- Adopt rt in middleware, so sorry
- add csrf
- make password reset delete all sessions
- make sure 2fa is not accidentally deleted when session deleted
- Make single use magic link through db
- magic links that can last at x time that we place when we make
- can be days
- convert OTP and MagicLink to 1 to many with usedAt