The user enters the email address or username associated with their account.
WordPress sends the time-limited link to that account’s email address.
FluentAuth checks that the token is valid, unexpired and unused.
The link is consumed. A required device challenge still applies before access is completed.
