringt Breaking Changes wie die stabile Option advanced.database.joins, kontoidentitätsbezogene Schlüssel über (issuer, accountId), strengere Captcha-Pfadangaben und das ausgelagerte Paket @better-auth/mcp, jeweils mit Migrationshinweisen.

Blog post: Better Auth 1.7

better-auth

❗ Breaking Changes

  • Moved database joins out of experimental into the stable advanced.database.joins option (#10359)

    Migration: Replace experimental: { joins: true } with advanced: { database: { joins: true } }. Drizzle and Prisma users should regenerate their schema (npx auth@latest generate) so it includes the required relations.

  • Scoped account identity by trusted issuer, keying accounts on (issuer, accountId) (#10403)

    Migration: Accounts now require Account.issuer. Read provider identity from accountInfo.account.accountId, drop mapping.id from SSO configs, and give the microsoftEntraId helper a concrete tenant GUID. Apply the account-identity backfill in the 1.7 upgrade guide before deploying.

  • Required captcha endpoint entries to match full auth paths, with wildcard support (#10004)

    Migration: Replace partial paths such as /sign-in with explicit wildcards like /sign-in/* or /sign-in/**.

  • Moved the MCP plugin into its own @better-auth/mcp package built on the OAuth provider (#9992) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.30: Race Condition behoben, SSO-Domain-Verifizierung gehärtet

Better Auth v1.6.30 behebt eine Race Condition bei gleichzeitigen Cold-Start-Anfragen und härtet in @better-auth/sso die automatische Organisationszuweisung per E-Mail-Domain sowie die Domain-Verifizierung (409 mit SSO_PROVIDER_CHANGED).

better-auth

Bug Fixes

  • Fixed concurrent cold-start requests from intermittently losing authentication or transaction context due to an async storage initialization race (#10833)

For detailed changes, see CHANGELOG

@better-auth/sso

Bug Fixes

  • Fixed automatic organization assignment via email domain to require both a verified provider domain and a verified stored user email, preventing social sign-in from joining an organization whose SSO provider merely claims that domain.
  • Fixed domain verification to snapshot the provider's domains at request start, returning 409 with SSO_PROVIDER_CHANGED if the provider changes during DNS resolution so callers can reload and retry.

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@bytaesu

Full changelog: v1.6.29...v1.6.30

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.0-rc.6: TypeScript-Client-Plugins und OAuth-Fixes

Better Auth v1.7.0-rc.6 stellt die Client-Plugin-Deklarationskompatibilität für TypeScript wieder her, behebt doppelte Session-Anfragen bei Suspense-Remounts und korrigiert mehrere OAuth-Provider-Fälle wie private_key_jwt-Assertions, RP-Initiated Logout, ACR-Anfragen und openid-Scope bei Claims.

better-auth

Bug Fixes

  • Restored client plugin declaration compatibility for downstream TypeScript consumers. (#10794)
  • Fixed duplicate session requests during transient Suspense remounts while ensuring incomplete refreshes are revalidated. (#10769)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Bug Fixes

  • Fixed private_key_jwt client assertions to accept the issuer URL as a valid aud claim (string or array) on token, introspection, and revocation requests. (#10811)
  • Completed the RP-Initiated Logout flow with form-encoded POST support, explicit confirmation pages, and strict post_logout_redirect_uri validation. (#10812)
  • Fixed handling of voluntary and essential ACR requests in authorization flows. (#10790)
  • Fixed claims requests to require the openid scope. (#10791)

For detailed changes, see CHANGELOG …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.29: Schnelleres deleteSessions, SSO-Härtung

Better Auth v1.6.29 beschleunigt deleteSessions durch paralleles Löschen und härtet in @better-auth/sso die automatische Organisationszuweisung per E-Mail-Domain sowie die Domain-Verifizierung (409 mit SSO_PROVIDER_CHANGED).

better-auth

Bug Fixes

  • Improved deleteSessions performance by running deletes in parallel instead of sequentially (#10805)

For detailed changes, see CHANGELOG

@better-auth/sso

Bug Fixes

  • Fixed automatic email-domain organization assignment to require both a verified provider domain and a verified user email, preventing social sign-in from granting access when an SSO provider merely claims a domain.
  • Fixed domain verification to snapshot the provider's domains at request start, returning 409 with SSO_PROVIDER_CHANGED if the provider changes during DNS verification so callers can reload and retry.

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@Emmaccen

Full changelog: v1.6.28...v1.6.29

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.28: Keine doppelten Session-Anfragen bei Suspense

Better Auth v1.6.28 verhindert doppelte Session-Anfragen bei React-Suspense-Wiederholungen und stellt die Client-Plugin-Deklarationskompatibilität für TypeScript in better-auth, @better-auth/electron und @better-auth/expo wieder her.

better-auth

Bug Fixes

  • Prevented duplicate session requests during React Suspense retries while preserving revalidation for interrupted refreshes (#10769)
  • Restored client plugin declaration compatibility for downstream TypeScript consumers (#10794)

For detailed changes, see the CHANGELOG.

@better-auth/electron

Bug Fixes

  • Restored client plugin declaration compatibility for downstream TypeScript consumers (#10794)

For detailed changes, see the CHANGELOG.

@better-auth/expo

Bug Fixes

  • Restored client plugin declaration compatibility for downstream TypeScript consumers (#10794)

For detailed changes, see the CHANGELOG.

Contributors

Thanks to everyone who contributed to this release:

@bytaesu …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.0-rc.5: Device Grant über oauthDeviceAuthorization()

Better Auth v1.7.0-rc.5 stellt die OAuth-Device-Grant-Einbindung auf oauthDeviceAuthorization() neben oauthProvider() oder mcp() um (Breaking Change mit Schemaänderung) und ergänzt eine Option zum Deaktivieren von displayName im Username-Plugin.

better-auth

❗ Breaking Changes

  • Refactored OAuth device grant ownership to use oauthDeviceAuthorization() alongside oauthProvider() or mcp() (#10746)

Migration: Replace the standalone deviceCodeGrant() plugin with oauthDeviceAuthorization() used alongside oauthProvider() or mcp(). Regenerate and apply the schema (resource column is replaced by oauthClientId and resources). Let any pending device codes expire or delete them before upgrading, as they cannot be exchanged through the new integration.

Features

  • Added option to disable displayName in the username plugin (#10330)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

❗ Breaking Changes

  • Refactored OAuth device grant ownership to use oauthDeviceAuthorization() alongside oauthProvider() or mcp() (#10746) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.27: Suspense-Fix, SCIM-Typen und CLI-Paketabstimmung

Better Auth v1.6.27 behebt doppelte Session-Anfragen bei Suspense-Wiederholungen, die Typen der SCIM-Endpunkte passend zu better-call und die Abstimmung installierter Pakete mit der laufenden CLI-Version.

better-auth

Bug Fixes

  • Fixed duplicate session requests being made across Suspense retries (#10676)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed auth endpoint types to align with better-call (#10657)

For detailed changes, see CHANGELOG

auth

Bug Fixes

  • Fixed the CLI to align installed packages with the running CLI version (#10743)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@bytaesu

Full changelog: v1.6.26...v1.6.27

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.0-rc.4: Platzhalter-E-Mail-Hilfe und mehrere Fehlerbehebungen

Better Auth v1.7.0-rc.4 ergänzt ein Platzhalter-E-Mail-Hilfsprogramm und behebt unter anderem die Session-Bereinigung beim Löschen von Nutzern, fehlendes PKCE bei Apple OAuth, mehrere Email-OTP-Abläufe und die Typableitung bei jwtClient.

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.26: Fixes bei Session-Bereinigung, Email-OTP und jwtClient

Better Auth v1.6.26 behebt unter anderem die Session-Bereinigung im Secondary Storage beim Löschen von Nutzern, mehrere Email-OTP-Abläufe (inklusive fehlender Offenlegung registrierter E-Mails), die Typableitung bei jwtClient(), JWT-Key-Erzeugung in Transaktionen und Apple-Nutzerdaten in oAuthProxy.

better-auth

Bug Fixes

  • Fixed session cleanup on user deletion to also remove sessions from secondary storage (#10520)
  • Fixed findSessions to skip invalid secondary-storage session entries without discarding other valid sessions (#10580)
  • Fixed email OTP sign-up to pass the verification type to custom OTP generators (#10608)
  • Fixed email OTP password reset to allow retrying after entering an invalid password (#10552)
  • Fixed email OTP verification to no longer reveal whether an email is registered before the OTP is verified (#10605)
  • Fixed jwtClient() collapsing createAuthClient type inference when combined with other client plugins (#10513)
  • Fixed JWT key minting inside database transactions to use the transaction-scoped adapter, preventing deadlocks on SQLite and ensuring keys commit with their surrounding transaction on Postgres and MySQL (#10623)
  • Fixed oAuthProxy to preserve Apple user data from form_post callbacks (#10599) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.0-rc.3: Device-Grant, RP-initiated Logout, Microsoft-oid-Mapping

Better Auth v1.7.0-rc.3 fügt Datenbankindizes für Device- und User-Codes sowie ein Microsoft-Konto-Mapping über den oid-Claim statt sub hinzu (beides Breaking Changes mit Migration), unterstützt RP-initiated Logout für Generic OAuth und den RFC-8628-Device-Grant im OAuth Provider und behebt einen Deadlock bei der Registrierung.

better-auth

❗ Breaking Changes

  • Added database indexes for device and user code lookups in the device authorization flow (#10059)

Migration: MySQL and SQL Server users must convert device code and user code columns to bounded strings (max 191 characters) and resolve any oversized values before applying the migration.

  • Changed Microsoft and microsoftEntraId accounts to use the stable oid claim as the account identifier instead of sub (#10204)

Migration: Migrate existing Microsoft account rows keyed by sub to oid before upgrading; tokens without a valid oid claim are rejected after the update.

Features

  • Added RP-initiated logout support for Generic OAuth providers, redirecting users to their OpenID provider's logout endpoint on sign-out (#9368)
  • Added RFC 8628 device authorization grant support to the OAuth provider, enabling device-flow token exchanges for registered OAuth clients (#10135)

Bug Fixes

  • Enabled native database transactions in test instances for Postgres and MySQL databases.
  • Fixed a deadlock during sign-up when JWT session caching and native transactions are both enabled on single-connection databases (#10622) …

Originalquelle(öffnet in neuem Tab)Problem melden