Function
This is the single definition of an account action in flight. Both callers
use it — AccountSubmitArea, for the four account forms, and
DeleteAccountSection, which is not a form and drives isPending from its
own state — so the destructive action on the profile page waits exactly the
way signing in does.
The button disables itself while pending, which is what actually prevents the double submission; the arc only says so. The arc is hidden from assistive technology, so the button's accessible name stays the pending label alone.
A pending button keeps its full ink, overriding Button's disabled:opacity-50.
The two disabled states mean different things and must not look alike: a
button that cannot be pressed yet — a Turnstile challenge still unsolved —
is dimmed, while a button that is working has to stay legible, or the arc
and the pending label fade out exactly when they are the only thing to read.
The button an account surface waits on: at rest it is an ordinary Button, and while its request is in flight it swaps its label and turns a SpinnerArc beside it.