Sloth-ninja closes an MFA gap in firm-template reversions
A firm-wide template rollback now gets the same extra identity check as other destructive admin actions.
Sloth-ninja found one exception in the product's admin safeguards: an enrolled administrator could reverse a shared firm template without completing two-factor confirmation. That action can change access across a firm, so the exception mattered.
The rollback now pauses for a time-based one-time-password check when the administrator has enrolled in MFA, then completes the original action after verification. Teams that have not adopted MFA are not newly forced into it. The interface also keeps the rollback and retry in one flow, so an approved step-up does not require a second click or leave the template list in an odd state.
Spotted something wrong? Or know the PR text has fresher detail than the writeup above?