better-auth · Issues· 719 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #10748
feat: email confirmation for org deletion & ownership transfer, plus opt-in confirmationMode
organizationUpdated Sep 17, 2026 - #11323
`maxPasswordLength` is not enforced before hashing on sign-in, verify-password, change-password (currentPassword), delete-user, two-factor and admin create-user
Updated Sep 17, 2026 - #11321
`trustedProviders` is not respected with social login
Updated Sep 17, 2026 - #11318
oauth-provider: consent deletion leaves pending codes redeemable
Updated Sep 17, 2026 - #11317
oauth-provider: refresh replay can leave successor usable
Updated Sep 17, 2026 - #9636
Support Prisma ORM 8
target: patchdatabaseUpdated Sep 17, 2026 - #10806
feat(cookies): support the `__Host-` cookie prefix
target: patchcoresecurityUpdated Sep 17, 2026 - #11096
Organization: check an arbitrary member’s current permissions server-side
target: patchUpdated Sep 16, 2026 - #11308
Allow multiple domains in the SIWE plugin
Updated Sep 16, 2026 - #11303
organization: `create-role` and `update-role` accept a comma in the role name, persisting a role that can never be assigned
Updated Sep 16, 2026 - #11296
sso: SAML ACS from samlConfig.callbackUrl never reaches expectedRecipients (binding URN passed where samlify expects "post")
Updated Sep 16, 2026 - #11294
The model "oauthResource" was not found in the schema object
Updated Sep 15, 2026 - #11297
phone-number plugin stores the OTP in clear; no storeOTP option as email-otp has
Updated Sep 15, 2026 - #4291
Encrypt OIDC Config at Rest
target: patchsecurityenterpriseUpdated Sep 15, 2026 - #10885
feat(organization): support opt-in soft deletion for organization members
organizationUpdated Sep 15, 2026