Session authentication, password controls and TOTP
The owner application uses Laravel session authentication and CSRF protection. New passwords require upper- and lowercase letters, a number and a special character, and changing your password signs out your other sessions. Two-factor sign-in works with an authenticator app or an email code, and switching it off requires you to confirm your identity again.
- Authenticated web sessions
- CSRF checks on state changes
- Optional two-factor sign-in with recovery codes







