4 High findings caught during development — fixed and re-verified:
- H1M1-F012FA-disable bypass via /2fa/setupFIXED
- H2M1-F02No brute-force lockout on the TOTP second factorFIXED
- H3M4-F01OWASP headers missing from 429 responsesFIXED
- H4M6-F01entrypoint.sh missing from the Docker imageFIXED
Finding flaws during development is not a failure: it is the point of the method. Hiding them would be.
| Severity | Remaining findings |
|---|---|
| Critical | 0 |
| High | 0 |
| Medium | 4 |
| Low | 5 |
| Info | 2 |