A verified non-primary address cannot be used to request a login link #158

closed cmc opened this on 2026-09-05 04:10 UTC · milestone v1.14.0

Discussion

cmc 2026-09-05 04:10 UTC

RequestLoginLink resolves a username through PrimaryVerifiedEmail, which requires is_primary = 1 AND verified_at IS NOT NULL (internal/store/mrs.go:443).

An account that verified a second address but left its primary unverified gets nothing when identifying by username, while identifying by that same verified address succeeds. Inconsistent rather than unsafe — responses stay identical, so there is no enumeration angle.

Reachable via self-registration, which clears pending on verifying any address.

Ref #155.

closed by commit d7a0d77892 by cmc: store, control: resolve a login link to any verified address, not just the primary

2026-09-05 19:51 UTC