We already store and generate TOTP tokens. It should be trivial to allow 2FA logins using much of the same code. This will need to be implemented on all clients as well otherwise no one will be able to login