v1.7.1
Added 1
- Add optional SCIM-owned connection and credential catalog via managedConnections configuration for creating runtime tenant connections and managing bearer credentials
Changed 3
- Update bundled dependencies (jose, nanostores, noble crypto packages, SimpleWebAuthn) to their latest compatible releases
- Enforce signing policy and size limits on SP metadata
- Make wantAssertionsSigned now correctly control whether the SP requires signed assertions
Fixed 11
- Add native database transaction support to test instances for PostgreSQL and MySQL
- Fix case-insensitive parsing of string Boolean values for SCIM User active and primary sub-attributes of emails, phoneNumbers, addresses, roles, and entitlements at the HTTP ingress
- Fix an issue where trusted server code could not retain a terminal connection binding before a dynamic SCIM connection's first authenticated request when supplying a provisioning domain during decommissioning
- Fix SSO provider registration to allow reusing a SCIM connection ID
- Fix SAML assertion signature verification to validate signatures on the raw assertion instead of trusting an already-parsed response
- Fix Client ID Metadata Document caching to follow shared-cache freshness rules with proper handling of s-maxage, max-age, Expires, ETag, and Last-Modified
- Fix concurrent metadata refreshes to converge on a single client-resource link instead of failing on a unique constraint
- Fix native adapter transactions for raw database instances passed directly as database parameter
- Enable plugins requiring native transactions such as @better-auth/scim to work correctly when using the quickstart database form
- Fix scope error responses so MCP clients receive a 403 with an RFC 6750 insufficient_scope WWW-Authenticate challenge naming every missing scope
- Fix the CLI to refuse adding required columns without default values to already-populated tables
From Better Auth
better-auth
Bug Fixes
- Added native database transaction support to test instances for PostgreSQL and MySQL.
- Updated bundled dependencies (
jose, nanostores, noble crypto packages, SimpleWebAuthn) to their latest compatible releases, with no changes required to existing projects.
For detailed changes, see CHANGELOG
@better-auth/scim
Bug Fixes
- Fixed case-insensitive parsing of string Boolean values for SCIM User
activeand theprimarysub-attribute ofemails,phoneNumbers,addresses,roles, andentitlementsat the HTTP ingress, improving Microsoft Entra interoperability. - Added an optional SCIM-owned connection and credential catalog: configure
managedConnectionsto allow trusted server code to create runtime tenant connections and issue, rotate, and revoke bearer credentials through server-onlyauth.apimethods, without a code-defined connection or an application-owned verifier. - Fixed an issue where trusted server code could not retain a terminal connection binding before a dynamic SCIM connection's first authenticated request when supplying a provisioning domain during decommissioning.
For detailed changes, see CHANGELOG
@better-auth/sso
Bug Fixes
- Fixed SSO provider registration to allow reusing a SCIM connection ID, as SCIM connections no longer participate in the authentication provider namespace.
- Fixed SAML assertion signature verification to validate signatures on the raw assertion instead of trusting an already-parsed response, and enforced signing policy and size limits on SP metadata.
wantAssertionsSignednow correctly controls whether the SP requires signed assertions, matching real-world IdP signing behavior.
For detailed changes, see CHANGELOG
@better-auth/cimd
Bug Fixes
- Fixed Client ID Metadata Document caching to follow shared-cache freshness rules: the plugin now prefers
s-maxageovermax-ageandExpires, honorss-maxage=0, conditionally revalidates withETagorLast-Modified, and treats invalid or duplicate freshness directives as immediately stale. Concurrent refreshes now converge on a single client-resource link instead of failing on a unique constraint.
For detailed changes, see CHANGELOG
@better-auth/kysely-adapter
Bug Fixes
- Fixed native adapter transactions for raw database instances (better-sqlite3,
node:sqlite,bun:sqlite,mysql2,pg) passed directly asdatabase, matching the behavior of the explicit{ db }/{ dialect }config shapes. Plugins requiring native transactions (such as@better-auth/scim) now work correctly when using the quickstartdatabase: new Database(...)form.
For detailed changes, see CHANGELOG
@better-auth/oauth-provider
Bug Fixes
- Fixed scope error responses so MCP clients now receive a
403with an RFC 6750insufficient_scopeWWW-Authenticatechallenge naming every missing scope, allowing clients to request all needed scopes in a single authorization request.
For detailed changes, see CHANGELOG
auth
Bug Fixes
- Fixed the CLI to refuse adding required columns without default values to already-populated tables (#10863)
For detailed changes, see CHANGELOG
Contributors
Thanks to everyone who contributed to this release:
@gustavovalverde
Full changelog: v1.7.0...v1.7.1