When the "Centralise organisation ownership" (PersonalOwnership) policy
is active, a non-admin/owner member can't own personal items and must
create organization items instead. The official web-vault already
gates the Import destination on this: it offers an org as an import
target if the member has `manage: true` on at least one of its
collections in their sync data — but Vaultwarden's
Collection::to_json_details() only ever set `manage: true` for members
with the org-level "Manager" role, ignoring the actual per-collection
Manage permission granted to a plain "User" role member. That left the
whole Import form disabled for exactly the members this policy is
meant to still let use it.
- collection.rs: compute `manage` from the per-collection flag (or
group grant) directly, independent of the member's org role. Keeps
the existing Manager-with-full-access fallback.
- organizations.rs (post_org_import): require the same "Manage"
permission (not just write access) for existing target collections,
and reject the whole import up front if a member without full org
access would leave any item unassigned to a collection they can
manage — no cipher is created before that's confirmed.
- Adds a Playwright test (against a real HTTPS-enabled Vaultwarden +
the current official web-vault) proving the import destination,
collection, file format and content fields are enabled for such a
member, with the org's collection pre-selected instead of the
personal vault. Depends on the HTTPS/selector fixes on
playwright-https-and-selector-fixes.
- Adds unit tests for the new per-cipher-collection-assignment check.
Security: this only widens who can be offered as an import target in
line with permissions Vaultwarden already enforces elsewhere for
manual collection management (is_manageable_by_user); it does not
change who is authorized to write to a collection, and the
personal-ownership policy itself is unaffected.
* Add SSO functionality using OpenID Connect
Co-authored-by: Pablo Ovelleiro Corral <mail@pablo.tools>
Co-authored-by: Stuart Heap <sheap13@gmail.com>
Co-authored-by: Alex Moore <skiepp@my-dockerfarm.cloud>
Co-authored-by: Brian Munro <brian.alexander.munro@gmail.com>
Co-authored-by: Jacques B. <timshel@github.com>
* Improvements and error handling
* Stop rolling device token
* Add playwright tests
* Activate PKCE by default
* Ensure result order when searching for sso_user
* add SSO_ALLOW_UNKNOWN_EMAIL_VERIFICATION
* Toggle SSO button in scss
* Base64 encode state before sending it to providers
* Prevent disabled User from SSO login
* Review fixes
* Remove unused UserOrganization.invited_by_email
* Split SsoUser::find_by_identifier_or_email
* api::Accounts::verify_password add the policy even if it's ignored
* Disable signups if SSO_ONLY is activated
* Add verifiedDate to organizations::get_org_domain_sso_details
* Review fixes
* Remove OrganizationId guard from get_master_password_policy
* Add wrapper type OIDCCode OIDCState OIDCIdentifier
* Membership::confirm_user_invitations fix and tests
* Allow set-password only if account is unitialized
* Review fixes
* Prevent accepting another user invitation
* Log password change event on SSO account creation
* Unify master password policy resolution
* Upgrade openidconnect to 4.0.0
* Revert "Remove unused UserOrganization.invited_by_email"
This reverts commit 548e19995e141314af98a10d170ea7371f02fab4.
* Process org enrollment in accounts::post_set_password
* Improve tests
* Pass the claim invited_by_email in case it was not in db
* Add Slack configuration hints
* Fix playwright tests
* Skip broken tests
* Add sso identifier in admin user panel
* Remove duplicate expiration check, add a log
* Augment mobile refresh_token validity
* Rauthy configuration hints
* Fix playwright tests
* Playwright upgrade and conf improvement
* Playwright tests improvements
* 2FA email and device creation change
* Fix and improve Playwright tests
* Minor improvements
* Fix enforceOnLogin org policies
* Run playwright sso tests against correct db
* PKCE should now work with Zitadel
* Playwright upgrade maildev to use MailBuffer.expect
* Upgrades playwright tests deps
* Check email_verified in id_token and user_info
* Add sso verified endpoint for v2025.6.0
* Fix playwright tests
* Create a separate sso_client
* Upgrade openidconnect to 4.0.1
* Server settings for login fields toggle
* Use only css for login fields
* Fix playwright test
* Review fix
* More review fix
* Perform same checks when setting kdf
---------
Co-authored-by: Felix Eckhofer <felix@eckhofer.com>
Co-authored-by: Pablo Ovelleiro Corral <mail@pablo.tools>
Co-authored-by: Stuart Heap <sheap13@gmail.com>
Co-authored-by: Alex Moore <skiepp@my-dockerfarm.cloud>
Co-authored-by: Brian Munro <brian.alexander.munro@gmail.com>
Co-authored-by: Jacques B. <timshel@github.com>
Co-authored-by: Timshel <timshel@480s>