I noticed that the magic-link resend endpoint can be repeatedly triggered without any visible throttling or friction layer. This could lead to automated email flooding and weak identity verification during onboarding/waitlist flows. I'm happy to take a deeper look at the full onboarding + auth chain and flag anything concrete if useful.