AI студия Владимира Ломтева
УСЛУГИПРОЕКТЫСТАТЬИБАЗА ЗНАНИЙМаркетплейсПолезные сервисы

Оставьте заявку,
чтобы обсудить проект

Напишите ваш вопрос, не забудьте указать телефон. Мы перезвоним и все расскажем.

Контакты

Москва

Работаем по всей России
и миру (онлайн)

+7 (999) 760-24-41

Ежедневно с 9:00 до 21:00

lamooof@gmail.com

По вопросам сотрудничества

TelegramWhatsApp

Есть предложение?

Напишите нам в мессенджеры

© 2025 AI студия Владимира Ломтева

Политика конфиденциальностиСогласие на обработку ПДн|ИНН 623412173261
    Better Auth Best Practices — Скилл для ИИ-агентов | AI Рассвет

    Better Auth Best Practices

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration.

    Скиллы для разработки#GitHub#better-auth/skills#skills.sh
    Скачивания
    0
    В избранном
    0
    Комментарии
    0
    Просмотры
    3

    Установить скилл

    Добавьте инструмент одной командой или скачайте проверенный архив версии.

    npx skills add better-auth/skills --skill better-auth-best-practices
    Скачать ZIP
    Версия
    1.0.0+17dfe3a1da1c
    Автор
    Владимир Ломтев
    Репозиторий
    better-auth/skills
    GitHub: better-auth/skills

    Как установить

    1. 1Скопируйте команду из блока установки.
    2. 2Запустите её в терминале из каталога проекта.

    Документация

    Better Auth Integration Guide

    Always consult better-auth.com/docs for code examples and latest API.


    Setup Workflow

    1. Install: npm install better-auth
    2. Set env vars: BETTER_AUTH_SECRET and BETTER_AUTH_URL
    3. Create auth.ts with database + config
    4. Create route handler for your framework
    5. Run migrations:
      • Built-in adapter: npx @better-auth/cli@latest migrate
      • Drizzle: npx @better-auth/cli@latest generate --output src/db/auth-schema.ts then npx drizzle-kit push (dev) or npx drizzle-kit generate && npx drizzle-kit migrate (prod)
      • Prisma: npx @better-auth/cli@latest generate --output prisma/schema.prisma then npx prisma migrate dev
    6. Verify: call GET /api/auth/ok — should return { status: "ok" }

    Quick Reference

    Environment Variables

    • BETTER_AUTH_SECRET - Encryption secret (min 32 chars). Generate: openssl rand -base64 32
    • BETTER_AUTH_URL - Base URL (e.g., https://example.com)

    Only define baseURL/secret in config if env vars are NOT set.

    File Location

    CLI looks for auth.ts in: ./, ./lib, ./utils, or under ./src. Use --config for custom path.

    CLI Commands

    • npx @better-auth/cli@latest migrate - Apply schema (built-in adapter)
    • npx @better-auth/cli@latest generate - Generate schema for Prisma/Drizzle
    • npx @better-auth/cli mcp --cursor - Add MCP to AI tools

    Re-run after adding/changing plugins.


    Core Config Options

    Option Notes
    appName Optional display name
    baseURL Only if BETTER_AUTH_URL not set
    basePath Default /api/auth. Set / for root.
    secret Only if BETTER_AUTH_SECRET not set
    database Required for most features. See adapters docs.
    secondaryStorage Redis/KV for sessions & rate limits
    emailAndPassword { enabled: true } to activate
    socialProviders { google: { clientId, clientSecret }, ... }
    plugins Array of plugins
    trustedOrigins CSRF whitelist

    Database

    Direct connections: Pass pg.Pool, mysql2 pool, better-sqlite3, or bun:sqlite instance. For Postgres, also supports postgres (postgres.js) and @neondatabase/serverless.

    ORM adapters: Import from better-auth/adapters/drizzle, better-auth/adapters/prisma, better-auth/adapters/mongodb.

    Drizzle provider values: "pg" (PostgreSQL), "mysql" (MySQL), "sqlite" (SQLite). Must match the driver used.

    Critical: Better Auth uses adapter model names, NOT underlying table names. If Prisma model is User mapping to table users, use modelName: "user" (Prisma reference), not "users".


    Session Management

    Storage priority:

    1. If secondaryStorage defined → sessions go there (not DB)
    2. Set session.storeSessionInDatabase: true to also persist to DB
    3. No database + cookieCache → fully stateless mode

    Cookie cache strategies:

    • compact (default) - Base64url + HMAC. Smallest.
    • jwt - Standard JWT. Readable but signed.
    • jwe - Encrypted. Maximum security.

    Key options: session.expiresIn (default 7 days), session.updateAge (refresh interval), session.cookieCache.maxAge, session.cookieCache.version (change to invalidate all sessions).


    User & Account Config

    User: user.modelName, user.fields (column mapping), user.additionalFields, user.changeEmail.enabled (disabled by default), user.deleteUser.enabled (disabled by default).

    Account: account.modelName, account.accountLinking.enabled, account.storeAccountCookie (for stateless OAuth).

    Required for registration: email and name fields.


    Email Flows

    • emailVerification.sendVerificationEmail - Must be defined for verification to work
    • emailVerification.sendOnSignUp / sendOnSignIn - Auto-send triggers
    • emailAndPassword.sendResetPassword - Password reset email handler

    Security

    In advanced:

    • useSecureCookies - Force HTTPS cookies
    • disableCSRFCheck - ⚠️ Security risk
    • disableOriginCheck - ⚠️ Security risk
    • crossSubDomainCookies.enabled - Share cookies across subdomains
    • ipAddress.ipAddressHeaders - Custom IP headers for proxies
    • database.generateId - Custom ID generation or "serial"/"uuid"/false

    Rate limiting: rateLimit.enabled, rateLimit.window, rateLimit.max, rateLimit.storage ("memory" | "database" | "secondary-storage").


    Hooks

    Endpoint hooks: hooks.before / hooks.after - Array of { matcher, handler }. Use createAuthMiddleware. Access ctx.path, ctx.context.returned (after), ctx.context.session.

    Database hooks: databaseHooks.user.create.before/after, same for session, account. Useful for adding default values or post-creation actions.

    Hook context (ctx.context): session, secret, authCookies, password.hash()/verify(), adapter, internalAdapter, generateId(), tables, baseURL.


    Plugins

    Import from dedicated paths for tree-shaking:

    import { twoFactor } from "better-auth/plugins/two-factor"
    

    NOT from "better-auth/plugins".

    Popular plugins: twoFactor, organization, passkey, magicLink, emailOtp, username, phoneNumber, admin, apiKey, bearer, jwt, multiSession, sso, oauthProvider, oidcProvider, openAPI, genericOAuth.

    Client plugins go in createAuthClient({ plugins: [...] }).


    Client

    Import from: better-auth/client (vanilla), better-auth/react, better-auth/vue, better-auth/svelte, better-auth/solid.

    Key methods: signUp.email(), signIn.email(), signIn.social(), signOut(), useSession(), getSession(), revokeSession(), revokeSessions().


    Type Safety

    Infer types: typeof auth.$Infer.Session, typeof auth.$Infer.Session.user.

    For separate client/server projects: createAuthClient<typeof auth>().


    Common Gotchas

    1. Model vs table name - Config uses ORM model name, not DB table name
    2. Plugin schema - Re-run CLI after adding plugins
    3. Secondary storage - Sessions go there by default, not DB
    4. Cookie cache - Custom session fields NOT cached, always re-fetched
    5. Stateless mode - No DB = session in cookie only, logout on cache expiry
    6. Change email flow - Sends to current email first, then new email
    7. Drizzle: db not initialized - drizzleAdapter(db, ...) requires a db instance from drizzle(). See create-auth skill for setup examples (node-postgres, postgres.js, Neon).
    8. Drizzle: missing drizzle.config.ts - drizzle-kit commands require a drizzle.config.ts pointing to the generated schema file and DB credentials.

    Resources

    • Docs
    • Options Reference
    • LLMs.txt
    • GitHub
    • Init Options Source

    Требования и возможности

    Источник пакета
    https://github.com/better-auth/skills/tree/17dfe3a1da1c3982de723098ba1015d67f35694c/better-auth/best-practices

    Файлы версии

    ПутьРазмерSHA256
    SKILL.md74096d41db1678dbda3a...

    Частые вопросы

    Как установить Better Auth Best Practices?
    Используйте команду npx skills add better-auth/skills --skill better-auth-best-practices или скачайте ZIP-архив.
    Можно ли скачать Better Auth Best Practices бесплатно?
    Да, опубликованную версию можно скачать из маркетплейса бесплатно.

    Похожие инструменты

    Смотреть все
    React DoctorUse when finishing a feature, fixing a bug, before committing React code, or when the user types `/doctor`, asks to scan, triage, or clean up React diagnostics. Covers lint, accessibility, bundle size, architecture. Includes a regression check and a full local-triage workflow that fetches the canonical playbook.Argent Android Emulator SetupSet up and connect to an Android emulator using argent MCP tools. Use when starting a new session on Android, booting an emulator, getting a device serial, or before any UI interaction task.Fireworks Tech GraphCreate technical diagrams such as software architecture, data flow, flowcharts, sequence diagrams, C4 reviews, cloud deployments, event streams, observability investigations, agent/memory systems, UML, ER, network topology, timelines, and technical concept maps, then export SVG, PNG, focused semantic SVG-to-GIF motion, or offline interactive HTML. Treat direct requests such as "Generate a GIF", "生成 GIF", or "制作 GIF" as motion requests, and use this skill when the user asks to visualize a system or engineering concept. Do not use for photos, raster artwork, or quantitative data charts.
    Комментарии

    Войдите, чтобы оставить комментарий.

    Комментариев пока нет.

    Установить скилл

    Добавьте инструмент одной командой или скачайте проверенный архив версии.

    npx skills add better-auth/skills --skill better-auth-best-practices
    Скачать ZIP
    Версия
    1.0.0+17dfe3a1da1c
    Автор
    Владимир Ломтев
    Репозиторий
    better-auth/skills
    GitHub: better-auth/skills
    Modern Web GuidanceSearch tool for modern web development best practices. MANDATORY: Execute FIRST for all HTML/CSS and clientside JS tasks. Do NOT skip — web APIs evolve rapidly and training weights contain obsolete patterns.