The way I have it now;
- Registration asks for a user public key and will only take something starting with npub1
- Registration tells the user NOT to enter their private key and to enter a NEW password
- Login I don’t tell people that because I assume they paid attention at registration and used correct credentials