Third-Party Apps' Email-Based Authentication Vulnerabilities Exposed
Third-party apps must delete user data after account deactivation to prevent domain vulnerabilities. Adding claims/properties won't solve the problem & may create complexity. Consumers should know who's handling their data & take steps to protect it.