Read the account inside a transaction before sending a reset

FixSecurityService
Shipped
September 4, 2026 at 8:21 PM UTC
Author
Kamo
Commit
a45198d

sendPasswordReset had no transaction, so the User came back detached and `securityProvider` stayed an unresolvable lazy proxy. Working out which organization's sign-in host the letter belongs to would have thrown, been caught by the guard around it, and reported the account as having no sign-in host — a refusal with a plausible-sounding reason and nothing wrong with the account at all. Read-only: recovery opens its own transaction for the write.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing