Organisation invite in Vaultwarden not working #3879
Replies: 3 comments 23 replies
|
Have you followed https://bitwarden.com/help/managing-users/#onboard-users Also the user need to create the account via the link with the token. Of they somehow didn't used that link, or revisited the page manually the invite will not be processed. If a user successfully used the invite, the status of that user will change, after which you can confirm the user. The rest is basically all explained in the link above. So if the state stays at invited, the user didn't used the link correctly. |
|
I followed the instructions from the link to the bone. (And in addition - it did work in the past aswell) In regards of the user - we did two test it also with a fresh new created user and a fresh installation (and a new organisation) - so everything from scratch - still same result. Something get stuck. And I can't figure out where or why. The "accept invitation" message appear (as expected) at user side - but the status get not changed and a email to admin get not send. |
|
Same issue here. Using Vaultwarden Addon of Home assistant. The invited person (a valid user) with a registered local vaultwarden account receives the email invitation in their mail inbox. Clicking the button "Join Organization Now" redirects to the home assistant login website. I login with Home Assitant username and password and i am on my homeassistant in the browser - and done. There is no message i would usually expect like "sucessfully added as user"... nothing. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Subject of the issue
Registered user in Vaultwarden get organisation invite email after beeing add by organisation administrator, but after clicking the join organisation link from mail user status in the backend doesn't change, even though message on user side appear saying "you successfully accept the organisation invitation. The status in the backend stay for the user at "invited" and there is no way to confirm that the invitation got accepted. Status doesn't change to pending or similar, as it did in the past.
Deployment environment
Your environment (Generated via diagnostics page)
Config (Generated via diagnostics page)
Show Running Config
Environment settings which are overridden:
{ "_duo_akey": null, "_enable_duo": false, "_enable_email_2fa": false, "_enable_smtp": true, "_enable_yubico": true, "_icon_service_csp": "", "_icon_service_url": "", "_ip_header_enabled": true, "_smtp_img_src": "cid:", "admin_ratelimit_max_burst": 3, "admin_ratelimit_seconds": 300, "admin_session_lifetime": 20, "admin_token": "***", "allowed_iframe_ancestors": "", "attachments_folder": "data/attachments", "auth_request_purge_schedule": "30 * * * * *", "authenticator_disable_time_drift": false, "data_folder": "data", "database_conn_init": "", "database_max_conns": 10, "database_timeout": 30, "database_url": "*****://**********************************************************************************************", "db_connection_retries": 15, "disable_2fa_remember": false, "disable_admin_token": false, "disable_icon_download": false, "domain": "*****://*************", "domain_origin": "*****://*************", "domain_path": "", "domain_set": true, "duo_host": null, "duo_ikey": null, "duo_skey": null, "email_attempts_limit": 3, "email_expiration_time": 600, "email_token_size": 6, "emergency_access_allowed": true, "emergency_notification_reminder_schedule": "0 3 * * * *", "emergency_request_timeout_schedule": "0 7 * * * *", "enable_db_wal": true, "event_cleanup_schedule": "0 10 0 * * *", "events_days_retain": null, "extended_logging": true, "helo_name": null, "hibp_api_key": null, "icon_blacklist_non_global_ips": true, "icon_blacklist_regex": null, "icon_cache_folder": "data/icon_cache", "icon_cache_negttl": 259200, "icon_cache_ttl": 2592000, "icon_download_timeout": 10, "icon_redirect_code": 302, "icon_service": "internal", "incomplete_2fa_schedule": "30 * * * * *", "incomplete_2fa_time_limit": 3, "invitation_expiration_hours": 120, "invitation_org_name": "*********", "invitations_allowed": false, "ip_header": "X-Real-IP", "job_poll_interval_ms": 30000, "log_file": "/data/vaultwarden.log", "log_level": "error", "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f", "login_ratelimit_max_burst": 10, "login_ratelimit_seconds": 60, "org_attachment_limit": null, "org_creation_users": "********************,*********************", "org_events_enabled": false, "org_groups_enabled": false, "password_hints_allowed": false, "password_iterations": 600000, "push_enabled": false, "push_installation_id": "***", "push_installation_key": "***", "push_relay_uri": "https://push.bitwarden.com", "reload_templates": false, "require_device_email": true, "rsa_key_filename": "data/rsa_key", "send_purge_schedule": "0 5 * * * *", "sendmail_command": null, "sends_allowed": false, "sends_folder": "data/sends", "show_password_hint": false, "signups_allowed": false, "signups_domains_whitelist": "******,********,*********", "signups_verify": true, "signups_verify_resend_limit": 3, "signups_verify_resend_time": 86400, "smtp_accept_invalid_certs": true, "smtp_accept_invalid_hostnames": false, "smtp_auth_mechanism": "plain", "smtp_debug": false, "smtp_embed_images": true, "smtp_explicit_tls": null, "smtp_from": "******************", "smtp_from_name": "Vault Warden Passwortmanager", "smtp_host": "***********", "smtp_password": null, "smtp_port": 25, "smtp_security": "starttls", "smtp_ssl": null, "smtp_timeout": 60, "smtp_username": null, "templates_folder": "data/templates", "tmp_folder": "data/tmp", "trash_auto_delete_days": 4, "trash_purge_schedule": "0 5 0 * * *", "use_sendmail": false, "use_syslog": false, "user_attachment_limit": 1024000, "web_vault_enabled": true, "web_vault_folder": "web-vault/", "websocket_address": "0.0.0.0", "websocket_enabled": true, "websocket_port": 3012, "yubico_client_id": "********", "yubico_secret_key": "***", "yubico_server": "https://api2.yubico.com" }Steps to reproduce
Create Organisation
Add Domains in Administration interface for domains to be able to accept invites
Invite user to vaultwarden
Enable MFA for user account (yubikey)
Change Organisation settings policy to:
(rest default)
Expected behaviour
User click invitation link for organisation, admin get notification, accept the pending request, user get access to organisation
Actual behaviour
User click invitation link for organisation, get confirmation that his link invite got processed successfully - nothing else happens (user stay at invited state in backend from administrator perspective)
Troubleshooting data
All reactions