September 25, 2026
Mandatory two-factor authentication and session timeout controls
- Email-based 2FA added to every login: a 6-digit one-time code is required in addition to password, with a 5-minute expiry and a 5-codes-per-hour per-account send limit to prevent abuse.
- Session hardening: JWTs now carry and enforce an explicit type claim, so a refresh token or a pending-2FA token can never be replayed as a full access token.
- Absolute session limit: sessions now expire after 12 hours regardless of activity.
- Idle timeout: sessions are also terminated server-side after 60 minutes of genuine user inactivity, tracked independently of background polling so it reflects real idle time.