internal/sshd/sshd.go:246 refuses a disabled user, but control.Dispatch (internal/control/control.go:78), apiAuth (internal/httpd/api.go:125) and store.APITokenUser never check the flag. SetUserDisabled (internal/store/users.go:185) deletes web sessions but not API tokens. A disabled user's bearer token still runs every non-SSHOnly write through /api/v1/cmd.
Remedy: check Disabled in Dispatch next to the pending check; have SetUserDisabled delete api_tokens.
closed by commit b56876ccbf by cmc: control: a disabled account is refused on every surface
2026-09-03 17:10 UTC