Conversation
- Add MFA policy enforcement for admin users with config toggle - Integrate django-allauth for headless authentication with JWT tokens - TOTP, WebAuthn, and recovery code MFA methods - Create MFA setup allowed paths for first enrollment - Update frontend authentication flow with MFA-aware login component - Enable passkey-based login with MFA as optional verification layer
|
Created image with name |
- Prevent admin users from bypassing MFA through legacy login endpoint during SSO handoff
|
Created image with name |
|
Created image with name |
- Fix `_session_for_token()` to support both raw session token and encrypted AllAuth JWT claim
|
Created image with name |
- Add SE translation (machine translation)
|
Created image with name |
|
Created image with name |
|
|
Created image with name |



Closes #45.
Uses Django-allauth to add MFA via TOTP, Passkey, and backup codes.
Also accepts legacy session JWTs to minimize deployment disruption.