Configuration
godevauth.Config mirrors better-auth’s options:
EmailAndPassword- enable/disable, min/max length, verification requirements, reset delivery, customPasswordHasher.EmailVerification- delivery and required-before-sign-in rules, plus an optional interstitialConfirmationPageso mail-security scanners (which fire GETs) cannot consume the one-time link before the user clicks.Session-ExpiresIn,UpdateAge,FreshAge, cookie cache.User- additional fields, change-email, delete-user flows. Changing a verified address is two-step: the approval link goes to the current verified address, and the new address must then verify itself before it gains recovery rights.Account- linking rules, trusted providers, OAuth token encryption at rest.Advanced- cookie prefix, cross-subdomain cookies, SameSite, proxy trust, custom ID generation, CSRF exemptions, auto-migration.TrustedOrigins- CSRF origin allow-list; wildcard entries (https://*.example.com) match strict subdomains only.RateLimit- windows, per-path rules, pluggable store for multi-instance deployments.Events- the audit hook.PreviousSecrets- secret rotation.Hooks/DatabaseHooks- request and persistence interception.
Rate-limit rules in RateLimit.CustomRules may be keyed by route
pattern ("/reset-password/:token") as well as literal path - buckets
are keyed by the pattern, so a parameterised route is limited as one
endpoint, not one bucket per token value.
Custom user fields
Section titled “Custom user fields”Extra columns are declared on the config and are not client-writable unless you say so - the difference between a profile field and a privilege:
User: godevauth.UserConfig{ AdditionalFields: []storage.Field{ {Name: "displayName", Type: storage.FieldString, Input: true}, // user may set it {Name: "plan", Type: storage.FieldString}, // server-controlled },},Fields contributed by plugins (role, banned, twoFactorEnabled, …)
are never writable from a request body, whatever Input says.
For the full field-by-field reference, see the pkg.go.dev documentation.