Apply per-IP / per-account rate limiting and throttling to login, signup, password-reset, and other public endpoints.
Why This Matters
Without limits, endpoints are open to brute-force credential attacks and denial-of-service (OWASP A07).
Related Rules
Catch this automatically on every PR
BeforeMerge scans your pull requests against this rule and dozens more. Get actionable feedback before code ships.