mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-04-26 01:35:54 +03:00
[GH-ISSUE #1608] Chrome extension bypasses 2fa ?! #1015
Labels
No labels
SSO
Third party
better for forum
bug
bug
documentation
duplicate
enhancement
future Vault
future Vault
future Vault
good first issue
help wanted
low priority
notes
pull-request
question
troubleshooting
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/vaultwarden#1015
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @H4R0 on GitHub (Apr 14, 2021).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/1608
Subject of the issue
Chrome Bitwarden extension is not asking for 2fa method on login anymore.
This started 2 days ago after I upgraded to bitwardenrs/server:latest
The Desktop Client as well as the Web Vault is asking for 2fa method.
How can 2fa even be bypassed ?! The Extension is LOGGED OUT not LOCKED !
bitwarden_rs version: https://hub.docker.com/layers/bitwardenrs/server/latest/images/sha256-20dfe5e0abf10febf01510a8a97a639372b933bfcb215b6a3a46fc09246b5f77
Install method: Docker
Clients used: https://chrome.google.com/webstore/detail/nngceckbapebfimnlniiiahkandclblb
Steps to reproduce
Setup 2fa with email or anything else and login using the chrome extension.
Expected behaviour
Client should ask for 2fa
Actual behaviour
Client logs in without asking for 2fa
Troubleshooting data
The container log differs for both logins.
Chrome Extension not asking for 2fa:
Desktop Client asking for 2fa:
@jjlin commented on GitHub (Apr 14, 2021):
You probably enabled
Remember me; see https://bitwarden.com/help/article/twostep-faqs/#q-why-is-bitwarden-not-asking-for-my-enabled-two-step-login-method.@H4R0 commented on GitHub (Apr 14, 2021):
Thanks a lot, must have clicked it by accident.
Settings → My Account -> Deauthorize Sessions