mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-02-05 00:29:40 +03:00
web-vault v2024.12.0 Manage role permission issue #2125
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Misterbabou on GitHub (Jan 8, 2025).
Vaultwarden Support String
Your environment (Generated via diagnostics page)
Config & Details (Generated via diagnostics page)
Show Config & Details
Environment settings which are overridden: DOMAIN, TRASH_AUTO_DELETE_DAYS, ORG_CREATION_USERS, EMERGENCY_ACCESS_ALLOWED, ADMIN_TOKEN, INVITATION_ORG_NAME, DISABLE_2FA_REMEMBER
Config:
Vaultwarden Build Version
v1.32.7-bc913d11
Deployment method
Build from source
Custom deployment method
No response
Reverse Proxy
No proxy
Host/Server Operating System
Linux
Operating System Version
Ubuntu 22.04
Clients
Web Vault
Client Version
No response
Steps To Reproduce
Issue 1:
Groupsand create a new group and link the new collection withCan editpermission and pressSaveCollectionsthe permission show isCan manageinstead ofCan editIssue 2:
collectionstab link the new collection withCan managePermission and pressSaveCollectionsthe permission show isCan editinstead ofCan manageExpected Result
Keep the permission previously set in the web-vault
Actual Result
Can managebecomeCan editCan editbecomeCan manageLogs
No response
Screenshots or Videos
No response
Additional Context
Thanks for the work added in #5219
The feature might not be added yet but for now, users with
Can managepermissions (on collection) can't manage collection in the Password Manager.On Vaulwarden Side:

(note Issue 1 and 2 prevent me to have a
Can Managein User permission and aCan editin group permission)User vault:

user can't edit the Collection even if they have
Can managepermissionOn Bitwarden side:

User vault:

User can edit the collection with
Can managepermission@BlackDex commented on GitHub (Jan 8, 2025):
I'm not sure how you got the
Can Managerights for users, since that is currently not something Vaultwarden supports, and thus have this function. It only works for Owners, Admins and Managers which have access_all rights currently, which means, for users this doesn't work.This is the same as reported in #5361.
Which in the end means, we need to add support for this specific cbac (Collection based access control) or whatever we want to call it.
@BlackDex commented on GitHub (Jan 8, 2025):
FYI @chrpinedo
@Misterbabou commented on GitHub (Jan 8, 2025):
I understand that Collection based access control is not implemented yet.
However the UI behavior described above might be an issue in the future as it change Permission (at least on UI side):
For Members permission
Can managebecomeCan editafter a save. I didn't manage to setCan manageFor Groups permission
Can editbecomeCan manageafter a save. I didn't manage to setCan editSee the Steps to reproduce above
@raultaboraz commented on GitHub (Jan 21, 2025):
I have exactly the same issue (I opened by mistake a thread in Bitwarden forum)