feat: user without tokens is redirected to new page, when mfa is enforced
I tested, that tokens with expired failcounter are still considered as active. Because of this, I think that we do not need to modify "active=true" filter when getting tokens from privacyidea.