diff --git a/app/Models/User.php b/app/Models/User.php index f2d1d11..fdb20a9 100644 --- a/app/Models/User.php +++ b/app/Models/User.php @@ -35,6 +35,10 @@ class User extends Authenticatable implements LunarUserInterface */ protected $hidden = [ 'remember_token', + 'otp_code', + 'otp_expires_at', + 'otp_attempts', + 'pending_email_code_hash', ]; /** diff --git a/bootstrap/app.php b/bootstrap/app.php index 2957643..d1d413a 100644 --- a/bootstrap/app.php +++ b/bootstrap/app.php @@ -23,6 +23,19 @@ // has set URL::defaults(['locale' => …]), so route() needs no locale arg. $middleware->redirectGuestsTo(fn () => route('login')); $middleware->redirectUsersTo(fn () => route('home')); + + // In production, the host's reverse proxy talks to the nginx container + // (bound to 127.0.0.1 only), so without this every visitor has the + // proxy's IP: the per-IP `throttle` limits on login become one shared + // bucket for the whole site. '*' trusts only the direct hop. + $middleware->trustProxies(at: '*'); + + // Enforces core's session registry: a session revoked via + // UserSessionService is logged out on its next request. Core leaves + // registering this to the app. + $middleware->web(append: [ + \Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked::class, + ]); }) ->withExceptions(function (Exceptions $exceptions): void { // diff --git a/docker/nginx/prod.conf b/docker/nginx/prod.conf index dea05a2..df275ee 100644 --- a/docker/nginx/prod.conf +++ b/docker/nginx/prod.conf @@ -1,5 +1,3 @@ -fastcgi_cache_path /tmp/fcgi_cache levels=1:2 keys_zone=app_cache:10m max_size=256m inactive=10m use_temp_path=off; - upstream php_fpm { server app:9000; keepalive 16; @@ -19,12 +17,9 @@ server { open_file_cache_min_uses 2; open_file_cache_errors on; - # --- FastCGI cache bypass rules --- - set $skip_cache 0; - - if ($request_method = POST) { set $skip_cache 1; } - if ($request_uri ~* "^/(boboko|up)") { set $skip_cache 1; } - if ($query_string) { set $skip_cache 1; } + # No FastCGI page cache: every Laravel response is per-visitor (session + # cookie, CSRF token, cart, login state), so a shared cache keyed on the + # URL replays one visitor's page and session cookie to everyone else. # Vite build assets — content-hashed filenames, safe to cache forever location /build/ { @@ -73,14 +68,6 @@ server { fastcgi_buffers 16 16k; fastcgi_buffer_size 32k; fastcgi_keep_conn on; - - fastcgi_cache app_cache; - fastcgi_cache_key "$scheme$request_method$host$request_uri"; - fastcgi_cache_valid 200 10m; - fastcgi_cache_bypass $skip_cache; - fastcgi_no_cache $skip_cache; - fastcgi_ignore_headers Cache-Control Expires Set-Cookie; - add_header X-Cache-Status $upstream_cache_status; } location /stoic/ {