Vulnerability fix, rate limit and documentation
- Added check on MFA code by the user (thanks Dirk of S-Unit for reporting after pentests!)
- Added rate limit on attempts for MFA codes. Will block after user after 3 times (just like normal login attempts)
- Custom info and error messages are now possible
- Small documentation fixes