Skip to content
Snippets Groups Projects
  1. Mar 22, 2023
  2. Mar 15, 2023
  3. Mar 11, 2023
  4. Mar 07, 2023
  5. Mar 06, 2023
  6. Mar 05, 2023
    • Jeremy Lin's avatar
      Add HEAD routes to avoid spurious error messages · d3626eba
      Jeremy Lin authored
      Rocket automatically implements a HEAD route when there's a matching GET
      route, but relying on this behavior also means a spurious error gets
      logged due to <https://github.com/SergioBenitez/Rocket/issues/1098>.
      
      Add explicit HEAD routes for `/` and `/alive` to prevent uptime monitoring
      services from generating error messages like `No matching routes for HEAD /`.
      With these new routes, `HEAD /` only checks that the server can respond over
      the network, while `HEAD /alive` also checks that the database connection is
      alive, similar to `GET /alive`.
      d3626eba
  7. Mar 04, 2023
    • BlackDex's avatar
      Admin token Argon2 hashing support · de157b26
      BlackDex authored
      Added support for Argon2 hashing support for the `ADMIN_TOKEN` instead
      of only supporting a plain text string.
      
      The hash must be a PHC string which can be generated via the `argon2`
      CLI **or** via the also built-in hash command in Vaultwarden.
      
      You can simply run `vaultwarden hash` to generate a hash based upon a
      password the user provides them self.
      
      Added a warning during startup and within the admin settings panel is
      the `ADMIN_TOKEN` is not an Argon2 hash.
      
      Within the admin environment a user can ignore that warning and it will
      not be shown for at least 30 days. After that the warning will appear
      again unless the `ADMIN_TOKEN` has be converted to an Argon2 hash.
      
      I have also tested this on my RaspberryPi 2b and there the `Bitwarden`
      preset takes almost 4.5 seconds to generate/verify the Argon2 hash.
      
      Using the `OWASP` preset it is below 1 second, which I think should be
      fine for low-graded hardware. If it is needed people could use lower
      memory settings, but in those cases I even doubt Vaultwarden it self
      would run. They can always use the `argon2` CLI and generate a faster hash.
      de157b26
  8. Mar 01, 2023
  9. Feb 28, 2023
  10. Feb 27, 2023
    • BlackDex's avatar
      Fix the web-vault v2023.2.0 API calls · 7ec00d38
      BlackDex authored
      - Supports the new Collection/Group/User editing UI's
      - Support `/partial` endpoint for cipher updating to allow folder and favorite update for read-only ciphers.
      - Prevent `Favorite`, `Folder`, `read-only` and `hide-passwords` from being added to the organizational sync.
      - Added and corrected some `Object` key's to the output json.
      
      Fixes #3279
      7ec00d38
  11. Feb 24, 2023
  12. Feb 23, 2023
  13. Feb 22, 2023
    • Jeremy Lin's avatar
      Fix vault item display in org vault view · 61183d00
      Jeremy Lin authored
      In the org vault view, the Bitwarden web vault currently tries to fetch the
      groups for an org regardless of whether it claims to have group support.
      If this errors out, no vault items are displayed.
      61183d00
  14. Feb 21, 2023
Loading