Back to changelog
Product
Dependency refresh, and more settings leave environment variables
Direct dependencies are current, including Next.js 16.3.7, OpenNext Cloudflare 1.20.7, Wrangler 4.144, and Better Auth 1.7.6. The avatar read URL, newsletter signing secret, and Turnstile keys now live in admin runtime settings.
This release brings the template's direct dependencies up to date, removes unused packages, and moves three more settings out of environment variables into the admin runtime settings page.
Dependencies
- Next.js and
@next/third-partiesare on 16.3.7.@opennextjs/cloudflareis on 1.20.7. Wrangler is on 4.144. Better Auth is on 1.7.6. - The rest of the direct dependencies were updated to their current releases in the same pass.
0001_better_auth_1_7_6.sqlmatches Better Auth 1.7.6:account.issueris nullable, andtwo_factorgainsverified,failed_verification_count, andlocked_until. Existing databases needpnpm drizzle:migrate.
Cleanup
- Unused packages were removed from
package.json. - Unused UI components under
src/components/uiwere removed. pnpm drizzle:statuslists applied and pending migrations. Drizzle scripts load.envwithdotenv run -f .env.
Runtime settings
- The public avatar read URL is no longer
NEXT_PUBLIC_AVATARS_PROXY_URL. Set it on the Storage tab. Signed-in clients receive it asavatarsFileProxyUrlon/api/auth/get-session. If the admin field is empty, the app usesAVATARS_FILE_PROXY_URL_FALLBACKinsrc/config/storage.ts. - Newsletter unsubscribe signing has its own Newsletter tab. Leave the secret empty to keep using
BETTER_AUTH_SECRET. Saving a new secret invalidates unsubscribe links that were already sent. - Cloudflare Turnstile has its own Captcha tab. The forgot-password page reads the site key on the server and passes it into the form. The widget and the server check both stay off until the site key and the secret are saved.
NEXT_PUBLIC_AVATARS_PROXY_URL,NEWSLETTER_TOKEN_SECRET,NEXT_PUBLIC_TURNSTILE_SITE_KEY, andCAPTCHA_SECRET_KEYare removed from.env.local.example.