Hi,
We are using the BitWarden integration in RDM with a self-hosted instance of BitWarden.
When using an OTP-enabled account, the following prompt is displayed:
However, the "Remind this device" option doesn't word as intended: When checked, it will works for the next logon (the 2FA is bypassed as intended), but the prompt will be displayed again for the 3rd logon.
In other words, I have to enter the OTP code every 2 logons.
This issue has already been reported by someone else there: https://forum.devolutions.net/topics/36444/bitwarden-with-2fa#156726, but I don't know if a solution was found or if a fix is planned.
Do you know if there is any way to fix this issue?
Regards,
Hello,
If you are using Vaultwarden (which is an unofficial Bitwarden server), there are unfortunately some things that do not work as expected, like the "remember me" feature. It's not an official product by the Bitwarden team and there are some differences between both products. RDM currently only fully supports the official Bitwarden product.
Also in RDM 2022.1 we are adding the API key login method to our Bitwarden implementation. Vaultwarden doesn't yet support this (https://vaultwarden.discourse.group/t/personal-api-key-cli/1190/2) but when they do, it could be an alternative as it would avoid you needing to enter your 2FA.
Regards,
Hubert Mireault
Thank you for your response !
This is indeed a VaultWarden instance. It looks a bit weird that there is a difference on how the "2FA's remind me" feature is handled considering that official BitWarden clients don't have any issue with it. But I understand you don't officially support VaultWarden.
Thanks for the tip about API keys. I'll keep this around in case they support it in the future.
Regards,
Hello,
A quick follow up in case someone with this issue come across this topic.
Almost at the same time that your response, a PR to add support for API keys was merged in Vaultwarden and landed in 1.24.0 which was released on January 30.
I've tested it with RDM 2022.2, and it works as expected! :)
Regards,
Yohan Prod'homme
Hello Yohan,
Thanks for letting us and the community know! Glad that it's working with this VaultWarden update.
Regards,
Hubert Mireault