Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows desktop client shows email in upper right account info on login screen despite Remember email not being checked #10367

Open
1 task done
sylerner opened this issue Aug 1, 2024 · 4 comments
Labels
bug desktop Desktop Application

Comments

@sylerner
Copy link

sylerner commented Aug 1, 2024

Steps To Reproduce

  1. Go to 'login screen'
  2. Account information (email address and server) is shown in upper right corner in blue bar
  3. Email address field is empty (as it should be)
  4. Remember email is not checked

Expected Result

The account email address should not be displayed anywhere when logged out. Lack of the account's email address is a major part of vault security and is the reason many choose to not have their email address automatically filled into the email field.

Actual Result

The account's email address is compromised.

Screenshots or Videos

Additional Context

No response

Operating System

Windows

Operating System Version

Windows 11 Home 23H2

Installation method

Direct Download (from bitwarden.com)

Build Version

Version 2024.7.1, Shell 31.2.0, Renderer 126.0.6478.127, Node 20.15.0, Architecture x64

Issue Tracking Info

  • I understand that work is tracked outside of GitHub. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
@sylerner sylerner added bug desktop Desktop Application labels Aug 1, 2024
@sylerner
Copy link
Author

sylerner commented Aug 1, 2024

Bitwarden windows client

@TroyBW
Copy link

TroyBW commented Aug 2, 2024

Hi there,

I am unable to reproduce this issue, it has been escalated for further investigation. If you have more information that can help us, please add it below.

Thanks!

@sylerner
Copy link
Author

sylerner commented Aug 2, 2024

System info:

  • 15.6" HP Pavilion 15 Laptop, FHD screen
  • Intel Core i7-1165G7 @ 2.80GHz, 4 Cores, 8 Logical Processors
  • 16 GB RAM
  • 100 GB partition on 512 GB M2 drive

I am using a few older Yubikey devices in OTP mode for second factor authentication.

The showing of account information persists after logout/login and even restart.

To recreate, in settings, set "Vault timeout action" to "Log out".

If you exit Bitwarden by selecting File, Logout, , the account information isn't shown in the blue bar.

If however, you exit Bitwarden by either:

  • typing alt-F4
  • typing Ctrl-W
  • clicking on the upper right X
  • navigating in the menu and selecting Window/Close
  • navigating in the menu and selecting File/Quit Bitwarden

the account information will display in the blue bar in a very persistent manner.

BTW, I discovered that when the account information is being showed in the blue bar on a login screen, clicking the account information brings a dropdown that includes "Add account". Clicking on "Add account" makes the account information disappear.

@sylerner
Copy link
Author

sylerner commented Aug 5, 2024

I tried things out on Linux (OpenSuse Tumbleweed) and found that exiting Bitwarden with ctrl-Q or ctrl-W caused the same behavior. When next opening Bitwarden, my email is shown in the upper right in the blue bar.

Interestingly, when testing alt-F4, I discovered that it closed the window to the system tray instead of closing the app. Invoking Bitwarden in this state brings you back to your open vault. Alt-F4 neither locks or logs out on Linux.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug desktop Desktop Application
Projects
None yet
Development

No branches or pull requests

2 participants