a. you're sending the auth credentials every single time a user wants to login. If email was secure, that might be fine, but it's not.
b. On a password reset, you typically require a user to actually reset their credentials, and then allow them to continue. In this case, if someone accidentally forwards the email, or enters the wrong email address, the recipient automatically gets access to the account, no questions asked.
It is an interesting concept, though. I don't really know if I like it yet, but it's nice to see people trying to work on this problem.