better-auth
Bug Fixes
- Fixed
forceAllowIdUUIDs set in database hooks being ignored on PostgreSQL adapters whenadvanced.database.generateIdis set to"uuid"(#9068) - Reverted 2FA enforcement scope to credential sign-in paths only, so magic link, email OTP, OAuth, SSO, passkey, and other non-credential sign-in flows no longer trigger a 2FA challenge (#9205)
For detailed changes, see CHANGELOG
Contributors
Thanks to everyone who contributed to this release:
@GautamBytes, @gustavovalverde
Full changelog: v1.6.3...v1.6.4