Security hardening: signed federation manifests, rate limiting, MFA guards, and enumeration fixes.
- Signed federation manifests and remoteEntry pins verified by the shell.
- Per-IP rate limiting on unauthenticated endpoints.
- MFA enrollment and disable require the current password; MFA enumeration signal removed from login.
- Registration enumeration prevented; MFA verify CSRF-protected; NIR upload capped client-side.