Bug: API Bypasses Two Factor Authentication

Using the API bypasses two factor authentication.

To reproduce, install a fresh copy of tt-rss, create an account and then enable two factor authentication.
Using the API login to the new account with just the username and password.

Versions:
Tiny Tiny RSS v17.12 - git (32101389b6)
Ubuntu 18.04 Kernel 4.15.0-20-generic
PHP 7.2.5-0ubuntu0.18.04.1
mysql Ver 14.14 Distrib 5.7.22

thats how it works by design because 2fa prompts on a phone would be annoying

if you feel its insecure don’t enable it :man_shrugging: