MFA Enroll-at-Login (mandatory MFA, no session yet)
POST /api/v1/auth/login/mfa/enroll — begin TOTP enrollment, authorized by the mfa_token
POST /api/v1/auth/login/mfa/enroll/confirm — confirm the first code, issue the session + recovery codes
Rate limit: 5 requests per minute per IP (shared with login). Both are authorized by the mfa_token from an mfa_enroll_required login — not a session. enroll returns {secret, otpauth_uri, qr_png} (a pending enrollment). enroll/confirm atomically verifies the first timestep, confirms the enrollment, stores the recovery hashes, and consumes the challenge; it issues session cookies only after that transaction succeeds and returns {user, recovery_codes} (shown once). Only local and LDAP accounts may enroll; OIDC/SAML get 400.