1
0
Fork 0
Test fork
Datei suchen
Jeremy Lin c476e19796 Add email notifications for incomplete 2FA logins
An incomplete 2FA login is one where the correct master password was provided,
but the 2FA token or action required to complete the login was not provided
within the configured time limit. This potentially indicates that the user's
master password has been compromised, but the login was blocked by 2FA.

Be aware that the 2FA step can usually still be completed after the email
notification has already been sent out, which could be confusing. Therefore,
the incomplete 2FA time limit should be long enough that this situation would
be unlikely. This feature can also be disabled entirely if desired.
2021-10-28 00:19:43 -07:00
.github Optimize release workflow. 2021-09-13 14:42:15 +02:00
docker Update web vault to 2.24.1 2021-10-27 22:46:12 +02:00
hooks Optimize release workflow. 2021-09-13 14:42:15 +02:00
migrations Add email notifications for incomplete 2FA logins 2021-10-28 00:19:43 -07:00
resources Storing the original Vaultwarden svg images 2021-07-04 18:37:01 +02:00
src Add email notifications for incomplete 2FA logins 2021-10-28 00:19:43 -07:00
tools global_domains.py: allow syncing to a specific Git ref 2021-02-03 12:20:44 -08:00
.dockerignore Misc changes. 2021-03-30 21:45:10 +02:00
.editorconfig Misc changes. 2021-03-30 21:45:10 +02:00
.env.template Add email notifications for incomplete 2FA logins 2021-10-28 00:19:43 -07:00
.gitattributes Just ignore scripts 2021-04-01 20:44:58 +01:00
.gitignore Rename included .env file to .env.template and ignored .env 2019-01-06 22:50:30 +01:00
.hadolint.yaml add hadolint config file 2019-07-05 11:06:44 +02:00
.pre-commit-config.yaml Update some JS Libraries and fix small issues 2021-09-18 19:49:44 +02:00
build.rs Fix branch name 2021-04-28 21:46:20 +02:00
Cargo.lock Update dependencies 2021-10-24 21:50:26 +02:00
Cargo.toml Update dependencies 2021-10-24 21:50:26 +02:00
diesel.toml Updated dependencies and created 'rust-toolchain', to mark a working nightly to rustup users, and hopefully avoid some nightly breakage. 2018-06-12 17:30:36 +02:00
Dockerfile Change Dockerfiles to make the AMD image multidb 2020-08-24 20:58:00 +02:00
LICENSE.txt Upload and download attachments, and added License file 2018-02-15 00:40:34 +01:00
README.md Update README.md 2021-09-25 13:10:06 +03:00
Rocket.toml Document configuration a bit and increase JSON size limit to 10MB 2018-06-29 23:11:15 +02:00
rust-toolchain Update dependencies 2021-10-18 22:14:29 +02:00
rustfmt.toml Modify rustfmt file 2021-04-06 21:54:42 +01:00
SECURITY.md Adding a SECURITY.md 2021-06-26 11:49:00 +02:00

Alternative implementation of the Bitwarden server API written in Rust and compatible with upstream Bitwarden clients*, perfect for self-hosted deployment where running the official resource-heavy service might not be ideal.

📢 Note: This project was known as Bitwarden_RS and has been renamed to separate itself from the official Bitwarden server in the hopes of avoiding confusion and trademark/branding issues. Please see #1642 for more explanation.


Docker Pulls Dependency Status GitHub Release GPL-3.0 Licensed Matrix Chat

Image is based on Rust implementation of Bitwarden API.

This project is not associated with the Bitwarden project nor 8bit Solutions LLC.

⚠️IMPORTANT⚠️: When using this server, please report any bugs or suggestions to us directly (look at the bottom of this page for ways to get in touch), regardless of whatever clients you are using (mobile, desktop, browser...). DO NOT use the official support channels.


Features

Basically full implementation of Bitwarden API is provided including:

  • Organizations support
  • Attachments
  • Vault API support
  • Serving the static files for Vault interface
  • Website icons API
  • Authenticator and U2F support
  • YubiKey and Duo support

Installation

Pull the docker image and mount a volume from the host for persistent storage:

docker pull vaultwarden/server:latest
docker run -d --name vaultwarden -v /vw-data/:/data/ -p 80:80 vaultwarden/server:latest

This will preserve any persistent data under /vw-data/, you can adapt the path to whatever suits you.

IMPORTANT: Some web browsers, like Chrome, disallow the use of Web Crypto APIs in insecure contexts. In this case, you might get an error like Cannot read property 'importKey'. To solve this problem, you need to access the web vault from HTTPS.

This can be configured in vaultwarden directly or using a third-party reverse proxy (some examples).

If you have an available domain name, you can get HTTPS certificates with Let's Encrypt, or you can generate self-signed certificates with utilities like mkcert. Some proxies automatically do this step, like Caddy (see examples linked above).

Usage

See the vaultwarden wiki for more information on how to configure and run the vaultwarden server.

Get in touch

To ask a question, offer suggestions or new features or to get help configuring or installing the software, please use the forum.

If you spot any bugs or crashes with vaultwarden itself, please create an issue. Make sure there aren't any similar issues open, though!

If you prefer to chat, we're usually hanging around at #vaultwarden:matrix.org room on Matrix. Feel free to join us!

Sponsors

Thanks for your contribution to the project!

netdadaltd
netDada Ltd.

Chono N
Chris Alfano