Zum Inhalt springen

Betterauth Updates & Release Notes

30 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Betterauth, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.25: Fixes für Apple-PKCE, Google One Tap und Solid-Client

better-auth 1.6.25 behebt fehlende PKCE-Code-Challenges bei Apple OAuth, das Anlegen neuer Nutzer über Google One Tap trotz deaktivierter Registrierung, fehlende $fetch und $store im Solid-Client sowie falsch zugeordnete interne Adapter-Abfragen bei geändertem modelName.

better-auth

Bug Fixes

  • Fixed Apple OAuth not sending the PKCE code challenge during authorization, causing token exchange failures (#10294)
  • Fixed Google One Tap creating new users when sign-up was disabled on the Google provider (#10479)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Fixed internal adapter queries being routed to the wrong table when a built-in table's modelName was set to another table's schema key (e.g. user.modelName = "account").

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@birkskyum, @jsj, @krish-vachhani

Full changelog: v1.6.24...v1.6.25

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.7.0-rc.2: Joins-Option verschoben, Account-Felder umbenannt

better-auth 1.7.0-rc.2 verschiebt die Joins-Option von experimental.joins nach advanced.database.joins und benennt Account.accountId in Account.providerAccountId um, wobei Account.issuer nun Pflicht ist und Konten nach Issuer getrennt werden (Breaking Changes).

better-auth

❗ Breaking Changes

  • chore!: move joins to advanced.database.joins (#10359)

    If you previously set experimental: { joins: true }, update your config to:

    advanced: {
      database: {
        joins: true,
      },
    }
    

    Adapters that support native joins use them when enabled. If an adapter cannot return joined data for a query, Better Auth falls back to additional queries and combines the results. Drizzle and Prisma users should ensure their schema includes the required relations (npx auth@latest generate).

  • feat(auth)!: scope accounts by issuer (#10403)

    This release is breaking. Account.accountId is renamed to Account.providerAccountId, and Account.issuer is required. Account-specific APIs select the local Account.id through accountId; token and provider-profile APIs can instead select the signed account cookie with useAccountCookie: true. Credential accounts use local:credential and the linked user's stable id as their provider identity. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth 1.6.24: Request-Kontext für verifyIdToken und beforeStoreCookie

better-auth 1.6.24 ergänzt Request-Kontext als drittes Argument für verifyIdToken und die Option beforeStoreCookie im last-login-method-Plugin und behebt mehrere Fehler, darunter fehlende no-store-Header bei get-session, SQLite-Migrationsdiffs mit BIGINT und den useSession-Typ mit throw: true.

better-auth

Features

  • Added request context (ctx) as a third argument to verifyIdToken, enabling custom ID token verifiers to read request headers (#10376)
  • Added beforeStoreCookie option to the last-login-method plugin for GDPR compliance (#5753)

Bug Fixes

  • Replaced flaky MongoDB where-coercion integration test with a direct unit test for more reliable test runs (#10369)
  • Fixed the get-session endpoint to include no-store cache control headers, preventing stale session data from being served (#10222)
  • Fixed SQLite migration diffs to recognize BIGINT as a valid number type, preventing spurious pending changes on rate limiter columns (#10316)
  • Fixed auth requests failing when request cloning throws an error inside verification callbacks (#10336)
  • Fixed useSession({ throw: true }) incorrectly excluding null from its data type (#9787)
  • Fixed auth query revalidation and signal listeners not being restored after a client component remounts (#10379) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth Version 1.7.0-rc.1

Version 1.7.0-rc.1 fügt Yandex als OAuth-Social-Provider hinzu und behebt unter anderem den Abbruch von auth migrate beim Hinzufügen erforderlicher oder eindeutiger Spalten, die Zeilenzählung in den D1- und postgres-js-Adaptern sowie das Escaping von String-Defaults im generierten Drizzle-Schema.

better-auth

Features

  • Added Yandex as a supported OAuth social provider (#9138)

Bug Fixes

  • Fixed auth migrate to no longer abort when adding required or unique columns to an existing table (#10293)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed affected row counting for D1 and postgres-js adapters (#10257)

For detailed changes, see CHANGELOG

auth

Bug Fixes

  • Fixed string default values to be properly escaped in generated Drizzle schema (#10259)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@bytaesu, @gustavovalverde, @vladflotsky

Full changelog: v1.7.0-rc.0...v1.7.0-rc.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth Version 1.6.23

Version 1.6.23 fügt Yandex als OAuth-Provider hinzu und behebt Fehler bei der Zeilenzählung in den D1- und postgres-js-Adaptern, bei Organisations-Abo-Aktionen im Stripe-Plugin sowie beim Escaping von String-Defaults im Drizzle-Schema.

better-auth

Features

  • Added Yandex as a social OAuth provider (#9138)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed affected row counting for D1 and postgres-js adapters (#10257)

For detailed changes, see CHANGELOG

@better-auth/stripe

Bug Fixes

  • Fixed organization subscription actions (cancel, upgrade, restore, and the billing portal) that could act on the wrong organization.

For detailed changes, see CHANGELOG

auth

Bug Fixes

  • Fixed string default values not being properly escaped in the generated Drizzle schema (#10259)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@bytaesu, @vladflotsky …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth Version 1.7.0-rc.0

Version 1.7.0-rc.0 bringt Breaking Changes, darunter Wildcard-Endpunkt-Matching beim Captcha, MCP als eigenes Paket (@better-auth/mcp) mit umbenannten Helfern und geändertem Datenbankschema sowie OIDC Back-Channel Logout im OAuth-Provider.

better-auth

❗ Breaking Changes

  • feat(captcha)!: support wildcard endpoint matching (#10004)

  • feat(mcp)!: ship MCP as its own package built on the OAuth provider (#9992)

    The route helper is renamed requireMcpAuth (was withMcpAuth), and the remote client is createMcpResourceClient (was createMcpAuthClient). requireMcpAuth verifies the bearer token against the published JWKS and passes the verified JWT claims to your handler.

    To migrate, install @better-auth/mcp, add the jwt() plugin (now required for token signing), and move options that were nested under oidcConfig to flat options on mcp({ ... }). The database models change: oauthApplication becomes oauthClient, with new oauthRefreshToken and oauthClientAssertion tables. Regenerate or migrate your schema with npx auth migrate or npx auth generate.

  • feat(oauth-provider)!: add OIDC back-channel logout (#9304) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth Version 1.7.0-beta.10

Version 1.7.0-beta.10 aktualisiert gebündelte Abhängigkeiten und behebt mehrere Fehler, etwa Rate Limiting vor Plugin-Handlern, das Widerrufen unbestätigter Credentials bei Magic-Link- und E-Mail-OTP-Anmeldung, Redirects bei serverseitigen OAuth-Requests und die Hosted-Domain-Prüfung bei Google.

better-auth

Bug Fixes

  • Bundled dependencies were refreshed to their latest compatible releases, including jose, nanostores, the noble crypto packages, and SimpleWebAuthn. These updates are backward compatible and require no changes to existing projects.
  • Fixed rate limiting to be applied before plugin request handlers run (#10191)
  • Fixed unproven credentials to be revoked when signing in via magic link or email OTP (#10239)
  • Fixed account-linking logs to be routed through the configured logger (#10121)
  • Fixed admin authorization to use authoritative session reads (#10187)
  • Fixed TypeScript inference errors by declaring inherited APIError properties (#8734)
  • Fixed server-side OAuth requests to no longer follow redirects (#10241)
  • Fixed the schema option in device authorization to be optional under Zod v4 (#9939)
  • Fixed hosted-domain validation to be applied consistently across all Google sign-in flows (#10197) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth Version 1.6.22

Version 1.6.22 behebt das fehlende Widerrufen unbestätigter Credentials bei Magic-Link- und E-Mail-OTP-Anmeldung, verhindert das Folgen von Redirects bei serverseitigen OAuth-Requests, korrigiert SCIM-Schreiboperationen und Stripe-Organisations-Abo-Aktionen und ergänzt eine kontenbezogene Verifizierungssperre für die Zwei-Faktor-Authentifizierung.

better-auth

Bug Fixes

  • Fixed unproven credentials not being revoked during magic link and email OTP sign-in (#10239)
  • Fixed server-side OAuth requests to refuse redirect responses instead of following them (#10241)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM write-path operations to be properly scoped and to correctly honor the active attribute (#10242)

For detailed changes, see CHANGELOG

@better-auth/stripe

Bug Fixes

  • Fixed organization subscription actions (cancel, upgrade, restore, and the billing portal) that could act on the wrong organization.

For detailed changes, see CHANGELOG

auth

Bug Fixes

  • Added account-level verification lockout for two-factor authentication (#10240) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth Version 1.6.21

Version 1.6.21 behebt mehrere Fehler, unter anderem werden Rate Limits nun vor den Plugin-Handlern durchgesetzt, Admin-Berechtigungsänderungen und Sperren wirken trotz Session-Cookie-Cache sofort, und die Prüfung bei Google-, OAuth-, PayPal- und SIWE-Anmeldungen wurde verbessert.

better-auth

Bug Fixes

  • Fixed rate limits to be enforced before plugin request handlers run (#10191)
  • Fixed admin permission changes and bans to take effect immediately, even when session cookie cache is enabled (#10187)
  • Fixed deviceAuthorization() throwing a ZodError when called without a schema option under Zod v4 (#9939)
  • Fixed Google hosted-domain validation to apply consistently across all sign-in flows, including Google One Tap (#10197)
  • Fixed OAuth proxy to reject profile callbacks that do not match an issued OAuth state, preventing session creation with stale state (#10183)
  • Fixed OAuth sign-up and account linking to ignore provider profile values for fields marked input: false (#10196)
  • Fixed PayPal sign-in to validate user info against the verified ID token subject (#10192)
  • Fixed SIWE sign-in to reject emails that already belong to another account, preventing one email from being attached to two accounts (#10228) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Betterauth von Better Auth

Better Auth Version 1.7.0-beta.9 mit Breaking Change im oauth-provider

Version 1.7.0-beta.9 von @better-auth/oauth-provider verhindert, dass geschützte OIDC/JWT-Claims wie iss oder sub über benutzerdefinierte ID-Token-Claims überschrieben werden (Breaking Change), unterstützt confidential DCR-Clients ohne PKCE sowie den Parameter claims.userinfo und behebt Fehler am UserInfo-Endpoint und bei offline_access.

@better-auth/oauth-provider

❗ Breaking Changes

  • Restricted customIdTokenClaims, extension ID-token claims, and per-issuance idTokenClaims from overriding protected OIDC/JWT protocol claims (#10140)

Migration: Remove any iss, sub, aud, exp, nonce, auth_time, acr, amr, or azp fields from customIdTokenClaims, extension ID-token claims, and per-issuance idTokenClaims. Use namespaced custom claims (e.g., "https://example.com/role") for application-specific data instead.

Features

  • Added support for confidential DCR clients to complete authorization-code flows without PKCE when clientRegistrationRequirePKCE: false is set (#10146)
  • Added support for the claims.userinfo authorization request parameter, allowing clients to request specific standard claims from the UserInfo endpoint (#10156)

Bug Fixes

  • Fixed the UserInfo endpoint to accept bearer tokens in application/x-www-form-urlencoded POST request bodies (#10155)
  • Fixed confidential clients that opted out of PKCE to successfully request offline_access when the authorization includes both openid scope and a nonce (#10153) …

Originalquelle(öffnet in neuem Tab)Problem melden

Betterauth Updates & Release Notes (Better Auth) – Oktober 2026 (Seite 2) | updatefeed