Repository navigation
Commit f904e61
fix(client):
* fix(client): getActiveMember addresses the organisation the caller names
`organizations.getActiveMember(organizationId)` built
`GET /organization/get-active-member?organizationId=...`, and better-auth
1.7.2's handler for that path reads `session.session.activeOrganizationId`
and never looks at `ctx.query`. The query string was dead on arrival: a
permission check for organisation B while A was active answered A's row,
with a 200 and no diagnostic.
The method now asks the question honestly, in two requests: `GET
/get-session` for the caller's own user id, then `GET
/organization/list-members?organizationId=...&filterField=userId&filterValue=<self>&limit=1`,
unwrapping the one-entry page. `list-members` reads `ctx.query.organizationId`
and its rows carry the identical shape, so the signature and the declared
return type are unchanged.
The `get-active-member` ledger row is rebooked `server-only`: no SDK method
builds that URL any more, and `sdk` means "expressed by the SDK".
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QE8qk46e5CHJxyQEUjbf8
* chore(changeset): declare the getActiveMember addressing fix
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QE8qk46e5CHJxyQEUjbf8
* chore(plugin-auth): keep the tracker id out of the ledger note string
check:doc-authoring — a runtime string reaches authors and generated
surfaces, none of whom can resolve `#NNNN`; git history keeps the anchor.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QE8qk46e5CHJxyQEUjbf8
* chore(changeset): grade @objectstack/client minor, not patch
Check Changeset: a PR declaring clause-② yes may not grade a package it
grew `patch`. The maintainer's ruling of 2026-09-04 (decision batch #35)
holds that a change to a published package's public surface takes at
least `minor`; a commit type may raise a bump, never lower it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QE8qk46e5CHJxyQEUjbf8
* fix(client): refuse a falsy organizationId in getActiveMember
better-auth resolves `ctx.query.organizationId || session.activeOrganizationId`
on `list-members`, so an empty string fell through to session state and came
back 200 carrying the ACTIVE organisation's row — the same silent substitution
this method was fixed to stop making, surviving on one argument while the
JSDoc says "the GIVEN organisation".
The SDK now refuses it before the wire, in the shape `environment(id)` already
uses. The pinned case asserts nothing reaches the wire at all, and drives
`list-members` with an empty id through the same double to show the fallback
the refusal prevents is real in the fixture, not assumed.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018rzQyhLGC5iVs11V3TzRs5
* docs(plugin-auth): the ledger notes name every SDK method that builds each URL
`get-active-member` was rebooked `server-only` because a truth ledger must not
ship a false statement; by the same standard two rows were left incomplete.
`get-session` named only `auth.me` and `auth.refreshToken`, and `list-members`
named only `organizations.listMembers`, while `organizations.getActiveMember`
now builds both. The `invite-member` row is the precedent for exactly this.
Also restores a by-name anchor for the method: after the rebooking it was
pinned by URL through `client-url-conformance.test.ts` but by no `client:` or
`note:` string anywhere in the ledger.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018rzQyhLGC5iVs11V3TzRs5
* chore(changeset): carry the breaking-ness and its ADR-0087 disposition
The changeset now carries the `**BREAKING**` banner, one before/after pair per
moved input, and an ADR-0087 `not-required (no-migration-prescription)`
disposition. The level stays `minor`: under the launch-window convention the
level cannot carry breaking-ness, so the banner and the disposition are the
carriers.
Four inputs move, each stated as the response it drew before and the response
it draws now: an id other than the active organisation; an organisation the
caller is not a member of; any id on a session with no active organisation;
and an empty id, which this round refuses client-side.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018rzQyhLGC5iVs11V3TzRs5
* docs(client): correct the pre-fix answer stated for a non-member of the named organisation
The changeset bullet and the `getActiveMember` docblock both said a caller who
was not a member of the NAMED organisation used to draw `400 MEMBER_NOT_FOUND`.
better-auth 1.7.2's `get-active-member` handler reads
`session.session.activeOrganizationId` and never `ctx.query`, so the named
organisation was never consulted at all: such a caller drew a 200 carrying the
ACTIVE organisation's row, and `MEMBER_NOT_FOUND` fired only when the caller
had no row in the active organisation either. The PR's own ablation agrees —
case ⑤ went red as "expected undefined to be 'YOU_ARE_NOT_A_MEMBER…'", i.e.
the old shape resolved rather than throwing.
Both sentences now state that before-state. The `after` (403) was already
right, and the neighbouring bullets already stated it for every other input.
Prose only: the changeset body ships as CHANGELOG text and the docblock is a
comment. No executable line, no test and no behaviour moves.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Js5kTpTtxieBjPyScgxJ3
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: huangyiirene <huangyi@hotoa.com>organizations.getActiveMember addresses the organisation the caller NAMES, not whichever one the session has active (#16761)1 parent 91f65c4 commit f904e61
4 files changed
Lines changed: 416 additions & 13 deletions
File tree
- .changeset
- packages
- client/src
- plugins/plugin-auth/src
Lines changed: 33 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3426 | 3426 | | |
3427 | 3427 | | |
3428 | 3428 | | |
3429 | | - | |
| 3429 | + | |
3430 | 3430 | | |
3431 | 3431 | | |
3432 | 3432 | | |
3433 | | - | |
| 3433 | + | |
3434 | 3434 | | |
3435 | | - | |
3436 | | - | |
3437 | | - | |
3438 | | - | |
3439 | | - | |
3440 | | - | |
| 3435 | + | |
| 3436 | + | |
| 3437 | + | |
| 3438 | + | |
| 3439 | + | |
| 3440 | + | |
| 3441 | + | |
| 3442 | + | |
| 3443 | + | |
| 3444 | + | |
| 3445 | + | |
| 3446 | + | |
| 3447 | + | |
| 3448 | + | |
| 3449 | + | |
| 3450 | + | |
| 3451 | + | |
| 3452 | + | |
| 3453 | + | |
| 3454 | + | |
| 3455 | + | |
| 3456 | + | |
| 3457 | + | |
| 3458 | + | |
| 3459 | + | |
| 3460 | + | |
| 3461 | + | |
| 3462 | + | |
| 3463 | + | |
| 3464 | + | |
| 3465 | + | |
| 3466 | + | |
| 3467 | + | |
| 3468 | + | |
| 3469 | + | |
| 3470 | + | |
| 3471 | + | |
| 3472 | + | |
| 3473 | + | |
| 3474 | + | |
| 3475 | + | |
| 3476 | + | |
| 3477 | + | |
| 3478 | + | |
| 3479 | + | |
3441 | 3480 | | |
3442 | 3481 | | |
| 3482 | + | |
| 3483 | + | |
| 3484 | + | |
| 3485 | + | |
| 3486 | + | |
| 3487 | + | |
3443 | 3488 | | |
| 3489 | + | |
| 3490 | + | |
| 3491 | + | |
| 3492 | + | |
| 3493 | + | |
| 3494 | + | |
| 3495 | + | |
| 3496 | + | |
| 3497 | + | |
| 3498 | + | |
| 3499 | + | |
3444 | 3500 | | |
3445 | | - | |
| 3501 | + | |
| 3502 | + | |
| 3503 | + | |
3446 | 3504 | | |
3447 | | - | |
| 3505 | + | |
| 3506 | + | |
| 3507 | + | |
| 3508 | + | |
| 3509 | + | |
| 3510 | + | |
| 3511 | + | |
| 3512 | + | |
| 3513 | + | |
| 3514 | + | |
| 3515 | + | |
3448 | 3516 | | |
3449 | 3517 | | |
3450 | 3518 | | |
| |||
0 commit comments