ce76046a29
- consolidate API ownership and remove dead vendor code - add Stripe billing, learning paths, and public CV hardening - add migration, recovery, security, audit, and browser gates
486 B
486 B
2fa
Local accounts can enable TOTP from Profile settings. Setup requires the current password, verification of the first six-digit code, and acknowledgement of one-time recovery codes. Users can disable TOTP, regenerate recovery codes, list/revoke trusted devices, and revoke every trusted device.
Challenge attempts are rate-limited. Recovery codes are hashed at rest and shown only when generated.
See docs/security/two-factor-authentication.md for the detailed trust model.