RequestLoginLink resolves a username through PrimaryVerifiedEmail, which
requires is_primary = 1 AND verified_at IS NOT NULL
(internal/store/mrs.go:443).
An account that verified a second address but left its primary unverified gets nothing when identifying by username, while identifying by that same verified address succeeds. Inconsistent rather than unsafe — responses stay identical, so there is no enumeration angle.
Reachable via self-registration, which clears pending on verifying any address.
Ref #155.
closed by commit d7a0d77892 by cmc: store, control: resolve a login link to any verified address, not just the primary
2026-09-05 19:51 UTC