Empty NameID values were stored as '' and occupied the unique saml_subject index, causing duplicate-key failures on later logins. Reject blank NameIDs during assertion validation, return a clear error when a NameID is already linked to another account, and stop returning internal errors from the SAML consume endpoint. Signed-off-by: Sacha Al Himdani <sacha@probo.com>