Bump version to 0.27.5
This commit is contained in:
@@ -4,6 +4,26 @@ All notable changes to this project will be documented in this file.
|
|||||||
|
|
||||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
||||||
|
|
||||||
|
## [0.27.5] - 2026-09-30
|
||||||
|
### Security
|
||||||
|
- OTP codes (both customer login via `UserOtpService` and staff login via
|
||||||
|
`OtpService`) were stored in plaintext in `users.otp_code`/`lunar_staff.otp_code`
|
||||||
|
and compared against the plaintext guess. The staff path was additionally
|
||||||
|
weaker — a loose `!=` comparison with no timing-attack protection and no
|
||||||
|
attempt-limiting at all. Both columns are replaced with `otp_code_hash`
|
||||||
|
(bcrypt, via a `'hashed'` cast — same convention `password` already uses),
|
||||||
|
compared with `Hash::check()`. The cache-backed pending-signup OTP path
|
||||||
|
(an email with no `User` row yet) is hashed the same way. No backfill —
|
||||||
|
any code mid-flight when this deploys is invalidated (codes expire in 10
|
||||||
|
minutes regardless, so the practical impact is limited to a re-request).
|
||||||
|
- `App\Models\User`'s (3dealer) and `Modules\Core\Auth\Models\Staff`'s
|
||||||
|
`$hidden` arrays didn't list `otp_code`/`otp_expires_at`/`otp_attempts`/
|
||||||
|
`pending_email_code_hash`/etc. at all — any serialization of either model
|
||||||
|
(an API response, `Auth::user()` returned somewhere) would have leaked
|
||||||
|
those fields, including the (now-hashed, previously plaintext) OTP code
|
||||||
|
itself. `Staff` additionally never overrode Lunar's own base `$hidden`, so
|
||||||
|
it also lacked `password`/`remember_token` protection until now.
|
||||||
|
|
||||||
## [0.27.4] - 2026-09-29
|
## [0.27.4] - 2026-09-29
|
||||||
### Added
|
### Added
|
||||||
- Generic `.bbk-notice` / `.bbk-notice--info` message box and a
|
- Generic `.bbk-notice` / `.bbk-notice--info` message box and a
|
||||||
|
|||||||
+1
-1
@@ -2,7 +2,7 @@
|
|||||||
"name": "boboko/core",
|
"name": "boboko/core",
|
||||||
"description": "Core module — authentication and shared panel behaviour",
|
"description": "Core module — authentication and shared panel behaviour",
|
||||||
"type": "library",
|
"type": "library",
|
||||||
"version": "0.27.4",
|
"version": "0.27.5",
|
||||||
"autoload": {
|
"autoload": {
|
||||||
"psr-4": {
|
"psr-4": {
|
||||||
"Modules\\Core\\": "src/"
|
"Modules\\Core\\": "src/"
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "@boboko/core",
|
"name": "@boboko/core",
|
||||||
"version": "0.27.4",
|
"version": "0.27.5",
|
||||||
"private": true,
|
"private": true,
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.",
|
"description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.",
|
||||||
|
|||||||
Reference in New Issue
Block a user