Single sign-on means trusting the identity provider. We trusted it for one thing too many: we resolved returning federated users by the email in the assertion, so any connection could assert someone else's address and land on their account. The fix wasn't more validation. It was changing the identity join key from email to a per-provider subject the asserting party can't forge.