1
Mysterious Webauth issue solved
Source: dani-garcia/vaultwarden#3708 · opened by @NeoLizzard
Greetings, I had now a couple of hours sacrificed into checking on a very strange problem and just figured it out and wanted to share my finding. I have a private instance of vaultwarden and setup another one in a bigger environment. Moved my configuration (all tested and working) into the new one - everything was fine aswell... except webauth with yubikey. For whatever reason I got all the time the information, that based on CSP (sameorigin) the auth process was blocked from loading. Browser vault was working, at home it was working, but in the new environment it was not (on the clients desktop app). And I just couldn't wrap my head around why. Then I noticed that in that environment (not setup by me, except for the vaultwarden server) the clients, who connected have been not getting the bitwarden client from the bitwarden website - instead they have been using the windows store one... While doing my research I learned that vaultwarden handles his CSP by himself…
No pledges yet. Be the first to back this.
Comments
Similar requests
Additional configuration for hardening 2FA
2 votes · 0 comments
Allow configuring WebAuthn userVerification (currently hardcoded to "discouraged")
1 vote · 0 comments
Add support for Bitwarden-style passkey login (WebAuthn / PRF)
3 votes · 0 comments
[Docs] Example caddy configuration breaks Webauthn login
3 votes · 0 comments
Support log in and decrypt with passkeys
90 votes · 0 comments
No comments yet.