Skip to content

Add authentication protocol specification - #46

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-better-auth-plugin
Jan 21, 2026
Merged

Add authentication protocol specification#46
hotlong merged 7 commits into
mainfrom
copilot/add-better-auth-plugin

Conversation

CopilotAI commented Jan 21, 2026

Copy link
Copy Markdown
Contributor

Authentication Standard Specification

Status: All Review Issues Fixed

Summary

Fixed all inconsistencies identified by code review - updated type names, file paths, and examples throughout tests and documentation.

Changes Made

1. File Renaming:

  • authentication.zod.tsauth.zod.ts
  • authentication.test.tsauth.test.ts
  • AUTHENTICATION.mdAUTHENTICATION_STANDARD.md

2. Symbol Renaming (Shorter Names):

  • AuthenticationConfigSchemaAuthConfigSchema
  • AuthenticationConfigAuthConfig
  • AuthenticationProviderSchemaStandardAuthProviderSchema (to avoid conflict with identity.zod.ts)
  • AuthenticationProviderStandardAuthProvider
  • AuthStrategy (already short, kept as-is)

3. Schema Updates:

  • ✅ Added driver field to AuthConfig (string, default: 'better-auth')
  • ✅ Updated schema descriptions to refer to "the authentication system" instead of specifically "better-auth"
  • ✅ Changed provider type literal from 'authentication' to 'standard_auth' to avoid conflicts

4. Documentation Updates:

  • ✅ Updated title to "ObjectStack Authentication Standard"
  • ✅ Stated this is the standard protocol for authentication in ObjectStack
  • ✅ Mentioned that better-auth is the "Reference Implementation" (Default Driver)
  • ✅ Updated all code examples to use new names
  • ✅ Added section on Implementation Drivers

5. Bug Fixes (Latest Commit):

  • ✅ Fixed test imports: AuthenticationConfigAuthConfig, AuthenticationProviderStandardAuthProvider
  • ✅ Fixed all documentation references: BetterAuthConfigAuthConfig, BetterAuthStrategyAuthStrategy
  • ✅ Fixed file path references: auth-better.zod.tsauth.zod.ts, auth-better.test.tsauth.test.ts
  • ✅ Fixed misleading example: name: 'better_auth'name: 'main_auth'
  • ✅ Fixed JSON schema reference: BetterAuthConfig.jsonAuthConfig.json

Architecture

Clear Interface/Driver Separation:

  • AuthConfig is the interface (standard specification)
  • driver field specifies the implementation ('better-auth', 'auth-js', 'passport', 'custom')
  • better-auth is the default/reference implementation

No Naming Conflicts:

  • StandardAuthProviderSchema doesn't conflict with AuthProviderSchema in identity.zod.ts
  • identity.zod.ts handles legacy OIDC/SAML/LDAP providers
  • auth.zod.ts handles modern standard authentication protocol

Quality Assurance

Tests: All 46 tests passing
Build: TypeScript compilation successful
Exports: Updated in packages/spec/src/index.ts
JSON Schemas: Auto-generated successfully
Documentation: Auto-generated and manually updated
Code Review: All 12 review issues fixed

Files Changed

  • packages/spec/src/system/auth.zod.ts - Renamed from authentication.zod.ts, added driver field
  • packages/spec/src/system/auth.test.ts - Renamed, updated imports and type references
  • packages/spec/src/index.ts - Updated export path
  • docs/AUTHENTICATION_STANDARD.md - Renamed and fixed all type/path references
  • Auto-generated JSON schemas and MDX documentation

All review feedback addressed: type name consistency, correct file paths, and clear examples.

Original prompt

写一个better-auth身份认证插件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

@vercel

vercelBot commented Jan 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
specErrorErrorJan 21, 2026 1:32am

Request Review

Co-authored-by: hotlong <50353452+hotlong@users.noreply.github.com>
Co-authored-by: hotlong <50353452+hotlong@users.noreply.github.com>
CopilotAI changed the title [WIP] Add better-auth authentication pluginAdd better-auth authentication provider specificationJan 21, 2026
CopilotAI requested a review from hotlongJanuary 21, 2026 00:24
@hotlong

Copy link
Copy Markdown
Contributor

这个不是内核,我只是希望作为一个插件接入 @copilot

@hotlong

Copy link
Copy Markdown
Contributor

这个不是内核,我只是希望作为一个插件接入 @copilot

我改主意了,把这个做成标准规范,但是不能叫BetterAuth @copilot

Co-authored-by: hotlong <50353452+hotlong@users.noreply.github.com>

CopilotAI commented Jan 21, 2026

Copy link
Copy Markdown
ContributorAuthor

这个不是内核,我只是希望作为一个插件接入 @copilot

已重构为独立插件包 packages/plugin-better-auth/,不再是核心规范的一部分。现在遵循 ObjectStack 插件架构模式,实现了 PluginDefinition 接口,包含完整的生命周期钩子。

(Restructured as a standalone plugin package packages/plugin-better-auth/, no longer part of the core spec. Now follows ObjectStack plugin architecture patterns with PluginDefinition interface and complete lifecycle hooks.)

Commit: e8f0d88

CopilotAI changed the title Add better-auth authentication provider specificationAdd better-auth authentication pluginJan 21, 2026
… not BetterAuth)
Co-authored-by: hotlong <50353452+hotlong@users.noreply.github.com>

CopilotAI commented Jan 21, 2026

Copy link
Copy Markdown
ContributorAuthor

这个不是内核,我只是希望作为一个插件接入 @copilot

我改主意了,把这个做成标准规范,但是不能叫BetterAuth @copilot

已重构为核心规范,使用通用名称 "Authentication" 而不是 "BetterAuth"。现在这是 ObjectStack 的标准认证协议规范,与具体实现无关(可以用 better-auth、Auth.js、Passport 等任何认证库实现)。

(Restructured as core specification with generic name "Authentication" instead of "BetterAuth". Now it's the standard authentication protocol specification for ObjectStack, framework-agnostic and can be implemented with any auth library like better-auth, Auth.js, Passport, etc.)

Schema: packages/spec/src/system/authentication.zod.ts
Commit: b3a909e

CopilotAI changed the title Add better-auth authentication pluginAdd authentication protocol specificationJan 21, 2026
@hotlong

Copy link
Copy Markdown
Contributor

@copilot

Please refactor the changes in this PR to promote the "Better-Auth Plugin" specification into a generic "Standard Authentication Protocol".

The goal is to decouple the specification from the specific implementation (better-auth), making the spec the "Interface" and better-auth just one possible "Driver".

Please perform the following tasks:

  1. File Renaming:

    • Rename packages/spec/src/system/auth-better.zod.ts to packages/spec/src/system/auth.zod.ts.
    • Rename packages/spec/src/system/auth-better.test.ts to packages/spec/src/system/auth.test.ts.
    • Rename docs/BETTER_AUTH_PLUGIN.md to docs/AUTHENTICATION_STANDARD.md.
  2. Code Refactoring (Renaming Symbols):

    • Rename the main schema/type BetterAuthConfig to AuthConfig.
    • Rename BetterAuthStrategy to AuthStrategy.
    • Rename BetterAuthProvider to AuthProvider.
    • Remove the "Better" prefix from all other exported types/schemas in the file.
    • Update packages/spec/src/index.ts to export the new names.
  3. Schema Updates:

    • Add a new optional field driver to the AuthConfig schema (type: string, default: 'better-auth', description: 'The underlying authentication implementation driver').
    • Ensure the schema descriptions in z.describe() refer to "the authentication system" instead of specifically "better-auth" where appropriate.
  4. Documentation Updates:

    • Update the title in docs/AUTHENTICATION_STANDARD.md to "ObjectStack Authentication Standard".
    • Update the introduction to state that this is the standard protocol for authentication in ObjectStack.
    • Mention that better-auth is the current "Reference Implementation" (Default Driver) for this standard.

Please ensure all tests pass after the refactoring.

… driver field
Co-authored-by: hotlong <50353452+hotlong@users.noreply.github.com>

CopilotAI commented Jan 21, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot

Please refactor the changes in this PR to promote the "Better-Auth Plugin" specification into a generic "Standard Authentication Protocol"....

Refactoring completed:

File Renaming:

  • authentication.zod.tsauth.zod.ts
  • authentication.test.tsauth.test.ts
  • AUTHENTICATION.mdAUTHENTICATION_STANDARD.md

Symbol Renaming:

  • AuthenticationConfigSchemaAuthConfigSchema
  • AuthenticationConfigAuthConfig
  • AuthenticationProviderSchemaStandardAuthProviderSchema
  • AuthenticationProviderStandardAuthProvider
  • AuthStrategy (kept as-is)

Schema Updates:

  • Added driver field (type: string, default: 'better-auth')
  • Updated descriptions to be framework-agnostic

Documentation:

  • Title updated to "ObjectStack Authentication Standard"
  • Clarified as the standard protocol for ObjectStack
  • better-auth documented as "Reference Implementation" (Default Driver)

All Tests Passing: 46/46 tests pass

Commit: ad7a87b

@github-actions

Copy link
Copy Markdown
Contributor

This PR is very large. Consider breaking it into smaller PRs for easier review.

@hotlong

Copy link
Copy Markdown
Contributor

@copilot 继续

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a comprehensive authentication protocol specification to the ObjectStack ecosystem. It introduces a framework-agnostic authentication standard that can be implemented by various authentication libraries, with better-auth as the reference implementation.

Changes:

  • Added authentication protocol specification with Zod schemas and TypeScript types
  • Implemented support for multiple authentication strategies (email/password, OAuth, magic link, passkey, OTP, anonymous)
  • Included comprehensive test coverage (46 passing tests) and auto-generated JSON schemas and documentation

Reviewed changes

Copilot reviewed 40 out of 40 changed files in this pull request and generated 12 comments.

Show a summary per file
FileDescription
packages/spec/src/system/auth.zod.tsCore authentication protocol specification with Zod schemas
packages/spec/src/system/auth.test.tsComprehensive test suite for authentication schemas
packages/spec/src/index.tsExport path for authentication specifications
packages/spec/json-schema/*.jsonAuto-generated JSON schemas for all authentication types
content/docs/references/system/*.mdxAuto-generated documentation for authentication schemas
docs/AUTHENTICATION_STANDARD.mdDetailed documentation of the authentication standard

Comment on lines +18 to +19
type AuthenticationConfig,
type AuthenticationProvider,

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The imported types AuthenticationConfig and AuthenticationProvider are inconsistent with the exported types AuthConfig and StandardAuthProvider from auth.zod.ts. Update these imports to use AuthConfig and StandardAuthProvider respectively to match the actual exported type names.

Suggested change
typeAuthenticationConfig,
typeAuthenticationProvider,
typeAuthConfig,
typeStandardAuthProvider,

Copilot uses AI. Check for mistakes.

describe('AuthConfigSchema', () => {
it('should accept minimal valid configuration', () => {
const config: AuthConfig = {

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The type annotation uses AuthConfig but should use AuthenticationConfig based on the imports. However, the correct fix is to update the imports as noted in Comment 1, since AuthConfig is the actual exported type name.

Copilot uses AI. Check for mistakes.

describe('StandardAuthProviderSchema', () => {
it('should accept valid authentication provider', () => {
const provider: AuthenticationProvider = {

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The type annotation uses AuthenticationProvider but should use StandardAuthProvider to match the exported type from auth.zod.ts.

Copilot uses AI. Check for mistakes.

describe('Type inference', () => {
it('should correctly infer AuthenticationConfig type', () => {
const config: AuthConfig = {

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same issue as Comment 2 - type annotation inconsistency with imports.

Suggested change
constconfig: AuthConfig={
constconfig: AuthenticationConfig={

Copilot uses AI. Check for mistakes.
});

it('should correctly infer StandardAuthProvider type', () => {
const provider: AuthenticationProvider = {

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same issue as Comment 3 - type annotation uses AuthenticationProvider instead of StandardAuthProvider.

Copilot uses AI. Check for mistakes.
Comment threaddocs/AUTHENTICATION_STANDARD.md Outdated
|----------|------|----------|-------------|
| `name` | `string` | ✅ | Configuration identifier (snake_case) |
| `label` | `string` | ✅ | Human-readable label |
| `strategies` | `BetterAuthStrategy[]` | ✅ | Enabled authentication strategies |

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The type BetterAuthStrategy[] should be AuthStrategy[] to match the exported type from auth.zod.ts.

Suggested change
|`strategies`|`BetterAuthStrategy[]`|| Enabled authentication strategies |
|`strategies`|`AuthStrategy[]`|| Enabled authentication strategies |

Copilot uses AI. Check for mistakes.
Comment threaddocs/AUTHENTICATION_STANDARD.md Outdated
Comment on lines +340 to +343
- **Zod Schema**: `packages/spec/src/system/auth-better.zod.ts`
- **Tests**: `packages/spec/src/system/auth-better.test.ts`
- **JSON Schema**: `packages/spec/json-schema/BetterAuthConfig.json`
- **Documentation**: `content/docs/references/system/BetterAuthConfig.mdx`

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The file paths reference non-existent files with 'better' or 'BetterAuth' naming. These should be updated to use the actual file names: auth.zod.ts, auth.test.ts, AuthConfig.json, and AuthConfig.mdx respectively.

Copilot uses AI. Check for mistakes.
Comment threaddocs/AUTHENTICATION_STANDARD.md Outdated
Comment on lines +351 to +353
BetterAuthConfig,
BetterAuthProvider,
BetterAuthStrategy,

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These import examples reference non-existent types. Should be AuthConfig, StandardAuthProvider, and AuthStrategy respectively to match the actual exports from auth.zod.ts.

Suggested change
BetterAuthConfig,
BetterAuthProvider,
BetterAuthStrategy,
AuthConfig,
StandardAuthProvider,
AuthStrategy,

Copilot uses AI. Check for mistakes.
Comment threaddocs/AUTHENTICATION_STANDARD.md Outdated
Following ObjectStack conventions:

- **Configuration Keys** (TypeScript properties): `camelCase` (e.g., `maxAttempts`, `emailPassword`)
- **Machine Names** (Data values): `snake_case` (e.g., `name: 'better_auth'`, `strategy: 'email_password'`)

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The example name: 'better_auth' is misleading since 'better_auth' refers to the driver implementation, not the name field which should be something like 'main_auth'. Consider using a more appropriate example that doesn't reference the implementation.

Suggested change
-**Machine Names** (Data values): `snake_case` (e.g., `name: 'better_auth'`, `strategy: 'email_password'`)
-**Machine Names** (Data values): `snake_case` (e.g., `name: 'main_auth'`, `strategy: 'email_password'`)

Copilot uses AI. Check for mistakes.
Comment threaddocs/AUTHENTICATION_STANDARD.md Outdated

- [Better-Auth Documentation](https://better-auth.com)
- [ObjectStack Documentation](https://objectstack.ai)
- [JSON Schema Reference](../packages/spec/json-schema/BetterAuthConfig.json)

CopilotAIJan 21, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The file path references a non-existent file. Should be AuthConfig.json instead of BetterAuthConfig.json.

Copilot uses AI. Check for mistakes.
@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot fix all

@hotlong

Copy link
Copy Markdown
Contributor

@copilot 继续

Co-authored-by: hotlong <50353452+hotlong@users.noreply.github.com>

CopilotAI commented Jan 21, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 继续

All review issues fixed:

✅ Test imports updated: AuthConfig, StandardAuthProvider
✅ Documentation references: BetterAuthConfigAuthConfig, BetterAuthStrategyAuthStrategy
✅ File paths corrected: auth.zod.ts, auth.test.ts
✅ Example clarified: name: 'main_auth' (not 'better_auth')
✅ JSON schema reference: AuthConfig.json

All 46 tests passing.

Commit: 6254324

@github-actions

Copy link
Copy Markdown
Contributor

This PR is very large. Consider breaking it into smaller PRs for easier review.

@hotlong
hotlong merged commit 64e275e into mainJan 21, 2026
9 of 10 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationprotocol:systemsize/xltests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hotlong@huangyiirene