Timshel / vaultwarden

Fork from dani-garcia/vaultwarden to add OpendID support.
GNU Affero General Public License v3.0
87 stars 12 forks source link

SSO enabled - Masterpassword still requested #38

Closed Estradamis closed 8 months ago

Estradamis commented 8 months ago

Hey all,

today I deployed the SSO enabled Vaultwarden to try it out. When using SSO, it first asks for userID which is fine and creates the account - but then it asks for a master password as well as with each login, the MasterPassword is required (I hoped that this can be avoided with SSO, correct me if I'm wrong?).

In the admin config, I have checked Disable Email+Master Password login

Estradamis commented 8 months ago

nvm - I should read the comments provided in the vaultwarden discussion. Sorry :)

arabezar commented 3 months ago

Hi @Estradamis, And what was the issue? I have the same behavior, still cannot figure it out :( I'll appreciate if you could provide a link to that discussion please

Estradamis commented 3 months ago

Hi @Estradamis, And what was the issue? I have the same behavior, still cannot figure it out :( I'll appreciate if you could provide a link to that discussion please

@arabezar there is no issue, this is intended behavior and described in the discussion, so you cannot get around it

arabezar commented 3 months ago

there is no issue, this is intended behavior and described in the discussion, so you cannot get around it

Hmm... Probably we are talking about different things. I have no problem to enter password one time when logging in... I would like not no enter password every time I refresh the web page. Even when logging with SSO (with master password) for the 1st time, the web page is automaticaly refreshed requiring master password to enter in order to unlock the blocked site. (( Same request I get each time when trying to refresh the browser web page with F5.