Skip to content

Commit 6b0f00e

Browse files
committed
docs(plugin-auth): state the linking precondition at class level
Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6
1 parent 3532f09 commit 6b0f00e

1 file changed

Lines changed: 4 additions & 5 deletions

File tree

‎packages/plugins/plugin-auth/src/implicit-account-linking.ts‎

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,11 +15,10 @@
1515
*
1616
* 1. **Every provider meets the library's standard local-ownership
1717
* requirement** before an implicit link: the existing local row must be
18-
* `emailVerified: true`. Without it, anyone who can register an
19-
* UNVERIFIED local row at a victim's address (open self-registration)
20-
* gets the victim's external identity linked into the row they control —
21-
* and the link then flips that row to verified. better-auth names this
22-
* exact case as the reason `requireLocalEmailVerified` defaults to `true`.
18+
* `emailVerified: true` — the account-ownership precondition better-auth
19+
* documents as the reason `requireLocalEmailVerified` defaults to `true`.
20+
* A refused link writes nothing, so it also never flips the local row to
21+
* verified.
2322
* 2. **The platform's own cloud identity provider keeps its documented
2423
* exception** ({@link PLATFORM_IDP_PROVIDER_ID}). The cloud is the IdP
2524
* for every environment, and the environment's owner row is seeded by the

0 commit comments

Comments
 (0)