- check user status on login as well as session creation - don't even create sessions for blocked users