WebAuthn/YubiKey as an optional login 2nd factor (web-auth/webauthn-lib), gated on domain+HTTPS. TOTP + backup codes stay the required 2FA. Register/use/remove keys in Settings + at the challenge; 2FA reset (UI + CLI) clears keys. Real YubiKey end-to-end is browser-verified on a domain host. See CHANGELOG. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| app.php | ||
| auth.php | ||
| broadcasting.php | ||
| cache.php | ||
| clusev.php | ||
| database.php | ||
| filesystems.php | ||
| logging.php | ||
| mail.php | ||
| queue.php | ||
| reverb.php | ||
| services.php | ||
| session.php | ||
| wire-elements-modal.php | ||