chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4 - #7200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4
Closed

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4#7200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4.

Release notes

Sourced from @​better-auth/sso's releases.

v1.7.0-rc.4

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513)
  • Fixed JWT signing to use the transaction-scoped adapter (#10623)
  • Fixed Apple user data being lost when using the OAuth proxy (#10599)
  • Fixed Google One Tap to enforce provider signup restrictions (#10479)
  • Fixed client plugin type inference when using oneTapClient (#10635)
  • Fixed rate limit database cleanup to be awaited by default (#10619)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Improved Next.js performance by reusing the next/headers import promise in production (#10467)

For detailed changes, see CHANGELOG

@better-auth/expo

❗ Breaking Changes

  • Switched to async secure storage access to prevent crashes when iOS Keychain is unavailable (#10438)

Migration:getCookie() now returns a Promise. Custom storage implementations must provide both sync and async SecureStore methods, and should use setItemAsync() when the write must be awaited.

For detailed changes, see CHANGELOG

@better-auth/redis-storage

Bug Fixes

  • Fixed Redis storage to use SCAN instead of KEYS to avoid blocking the server (#10507)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM PATCH to create filtered attribute values when no target matches, instead of rejecting with a noTarget error (#10682)

... (truncated)

Changelog

Sourced from @​better-auth/sso's changelog.

1.7.0-rc.4

1.7.0-rc.3

Minor Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Extend resolveUser to SAML sign-ins. The callback now receives a discriminated protocol field: OIDC input keeps verifiedIdTokenClaims and providerClaims, while SAML input carries the verified assertion's providerAttributes. Both variants include a providerReference, an opaque reference to the accepted provider configuration that detects provider replacement or configuration changes mid-flow.

    Add guardProviderMutation, a callback that authorizes updates and deletions of a persisted SSO provider before Better Auth applies them.

Patch Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Verify SAML assertion signatures directly instead of trusting an already-parsed response, and enforce a signing policy and size limit on SP metadata the same way IdP metadata is already enforced. wantAssertionsSigned now controls whether the SP requires signed assertions instead of signed response messages, matching how IdPs sign SAML responses in practice.

    A SAML callback that supplies RelayState now validates it unconditionally; a malformed or expired value is rejected even when enableInResponseToValidation is disabled. Service Provider metadata with an ACS location containing a URL fragment is rejected.

    Redact provider claims and resolver-thrown errors from log output on SAML and OIDC resolution failures.

  • #1059226b1949 Thanks @​gustavovalverde! - Allow SSO provider registration to reuse a SCIM connection ID. SCIM connections no longer participate in the authentication provider namespace.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) from 1.7.0-rc.2 to 1.7.0-rc.4.
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/v1.7.0-rc.4/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0-rc.4/packages/sso)
---
updated-dependencies:
- dependency-name: "@better-auth/sso"
dependency-version: 1.7.0-rc.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript labels Aug 10, 2026
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectstackIgnoredIgnoredAug 10, 2026 2:32am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/plugin-auth.

8 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/deployment/cli.mdx(via @objectstack/plugin-auth)
  • content/docs/deployment/production-readiness.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/contracts/cache-service.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/services-checklist.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/authentication.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/sso.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/index.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/packages.mdx(via @objectstack/plugin-auth)

2 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/implementation-status.mdx(via @objectstack/plugin-auth)
  • content/docs/releases/v9.mdx(via @objectstack/plugin-auth)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@dependabot@github

dependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filesize/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4 - #7200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4
Closed

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4#7200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4.

Release notes

Sourced from @​better-auth/sso's releases.

v1.7.0-rc.4

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513)
  • Fixed JWT signing to use the transaction-scoped adapter (#10623)
  • Fixed Apple user data being lost when using the OAuth proxy (#10599)
  • Fixed Google One Tap to enforce provider signup restrictions (#10479)
  • Fixed client plugin type inference when using oneTapClient (#10635)
  • Fixed rate limit database cleanup to be awaited by default (#10619)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Improved Next.js performance by reusing the next/headers import promise in production (#10467)

For detailed changes, see CHANGELOG

@better-auth/expo

❗ Breaking Changes

  • Switched to async secure storage access to prevent crashes when iOS Keychain is unavailable (#10438)

Migration:getCookie() now returns a Promise. Custom storage implementations must provide both sync and async SecureStore methods, and should use setItemAsync() when the write must be awaited.

For detailed changes, see CHANGELOG

@better-auth/redis-storage

Bug Fixes

  • Fixed Redis storage to use SCAN instead of KEYS to avoid blocking the server (#10507)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM PATCH to create filtered attribute values when no target matches, instead of rejecting with a noTarget error (#10682)

... (truncated)

Changelog

Sourced from @​better-auth/sso's changelog.

1.7.0-rc.4

1.7.0-rc.3

Minor Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Extend resolveUser to SAML sign-ins. The callback now receives a discriminated protocol field: OIDC input keeps verifiedIdTokenClaims and providerClaims, while SAML input carries the verified assertion's providerAttributes. Both variants include a providerReference, an opaque reference to the accepted provider configuration that detects provider replacement or configuration changes mid-flow.

    Add guardProviderMutation, a callback that authorizes updates and deletions of a persisted SSO provider before Better Auth applies them.

Patch Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Verify SAML assertion signatures directly instead of trusting an already-parsed response, and enforce a signing policy and size limit on SP metadata the same way IdP metadata is already enforced. wantAssertionsSigned now controls whether the SP requires signed assertions instead of signed response messages, matching how IdPs sign SAML responses in practice.

    A SAML callback that supplies RelayState now validates it unconditionally; a malformed or expired value is rejected even when enableInResponseToValidation is disabled. Service Provider metadata with an ACS location containing a URL fragment is rejected.

    Redact provider claims and resolver-thrown errors from log output on SAML and OIDC resolution failures.

  • #1059226b1949 Thanks @​gustavovalverde! - Allow SSO provider registration to reuse a SCIM connection ID. SCIM connections no longer participate in the authentication provider namespace.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) from 1.7.0-rc.2 to 1.7.0-rc.4.
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/v1.7.0-rc.4/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0-rc.4/packages/sso)
---
updated-dependencies:
- dependency-name: "@better-auth/sso"
dependency-version: 1.7.0-rc.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript labels Aug 10, 2026
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectstackIgnoredIgnoredAug 10, 2026 2:32am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/plugin-auth.

8 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/deployment/cli.mdx(via @objectstack/plugin-auth)
  • content/docs/deployment/production-readiness.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/contracts/cache-service.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/services-checklist.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/authentication.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/sso.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/index.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/packages.mdx(via @objectstack/plugin-auth)

2 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/implementation-status.mdx(via @objectstack/plugin-auth)
  • content/docs/releases/v9.mdx(via @objectstack/plugin-auth)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@dependabot@github

dependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filesize/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4 - #7200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4
Closed

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4#7200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4.

Release notes

Sourced from @​better-auth/sso's releases.

v1.7.0-rc.4

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513)
  • Fixed JWT signing to use the transaction-scoped adapter (#10623)
  • Fixed Apple user data being lost when using the OAuth proxy (#10599)
  • Fixed Google One Tap to enforce provider signup restrictions (#10479)
  • Fixed client plugin type inference when using oneTapClient (#10635)
  • Fixed rate limit database cleanup to be awaited by default (#10619)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Improved Next.js performance by reusing the next/headers import promise in production (#10467)

For detailed changes, see CHANGELOG

@better-auth/expo

❗ Breaking Changes

  • Switched to async secure storage access to prevent crashes when iOS Keychain is unavailable (#10438)

Migration:getCookie() now returns a Promise. Custom storage implementations must provide both sync and async SecureStore methods, and should use setItemAsync() when the write must be awaited.

For detailed changes, see CHANGELOG

@better-auth/redis-storage

Bug Fixes

  • Fixed Redis storage to use SCAN instead of KEYS to avoid blocking the server (#10507)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM PATCH to create filtered attribute values when no target matches, instead of rejecting with a noTarget error (#10682)

... (truncated)

Changelog

Sourced from @​better-auth/sso's changelog.

1.7.0-rc.4

1.7.0-rc.3

Minor Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Extend resolveUser to SAML sign-ins. The callback now receives a discriminated protocol field: OIDC input keeps verifiedIdTokenClaims and providerClaims, while SAML input carries the verified assertion's providerAttributes. Both variants include a providerReference, an opaque reference to the accepted provider configuration that detects provider replacement or configuration changes mid-flow.

    Add guardProviderMutation, a callback that authorizes updates and deletions of a persisted SSO provider before Better Auth applies them.

Patch Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Verify SAML assertion signatures directly instead of trusting an already-parsed response, and enforce a signing policy and size limit on SP metadata the same way IdP metadata is already enforced. wantAssertionsSigned now controls whether the SP requires signed assertions instead of signed response messages, matching how IdPs sign SAML responses in practice.

    A SAML callback that supplies RelayState now validates it unconditionally; a malformed or expired value is rejected even when enableInResponseToValidation is disabled. Service Provider metadata with an ACS location containing a URL fragment is rejected.

    Redact provider claims and resolver-thrown errors from log output on SAML and OIDC resolution failures.

  • #1059226b1949 Thanks @​gustavovalverde! - Allow SSO provider registration to reuse a SCIM connection ID. SCIM connections no longer participate in the authentication provider namespace.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) from 1.7.0-rc.2 to 1.7.0-rc.4.
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/v1.7.0-rc.4/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0-rc.4/packages/sso)
---
updated-dependencies:
- dependency-name: "@better-auth/sso"
dependency-version: 1.7.0-rc.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript labels Aug 10, 2026
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectstackIgnoredIgnoredAug 10, 2026 2:32am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/plugin-auth.

8 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/deployment/cli.mdx(via @objectstack/plugin-auth)
  • content/docs/deployment/production-readiness.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/contracts/cache-service.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/services-checklist.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/authentication.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/sso.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/index.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/packages.mdx(via @objectstack/plugin-auth)

2 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/implementation-status.mdx(via @objectstack/plugin-auth)
  • content/docs/releases/v9.mdx(via @objectstack/plugin-auth)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@dependabot@github

dependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filesize/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4 - #7200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4
Closed

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4#7200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4.

Release notes

Sourced from @​better-auth/sso's releases.

v1.7.0-rc.4

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513)
  • Fixed JWT signing to use the transaction-scoped adapter (#10623)
  • Fixed Apple user data being lost when using the OAuth proxy (#10599)
  • Fixed Google One Tap to enforce provider signup restrictions (#10479)
  • Fixed client plugin type inference when using oneTapClient (#10635)
  • Fixed rate limit database cleanup to be awaited by default (#10619)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Improved Next.js performance by reusing the next/headers import promise in production (#10467)

For detailed changes, see CHANGELOG

@better-auth/expo

❗ Breaking Changes

  • Switched to async secure storage access to prevent crashes when iOS Keychain is unavailable (#10438)

Migration:getCookie() now returns a Promise. Custom storage implementations must provide both sync and async SecureStore methods, and should use setItemAsync() when the write must be awaited.

For detailed changes, see CHANGELOG

@better-auth/redis-storage

Bug Fixes

  • Fixed Redis storage to use SCAN instead of KEYS to avoid blocking the server (#10507)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM PATCH to create filtered attribute values when no target matches, instead of rejecting with a noTarget error (#10682)

... (truncated)

Changelog

Sourced from @​better-auth/sso's changelog.

1.7.0-rc.4

1.7.0-rc.3

Minor Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Extend resolveUser to SAML sign-ins. The callback now receives a discriminated protocol field: OIDC input keeps verifiedIdTokenClaims and providerClaims, while SAML input carries the verified assertion's providerAttributes. Both variants include a providerReference, an opaque reference to the accepted provider configuration that detects provider replacement or configuration changes mid-flow.

    Add guardProviderMutation, a callback that authorizes updates and deletions of a persisted SSO provider before Better Auth applies them.

Patch Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Verify SAML assertion signatures directly instead of trusting an already-parsed response, and enforce a signing policy and size limit on SP metadata the same way IdP metadata is already enforced. wantAssertionsSigned now controls whether the SP requires signed assertions instead of signed response messages, matching how IdPs sign SAML responses in practice.

    A SAML callback that supplies RelayState now validates it unconditionally; a malformed or expired value is rejected even when enableInResponseToValidation is disabled. Service Provider metadata with an ACS location containing a URL fragment is rejected.

    Redact provider claims and resolver-thrown errors from log output on SAML and OIDC resolution failures.

  • #1059226b1949 Thanks @​gustavovalverde! - Allow SSO provider registration to reuse a SCIM connection ID. SCIM connections no longer participate in the authentication provider namespace.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) from 1.7.0-rc.2 to 1.7.0-rc.4.
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/v1.7.0-rc.4/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0-rc.4/packages/sso)
---
updated-dependencies:
- dependency-name: "@better-auth/sso"
dependency-version: 1.7.0-rc.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript labels Aug 10, 2026
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectstackIgnoredIgnoredAug 10, 2026 2:32am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/plugin-auth.

8 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/deployment/cli.mdx(via @objectstack/plugin-auth)
  • content/docs/deployment/production-readiness.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/contracts/cache-service.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/services-checklist.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/authentication.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/sso.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/index.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/packages.mdx(via @objectstack/plugin-auth)

2 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/implementation-status.mdx(via @objectstack/plugin-auth)
  • content/docs/releases/v9.mdx(via @objectstack/plugin-auth)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@dependabot@github

dependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filesize/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4 - #7200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4
Closed

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4#7200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4.

Release notes

Sourced from @​better-auth/sso's releases.

v1.7.0-rc.4

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513)
  • Fixed JWT signing to use the transaction-scoped adapter (#10623)
  • Fixed Apple user data being lost when using the OAuth proxy (#10599)
  • Fixed Google One Tap to enforce provider signup restrictions (#10479)
  • Fixed client plugin type inference when using oneTapClient (#10635)
  • Fixed rate limit database cleanup to be awaited by default (#10619)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Improved Next.js performance by reusing the next/headers import promise in production (#10467)

For detailed changes, see CHANGELOG

@better-auth/expo

❗ Breaking Changes

  • Switched to async secure storage access to prevent crashes when iOS Keychain is unavailable (#10438)

Migration:getCookie() now returns a Promise. Custom storage implementations must provide both sync and async SecureStore methods, and should use setItemAsync() when the write must be awaited.

For detailed changes, see CHANGELOG

@better-auth/redis-storage

Bug Fixes

  • Fixed Redis storage to use SCAN instead of KEYS to avoid blocking the server (#10507)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM PATCH to create filtered attribute values when no target matches, instead of rejecting with a noTarget error (#10682)

... (truncated)

Changelog

Sourced from @​better-auth/sso's changelog.

1.7.0-rc.4

1.7.0-rc.3

Minor Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Extend resolveUser to SAML sign-ins. The callback now receives a discriminated protocol field: OIDC input keeps verifiedIdTokenClaims and providerClaims, while SAML input carries the verified assertion's providerAttributes. Both variants include a providerReference, an opaque reference to the accepted provider configuration that detects provider replacement or configuration changes mid-flow.

    Add guardProviderMutation, a callback that authorizes updates and deletions of a persisted SSO provider before Better Auth applies them.

Patch Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Verify SAML assertion signatures directly instead of trusting an already-parsed response, and enforce a signing policy and size limit on SP metadata the same way IdP metadata is already enforced. wantAssertionsSigned now controls whether the SP requires signed assertions instead of signed response messages, matching how IdPs sign SAML responses in practice.

    A SAML callback that supplies RelayState now validates it unconditionally; a malformed or expired value is rejected even when enableInResponseToValidation is disabled. Service Provider metadata with an ACS location containing a URL fragment is rejected.

    Redact provider claims and resolver-thrown errors from log output on SAML and OIDC resolution failures.

  • #1059226b1949 Thanks @​gustavovalverde! - Allow SSO provider registration to reuse a SCIM connection ID. SCIM connections no longer participate in the authentication provider namespace.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) from 1.7.0-rc.2 to 1.7.0-rc.4.
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/v1.7.0-rc.4/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0-rc.4/packages/sso)
---
updated-dependencies:
- dependency-name: "@better-auth/sso"
dependency-version: 1.7.0-rc.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript labels Aug 10, 2026
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectstackIgnoredIgnoredAug 10, 2026 2:32am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/plugin-auth.

8 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/deployment/cli.mdx(via @objectstack/plugin-auth)
  • content/docs/deployment/production-readiness.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/contracts/cache-service.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/services-checklist.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/authentication.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/sso.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/index.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/packages.mdx(via @objectstack/plugin-auth)

2 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/implementation-status.mdx(via @objectstack/plugin-auth)
  • content/docs/releases/v9.mdx(via @objectstack/plugin-auth)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@dependabot@github

dependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filesize/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4 - #7200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4
Closed

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4#7200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4.

Release notes

Sourced from @​better-auth/sso's releases.

v1.7.0-rc.4

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513)
  • Fixed JWT signing to use the transaction-scoped adapter (#10623)
  • Fixed Apple user data being lost when using the OAuth proxy (#10599)
  • Fixed Google One Tap to enforce provider signup restrictions (#10479)
  • Fixed client plugin type inference when using oneTapClient (#10635)
  • Fixed rate limit database cleanup to be awaited by default (#10619)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Improved Next.js performance by reusing the next/headers import promise in production (#10467)

For detailed changes, see CHANGELOG

@better-auth/expo

❗ Breaking Changes

  • Switched to async secure storage access to prevent crashes when iOS Keychain is unavailable (#10438)

Migration:getCookie() now returns a Promise. Custom storage implementations must provide both sync and async SecureStore methods, and should use setItemAsync() when the write must be awaited.

For detailed changes, see CHANGELOG

@better-auth/redis-storage

Bug Fixes

  • Fixed Redis storage to use SCAN instead of KEYS to avoid blocking the server (#10507)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM PATCH to create filtered attribute values when no target matches, instead of rejecting with a noTarget error (#10682)

... (truncated)

Changelog

Sourced from @​better-auth/sso's changelog.

1.7.0-rc.4

1.7.0-rc.3

Minor Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Extend resolveUser to SAML sign-ins. The callback now receives a discriminated protocol field: OIDC input keeps verifiedIdTokenClaims and providerClaims, while SAML input carries the verified assertion's providerAttributes. Both variants include a providerReference, an opaque reference to the accepted provider configuration that detects provider replacement or configuration changes mid-flow.

    Add guardProviderMutation, a callback that authorizes updates and deletions of a persisted SSO provider before Better Auth applies them.

Patch Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Verify SAML assertion signatures directly instead of trusting an already-parsed response, and enforce a signing policy and size limit on SP metadata the same way IdP metadata is already enforced. wantAssertionsSigned now controls whether the SP requires signed assertions instead of signed response messages, matching how IdPs sign SAML responses in practice.

    A SAML callback that supplies RelayState now validates it unconditionally; a malformed or expired value is rejected even when enableInResponseToValidation is disabled. Service Provider metadata with an ACS location containing a URL fragment is rejected.

    Redact provider claims and resolver-thrown errors from log output on SAML and OIDC resolution failures.

  • #1059226b1949 Thanks @​gustavovalverde! - Allow SSO provider registration to reuse a SCIM connection ID. SCIM connections no longer participate in the authentication provider namespace.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) from 1.7.0-rc.2 to 1.7.0-rc.4.
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/v1.7.0-rc.4/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0-rc.4/packages/sso)
---
updated-dependencies:
- dependency-name: "@better-auth/sso"
dependency-version: 1.7.0-rc.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript labels Aug 10, 2026
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectstackIgnoredIgnoredAug 10, 2026 2:32am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/plugin-auth.

8 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/deployment/cli.mdx(via @objectstack/plugin-auth)
  • content/docs/deployment/production-readiness.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/contracts/cache-service.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/services-checklist.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/authentication.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/sso.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/index.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/packages.mdx(via @objectstack/plugin-auth)

2 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/implementation-status.mdx(via @objectstack/plugin-auth)
  • content/docs/releases/v9.mdx(via @objectstack/plugin-auth)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@dependabot@github

dependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filesize/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4 - #7200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4
Closed

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4#7200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4.

Release notes

Sourced from @​better-auth/sso's releases.

v1.7.0-rc.4

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513)
  • Fixed JWT signing to use the transaction-scoped adapter (#10623)
  • Fixed Apple user data being lost when using the OAuth proxy (#10599)
  • Fixed Google One Tap to enforce provider signup restrictions (#10479)
  • Fixed client plugin type inference when using oneTapClient (#10635)
  • Fixed rate limit database cleanup to be awaited by default (#10619)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Improved Next.js performance by reusing the next/headers import promise in production (#10467)

For detailed changes, see CHANGELOG

@better-auth/expo

❗ Breaking Changes

  • Switched to async secure storage access to prevent crashes when iOS Keychain is unavailable (#10438)

Migration:getCookie() now returns a Promise. Custom storage implementations must provide both sync and async SecureStore methods, and should use setItemAsync() when the write must be awaited.

For detailed changes, see CHANGELOG

@better-auth/redis-storage

Bug Fixes

  • Fixed Redis storage to use SCAN instead of KEYS to avoid blocking the server (#10507)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM PATCH to create filtered attribute values when no target matches, instead of rejecting with a noTarget error (#10682)

... (truncated)

Changelog

Sourced from @​better-auth/sso's changelog.

1.7.0-rc.4

1.7.0-rc.3

Minor Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Extend resolveUser to SAML sign-ins. The callback now receives a discriminated protocol field: OIDC input keeps verifiedIdTokenClaims and providerClaims, while SAML input carries the verified assertion's providerAttributes. Both variants include a providerReference, an opaque reference to the accepted provider configuration that detects provider replacement or configuration changes mid-flow.

    Add guardProviderMutation, a callback that authorizes updates and deletions of a persisted SSO provider before Better Auth applies them.

Patch Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Verify SAML assertion signatures directly instead of trusting an already-parsed response, and enforce a signing policy and size limit on SP metadata the same way IdP metadata is already enforced. wantAssertionsSigned now controls whether the SP requires signed assertions instead of signed response messages, matching how IdPs sign SAML responses in practice.

    A SAML callback that supplies RelayState now validates it unconditionally; a malformed or expired value is rejected even when enableInResponseToValidation is disabled. Service Provider metadata with an ACS location containing a URL fragment is rejected.

    Redact provider claims and resolver-thrown errors from log output on SAML and OIDC resolution failures.

  • #1059226b1949 Thanks @​gustavovalverde! - Allow SSO provider registration to reuse a SCIM connection ID. SCIM connections no longer participate in the authentication provider namespace.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) from 1.7.0-rc.2 to 1.7.0-rc.4.
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/v1.7.0-rc.4/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0-rc.4/packages/sso)
---
updated-dependencies:
- dependency-name: "@better-auth/sso"
dependency-version: 1.7.0-rc.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript labels Aug 10, 2026
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectstackIgnoredIgnoredAug 10, 2026 2:32am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/plugin-auth.

8 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/deployment/cli.mdx(via @objectstack/plugin-auth)
  • content/docs/deployment/production-readiness.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/contracts/cache-service.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/services-checklist.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/authentication.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/sso.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/index.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/packages.mdx(via @objectstack/plugin-auth)

2 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/implementation-status.mdx(via @objectstack/plugin-auth)
  • content/docs/releases/v9.mdx(via @objectstack/plugin-auth)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@dependabot@github

dependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filesize/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4 - #7200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4
Closed

chore(deps)(deps): bump @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4#7200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/better-auth/sso-1.7.0-rc.4

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @better-auth/sso from 1.7.0-rc.2 to 1.7.0-rc.4.

Release notes

Sourced from @​better-auth/sso's releases.

v1.7.0-rc.4

better-auth

Features

  • Added a placeholder email utility for generating temporary email addresses (#10576)

Bug Fixes

  • Fixed sessions not being cleaned up when a user is deleted (#10520)
  • Fixed missing PKCE challenge in Apple OAuth flows (#10294)
  • Fixed duplicate in-flight session requests when React retries a suspended component (#10676)
  • Fixed cookie cache to work independently of the JWT plugin internals (#10666)
  • Fixed findSessions to skip null-parsed session tokens instead of returning early (#10580)
  • Fixed missing verification type when sending email OTP during sign-up (#10608)
  • Fixed OTP being cleared after password validation errors in email OTP flows (#10552)
  • Fixed email OTP to verify the code before revealing whether the email exists (#10605)
  • Fixed client plugin type inference when using jwtClient (#10513)
  • Fixed JWT signing to use the transaction-scoped adapter (#10623)
  • Fixed Apple user data being lost when using the OAuth proxy (#10599)
  • Fixed Google One Tap to enforce provider signup restrictions (#10479)
  • Fixed client plugin type inference when using oneTapClient (#10635)
  • Fixed rate limit database cleanup to be awaited by default (#10619)
  • Fixed $fetch and $store not being exposed on the Solid client (#10444)
  • Improved Next.js performance by reusing the next/headers import promise in production (#10467)

For detailed changes, see CHANGELOG

@better-auth/expo

❗ Breaking Changes

  • Switched to async secure storage access to prevent crashes when iOS Keychain is unavailable (#10438)

Migration:getCookie() now returns a Promise. Custom storage implementations must provide both sync and async SecureStore methods, and should use setItemAsync() when the write must be awaited.

For detailed changes, see CHANGELOG

@better-auth/redis-storage

Bug Fixes

  • Fixed Redis storage to use SCAN instead of KEYS to avoid blocking the server (#10507)

For detailed changes, see CHANGELOG

@better-auth/scim

Bug Fixes

  • Fixed SCIM PATCH to create filtered attribute values when no target matches, instead of rejecting with a noTarget error (#10682)

... (truncated)

Changelog

Sourced from @​better-auth/sso's changelog.

1.7.0-rc.4

1.7.0-rc.3

Minor Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Extend resolveUser to SAML sign-ins. The callback now receives a discriminated protocol field: OIDC input keeps verifiedIdTokenClaims and providerClaims, while SAML input carries the verified assertion's providerAttributes. Both variants include a providerReference, an opaque reference to the accepted provider configuration that detects provider replacement or configuration changes mid-flow.

    Add guardProviderMutation, a callback that authorizes updates and deletions of a persisted SSO provider before Better Auth applies them.

Patch Changes

  • #1062159c4c83 Thanks @​gustavovalverde! - Verify SAML assertion signatures directly instead of trusting an already-parsed response, and enforce a signing policy and size limit on SP metadata the same way IdP metadata is already enforced. wantAssertionsSigned now controls whether the SP requires signed assertions instead of signed response messages, matching how IdPs sign SAML responses in practice.

    A SAML callback that supplies RelayState now validates it unconditionally; a malformed or expired value is rejected even when enableInResponseToValidation is disabled. Service Provider metadata with an ACS location containing a URL fragment is rejected.

    Redact provider claims and resolver-thrown errors from log output on SAML and OIDC resolution failures.

  • #1059226b1949 Thanks @​gustavovalverde! - Allow SSO provider registration to reuse a SCIM connection ID. SCIM connections no longer participate in the authentication provider namespace.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@better-auth/sso](https://github.com/better-auth/better-auth/tree/HEAD/packages/sso) from 1.7.0-rc.2 to 1.7.0-rc.4.
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/v1.7.0-rc.4/packages/sso/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0-rc.4/packages/sso)
---
updated-dependencies:
- dependency-name: "@better-auth/sso"
dependency-version: 1.7.0-rc.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript labels Aug 10, 2026
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectstackIgnoredIgnoredAug 10, 2026 2:32am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/plugin-auth.

8 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/deployment/cli.mdx(via @objectstack/plugin-auth)
  • content/docs/deployment/production-readiness.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/contracts/cache-service.mdx(via @objectstack/plugin-auth)
  • content/docs/kernel/services-checklist.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/authentication.mdx(via @objectstack/plugin-auth)
  • content/docs/permissions/sso.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/index.mdx(via @objectstack/plugin-auth)
  • content/docs/plugins/packages.mdx(via @objectstack/plugin-auth)

2 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/implementation-status.mdx(via @objectstack/plugin-auth)
  • content/docs/releases/v9.mdx(via @objectstack/plugin-auth)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@dependabot@github

dependabotBot commented on behalf of githubAug 10, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filesize/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang