GET ?password= and X-Paste-Password header checks in handleGetPaste were unlimited (pentest2: 8 wrong = 8x401, no 429). Gate every password verification on the same per-IP+paste unlock limiter (5/min, 429 with Retry-After) already used by the POST unlock form path. Regression tests: repeated wrong passwords via GET ?password= and via header must eventually 429; correct password within burst still 200. Fixes #81