generated from boboko/starter
Fix: Updates on Middlewares, User hiding fields
This commit is contained in:
+16
-1
@@ -29,12 +29,26 @@ class User extends Authenticatable implements LunarUserInterface
|
||||
];
|
||||
|
||||
/**
|
||||
* The attributes that should be hidden for serialization.
|
||||
* The attributes that should be hidden for serialization. Every
|
||||
* secret-bearing OTP/pending-email-change field is included here,
|
||||
* not just remember_token — otp_code_hash and
|
||||
* pending_email_code_hash are bcrypt hashes rather than the raw
|
||||
* codes (see Modules\Core\Auth\Services\UserOtpService and
|
||||
* Modules\Core\Customer\Services\CustomerEmailChangeService), but a
|
||||
* hash is still not something any serialized response should leak,
|
||||
* and otp_attempts/pending_email_attempts reveal in-progress guess
|
||||
* counts.
|
||||
*
|
||||
* @var list<string>
|
||||
*/
|
||||
protected $hidden = [
|
||||
'remember_token',
|
||||
'otp_code_hash',
|
||||
'otp_expires_at',
|
||||
'otp_attempts',
|
||||
'pending_email_code_hash',
|
||||
'pending_email_expires_at',
|
||||
'pending_email_attempts',
|
||||
];
|
||||
|
||||
/**
|
||||
@@ -46,6 +60,7 @@ protected function casts(): array
|
||||
{
|
||||
return [
|
||||
'email_verified_at' => 'datetime',
|
||||
'otp_code_hash' => 'hashed',
|
||||
];
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user