The Secret for this implementaiton is hard coded to OI3BFP5BUK4Y4NLR, this should be set and stored per user and encrypted with the user's password. Note then, though, that if a person resets their password, they need to re-generate their TOTP secret