But if an in-transit plaintext password is leaked by CloudFlare, server-side encryption is irrelevant.
(... that said, it's not like revoking sessions would impede a password-holding adversary...)
(... that said, it's not like revoking sessions would impede a password-holding adversary...)