Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

better-auth adapter: update() with compound where fails (deviceAuthorization verify-claim) — no updateMany fallback

Open Beginner friendly
#2,694 3 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
72/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
typescript

Research direction

Start in packages/auth-adapters/better-auth/src/adapter.ts: read convertWhereClause() (L47-90) and update() (L146-152), then compare with the updateMany() implementation directly below. Decide whether the converted where is a single top-level unique selector and route non-unique compounds through updateMany, optionally re-reading by the unique field. Reproduce with the deviceAuthorization verify step on DeviceCode; done when that update no longer raises 'At least one unique field must be set at where' and the adapter tests pass.

Written by the indexing model from the issue text.

Description

Summary

@zenstackhq/better-auth's update() forwards a compound (AND) where straight to ZenStack ORM update(), which requires a unique field at the top level of where. Any better-auth flow that updates by a multi-condition where therefore fails before SQL runs. This is now hit in normal usage by better-auth's deviceAuthorization plugin.

Environment
  • @zenstackhq/better-auth: 3.3.3 and 3.7.2 (latest) — same behavior
  • better-auth: 1.6.12 (regression triggered by >= 1.6.11)
  • ZenStack ORM 3.x, provider sqlite/postgresql
Repro
  1. Use zenstackAdapter as the better-auth database.
  2. Enable the deviceAuthorization plugin.
  3. Sign in, then open GET /device?user_code=... (verify step).
  4. Error:
    Invalid update args for model "DeviceCode": Validation error:
    At least one unique field or field set must be set at "where"
    
Root cause

better-auth >=1.6.11 added a verify-time ownership claim that updates with a compound where { id, status: "pending", userId: null } (https://github.com/better-auth/better-auth/blob/a6f38c72ee3423ae80b0595fec3b4a61158c374d/packages/better-auth/src/plugins/device-authorization/routes.ts#L144-L154).
The adapter's convertWhereClause() turns >=2 conditions into { AND: [...] } (https://github.com/zenstackhq/zenstack/blob/f41a1f6e4ae08af29bff3d2b3d8cde980708c214/packages/auth-adapters/better-auth/src/adapter.ts#L47-L90), and update() calls modelDb.update({ where }) unconditionally (https://github.com/zenstackhq/zenstack/blob/f41a1f6e4ae08af29bff3d2b3d8cde980708c214/packages/auth-adapters/better-auth/src/adapter.ts#L146-L152). ORM update() rejects the nested unique.

Suggested fix

In update(), when the converted where is not a single top-level unique selector, fall back to the existing updateMany() (then optionally re-read by the unique field) — mirroring how better-auth's own Prisma adapter handles non-unique update where. The adapter already implements updateMany() right below update().

Dominant language
TypeScript
Stars
2.9k
Forks
157
Avg merge
11h 42m
Merged PRs (30d)
20

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from zenstackhq/zenstack

All issues in zenstackhq/zenstack

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.