generated from boboko/starter
Fix: Updates on Middlewares, User hiding fields
This commit is contained in:
+16
-1
@@ -29,12 +29,26 @@ class User extends Authenticatable implements LunarUserInterface
|
|||||||
];
|
];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* The attributes that should be hidden for serialization.
|
* The attributes that should be hidden for serialization. Every
|
||||||
|
* secret-bearing OTP/pending-email-change field is included here,
|
||||||
|
* not just remember_token — otp_code_hash and
|
||||||
|
* pending_email_code_hash are bcrypt hashes rather than the raw
|
||||||
|
* codes (see Modules\Core\Auth\Services\UserOtpService and
|
||||||
|
* Modules\Core\Customer\Services\CustomerEmailChangeService), but a
|
||||||
|
* hash is still not something any serialized response should leak,
|
||||||
|
* and otp_attempts/pending_email_attempts reveal in-progress guess
|
||||||
|
* counts.
|
||||||
*
|
*
|
||||||
* @var list<string>
|
* @var list<string>
|
||||||
*/
|
*/
|
||||||
protected $hidden = [
|
protected $hidden = [
|
||||||
'remember_token',
|
'remember_token',
|
||||||
|
'otp_code_hash',
|
||||||
|
'otp_expires_at',
|
||||||
|
'otp_attempts',
|
||||||
|
'pending_email_code_hash',
|
||||||
|
'pending_email_expires_at',
|
||||||
|
'pending_email_attempts',
|
||||||
];
|
];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -46,6 +60,7 @@ protected function casts(): array
|
|||||||
{
|
{
|
||||||
return [
|
return [
|
||||||
'email_verified_at' => 'datetime',
|
'email_verified_at' => 'datetime',
|
||||||
|
'otp_code_hash' => 'hashed',
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -35,6 +35,15 @@
|
|||||||
// has set URL::defaults(['locale' => …]), so route() needs no locale arg.
|
// has set URL::defaults(['locale' => …]), so route() needs no locale arg.
|
||||||
$middleware->redirectGuestsTo(fn() => route('login'));
|
$middleware->redirectGuestsTo(fn() => route('login'));
|
||||||
$middleware->redirectUsersTo(fn() => route('home'));
|
$middleware->redirectUsersTo(fn() => route('home'));
|
||||||
|
|
||||||
|
// Core's session registry (Modules\Core\Auth\Services\
|
||||||
|
// UserSessionService) is enforcement-optional by design — see
|
||||||
|
// EnsureSessionNotRevoked's own docblock — and this app never
|
||||||
|
// wired it in. Without this, revokeAllSessions() only flips a DB
|
||||||
|
// flag that nothing checks per-request: a leaked/stolen session
|
||||||
|
// cookie keeps working even after being "revoked". Appended to
|
||||||
|
// `web` (runs after `auth` resolves the user, which it needs).
|
||||||
|
$middleware->appendToGroup('web', \Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked::class);
|
||||||
})
|
})
|
||||||
->withExceptions(function (Exceptions $exceptions): void {
|
->withExceptions(function (Exceptions $exceptions): void {
|
||||||
//
|
//
|
||||||
|
|||||||
Reference in New Issue
Block a user