439acdc1

By: Michael Lynch <git@mtlynch.io>

Return 429 for rate-limited login attempts

Rate-limited requests were silently returning an empty entry (same as
unregistered emails) to prevent email enumeration. But an attacker needs
a valid registered email to trigger rate limiting, so the 429 doesn't
leak meaningful information. Restoring the status code gives operators
HTTP-level visibility into rate limiting without weakening anti-enumeration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

Suite timing

Time to Start Worker time Duration Time to finish Idle
Config 0s 8s 8s 9s 0s
Eval 8s 54s 54s 1m03s 0s
Build 12s 7m44s 1m18s 1m30s 0s
Suite 0s 8m47s 1m29s 1m30s 0s

Timeline

0s10s20s30s40s50s1m1m10s1m20s1m30s