Skip to content

Master password re-prompt does not prevent viewing of note content on Android #5263

@GideonBear

Description

@GideonBear

Steps To Reproduce

  1. Go to "My vault"
  2. Click on "Secure note"
  3. Click on "+"
  4. Write a title and note
  5. Click on "Additional options"
  6. Enable "Master password re-prompt"
  7. Click "Save"
  8. Click the newly created note

Expected Result

The note content to be inaccessible before the master password is re-entered, in accordance to the "Master password re-prompt" option, and consistent with the browser extension.

Actual Result

The note content is visible without re-entering the master password. The master password is only required to edit the note.

Screenshots or Videos

No response

Additional Context

This is not a duplicate of #5153. #5153 is about hidden field history, this is about the secure note "Note" field. (nothing to do with the edit history)
This is not a duplicate of #4549. #4549 is about hidden fields (only directly after creation?), this is about the secure note "Note" field, being visible all the time.

I believe this is a bug and not a feature request, because:

  • The expected behavior is there on desktop
  • The current behavior is obviously harmful to privacy
  • The text "Master password re-prompt" does not convey that it is still possible to view the note, and this behavior can thus be unexpected for many users.

Even though this behavior is documented, not many people read this documentation.

Prior reports:
#5226
https://community.bitwarden.com/t/secure-notes-visible-in-view-even-when-master-pw-is-enabled-for-editing/47825/4

ping @StellarGuardian

Build Version

2025.4.0 (20100)

What server are you connecting to?

US

Self-host Server Version

No response

Environment Details

N/A

Issue Tracking Info

  • I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions