Key risks covered
- - Valid email or username login with the expected token response.
- - Missing identifiers, missing passwords, malformed emails, wrong passwords, and unknown users.
- - Locked, disabled, unverified, deleted, and MFA-required account states.
- - Generic errors that prevent user enumeration and brute-force clues.
- - Rate limiting, secure token/session behavior, password exposure checks, and auth telemetry.