pub const PENDING_MFA_TTL: Duration;Expand description
How long a half-authenticated session may sit unfinished.
Deliberately not admin.session_ttl_seconds and deliberately not a
configuration key. A pending_mfa row is a password that has been accepted
and nothing more; it should not outlive the tab that created it. Five
minutes is longer than reading a code off a phone and shorter than walking
away from the keyboard – a UI timing constant, not a policy an operator
tunes.
It is also the only per-session bound on code guessing: within it an
attacker holding a correct password gets admin.login_max_attempts tries
from one address, and then the row is gone regardless.