Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BW for ipad- Master Password reprompt issue for logins and Credit Cards #9145

Open
1 task done
lyricist9232 opened this issue May 13, 2024 · 1 comment
Open
1 task done
Labels

Comments

@lyricist9232
Copy link

Steps To Reproduce

  1. Go to 'logins or credit cards'
  2. Click on 'specific login or credit card '
  3. Click on ‘edit’
  4. enable 'master password reprompt '
  5. Click on ‘save’
  6. Relaunch the app
  7. Go to the specific login or credit card you enabled the feature for
  8. Click on ‘edit’ or the ‘eye button’ to show password or show credit card number or any hidden field by default

Expected Result

Any action from step 8 should prompt the master password

Actual Result

It shows the hidden value and you can edit without prompting the master password

Screenshots or Videos

IMG_7153

Additional Context

Enabling the ‘reprompt master pass’ does function on other devices(synced with same BW account) like iPhone even when enabled from iPad or initially enabled from the iphone.
But doesn’t function on ipad if enabled from iphone. So the problem is in the iPad app.

Operating System

macOS

Operating System Version

iPadOS 17.4.1

Shell

Bash

Build Version

Bw 2024.4.2(7528)

Issue Tracking Info

  • I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
@lyricist9232 lyricist9232 added bug cli CLI Application labels May 13, 2024
@Krychaz Krychaz removed the cli CLI Application label May 14, 2024
@Krychaz
Copy link
Member

Krychaz commented May 14, 2024

Hello there,

Master password re-prompt will behave slightly differently depending on which app you're using, for example:

  • In the web app, accessing or editing anything about a vault item with this enabled will require you to re-enter your master password.
  • On browser extensions, desktop apps, and mobile apps, only viewing hidden fields (e.g. passwords, hidden custom fields, credit card numbers) will require you to re-enter your master password. Editing anything about the item will also require you to re-enter your master password.

Running 2024.2.1 I was prompted for master password whenever I tried to see a hidden item or tried to edit an entry that was protected by password reprompt.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants