Feature Request: Whitelisting OTP Email whitelisting #1678

Closed
opened 2026-04-05 19:39:13 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @jimmy-ck on 3/25/2025

Pangolin shows the user who is trying to insert a non-whitelisted email that the email is not whitelisted explicitly. This opens the door to try out multiple addresses and get a potential positive feedback if they are whitelisted or not.
I prefer Cloudflare's approach of just showing the user in general that OTP password has been sent but only actually sends the OTP in the background, if the address is whitelisted.

What do you think about that?

https://developers.cloudflare.com/cloudflare-one/identity/one-time-pin/

By design, blocked users will not receive an email. The login page will always say A code has been emailed to you, regardless of whether or not an email was sent.

*Originally created by @jimmy-ck on 3/25/2025* Pangolin shows the user who is trying to insert a non-whitelisted email that the email is not whitelisted explicitly. This opens the door to try out multiple addresses and get a potential positive feedback if they are whitelisted or not. I prefer Cloudflare's approach of just showing the user in general that OTP password has been sent but **only** actually sends the OTP in the background, if the address is whitelisted. What do you think about that? [https://developers.cloudflare.com/cloudflare-one/identity/one-time-pin/](https://developers.cloudflare.com/cloudflare-one/identity/one-time-pin/) > By design, blocked users will not receive an email. The login page will always say A code has been emailed to you, regardless of whether or not an email was sent.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/pangolin#1678