Exempt public register POST from cross-site CSRF, collect email on the landing form, and handle API errors instead of navigating to a missing success_url. Co-authored-by: Cursor <cursoragent@cursor.com>