Skip to content

fix(session): use adapter-generated dual-store IDs - #136

Draft
salasebas wants to merge 2 commits into
mainfrom
salasebas/parity-redis-18-session-id-generation
Draft

fix(session): use adapter-generated dual-store IDs#136
salasebas wants to merge 2 commits into
mainfrom
salasebas/parity-redis-18-session-id-generation

Conversation

@salasebas

Copy link
Copy Markdown
Owner

Summary

  • ignore caller-supplied session IDs when creating new sessions
  • generate IDs internally only when secondary storage is the sole session store
  • let the primary database adapter generate dual-store IDs, then expose the same record through the return value, cache, hooks, and active-session index

Upstream parity

Validated against Better Auth v1.6.23 at 9dfceee14021fc15a2fb93023f39635f25b0b5ba.

Pinned upstream createSession removes override.id and generates a session ID only for secondaryStorage && !storeSessionInDatabase. With database storage enabled, createWithHooks lets the primary adapter create the row before the secondary callback caches the adapter-returned record.

Dependency

This branch is intentionally stacked on draft PR #125 (69e4c606), which already owns the dual-write ordering and adapter-returned-record caching changes. This PR adds one scoped commit, 8686df1e, for ID generation and its regression coverage; it does not reimplement #125. Rebase this branch after #125 lands before merging.

Regression coverage

The new observable Memory-adapter regression uses serial database IDs and a caller-supplied ID, then verifies:

  • the caller ID is ignored and the adapter-generated ID is returned and persisted
  • the cached session and create-after hook observe the same adapter-generated ID
  • the secondary active-session index contains the session token

Checks

  • focused internal adapter tests: 39 runs, 158 assertions, 0 failures
  • full Better Auth core suite: 1545 runs, 9429 assertions, 0 failures
  • full repository StandardRB: clean
  • git diff --check: clean
  • fresh blind pinned-v1.6.23 diff-only review: Approve

Create database-backed sessions before publishing their secondary-storage entries. Cache and return the adapter-created record so database normalization is preserved.
Ignore caller-supplied session IDs and let the primary adapter assign IDs when sessions are stored in both the database and secondary storage.
@vercel

vercel Bot commented Aug 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
better-auth Ignored Ignored Aug 20, 2026 10:06pm

@github-actions github-actions Bot added the core label Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant