)); // middleware/mfa.js async function requireMfa(req, res, next) user.roles.includes('admin')) if (!req.session.mfaVerified) return res.redirect('/mfa/setup'); // TOTP or WebAuthn next();