Offline mode creation of session or credential in private vault in root goes global

Offline mode creation of session or credential in private vault in root goes global

avatar
jan-pieter
Disabled

Hi,

When I'm in offline mode (RDM 10.1.3.0) and create an entry in the private vault it is being created in "All entries".
And if I do not specify a folder for the entry it is created in the root of "All entries" even if I'm not allowed to (i.e. "Deny add entry in root folder" is ticked) and when going online (and accepting the changes) it is there for everyone to see and use (if no security were added but it was supposed to be a private vault entry so no security was added).

Regards,
Jan-Pieter

All Comments (17)

avatar

Hi,
I will enter a bug report for that. I'm not even sure if the private vault in offline was supported. I suspect that this is a side effect.

David Hervieux

avatar

pv in offline-mode wasn't supported but would be a great new feature ....

Kind Regards
Markus

======================

avatar

Yes of course.

David Hervieux

avatar

We've got the same issue, not with credentials, but with normal entrys... websites, rdp and so on..

Its really bad, because the private information of websites is saved in it.

Our Problem was, that the private vault entries was added in online mode, after a disconnect to the database and a reconnect sometimes it appears in the root of the global entrys.

Should be fixed fast

avatar

Hello,

As a temporary fix, offline mode will disable the Private Vault. This will be available in the upcoming version.
It's in our plans to make the Private Vault compatible with offline mode.

Regards,

Hubert Mireault

avatar

Hello,

also in our system sometimes it can happen that an entry from a users private vault appears in the root of all entries, although this user does not have permission to create entries in the root.

But it can not be an issue in the offline mode because our offline mode is read-only.

Best regards,
Andy

avatar

Do you have the steps to reproduce it? Can you reproduce it all the time?

David Hervieux

avatar

Unfortunatelly not now. If I know more I'll let you know.

avatar

Now it happened again. The user had Firefox and RDM open. In Firefox the message appeared that RDM extension lost connection and he clicked on connect. After that he logged in to a website.

Credentials for this website are not stored in RDM. How can I reproduce the message of the extension?

avatar

Hi,
The credential was created by the browser extension?

David Hervieux

avatar

Yes, it seems like but not reproducible. Also the entries always are named like web addresses.

avatar

I will ask Olivier to verify the internal behaviour to check if we can find a pattern.

David Hervieux

avatar

We should have a fix for the next update.

David Hervieux

avatar

Now it was good for a long time but today this issue occured again with RDM 10.1.9.0 and Firefox Extension 3.0.5.0

avatar

Scince we updated RDM to V 10.5.4.0 this issue appears again regularly.

avatar

Could you try RDM beta to see if this also happen?

David Hervieux

avatar

It is very hard to determine if the new beta has solved the problem but at the moment this looks ok again.
I've installed it only on the PC of the colleague who "created" that strange entries.