Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

better-auth adapter: update() with compound where fails (deviceAuthorization verify-claim) — no updateMany fallback

Abierto Apto para principiantes
#2,694 3 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
72/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
typescript

Línea de trabajo

Comienza en packages/auth-adapters/better-auth/src/adapter.ts: lee convertWhereClause() (L47-90) y update() (L146-152), luego compara con la implementación de updateMany() justo debajo. Decide si el where convertido es un único selector único de nivel superior y enruta los compuestos no únicos a través de updateMany, opcionalmente releyendo por el campo único. Reproduce con el paso verify de deviceAuthorization en DeviceCode; hecho cuando esa actualización ya no lance 'At least one unique field must be set at where' y pasen las pruebas del adaptador.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Summary

@zenstackhq/better-auth's update() forwards a compound (AND) where straight to ZenStack ORM update(), which requires a unique field at the top level of where. Any better-auth flow that updates by a multi-condition where therefore fails before SQL runs. This is now hit in normal usage by better-auth's deviceAuthorization plugin.

Environment
  • @zenstackhq/better-auth: 3.3.3 and 3.7.2 (latest) — same behavior
  • better-auth: 1.6.12 (regression triggered by >= 1.6.11)
  • ZenStack ORM 3.x, provider sqlite/postgresql
Repro
  1. Use zenstackAdapter as the better-auth database.
  2. Enable the deviceAuthorization plugin.
  3. Sign in, then open GET /device?user_code=... (verify step).
  4. Error:
    Invalid update args for model "DeviceCode": Validation error:
    At least one unique field or field set must be set at "where"
    
Root cause

better-auth >=1.6.11 added a verify-time ownership claim that updates with a compound where { id, status: "pending", userId: null } (https://github.com/better-auth/better-auth/blob/a6f38c72ee3423ae80b0595fec3b4a61158c374d/packages/better-auth/src/plugins/device-authorization/routes.ts#L144-L154).
The adapter's convertWhereClause() turns >=2 conditions into { AND: [...] } (https://github.com/zenstackhq/zenstack/blob/f41a1f6e4ae08af29bff3d2b3d8cde980708c214/packages/auth-adapters/better-auth/src/adapter.ts#L47-L90), and update() calls modelDb.update({ where }) unconditionally (https://github.com/zenstackhq/zenstack/blob/f41a1f6e4ae08af29bff3d2b3d8cde980708c214/packages/auth-adapters/better-auth/src/adapter.ts#L146-L152). ORM update() rejects the nested unique.

Suggested fix

In update(), when the converted where is not a single top-level unique selector, fall back to the existing updateMany() (then optionally re-read by the unique field) — mirroring how better-auth's own Prisma adapter handles non-unique update where. The adapter already implements updateMany() right below update().

Lenguaje dominante
TypeScript
Estrellas
2.9k
Forks
157
Merge medio
11 h 42 min
PR fusionados (30 d)
20

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de zenstackhq/zenstack

Todos los issues de zenstackhq/zenstack

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.