Commit graph

  • 169aa5efcc
    Misc updates and fixes (#7406) Mathijs van Veluw 2026-07-08 22:10:29 +02:00
  • 64d28ab66e
    improve CI (#6991) Denis Pisarev 2026-07-08 22:08:20 +02:00
  • 89a25c4e12
    Merge branch 'main' of https://github.com/dani-garcia/vaultwarden into feat/webauthn_login Raphaël Roumezin 2026-07-08 13:59:48 +02:00
  • a711aa1274
    Update MSRV to v1.94.1 BlackDex 2026-07-08 19:26:08 +02:00
  • f7df02b483
    Misc updates and fixes BlackDex 2026-07-08 19:13:15 +02:00
  • 4720cdbe86
    Add pm-26340-linux-biometrics-v2 feature flag (#7358) pilotstew 2026-07-07 08:59:57 -05:00
  • 5447ee6af2
    SSO use ClientSecretPost if ClientSecretBasic is not available (#7357) Timshel 2026-07-07 15:59:48 +02:00
  • 5c5e8e1a6f
    2026.6.0 send support (#7346) Timshel 2026-07-07 15:59:36 +02:00
  • 7320a1db4b
    PutPolicy now using vnext format (#7296) Timshel 2026-07-07 15:59:26 +02:00
  • a058a35ccd
    [v2026.5.0] Registration request update (#7295) Timshel 2026-07-07 15:59:17 +02:00
  • a16b5afaaa
    Org membership delete remove Invitation (#7284) Timshel 2026-07-07 15:59:06 +02:00
  • fddc16d2b8
    fix(sends): emit hideEmail as non-null boolean in sync response (#7283) kvdb 2026-07-07 15:58:54 +02:00
  • ec7fa137b7
    Admin password recovery endpoint change (#7270) Timshel 2026-07-07 15:58:41 +02:00
  • b25f715364
    Fix enforce blocked (#7246) Timshel 2026-07-07 15:58:34 +02:00
  • 9e4aa5efe7
    feat: Added support for passkey vault unlock feature Raphaël Roumezin 2026-06-30 11:07:00 +02:00
  • c99ffe3d83 Review fix Timshel 2026-06-29 10:09:52 +02:00
  • 7dbd82a311 add Zenith Hosting badge l1mey112 2026-06-29 16:53:04 +10:00
  • 055cb61888 Don't block the login response on the new-device email max 2026-06-28 21:07:45 +02:00
  • 5261bd7b0d Review fixes Timshel 2026-06-27 23:16:30 +02:00
  • 3b669264bb
    fix(clippy): few refactors Raphael Roumezin 2026-06-27 16:55:05 +02:00
  • 05c9af4d1e
    fix: Allowed Chromium extensions as origins for passwordless login Raphael Roumezin 2026-06-27 16:30:32 +02:00
  • 9351e91de0 Do not fail login when push device registration fails max 2026-06-26 12:53:02 +02:00
  • 224ad8a406 fix: typos Raphaël Roumezin 2026-06-24 13:00:48 +02:00
  • 8cba57a1af feat(config): Add passkey_login_allowed config option Raphaël Roumezin 2026-06-24 11:44:53 +02:00
  • 007ac4f992 fix: Correct attestation options Raphaël Roumezin 2026-06-23 16:01:02 +02:00
  • 7711b02153 feat: passwordless login Raphaël Roumezin 2026-06-23 15:27:37 +02:00
  • d9695088c7
    Add Podman Quadlet instructions to Readme 4liceD 2026-06-23 10:37:15 +02:00
  • af02911b71 SSO use ClientSecretPost if ClientSecretBasic is not available Timshel 2026-06-23 08:24:33 +02:00
  • 409031715f
    Merge branch 'main' into pr/3x8_improve-ci Denis Pisarev 2026-06-22 11:07:13 +02:00
  • 995c96a55a Add pm-26340-linux-biometrics-v2 feature flag pilotstew 2026-06-21 09:28:53 -05:00
  • fb9e70b79f Use default to keep compatibility Timshel 2026-06-21 16:13:37 +02:00
  • 649ed31aa7 enable rocket/mtls feature Simonas Kazlauskas 2026-06-20 16:11:51 +03:00
  • 89dae0f082 fix: pin Debian MariaDB packages to 11.8.6 maxpetrusenkoagent 2026-06-18 16:36:13 -04:00
  • 8450af2094 Prevent creating and editing a Send with email verification Timshel 2026-06-18 19:52:09 +02:00
  • 4900b8fd81
    fix: use request-body OIDC auth Puria Nafisi Azizi 2026-06-18 03:02:12 +02:00
  • 64d943b625 2026.6.0 send support Timshel 2026-06-16 20:48:12 +02:00
  • dc82ad6d6c Pin Debian MariaDB client library maxpetrusenkoagent 2026-06-15 05:04:40 -04:00
  • 2c97b41e87
    fix(sends): emit hideEmail as non-null boolean in sync response Kees van den Broek 2026-06-01 11:04:42 +02:00
  • d0f6d297db Admin password recovery endpoint change Timshel 2026-05-28 14:11:07 +02:00
  • ca446d46b2 Fix enforce blocked Timshel 2026-05-20 19:42:55 +02:00
  • 00cc9f79b1 Registration request update Timshel 2026-06-03 15:12:21 +02:00
  • 77283882e1 PutPolicy now using vnext format Timshel 2026-06-03 16:26:48 +02:00
  • 283467f90e Add GET /public/events Bitwarden-compatible Public API endpoint svrforum 2026-06-09 10:56:16 +09:00
  • 1c91b8a8c9 Make get_continuation_token reusable across modules svrforum 2026-06-09 10:56:16 +09:00
  • 989fa9ac0d Add Event::to_json_public for Public API event model svrforum 2026-06-09 10:40:21 +09:00
  • f750116afa
    Merge branch 'main' into pr/3x8_cargo-deny Denis Pisarev 2026-06-08 14:24:12 +02:00
  • 3c584be7d0
    Fix invalid SSH key sync for Bitwarden 2026.5 MengYX 2026-06-06 12:28:27 +08:00
  • d6a3d539ed
    Update Rust, Crates and GHA (#7307) Mathijs van Veluw 2026-06-05 21:52:52 +02:00
  • 660a02db4a
    Update Rust, Crates and GHA BlackDex 2026-06-05 17:39:16 +02:00
  • b999841de0
    Ignore RUSTSEC-2026-0098, -0099, -0104 in deny.toml TriplEight 2026-06-04 15:23:01 +02:00
  • 727fead3a0 playwright: pin webauthn-grant 2FA-usability gate Zaid Marji 2026-06-02 19:13:27 +03:00
  • e94b8556c8 playwright: disabled-account passkey login coverage Zaid Marji 2026-06-01 23:38:46 +03:00
  • fcef37bfc7 webauthn: concurrent-modification handling + login error helpers Zaid Marji 2026-06-02 18:18:46 +03:00
  • 6be69056d1 2FA: harden enforce_2fa_policy for unauthenticated callers Zaid Marji 2026-05-31 13:24:50 +03:00
  • 019a1adf98 webauthn: passkey-management module + login hardening + Result-typed 2FA lookups Zaid Marji 2026-06-02 19:09:41 +03:00
  • b5678daf8e webauthn: harden passkey management flows Zaid Marji 2026-06-02 17:43:24 +03:00
  • 247a8905d8 Fix correctness, test reliability, and observability issues Zaid Marji 2026-06-02 19:08:20 +03:00
  • 58bbc2d533 playwright: passkey UI flow tests + SSO_ONLY denial coverage Zaid Marji 2026-05-29 11:59:58 +03:00
  • 6522923cdb playwright: account lifecycle test + host-iteration config Zaid Marji 2026-05-28 07:34:36 +03:00
  • 2d59e7e631 playwright: implement fido2 + auto-pick 2FA provider in submitTwoFactor Zaid Marji 2026-05-28 07:34:11 +03:00
  • 524194bbf4 config: advertise pm-2035-passkey-unlock feature flag Zaid Marji 2026-05-28 07:19:37 +03:00
  • 3f96c26322 two_factor/webauthn: gate every entry point with is_webauthn_2fa_supported Zaid Marji 2026-05-27 15:04:05 +03:00
  • a75273d40f playwright: cover PRF login-passkey enrolment via Chromium virtual authenticator Zaid Marji 2026-05-27 06:17:23 +03:00
  • 6f2751ee79 Align UserDecryption response shapes with upstream Bitwarden Zaid Marji 2026-06-02 18:15:15 +03:00
  • c489186e4f Add playwright tests for passkey login Zaid Marji 2026-05-24 06:04:07 +03:00
  • a7dd529f1f
    Merge branch 'main' into pr/3x8_cargo-deny Denis Pisarev 2026-06-04 14:55:56 +02:00
  • 95d2a73671 Fix local attachment download endpoint Puneet Dixit 2026-06-04 14:53:21 +05:30
  • 89a9ef9afa Prevent duplicate passkey credential registration Zaid Marji 2026-05-23 12:51:55 +03:00
  • ced3520def Harden passkey login flow Zaid Marji 2026-05-24 14:09:04 +03:00
  • f728963aaa Tighten passkey credential persistence and enrollment Zaid Marji 2026-05-24 14:16:42 +03:00
  • 3ab20f1f41 Centralize SSO_ONLY enforcement (deny-by-default) Zaid Marji 2026-06-02 17:43:12 +03:00
  • 5760ade325 Fix and harden the passkey login implementation Zaid Marji 2026-06-02 17:43:12 +03:00
  • 912c31324c
    set user_created bool for each separate invitation stefan0xC 2026-06-02 06:11:55 +02:00
  • 21eafd0dde
    don't auto-enable signups via allowed domains list stefan0xC 2026-06-02 05:57:28 +02:00
  • 2706e9be3a Org membership delete remove Invitation Timshel 2026-06-01 12:06:55 +02:00
  • 896952a5ad fix: CVE-2026-27803 security vulnerability orbisai0security 2026-05-30 04:49:24 +00:00
  • ff85ddff73 fix: the build tool tools/global_domains in global_domains.py orbisai0security 2026-05-30 03:11:26 +00:00
  • 45ea185f48 fix: V-001 security vulnerability orbisai0security 2026-05-30 03:10:18 +00:00
  • 1cdf0b7b86 Feat add webauthn login Sammy ETUR 2026-02-12 04:31:09 +01:00
  • 88ab51443a playwright: centralize 2FA challenge handling Zaid Marji 2026-05-27 11:14:30 +03:00
  • ad582b460a playwright: centralize web-vault selectors into shared setup helpers Zaid Marji 2026-05-27 10:03:29 +03:00
  • 0c009d679d playwright: fix invitation-accepted toast text + SSO existing-account redirect Zaid Marji 2026-05-26 07:22:37 +03:00
  • 9186ec245b playwright: fix stale org-nav selectors against bundled web vault Zaid Marji 2026-05-26 03:46:59 +03:00
  • a3fb02776d gitignore: catch stray playwright artifacts at the repo root Zaid Marji 2026-05-24 10:42:41 +03:00
  • f30847d15e playwright: serve the test Vaultwarden over HTTPS Zaid Marji 2026-05-24 10:24:07 +03:00
  • c02ced432d playwright: fix TOTP setup flow against bundled web vault Zaid Marji 2026-05-24 10:23:45 +03:00
  • c0589bbd74 playwright: fix stale Master password selectors against bundled web vault Zaid Marji 2026-05-24 10:22:49 +03:00
  • a9893d60a3
    http_client: don't panic on invalid block regex; use RwLock Pham Quang Nghi 2026-05-20 18:26:45 +07:00
  • d626ea81ab
    Serve Apple app site association file (#7191) user71424q 2026-05-17 19:46:10 +00:00
  • be5bff1247
    Merge 34feefa9f8 into 1ba2c6a26c Daniel 2026-05-17 20:48:22 +02:00
  • 1ba2c6a26c
    Switch to Edition 2024, more clippy lints, and less macro calls (#7200) Mathijs van Veluw 2026-05-17 19:38:49 +02:00
  • 95c413d58d
    Remove "db_run!" macro calls where possible BlackDex 2026-05-08 18:12:00 +02:00
  • b3861e8765
    Reorder and merge imports BlackDex 2026-05-08 17:16:47 +02:00
  • 83317d90b7
    Update to Rust 2024 Edition Mathijs van Veluw 2026-05-02 18:56:15 +02:00
  • bec8ce5331 revert cors rwjack 2026-03-30 13:46:58 +02:00
  • c760e63a9b add trusted device verification: https://github.com/dani-garcia/vaultwarden/discussions/6655 rwjack 2026-03-30 00:52:07 +02:00
  • c7d6abe849
    Merge branch 'main' into jueti-patch-1 Jason Yang 2026-05-17 15:03:32 +08:00
  • f38ff95934
    Merge pull request #3 from jueti/main Jason Yang 2026-05-17 14:59:14 +08:00
  • 22f5e0496c
    Updates and fixes (#7235) Mathijs van Veluw 2026-05-17 00:43:58 +02:00
  • 48fe504b31
    Update datatables BlackDex 2026-05-16 15:30:34 +02:00