megachangelog
Fix1.6.30

Bug fixes and SSO domain verification improvements

Fixed concurrent cold-start requests that could lose authentication context due to async storage race conditions, and improved SSO domain verification to require verified provider domains and prevent unauthorized organization assignment via social sign-in.

better-auth

Bug Fixes

  • Fixed concurrent cold-start requests from intermittently losing authentication or transaction context due to an async storage initialization race (#10833)

For detailed changes, see CHANGELOG

@better-auth/sso

Bug Fixes

  • Fixed automatic organization assignment via email domain to require both a verified provider domain and a verified stored user email, preventing social sign-in from joining an organization whose SSO provider merely claims that domain.
  • Fixed domain verification to snapshot the provider's domains at request start, returning 409 with SSO_PROVIDER_CHANGED if the provider changes during DNS resolution so callers can reload and retry.

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@bytaesu

Full changelog: v1.6.29...v1.6.30

authssobug-fixsecuritystorage

Source: original entry ↗