ADR-0005: Login-Required and MFA Enforcement¶
- Status: Accepted
Context¶
OpenSESA handles governance and assurance data requiring stricter access posture.
Decision¶
Enforce login globally and apply MFA requirements via middleware-based controls.
Consequences¶
- stronger baseline security posture
- auth flow changes require regression testing across all domains