I have reworked the two-factor authentication page to require a confirmation and it is now live on .social. Given all the other fixes I am considering tagging a v1.1.1 release right now
@Gargron how will that effect current 2FA users once it's implimented on an instance? I.e for someone locked out? Guessing it only applies to new 2FA users on an natance once that's installed?