- Do export, admin, and “internal” MFA-gated routes use the same object checks as the public API?
- If you temporarily disable MFA during an outage, what still enforces authorization?
Keep MFA for account takeover resistance. Put authorization next to every sensitive read and write. A green MFA checkmark is still not a permission check.
Top comments (0)