Feat: Adding hashes for otp codes
This commit is contained in:
@@ -23,7 +23,7 @@ use Modules\Core\Customer\Exceptions\InvalidEmailChangeCodeException;
|
||||
* hash of the code, expiry, wrong-guess count) lives on the user's own
|
||||
* row (see the migration adding pending_email/pending_email_code_hash/
|
||||
* pending_email_expires_at/pending_email_attempts) — the same convention
|
||||
* Auth\Services\UserOtpService's otp_code/otp_expires_at/otp_attempts
|
||||
* Auth\Services\UserOtpService's otp_code_hash/otp_expires_at/otp_attempts
|
||||
* already use — rather than the session, since a code arrives by email
|
||||
* and is often opened on a different device/session than the one that
|
||||
* requested it; a session-scoped pending change couldn't be confirmed
|
||||
|
||||
Reference in New Issue
Block a user