2FA becomes optional + pluggable: TOTP, a security key, or both, fully deactivatable, recommended not forced. hasTwoFactorEnabled = either factor; onboarding drops the forced-2FA redirect; recovery codes become a modal (drop the dedicated page/route); challenge adapts to whichever factor(s) exist; last-factor removal clears codes. WebAuthn E2E stays domain-deferred. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| plans | ||
| specs | ||