pub fn totp_disable(conn: &Connection, user_id: &str) -> Result<(), String>Expand description
Removes the factor entirely, secret included.
Clearing the secret rather than only the flag matters: leaving it behind
means a later totp_enable could silently re-arm a secret the user believes
they destroyed, on an authenticator entry they may have deleted.