E.1 Vaultwarden invite-without-SMTP spike — 2026-09-15 ~07:35-07:37Z, demo-hp scratch LXC 9202
Container vwspike: vaultwarden/server:1.36.0-alpine (catalog image), env as catalog template with SIGNUPS_ALLOWED=false,
ADMIN_TOKEN=<hex, 64 chars>, _ENABLE_SMTP=false + SMTP_* empty (catalog default when app-email is off), 127.0.0.1:18480, data /tmp/vwspike.
Admin page defaults observed: invitations_allowed CHECKED, signups_verify unchecked, signups_allowed unchecked, _enable_smtp unchecked.

=== /api/config (features) ===
{"environment":{"api":"http://127.0.0.1:18480/api","cloudRegion":null,"identity":"http://127.0.0.1:18480/identity","notifications":"http://127.0.0.1:18480/notifications","sso":"","vault":"http://127.0.0.1:18480"},"featureStates":{"pm-19148-innovation-archive":true},"gitHash":"f21a3ada","object":"config","push":{"pushTechnology":0,"vapidPublicKey":null},"server":{"name":"Vaultwarden","url":"https://github.com/dani-garcia/vaultwarden"},"settings":{"disableUserRegistration":false},"version":"2025.12.0"}
=== 1. stranger registration ===
--- POST /identity/accounts/register email=idegen.probe@example.com
{"message":"Registration not allowed or user already exists","validationErrors":{"":["Registration not allowed or user already exists"]},"errorModel":{"message":"Registration not allowed or user already exists","object":"error"},"error":"","error_description":"","exceptionMessage":null,"exceptionStackTrace":null,"innerExceptionMessage":null,"object":"error"}
HTTP 400

--- POST /api/accounts/register email=idegen.probe@example.com
{"error":{"code":404,"description":"The requested resource could not be found.","reason":"Not Found"}}
HTTP 404

=== 2. admin login + invite ===
POST /admin login HTTP 200
{"_status":1,"avatarColor":null,"creationDate":"2026-09-15T07:36:18.177612Z","culture":"en-US","email":"meghivott.probe@example.com","emailVerified":true,"forcePasswordReset":false,"id":"8dbdfec6-2cfb-4794-9156-5a67cb27b57b","key":"","name":"meghivott.probe@example.com","object":"profile","organizations":[],"premium":true,"premiumFromOrganization":false,"privateKey":null,"providerOrganizations":[],"providers":[],"securityStamp":"4f4d1ee9-1295-4263-8fc2-96cb79236f86","twoFactorEnabled":false,"usesKeyConnector":false}
POST /admin/invite HTTP 200

[{"_status":1,"avatarColor":null,"createdAt":"2026-09-15 09:36:18 CEST","creationDate":"2026-09-15T07:36:18.177612Z","culture":"en-US","email":"meghivott.probe@example.com","emailVerified":true,"forcePasswordReset":false,"id":"8dbdfec6-2cfb-4794-9156-5a67cb27b57b","key":"","lastActive":null,"name":"meghivott.probe@example.com","object":"profile","organizations":[],"premium":true,"premiumFromOrganization":false,"privateKey":null,"providerOrganizations":[],"providers":[],"securityStamp":"4f4d1ee9-1295-4263-8fc2-96cb79236f86","twoFactorEnabled":false,"userEnabled":true,"usesKeyConnector":false}]
=== 3. invited registration ===
--- POST /identity/accounts/register email=meghivott.probe@example.com
{"captchaBypassToken":"","object":"register"}
HTTP 200

--- POST /api/accounts/register email=meghivott.probe@example.com
{"error":{"code":404,"description":"The requested resource could not be found.","reason":"Not Found"}}
HTTP 404

=== control: second stranger after invite ===
--- POST /identity/accounts/register email=idegen2.probe@example.com
{"message":"Registration not allowed or user already exists","validationErrors":{"":["Registration not allowed or user already exists"]},"errorModel":{"message":"Registration not allowed or user already exists","object":"error"},"error":"","error_description":"","exceptionMessage":null,"exceptionStackTrace":null,"innerExceptionMessage":null,"object":"error"}
HTTP 400

=== admin users after ===
[{"_status":0,"avatarColor":null,"createdAt":"2026-09-15 09:36:18 CEST","creationDate":"2026-09-15T07:36:18.177612Z","culture":"en-US","email":"meghivott.probe@example.com","emailVerified":true,"forcePasswordReset":false,"id":"8dbdfec6-2cfb-4794-9156-5a67cb27b57b","key":"2.AAAAAAAAAAAAAAAAAAAAAA==|AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=|AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=","lastActive":null,"name":"probe","object":"profile","organizations":[],"premium":true,"premiumFromOrganization":false,"privateKey":"2.AAAAAAAAAAAAAAAAAAAAAA==|AAAA|AAAA","providerOrganizations":[],"providers":[],"securityStamp":"032fbc2f-aa0e-4e0f-8390-485f3077493c","twoFactorEnabled":false,"userEnabled":true,"usesKeyConnector":false}]
=== config defaults (admin) ===
name="signups_allowed" 
name="signups_verify" 
name="invitations_allowed"  checked 
name="_enable_smtp" 

=== newer web-vault flow (send-verification-email) ===
--- POST /identity/accounts/register/send-verification-email email=idegen3.probe@example.com (stranger)
{"message":"Registration not allowed or user already exists","validationErrors":{"":["Registration not allowed or user already exists"]},"errorModel":{"message":"Registration not allowed or user already exists","object":"error"},"error":"","error_description":"","exceptionMessage":null,"exceptionStackTrace":null,"innerExceptionMessage":null,"object":"error"}
HTTP 400

invite meghivott2 HTTP 200
--- POST /identity/accounts/register/send-verification-email email=meghivott2 (invited)
"<register_verify JWT redacted, returned inline because SMTP is off>
--- web vault register route present:
GET / HTTP 200
[2026-09-15 09:36:34.927][response][INFO] (register_verification_email) POST /identity/accounts/register/send-verification-email => 400 Bad Request
[2026-09-15 09:36:34.967][request][INFO] POST /admin/invite
[2026-09-15 09:36:34.968][response][INFO] (invite_user) POST /admin/invite application/json => 200 OK
[2026-09-15 09:36:34.981][request][INFO] POST /identity/accounts/register/send-verification-email
[2026-09-15 09:36:34.984][response][INFO] (register_verification_email) POST /identity/accounts/register/send-verification-email => 200 OK

Teardown: docker rm -f vwspike; rm -rf /tmp/vwspike /tmp/vw.sh /tmp/vw2.sh /tmp/vwtok /tmp/vwjar /tmp/vwjar2 /tmp/vwreg.json in 9202; image vaultwarden/server:1.36.0-alpine left pulled in 9202 (scratch).
