* Fixed an issue where migrate-email could be called when an admin already existed
* When logging in, ensure there is no bias towards username or password when rejecting
* Cleaned up some messaging around anonymous apis to ensure there are no attack vectors.