Address Codex security review: - ForgotPassword + clusev:reset-admin now rotate remember_token, so a stolen remember-me cookie cannot survive a password reset (the email-token path already did this). - useRecoveryCode reads/checks/removes under a row lock (DB transaction + lockForUpdate), so two concurrent requests can't both spend the same one-time code (replay). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| .gitkeep | ||
| ForgotPassword.php | ||
| Login.php | ||
| PasswordChange.php | ||
| RecoveryCodes.php | ||
| ResetPassword.php | ||
| TwoFactorChallenge.php | ||
| TwoFactorSetup.php | ||