Skip to content

LOTTO v1.24.3 — Auth.js upgrade, zero remaining criticals

Choose a tag to compare

@MattGeiger MattGeiger released this 26 Aug 15:30
· 78 commits to main since this release

LOTTO v1.24.3 completes the security work begun in v1.24.1. Upgrading next-auth to 5.0.0-beta.32 and @auth/pg-adapter to 1.11.3 brings @auth/core to 0.41.3 and clears the last three critical advisories.

Production advisories: 6, none critical — against 16 (3 critical) before v1.24.1.

Upstream now fixes what v1.24.1 patched by hand

@auth/core 0.41.3 makes a non-OK session response yield no session rather than an error object, so existence checks fail closed (GHSA-8fpg-xm3f-6cx3), and applies NFKC email normalization (GHSA-7rqj-j65f-68wh). Those are precisely the two weaknesses v1.24.1 had to mitigate in LOTTO's own code.

Both LOTTO mitigations are retained, not reverted. Each is stricter than its upstream counterpart:

LOTTO mitigation Upstream fix Why it stays
proxy.ts requires a populated session.user !!auth now fails closed Stricter — an error object with no user is still refused
ASCII screen on the raw address NFKC normalization Runs first, and rejects confusables that normalize into ASCII

On the beta channel

The v5 line has been in beta for roughly 1,000 days across 33 releases, with no committed stable date and a cadence that has been lengthening rather than converging. That is not an argument for staying on beta.30 — v4 does not support the App Router, so the real choice was between an older beta carrying three criticals and a current one that fixes them.

next-auth remains pinned exactly, without a caret, enforced by tests/security-nextauth-pin.test.ts.

Also fixed

The nodemailer peer-dependency drift reported during v1.24.1: @auth/core required ^6.8.0 against an installed 7.0.10, producing an ERESOLVE warning on every Vercel build. Both packages now declare ^7.0.7 || ^8.0.5.

Verification

No client code changed. 47 of 48 built chunks are byte-identical to v1.24.2 and total chunk bytes are unchanged; the only difference is inlined package.json metadata carrying the two new version strings. next-auth's client surface (SessionProvider, signIn) is untouched — consistent with beta.31 changing no next-auth source and every @auth/core fix being server-side.

beta.31's stricter email validation was exercised against the live OTP route rather than assumed: well-formed and plus-addressed staff addresses pass validation and the allowlist, unauthorized domains are refused, malformed forms (quoted local parts, doubled @, empty domain) are rejected, and a U+3000 ideographic space is still caught by LOTTO's own ASCII screen.

780 tests, lint, tsc, a production build and the legacy-bundle scan pass. Sign-in confirmed rendering and hydrating on a simulated iPad mini 4 running iPadOS 15.4 with a custom appearance applied.

Still deferred

next 16.0.10 → 16.3.2 spans three minor versions and stays separate so any regression remains attributable. nodemailer 7 → 9 stays held — every advisory is in the SMTP transport path production doesn't use, and 9.x falls outside the newly declared peer range.

Full changelog: v1.24.2...v1.24.3