No way to remove an email address, or change the primary #181

closed cmc opened this on 2026-09-07 17:51 UTC

Discussion

cmc 2026-09-07 17:51 UTC

The registry has only email add and email verify, the settings page lists addresses with no control on each, and Parity carries one row. A mistyped address, or one you no longer own, stays on the account forever; the primary is set at registration and never moves. An admin cannot remove one either.

Two commands, own account only:

  • email remove <address> — exit 3 when not on the account.
  • email primary <address> — must be verified.

Rules the store holds, since other things read the table:

  • never remove the last verified address: activation, login links and commit identity all resolve through verified addresses (exit 4).
  • never remove the primary; set another first (exit 4).
  • removing a verified address bumps the key epoch: the signature cache keys on verified addresses too, and a commit authored from the removed address is signed_email_mismatch afterwards.
  • pending verification tokens for the address go with it.

Web: a remove control per address and a set-primary control on verified non-primary ones, on the settings page. Parity rows and a paragraph on the Users page.

closed by commit 93a9e66ebf by cmc: control, store, web, wiki: email list, remove and primary

2026-09-07 18:32 UTC