fix: align oauth client seed with the better-auth 1.7 schema - #82
Conversation
better-auth and @better-auth/oauth-provider 1.7 remove the oauthClient "public" and "type" columns. The raw planner-client seed still inserts "public", so it fails on every schema the 1.7 migrations create: 31 of 81 tests failed, and a fresh environment could not seed at all. Drop the column from the seed, assert that both removed columns are absent, and pin better-auth to ^1.7.5 so a fresh resolution cannot land on 1.6. The release-phase seed still runs against a production table that keeps the legacy columns, and the migrator never drops them, so that path is unaffected. Public-client behaviour is unchanged: tokenEndpointAuthMethod "none" decides it in 1.7, and the seed still sets it, with skipConsent and requirePKCE true.
|
I haven't looked but maybe better auth has another way than an sql query? I only found this: Not sure if admin api works from CLI? |
It seems that using direct access to database is the current "recommended" way to handle this. |
better-auth and @better-auth/oauth-provider 1.7 remove the
oauthClientpubliccolumn, so the raw planner-client seed fails on every schema the 1.7 migrations create: 31 of 81 tests fail on the dependency bump alone, and a fresh environment cannot seed at all. This PR makes the seed and its test match the 1.7 schema, and carries only the two dependency upgrades the fix needs.src/app/db/seed-client.jsdrops"public"from the column list and its bound value; the statement stays 12 columns to 12 values, and every other seeded value is unchanged.public,type) are absent and reads backskipConsent, so a schema drift in either direction fails the suite rather than passing silently.@better-auth/oauth-provider1.6.27 -> 1.7.5 (exact pin) andbetter-auth^1.6.20->^1.7.5.Review notes
Start with the seed statement. The Heroku release phase runs this same SQL under
set -eagainst a database created by the 1.6 migrations, wherepublicandtypestill exist. The 1.7 migrator only ever adds columns, so that path keeps working, and the statement no longer names the column on either shape of schema. The residual risk is structural rather than specific to this diff: the seed is raw SQL with no schema check, so a future column change fails at release time instead of at review time.The
better-authrange moved to^1.7.5rather than staying^1.6.20as it does in #81. The code now requires the 1.7 schema, and a lockfile-free install of^1.6.20could resolve a 1.6.x release and fail.Deliberately not done: the remaining upgrades in #81 stay there — hono 4.13.9 (which carries GHSA-hxh3-vqpv-xpqv, a
hono/jsxXSS fix; this application does not usehono/jsx), eslint, @playwright/test, fallow, prettier, tap, lint-staged, globals and commitlint. Nothing here needs them.Also outside this PR, for a follow-up: after the upgrade the production table keeps
publicandtypeas dead columns, and the existing planner row keepsapplicationTypeNULL.Lockfile detail
Fourteen entries move, all consequences of better-auth 1.7.5:
better-auth,@better-auth/core,@better-auth/oauth-provider,@better-auth/{kysely,memory,mongo,prisma,drizzle}-adapter,@better-auth/telemetry@better-fetch/fetch1.3.1 -> 1.3.2 (peer of oauth-provider 1.7)zod4.4.3 -> 4.6.5,@types/node26.0.0 -> 26.6.3,undici-types8.3.0 -> 8.9.0 (transitive)better-auth/node_modules/@better-auth/drizzle-adapter, which is hoisted to the root at 1.7.5No other package in the lockfile changes: hono stays 4.13.5, eslint stays 10.8.1.