Lab 7: Client-Side OTP Verification Trust

Intentional flaw: backend trusts a hidden input flag from the browser.

Credentials: client_user / client123

Reset Back