Controls
- PASSWORD_DEFAULT password hashing.
- Rate limiting and temporary lockout.
- Session rotation after password and TOTP checks.
- Optional TOTP and one-use recovery codes.
- CSRF protection and security audit events.
Operations
Always use HTTPS. Expose only public to the web and back up config.php and storage regularly.