{{-- ========================================================= Profile --}}
@csrf @method('PATCH') Save changes
{{-- ======================================================== Password --}}
@csrf @method('PUT') Update password
{{-- ============================================================= 2FA --}} @if (session('recovery_codes')) Each code works once, and this is the only time they are shown. Store them somewhere safe — they are how you get back in if you lose your phone.
    @foreach (session('recovery_codes') as $code)
  • {{ $code }}
  • @endforeach
@endif @if (session('two_factor_qr')) {{-- Enrolment in progress: scan, then confirm with a live code. --}}

Scan this with your authenticator app, then enter the 6-digit code it shows to finish enabling.

{!! session('two_factor_qr') !!}

Can't scan? Enter this key manually:

{{ session('two_factor_secret') }}

@csrf
Confirm
@elseif ($user->hasTwoFactorEnabled())
Enabled Since {{ $user->two_factor_confirmed_at->format('j M Y') }}
@csrf Regenerate recovery codes
@csrf @method('DELETE')
Disable
@else
Not enabled

Strongly recommended. Without it, anyone who learns your password has your account and every device configuration in it.

@csrf Enable
@endif
{{-- ======================================================== Sessions --}} @if ($sessions->isEmpty()) @else
    @foreach ($sessions as $session)
  • {{ $session->ip_address ?? 'Unknown IP' }}

    @if ($session->is_current) This device @endif

    {{ Str::limit($session->user_agent ?? 'Unknown browser', 60) }} · {{ $session->last_active->diffForHumans() }}

    @unless ($session->is_current)
    @csrf @method('DELETE') Sign out
    @endunless
  • @endforeach
@endif