Function
challenged: whether the endpoint requires a Turnstile token
The submission state and run
Holds the Turnstile token and sends it as x-captcha-response, tracks the
request in flight, and turns a refusal into an Account.errors key. A
Turnstile token is single-use, so a refused attempt spends it: the token is
dropped and challengeKey changes, which remounts the widget for a new one.
Every request also states the locale as x-app-locale. The endpoints that
email on success — a changed password, a completed reset — run their
callbacks outside any request, so the browser is the only one that knows
which of the three catalogues the message should be written in.
The submission mechanics every account form shares.