- Implement rate limiting for login attempts (10 attempts per 5min window, 15min lockout) - Add Retry-After header and 429 response for rate-limited requests - UI shows rate-limited state with countdown message - Separate limits for identified IPs vs unknown clients (3 attempts without IP) - Add cleanup mechanism for stale rate limit records Co-authored-by: Jovines <jovines@qq.com>