generated from boboko/starter
Fix: Updates on Middlewares, User hiding fields
This commit is contained in:
@@ -35,6 +35,15 @@
|
||||
// has set URL::defaults(['locale' => …]), so route() needs no locale arg.
|
||||
$middleware->redirectGuestsTo(fn() => route('login'));
|
||||
$middleware->redirectUsersTo(fn() => route('home'));
|
||||
|
||||
// Core's session registry (Modules\Core\Auth\Services\
|
||||
// UserSessionService) is enforcement-optional by design — see
|
||||
// EnsureSessionNotRevoked's own docblock — and this app never
|
||||
// wired it in. Without this, revokeAllSessions() only flips a DB
|
||||
// flag that nothing checks per-request: a leaked/stolen session
|
||||
// cookie keeps working even after being "revoked". Appended to
|
||||
// `web` (runs after `auth` resolves the user, which it needs).
|
||||
$middleware->appendToGroup('web', \Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked::class);
|
||||
})
|
||||
->withExceptions(function (Exceptions $exceptions): void {
|
||||
//
|
||||
|
||||
Reference in New Issue
Block a user