- credential_id can exceed the unique-index key length; store it in TEXT and enforce uniqueness on an auto-derived sha256 hash column (lookups use the hash). - Disabling 2FA now also deletes the user's security keys + backup codes, so re-enrolling starts clean and old factors never silently revive. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| AuditEvent.php | ||
| Server.php | ||
| Setting.php | ||
| SshCredential.php | ||
| User.php | ||
| WebauthnCredential.php | ||