When a federated user's local password hash is stale (e.g. they changed their password on the home instance and sync failed), the login handler now falls back to verifying credentials against the home instance. If the home instance accepts the password, the local hash is silently updated without touching passwordChangedAt, so existing valid JWTs remain valid.