1
Warm users about access key leakage in access logs
Source: dani-garcia/vaultwarden#4631 · opened by @rwjack
Not really a bug, but I think the docs should provide info about this:
I just saw that from v1.29.0, WSS is enabled by default, which means all access tokens and encrypted data is being stored in plaintext in reverse proxy access logs, unless the proxy is configured to filter out such requests.
I just saw that from v1.29.0, WSS is enabled by default, which means all access tokens and encrypted data is being stored in plaintext in reverse proxy access logs, unless the proxy is configured to filter out such requests.
No pledges yet. Be the first to back this.
Comments
Similar requests
Improve RSA key file generation and reads
1 vote · 0 comments
Browser extension API authentication, without 2FA
1 vote · 0 comments
Feature request: Include user email in successful login logs
3 votes · 0 comments
Use Send for Text only
1 vote · 0 comments
User account key rotation is not atomic
2 votes · 0 comments
No comments yet.