Why this matters
Step-up authentication supports SOC 2 access control.
Require TOTP or WebAuthn MFA for admin areas; verify mfa_verified_at timestamp before sensitive routes.
Step-up authentication supports SOC 2 access control.
Side-by-side examples engineers can pattern-match during review.
before_action :require_adminbefore_action :require_admin; before_action :require_fresh_mfa, only: [:export, :rotate_keys]session[:mfa_verified_at] = Time.nowsession[:mfa_verified_at] = nilFrom the same buckets as this rule.
Public services must require TLSv1.2 or higher and set HSTS (max-age ≥ 15552000, includeSubDomains). Reject plaintext HTTP and weak ciphers; cookies must be Secure and HttpOnly with SameSite set.