Skip to content

Add Microsoft login and remembered login methods - #4

Merged
nedtwigg merged 2 commits into
mainfrom
microsoft-last-login
Sep 11, 2026
Merged

Add Microsoft login and remembered login methods#4
nedtwigg merged 2 commits into
mainfrom
microsoft-last-login

Conversation

@nedtwigg

Copy link
Copy Markdown
Member

Add Microsoft sign-in to the Better Auth recipe, with signed OIDC verification, PKCE, nonce checks, and tenant/object identity keys. Only verified Microsoft email assertions can join an existing email account; consumers that allow missing email can create provider-only accounts.

Add opt-in last-login-method cookies using Better Auth's plugin. Successful sign-ins remember the method for 30 days; logout preserves the hint, failed attempts do not change it, and the cookie carries no email or authentication authority.

Validation: pnpm check (154 tests), pnpm packages:verify, including invalid Microsoft tokens, tenant separation, same-email linking in both orders, missing email, and successful/failed login cookie behavior.

@nedtwigg
nedtwigg merged commit 415db94 into main Sep 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant