If you're going to have a 2-page login worflow, just make sure that you aren't making network calls client-side to check if the email is registered on the site.
This is a super easy way for attackers to enumerate valid email addresses to then come back and stuff credentials.