Login and brute-force controls
Review how the application handles repeated login attempts and protects account access. For Laravel, this can include assessing the existing rate-limiting configuration and authentication workflow within the agreed review scope.
