Prototype demo: if you've registered before, the password you set is checked and repeated wrong attempts get temporarily locked out — an unrecognized email just starts a fresh guest session. See SECURITY_AND_ANTIFRAUD.md for what a real login needs on the backend.