By: Michael Lynch <git@mtlynch.io>
Return 429 for rate-limited login attempts Rate-limited requests were silently returning an empty entry (same as unregistered emails) to prevent email enumeration. But an attacker needs a valid registered email to trigger rate limiting, so the 429 doesn't leak meaningful information. Restoring the status code gives operators HTTP-level visibility into rate limiting without weakening anti-enumeration. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
| Time to Start | Worker time | Duration | Time to finish | Idle | |
| Config | 0s | 8s | 8s | 9s | 0s |
| Eval | 8s | 54s | 54s | 1m03s | 0s |
| Build | 12s | 7m44s | 1m18s | 1m30s | 0s |
| Suite | 0s | 8m47s | 1m29s | 1m30s | 0s |