Wave 1 of PLAN-1933 (email verification). Pure infra — nothing reads the
column until Wave 3, so this is behaviourally a no-op and mergeable early.
- Migration 070 (SQLite) / 048 (Postgres): add nullable email_verified_at
TEXT, mirroring disabled_at. UNCONDITIONALLY backfill every existing row
to verified (RFC3339 'Z'-suffixed) so no existing / OAuth / self-host
account is write-locked on deploy (inverted vs password_set's conditional
backfill). SQLite ALTER without IF NOT EXISTS; Postgres with it.
- SAFE default = verified (DR-3): CreateUser / CreateOAuthUser write a
verified timestamp unless UserCreate.Unverified is explicitly requested
(only the future cloud self-serve branch will set that). A missed call
site fails SAFE (verified), not write-locked.
- models.User.EmailVerifiedAt + IsEmailVerified() (mirror IsDisabled).
- Update userColumns + BOTH scan sites (scanUser AND the inline SearchUsers
scan) so the admin user list keeps working.
- Expose derived email_verified bool in sessionUserPayload for a later wave.
Gates: make check + make test-pg both green (dual-dialect verified).
Claude-Session: https://claude.ai/code/session_01HxBkAMiFBtCRJ2tKSCt3ST