diff --git a/PACKAGES.md b/PACKAGES.md index 9735a18..7ad4d9a 100644 --- a/PACKAGES.md +++ b/PACKAGES.md @@ -14,7 +14,7 @@ Every archive carries `package/dist/provenance.json`, holding the 40-character ` Applications declare pgstencil's peer dependencies themselves: `kysely` for every package, `hono` for `@pgstencil/auth`, and `stripe` for `@pgstencil/stripe`. Auth and billing also peer on the `pgstencil` released with them. A library is a peer when the application and pgstencil must share one copy. Either objects cross the boundary, or the library holds module-level state. Kysely and Hono classes have private fields, so two copies are incompatible types. `pgstencil/diagnostics` keeps its request scope in `AsyncLocalStorage`. The application's Renovate updates each shared library once, and pgstencil uses that copy. pnpm reports a release outside a peer range; pgstencil must widen the range first. -Every other dependency is private: pgstencil owns its version and applications do not import it. Better Auth is deliberately private. pgstencil imports its internal subpaths and tests login and linking rules against specific releases, so its range admits patches only. A new login provider or Better Auth plugin belongs in `@pgstencil/auth`, not in an application. Private ranges start at the version pgstencil's CI tested. [`.github/renovate.json`](.github/renovate.json) raises that floor, and re-vendoring carries it into each application. +Every other dependency is private: pgstencil owns its version and applications do not import it. Better Auth is deliberately private. pgstencil imports its internal subpaths and tests login and linking rules against specific releases, so it is pinned to the exact release CI tested. Even a patch can change internals pgstencil reads (1.7.7 renamed its OAuth state rows), so each Better Auth upgrade reaches applications only through a pgstencil release. A new login provider or Better Auth plugin belongs in `@pgstencil/auth`, not in an application. Private ranges start at the version pgstencil's CI tested. [`.github/renovate.json`](.github/renovate.json) raises that floor, and re-vendoring carries it into each application. ## Releasing diff --git a/SECURITY.md b/SECURITY.md index fcc104c..66bf722 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -94,7 +94,7 @@ Report privately through GitHub's [advisory form for diffplug/pgstencil](https:/ - The consumer-owned controls listed above. - An attacker holding both the database contents and `AUTH_SECRET`. Better Auth stores native session tokens, so that pair mints a session cookie; either alone does not. -- Better Auth behavior beyond what these tests pin; its private range admits patches only, and an upgrade must rerun the security and snapshot suites. +- Better Auth behavior beyond what these tests pin; its private dependency is pinned to the exact tested release, and an upgrade must rerun the security and snapshot suites. - A provider that asserts an email it did not verify, and account recovery after a lost provider account or mailbox. Facebook sends no verification claim, so pgstencil treats any address Facebook returns as verified. - Two applications sharing both a database and `AUTH_SECRET`: they share OAuth state, sessions and limits, and count as one application here. - Multi-factor authentication and passkeys, and abuse beyond the budgets above. diff --git a/packages/auth/package.json b/packages/auth/package.json index 37db3a0..dbfb358 100644 --- a/packages/auth/package.json +++ b/packages/auth/package.json @@ -23,7 +23,7 @@ "./better-auth-workers": "./src/better-auth-workers.ts" }, "dependencies": { - "better-auth": "~1.7.7", + "better-auth": "1.7.7", "jose": "^6.2.12", "openid-client": "^6.8.8" }, diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 84c3742..a65f294 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -272,7 +272,7 @@ importers: packages/auth: dependencies: better-auth: - specifier: ~1.7.7 + specifier: 1.7.7 version: 1.7.7(pg@8.23.1)(vitest@5.0.3(@types/node@24.19.0)(vite@8.2.2(@types/node@24.19.0)(esbuild@0.28.2)(jiti@2.7.0)(tsx@4.23.15)(yaml@2.9.0))) jose: specifier: ^6.2.12