Severity: MEDIUM
Location: src/Controllers/AuthController.php:808-813
Bug: Once lockout expires, counted failures also fall outside the window; exponential backoff never escalates.
Fix: Longer observation window (24h) separate from lockout duration.
Status: open. Will reply with remediation details when resolved.