feat: dry-run legacy identity audit report - #116
Open
felixgateru wants to merge 8 commits into
Open
felixgateru wants to merge 8 commits into
felixgateru wants to merge 8 commits into
Conversation
… verified email-change flow Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…contracts Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…ries Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…ontracts Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…port Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
felixgateru
force-pushed
the
feat/legacy-identity-audit-report
branch
from
October 1, 2026 10:38
0c7c15c to
79ab807
Compare
Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Depends on #115:
pendingTokens.emailChangequeries theemail_change_tokenstable introduced there. This diff includes #115's commits until it merges.Fix
Four read-only, platform-admin-only GraphQL queries, each paginated and filterable by
entityId:legacyUnverifiedEmails— liveentity_emailsrows withverified_at IS NULLlegacyCredentialIdentifierMismatches— active password credentials whose identifier disagrees with (or is missing) the canonical emaillegacyOauthEmailMismatches— OAuth identities whose claimed email doesn't match an active, verified canonical emaillegacyAttributesEmailMismatches— human entities whose legacyattributes.emaildisagrees with the canonical rowEvery row carries
pendingTokens— counts only, never values — so an operator can see a self-service fix may already be in flight before reaching for manual recovery. Nothing here mutates a row.Tests
{"email": null}passes the JSONB key-exists check but breaks non-optional string extraction — now excluded explicitlyPart of #110 (workstream B, report half; remediation tooling and the operator runbook remain a separate PR).