Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bitwarden browser extension opens new windows with master password reprompt #6418

Closed
1 task done
Voyage7082 opened this issue Sep 27, 2023 · 1 comment
Closed
1 task done
Labels
browser Browser Extension bug

Comments

@Voyage7082
Copy link

Voyage7082 commented Sep 27, 2023

Steps To Reproduce

Preconditions

  • Chromium based browser (e.g. Chrome, Brave, Edge) [not yet observed on Firefox?]
  • Bitwarden browser client installed (2023.9.1, likely to also affect 2023.9.0)
  • Vault unlocked with “Autofill on page load” enabled
  • Vault entry exists for affected website with both 1) “Master password re-prompt” enabled and 2) a matching URI for that website

Steps to Reproduce

  1. Open the affected website

Expected Result

No result / no autofill

Actual Result

If the page is loaded, Bitwarden opens in a new window (re)prompting the master password.

In some cases, interacting with the website (e.g. on one occasion, attempting to type an email in Gmail) causes the new window to repeatedly close and re-open the new windows.

This can appear at the forefront of the user’s screen, in effect ‘absorbing’ the user’s text input into the master password reprompt field.

Clicking back to the affected website or closing the new window does not prevent further input to that website causing further new-windows with master password reprompts to open.

Screenshots or Videos

An image is included below, showing an example of the new window in a red border (image courtesy @chraebsli)
270190507-86422e10-521a-47e8-a80e-edb9893e734a

Additional Context

Affected Websites/Browsers
This does not appear to affect every website. However, certain websites do appear affected (when the preconditions above are also met), including Bitwarden.com and several Google websites (observed on Maps, Calendar, Gmail, YouTube).

Likely Related
This behavior may be related to PR #5384, which I understand was merged into version of 2023.9.0 of the Bitwarden browser clients.

Workarounds
I have had some success with each of the following workarounds:

  1. Disabling “Autofill on page load” and restarting the browser; or
  2. Downgrading to a previous version of the Bitwarden browser client (in my case, to 2023.7.0).

Other Discussion
This behavior is similar to, or has also been discussed in, the below:
Link 1 - Community forum
Link 2 - Issue 6416 [possible duplicate]
Link 3 - Issue 6389 [closed due to inability to reproduce – missed step “Autofill on page load” required to be enabled]
Link 4 - Issue 6401 [closed due to inability to reproduce – missed step “Autofill on page load” required to be enabled]
Link 5 - Reddit
Link 6 - Reddit

Operating System

Windows, Linux

Operating System Version

Win11 22H2

Web Browser

Chrome, Microsoft Edge, Brave

Browser Version

117.0.5938.92

Build Version

2023.9.1

Issue Tracking Info

  • I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
@Voyage7082 Voyage7082 added browser Browser Extension bug labels Sep 27, 2023
@Voyage7082
Copy link
Author

Duplicate of #6416 / #6389 / #6401

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
browser Browser Extension bug
Projects
None yet
Development

No branches or pull requests

1 participant