Should I display the 2FA secret only once or it can be always available?
A logged-in user enables 2FA for his account and a QR code with the secret is displayed.
Is it correct to display the same QR code again when the user visits the 2FA settings page after some time? Or the QR code should be displayed only on…