ADR-0004: Use Better Auth database sessions
PRODUCT SOURCE / 32ecfb2View original ↗
Status: Accepted Date: 2026-10-06
Context
Registration, credentials, cookie handling and session revocation should use a maintained authentication library.
Decision
Use Better Auth with the Prisma adapter and email/password login. Keep memberships and permission policy in the domain boundary. Enable origin/CSRF checks explicitly and disable cookie session caching.
Alternatives considered
Handwritten authentication increases password and session risk. A proprietary hosted identity service would make basic self-hosting dependent on outside infrastructure.
Consequences
Sessions are revocable against PostgreSQL. HTTPS origins use Secure cookies. Registration is open; verification, recovery mail, invitations and shared rate limiting remain separate work.