
rule /account/activate must be uncoupled & unexpired does not seem to be enforced

henriterhofte opened this issue · 1 comments

Slide 9 of the design states:
“5.API verifies account token: must belong to uncoupled account, and must be unexpired”

This rule does not seem to be enforced currently; symptoms:

Please coordinate with app devs when you (plan to) start enforcing this rule. They know it's likely coming and that they may need to create multiple uncoupled and unexpired accounts per test user.

arpe commented

I confirm this is not enforced, and needs to be fixed.