Skip to content

Update dependency better-auth to v1.7.7 - #50

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/better-auth-1.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/better-auth-1.x

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
better-auth (source) ~1.7.6 → ~1.7.7 age adoption passing confidence
better-auth (source) 1.7.6 → 1.7.7 age adoption passing confidence

Release Notes

better-auth/better-auth (better-auth)

v1.7.7

Compare Source

Patch Changes
  • #​11476 4186e36 Thanks @​bytaesu! - Return CAPTCHA errors with the correct JSON Content-Type header.

  • #​11469 8620aa9 Thanks @​aryan1306! - Return rate limit errors with a JSON Content-Type header.

  • #​11491 55cb92e Thanks @​bytaesu! - Respect social provider disableSignUp when signing in with an ID token.

  • #​11375 69defbc Thanks @​bytaesu! - Refresh the active organization after sign-in when a session hook selects the initial organization.

  • #​11494 ac54bfd Thanks @​gustavovalverde! - Isolate OAuth state cookies and each OAuth Proxy payload with purpose-specific encryption keys. The oAuthProxy options and supported configuration remain unchanged.

    Upgrade all Better Auth nodes that handle the same cookie-backed OAuth or SAML relay-state flow together. Upgrade every OAuth Proxy participant, including production and preview or development deployments, in the same cutover. OAuth sign-in, account-linking, and cookie-backed SAML sign-in flows started before the upgrade must be restarted. Mixed old and new participants cannot exchange existing state or proxy payloads, and there is no fallback to the previous shared key.

  • #​11494 ac54bfd Thanks @​gustavovalverde! - Magic Link verification now accepts only records issued for Magic Link. Magic
    Link records and database-backed OAuth or SAML state use separate verification
    identifier prefixes. Links and database-backed sign-ins started before the
    upgrade cannot complete; request new Magic Links and restart those sign-ins.
    Upgrade servers sharing verification storage together, and update
    verification.storeIdentifier.overrides rules for these flows to match the new
    magic-link: and auth-state: prefixes. The link token, callback state,
    endpoints, and public option types are unchanged.

    Upgrade installed Better Auth adapters, plugins, and integrations released
    with better-auth alongside it so participating packages use the same release
    version.

  • Updated dependencies [35d7cd3, 07bdf7e]:


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • Only on Thursday (* * * * 4)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants