Authentication
Verification and recovery
The database model records verification state, but outbound verification and password-recovery delivery are not implemented yet.
Trestle therefore does not pretend to send email. Deployments should not expose self-service recovery controls until signed, expiring, single-use recovery challenges and a configured delivery provider are available.
Administrator action
Administrators can inspect and disable users. They cannot read passwords or refresh tokens, and there is deliberately no “set arbitrary password” shortcut.