Skip to content
Site updates

GGScore 2.6.0 — TOTP authenticator + passkeys for cabinet

7/20/2026, 3:50:54 PM

Opt-in MFA for the cabinet: authenticator apps (TOTP) and WebAuthn passkeys. After email, Google, or Telegram identity, complete sign-in with a code or a passkey.

Version 2.6.0

Frontend and API ship the same semver.

What is new

  • Opt-in authenticator (TOTP): enable from Cabinet → Profile.
  • Passkeys (WebAuthn): add Face ID, Windows Hello, security keys, or password-manager passkeys (KeePassXC, 1Password, Bitwarden, …).
  • After email magic link, Google, or Telegram identity succeeds, accounts with TOTP and/or passkeys enter a second step.
  • Session cookies are issued only after MFA succeeds (code, recovery code, or passkey).
  • Recovery codes are shown once when enabling TOTP; you can regenerate them later.

Why this matters

HttpOnly cookie sessions (2.4.0) protect against XSS token theft. MFA adds a second factor so a stolen magic link or OAuth handoff alone is not enough to open the cabinet.

Sensitive-action step-up MFA and passwordless-only login remain later ideas.

See also the repo CHANGELOG.md.

GGScore 2.6.0 changelog: TOTP + passkeys | GGScore