Extends the diagram from ADR-020 Phase 1 to cover: - Rate limiter gate before credential validation in login - CSRF double-submit cookie handshake for mutating requests - Session revocation on password change (revokeOtherSessions) and password reset (revokeAllSessions) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>