Ive been using "unverifyUserEmail" during testing but it seems this does not update the current token / cookies, even calling refresh it seems the cookies are not updated. Is there a call required to refresh the claims on the current session after calling unverifyEmail?