How to use this reference
Model consuming a grant as one indivisible state transition, including across service replicas and storage adapters. A successful read must not itself authorize issuance. Maintainer release 1.6.11 adds atomic consumption and corroborates the OAuth fix; review adapter guarantees rather than relying on process-local serialization.
Before reading
- OAuth authorization-code and token lifecycle concepts
- Atomic database transitions and concurrent request handling
Context and limits
- Requires an affected OAuth/OIDC provider deployment and a redeemable authorization code; the source does not establish bypass of code possession or PKCE.
- Maintainer-reported behavior, not evidence of production compromise. The advisory covers @better-auth/oauth-provider 1.6.0 before 1.6.11 and specified legacy plugins; an effective external atomic single-use control changes exposure.
- The source credits chdanielmueller as reporter; no advisory author byline is established.
- This is a substantive maintainer disclosure corroborated by release notes, not an independently peer-reviewed paper or an award-backed record.
Sources and provenance
- @better-auth/oauth-provider: Parallel requests can reuse one authorization code Better Auth · reviewed 2026-10-03
- Release v1.6.11 Better Auth · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.