962ba26c7c
Record TOTP (RFC 6238) as a deferred hardening idea for the now public-facing Web dashboard: second factor on the single-admin login, with CLI-only password reset and a CLI TOTP reset/recovery path that works even if the recovery codes are lost (no lock-out dead end). Not M2.5, not scheduled — parked under a new Future Ideas section.