The tests build the server's real routes and log in as a browser does.
The attempt after LoginAttemptsPerMinute failed logins from one client
must get 429 with Retry-After; another client must still get the login
form and log in with the signing key; two clients behind a trusted proxy
must be counted separately; X-Forwarded-For from an untrusted peer must
not get around the limit; an IPv6 client must be counted by its /64.
They do not compile yet: LoginAttemptsPerMinute comes with the change.
Model: opus-5-5