- Swap the strict counter checker for a zero-tolerant one so platform authenticators / synced passkeys (which always report counter 0) can assert, while non-zero counters still must strictly increase (clone detection). - Guard registration (options + register) and the UI on hasTwoFactorEnabled, so a key is never created against a disabled/reset second factor. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Audit | ||
| Auth | ||
| Concerns | ||
| Files | ||
| Modals | ||
| Servers | ||
| Services | ||
| Settings | ||
| System | ||
| Versions | ||
| Dashboard.php | ||
| ServerSwitcher.php | ||