Commit 73dc89b
fix(auth): canonicalise
* fix(auth): canonicalise sys_member.role at the write (#8317)
better-auth reads sys_member.role with a raw split(',') -- no trim, no
lower-case -- so a row stored as 'Owner' or ' owner' is an owner to the
#5942 grade ladder and a plain member to the vendor. Its 'only an owner
may remove an owner' branch therefore never fires and the request falls
through to hasPermission({ member: ['delete'] }), which an org admin
passes: an org admin could remove an owner.
Maintainer ruling 2026-08-13, option A -- normalise at the write:
beforeInsert/beforeUpdate hooks on sys_member plus a one-off convergent
boot pass for existing rows.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PEVB6w7D7uCszR9Mw1BL73
* test(auth): pin the #8317 inversion against better-auth's own extracted predicates
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PEVB6w7D7uCszR9Mw1BL73
* fix(auth): match the kernel Logger's error() arity; add the changeset
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PEVB6w7D7uCszR9Mw1BL73
* test(auth): drop import.meta from the vendor-source pin (TS1470 in this CJS-typed package)
plugin-auth publishes CommonJS, so under module: NodeNext any import.meta
is a TS1470 — which drifted the package's frozen TEST_DEBT ledger entry
111 -> 112. Fixed the type rather than the ledger: reuse the findUp-from-CWD
idiom rate-limit-storage-isolation.test.ts already established here, and
seed createRequire from the package root so the better-auth file read is
the one THIS package is pinned to. Re-measure is back at 111.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PEVB6w7D7uCszR9Mw1BL73
---------
Co-authored-by: Claude <noreply@anthropic.com>sys_member.role at the write, and converge existing rows (#8417)1 parent 2c0b2f3 commit 73dc89b
5 files changed
Lines changed: 1116 additions & 0 deletions
File tree
- .changeset
- packages/plugins/plugin-auth/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| 46 | + | |
46 | 47 | | |
47 | 48 | | |
48 | 49 | | |
| |||
843 | 844 | | |
844 | 845 | | |
845 | 846 | | |
| 847 | + | |
| 848 | + | |
| 849 | + | |
| 850 | + | |
| 851 | + | |
| 852 | + | |
| 853 | + | |
| 854 | + | |
| 855 | + | |
| 856 | + | |
| 857 | + | |
| 858 | + | |
| 859 | + | |
| 860 | + | |
| 861 | + | |
| 862 | + | |
| 863 | + | |
| 864 | + | |
| 865 | + | |
| 866 | + | |
846 | 867 | | |
847 | 868 | | |
848 | 869 | | |
| |||
1019 | 1040 | | |
1020 | 1041 | | |
1021 | 1042 | | |
| 1043 | + | |
| 1044 | + | |
| 1045 | + | |
| 1046 | + | |
| 1047 | + | |
| 1048 | + | |
| 1049 | + | |
| 1050 | + | |
| 1051 | + | |
| 1052 | + | |
| 1053 | + | |
| 1054 | + | |
| 1055 | + | |
1022 | 1056 | | |
1023 | 1057 | | |
1024 | 1058 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
31 | 38 | | |
32 | 39 | | |
33 | 40 | | |
| |||
0 commit comments