GGScore 2.6.0 — TOTP authenticator + passkeys for cabinet
7/20/2026, 3:50:54 PM
Opt-in MFA for the cabinet: authenticator apps (TOTP) and WebAuthn passkeys. After email, Google, or Telegram identity, complete sign-in with a code or a passkey.
Version 2.6.0
Frontend and API ship the same semver.
What is new
- Opt-in authenticator (TOTP): enable from Cabinet → Profile.
- Passkeys (WebAuthn): add Face ID, Windows Hello, security keys, or password-manager passkeys (KeePassXC, 1Password, Bitwarden, …).
- After email magic link, Google, or Telegram identity succeeds, accounts with TOTP and/or passkeys enter a second step.
- Session cookies are issued only after MFA succeeds (code, recovery code, or passkey).
- Recovery codes are shown once when enabling TOTP; you can regenerate them later.
Why this matters
HttpOnly cookie sessions (2.4.0) protect against XSS token theft. MFA adds a second factor so a stolen magic link or OAuth handoff alone is not enough to open the cabinet.
Sensitive-action step-up MFA and passwordless-only login remain later ideas.
See also the repo CHANGELOG.md.