Title: improvement(auth): bump better-auth to 1.6.23 and add trusted-proxy client IP resolution by waleedlatif1 · Pull Request #5857 · simstudioai/sim · GitHub
Open Graph Title: improvement(auth): bump better-auth to 1.6.23 and add trusted-proxy client IP resolution by waleedlatif1 · Pull Request #5857 · simstudioai/sim
X Title: improvement(auth): bump better-auth to 1.6.23 and add trusted-proxy client IP resolution by waleedlatif1 · Pull Request #5857 · simstudioai/sim
Description: Summary Bump better-auth, @better-auth/sso, and @better-auth/stripe from 1.6.13 to 1.6.23 (1.6.24 was published today and is blocked by our 7-day minimumReleaseAge supply-chain gate; the only change it adds is an emailOTP origin-validation fix we can pick up later) Wire up advanced.ipAddress.trustedProxies (added upstream in 1.6.21) behind a new optional AUTH_TRUSTED_PROXIES env var — comma-separated proxy IPs/CIDRs; the forwarded-IP chain is walked right to left, trusted hops are skipped, and the first untrusted address becomes the client IP This closes the x-forwarded-for spoofing hole in Better Auth's client IP resolution and is the foundation for upcoming org-level security policies (IP allowlisting, session policies, MFA enforcement) Backwards-compat audit Three-way audit performed: full release-notes + PR review for all 10 releases, field-by-field DB schema diff (programmatic cross-check of 1.6.23's getAuthTables output for our exact plugin set against @sim/db/schema), and a call-site cross-check of every auth.api.*/client usage against the installed 1.6.23 dist source. Clean: No DB migrations needed — zero schema changes for our plugin set; the only new column (ssoProvider.domainVerified) is gated behind domainVerification.enabled, which we don't set, and writes to it are dropped by the adapter's schema-field filter Rolling deploy + rollback safe — cookie-cache HMAC/envelope/chunking byte-identical in both versions; 1.6.13 cookies validate under 1.6.23 and vice versa; one-time tokens are format-identical so app/realtime version skew during the deploy window is safe both directions No code changes required — no Sim call site uses /update-session (org activation goes through setActive), no admin call passes role/ban via data, socket reconnects mint fresh one-time tokens (atomic-consume fix is a no-op for us), customSession/databaseHooks/session-config semantics unchanged Bonus fix: invalid cookie-cache now falls through to a DB read instead of returning null (likely resolves the stale-cookie impersonation blank-loader bug) 1.6.23 is the correct landing version — the postgres-js affected-row-count fix (#10257) is required by 1.6.17+'s atomic state transitions; do not stop at 1.6.17–1.6.22 Pre-deploy actions: SSO account-linking regression (1.6.16): SSO sign-in trust is no longer granted via accountLinking.trustedProviders — our SSO_TRUSTED_PROVIDERS/SSO_TRUSTED_PROVIDER_IDS lists are now inert for SSO. Auto-linking an SSO login to an existing same-email account now requires the IdP to assert a verified email (OIDC email_verified — strictly boolean true/"true" now — or a SAML emailVerified attribute mapping). Audit sso_provider rows before deploy: confirm each tenant's IdP asserts verified email, or affected users get "account not linked" on sign-in AUTH_TRUSTED_PROXIES MUST be set in cloud prod as part of this deploy — hard requirement, not hygiene. Better Auth'''s built-in rate limiter is on by default in production (sign-in/sign-up: 3 req / 10 s per key, keyed by IP). On 1.6.23, a multi-entry XFF chain with no trustedProxies resolves the client IP to null, and all null-IP requests collapse into one shared no-trusted-ip bucket per path — i.e. the entire user base would share 3 sign-ins per 10 seconds. An attacker can force this on any topology by sending a forged XFF header (LB appends the real IP → multi-entry → null), so blank is also a sign-in DoS vector. Set it to the LB/VPC CIDR (+ CDN egress ranges if one fronts the app). Self-hosters: blank remains functional for single-proxy setups; the var is exposed in docker-compose.prod.yml and the Helm chart Staging verification list: SAML sign-in per live tenant: assertions missing AudienceRestriction/bearer SubjectConfirmationData are now rejected; audience/recipient must match SP entityID/ACS (per-provider samlConfig.audience is the escape hatch) SSO OIDC sign-in: token/userinfo/jwks endpoints resolving to private addresses are now rejected unless the IdP origin is in TRUSTED_ORIGINS — needs a self-hoster release note genericOAuth smoke pass (sign-in + connector token refresh): token-exchange fetches now refuse 3xx responses; any provider whose tokenUrl redirects (www/apex, region) fails Stripe: billing-portal/checkout returnUrl now validated against trustedOrigins; cancel/restore 400s on subscription rows lacking stripeSubscriptionId (check manually provisioned enterprise rows) Email sign-in/up from non-browser callers: Origin/Referer, when present, is now validated against trustedOrigins even without cookies Watch 429 rates post-deploy (rate limiting is now concurrency-safe and runs before plugin handlers) Support note: email-OTP sign-in by a never-verified password user now deletes their password credential and revokes sessions first (anti-pre-hijack, #10239) Type of Change Improvement Testing Typecheck clean 235 auth tests + 1098 organization/billing/SSO/EE tests pass Realtime suite: identical pre-existing failures on staging baseline (env-dependent, unrelated) Checklist Code follows project style guidelines Self-reviewed my changes Tests added/updated and passing No new warnings introduced I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)
Open Graph Description: Summary Bump better-auth, @better-auth/sso, and @better-auth/stripe from 1.6.13 to 1.6.23 (1.6.24 was published today and is blocked by our 7-day minimumReleaseAge supply-chain gate; the only chan...
X Description: Summary Bump better-auth, @better-auth/sso, and @better-auth/stripe from 1.6.13 to 1.6.23 (1.6.24 was published today and is blocked by our 7-day minimumReleaseAge supply-chain gate; the only chan...
Opengraph URL: https://github.com/simstudioai/sim/pull/5857
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:d5afd5e3-1d9a-eede-2e2a-9b77e7c72406 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | 9864:1BB886:1B289E:2795C8:6A6364C9 |
| html-safe-nonce | 7aaf6a8613856782fc85963519ab34f245d175e324e2a8c20cad82506bb0adf1 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5ODY0OjFCQjg4NjoxQjI4OUU6Mjc5NUM4OjZBNjM2NEM5IiwidmlzaXRvcl9pZCI6IjgxMDYxNTk4OTI4NTkxNTE1NjEiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 08ea664129e751fe777ecddf83613970d8aee09acce3a1c277c8baf9c55c9fc8 |
| hovercard-subject-tag | pull_request:4111564590 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/simstudioai/sim/pull/5857/files |
| twitter:image | https://avatars.githubusercontent.com/u/40672544?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/40672544?s=400&v=4 |
| og:image:alt | Summary Bump better-auth, @better-auth/sso, and @better-auth/stripe from 1.6.13 to 1.6.23 (1.6.24 was published today and is blocked by our 7-day minimumReleaseAge supply-chain gate; the only chan... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 669d3fcd704a169521d2b6431762f95a6878a9e8ccaf0fd5f2d0802fc5b971f9 |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/simstudioai/sim git https://github.com/simstudioai/sim.git |
| octolytics-dimension-user_id | 199344406 |
| octolytics-dimension-user_login | simstudioai |
| octolytics-dimension-repository_id | 912559512 |
| octolytics-dimension-repository_nwo | simstudioai/sim |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 912559512 |
| octolytics-dimension-repository_network_root_nwo | simstudioai/sim |
| turbo-body-classes | logged-out env-production page-responsive full-width |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 20da292f132ff51328be50073854259f417052c1 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width