bitwarden / mobile

Retired Bitwarden mobile app for iOS and Android (MAUI/Xamarin).
https://bitwarden.com
GNU General Public License v3.0
24 stars 3 forks source link

One-time key from YubiKey NFC not written to input during 2FA from iPhone AutoFill Passwords #2085

Open YBRCPtSXmwloooFv9E1239PpOLeSh1Wp1LnJ36T opened 1 year ago

YBRCPtSXmwloooFv9E1239PpOLeSh1Wp1LnJ36T commented 1 year ago

Steps To Reproduce

  1. Go to a mobile app with 2FA
  2. Tap on Password field
  3. Tap on Password button
  4. Log in to Bitwarden after redirect
  5. Scan YubiKey

Expected Result

Generate one-time key, and Continue option to turn opaque.

Actual Result

iPhone notification "Firefox NFC Tag: Open in Firefox" appears.

Screenshots or Videos

The keyboard and Passwords button are not captured by the screenshot tool. 97FDFB01-444F-4732-8659-1050E0DE34E1_1_201_a 18960183-FD66-4386-948D-CF1CAA487361_1_201_a 4D7DED4E-1EDE-4E12-AFB4-7967800BE8EC_1_102_o 20615408-88F4-4F20-9AB6-352A71FD0A70_1_102_o

Additional Context

No response

Operating System

iOS

Operating System Version

15.6.1

Device

iPhone SE

Build Version

19G82

Beta

bDwSyFLFOSvPF4gp8n6bPv4ipFPd2CjDbtyxtqb commented 1 year ago

ha, that same exact totally annoying popup happens to me too: iOS 16.0.2, iPhone 14 Pro (but also happened on iOS 15 with iPhone 13 mini as well): I try using the yubikey NFC and i get the pop up redirecting me to a webpage (on Opera) and it does nothing for me : I get a validation option or an option to copy the 30+ character code, but I can't get into the place I want to get in to. :(

jJuZv5mAHyDCeg58I3JCrCnokELVyWSkBkqXA79 commented 1 year ago

Hello! I hope you're well!

I was able to confirm this bug and we are going to work on it ASAP. For now, the recommended work-around is to log into the Bitwarden app before you attempt to auto-fill, and setting your Vault Timeout Action to Lock instead of Logout would prevent the need for the hardware key to unlock each time.

Thanks for catching this and reporting it!

mpbw2 commented 1 year ago

@mtcarbon Thanks for the screenshots! Can you and @THEOCKID try tapping on the text entry (dark line directly above the Remember Me switch) to confirm the entry has focus before scanning your key? (This is supposed to happen automatically when that screen is first displayed but it doesn't look focused in the screenshot, which could be a bug on our part)

YBRCPtSXmwloooFv9E1239PpOLeSh1Wp1LnJ36T commented 1 year ago

@mp-bw Thanks for responding. I confirmed the entry had focus (was automatic, like you said it should be) and then got the same behavior.