hi! i might have a security issue for kratos using API (haven't tried browser yet). There's no limit on how many failed attempts to a two factor authentication using API endpoint with an authenticated user(aal1 authenticated). Not sure if this is by design but I'm thinking this can be bypassed by bruteforcing.
EDIT: Once logged in, and requested a flow for aal2, I can try unlimited times to enter incorrect code and not getting kicked out or something that prevents me from entering another failed login. Using v0.13.0