Admin page is available even without ADMIN_TOKEN #3426

Closed
opened 2026-04-06 04:48:46 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @poblabs on 6/27/2019

I admit I'm a bit new to bitwarden_rs, so I'm still trying to figure it out. I'm running this in a docker container on my Synology and it's working great.

I do not have the ADMIN_TOKEN, nor DISABLE_ADMIN_TOKEN environment variables specified, yet /admin is available to me without authentication.

Anything I'm missing? I would assume that page would be disabled if I wasn't explicitly defining something with those environment variables.

Here's the version from the header of the admin page: Version: 1.9.1-3fb63bbe

*Originally created by @poblabs on 6/27/2019* I admit I'm a bit new to bitwarden_rs, so I'm still trying to figure it out. I'm running this in a docker container on my Synology and it's working great. I **do not** have the `ADMIN_TOKEN`, nor `DISABLE_ADMIN_TOKEN` environment variables specified, yet `/admin` is available to me without authentication. Anything I'm missing? I would assume that page would be disabled if I wasn't explicitly defining something with those environment variables. Here's the version from the header of the admin page: `Version: 1.9.1-3fb63bbe`
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/vaultwarden#3426