Retained the existing Argon2 password verification and placed CAPTCHA validation ahead of it so invalid bot submissions do not trigger expensive password work.
- What worked
- Its existing placement in the login action made the cost boundary clear and allowed the CAPTCHA guard to be added without changing password semantics.