FeatureFuel
1

Log Exports of the vault - restrict export of organisation

Source: dani-garcia/vaultwarden#6537 · opened by @4lexRed
Hi,

as far as I have noticed, exports of the vault are not logged.
Probably the export is only done by the client software with the cached data -
but maybe Bitwarden clients do send an info to the server that an export was requested?

Yet, exports through the vaultwarden web interface could be traceable.
(Log Entry: YYYY-MM-DD hh:mm:ss -- User X exported his entries)

Also restricting the option to export passwort entries that belong to an organisation would be great.
(An option like "only admins can export organisation entries")

Background is a data breach by a user who (very likely) exported all his available entries - including the ones belonging to the organisation.

Would be great to see if there are possibilities to prevent theft by organisation users.

Kind regards
Alex

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests