* refactor: upgrade Svelte, Vite and related packages
* refactor: replace no longer supported `body.callbackURL` with `onSuccess`
* fix: add missing `svelte-kit sync` on `prepare`
* fix: add missing `import`s
* chore(svelte-kit-example): show message & redirect to index after sign up
* chore: add npm script to migrate database
* doc: add more commands to set up
* chore: explicitly disable verification email on sign up
The example does not work if you set `sendOnSignUp: true` without setting up the email server.
* refactor(svelte-kit-example): add type for hooks
* chore(svelte-kit-example): redirect to sign in page if users open dashboard without log in
* chore: diable some rules for svelte-kit-example due to Biome's limited Svelte support
* style: fix format
* chore: update pnpm-lock.yaml
* chore: fix lock file
---------
Co-authored-by: Bereket Engida <Bekacru@gmail.com>
* feat: first draft of SIWE plugin
* fix: run biome linter
* refactor(siwe): rename publicKey to walletAddress for clarity
- Add ensName as an optional param from the client
- Add emailDomainName to plugin options - fallback to getOrigin()
- Move schema to a separate file
* fix(siwe): update emailDomainName assignment to use nullish coalescing operator
* run biome linter
* fix(siwe): avatar field is not included in createUser call
* refactor(siwe): remove siwe dependency and implement nonce generation and message verification through plugin options
- Removed direct dependency on 'siwe' package.
- Introduced 'generateSiweNonce' and 'verifySiweMessage' as user functions
- Updated tests to reflect changes in nonce handling and message verification logic (WIP)
* feat: add anonymous flag to plugin options
* refactor(siwe): improve test coverage - anonymous flag, missing nonce & other edge cases
* feat(siwe): add checksum address validation using keccak256 + test case
* fix(siwe): refactor hashing utility to use @noble/hashes
* feat(siwe): enhance SIWE plugin with chainId support, strong typing, dedicated table for wallet adresses and more test coverage
* refactor(siwe): remove unused SIWE interfaces
* fix(siwe): PR review issues
* fix(siwe): rename const "siweClientPlugin" to "siweClient" for simplicity
* feat(siwe): add docs
* chore: fix lock file
* fix: account linking & code formatting
* run pnpm lint
---------
Co-authored-by: Bereket Engida <Bekacru@gmail.com>
Refactors
- Updated all imports and type references to use zod/v4.
- Replaced deprecated or changed Zod APIs and options across the codebase.
- Adjusted validation schemas and error messages to match Zod v4 requirements.
- Updated dependencies and lockfiles to use Zod v4.
* docs: Add guide for Sign In with Apple
* docs-feat: add apple JWT generator
* fix-lint: ran lint:fix to fix CI test
* chore: refactor to remove jose
* update docs
* chore: lock file
* fix test
---------
Co-authored-by: Bereket Engida <Bekacru@gmail.com>
- Bump '@types/bun' from 1.2.17 to 1.2.18
- Update '@better-auth/utils' from 0.2.5 to 0.2.6
- Adjust versioning for 'bun-types' and 'vinxi' to reflect new dependencies
* fix(email-verification): improve email verification logic to check session and user email consistency (#3042)
* docs(passkey): Fixed signIn passkey props (#3014)
callbackURL doesn't exist.
* fix(email-otp): auto-verify on email otp reset (#3022)
* fix: delete user should respect freshAge config (#3075)
* fix: delete user needs to enforced through fresh age
* cleanup
* cleanup
* chore(org): add comments explaining what shimContext does (#3098)
* feat: Allow passing `id` in DB hook `create` (#3048)
* feat(database-hooks): Allow passing `id` in DB hook `create`
It's the same to using a custom `idGenerator`, except configurable by the database hook which would in theory provide more data.
A use-case is to generate the id based on user info in the user before DB hook.
Solves https://discord.com/channels/1288403910284935179/1379190465588367540/1384217435535835216
* chore: lint
* fix: tests failing
* docs: basic errs with svg props (#3102)
* docs: corrected github user email scope name (#3099)
* docs: corrected github user email scope name
* docs: cubic dev suggestion
* fix: use correct refresh token endpoint for github (#3095)
* chore: fix typo in authorize comment (#3106)
* docs: fix session parameter spelling (#3108)
* docs: input field usage on additional fields (#2991)
* fix: onLinkAccount trigger on phone number verification (#3007)
* fix: expose headers override in jwt plugin (#3019)
* expose headers override in jwt plugin
* clean up
* lint
* fix(expo): remove duplicated trusted origins
* feat: link account with idToken (#1830)
* add idToken to link account
* add docs
* Implemented linking accounts based on idToken
* fix: tests
* docs: prevent diff
* docs: prevent diff
---------
Co-authored-by: kzlar <120426485+kzlar@users.noreply.github.com>
* feat: add Hugging Face provider (#3089)
* feat: add huggingface provider
* Add hugging face to doc
* chore: update hugging face logo
* chore: release v1.2.10
* docs: fix builder failing to open
* docs(NextJS): Improve middleware example to be more secure (#3135)
* docs(NextJS): Improve middleware example to be more secure
Users can skim code without reading the text, and LLMs can read code and miss-understand context correctly. Our current middleware example only checks for existence of a cookie, and doesn't validate it.
While we do warn users this isn't secure, some users has raised concern in a Github issue saying it's not obvious enough for users who skim.
Also we don't provide examples on how to authenticate users on each route, we only show middleware optimistic check examples.
* Update docs/content/docs/integrations/next.mdx
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
---------
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* fix(username): log the correct username (#3127)
* docs: fix typo in plugin (#3122)
* typo
* typo
* typo
* typo
* typo
* docs: fix typos on mcp guide (#3146)
* docs: update TanStack Start integration guide (#3142)
* fix(sveltekit): only dynamic import $app/environment once (#3152)
Co-authored-by: Work <work@Jasons-MacBook-Pro.local>
* docs: fix typo in oauth proxy documentation (#3151)
* blog: seed round announcement (#3168)
* init
* cleanup
* fix seed round announcemnt
* fix seed round announcemnt
* seed round blog
* add nav mobile
* fix typo
* Update docs/content/blogs/seed-round.mdx
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* Update docs/app/blog/[[...slug]]/page.tsx
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* Update docs/app/blog/[[...slug]]/page.tsx
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* update og
* cleanup
---------
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
* docs: fix email address
* refactor(mongo-adapter): migrate to createAdapter (#3170)
In the past we didn't have mongoDb adapter move over to createAdapter since we've seen users running into issues.
However some time ago I've merged a PR which I believe fixed the issue, and after testing the org plugin with the mongo adapter that uses `createAdapter` I don't see any issues.
* fix(api-key): update should only use by ID
* docs: fix blog page layout (#3176)
* fix/blog-page-layouts
* clean up
* docs: update contact email in seed round blog
* init
* cleanup
* feat(better-auth): add test utilities and update dependencies
- Introduced a new test utility module in `src/test-utils/index.ts` for better testing support.
- Updated `package.json` to include new test utilities in the build configuration.
- Added `oauth2-mock-server` dependency to `pnpm-lock.yaml` and `sso/package.json` for OAuth2 testing.
- Enhanced the SSO provider registration process with improved error handling.
* docs update
---------
Co-authored-by: Maxwell <145994855+ping-maxwell@users.noreply.github.com>
Co-authored-by: KinfeMichael Tariku <65047246+Kinfe123@users.noreply.github.com>
Co-authored-by: Undefined Ninja <74867549+0xCodeMaieutics@users.noreply.github.com>
Co-authored-by: artemoire <18062266+artemoire@users.noreply.github.com>
Co-authored-by: reslear <12596485+reslear@users.noreply.github.com>
Co-authored-by: kzlar <120426485+kzlar@users.noreply.github.com>
Co-authored-by: Eliott C. <coyotte508@protonmail.com>
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
Co-authored-by: Alessandro Bortolin <bortolin.alessandro@outlook.it>
Co-authored-by: Lakshya Thakur <lapstjup@gmail.com>
Co-authored-by: Usman S. (Max Programming) <51731966+max-programming@users.noreply.github.com>
Co-authored-by: Jason Venable <jason.venable@gmail.com>
Co-authored-by: Work <work@Jasons-MacBook-Pro.local>
Co-authored-by: Dan McGrath <daniel.mcgrath9@gmail.com>
* refactor(adapter): `createAdapter` helper
* update: Kysely adapter support
* update: memory adapter
* chore: cleanup
* update: MongoDB adapter supported
* update: mongodb adapter file names
* update: support for prisma adapter
- also fixed memory adapter with `getField`
- disabled all debug logs by default
* chore: lint
* fix: generate an `id` if it isn't already provided
* update(test): init config snapshot
* update: existing adapters tests to include an `id` existence check
* fix: renamed prisma adapter file names
* ^
* update(mongo): Removed `disableIdGeneration` for mongo adapter
* fix: dont add `id` from fields if `disableIdGeneration` is false
* fix: adapter converting dates to string using the wrong value data
* add: create-adapter tests
* update: moved `adapter` to `create-adapter` under the existing `adapters` folder
* WIP: docs
* fix: create-adapter test importing from wrong path
* WIP: docs
* update: key transformation map options are now objs not fns
* chore: lint
* update: cleanup & added debugLogs/usePlural option to some adapters
* update: tests
* chore: cleanup
* update: fields name & made customTransforminput/output to run after supportsDates/supportsBoolean/SupportsJSON to run
* chore: lint
* Update: docs
* update: update-many to not use transformOutput
* chore: lint
* fix: adapter options breaking
* update: set the default limit on findMany
* update: docs
* update: docs & cleaned up code
* update: create schema comes with `tables` now
* This is useless
* fix: api-key shouldn't handle id gen in row creation
* chore: lint
* WIP: useNumberId
* chore: cleanup
* removed all cases of `id` during adapter.create call
* update: useNumberId
* update: drizzle adapter schema generation
- update: pg now sets `id` field to use `uuid`.
- fix: sets the correct reference `onDelete` action.
- refactor: cleaned up the code a lot more
* update: added `supportNumericIds` in create adapter options
* chore: cleanup
* update(tests): added option to disable any adapter tests & created a `useNumberId` test
* fix: skip tests options were using old method
* chore: lint
* WIP: Drizzle tests with number id
* chore: lint
* fix: memory adapter failing on number id adapter tests
* chore: cleanup
* fix: adapter tests fail due to emails needing to be unique
* update: support drizzle adapter use-number-id
* fix: cleanup Drizzle Adapter tests
* fix: drizzle schema generation for reference id fields
* fix: type errs in memory adapter tests
* fix: memory adapter tests
* Update init.test.ts.snap
* fix: prisma tests correctly uses the right primsa client per schema
* Delete run-vitest.ts
* update: create-adapter to support `getDefaultFieldName`
* update: create-adapter adapter options updated
* fix: adapters using older function names
* fix: create-adapter now converts where clauses & added tests
* update: new `getFieldAttributes` option in create-adapter, and fixed convert where clause fn
* chore: cleanup
* update: convertWhereClause in create-adapter improved
* update: BAOptions to start using `database` & updated adapter tests
* fix: type errors
* chore: lint
* update: default config values for the create-adapter config
* fix: getModelName doesnt take into account of plural
* chore: cleanup
* update: improved getDefaultModelname
* fix: create-adapter transform input doesn't take into account reference IDs
* fix: transformInput on reference IDs doesn't take into account of array IDs
* chore: lint
* fix: prisma tests
* fix: Prisma adapter tests running one after another
* fix: init snapshot should state supportJSON as `false`
* fix: drizzle adapter tests
* update: adapter test options to allow passing a test prefix
* chore: add state.txt to gitignore
* remove: state.txt from gitignore, it's useless
* chore: lint
* Update adapter.prisma.numberid.test.ts
* fix: get-migration for mysql & mssql `id` fields to use varchar
* chore: cleanup
* update: adapter comes with adapter-test-debug-log functions
* update: made adapterTestDebugLog functions only be in adapter if config enabled it
* fix: transactionId for debug logs not working correctly
This was due to the adapter being reinitialized each test case
* update: Added colors to debug logs
* update: adapter tests a little more refined
* add: deepmerge dev deps to deep merge better auth options config for adapters
* fix: create-adapter types
* update: revert back to old types
* fix: prisma adapter tests now run one after another
* fix: kysely adapter to work when no `id` is provided
* update: mongoDB to set `supportNumericids` to false
* update(docs): discuss new `database` object in BetterAuthOptions
* add: support for custom ID generation
* fix: docs had incorrect default value for `supportsJSON`
* update(docs): added number id adapter test documentation
* fix: drizzle-adapter mysql tests
* update: drizzle-adapter tests to use deepmerge
* add: drizzle-adapter mysql tests to test useNumberId
* add: Prisma generate to support number id
* update: support the old `generateId` option, but warn the user for deprecation
* update: init test snapshot
* update: adapter tests not included in normal tests
* Update pnpm-lock.yaml
* fix: typo in file names for kysley test files
* update: separated adapter tests
* Update pnpm-lock.yaml
* fix: please tell me I actually fixed this
* fix: pnpm-lock merge conflict
* chore: lint
* fix: sveltekit pkg.json merge conflicts (hopefully)
* Delete pnpm-lock.yaml
* update: createSchema takes into account of rate-limit and secondaryStorage
* improve docs
* add drizzle returning id retriver
* chore: fix test script
---------
Co-authored-by: Bereket Engida <bekacru@gmail.com>