Is there an existing issue for this?
Current Behavior
- A client is configured to use this flow :

- A user receives an email with a link including an action-token (for example : email validation, reset credentials ...).
- The user follows the link, he's identified, optionaly confirm his email/set password, and he's logged in.
In case user use the classic form, the restriction works and he get the normal message that he's not allowed to access it.
Expected Behavior
He should not be allowed to logged in.
Steps To Reproduce
No response
Version
- Keycloak: 16.0.0
- This extension: 16.0.0
Anything else?
I'm not an expert on Keycloak so maybe I missed something ... My first idea is that using action token uses another flow but I can't identifie it (and "events" doesn't sho which flow has been used).
Regards
Is there an existing issue for this?
Current Behavior
In case user use the classic form, the restriction works and he get the normal message that he's not allowed to access it.
Expected Behavior
He should not be allowed to logged in.
Steps To Reproduce
No response
Version
Anything else?
I'm not an expert on Keycloak so maybe I missed something ... My first idea is that using action token uses another flow but I can't identifie it (and "events" doesn't sho which flow has been used).
Regards