I neglected to include a field for username in the TOTP audit logging and injecting it back in turned out to be more complicated than it should be, so both issues are addressed in a 2.3.1 patch I've pushed out this morning. -- Scott