mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-10 05:41:39 +00:00
Setup returned a fresh secret and recovery codes to any session, and enable flipped otp_enabled without proof of the secret, so a stolen session could enroll its own authenticator and lock the owner out. Setup now lives at /user-protected/setup-2fa behind the same password / OIDC revalidation gate as disable-2fa, and enable requires a live code for the stored secret. The GUI setup window asks for the password (or opens the revalidation popup) first, and sends the code it already collected to enable.