Login
Secure sign-in with room for email verification, lockouts, and 2FA.
Final authentication should use secure password hashing, HttpOnly cookies, CSRF protection, rate limiting, and staff-only 2FA requirements.

Final authentication should use secure password hashing, HttpOnly cookies, CSRF protection, rate limiting, and staff-only 2FA requirements.
