Skip to content

fix(auth): upgrade Better Auth to patched 1.7.6 - #1719

Merged
MaheshtheDev merged 7 commits into
mainfrom
capy/upgrade-better-auth-to
Oct 3, 2026
Merged

MaheshtheDev merged 7 commits into
mainfrom
capy/upgrade-better-auth-to

Conversation

@Dhravya

@Dhravya Dhravya commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

This PR contains the existing Better Auth upgrade and the root dependency security changes from #1724, which was merged into this branch. It targets main; it is not an auth-only diff.

Auth scope

Upgrade root Better Auth and packages/lib Better Auth/API-key plugin to 1.7.6. main now already contains packages/lib's 1.6.22/API-key fix from #1741. The remaining auth source diff removes genericOAuthClient() because 1.7.6 no longer exports it. Its published 1.3.3 implementation was inference-only; scratch mocked request routing was checked, but actual login/session compatibility against the deployed backend is not established by this PR's builds/typechecks. Keep that distinction when reviewing.

The separate mono console's AgentID genericOAuthClient/signIn.oauth2 flow, backend genericOAuth agentid provider, and MCP issuer/resource-server configuration are not changed here. No database migrations or server auth configuration changes are included.

Root dependency scope

Retain #1724's Next 16.3.3, Drizzle 0.45.2, Vite 7.3.5, Vitest 3.2.6 and root transitive security overrides. Sharp moves to 0.35.4, jsondiffpatch to 0.7.6 and adm-zip to 0.6.1; these are part of the existing PR, not newly added by conflict resolution. Docs Mintlify/archive fixes already merged on main are preserved.

Conflict resolution and validation

Merged main at b85a1bf without force-pushing. Resolved packages/lib/package.json's 1.6.22 versus existing 1.7.6 entries and bun.lock from combined manifests. The resolved lockfile and auth sources exactly match the pre-merge PR, with no new removal or dependency version selection. PR-relative diff contains eight expected files and no docs/test changes.

Fresh frozen Bun install, targeted auth Biome, lib/hooks/web/AI SDK/memory-graph typechecks, web/tools/AI SDK/memory-graph builds, and git diff against main --check pass. Existing suites pass: 4 AI SDK tests (3 skipped), 101 tools tests, 197 graph tests, 20 MCP unit tests and 11 active MCP e2e tests (26 skipped); MCP build/server typecheck pass. Tools' 146 full-typecheck diagnostics exactly match the previously established baseline. Removed a stale local untracked Better Auth 1.3.3 install before rerunning affected auth checks; no source workaround was used.

Fresh Bun audit finds no Better Auth advisory entries, but other root transitive High findings remain (including newly published advisories). This conflict-only update does not claim complete current repository security clearance or end-to-end auth compatibility. Exact Dependabot alert mapping remains blocked by alerts API HTTP 403.

Critical Better Auth advisories originally addressed include GHSA-xg6x-h9c9-2m83 and GHSA-pw9m-5jxm-xr6h (CVE-2026-53512); main's lib version is now already beyond their patched thresholds.

@socket-security

socket-security Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
supermemory-app 5efda20 Commit Preview URL

Branch Preview URL
Oct 02 2026, 11:56 PM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
supermemory-mcp 5efda20 Oct 02 2026, 11:56 PM

@Dhravya
Dhravya force-pushed the capy/upgrade-better-auth-to branch from 0dbb811 to 750b59b Compare September 30, 2026 00:05

@capy-ai capy-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the latest head f614459, including the broader root dependency changes and the updated Next/OpenNext pairing. Holding approval because two new global overrides downgrade already-patched dependencies on main to vulnerable versions; see inline findings. Please raise or scope those overrides and regenerate bun.lock so existing patched versions are preserved.

Fresh frozen install, targeted auth/config lint, lib/hooks/web typechecks, Next build, OpenNext Cloudflare build and Wrangler dry-run pass. Repository-defined offline suites pass (101 tools, 4 AI SDK, 197 graph tests), as do AI SDK typecheck/build and graph build. The generic tools test command also includes API-key-dependent tests and an existing broken relative import, so the passing result here refers to test:unit, not that full command. Actual deployed login/session compatibility was not exercised, and this review does not establish production exploitability of the dependency findings. No code changed or merge performed.

Comment thread package.json Outdated
Comment thread package.json Outdated

@capy-ai capy-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed head 5efda20. Both requested changes are fixed: PostCSS resolves to 8.5.23 and Mintlify scraping resolves to fast-xml-parser 5.7.3 with fast-xml-builder 1.3.1. The harmless PostCSS reproduction no longer discloses an out-of-tree map; neither reviewed advisory appears in the fresh Bun audit. Both inline threads are resolved. I reviewed the additional override/lockfile changes and found no new blocking issue.

Fresh frozen install, scoped lib/hooks/web/AI SDK/graph typechecks, targeted auth/config lint, tools build, 101 tools unit tests, 4 AI SDK unit tests, 197 graph tests, OpenNext Cloudflare build and Wrangler dry-run pass. MCP widget build, 20 unit tests, 11 active e2e tests (26 skipped) and server typecheck also pass. All six PR checks are green on this head. Tools full typecheck still has 146 diagnostics; a fresh comparison confirms they exactly match current main, so they are not introduced by this PR.

Approval covers the reviewed code/dependency changes, not complete repository security clearance or live deployed login/session compatibility. No code changes or merge performed.

@MaheshtheDev
MaheshtheDev merged commit 62cc57e into main Oct 3, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants