FeatureFuel
2

Feature Request: Audit logging for successful personal vault logins

Source: dani-garcia/vaultwarden#6953 · opened by @potfile0
Summary Vaultwarden currently does not log successful personal vault login events, creating a significant security audit gap. Current Behavior The following events ARE logged: • Failed admin token attempts • Rate limiting events • Registration attempts • Organizational events (via existing audit log feature #2868) The following are NOT logged: • Successful personal vault logins • Which vault items were accessed/viewed • Vault item modifications by authenticated users Security Impact Without successful login logging: • Cannot detect unauthorized account access after the fact • Cannot investigate security incidents meaningfully • No audit trail for compliance requirements (GDPR, SOC2, HIPAA) • Attacker can access vault repeatedly with zero evidence in logs • The most sensitive service in a self hosted stack produces zero evidence of successful unauthorized access Proposed Solution In…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests