A regression introduced in 1.16.4 was identified today after a bug report from @codeberg.

Gitea users registered before the upgrade to 1.16.4 with an email that is no longer considered valid are unable to login or recover their account.

The simplest workaround is to kindly ask the Gitea admin to change the email: this is likely to only impact a handful of users, even on instances with thousands of registered accounts.



Authored by @dachary

@hostea @codeberg @dachary It's not per-se a regression, as noted by Lunny on Github. This was a change whereby the "breakage" was considered when creating and merging this PR. The PR was tagged as kind/security 😉.

