Does this code have any flaws in terms of Better Auth best practices?
I'm using Next JS, Drizzle and next-safe-auth
1 Reply
I assume anyone could in theory call that server function if they know the endpoint and pass any user id with a role they want for the user