Are you replying to the right node?
If so, I say nothing of fatalsToBrowser.
And Invalid password/Invalid login
is something the user can fix, and it is
not really input validation as
you cannot (usually) do it programmatically
i.e. verify that the user has in fact
authenticated himself.
Also my discussion of paths
(your point about open) was seperate,
following "on the other hand",
therefore we are in accordance.