fix(settings): correct unverified session and 2FA routing
commit 27791aebe8c131203830e4f67050e53773105cbc Author: Valerie PomerleauDate: Wed Aug 20 15:24:24 2025 -0700 fix(settings): correct unverified session and 2FA routing Because: * Forced 2FA OAuth flows without existing TOTP were incorrectly routed to TOTP code * Unverified sessions should complete email verification before 2FA setup This commit: * Revise navigation targets for unverified session * Update tests to match Closes #FXA-12285