*/ use HasFactory, Notifiable; /** * The attributes that are mass assignable. * * @var list */ protected $fillable = [ 'name', 'email', ]; /** * The attributes that should be hidden for serialization. Every * secret-bearing OTP/pending-email-change field is included here, * not just remember_token — otp_code_hash and * pending_email_code_hash are bcrypt hashes rather than the raw * codes (see Modules\Core\Auth\Services\UserOtpService and * Modules\Core\Customer\Services\CustomerEmailChangeService), but a * hash is still not something any serialized response should leak, * and otp_attempts/pending_email_attempts reveal in-progress guess * counts. * * @var list */ protected $hidden = [ 'remember_token', 'otp_code_hash', 'otp_expires_at', 'otp_attempts', 'pending_email_code_hash', 'pending_email_expires_at', 'pending_email_attempts', ]; /** * Get the attributes that should be cast. * * @return array */ protected function casts(): array { return [ 'email_verified_at' => 'datetime', 'otp_code_hash' => 'hashed', ]; } }