- We are building a "good enough" framework, not a "perfect" one. Focus on building in a way where we are able to ship faster without compromising reliability, mantainability and security but know when we are going overboard and being pedantic.
- None of our platform has get hit thousands of users (let alone millions), so don't waste time trying to pre-optimize the stack for such cases.
- Every product must set a product-specific
advanced.cookiePrefixon its Better Auth instance (for example,courselitorsendlit) so products on the same browser hostname do not overwrite each other's session cookies. Keep any cookie-name parsing or legacy-cookie cleanup aligned with that prefix, and preserve otheradvancedsettings such ascrossSubDomainCookies. This belongs in the product's Better Auth configuration, not@codelitdev/oauth-server-kit, which does not create the auth instance. - Make sure to record critical decisions as ADR in
docs/decisions