Ideally implement a middleware that checks the session for an authenticated session with a 'two_factor_authenticated' = false, then when false redirect to the 2fa code entering page, upon successful code, set two_factor_authenticated = true and redirect