Rate Limiting Alone Won't Stop a Patient Attacker
@nestjs/throttler counts requests per IP address within a time window. That's the entire mechanism — no concept of accounts, passwords, or "this one person is being targeted." Point it at a login endp