I can't speak to the specifics of this particular implementation but usually if someone has the login (username + password) to get to totp that user has already been compromised..
If you have username and password and are able to force the TOTP in the 60s window, the TOTP would be useless imho.