Summary
The application has no MFA/2FA option. Given the email-only login limiter and the sensitivity of the data, a second factor would meaningfully raise the bar — especially for accounts with elevated permissions.
Remediation
Add optional TOTP (and/or WebAuthn) 2FA, at least for admin/elevated accounts.
Severity
Info.
Source: internal security review (commit 0360e87, 2026-07-21).
Summary
The application has no MFA/2FA option. Given the email-only login limiter and the sensitivity of the data, a second factor would meaningfully raise the bar — especially for accounts with elevated permissions.
Remediation
Add optional TOTP (and/or WebAuthn) 2FA, at least for admin/elevated accounts.
Severity
Info.
Source: internal security review (commit
0360e87, 2026-07-21).