EnsureCustomerActive used session()->invalidate() to sign a suspended or closed customer out. In shared-host mode the console and the portal keep their login key in one session, so invalidate() (flush() + migrate(true)) silently signed out an operator elsewhere in that same browser too. Same fix as the console's own /logout route: regenerate() gets a fresh session id without flushing attributes belonging to another guard. |
||
|---|---|---|
| .. | ||
| Controllers | ||
| Middleware | ||