Spec 1 of 2 for the 2FA challenge rework. Moves the backup (recovery) code off the combined challenge screen into a dedicated /two-factor-challenge/backup route + view, behind a 'Backup-Code verwenden' button; the main screen shows only the primary factor. A key-only user without secure context (http + bare IP) is redirected straight to the backup view. Shared rate-limit/login logic is extracted into a CompletesTwoFactorChallenge trait so both views hit one bucket set. IP-vs-domain factor routing is already correct (WebauthnService::available) and unchanged. Spec 2 (auth-failure -> fail2ban hard IP ban) is out of scope here. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| superpowers | ||
| install-update-design.md | ||
| session-handoff.md | ||
| v1-ui-review.md | ||