1
Your view. Fortify::loginView(fn () => view('auth.login')). Fortify defines the GET route; you draw the form.
2
POST /login. Expects email or username, password, optional remember. XHR gets 200 or 422; a browser gets a redirect.
3
Pipeline. Throttle, canonicalise the username, redirect to 2FA if on, attempt, prepare the session. Swappable as a whole.
4
Actions. app/Actions/Fortify: CreateNewUser, ResetUserPassword and the password rules. Yours to edit after install.
5
Features. features in config/fortify.php: registration, reset, verification, two-factor, passkeys. Off means no route.
6
Home. On success, a redirect to home from config, or 200 for XHR. Bind LoginResponse for anything else.