Update: 2026-07-30 02:27:45
This commit is contained in:
@@ -44,6 +44,13 @@ final class AuthMiddleware
|
||||
exit;
|
||||
}
|
||||
|
||||
// Defence in depth for mobile requests: prove the caller also holds the
|
||||
// per-device secret, so a stolen bearer token on its own is not enough.
|
||||
// Controlled by HMAC_ENFORCE in .env - see HmacMiddleware.
|
||||
if (($decoded['source'] ?? null) === 'mobile') {
|
||||
HmacMiddleware::verify($decoded);
|
||||
}
|
||||
|
||||
return $decoded;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user