Sub-Task #243
Updated by Bricklou about 1 month ago
Extend the MFA step of login to support signing in with a registered security key.
Behavior:
- If the user has exactly one MFA method enrolled, that method is used directly (as today)
- If the user has more than one MFA method enrolled (e.g. TOTP + security key), they can pick which one to use
- Choosing security key prompts the browser/OS ceremony; on success, login completes
- Handles and clearly messages: user cancels the prompt, browser/device doesn't support security keys, no matching key, ceremony fails or times out — with an option to switch to another enrolled method
- "Cancel" returns to the method choice (or to the start of login), consistent with existing MFA cancel behavior