Commit fd44775
authored
Support HMAC password hash format from Laravel 12.45.0+ (#578)
Laravel Framework v12.45.0 (PR laravel/framework#58107) changed how
password hashes are stored in sessions - they're now stored as HMACs
instead of raw hashes for improved security.
This updates Sanctum's AuthenticateSession middleware to:
1. Use hashPasswordForCookie() when storing the password hash (if available)
2. Add validatePasswordHash() that tries HMAC format first, falls back to
raw hash comparison for backward compatibility
This ensures compatibility when both $middleware->authenticateSessions()
and Sanctum stateful auth are enabled together.
Fixes #5771 parent fe4633e commit fd44775
1 file changed
+31
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
50 | 50 | | |
51 | 51 | | |
52 | 52 | | |
53 | | - | |
54 | | - | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
55 | 58 | | |
56 | 59 | | |
57 | 60 | | |
| |||
94 | 97 | | |
95 | 98 | | |
96 | 99 | | |
| 100 | + | |
| 101 | + | |
97 | 102 | | |
98 | | - | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
99 | 106 | | |
100 | 107 | | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
101 | 129 | | |
0 commit comments