From 425510fb161e2138bca9d15b1785206a1344fd63 Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Wed, 30 Sep 2026 11:34:14 +0300 Subject: [PATCH] Fix: Updates on Middlewares, User hiding fields --- app/Models/User.php | 17 ++++++++++++++++- bootstrap/app.php | 9 +++++++++ 2 files changed, 25 insertions(+), 1 deletion(-) diff --git a/app/Models/User.php b/app/Models/User.php index f2d1d11..ed41d58 100644 --- a/app/Models/User.php +++ b/app/Models/User.php @@ -29,12 +29,26 @@ class User extends Authenticatable implements LunarUserInterface ]; /** - * The attributes that should be hidden for serialization. + * The attributes that should be hidden for serialization. Every + * secret-bearing OTP/pending-email-change field is included here, + * not just remember_token — otp_code_hash and + * pending_email_code_hash are bcrypt hashes rather than the raw + * codes (see Modules\Core\Auth\Services\UserOtpService and + * Modules\Core\Customer\Services\CustomerEmailChangeService), but a + * hash is still not something any serialized response should leak, + * and otp_attempts/pending_email_attempts reveal in-progress guess + * counts. * * @var list */ protected $hidden = [ 'remember_token', + 'otp_code_hash', + 'otp_expires_at', + 'otp_attempts', + 'pending_email_code_hash', + 'pending_email_expires_at', + 'pending_email_attempts', ]; /** @@ -46,6 +60,7 @@ protected function casts(): array { return [ 'email_verified_at' => 'datetime', + 'otp_code_hash' => 'hashed', ]; } } diff --git a/bootstrap/app.php b/bootstrap/app.php index 93c0d3e..0190c1b 100644 --- a/bootstrap/app.php +++ b/bootstrap/app.php @@ -35,6 +35,15 @@ // has set URL::defaults(['locale' => …]), so route() needs no locale arg. $middleware->redirectGuestsTo(fn() => route('login')); $middleware->redirectUsersTo(fn() => route('home')); + + // Core's session registry (Modules\Core\Auth\Services\ + // UserSessionService) is enforcement-optional by design — see + // EnsureSessionNotRevoked's own docblock — and this app never + // wired it in. Without this, revokeAllSessions() only flips a DB + // flag that nothing checks per-request: a leaked/stolen session + // cookie keeps working even after being "revoked". Appended to + // `web` (runs after `auth` resolves the user, which it needs). + $middleware->appendToGroup('web', \Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked::class); }) ->withExceptions(function (Exceptions $exceptions): void { //