Release v5.2.8 (#3375)

Upgrades to Better Auth 1.7, expands Custom Styles coverage of item headers, and adds a human-approval step to the AI agent's resume edits.

Breaking for self-hosters using a custom OAuth provider: the callback path changes from /api/auth/oauth2/callback/custom to /api/auth/callback/custom, and installs using OAUTH_DISCOVERY_URL need one additional UPDATE after upgrading. Both are documented in docs/self-hosting/sso.mdx.

- Better Auth 1.7, with the account issuer migration and the jwks alg/crv columns the 1.7 jwt plugin requires
- Agent edits gated behind an approval step, with crash-safe runs and context pruning
- item-header now covers every section header row on every template; adds the item-header-row part
- Fixes provider unlinking, auth error messages, and version conflicts on freshly created resumes
- New /auth/error page, translated across all 53 target locales
- DeepSeek Harness plugin moved into packages/dsh-plugin
- Dependency bumps across the workspace
This commit is contained in:
Amruth Pillai
2026-08-24 21:44:16 +02:00
committed by GitHub
parent 3221afda9d
commit 3c195dc3f8
160 changed files with 17743 additions and 3892 deletions
@@ -0,0 +1,41 @@
-- Better Auth 1.7 scopes account identity to (issuer, accountId) instead of providerId alone.
-- `findCredentialAccount`, `findAccountByKey`, and `findAccountOwnerByKey` all filter on `issuer`,
-- so every sign-in fails until this column exists and is backfilled to match what the runtime
-- computes for each provider.
--
-- Issuer values below mirror better-auth@1.7.1 exactly:
-- * credential -> `local:credential`, with accountId normalised to the user id
-- * google -> `https://accounts.google.com` (social-providers/google.mjs: accountIssuer)
-- * github/linkedin -> `local:oauth:<id>` (no accountIssuer -> createOAuthAccountIssuer)
-- * anything else -> `local:oauth:<id>` (same fallback)
--
-- Generic-OAuth providers configured with OAUTH_DISCOVERY_URL resolve their issuer from discovery
-- at runtime, which is deployment-specific and cannot be known here. Those rows get the
-- `local:oauth:<id>` fallback; see docs/self-hosting/sso.mdx for the one-line UPDATE they need.
ALTER TABLE "account" ADD COLUMN "issuer" text;--> statement-breakpoint
UPDATE "account" SET "issuer" = 'local:credential', "account_id" = "user_id" WHERE "provider_id" = 'credential';--> statement-breakpoint
UPDATE "account" SET "issuer" = 'https://accounts.google.com' WHERE "provider_id" = 'google';--> statement-breakpoint
UPDATE "account" SET "issuer" = 'local:oauth:' || "provider_id" WHERE "issuer" IS NULL;--> statement-breakpoint
DO $$
DECLARE
collisions bigint;
BEGIN
SELECT count(*) INTO collisions FROM (
SELECT 1 FROM "account" GROUP BY "issuer", "account_id" HAVING count(*) > 1
) AS duplicates;
IF collisions > 0 THEN
RAISE EXCEPTION
'account issuer backfill produced % duplicate (issuer, account_id) pair(s); resolve them before retrying. Inspect with: SELECT issuer, account_id, count(*) FROM account GROUP BY 1, 2 HAVING count(*) > 1;',
collisions;
END IF;
END $$;--> statement-breakpoint
ALTER TABLE "account" ALTER COLUMN "issuer" SET NOT NULL;--> statement-breakpoint
CREATE UNIQUE INDEX "account_issuer_account_id_unique_idx" ON "account" ("issuer","account_id");
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,2 @@
ALTER TABLE "jwks" ADD COLUMN "alg" text;--> statement-breakpoint
ALTER TABLE "jwks" ADD COLUMN "crv" text;
File diff suppressed because it is too large Load Diff