Authentication

Verification and recovery

The database model records verification state, but outbound verification and password-recovery delivery are not implemented yet.

Trestle therefore does not pretend to send email. Deployments should not expose self-service recovery controls until signed, expiring, single-use recovery challenges and a configured delivery provider are available.

Administrator action

Administrators can inspect and disable users. They cannot read passwords or refresh tokens, and there is deliberately no “set arbitrary password” shortcut.