better-auth >=1.7 (1.7.1 measured on web1; our ^1.5.5 range resolves it
on fresh installs) requires an issuer on every account row: sign-up
writes the synthetic 'local:credential' and sign-in filters accounts on
(providerId='credential' AND issuer=that value). The db schema had no
issuer column, so every fresh next install 500s at signup and 401s every
sign-in while admin-token auth kept working.
- schema: accounts.issuer text, nullable — the 1.5.x line our lockfile
resolves to does not know the field (1.5 ignores, 1.7 populates; one
schema serves both)
- migration 0017 (drizzle-kit generated snapshot/ALTER, hand backfill
folded in): ADD COLUMN issuer text; UPDATE credential rows with NULL
issuer to 'local:credential'. OAuth/sso rows deliberately left NULL —
better-auth owns their issuer semantics going forward
- tests: greenfield column assertion (nullable, text); UPGRADE-PATH arm
replays 0000..0016, seeds one credential + one oauth row without
issuer, applies 0017, and discriminates: credential backfilled,
oauth stays NULL
- mutants killed: backfill dropped -> upgrade arm fails; backfill-all ->
oauth assertion fails
Found by T63 on web1 greenfield; verified there as a dist-patch (prior
art). Root cause, error strings, and the post-fix 200 measured by fred;
independently re-derived here against @better-auth/[email protected]'s schema
exports (issuer exists ONLY on account — user/session/verifications
carry no issuer field).