Bump version to 0.27.5
This commit is contained in:
@@ -4,6 +4,26 @@ All notable changes to this project will be documented in this file.
|
||||
|
||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
||||
|
||||
## [0.27.5] - 2026-09-30
|
||||
### Security
|
||||
- OTP codes (both customer login via `UserOtpService` and staff login via
|
||||
`OtpService`) were stored in plaintext in `users.otp_code`/`lunar_staff.otp_code`
|
||||
and compared against the plaintext guess. The staff path was additionally
|
||||
weaker — a loose `!=` comparison with no timing-attack protection and no
|
||||
attempt-limiting at all. Both columns are replaced with `otp_code_hash`
|
||||
(bcrypt, via a `'hashed'` cast — same convention `password` already uses),
|
||||
compared with `Hash::check()`. The cache-backed pending-signup OTP path
|
||||
(an email with no `User` row yet) is hashed the same way. No backfill —
|
||||
any code mid-flight when this deploys is invalidated (codes expire in 10
|
||||
minutes regardless, so the practical impact is limited to a re-request).
|
||||
- `App\Models\User`'s (3dealer) and `Modules\Core\Auth\Models\Staff`'s
|
||||
`$hidden` arrays didn't list `otp_code`/`otp_expires_at`/`otp_attempts`/
|
||||
`pending_email_code_hash`/etc. at all — any serialization of either model
|
||||
(an API response, `Auth::user()` returned somewhere) would have leaked
|
||||
those fields, including the (now-hashed, previously plaintext) OTP code
|
||||
itself. `Staff` additionally never overrode Lunar's own base `$hidden`, so
|
||||
it also lacked `password`/`remember_token` protection until now.
|
||||
|
||||
## [0.27.4] - 2026-09-29
|
||||
### Added
|
||||
- Generic `.bbk-notice` / `.bbk-notice--info` message box and a
|
||||
|
||||
Reference in New Issue
Block a user