ok - session identity helper exists ok - login helper exists: dalo_operator_config_boolean ok - login helper exists: dalo_operator_auth_enabled ok - login helper exists: dalo_operator_auth_select_source ok - login helper exists: dalo_operator_auth_row_source ok - login helper exists: dalo_operator_ldap_provider_config ok - login helper exists: dalo_operator_ldap_link_external_id ok - login helper exists: dalo_operator_auth_set_pending ok - login helper exists: dalo_operator_auth_set_authenticated ok - login page auth settings helper exists ok - OTP helper exists: dalo_operator_auth_otp_prepare_session ok - OTP helper exists: dalo_operator_auth_otp_identity_matches ok - OTP helper exists: dalo_operator_auth_otp_finalize_session ok - local-only missing provider remains local-compatible ok - local-only explicit LDAP is rejected ok - both enabled requires explicit source POST ok - explicit LDAP stays LDAP with no local fallback ok - explicit local stays local ok - unknown provider is rejected ok - LDAP config maps the configured URI ok - LDAP environment bind password overrides file config ok - LDAP group configuration reaches the provider ok - empty LDAP bind environment value preserves file config ok - pending session carries provider ok - pending session carries operator identity ok - LDAP pending session carries external identity ok - pending session does not carry password ok - same-identity concurrent link is accepted ok - different-identity concurrent link is rejected ok - identity link database update errors fail closed ok - unchanged LDAP identity permits MFA continuity ok - changed LDAP identity rejects MFA continuity ok - final session carries provider ok - final session preserves ACL identity ok - final session is authenticated ok - LDAP pending session accepts a valid common TOTP factor ok - common TOTP rejects an incorrect factor ok - common recovery code is accepted once for provider sessions ok - local provider enters the same MFA pending flow ok - local MFA compatibility keeps external identity absent ok - login page hides provider selection when only local auth is enabled ok - login page exposes provider selection when both providers are enabled ok - pre-provider pending MFA sessions default to local auth ok - MFA accepts an unchanged LDAP identity ok - MFA rejects a changed LDAP identity ok - local MFA does not require an external identity ok - MFA finalization preserves the provider and ACL identity ok - MFA finalization clears pending LDAP state ok - pre-migration operator rows default to local auth ok - migrated operator rows retain their configured provider ok - MFA locks the identity row before provider verification and state update ok - MFA checks provider identity before updating one-time state ok - MFA validates both TOTP and recovery-code state updates before commit ok - MFA rolls back failed or invalid verification attempts ALL PASSED