authenticationHigh SeverityResolved
5 min
Authentication Incident: OAuth State Mismatch & Session Reliability
Investigation and resolution of cross-origin OAuth state verification failures, cookie scoping mismatches, and session lifecycle boundaries across Next.js and Express.
Impact: Users attempting social sign-in via Google and GitHub experienced state mismatch rejections. Cross-origin session cookies failed to persist across client redirects, resulting in 401s on protected dashboard routes.
#OAuth#Better Auth#Cookies#Next.js+3 more
Read Report