Skip to content

fix: pin the browser better-auth client to the server's version - #92

Closed
mroderick wants to merge 1 commit into
mainfrom
fix/pin-browser-better-auth-version
Closed

mroderick wants to merge 1 commit into
mainfrom
fix/pin-browser-better-auth-version

Conversation

@mroderick

Copy link
Copy Markdown
Collaborator

What

static/auth-client.js loaded the browser Better Auth client from https://esm.sh/better-auth@latest/client. @latest let the browser client drift from the server's pinned version, independently of any dependency PR and with no PR in the loop. This pins the import to 1.7.6 (main's lockfile version) and adds a comment telling the next bumper to keep it in sync.

Why not a wider fix

A bundler (per the TODO in the file) would remove the CDN import entirely, and a CI check asserting the pin matches package-lock.json would remove the manual sync step. Both are bigger than the drift being fixed here.

Scope

One file, one line plus comment. No behavior change at the pinned version today (main already resolves 1.7.6 everywhere else).

static/auth-client.js loaded better-auth@latest from esm.sh, so the browser
client could drift from the server version. Pin it to 1.7.6 (the lockfile
version on main) with a comment to keep the pin synced on better-auth bumps.
@mroderick

Copy link
Copy Markdown
Collaborator Author

Closing in favor of removing the unused module entirely (see replacement PR): static/auth-client.js has no live call sites — the sign-in flow is server-rendered, and no component or test references the module or its exports. Pinning would preserve a dead dependency.

@mroderick mroderick closed this Oct 10, 2026
@mroderick
mroderick deleted the fix/pin-browser-better-auth-version branch October 10, 2026 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant