🚀 Feature: Email Login Codes should be usable only on the device that requested them #563

Closed
opened 2026-02-04 20:28:44 +03:00 by OVERLORD · 0 comments
Owner

Originally created by @ItalyPaleAle on GitHub (Dec 8, 2025).

Feature description

For security reasons, email-based login codes should only be usable on the same device / browser that requested them.

Practically speaking, when users request an email login code for themselves, a cookie is set in the browser. The login code should be redeemable only if the cookie is available in the same browser.

Pitch

Other apps enforce similar requirements, as this prevents certain kinds of social engineering attacks.

Originally created by @ItalyPaleAle on GitHub (Dec 8, 2025). ### Feature description For security reasons, email-based login codes should only be usable on the same device / browser that requested them. Practically speaking, when users request an email login code for themselves, a cookie is set in the browser. The login code should be redeemable only if the cookie is available in the same browser. ### Pitch Other apps enforce similar requirements, as this prevents certain kinds of social engineering attacks.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/pocket-id#563