Commit d4c2cb1
fix(plugin-auth): the auth catch-all yields only a 404 that disclaims ownership (#15918)
* fix(plugin-auth): the auth catch-all yields only a 404 that disclaims ownership
`registerAuthRoutes` mounts one catch-all over the auth namespace and, since
#4088, deliberately yields to the rest of the Hono chain when better-auth
answers 404 — that is what keeps `plugin-hono-server`'s `/auth/me/permissions`
and `/auth/me/localization` reachable in either registration order.
The yield had only the status to go on, so it could not tell "I do not serve
this path" from "I serve it and the answer is 404". Measured with the shipped
handler on a real Hono app: with one broad downstream mount in the chain —
`app.all('/api/v1/*', c => c.json({}))`, the shape a composition adds —
`POST /api/v1/auth/delete-user` came back `200 {}` where better-auth had
answered 404 because `user.deleteUser` is unconfigured. `auth-route-ledger.ts`
carries that route under the `disabled` disposition precisely because it is
published and refused, and the same held for every 404 a routed endpoint
produces for a bad token, an unknown id, or an admin family the deployment does
mount. All of those answers were up for grabs.
The catch-all now asks better-auth's live instance whether it owns the path
before it yields. The seam is `auth.api` — the same one the route ledger's
conformance test reads and the `/admin/` dogfood sweep derives from — and the
matching mirrors better-call's own `createRouter` walk: its `SERVER_ONLY` skip,
its `:param` syntax, its per-method registration. The skip is load-bearing, not
cosmetic: measured on the stock boot, all nine `/admin/oauth2/*` endpoints are
in `auth.api` carrying `SERVER_ONLY: true`, so better-call never routes them and
their 404 stays yieldable. Ownership is "does better-call route this", not "is
it in `auth.api`". A table that cannot be built answers "not owned", so an
enumeration failure degrades to the previous behaviour instead of taking the
#4088 surface down with it.
The mount is untouched: it still claims exactly `${basePath}/*` and still
forwards every request under it. What narrowed is which 404 may be handed on.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpTx2tbq3pZRYAdoGt6E6Y
* docs(changeset): carve the trailing-slash and doubled-slash spellings out of the "yielded as before" claim
Text-only; no source, pins or behaviour move on this commit.
The changeset said a path better-auth does not own is "yielded exactly as
before". A live differential built for the clause-② review — better-call
1.4.0's `createRouter` plus `processRequest`'s pre-checks, re-run over rou3
0.9.2 against the real `auth.api` at the stock and the maximal configuration,
4004 + 5278 (method, path) pairs — found 0 divergences in the yield direction,
so that half of the claim is now measured rather than asserted. It also found
the sentence is not unconditional in the other direction.
A TRAILING-SLASH OR DOUBLED-SLASH SPELLING OF A PATH BETTER-AUTH DOES OWN —
`/api/v1/auth/delete-user/`, `/api/v1/auth//sign-in/social` — is claimed by
this ownership table rather than yielded. better-call refuses those spellings
as unrouted: it returns its 404 on a `//` and on trailing-slash parity before
it ever looks the route up, while `betterAuthEndpointPath` strips the trailing
slash and `splitPath` drops empty segments, so the table counts them as owned.
On a composition with a broad downstream mount, such a spelling now answers
better-auth's 404 instead of that mount's response — measured on the wire:
`POST /auth/delete-user/` answers 404 at this head where the pre-fix yield gave
the wildcard's `200 {}`. Bounded at 91 + 153 pairs (stock) and 121 + 212
(maximal).
Left as it is, deliberately: no route in this repo registers a spelling of that
shape, nothing under `/auth/me/*` or any genuinely unowned path is touched, and
the effect where it does show is that a near-miss spelling stops answering a
foreign mount's vacuous 200 — the direction this change argues for. Aligning
`ownsRoute` with better-call's own pre-checks, with a pin, is a follow-up card
rather than a source change on this head.
The changeset feeds release notes, which is why the sentence had to stop being
unqualified even though the divergence is graded non-blocking.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpTx2tbq3pZRYAdoGt6E6Y
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent abe980c commit d4c2cb1
7 files changed
Lines changed: 565 additions & 2 deletions
File tree
- .changeset
- packages/plugins/plugin-auth/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
Lines changed: 8 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
63 | | - | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
64 | 71 | | |
65 | 72 | | |
66 | 73 | | |
| |||
Lines changed: 224 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
59 | 59 | | |
60 | 60 | | |
61 | 61 | | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
62 | 66 | | |
63 | 67 | | |
64 | 68 | | |
| |||
5380 | 5384 | | |
5381 | 5385 | | |
5382 | 5386 | | |
| 5387 | + | |
| 5388 | + | |
| 5389 | + | |
| 5390 | + | |
| 5391 | + | |
| 5392 | + | |
| 5393 | + | |
| 5394 | + | |
| 5395 | + | |
| 5396 | + | |
| 5397 | + | |
| 5398 | + | |
| 5399 | + | |
| 5400 | + | |
| 5401 | + | |
| 5402 | + | |
| 5403 | + | |
| 5404 | + | |
| 5405 | + | |
| 5406 | + | |
| 5407 | + | |
| 5408 | + | |
| 5409 | + | |
| 5410 | + | |
| 5411 | + | |
| 5412 | + | |
| 5413 | + | |
| 5414 | + | |
| 5415 | + | |
| 5416 | + | |
| 5417 | + | |
| 5418 | + | |
| 5419 | + | |
| 5420 | + | |
| 5421 | + | |
| 5422 | + | |
| 5423 | + | |
| 5424 | + | |
| 5425 | + | |
5383 | 5426 | | |
5384 | 5427 | | |
5385 | 5428 | | |
| |||
0 commit comments