mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-02-05 00:29:40 +03:00
Autofilling on /#/settings/security/change-password will expose password
#1722
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @bilogic on GitHub (Sep 29, 2023).
While trying to test out multi user behavior, I saved the various user passwords into my vault.
When loading
/#/settings/security/change-password, the Chrome extension autofills theCurrent master passwordandMaster password hint. The problem is,Master password hintis in plain text and it exposes the autofilled password.Is there a way to break this behavior? Preferrably on just this page, perhaps by renaming the
inputtag'sidthat ismasterPasswordHintto something else?Your environment (Generated via diagnostics page)
Config (Generated via diagnostics page)
Show Running Config
Environment settings which are overridden: