80 characterization tests: registration/admin/email/password changesets, password hashing, admin-flag grant logic, and the full token lifecycle (session, magic link, confirm, change-email) including expiry boundaries and cross-context rejection.