Two-factor panel forms CompositeSprite
The 2FA enrolment/settings card: QR + manual secret, the big-digit code input, recovery-code grid, and factor status rows.
Layer: L2 host · Recipe: unset — see docs/agent/pick-a-surface.md. Curriculum: AGENTS.md; pick matrix: docs/agent/pick-a-surface.md; blast radius: CONSUMER_MAP.md.
Set Up 2FA
Aurora Ops
Authenticator App
Scan this QR code with your authenticator app.
Or enter the secret manually: JBSW Y3DP EHPK 3PXP
Save Your Recovery Codes
Store these codes in a safe place. Each code can only be used once.
Copy this
<div class="auth-card hm-measure">
<h1 class="auth-card-title">Set Up 2FA</h1>
<p class="auth-card-subtitle">Aurora Ops</p>
<h2 class="auth-section-title">Authenticator App</h2>
<p class="auth-section-body">Scan this QR code with your authenticator app.</p>
<div class="auth-qr-container"><button class="button" data-variant="outline">Generate QR Code</button></div>
<p class="auth-section-body">Or enter the secret manually: <code class="auth-secret-inline">JBSW Y3DP EHPK 3PXP</code></p>
<form class="auth-form">
<div class="auth-field">
<label for="hm-2fa-code" class="auth-label">Enter code from app</label>
<input type="text" id="hm-2fa-code" inputmode="numeric" pattern="[0-9]*" maxlength="6" placeholder="000000" class="auth-input-code">
</div>
<button type="submit" class="button auth-submit" data-variant="primary">Verify and Enable</button>
</form>
<hr class="auth-hr">
<div class="auth-recovery-alert" role="alert">
<h3 class="auth-recovery-alert-title">Save Your Recovery Codes</h3>
<p class="auth-recovery-alert-body">Store these codes in a safe place. Each code can only be used once.</p>
</div>
<div class="auth-recovery-grid"><span class="auth-recovery-pill">QK2M-8Y1D</span><span class="auth-recovery-pill">HW7C-04RA</span><span class="auth-recovery-pill">ZX3N-55PT</span><span class="auth-recovery-pill">MB9E-71LQ</span></div>
<div class="auth-status-row">
<div class="auth-status-label">Authenticator app</div>
<span class="badge" data-tone="success">Enabled</span>
</div>
<div class="auth-status-row is-last">
<div class="auth-status-label">Email codes</div>
<span class="badge">Off</span>
</div>
<a href="#" class="auth-back-link">Back to App</a>
</div>Server exchange
This Hyperpart has no server exchange — it is presentation or client chrome only. htmx does not issue a request on this part's behalf. If you put an affordance (hx-*) on a control that uses this markup, that action's exchange belongs to the action, not this part. See Swap contract for host-owned envelopes.
Swap contract
Agent-visible HTMX topology (ADR-0054 / decision 0012). exchange envelope = what the response may re-emit relative to the persistent slot (body_only | outer | none | host_owned | document). dual-lock validates part markup only — not this envelope. Stem: stems/morph-safe-hypermedia.md; decision: docs/decisions/0012-swap-identity-contract.md.
No host HTMX exchange on this part — presentation or client chrome only. exchange envelope: n/a.
If a host wraps this markup in hx-*, that host owns the swap contract (sole identity + envelope). Prefer innerMorph / outerMorph for stable slots; replacement for flash; body-only responses under inner swaps.
Envelope response examples
This part has no owned exchange (envelope n/a). If a host adds hx-*, that host’s envelope applies — typically body_only:
<!-- Host wraps this presentation part with hx-* (host owns envelope) -->
<!-- Prefer: hx-swap="innerMorph" hx-target="#panel-body" -->
<!-- Server returns body_only interior for #panel-body -->
<div class="dz-stack">content…</div>
Do not re-own the slot:
<!-- WRONG: server returns the presentation root with a new id every poll -->
<div id="two-factor-root" data-dz-region>…</div>
How to use it
No extended guidance authored yet — start from Copy this and the dependency chips (Primitive = markup only; controller = load listed JS; Endpoint = implement Server exchange).
Seams
- copy the partial under Copy this; keep root class and data-* modifiers so the CSS/JS bundle matches
- no Server exchange on this part — pure presentation or client chrome
- satisfy the DOM contract tables (CI stop-ship)
DOM contract
What the emitted HTML must satisfy — the table is the required surface; Python under contracts/ is the package-internal dual-lock CI runs (tests/test_contracts.py), not an app route. Standalone HTMX4: implement the API so responses match this markup. Dazzle: the agent emits SSR that already satisfies it. Do not invent attrs outside these tables. For request/response wiring see Server exchange.
contracts/two_factor.py
Required in the DOM: root .auth-card (part two_factor). Emit only these attributes — inventing extras is fine only if controllers ignore them; omitting required ones fails CI (tests/test_contracts.py).
| Node | Attr | Constraint |
|---|---|---|
.auth-card | — | — |
Module source
Import path is monorepo/package-local (from contracts._kit import …). Source-token form often uses data-*; gallery demos above are unprefixed. Do not copy this into app routes.
"""HYPERPART: two_factor — 2FA enrolment/settings auth card.
Dual-lock unit is the auth-card root. QR container, code input, recovery
grid, and factor status rows are host-owned. Class ``.dz-auth-card`` is the
stable substrate root (gallery CSS / two-factor panel; no FragmentRenderer
emit yet).
"""
from contracts._kit import DomContract, Node
DOM_CONTRACT = DomContract(
part="two_factor",
root=".dz-auth-card",
nodes=(Node(".dz-auth-card", attrs={}),),
)
__all__ = ["DOM_CONTRACT"]
Notes
2fa-setup.js/-settings.js against JSON endpoints): the QR image lands CLASSLESS in auth-qr-container (the container styles it), recovery pills and status rows are JS-created (shown here with status badges; the Dazzle settings JS renders button action controls in that slot), and the error/success alerts toggle via the native hidden attribute on stable ids. The code input reserves letter-spacing for six digits. Wrap full pages in auth-page for the centered layout. Dual-lock root .auth-card (HMC-148).Source files
Canonical registration in the registry. No dedicated controller — CSS for this part lives in the layered bundle.
site/registry.py · contracts/two_factor.py