another thought - has anyone migrated from another id provider (e.g. AWS Cognito) to kratos? I'm wondering if there is some flow (after importing all user ids) whereby if kratos can't authorise a user it could fallback to legacy auth provider (i.e. attempt to log user in via Cognito), and if that succeeds then apply the password that was just provided to the kratos user record