"Bypass admin page security" should not be overrideable by admin-page #1993

Closed
opened 2026-04-06 02:46:06 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @kosli on 9/23/2022

The option in the admin page to "Bypass admin page security" should not be able to override what was set in the environment as this imposes a security risk.

e.g. as owner of a vaultwarden instance it would be great to set the "default" values in the environment, so that I still give an admin access to the admin pages, but he cannot override the values that I have set. -> especially if the settings can have such a big impact as bypassing the admin page security.

*Originally created by @kosli on 9/23/2022* The option in the admin page to "Bypass admin page security" should not be able to override what was set in the environment as this imposes a security risk. e.g. as owner of a vaultwarden instance it would be great to set the "default" values in the environment, so that I still give an admin access to the admin pages, but he cannot override the values that I have set. -> especially if the settings can have such a big impact as bypassing the admin page security.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/vaultwarden#1993