Back to changelog
Product

Dependency refresh, and more settings leave environment variables

Direct dependencies are current, including Next.js 16.3.7, OpenNext Cloudflare 1.20.7, Wrangler 4.144, and Better Auth 1.7.6. The avatar read URL, newsletter signing secret, and Turnstile keys now live in admin runtime settings.

This release brings the template's direct dependencies up to date, removes unused packages, and moves three more settings out of environment variables into the admin runtime settings page.

Dependencies

  • Next.js and @next/third-parties are on 16.3.7. @opennextjs/cloudflare is on 1.20.7. Wrangler is on 4.144. Better Auth is on 1.7.6.
  • The rest of the direct dependencies were updated to their current releases in the same pass.
  • 0001_better_auth_1_7_6.sql matches Better Auth 1.7.6: account.issuer is nullable, and two_factor gains verified, failed_verification_count, and locked_until. Existing databases need pnpm drizzle:migrate.

Cleanup

  • Unused packages were removed from package.json.
  • Unused UI components under src/components/ui were removed.
  • pnpm drizzle:status lists applied and pending migrations. Drizzle scripts load .env with dotenv run -f .env.

Runtime settings

  • The public avatar read URL is no longer NEXT_PUBLIC_AVATARS_PROXY_URL. Set it on the Storage tab. Signed-in clients receive it as avatarsFileProxyUrl on /api/auth/get-session. If the admin field is empty, the app uses AVATARS_FILE_PROXY_URL_FALLBACK in src/config/storage.ts.
  • Newsletter unsubscribe signing has its own Newsletter tab. Leave the secret empty to keep using BETTER_AUTH_SECRET. Saving a new secret invalidates unsubscribe links that were already sent.
  • Cloudflare Turnstile has its own Captcha tab. The forgot-password page reads the site key on the server and passes it into the form. The widget and the server check both stay off until the site key and the secret are saved.
  • NEXT_PUBLIC_AVATARS_PROXY_URL, NEWSLETTER_TOKEN_SECRET, NEXT_PUBLIC_TURNSTILE_SITE_KEY, and CAPTCHA_SECRET_KEY are removed from .env.local.example.