Magic Link upgrade and critical security fixes
Better Auth v1.7.7 addresses a critical Magic Link account-takeover vulnerability and multiple security issues including OAuth/SAML sign-in bugs and missing JSON headers in error responses. Magic Link requires a server upgrade with verification storage coordination, but no database migration is needed.
better-auth
Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.
Bug Fixes
- Fixed a critical Magic Link account-takeover vulnerability. (#11494)
- Fixed ID-token sign-in ignoring the social provider’s
disableSignUpsetting. (#11491) - Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494)
Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance. - Fixed CAPTCHA errors missing the JSON
Content-Typeheader. (#11476) - Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
- Fixed rate-limit errors missing the JSON
Content-Typeheader. (#11469)
For detailed changes, see CHANGELOG
@better-auth/oauth-provider
Features
- Added optional
validateRedirectUrivalidation for trusted deployments with dynamic OAuth redirect URIs. (#8686) - Added
verifyOAuthQueryParamsto verify signed authorization queries before rendering a custom consent page. (#11402)
For detailed changes, see CHANGELOG
@better-auth/drizzle-adapter
Bug Fixes
- Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)
For detailed changes, see CHANGELOG
@better-auth/kysely-adapter
Bug Fixes
- Fixed
consumeOnedeleting a record after a concurrent write invalidates its original condition. (#11495)
For detailed changes, see CHANGELOG
Contributors
Thanks to everyone who contributed to this release:
@aryan1306, @bytaesu, @gitmotion, @gustavovalverde, @lennondotw
Full changelog: v1.7.6...v1.7.7
Source: original entry ↗
More from Better Auth
Follow Better Auth to get its new changes in your feed and email digest.
v1.7.6
Better Auth v1.7.6 adds support for customizable banned user messages and Vercel BotID captcha provider for authentication. This release fixes critical bugs including React hydration mismatches, password length validation, overlapping auth query requests, model identity issues across multiple adapters, and OAuth social account linking.
v1.7.5 Release
This release adds database schema name support for direct PostgreSQL connections and includes multiple bug fixes across better-auth packages, including improvements to server-side logging, database migrations, index validation, and adapter initialization.
Fixed database option type inference for non-Cloudflare projects
Fixed database option type inference for projects that do not use Cloudflare Workers, improving compatibility for diverse deployment environments.