- Consider https://github.com/peterbourgon/ctxdata for context storage/setting cookies
- DoS
- Lock accounts after failed attempts
- forgotten password tokens (or remeber me, CSRF, etc..) being used as logins (hash them all)
- someone faking a login attempt and that action loging out valid user sessions