Organization items shows up in My Vault even when no access #1627

Closed
opened 2025-10-09 17:23:09 +03:00 by OVERLORD · 0 comments
Owner

Originally created by @assid2 on GitHub.

Subject of the issue

If you disable the collection from a user EVEN owner, then the items of the organization should not show up in "My Vault". The owner must go to the organization's vault to see the items

Your environment

  • Bitwarden_rs version: 1.16.3
  • Install method: Docker latest/postgresql
  • Clients used:
  • Reverse proxy and version:
  • Version of mysql/postgresql: postgresql
  • Other relevant information:

Steps to reproduce

N/A

Expected behaviour

Organization Vault details should not show up in "My Vault" for owners, if the the checkbox for the collection has not been enabled to them.. If they still need to access the information, they can go to the organization vault.

Actual behaviour

make 2 owners.. then for yourself.. set it to : This user can access only the selected collections.
and remove access to the collection. Once you do this the collection should not show up in your vault and you should have to go to the organizations vault

Relevant logs

Originally created by @assid2 on GitHub. <!-- Please fill out the following template to make solving your problem easier and faster for us. This is only a guideline. If you think that parts are unneccessary for your issue, feel free to remove them. Remember to hide/obfuscate personal and confidential information, such as names, global IP/DNS adresses and especially passwords, if neccessary. --> ### Subject of the issue <!-- Describe your issue here.--> If you disable the collection from a user EVEN owner, then the items of the organization should not show up in "My Vault". The owner must go to the organization's vault to see the items ### Your environment <!-- The version number, obtained from the logs or the admin page --> * Bitwarden_rs version: 1.16.3 <!-- How the server was installed: Docker image / package / built from source --> * Install method: Docker latest/postgresql * Clients used: <!-- if applicable --> * Reverse proxy and version: <!-- if applicable --> * Version of mysql/postgresql: postgresql * Other relevant information: ### Steps to reproduce <!-- Tell us how to reproduce this issue. What parameters did you set (differently from the defaults) and how did you start bitwarden_rs? --> N/A ### Expected behaviour <!-- Tell us what should happen --> Organization Vault details should not show up in "My Vault" for owners, if the the checkbox for the collection has not been enabled to them.. If they still need to access the information, they can go to the organization vault. ### Actual behaviour <!-- Tell us what happens instead --> make 2 owners.. then for yourself.. set it to : This user can access only the selected collections. and remove access to the collection. Once you do this the collection should not show up in your vault and you should have to go to the organizations vault ### Relevant logs <!-- Share some logfiles, screenshots or output of relevant programs with us. -->
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/vaultwarden#1627