Skip to content

Bump the better-auth group in /server with 3 updates - #21

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/server/better-auth-ad1f334d56
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/server/better-auth-ad1f334d56

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the better-auth group in /server with 3 updates: @better-auth/drizzle-adapter, better-auth and auth.

Updates @better-auth/drizzle-adapter from 1.7.6 to 1.7.7

Release notes

Sourced from @​better-auth/drizzle-adapter's releases.

v1.7.7

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@​aryan1306, @​bytaesu, @​gitmotion, @​gustavovalverde, @​lennondotw

Full changelog: v1.7.6...v1.7.7

Changelog

Sourced from @​better-auth/drizzle-adapter's changelog.

1.7.7

Patch Changes

  • #11331 35d7cd3 Thanks @​gitmotion! - Drizzle incrementOne now rejects updates when a concurrent write makes the original where condition false. This prevents stale updates and counter limits from being exceeded on PostgreSQL. Both the default adapter and relations-v2 retain the single-row limit.
Commits

Updates better-auth from 1.7.6 to 1.7.7

Release notes

Sourced from better-auth's releases.

v1.7.7

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@​aryan1306, @​bytaesu, @​gitmotion, @​gustavovalverde, @​lennondotw

Full changelog: v1.7.6...v1.7.7

Changelog

Sourced from better-auth's changelog.

1.7.7

Patch Changes

  • #11476 4186e36 Thanks @​bytaesu! - Return CAPTCHA errors with the correct JSON Content-Type header.

  • #11469 8620aa9 Thanks @​aryan1306! - Return rate limit errors with a JSON Content-Type header.

  • #11491 55cb92e Thanks @​bytaesu! - Respect social provider disableSignUp when signing in with an ID token.

  • #11375 69defbc Thanks @​bytaesu! - Refresh the active organization after sign-in when a session hook selects the initial organization.

  • #11494 ac54bfd Thanks @​gustavovalverde! - Isolate OAuth state cookies and each OAuth Proxy payload with purpose-specific encryption keys. The oAuthProxy options and supported configuration remain unchanged.

    Upgrade all Better Auth nodes that handle the same cookie-backed OAuth or SAML relay-state flow together. Upgrade every OAuth Proxy participant, including production and preview or development deployments, in the same cutover. OAuth sign-in, account-linking, and cookie-backed SAML sign-in flows started before the upgrade must be restarted. Mixed old and new participants cannot exchange existing state or proxy payloads, and there is no fallback to the previous shared key.

  • #11494 ac54bfd Thanks @​gustavovalverde! - Magic Link verification now accepts only records issued for Magic Link. Magic Link records and database-backed OAuth or SAML state use separate verification identifier prefixes. Links and database-backed sign-ins started before the upgrade cannot complete; request new Magic Links and restart those sign-ins. Upgrade servers sharing verification storage together, and update verification.storeIdentifier.overrides rules for these flows to match the new magic-link: and auth-state: prefixes. The link token, callback state, endpoints, and public option types are unchanged.

    Upgrade installed Better Auth adapters, plugins, and integrations released with better-auth alongside it so participating packages use the same release version.

  • Updated dependencies [35d7cd3, 07bdf7e]:

    • @​better-auth/drizzle-adapter@​1.7.7
    • @​better-auth/kysely-adapter@​1.7.7
    • @​better-auth/core@​1.7.7
    • @​better-auth/memory-adapter@​1.7.7
    • @​better-auth/mongo-adapter@​1.7.7
    • @​better-auth/prisma-adapter@​1.7.7
    • @​better-auth/telemetry@​1.7.7
Commits
  • db02f23 chore: release v1.7.7 (#11413)
  • ac54bfd fix(auth): isolate verification records and encryption purposes (#11494)
  • 69defbc fix(organization): refresh active organization after email sign-in (#11375)
  • 55cb92e fix(auth): honor social disableSignUp for ID token sign-in (#11491)
  • 4186e36 fix(captcha): return JSON content type for errors (#11476)
  • 8620aa9 fix(rate-limit): set JSON content type on 429 responses (#11469)
  • See full diff in compare view

Updates auth from 1.7.6 to 1.7.7

Release notes

Sourced from auth's releases.

v1.7.7

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@​aryan1306, @​bytaesu, @​gitmotion, @​gustavovalverde, @​lennondotw

Full changelog: v1.7.6...v1.7.7

Changelog

Sourced from auth's changelog.

1.7.7

Patch Changes

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the better-auth group in /server with 3 updates: [@better-auth/drizzle-adapter](https://github.com/better-auth/better-auth/tree/HEAD/packages/drizzle-adapter), [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) and [auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/cli).


Updates `@better-auth/drizzle-adapter` from 1.7.6 to 1.7.7
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/drizzle-adapter/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/drizzle-adapter)

Updates `better-auth` from 1.7.6 to 1.7.7
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/better-auth)

Updates `auth` from 1.7.6 to 1.7.7
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/cli)

---
updated-dependencies:
- dependency-name: "@better-auth/drizzle-adapter"
  dependency-version: 1.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: better-auth
- dependency-name: better-auth
  dependency-version: 1.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: better-auth
- dependency-name: auth
  dependency-version: 1.7.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: better-auth
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 8, 2026
@seenu-k seenu-k closed this Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant