Ah, the classic security blunder that makes security professionals spit coffee. The code shows "brute-force attack protection" that only triggers the error message when the password is correct AND it's the first login attempt. So basically, it tells attackers "congrats, you got the right password, just try again!" Meanwhile, the kid who wrote this monstrosity sits there with a smug grin while the entire IT department has a collective aneurysm. This is why we can't have nice things in cybersecurity.