(I work for a competitor, FusionAuth.)
I noticed account linking, between social accounts and existing accounts, based on email matching, was a new feature.
It's documented here: https://www.ory.sh/docs/kratos/social-signin/link-multiple-p... I believe.
The document walks through the "linking an existing account with a password to social account" scenario. I was wondering if there was also the ability to go the other way, from an existing social account to adding a password?
How do you handle the case where Alice signs up with a username of alice@example.com but later wants to link alice@gmail.com?
I also wonder if you can block account linking on a per user basis or if it is enabled for everyone in a system.
We've had account linking for a few years (documentation here: https://fusionauth.io/docs/lifecycle/authenticate-users/iden... ) and have had customers bring up some edge cases like this.