1. Log in with the password (given on the page). You land on the OTP page. Instead of entering an OTP, browse directly to /dashboard. Why: the dashboard only checks that the password step set a session, not that MFA was completed β the second factor is never enforced server-side.
2. The dashboard loads and shows the flag.
Lesson: enforce every auth step server-side; a later resource must verify the full auth state (password AND mfa), not just presence of a session.