Sourced from better-auth's releases.
v1.7.2
better-authBug Fixes
- Fixed permanent user bans to clear expiration dates from previous temporary bans. (#10823)
- Fixed client types with more plugins being assignable to types declaring fewer plugins. (#10907)
- Added warnings for invalid signed session data in the cookie cache. (#10934)
- Fixed disabled MyISAM indexes from satisfying migration index checks. (#10877)
- Fixed programmatic migrations on Cloudflare D1 while preserving existing-index validation. (#10875)
- Allowed
~in relative callback URLs validated by trusted-origin checks. (#10041)- Improved validation of relative callback and redirect URLs with paths, queries, and fragments. (#10979)
- Allowed same-origin form submissions with
Referrer-Policy: no-referrerwhile continuing to reject untrusted origins. (#10959)- Improved
getTestInstanceperformance with a faster default password hasher. (#10879)- Standardized built-in placeholder emails to the namespaced
{identifier}@{namespace}.placeholder.invalidformat. (#10982)For detailed changes, see
CHANGELOG
@better-auth/coreBug Fixes
- Fixed async context loss in Cloudflare Workers bundles with multiple runtime conditions. (#10855)
- Fixed auth request logs to respect the configured logger, log level, and disabled setting. (#10939)
- Improved validation of relative callback and redirect URLs with paths, queries, and fragments. (#10979)
- Standardized built-in placeholder emails to the namespaced
{identifier}@{namespace}.placeholder.invalidformat. (#10982)- Added synchronous and optional access to the current auth endpoint context. (#10938)
For detailed changes, see
CHANGELOG
@better-auth/oauth-providerBug Fixes
- Fixed Client ID Metadata Document registration when clients share at least one supported grant with the server. (#11010)
- Improved validation of relative callback and redirect URLs with paths, queries, and fragments. (#10979)
- Fixed relative redirect URLs containing fragments. (#10983)
For detailed changes, see
CHANGELOG
@better-auth/drizzle-adapterBug Fixes
- Fixed one-to-one Drizzle relations when
usePluralis enabled. (#10941)- Added validation for missing Drizzle schema fields in compound
whereclauses. (#10859)For detailed changes, see
CHANGELOG
@better-auth/kysely-adapter
... (truncated)
Sourced from better-auth's changelog.
1.7.2
Patch Changes
#10875
d5d889bThanks@bytaesu! - Fix programmatic migrations failing on Cloudflare D1 while preserving existing-index validation across supported databases.#10982
b4ad5a1Thanks@bytaesu! - Built-in placeholder emails now consistently use the namespaced{identifier}@{namespace}.placeholder.invalidformat.#10934
c7a5c1aThanks@bytaesu! - Cookie-cache reads now warn when signed session data is invalid instead of silently appearing as a signed-out session.#10879
78f0c39Thanks@starslingdev! - Test suites usinggetTestInstancenow run faster because the shared fixture avoids production password-hashing costs by default. CustomemailAndPassword.passwordimplementations continue to take precedence.#10823
ce8a3abThanks@sosyz! - Ensure permanently banning a user clears any expiration from a previous temporary ban.#10907
a021eafThanks@heliohm! - A client created with more plugins is again assignable to a client type declaring fewer plugins, as in 1.6.#10959
c8dcfa5Thanks@bytaesu! - Allow same-origin form submissions from pages usingReferrer-Policy: no-referrerwhile continuing to reject untrusted request origins.#10979
fced1a5Thanks@bytaesu! - Allow relative callback and redirect URLs to use standard path, query, and fragment syntax while preserving open-redirect protections.#10041
f6891a2Thanks@GautamBytes! - Allow~in relative callback URLs validated by trusted origin checks.#10877
649818aThanks@bytaesu! - Prevent disabled MyISAM indexes from satisfying migration index checks.Updated dependencies [
557e19b,64da15b,d5d889b,b4ad5a1,ea77118,5aea9f7,fced1a5,e1d4011]:1.7.1
Patch Changes
#10863
845bbd1Thanks@gustavovalverde! -auth migrateno longer attempts to add a required column with no default value to a table that already has rows. It stops with an error naming the column and the backfill to run first. Previously the generated statement failed on SQLite, Postgres, and SQL Server; on MySQL it filled the new column with an empty string for every existing row and reported success. Ifauth migratealready ran against a MySQL database on 1.7, run the check in the upgrade guide's account identity section.
getMigrationsthrows the newUnsafeMigrationError(exported frombetter-auth/db/migration) for this refusal, so callers can distinguish it from other migration errors such as an index-definition conflict.
auth generatestill emits the statements for external migration tooling, with a comment banner naming any column that needs a manual backfill first.A required field whose database column is still nullable logs a warning instead of blocking the migration.
A CLI command that fails now prints its error and exits with a non-zero code instead of an unhandled promise rejection.
Updated dependencies []:
... (truncated)
ba12fcd
chore: release v1.7.2 (#10870)79904f0
fix(origin-check): support fragments in relative redirect URLs (#10983)c8dcfa5
fix(origin-check): validate null origins using fetch metadata (#10959)e1d4011
fix(logger): respect configured logger in auth request context (#10939)557e19b
refactor(context): clarify auth endpoint context access (#10938)b4ad5a1
refactor: centralize placeholder email generation (#10982)fced1a5
fix(origin-check): improve relative callback URL validation (#10979)f6891a2
fix(origin-check): allow tilde in relative callback URLs (#10041)ce8a3ab
fix(admin): ban without a duration should clear the previous expiration
(#10823)a021eaf
fix(client): a client with more plugins fits a narrower client type
again (#1...