@if($user->two_factor_enabled && ! empty($canDisableTwoFactor))
    <div class="border-b border-slate-100 p-6">
        <p class="font-medium text-slate-900">Two-factor authentication</p>
        <p class="mt-1 text-sm text-slate-500">
            Your company has turned off 2FA, but your account still has it enabled from before.
            You can remove it below so sign-in only requires your password.
        </p>
        <form action="{{ route('settings.profile.two-factor.disable') }}" method="post" class="mt-4 flex flex-wrap items-end gap-3">
            @csrf
            <div class="min-w-[200px] flex-1">
                <label for="legacy_two_factor_password" class="block text-xs font-medium text-slate-600">Confirm with password</label>
                <input type="password" name="password" id="legacy_two_factor_password" required
                       class="mt-1 w-full max-w-xs rounded-lg border border-slate-300 px-3 py-2 text-sm">
                @error('password') <p class="mt-1 text-xs text-red-600">{{ $message }}</p> @enderror
            </div>
            <button type="submit" class="rounded-lg border border-red-200 bg-red-50 px-4 py-2 text-sm font-medium text-red-700 hover:bg-red-100">
                Remove 2FA
            </button>
        </form>
    </div>
@endif
