Allow users to log in with OAuth 2.0, and while we're at it: ensure that brute force login's are not allowed.