Two fixes from manual SLA validation (06-LOCUST-01):
1. backend/api/auth.py: concurrent registrations with same email/handle caused
UniqueViolation to bubble as 500. Now wraps session.commit() in try/except
IntegrityError → 409 Conflict. Regression covered by existing auth API tests.
2. backend/load_tests/locustfile.py: rewrote from single-shared-account to
pre-authenticated unique accounts. New @events.test_start listener creates
50 accounts in 9-user batches (65 s pause between batches to stay under
10 req/min IP rate limit). Added min-request guard to SLA check so a
run-time-consumed-by-setup result never silently "passes".
Run command updated to --run-time 12m.
Known open issue: _account_key in services/rate_limiting.py falls back to IP
when request.state.current_user is not yet set (rate limiter key_func runs
before handler body). Fix: extract sub from JWT directly. See next session.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>