fix(auth)!: always mount client session lifecycle - #412
Merged
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
commit: |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
better-auth | 591ae37 | Commit Preview URL Branch Preview URL |
Aug 24 2026, 11:34 AM |
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
skipHydratedSsrGetSessioncurrently avoids the duplicate client request by skippingrawClient.useSession()entirely. That also prevents Better Auth's session refresh manager from mounting, so focus, polling, online, and broadcast refresh stop working on hydrated SSR pages.This keeps the existing opt-in and default behavior, but changes the optimized path to:
useSession()so Better Auth retains ownership of its refresh lifecycleThe bootstrap remains inside Better Fetch's normal hook and response pipeline. Its request identity survives supported plugin URL rewrites, query schema validation, and request-hook transformations. The controller is one-shot and fails closed if session fetching starts before Nuxt can arm it.
The docs now call out that the bootstrap response uses Nuxt's sanitized
userandsessionshape, so the session token and custom top-level response fields remain unavailable until Better Auth's next native refresh.Verification
corepack pnpm exec vitest run --maxWorkers=2— 324 tests passedcorepack pnpm typecheckcorepack pnpm lintcorepack pnpm prepackgit diff --check