Files
sim/packages/auth/src/verify.ts
T
Waleed 34c47f7e93 chore(auth): upgrade better-auth 1.3.12 → 1.6.11 (#4766)
* chore(auth): upgrade better-auth 1.3.12 → 1.6.11

* chore(auth): address Greptile review — broaden change-email type + migration newline

* fix(auth): correct oneTimeToken expiresIn unit (minutes, not seconds)

Better-auth's oneTimeToken expiresIn is in minutes (multiplied by 60_000ms
internally). Sim's existing 24*60*60 evaluated to ~60 days of token
lifetime instead of the intended 24 hours. Tokens are one-time-use and
typically consumed within seconds of generation (Socket.IO handshake),
so this tightens an unused security window without affecting UX.
2026-05-28 11:25:28 -07:00

37 lines
1.1 KiB
TypeScript

import { db } from '@sim/db'
import * as schema from '@sim/db/schema'
import { betterAuth } from 'better-auth'
import { drizzleAdapter } from 'better-auth/adapters/drizzle'
import { oneTimeToken } from 'better-auth/plugins'
export interface VerifyAuthOptions {
/** Better Auth shared secret. Must match the apps/sim Better Auth secret. */
secret: string
/** Public-facing Better Auth URL (usually same as NEXT_PUBLIC_APP_URL). */
baseURL: string
}
/**
* Minimal Better Auth instance used by services that only need to verify
* one-time tokens issued by the main app. Shares the Better Auth DB schema
* (`verification` table) and secret with the main app, so tokens issued by
* `apps/sim`'s full auth config are accepted here.
*/
export function createVerifyAuth(options: VerifyAuthOptions) {
return betterAuth({
baseURL: options.baseURL,
secret: options.secret,
database: drizzleAdapter(db, {
provider: 'pg',
schema,
}),
plugins: [
oneTimeToken({
expiresIn: 24 * 60,
}),
],
})
}
export type VerifyAuth = ReturnType<typeof createVerifyAuth>