- ReferralController now stores ip_hash (SHA-256) instead of raw IP in session - Cookie excludes IP entirely (only stores provider/model/timestamp) - PlantTreeForAgentReferral uses hashed IPs in tree metadata - Updated test to verify hashed IP storage Raw IPs should not be stored in cookies or persisted unnecessarily. Session-only hashed IP is sufficient for fraud detection. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| core-admin | ||
| core-api | ||
| core-mcp | ||
| core-php | ||