News

Laravel Remember Me Changes

Published

An old Laravel security vulnerability was brought back to life today and the issue reported was fixed 7 months ago and is not an issue currently. You can see the change here to confirm the strict equality check.

This did bring up some unrelated issues with the remember me functionality and it will require you to add a new column to your “users” table. These changes should be out this afternoon and be sure and read the release notes.

On the topic of security, never have full dumping of error messages and stack traces turned on in production!

And another good change coming:

As of today, you will now be forced to configure your local environment in order to receive full error messages.

Eric L. Barnes photo

Eric is the creator of Laravel News and has been covering Laravel since 2012.

Filed in

Sponsored

laravelcloud logo
Laravel Cloud

Easily create and manage your servers and deploy your Laravel applications in seconds.

Visit Laravel Cloud

The latest

View all →
CPX: The Composer Package Executor for PHP image

CPX: The Composer Package Executor for PHP

Read article
Laravel AI SDK Adds Human-in-the-Loop Tool Approval image

Laravel AI SDK Adds Human-in-the-Loop Tool Approval

Read article
Pest 5 Released With Test Impact Analysis, Agent Verification, and Evals image

Pest 5 Released With Test Impact Analysis, Agent Verification, and Evals

Read article
Queue-SQL: Run Mass Deletes and Updates Across Parallel Queue Jobs image

Queue-SQL: Run Mass Deletes and Updates Across Parallel Queue Jobs

Read article
Blade Formatting in Laravel Pint image

Blade Formatting in Laravel Pint

Read article
Inertia DevTools Is Now on the Chrome Web Store image

Inertia DevTools Is Now on the Chrome Web Store

Read article