2f37f0501fbb3d80bad2dd55bbec1f14d6a9e18b
Better-Auth v1.5.6 stores raw tokens in sessions.token, not SHA-256 hashes. The session cookie is signed (rawToken.hmacSignature), so strip the HMAC signature suffix before querying the DB. Fixes 401 errors on all data endpoints caused by the incorrect hash. Co-Authored-By: Paperclip <noreply@paperclip.ing>
Description
Languages
Python
99.3%
Dockerfile
0.5%
Mako
0.2%