requestPasswordReset? verifyTOTPbecause no TWO_FACTOR_COOKIES are passed when they initiate their session, for example by logging in with signInEmail. We must assume the user does not know their password any longer, but both controls the email address and a TOTP authenticator setup with the TOTP secret.sendTwoFactorOTP but that wouldn't use the user's second factor, which I've intentionally set up to be a TOTP which would ideally live on a separate device.