ajrosen / Bitwarden-Accelerator

Alfred Workflow to make using Bitwarden faster and smoother with all applications
GNU General Public License v3.0
44 stars 1 forks source link

Password handling #10

Closed blacs30 closed 5 months ago

blacs30 commented 6 months ago

I have switched back to your workflow. Impressive jq work undearneath ! I enabled debug mode and saw my Bitwarden password. It would be great if the Bitwarden masterpassword as well as the yubikey otp (if used) is not passed around but used directly. Reduces the attack surface and gives little bit more peace of mind IMO.

ajrosen commented 6 months ago

The values are only visible in Alfred's debugger (or log file if the workflow's DEBUG variable is 1). It won't take too much to keep them hidden.

And thanks, I love jq :)

ajrosen commented 5 months ago

Addressed in Release 4.1.2 #11