Show the progressive lockout, so a held sign-in explains itself

Featurekamo-login
Ya
5 Septemba 2026, 00:16 UTC
Mwandishi
Kamo
Ahadi ya
50cfdb0

The server now refuses sign-ins on a ladder — five free attempts, then five seconds, then locks of five, fifteen and thirty minutes, then a permanent block. Without any of this the screen would answer all of that with "Invalid username or password" and a button that quietly does nothing, which reads as the site being broken rather than as a security control working. Four states, and the differences between them are the design: A STRIKE METER appears under the password field once failures start accumulating, saying how many attempts remain before signing in pauses and for how long. Somebody who has genuinely forgotten their password should be nudged toward the reset link BEFORE they are locked out, not after. The FIVE-SECOND wait stays inline: the Sign in button becomes a countdown with a bar draining across it. Taking the form away and putting it back for five seconds would be more disruptive than the wait. A LOCK OF MINUTES takes over the card — a ring that empties, a mm:ss countdown, and a reset-password escape, because by the tenth failure the password is forgotten rather than mistyped and recovery is a door this lockout does not close. It OVERLAYS the form rather than replacing it: the fields stay mounted and disabled so a password manager mid-fill does not lose its target. A PERMANENT BLOCK gets no countdown, no ring and no retry affordance. An animation implying something is coming when nothing is would be a lie told slowly. It says the account is not the thing that was blocked, because that is true and is the first thing the person will want to know. No policy lives here. The browser owns the countdown and nothing else — a second copy of the ladder in client code is a copy an attacker can edit and a copy that drifts the moment either side changes. This repo has been bitten by exactly that before: the Node access-rule check compared rule types against "whitelist" while the publisher wrote "WHITELIST", matched nothing, and nobody noticed. So the API routes relay the server's numbers untouched, including forwarding 429 as itself rather than collapsing it into 400, which would report "bad request" for a response whose entire content is how long to wait. A lockout does not shake the password field or select its contents. The shake means "you typed the wrong password", and during a hold the password was never looked at — blaming the field would be blaming the wrong thing. All four states rendered and read back with puppeteer against canned server replies, because a green build proves nothing about how a page looks. Reduced motion is honoured explicitly; motion/react does not honour it on its own.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei