authentication_policy: fix credential recovery on password expiration

Credential Recovery are supposed to be related to persons, not logins.
Extend the tests to make sure that after the credential recovery is
accepted a reset password email is sent and fix authentication_policy
scripts to create a Credential Recovery related to the person.
6 jobs for fix/authentication_policy_create_recovery_on_expiration
in 0 seconds, using 0 compute credits, and was queued for 0 seconds