Fix1.6.30
Bug fixes and SSO domain verification improvements
Fixed concurrent cold-start requests that could lose authentication context due to async storage race conditions, and improved SSO domain verification to require verified provider domains and prevent unauthorized organization assignment via social sign-in.
better-auth
Bug Fixes
- Fixed concurrent cold-start requests from intermittently losing authentication or transaction context due to an async storage initialization race (#10833)
For detailed changes, see CHANGELOG
@better-auth/sso
Bug Fixes
- Fixed automatic organization assignment via email domain to require both a verified provider domain and a verified stored user email, preventing social sign-in from joining an organization whose SSO provider merely claims that domain.
- Fixed domain verification to snapshot the provider's domains at request start, returning
409withSSO_PROVIDER_CHANGEDif the provider changes during DNS resolution so callers can reload and retry.
For detailed changes, see CHANGELOG
Contributors
Thanks to everyone who contributed to this release:
Full changelog: v1.6.29...v1.6.30
authssobug-fixsecuritystorage
Source: original entry ↗