By: Michael Lynch <git@mtlynch.io>
Add per-IPv4 login rate limit Limit each IPv4 address to two login attempts per existing rate-limit window while preserving the existing global login limit. This reduces login email abuse from a single IPv4 source without restricting IPv6 requests through the IPv4-specific limiter.