From fc6e0c0e8e17a15b2be6fcccf8d2ce5fef6cf3bd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gabriele=20Vigan=C3=B2?= Date: Fri, 25 Sep 2026 15:22:18 +0000 Subject: [PATCH] test: check the Better Auth packages stay in one server bundle Signing in to an application through this provider dropped the caller when the person was not already signed in here: after authenticating with Google or PoliNetwork APS they landed on this app's home page instead of returning to the application that sent them. The cause was two copies of Better Auth in the server bundle, each with its own keys for the request state that carries the pending authorization across the provider redirect. The fix landed in #9, which bundles every `better-auth` and `@better-auth/*` package together and fails the build if any request state is duplicated. That check only runs on a build, so add a unit test that reads the Better Auth packages from package.json and checks that `ssr.noExternal` bundles each of them and their subpaths, and that none is marked external. It fails on the old config and on keeping `better-auth` external. Co-Authored-By: Claude Opus 5.5 (1M context) --- vite.config.test.ts | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 vite.config.test.ts diff --git a/vite.config.test.ts b/vite.config.test.ts new file mode 100644 index 0000000..b19a111 --- /dev/null +++ b/vite.config.test.ts @@ -0,0 +1,33 @@ +import { describe, expect, it } from "vite-plus/test"; + +import packageJson from "./package.json" with { type: "json" }; +import config from "./vite.config"; + +const betterAuthPackages = Object.keys({ + ...packageJson.dependencies, + ...packageJson.devDependencies, +}).filter((name) => name === "better-auth" || name.startsWith("@better-auth/")); + +function isBundled(id: string) { + const noExternal = config.ssr?.noExternal; + if (noExternal === true) return true; + const rules = noExternal === undefined ? [] : [noExternal].flat(); + return rules.some((rule) => (typeof rule === "string" ? rule === id : rule.test(id))); +} + +describe("server bundle", () => { + // Nothing type checks or fails at runtime when Better Auth is duplicated across the + // server bundle: the OAuth authorization request is simply lost while the browser is + // away at the login provider, and the person lands on this app's home page instead of + // the application that sent them. `scripts/check-server-bundle.mjs` catches that in the + // build; this catches the setting that causes it without building. + it("finds the Better Auth packages this app depends on", () => { + expect(betterAuthPackages).toContain("better-auth"); + }); + + it.each(betterAuthPackages)("bundles %s and its subpaths into the server graph", (name) => { + expect(isBundled(name)).toBe(true); + expect(isBundled(`${name}/client`)).toBe(true); + expect([config.ssr?.external ?? []].flat()).not.toContain(name); + }); +});