Files
PaperClipAI/server/package.json
T
dependabot[bot] 2e8521e57c chore(deps): bump better-auth from 1.7.0 to 1.7.2 (#12565)
Bumps
[better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth)
from 1.7.0 to 1.7.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/better-auth/better-auth/releases">better-auth's
releases</a>.</em></p>
<blockquote>
<h2>v1.7.2</h2>
<h2><code>better-auth</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed permanent user bans to clear expiration dates from previous
temporary bans. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10823">#10823</a>)</li>
<li>Fixed client types with more plugins being assignable to types
declaring fewer plugins. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10907">#10907</a>)</li>
<li>Added warnings for invalid signed session data in the cookie cache.
(<a
href="https://redirect.github.com/better-auth/better-auth/pull/10934">#10934</a>)</li>
<li>Fixed disabled MyISAM indexes from satisfying migration index
checks. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10877">#10877</a>)</li>
<li>Fixed programmatic migrations on Cloudflare D1 while preserving
existing-index validation. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10875">#10875</a>)</li>
<li>Allowed <code>~</code> in relative callback URLs validated by
trusted-origin checks. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10041">#10041</a>)</li>
<li>Improved validation of relative callback and redirect URLs with
paths, queries, and fragments. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10979">#10979</a>)</li>
<li>Allowed same-origin form submissions with <code>Referrer-Policy:
no-referrer</code> while continuing to reject untrusted origins. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10959">#10959</a>)</li>
<li>Improved <code>getTestInstance</code> performance with a faster
default password hasher. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10879">#10879</a>)</li>
<li>Standardized built-in placeholder emails to the namespaced
<code>{identifier}@{namespace}.placeholder.invalid</code> format. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10982">#10982</a>)</li>
</ul>
<p>For detailed changes, see <a
href="https://github.com/better-auth/better-auth/blob/c50200bfc716cf43f5c29a2dd5766f6485c46aa1/packages/better-auth/CHANGELOG.md"><code>CHANGELOG</code></a></p>
<h2><code>@better-auth/core</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed async context loss in Cloudflare Workers bundles with multiple
runtime conditions. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10855">#10855</a>)</li>
<li>Fixed auth request logs to respect the configured logger, log level,
and disabled setting. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10939">#10939</a>)</li>
<li>Improved validation of relative callback and redirect URLs with
paths, queries, and fragments. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10979">#10979</a>)</li>
<li>Standardized built-in placeholder emails to the namespaced
<code>{identifier}@{namespace}.placeholder.invalid</code> format. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10982">#10982</a>)</li>
<li>Added synchronous and optional access to the current auth endpoint
context. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10938">#10938</a>)</li>
</ul>
<p>For detailed changes, see <a
href="https://github.com/better-auth/better-auth/blob/c50200bfc716cf43f5c29a2dd5766f6485c46aa1/packages/core/CHANGELOG.md"><code>CHANGELOG</code></a></p>
<h2><code>@better-auth/oauth-provider</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed Client ID Metadata Document registration when clients share at
least one supported grant with the server. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/11010">#11010</a>)</li>
<li>Improved validation of relative callback and redirect URLs with
paths, queries, and fragments. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10979">#10979</a>)</li>
<li>Fixed relative redirect URLs containing fragments. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10983">#10983</a>)</li>
</ul>
<p>For detailed changes, see <a
href="https://github.com/better-auth/better-auth/blob/c50200bfc716cf43f5c29a2dd5766f6485c46aa1/packages/oauth-provider/CHANGELOG.md"><code>CHANGELOG</code></a></p>
<h2><code>@better-auth/drizzle-adapter</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed one-to-one Drizzle relations when <code>usePlural</code> is
enabled. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10941">#10941</a>)</li>
<li>Added validation for missing Drizzle schema fields in compound
<code>where</code> clauses. (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10859">#10859</a>)</li>
</ul>
<p>For detailed changes, see <a
href="https://github.com/better-auth/better-auth/blob/c50200bfc716cf43f5c29a2dd5766f6485c46aa1/packages/drizzle-adapter/CHANGELOG.md"><code>CHANGELOG</code></a></p>
<h2><code>@better-auth/kysely-adapter</code></h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md">better-auth's
changelog</a>.</em></p>
<blockquote>
<h2>1.7.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10875">#10875</a>
<a
href="https://github.com/better-auth/better-auth/commit/d5d889bfd8708601d8f27526d35fb9568450b51e"><code>d5d889b</code></a>
Thanks <a href="https://github.com/bytaesu"><code>@​bytaesu</code></a>!
- Fix programmatic migrations failing on Cloudflare D1 while preserving
existing-index validation across supported databases.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10982">#10982</a>
<a
href="https://github.com/better-auth/better-auth/commit/b4ad5a110ca4f2e043c0f23a8e5f87e0b31c3fc6"><code>b4ad5a1</code></a>
Thanks <a href="https://github.com/bytaesu"><code>@​bytaesu</code></a>!
- Built-in placeholder emails now consistently use the namespaced
<code>{identifier}@{namespace}.placeholder.invalid</code> format.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10934">#10934</a>
<a
href="https://github.com/better-auth/better-auth/commit/c7a5c1a7ed65a5169e98bd347df91b16bb394692"><code>c7a5c1a</code></a>
Thanks <a href="https://github.com/bytaesu"><code>@​bytaesu</code></a>!
- Cookie-cache reads now warn when signed session data is invalid
instead of silently appearing as a signed-out session.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10879">#10879</a>
<a
href="https://github.com/better-auth/better-auth/commit/78f0c3922c273de29bd0b77213fbc37cc3b5917e"><code>78f0c39</code></a>
Thanks <a
href="https://github.com/apps/starslingdev"><code>@​starslingdev</code></a>!
- Test suites using <code>getTestInstance</code> now run faster because
the shared fixture avoids production password-hashing costs by default.
Custom <code>emailAndPassword.password</code> implementations continue
to take precedence.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10823">#10823</a>
<a
href="https://github.com/better-auth/better-auth/commit/ce8a3ab5442fdd388f3b1346b71292cf617c3146"><code>ce8a3ab</code></a>
Thanks <a href="https://github.com/sosyz"><code>@​sosyz</code></a>! -
Ensure permanently banning a user clears any expiration from a previous
temporary ban.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10907">#10907</a>
<a
href="https://github.com/better-auth/better-auth/commit/a021eafaf235dd08c0835d91ee714aca24c4605e"><code>a021eaf</code></a>
Thanks <a href="https://github.com/heliohm"><code>@​heliohm</code></a>!
- A client created with more plugins is again assignable to a client
type declaring fewer plugins, as in 1.6.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10959">#10959</a>
<a
href="https://github.com/better-auth/better-auth/commit/c8dcfa57e11e22325dbb2a0cc1af6775f41b1315"><code>c8dcfa5</code></a>
Thanks <a href="https://github.com/bytaesu"><code>@​bytaesu</code></a>!
- Allow same-origin form submissions from pages using
<code>Referrer-Policy: no-referrer</code> while continuing to reject
untrusted request origins.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10979">#10979</a>
<a
href="https://github.com/better-auth/better-auth/commit/fced1a5d360c14e6358f88dedc9014ff862873f1"><code>fced1a5</code></a>
Thanks <a href="https://github.com/bytaesu"><code>@​bytaesu</code></a>!
- Allow relative callback and redirect URLs to use standard path, query,
and fragment syntax while preserving open-redirect protections.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10041">#10041</a>
<a
href="https://github.com/better-auth/better-auth/commit/f6891a2d2d4f7ead7e9b13e65316a0cbd88f3fe4"><code>f6891a2</code></a>
Thanks <a
href="https://github.com/GautamBytes"><code>@​GautamBytes</code></a>! -
Allow <code>~</code> in relative callback URLs validated by trusted
origin checks.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10877">#10877</a>
<a
href="https://github.com/better-auth/better-auth/commit/649818a2969594e58147a2cc08157812ea0b75ef"><code>649818a</code></a>
Thanks <a href="https://github.com/bytaesu"><code>@​bytaesu</code></a>!
- Prevent disabled MyISAM indexes from satisfying migration index
checks.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/better-auth/better-auth/commit/557e19bfad0f2d2842903ddb1e768a0506aceaea"><code>557e19b</code></a>,
<a
href="https://github.com/better-auth/better-auth/commit/64da15b0b1ca078d80f115ee0a5bd9ad4ca4d64e"><code>64da15b</code></a>,
<a
href="https://github.com/better-auth/better-auth/commit/d5d889bfd8708601d8f27526d35fb9568450b51e"><code>d5d889b</code></a>,
<a
href="https://github.com/better-auth/better-auth/commit/b4ad5a110ca4f2e043c0f23a8e5f87e0b31c3fc6"><code>b4ad5a1</code></a>,
<a
href="https://github.com/better-auth/better-auth/commit/ea77118d4e00f69ddffed4fb42dfedc08594ea9e"><code>ea77118</code></a>,
<a
href="https://github.com/better-auth/better-auth/commit/5aea9f77284dfb7b187e8e7bec0cebd4b8834123"><code>5aea9f7</code></a>,
<a
href="https://github.com/better-auth/better-auth/commit/fced1a5d360c14e6358f88dedc9014ff862873f1"><code>fced1a5</code></a>,
<a
href="https://github.com/better-auth/better-auth/commit/e1d40116e2b6a797372ac82b9feea39f57285632"><code>e1d4011</code></a>]:</p>
<ul>
<li><code>@​better-auth/core</code><a
href="https://github.com/1"><code>@​1</code></a>.7.2</li>
<li><code>@​better-auth/kysely-adapter</code><a
href="https://github.com/1"><code>@​1</code></a>.7.2</li>
<li><code>@​better-auth/drizzle-adapter</code><a
href="https://github.com/1"><code>@​1</code></a>.7.2</li>
<li><code>@​better-auth/memory-adapter</code><a
href="https://github.com/1"><code>@​1</code></a>.7.2</li>
<li><code>@​better-auth/mongo-adapter</code><a
href="https://github.com/1"><code>@​1</code></a>.7.2</li>
<li><code>@​better-auth/prisma-adapter</code><a
href="https://github.com/1"><code>@​1</code></a>.7.2</li>
<li><code>@​better-auth/telemetry</code><a
href="https://github.com/1"><code>@​1</code></a>.7.2</li>
</ul>
</li>
</ul>
<h2>1.7.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10863">#10863</a>
<a
href="https://github.com/better-auth/better-auth/commit/845bbd1de682ab87e03ce925f85087da81249a4e"><code>845bbd1</code></a>
Thanks <a
href="https://github.com/gustavovalverde"><code>@​gustavovalverde</code></a>!
- <code>auth migrate</code> no longer attempts to add a required column
with no default value to a table that already has rows. It stops with an
error naming the column and the backfill to run first. Previously the
generated statement failed on SQLite, Postgres, and SQL Server; on MySQL
it filled the new column with an empty string for every existing row and
reported success. If <code>auth migrate</code> already ran against a
MySQL database on 1.7, run the check in the upgrade guide's account
identity section.</p>
<p><code>getMigrations</code> throws the new
<code>UnsafeMigrationError</code> (exported from
<code>better-auth/db/migration</code>) for this refusal, so callers can
distinguish it from other migration errors such as an index-definition
conflict.</p>
<p><code>auth generate</code> still emits the statements for external
migration tooling, with a comment banner naming any column that needs a
manual backfill first.</p>
<p>A required field whose database column is still nullable logs a
warning instead of blocking the migration.</p>
<p>A CLI command that fails now prints its error and exits with a
non-zero code instead of an unhandled promise rejection.</p>
</li>
<li>
<p>Updated dependencies []:</p>
<ul>
<li><code>@​better-auth/core</code><a
href="https://github.com/1"><code>@​1</code></a>.7.1</li>
<li><code>@​better-auth/drizzle-adapter</code><a
href="https://github.com/1"><code>@​1</code></a>.7.1</li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/better-auth/better-auth/commit/ba12fcdfa774ca27d417079dbac0b1b5894ccaf2"><code>ba12fcd</code></a>
chore: release v1.7.2 (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10870">#10870</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/79904f0be8fadb939743e90a61bbfee207c152e1"><code>79904f0</code></a>
fix(origin-check): support fragments in relative redirect URLs (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10983">#10983</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/c8dcfa57e11e22325dbb2a0cc1af6775f41b1315"><code>c8dcfa5</code></a>
fix(origin-check): validate null origins using fetch metadata (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10959">#10959</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/e1d40116e2b6a797372ac82b9feea39f57285632"><code>e1d4011</code></a>
fix(logger): respect configured logger in auth request context (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10939">#10939</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/557e19bfad0f2d2842903ddb1e768a0506aceaea"><code>557e19b</code></a>
refactor(context): clarify auth endpoint context access (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10938">#10938</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/b4ad5a110ca4f2e043c0f23a8e5f87e0b31c3fc6"><code>b4ad5a1</code></a>
refactor: centralize placeholder email generation (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10982">#10982</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/fced1a5d360c14e6358f88dedc9014ff862873f1"><code>fced1a5</code></a>
fix(origin-check): improve relative callback URL validation (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10979">#10979</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/f6891a2d2d4f7ead7e9b13e65316a0cbd88f3fe4"><code>f6891a2</code></a>
fix(origin-check): allow tilde in relative callback URLs (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10041">#10041</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/ce8a3ab5442fdd388f3b1346b71292cf617c3146"><code>ce8a3ab</code></a>
fix(admin): ban without a duration should clear the previous expiration
(<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10823">#10823</a>)</li>
<li><a
href="https://github.com/better-auth/better-auth/commit/a021eafaf235dd08c0835d91ee714aca24c4605e"><code>a021eaf</code></a>
fix(client): a client with more plugins fits a narrower client type
again (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/1">#1</a>...</li>
<li>Additional commits viewable in <a
href="https://github.com/better-auth/better-auth/commits/v1.7.2/packages/better-auth">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-03 09:46:13 -07:00

148 lines
4.8 KiB
JSON

{
"name": "@paperclipai/server",
"version": "0.3.1",
"license": "MIT",
"homepage": "https://github.com/paperclipai/paperclip",
"bugs": {
"url": "https://github.com/paperclipai/paperclip/issues"
},
"repository": {
"type": "git",
"url": "https://github.com/paperclipai/paperclip",
"directory": "server"
},
"type": "module",
"exports": {
".": "./src/index.ts"
},
"publishConfig": {
"access": "public",
"exports": {
".": {
"types": "./dist/index.d.ts",
"import": "./dist/index.js"
}
},
"main": "./dist/index.js",
"types": "./dist/index.d.ts"
},
"files": [
"dist",
"ui-dist",
"skills"
],
"scripts": {
"dev": "tsx src/index.ts",
"dev:watch": "cross-env PAPERCLIP_MIGRATION_PROMPT=never PAPERCLIP_MIGRATION_AUTO_APPLY=true tsx ./scripts/dev-watch.ts",
"prepare:ui-dist": "bash ../scripts/prepare-server-ui-dist.sh",
"build": "pnpm run prepare:runner-vendor && tsc && mkdir -p dist/onboarding-assets dist/built-ins dist/services/scripts dist/vendor/paperclip-runner && cp -R src/onboarding-assets/. dist/onboarding-assets/ && cp -R src/built-ins/. dist/built-ins/ && cp -R src/services/scripts/. dist/services/scripts/ && cp -R ../packages/paperclip-runner/dist/. dist/vendor/paperclip-runner/ && node scripts/write-build-stamp.mjs",
"prepack": "pnpm run prepare:ui-dist && pnpm run build",
"postpack": "rm -rf ui-dist",
"clean": "rm -rf dist",
"start": "node dist/index.js",
"prepare:runner-vendor": "pnpm --filter @paperclipai/paperclip-runner build",
"typecheck": "pnpm run prepare:runner-vendor && pnpm --filter @paperclipai/plugin-sdk ensure-build-deps && tsc --noEmit"
},
"dependencies": {
"@aws-sdk/client-s3": "^3.1120.0",
"@opentelemetry/api": "^1.9.0",
"@paperclipai/adapter-claude-local": "workspace:*",
"@paperclipai/adapter-codex-local": "workspace:*",
"@paperclipai/adapter-cursor-cloud": "workspace:*",
"@paperclipai/adapter-cursor-local": "workspace:*",
"@paperclipai/adapter-gemini-local": "workspace:*",
"@paperclipai/adapter-grok-local": "workspace:*",
"@paperclipai/adapter-kimi-local": "workspace:*",
"@paperclipai/adapter-openclaw-gateway": "workspace:*",
"@paperclipai/adapter-opencode-local": "workspace:*",
"@paperclipai/adapter-pi-local": "workspace:*",
"@paperclipai/adapter-utils": "workspace:*",
"@paperclipai/db": "workspace:*",
"@paperclipai/hermes-paperclip-adapter": "workspace:*",
"@paperclipai/plugin-sdk": "workspace:*",
"@paperclipai/shared": "workspace:*",
"@paperclipai/skills-catalog": "workspace:*",
"@vercel/connect": "0.6.1",
"acpx": "0.13.1",
"ajv": "^8.20.0",
"ajv-formats": "^3.0.1",
"better-auth": "1.7.2",
"chokidar": "^5.0.0",
"detect-port": "^2.1.0",
"dompurify": "^3.4.13",
"dotenv": "^17.4.2",
"drizzle-orm": "^0.45.2",
"embedded-postgres": "^18.1.0-beta.16",
"express": "^5.1.0",
"jsdom": "^30.0.1",
"multer": "^2.2.0",
"open": "^11.0.1",
"pino": "^10.0.0",
"pino-http": "^11.0.0",
"pino-pretty": "^13.1.3",
"sharp": "^0.35.3",
"ssh2": "^1.17.0",
"ws": "^8.21.3",
"zod": "^4.4.3"
},
"bundleDependencies": [
"acpx"
],
"devDependencies": {
"@paperclipai/paperclip-runner": "workspace:*",
"@types/express": "^5.0.0",
"@types/express-serve-static-core": "^5.1.3",
"@types/jsdom": "^30.0.0",
"@types/multer": "^2.2.0",
"@types/node": "^24.0.0",
"@types/sharp": "^0.32.0",
"@types/supertest": "^7.2.1",
"@types/ws": "^8.18.1",
"cross-env": "^10.1.0",
"supertest": "^7.0.0",
"tsx": "^4.23.12",
"typescript": "^7.0.2",
"vite": "^8.2.2",
"vitest": "^4.1.10"
},
"peerDependencies": {
"@opentelemetry/auto-instrumentations-node": "0.79.0",
"@opentelemetry/exporter-trace-otlp-grpc": "0.221.0",
"@opentelemetry/exporter-trace-otlp-http": "0.221.0",
"@opentelemetry/exporter-trace-otlp-proto": "0.221.0",
"@opentelemetry/resources": "2.10.0",
"@opentelemetry/sdk-node": "0.221.0",
"@opentelemetry/semantic-conventions": "1.43.0",
"@sentry/node": "10.71.0"
},
"peerDependenciesMeta": {
"@opentelemetry/auto-instrumentations-node": {
"optional": true
},
"@opentelemetry/exporter-trace-otlp-grpc": {
"optional": true
},
"@opentelemetry/exporter-trace-otlp-http": {
"optional": true
},
"@opentelemetry/exporter-trace-otlp-proto": {
"optional": true
},
"@opentelemetry/resources": {
"optional": true
},
"@opentelemetry/sdk-node": {
"optional": true
},
"@opentelemetry/semantic-conventions": {
"optional": true
},
"@sentry/node": {
"optional": true
}
},
"engines": {
"node": ">=24.11.0"
}
}