Prove your email verification actually verifies: generateLink + token_hash callback, a throwaway user on a plus-alias, and the provider's send log
Outcome: hard evidence that a fresh signup gets no session until the emailed link is used, that the link is server-verified (token_hash, so it works cross-browser and in an iOS webview), and that the email really left your SMTP provider. We found our own signup was auto-confirming every account server-side, which meant anyone could register your address and get linked to your later OAuth sign-in. Turning that off is a one-line flag; proving it is this recipe.
Steps: (1) Switch the auth email templates from the PKCE confirmation URL to a token_hash link that hits /auth/callback?token_hash=...&type=email. (2) With the admin client, create a throwaway user on a plus-alias of a mailbox you control and call generateLink(type=signup); do not send it, just take the hashed token. (3) GET the callback with it and expect a 307 to onboarding plus an auth cookie in the response; re-read the user and check email_confirmed_at is set. (4) Do a real anonymous signUp() for a second throwaway and assert the response has no session. (5) Open the SMTP provider's log and find the message by subject and recipient with status Sent. (6) POST the old autoconfirm endpoint and expect it to say disabled. (7) Delete both throwaways and count their profile rows (0).
Pitfalls: keep an env-flag rollback (AUTH_AUTOCONFIRM=1) so a broken template cannot lock people out. Enumeration: the copy for "this email already exists via GitHub or Apple" must read the same as success. Provider logs show "delivery delayed" for made-up test domains, so use a real mailbox alias. Never print tokens or cookies into the report; print status codes and timestamps.