Repository navigation
Conversation
The browser Better Auth client module has no live call sites: the sign-in flow is server-rendered (GitHubButton posts /login/github, MagicLinkButton targets /login/magic-link), and no component, test, or e2e run references the module or its exports. Its esm.sh @latest import was a version-drift hazard reachable by every page load; remove it and the layout script tag.
mroderick
marked this pull request as ready for review
October 10, 2026 09:06
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Removes
static/auth-client.jsand the<script type="module">tag that loaded it fromsrc/app/components/layout.js. 36 lines gone, no additions. Closes out the esm.shbetter-auth@latestdrift noted in the dependency-upgrade reviews.Why the module is unused
GitHubButton(form POST to/login/github) andMagicLinkButton(form to/login/magic-link);startGitHubOAuthandsendMagicLinkare plain Hono handlers.handleGitHubSignIn,signIn,signUp, or thedata-redirect-urlattribute it reads).grep -rln authClientoversrc/returns nothing outside the script itself.e84db13), had its passkey code stripped (26b1e1d), and never got re-wired after the server-side form migration.Verification
CI=1 npm test; the pretest helper picks up the runningauth-test-pgcontainer on 5433).Follow-up
None. If a browser-side auth client is needed again, it should come with a bundler (per the TODO that used to be in the file) so the browser and server versions can't drift.
Context
Supersedes the pinning approach in closed #92, which kept the unused module alive to avoid drift; removal is the better fix.