Unfortunately, we are in 2019 and client-side hashing is rare because people use SSL instead.
One can argue that company like Facebook that is well stocked with tech resources should have figured this out already but here we are.
Replace the outer H with a proper key derivation function for extra credits.
This avoids sending any secret value over to the server, so no server side logging will cause a problem.
When the login screen loads, server sends the server time so with reasonably fast internet, the client can estimate the server time. Let's call the estimated current server time t. On login, client sends H(H(p)+t) with t. Now the server can compute H(H(p)+t) with the t from the client and verify if the hash match and also check if t is within few seconds of the current server time.
This way if any data that goes over the network leaks for gets logged, it'll only be valid for few seconds. Also salting before hashing should go somewhere in there but it'll make it a bit more complicated.