mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-02 02:07:25 +08:00
Bumps [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) from 1.6.23 to 1.6.25. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/better-auth/better-auth/releases">better-auth's releases</a>.</em></p> <blockquote> <h2>v1.6.25</h2> <h2><code>better-auth</code></h2> <h3>Bug Fixes</h3> <ul> <li>Fixed Apple OAuth not sending the PKCE code challenge during authorization, causing token exchange failures (<a href="https://redirect.github.com/better-auth/better-auth/pull/10294">#10294</a>)</li> <li>Fixed Google One Tap creating new users when sign-up was disabled on the Google provider (<a href="https://redirect.github.com/better-auth/better-auth/pull/10479">#10479</a>)</li> <li>Fixed <code>$fetch</code> and <code>$store</code> not being exposed on the Solid client (<a href="https://redirect.github.com/better-auth/better-auth/pull/10444">#10444</a>)</li> <li>Fixed internal adapter queries being routed to the wrong table when a built-in table's <code>modelName</code> was set to another table's schema key (e.g. <code>user.modelName = "account"</code>).</li> </ul> <p>For detailed changes, see <a href="https://github.com/better-auth/better-auth/blob/07a646ea190167370fbbb60a0fa2c3be3bec5522/packages/better-auth/CHANGELOG.md"><code>CHANGELOG</code></a></p> <h2>Contributors</h2> <p>Thanks to everyone who contributed to this release:</p> <p><a href="https://github.com/birkskyum"><code>@birkskyum</code></a>, <a href="https://github.com/jsj"><code>@jsj</code></a>, <a href="https://github.com/krish-vachhani"><code>@krish-vachhani</code></a></p> <p><strong>Full changelog:</strong> <a href="https://github.com/better-auth/better-auth/compare/v1.6.24...v1.6.25"><code>v1.6.24...v1.6.25</code></a></p> <h2>v1.6.24</h2> <h2><code>better-auth</code></h2> <h3>Features</h3> <ul> <li>Added request context (<code>ctx</code>) as a third argument to <code>verifyIdToken</code>, enabling custom ID token verifiers to read request headers (<a href="https://redirect.github.com/better-auth/better-auth/pull/10376">#10376</a>)</li> <li>Added <code>beforeStoreCookie</code> option to the last-login-method plugin for GDPR compliance (<a href="https://redirect.github.com/better-auth/better-auth/pull/5753">#5753</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>Replaced flaky MongoDB where-coercion integration test with a direct unit test for more reliable test runs (<a href="https://redirect.github.com/better-auth/better-auth/pull/10369">#10369</a>)</li> <li>Fixed the <code>get-session</code> endpoint to include <code>no-store</code> cache control headers, preventing stale session data from being served (<a href="https://redirect.github.com/better-auth/better-auth/pull/10222">#10222</a>)</li> <li>Fixed SQLite migration diffs to recognize <code>BIGINT</code> as a valid number type, preventing spurious pending changes on rate limiter columns (<a href="https://redirect.github.com/better-auth/better-auth/pull/10316">#10316</a>)</li> <li>Fixed auth requests failing when request cloning throws an error inside verification callbacks (<a href="https://redirect.github.com/better-auth/better-auth/pull/10336">#10336</a>)</li> <li>Fixed <code>useSession({ throw: true })</code> incorrectly excluding <code>null</code> from its <code>data</code> type (<a href="https://redirect.github.com/better-auth/better-auth/pull/9787">#9787</a>)</li> <li>Fixed auth query revalidation and signal listeners not being restored after a client component remounts (<a href="https://redirect.github.com/better-auth/better-auth/pull/10379">#10379</a>)</li> <li>Fixed the <code>CookieAttributes</code> index signature type to be more precise (<a href="https://redirect.github.com/better-auth/better-auth/pull/10442">#10442</a>)</li> <li>Fixed silent misrouting of adapter queries when <code>user.modelName</code> was set to a value that collides with another schema key (<a href="https://redirect.github.com/better-auth/better-auth/pull/10235">#10235</a>)</li> <li>Fixed Kysely migration generation producing duplicate indexes for fields marked both <code>unique</code> and <code>index</code> (<a href="https://redirect.github.com/better-auth/better-auth/pull/10357">#10357</a>)</li> <li>Fixed magic-link and email-OTP send endpoints to validate the <code>Origin</code> header on cookieless requests, preventing cross-origin abuse (<a href="https://redirect.github.com/better-auth/better-auth/pull/10368">#10368</a>)</li> <li>Fixed remote MCP auth 401 challenge headers being hidden from browser clients due to missing CORS exposure (<a href="https://redirect.github.com/better-auth/better-auth/pull/10290">#10290</a>)</li> <li>Fixed OpenAPI schema to include plugin user fields (such as <code>username</code> and <code>displayUsername</code>) in <code>/sign-up/email</code> and <code>/update-user</code> request bodies (<a href="https://redirect.github.com/better-auth/better-auth/pull/10453">#10453</a>)</li> <li>Fixed <code>organization.listMembers</code> failing with "User not found for member" for organizations with more than ~100 members (<a href="https://redirect.github.com/better-auth/better-auth/pull/10342">#10342</a>)</li> <li>Fixed organization invitations to use database-generated IDs when <code>advanced.database.generateId</code> is configured, matching the behavior of other models (<a href="https://redirect.github.com/better-auth/better-auth/pull/10040">#10040</a>)</li> <li>Fixed <code>getDefaultModelName</code> to prefer exact schema key matches over <code>modelName</code> aliases, preventing adapter queries from being misrouted when a built-in table's name collides with another schema key</li> </ul> <p>For detailed changes, see <a href="https://github.com/better-auth/better-auth/blob/9a661c7b7abceaa81123b2c56757ee24f3ad2ed6/packages/better-auth/CHANGELOG.md"><code>CHANGELOG</code></a></p> <h2><code>auth</code></h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md">better-auth's changelog</a>.</em></p> <blockquote> <h2>1.6.25</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10479">#10479</a> <a href="https://github.com/better-auth/better-auth/commit/5124c3487903e96223bb3f54347724bb0204bb95"><code>5124c34</code></a> Thanks <a href="https://github.com/krish-vachhani"><code>@krish-vachhani</code></a>! - Prevent Google One Tap from creating new users when sign-up is disabled for the Google provider.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10444">#10444</a> <a href="https://github.com/better-auth/better-auth/commit/743935991f9991e8243d6c3d14773b9cfca462e8"><code>7439359</code></a> Thanks <a href="https://github.com/birkskyum"><code>@birkskyum</code></a>! - Expose the real <code>$fetch</code> instance and <code>$store</code> atoms from the Solid client instead of resolving them as dynamic API routes.</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/better-auth/better-auth/commit/0ffd1fb28d44a8266d62791cd4c97e263444d03b"><code>0ffd1fb</code></a>]:</p> <ul> <li><code>@better-auth/core</code><a href="https://github.com/1"><code>@1</code></a>.6.25</li> <li><code>@better-auth/drizzle-adapter</code><a href="https://github.com/1"><code>@1</code></a>.6.25</li> <li><code>@better-auth/kysely-adapter</code><a href="https://github.com/1"><code>@1</code></a>.6.25</li> <li><code>@better-auth/memory-adapter</code><a href="https://github.com/1"><code>@1</code></a>.6.25</li> <li><code>@better-auth/mongo-adapter</code><a href="https://github.com/1"><code>@1</code></a>.6.25</li> <li><code>@better-auth/prisma-adapter</code><a href="https://github.com/1"><code>@1</code></a>.6.25</li> <li><code>@better-auth/telemetry</code><a href="https://github.com/1"><code>@1</code></a>.6.25</li> </ul> </li> </ul> <h2>1.6.24</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10235">#10235</a> <a href="https://github.com/better-auth/better-auth/commit/03dc5a046f536994950800ea557b8e2e2e0cdfdd"><code>03dc5a0</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - Fixes silent foreign-key and adapter-join misrouting when a user remaps a built-in model name to a string that collides with another schema key</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10357">#10357</a> <a href="https://github.com/better-auth/better-auth/commit/750894037639c4158472cc1d4994b0e07bf1f59a"><code>7508940</code></a> Thanks <a href="https://github.com/c-nicol"><code>@c-nicol</code></a>! - Fixes Kysely migration generation for new-table fields that are both unique: true and index: true.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10342">#10342</a> <a href="https://github.com/better-auth/better-auth/commit/bae71988ab79aeb4f19f245ceabac9eca8706a50"><code>bae7198</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - Fix <code>organization.listMembers</code> failing with "User not found for member" for orgs with more than ~100 members by applying the same membership limit to the users query.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10336">#10336</a> <a href="https://github.com/better-auth/better-auth/commit/ef4d27360cec8a0bc11a94e135ea4a3dd32b1969"><code>ef4d273</code></a> Thanks <a href="https://github.com/Tushar-Khandelwal-2004"><code>@Tushar-Khandelwal-2004</code></a>! - Prevent verification callbacks from failing auth requests when cloning the request throws.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10333">#10333</a> <a href="https://github.com/better-auth/better-auth/commit/99dbdd7ea98740d11689394220a718dfb9579276"><code>99dbdd7</code></a> Thanks <a href="https://github.com/c-nicol"><code>@c-nicol</code></a>! - Fixes Drizzle schema generation for fields that are both unique: true and index: true.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10368">#10368</a> <a href="https://github.com/better-auth/better-auth/commit/086ca91f51dd8158aff6cbf54c4f9c7ce220914d"><code>086ca91</code></a> Thanks <a href="https://github.com/gaurav0107"><code>@gaurav0107</code></a>! - Force-validate the request <code>Origin</code> on the magic-link (<code>/sign-in/magic-link</code>) and email-otp (<code>/email-otp/send-verification-otp</code>) send endpoints, including cookieless requests, to match the built-in <code>/sign-in/email</code> and <code>/sign-up/email</code> routes. A cookieless cross-origin POST can no longer trigger a magic-link or verification-OTP email to an arbitrary address. Cookieless requests that carry no <code>Origin</code> (server-to-server) are unaffected.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10290">#10290</a> <a href="https://github.com/better-auth/better-auth/commit/8f2dedd89301da9fb52c1a64df6a9683f9be55fd"><code>8f2dedd</code></a> Thanks <a href="https://github.com/GautamBytes"><code>@GautamBytes</code></a>! - Expose the remote MCP auth client's 401 challenge headers to browser clients using CORS.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10453">#10453</a> <a href="https://github.com/better-auth/better-auth/commit/4e685eef420b5576913b9803b58c7e7ee7342203"><code>4e685ee</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - OpenAPI now includes <code>user.additionalFields</code> and plugin user schema fields (e.g. username plugin <code>username</code> / <code>displayUsername</code>) on <code>/sign-up/email</code> and <code>/update-user</code> request bodies.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10190">#10190</a> <a href="https://github.com/better-auth/better-auth/commit/3bf0e4981e025ba9af684013a27b0102a04f7c56"><code>3bf0e49</code></a> Thanks <a href="https://github.com/gaurav-init"><code>@gaurav-init</code></a>! - Pass the endpoint context as the second argument to <code>beforeDeleteOrganization</code> and <code>afterDeleteOrganization</code> hooks in the organization plugin, matching the signature shown in the docs and the existing <code>databaseHooks</code> pattern. The Stripe plugin's <code>beforeDeleteOrganization</code> wrapper now forwards the context to user-supplied hooks instead of dropping it.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10040">#10040</a> <a href="https://github.com/better-auth/better-auth/commit/f59a0ee7895a024ddd4c5c387344173888e17be4"><code>f59a0ee</code></a> Thanks <a href="https://github.com/shiminshen"><code>@shiminshen</code></a>! - Organization invitations now let the database generate their <code>id</code> when ID generation is delegated to the database (e.g. <code>advanced.database.generateId: "uuid"</code> with a UUID-capable adapter such as Postgres), matching every other model. Previously <code>createInvitation</code> always generated the invitation <code>id</code> in application code, so invitation rows received an app-generated value instead of a database-generated one while organizations, members and teams correctly deferred to the database (<a href="https://redirect.github.com/better-auth/better-auth/issues/10024">better-auth/better-auth#10024</a>). A caller-provided id (e.g. via <code>beforeCreateInvitation</code>) is still honored.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10302">#10302</a> <a href="https://github.com/better-auth/better-auth/commit/0f2cc1b33b77850948dac4d889e5f46bba41e8d5"><code>0f2cc1b</code></a> Thanks <a href="https://github.com/momomuchu"><code>@momomuchu</code></a>! - Prefer exact schema-key matches over <code>modelName</code> aliases in <code>getDefaultModelName</code>, so remapping a built-in table onto another table's schema key (e.g. <code>user.modelName = "account"</code>) does not reroute internal adapter queries to the wrong table.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9787">#9787</a> <a href="https://github.com/better-auth/better-auth/commit/ae781091186f321b4e4ec9e84f64b6e4d5ea1043"><code>ae78109</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - Fixes an issue where <code>useSession({ throw: true })</code> incorrectly excluded <code>null</code> from its <code>data</code> type.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10222">#10222</a> <a href="https://github.com/better-auth/better-auth/commit/46d2bf02c98902da7b344753372d48cfe0e5ebb3"><code>46d2bf0</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - fix: add no-store cache-control headers to get-session route</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10316">#10316</a> <a href="https://github.com/better-auth/better-auth/commit/29a373eaf1778820061a9380c29831c2de2ce704"><code>29a373e</code></a> Thanks <a href="https://github.com/vinay-oppuri"><code>@vinay-oppuri</code></a>! - Recognize SQLite <code>BIGINT</code> as a valid number type in migration diffs so database-backed rate limiter columns like <code>lastRequest</code> no longer report spurious pending changes on every run.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10379">#10379</a> <a href="https://github.com/better-auth/better-auth/commit/f6d18fa8f79b9323e10b50f72e2b1a088844e4bb"><code>f6d18fa</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - fix(client): restore auth query revalidation and signal listeners after remount</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/better-auth/better-auth/commit/07a646ea190167370fbbb60a0fa2c3be3bec5522"><code>07a646e</code></a> chore: release v1.6.25 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10491">#10491</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/743935991f9991e8243d6c3d14773b9cfca462e8"><code>7439359</code></a> fix(solid): expose $fetch and $store on the solid client (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10444">#10444</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/dac701c94bcd777e7cb124570d644f8b4a7981a5"><code>dac701c</code></a> chore(deps): bump next from 16.2.6 to 16.2.11 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10493">#10493</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/5124c3487903e96223bb3f54347724bb0204bb95"><code>5124c34</code></a> fix(one-tap): enforce google provider signup restrictions (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10479">#10479</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/9a661c7b7abceaa81123b2c56757ee24f3ad2ed6"><code>9a661c7</code></a> chore: release v1.6.24 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10323">#10323</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/4e685eef420b5576913b9803b58c7e7ee7342203"><code>4e685ee</code></a> fix(open-api): include plugin user fields on sign-up/update bodies (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10453">#10453</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/d3ce7823324ba64efd423895b1c122d85c6d7663"><code>d3ce782</code></a> fix(cookies): tighten CookieAttributes index signature type (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10441">#10441</a>) (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10442">#10442</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/ae781091186f321b4e4ec9e84f64b6e4d5ea1043"><code>ae78109</code></a> fix(client): preserve null in useSession().data type with throw:true (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/9787">#9787</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/f6d18fa8f79b9323e10b50f72e2b1a088844e4bb"><code>f6d18fa</code></a> fix(client): restore auth query lifecycle after remount (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10379">#10379</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/086ca91f51dd8158aff6cbf54c4f9c7ce220914d"><code>086ca91</code></a> fix(magic-link, email-otp): force-validate Origin on cookieless send endpoint...</li> <li>Additional commits viewable in <a href="https://github.com/better-auth/better-auth/commits/v1.6.25/packages/better-auth">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>