Reduce login and nostr/session rate limits from 30 to 10 requests per minute per IP to prevent brute-force attacks. Add tests verifying 429 response after exceeding the limit. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Reduce login and nostr/session rate limits from 30 to 10 requests per minute per IP to prevent brute-force attacks. Add tests verifying 429 response after exceeding the limit. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>