Yeah, I gathered as much, but still, just a single URL to an email address to log me in? What about my 36 char password and my 2fa app?
Edit: I just found I didn't set up 2fa. I wonder, if I had, would they still do this? Then it would have just blatantly ignored my second factor...