email verify: say when a code belongs to another account !109

merged merged by cmc on 2026-08-28 22:13 UTC · krz/gitbay:verify-wrong-account into main

Discussion

cmc

ConsumeEmailToken scopes its lookup to the authenticated user, so a code minted for a different account is indistinguishable from a bad one and got "that code is invalid, expired, or already used" — wrong on all three counts.

The trap is that ssh git@host email verify <code> authenticates as whichever account owns your default SSH key. Verifying a second account therefore fails with a message pointing at the code, while the code is fine and the key is not. Hit live while verifying an account on this instance; ssh -F /dev/null -i <other key> worked immediately.

Now checks whether a live code exists under another user and says so, naming the account you authenticated as:

that code belongs to a different account; this key authenticated
you as cmc. Re-run with the key registered to the account being
verified: ssh -i <that key> git@<host> email verify <code>

It answers only yes-or-no on ownership and never names the owner — naming it would turn a guessed code into an oracle for which accounts exist. Exit is denied rather than usage: the request is well formed, the caller is not who it needs to be.

This gets more likely now that registration is open, since every second account someone registers hits it.