megachangelog
Security1.7.7

Magic Link upgrade and critical security fixes

Better Auth v1.7.7 addresses a critical Magic Link account-takeover vulnerability and multiple security issues including OAuth/SAML sign-in bugs and missing JSON headers in error responses. Magic Link requires a server upgrade with verification storage coordination, but no database migration is needed.

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494)
    Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@aryan1306, @bytaesu, @gitmotion, @gustavovalverde, @lennondotw

Full changelog: v1.7.6...v1.7.7

securityauthmagic-linkoauthbug-fix

Source: original entry ↗

More from Better Auth

Follow Better Auth to get its new changes in your feed and email digest.

Improvement1.7.6

v1.7.6

Better Auth v1.7.6 adds support for customizable banned user messages and Vercel BotID captcha provider for authentication. This release fixes critical bugs including React hydration mismatches, password length validation, overlapping auth query requests, model identity issues across multiple adapters, and OAuth social account linking.

authcaptchasecurityadaptersbug-fixes
Improvement1.7.5

v1.7.5 Release

This release adds database schema name support for direct PostgreSQL connections and includes multiple bug fixes across better-auth packages, including improvements to server-side logging, database migrations, index validation, and adapter initialization.

postgresqldatabasebug-fixesadapterslogging
See all Better Auth changes →