application/json only allows Unicode, so this prevents from wrong charset detection.
* Add rate limits for logins and sign-ups by IP (5 in 5 minutes) Should be enough for normal attempts * Add rate limit for forgotten password form as well