- ReferralController now stores ip_hash (SHA-256) instead of raw IP in session - Cookie excludes IP entirely (only stores provider/model/timestamp) - PlantTreeForAgentReferral uses hashed IPs in tree metadata - Updated test to verify hashed IP storage Raw IPs should not be stored in cookies or persisted unnecessarily. Session-only hashed IP is sufficient for fraud detection. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| config | ||
| src | ||
| stubs | ||
| tests | ||
| composer.json | ||
| phpunit.xml | ||
| TODO.md | ||