2
Feature Request: Audit logging for successful personal vault logins
Source: dani-garcia/vaultwarden#6953 · opened by @potfile0
Summary Vaultwarden currently does not log successful personal vault login events, creating a significant security audit gap. Current Behavior The following events ARE logged: • Failed admin token attempts • Rate limiting events • Registration attempts • Organizational events (via existing audit log feature #2868) The following are NOT logged: • Successful personal vault logins • Which vault items were accessed/viewed • Vault item modifications by authenticated users Security Impact Without successful login logging: • Cannot detect unauthorized account access after the fact • Cannot investigate security incidents meaningfully • No audit trail for compliance requirements (GDPR, SOC2, HIPAA) • Attacker can access vault repeatedly with zero evidence in logs • The most sensitive service in a self hosted stack produces zero evidence of successful unauthorized access Proposed Solution In…
No pledges yet. Be the first to back this.
Comments
Similar requests
Feature request: Include user email in successful login logs
3 votes · 0 comments
Publish a fork of the Bitwarden web browsers extension to allow usage of multiple logins
2 votes · 0 comments
Re-License of Vaultwarden to AGPLv3
26 votes · 0 comments
First-class Auth Method abstraction for OAuth/SSO logins (WeChat, Google, etc.)
1 vote · 0 comments
Feature Request: Map OIDC group claims to Collections (post-authentication)
9 votes · 0 comments
No comments yet.