xarmian
0dc3f0b61f
fix: address Codex review findings for TOTP 2FA
- Reject API token auth on 2FA enrollment endpoints (setup, verify,
disable) to prevent account takeover via leaked tokens (P1)
- Re-read 2FA challenge secret after persisting to handle multi-instance
startup race on fresh databases (P2)
2026-04-08 21:36:48 +00:00
..
2026-04-08 21:36:48 +00:00
2026-04-05 10:26:00 -04:00
2026-04-08 18:00:43 +00:00
2026-04-05 10:26:00 -04:00
2026-04-06 02:22:23 +00:00
2026-04-05 10:26:00 -04:00
2026-04-08 20:30:39 +00:00
2026-04-05 10:26:00 -04:00
2026-04-05 10:26:00 -04:00
2026-03-26 01:52:36 +00:00
2026-04-07 14:55:23 -04:00
2026-04-07 14:55:23 -04:00
2026-04-07 01:13:44 +00:00
2026-04-06 01:23:34 +00:00
2026-04-07 01:13:44 +00:00
2026-04-02 10:46:09 -04:00
2026-04-07 09:52:31 -04:00
2026-04-05 10:26:00 -04:00
2026-04-07 14:55:23 -04:00
2026-04-07 14:55:23 -04:00
2026-04-08 13:58:58 -04:00
2026-03-26 01:52:36 +00:00
2026-04-05 10:26:00 -04:00
2026-04-05 10:26:00 -04:00
2026-04-05 10:26:00 -04:00
2026-04-05 10:26:00 -04:00
2026-04-08 18:50:08 +00:00
2026-04-05 10:26:00 -04:00
2026-04-05 10:26:00 -04:00
2026-04-05 10:26:00 -04:00
2026-04-05 15:02:54 +00:00
2026-04-07 14:55:23 -04:00
2026-04-08 21:36:48 +00:00
2026-04-05 10:26:00 -04:00
2026-04-05 10:26:00 -04:00
2026-04-05 15:02:54 +00:00
2026-04-06 01:13:40 +00:00
2026-04-06 01:13:40 +00:00
2026-04-05 10:26:00 -04:00
2026-04-08 20:30:39 +00:00
2026-04-05 10:26:00 -04:00
2026-04-08 13:58:58 -04:00
2026-04-02 16:10:09 -04:00
2026-04-08 21:36:48 +00:00
2026-04-08 18:50:08 +00:00
2026-04-08 20:30:39 +00:00