Two hardening features completed in parallel (each with its own spec + tests), sharing call sites (TwoFactorSetup, WebauthnKeys, routes) so committed together: - ConfirmAction token hardening: destructive confirm flows now carry a server-issued, single-use, signed token (App\Support\Confirm\ConfirmToken) instead of trusting a client-mutable event/params/auditTarget. Every #[On] apply handler consumes + validates the token (forged/replayed/direct-bypass calls no-op). Server-scoped per action; closes the codebase-wide confirm-bypass + audit-forgery vector across Security, Sessions, Users, WebauthnKeys, Servers\Show, Services, System, Files. - Backup-code airtight reveal: codes are revealed via a transient channel, not a persisted Livewire property, so a captured/replayed snapshot can't re-render them; the recovery download is grant-gated. Full suite green (162). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| components | ||
| errors | ||
| layouts | ||
| livewire | ||
| partials | ||
| vendor/wire-elements-modal | ||