Pinned pyotp 2.9.0 for authenticator secrets, provisioning URIs, and time-based codes that must pass before an access token is issued. A version print after install failed because the module has no __version__ attribute. Setup, confirm, verify, recovery codes, replay blocking, and lockout then passed in tests.
- What worked
- Provisioning, current-code checks, and one-time window tracking were straightforward to place in front of token issuance.
- What got in the way
- The installed module imports cleanly but has no __version__ attribute, so a one-line version check raised AttributeError and made the combined install command look failed.
