better-auth
Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.
Bug Fixes
- Fixed a critical Magic Link account-takeover vulnerability. (#11494)
- Fixed ID-token sign-in ignoring the social provider’s
disableSignUpsetting. (#11491) - Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494)
Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance. - Fixed CAPTCHA errors missing the JSON
Content-Typeheader. (#11476) - Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
- Fixed rate-limit errors missing the JSON
Content-Typeheader. (#11469)
For detailed changes, see CHANGELOG
@better-auth/oauth-provider
Features
- Added optional
validateRedirectUrivalidation for trusted deployments with dynamic OAuth redirect URIs. (#8686) - Added
verifyOAuthQueryParamsto verify signed authorization queries before rendering a custom consent page. (#11402)
For detailed changes, see CHANGELOG
@better-auth/drizzle-adapter
Bug Fixes
- Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)
For detailed changes, see CHANGELOG
@better-auth/kysely-adapter
Bug Fixes
- Fixed
consumeOnedeleting a record after a concurrent write invalidates its original condition. (#11495)
For detailed changes, see CHANGELOG
Contributors
Thanks to everyone who contributed to this release:
@aryan1306, @bytaesu, @gitmotion, @gustavovalverde, @lennondotw
Full changelog: v1.7.6...v1.7.7