The registry has only email add and email verify, the settings page lists
addresses with no control on each, and Parity carries one row. A mistyped
address, or one you no longer own, stays on the account forever; the primary
is set at registration and never moves. An admin cannot remove one either.
Two commands, own account only:
email remove <address>— exit 3 when not on the account.email primary <address>— must be verified.
Rules the store holds, since other things read the table:
- never remove the last verified address: activation, login links and commit identity all resolve through verified addresses (exit 4).
- never remove the primary; set another first (exit 4).
- removing a verified address bumps the key epoch: the signature cache
keys on verified addresses too, and a commit authored from the removed
address is
signed_email_mismatchafterwards. - pending verification tokens for the address go with it.
Web: a remove control per address and a set-primary control on verified non-primary ones, on the settings page. Parity rows and a paragraph on the Users page.
closed by commit 93a9e66ebf by cmc: control, store, web, wiki: email list, remove and primary
2026-09-07 18:32 UTC