Repository navigation
Conversation
static/auth-client.js loaded better-auth@latest from esm.sh, so the browser client could drift from the server version. Pin it to 1.7.6 (the lockfile version on main) with a comment to keep the pin synced on better-auth bumps.
Collaborator
Author
|
Closing in favor of removing the unused module entirely (see replacement PR): static/auth-client.js has no live call sites — the sign-in flow is server-rendered, and no component or test references the module or its exports. Pinning would preserve a dead dependency. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
static/auth-client.jsloaded the browser Better Auth client fromhttps://esm.sh/better-auth@latest/client.@latestlet the browser client drift from the server's pinned version, independently of any dependency PR and with no PR in the loop. This pins the import to1.7.6(main's lockfile version) and adds a comment telling the next bumper to keep it in sync.Why not a wider fix
A bundler (per the TODO in the file) would remove the CDN import entirely, and a CI check asserting the pin matches
package-lock.jsonwould remove the manual sync step. Both are bigger than the drift being fixed here.Scope
One file, one line plus comment. No behavior change at the pinned version today (main already resolves 1.7.6 everywhere else).