== how long a stranger's burst holds the household out (right password every 15 s)
  +    1s right password -> 200
== the rate limit, read in the jar:
== BOOT-INF/classes/org/booklore/model/dto/response/BookDistributionsResponse$StatusBucket.class
9org/booklore/model/dto/response/BookDistributionsResponse
9BookDistributionsResponse.StatusBucket(status=
== BOOT-INF/classes/org/booklore/model/dto/response/BookDistributionsResponse$StatusBucket$StatusBucketBuilder.class
9org/booklore/model/dto/response/BookDistributionsResponse
== BOOT-INF/classes/org/booklore/model/dto/response/BookDistributionsResponse$ProgressBucket.class
9org/booklore/model/dto/response/BookDistributionsResponse
== BOOT-INF/classes/org/booklore/model/dto/response/BookDistributionsResponse.class
9org/booklore/model/dto/response/BookDistributionsResponse
3(Ljava/util/List;Ljava/util/List;Ljava/util/List;)V
== BOOT-INF/classes/org/booklore/model/dto/response/BookDistributionsResponse$ProgressBucket$ProgressBucketBuilder.class
9org/booklore/model/dto/response/BookDistributionsResponse
== BOOT-INF/classes/org/booklore/model/dto/response/BookDistributionsResponse$BookDistributionsResponseBuilder.class
9org/booklore/model/dto/response/BookDistributionsResponse
3(Ljava/util/List;Ljava/util/List;Ljava/util/List;)V

== re-measured: a stranger's 12 wrong tries, then the household's right password every 10 s
  stranger: ['401', '401', '401', '401', '401', '429', '429', '429', '429', '429', '429', '429']
  a DIFFERENT name right after (is it per address?): 429
  +    0s right password -> 429
  +   10s right password -> 429
  +   20s right password -> 429
  +   30s right password -> 429
  +   40s right password -> 429
  +   50s right password -> 429
  +   60s right password -> 429
  +   70s right password -> 429
  +   80s right password -> 429
  +   90s right password -> 429
  +  100s right password -> 429
  +  110s right password -> 429
  +  121s right password -> 429
  +  131s right password -> 429
  +  141s right password -> 429
  +  151s right password -> 429
  +  161s right password -> 429
  +  171s right password -> 429
  +  181s right password -> 429
  +  191s right password -> 429
  +  201s right password -> 429
  +  211s right password -> 429
  +  221s right password -> 429
  +  231s right password -> 429
  +  241s right password -> 429
  +  251s right password -> 429
  +  261s right password -> 429
  +  271s right password -> 429
  +  281s right password -> 429
  +  291s right password -> 429
  +  301s right password -> 429
  +  311s right password -> 429
  +  321s right password -> 429
  +  331s right password -> 429
  +  341s right password -> 429
  +  351s right password -> 429
  +  361s right password -> 429
  +  372s right password -> 429
  +  382s right password -> 429
  +  392s right password -> 429
  +  402s right password -> 429
  +  412s right password -> 429
  +  422s right password -> 429
  +  432s right password -> 429
  +  442s right password -> 429
  +  452s right password -> 429
  +  462s right password -> 429
  +  472s right password -> 429
  +  482s right password -> 429
  +  492s right password -> 429
  +  502s right password -> 429
  +  512s right password -> 429
  +  522s right password -> 429
  +  532s right password -> 429
  +  542s right password -> 429
  +  552s right password -> 429
  +  562s right password -> 429
  +  572s right password -> 429
  +  582s right password -> 429
  +  592s right password -> 429
== the limiter, read in the jar (class names and constants)
BOOT-INF/classes/org/booklore/config/security/service/AuthRateLimitService.class
BOOT-INF/classes/org/booklore/config/security/service/AuthenticationService.class
BOOT-INF/classes/org/booklore/service/metadata/parser/RanobeDbParser.class
BOOT-INF/classes/org/booklore/service/metadata/parser/GoogleParser.class
BOOT-INF/classes/org/booklore/service/metadata/parser/AudnexusAuthorParser.class
BOOT-INF/classes/org/booklore/service/metadata/parser/OpenLibraryParser.class
BOOT-INF/classes/org/booklore/service/metadata/parser/hardcover/HardcoverBookSearchService.class
BOOT-INF/classes/org/booklore/service/metadata/parser/ComicvineBookParser.class
== BOOT-INF/classes/org/booklore/config/security/service/AuthRateLimitService.class
maximumSize java/time/Duration 	ofMinutes (J)Ljava/time/Duration; C(Ljava/time/Duration;)Lcom/github/benmanes/caffeine/cache/Caffeine; attemptCache recordFailedAttempt resetAttempts MAX_ATTEMPTS recordFailedLoginAttempt "recordFailedLoginAttemptByUsername resetLoginAttempts resetLoginAttemptsByUsername recordFailedRefreshAttempt 
== BOOT-INF/classes/org/booklore/config/security/service/AuthenticationService.class
recordFailedLoginAttempt "recordFailedLoginAttemptByUsername	 resetLoginAttempts resetLoginAttemptsByUsername recordFailedRefreshAttempt resetRefreshAttempts 
== BOOT-INF/classes/org/booklore/service/metadata/parser/RanobeDbParser.class
waitLock max 	getIsbn13 isbn13 maximumSize java/time/Duration (J)Ljava/time/Duration; C(Ljava/time/Duration;)Lcom/github/benmanes/caffeine/cache/Caffeine; MAX_REQUESTS_PER_WINDOW 
== BOOT-INF/classes/org/booklore/service/metadata/parser/GoogleParser.class
truncateToMaxWords CISBN-13 search returned no results, trying general search with ISBN maxResults 	getIsbn13 	getIsbn10 ISBN_13 isbn13 ISBN_10 isbn10 MAX_SEARCH_TERM_LENGTH MAX_RESULTS 
    # Comma-separated list of allowed CORS origins.
  forward-headers-strategy: native
        physical-strategy: org.hibernate.boot.model.naming.PhysicalNamingStrategyStandardImpl
        generate_statistics: ${HIBERNATE_STATISTICS:false}

	ofMinutes expireAfterWrite getIfPresent incrementAndGet MAX_ATTEMPTS login:ip: login:user: 

AuthRateLimitService constant pool — long constants: [1000, 15] | int constants: [5]
(small ints 0..5 and bipush values are in the bytecode, not the pool; MAX_ATTEMPTS field present: True )
19:08:35 == ~16.5 min after the burst (18:51:5x), no tries since 19:01: right password -> 200 (the limiter: Caffeine expireAfterWrite ofMinutes(15), MAX_ATTEMPTS 5, keys login:ip: and login:user:)
