MFA Step-Up
POST /api/v1/auth/login/mfa
Rate limit: 5 requests per minute per IP (shared with login). Body: {mfa_token, code} or {mfa_token, recovery_code}. On success, sets the session cookies and returns the user. Challenge deletion and TOTP-timestep advancement or recovery-code removal are one transaction and must succeed before any session is issued. Concurrent reuse therefore has one winner; persistence failure fails closed. The account's is_active is re-checked at this step, so an account disabled during the step-up window gets no session. 401 on a wrong/expired/replayed code or an invalid/expired/consumed mfa_token; 429 when the account is locked.