Member Login
Accounts are created only after a purchase is recorded. No public signup.
2FA Direction
Use password login first, then add optional TOTP as the real MFA method.
- TOTP is stronger than email PIN if the mailbox is compromised.
- Email PIN is acceptable for recovery or fallback, not ideal as primary MFA.
- Public registration stays off. Accounts are created after purchase or by staff.