- ZeroTolerantCounterChecker only tolerates a 0 counter when the stored counter is also 0; a 0 after a non-zero counter is a rollback and is rejected. - clusev:reset-admin --disable-2fa now also deletes the user's security keys, so a compromised key can't revive when 2FA is re-enabled. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Feature | ||
| Unit | ||
| TestCase.php | ||