Repository navigation
LOTTO v1.24.3 — Auth.js upgrade, zero remaining criticals
LOTTO v1.24.3 completes the security work begun in v1.24.1. Upgrading next-auth to 5.0.0-beta.32 and @auth/pg-adapter to 1.11.3 brings @auth/core to 0.41.3 and clears the last three critical advisories.
Production advisories: 6, none critical — against 16 (3 critical) before v1.24.1.
Upstream now fixes what v1.24.1 patched by hand
@auth/core 0.41.3 makes a non-OK session response yield no session rather than an error object, so existence checks fail closed (GHSA-8fpg-xm3f-6cx3), and applies NFKC email normalization (GHSA-7rqj-j65f-68wh). Those are precisely the two weaknesses v1.24.1 had to mitigate in LOTTO's own code.
Both LOTTO mitigations are retained, not reverted. Each is stricter than its upstream counterpart:
| LOTTO mitigation | Upstream fix | Why it stays |
|---|---|---|
proxy.ts requires a populated session.user |
!!auth now fails closed |
Stricter — an error object with no user is still refused |
| ASCII screen on the raw address | NFKC normalization | Runs first, and rejects confusables that normalize into ASCII |
On the beta channel
The v5 line has been in beta for roughly 1,000 days across 33 releases, with no committed stable date and a cadence that has been lengthening rather than converging. That is not an argument for staying on beta.30 — v4 does not support the App Router, so the real choice was between an older beta carrying three criticals and a current one that fixes them.
next-auth remains pinned exactly, without a caret, enforced by tests/security-nextauth-pin.test.ts.
Also fixed
The nodemailer peer-dependency drift reported during v1.24.1: @auth/core required ^6.8.0 against an installed 7.0.10, producing an ERESOLVE warning on every Vercel build. Both packages now declare ^7.0.7 || ^8.0.5.
Verification
No client code changed. 47 of 48 built chunks are byte-identical to v1.24.2 and total chunk bytes are unchanged; the only difference is inlined package.json metadata carrying the two new version strings. next-auth's client surface (SessionProvider, signIn) is untouched — consistent with beta.31 changing no next-auth source and every @auth/core fix being server-side.
beta.31's stricter email validation was exercised against the live OTP route rather than assumed: well-formed and plus-addressed staff addresses pass validation and the allowlist, unauthorized domains are refused, malformed forms (quoted local parts, doubled @, empty domain) are rejected, and a U+3000 ideographic space is still caught by LOTTO's own ASCII screen.
780 tests, lint, tsc, a production build and the legacy-bundle scan pass. Sign-in confirmed rendering and hydrating on a simulated iPad mini 4 running iPadOS 15.4 with a custom appearance applied.
Still deferred
next 16.0.10 → 16.3.2 spans three minor versions and stays separate so any regression remains attributable. nodemailer 7 → 9 stays held — every advisory is in the SMTP transport path production doesn't use, and 9.x falls outside the newly declared peer range.
Full changelog: v1.24.2...v1.24.3