Commit Graph

  • d93538a7fe Fix migration for MariaDB 12.2.2 Timshel 2026-05-27 18:33:07 +0200
  • 0fecadd124
    template correction Guilhem Zeitoun 2026-07-15 07:10:04 +0200
  • 19dd24e24c
    bad use of get_env_str Guilhem Zeitoun 2026-07-15 07:06:44 +0200
  • 9f09c30623
    test if needed Guilhem Zeitoun 2026-07-14 23:13:11 +0200
  • 4e2bde6da3 Normalize SSO default organization UUID before lookup tom27052006 2026-07-14 23:11:09 +0200
  • 29d76b5451
    rebase fix Guilhem Zeitoun 2026-07-14 22:39:28 +0200
  • b9166502cb
    Corrections on env and naming. Guilhem Zeitoun 2026-04-26 17:41:34 +0200
  • eac74fa0d1
    changes for review Guilhem Zeitoun 2026-07-14 22:35:14 +0200
  • 3a27382c2d Add default organization for SSO users tom27052006 2026-07-14 22:33:19 +0200
  • c58eebc584
    rebase Guilhem Zeitoun 2026-07-14 22:07:19 +0200
  • 826aea858e Serve the login JWKS via OIDC discovery Luca Biemelt 2026-07-12 17:00:44 +0200
  • 7adf1b50cf Tighten the KEY_CONNECTOR_URL validation Luca Biemelt 2026-07-14 17:54:06 +0200
  • f60c30fd41 Lower maximum 2FA remember duration to 365 days Tom 2026-07-14 17:45:49 +0200
  • 80792cd304 Make 2FA remember duration configurable tom27052006 2026-07-14 15:20:53 +0200
  • a3232c9855 Add admin controls for timeout and export policies tom27052006 2026-07-14 14:35:05 +0200
  • c86ebd07fd Add Playwright tests for the Key Connector flow Luca Biemelt 2026-07-14 13:28:00 +0200
  • 317883c8c2 Advertise the Key Connector to new SSO users Luca Biemelt 2026-07-14 11:05:08 +0200
  • f48a4b7eba Harden the Key Connector account endpoints Luca Biemelt 2026-07-14 10:40:46 +0200
  • 6597146117 Add smoke test for the organization Public API read endpoints Rune Darrud 2026-07-12 15:27:16 +0300
  • 14497da8a0 Add Public API read endpoints for members, groups, and collections Rune Darrud 2026-07-12 15:13:58 +0300
  • 97ac457910 chore: remove `SHELL` instructions unknown to OCI images and use POSIX commands Jakob Probst 2026-07-11 20:37:00 +0200
  • 29de7e1e80 chore: enable the `s3` feature within the Dockerfiles Jakob Probst 2026-07-11 19:19:34 +0200
  • f513a01ef9 Add Key Connector support for SSO users Luca Biemelt 2026-07-11 15:49:36 +0200
  • b4caaab2df fix formatting Shocker 2026-07-11 16:28:41 +0300
  • 6302df6776
    Merge branch 'main' into icon-service-fallback Shocker 2026-07-11 16:04:26 +0300
  • 4b90b47dec Fix privilege escalation: restrict role-type changes to Admins/Owners in edit_member tom27052006 2026-07-11 00:31:18 +0200
  • 80741f30d9
    Merge 834a194816 into 169aa5efcc Rohmilchkaese 2026-07-10 00:20:39 +0000
  • a2451a6ee3
    Merge branch 'main' into feature/custom-role-permissions Tom 2026-07-09 18:42:33 +0200
  • 84b8de124e Keep per-collection manage working for Custom members tom27052006 2026-07-09 16:20:37 +0200
  • 011e5c005b Add the Custom role to the admin panel tom27052006 2026-07-09 16:20:36 +0200
  • b571efcadd Migrate legacy Manager members to the Custom type tom27052006 2026-07-09 16:20:16 +0200
  • b2047fd640
    Merge 2d68adcfed into 169aa5efcc Don Kendall 2026-07-09 14:32:29 +0200
  • 45cf471412
    Merge f750116afa into 169aa5efcc Denis Pisarev 2026-07-09 16:46:08 +0800
  • 6216a42c49
    Merge 88ab51443a into 169aa5efcc Zaid Marji 2026-07-09 16:46:08 +0800
  • 2155ea6232
    Merge bb9449bf35 into 169aa5efcc Matt Van Horn 2026-07-09 16:46:08 +0800
  • 1c76505ae3
    Merge a1d83ea29f into 169aa5efcc Timshel 2026-07-09 16:46:07 +0800
  • 89bcfe67f8
    Merge branch 'main' of https://github.com/dani-garcia/vaultwarden into feat/webauthn_login Raphaël Roumezin 2026-07-09 09:20:10 +0200
  • 169aa5efcc
    Misc updates and fixes (#7406) Mathijs van Veluw 2026-07-08 22:10:29 +0200
  • 64d28ab66e
    improve CI (#6991) Denis Pisarev 2026-07-08 22:08:20 +0200
  • 89a25c4e12
    Merge branch 'main' of https://github.com/dani-garcia/vaultwarden into feat/webauthn_login Raphaël Roumezin 2026-07-08 13:59:48 +0200
  • 8a65c6631a Security: gate group delete/member-removal on collection access tom27052006 2026-07-08 19:39:49 +0200
  • a711aa1274
    Update MSRV to v1.94.1 BlackDex 2026-07-08 19:26:08 +0200
  • f7df02b483
    Misc updates and fixes BlackDex 2026-07-08 19:13:15 +0200
  • 81b76d9782 Persist manage_* permission flags on invite tom27052006 2026-07-08 18:29:52 +0200
  • 1dcd3ea26f Block collection access via group assignment in edit_member and send_invite tom27052006 2026-07-08 15:51:57 +0200
  • 3b07e1ed83 Merge remote-tracking branch 'upstream/main' into feature/custom-role-permissions tom27052006 2026-07-08 13:30:22 +0200
  • 02b6c2c205 Restrict group reads to manage_groups and hide policy contents without manage_policies tom27052006 2026-07-08 13:24:51 +0200
  • 43fb19f190 Harden custom-role permission checks tom27052006 2026-07-08 08:11:27 +0200
  • 4720cdbe86
    Add `pm-26340-linux-biometrics-v2` feature flag (#7358) pilotstew 2026-07-07 08:59:57 -0500
  • 5447ee6af2
    SSO use ClientSecretPost if ClientSecretBasic is not available (#7357) Timshel 2026-07-07 15:59:48 +0200
  • 5c5e8e1a6f
    2026.6.0 send support (#7346) Timshel 2026-07-07 15:59:36 +0200
  • 7320a1db4b
    PutPolicy now using vnext format (#7296) Timshel 2026-07-07 15:59:26 +0200
  • a058a35ccd
    [v2026.5.0] Registration request update (#7295) Timshel 2026-07-07 15:59:17 +0200
  • a16b5afaaa
    Org membership delete remove Invitation (#7284) Timshel 2026-07-07 15:59:06 +0200
  • fddc16d2b8
    fix(sends): emit hideEmail as non-null boolean in sync response (#7283) kvdb 2026-07-07 15:58:54 +0200
  • ec7fa137b7
    Admin password recovery endpoint change (#7270) Timshel 2026-07-07 15:58:41 +0200
  • b25f715364
    Fix enforce blocked (#7246) Timshel 2026-07-07 15:58:34 +0200
  • 9f45aa77e7 Fix privilege escalation: gate access_all in edit_member tom27052006 2026-07-07 14:12:36 +0200
  • e72c97c30d Harden custom-role permissions: block indirect collection access via groups; block manage_users revoke/restore of admins; cargo fmt tom27052006 2026-07-07 11:59:44 +0200
  • 4d6b667ffc Server-side collection/group permission hardening; works without web-vault changes tom27052006 2026-07-02 17:12:23 +0200
  • 9e4aa5efe7
    feat: Added support for passkey vault unlock feature Raphaël Roumezin 2026-06-30 11:07:00 +0200
  • df18711b49 Silence struct_excessive_bools lint for Membership tom27052006 2026-07-01 19:39:10 +0200
  • 1f6d457533 Add custom role permissions: Manage Users, Groups, Policies tom27052006 2026-07-01 19:30:54 +0200
  • c99ffe3d83 Review fix Timshel 2026-06-29 10:09:52 +0200
  • 7dbd82a311 add Zenith Hosting badge l1mey112 2026-06-29 16:53:04 +1000
  • 055cb61888 Don't block the login response on the new-device email max 2026-06-28 21:07:45 +0200
  • 5261bd7b0d Review fixes Timshel 2026-06-27 23:16:30 +0200
  • 3b669264bb
    fix(clippy): few refactors Raphael Roumezin 2026-06-27 16:55:05 +0200
  • 05c9af4d1e
    fix: Allowed Chromium extensions as origins for passwordless login Raphael Roumezin 2026-06-27 16:30:32 +0200
  • 9351e91de0 Do not fail login when push device registration fails max 2026-06-26 12:53:02 +0200
  • 224ad8a406 fix: typos Raphaël Roumezin 2026-06-24 13:00:48 +0200
  • 8cba57a1af feat(config): Add passkey_login_allowed config option Raphaël Roumezin 2026-06-24 11:44:53 +0200
  • 007ac4f992 fix: Correct attestation options Raphaël Roumezin 2026-06-23 16:01:02 +0200
  • 7711b02153 feat: passwordless login Raphaël Roumezin 2026-06-23 15:27:37 +0200
  • d9695088c7
    Add Podman Quadlet instructions to Readme 4liceD 2026-06-23 10:37:15 +0200
  • af02911b71 SSO use ClientSecretPost if ClientSecretBasic is not available Timshel 2026-06-23 08:24:33 +0200
  • d79de9559c clippy fixes Kyattsukuro 2026-06-22 15:51:01 +0200
  • 44cc4426ef revertet changing names of organisation attachment_count Kyattsukuro 2026-05-08 13:40:30 +0200
  • 2de70aa59c use camel case for attachmentCount, use safer way to get user JSON Kyattsukuro 2026-04-05 13:55:56 +0200
  • 59ecb5ae7e in enrich_users_json, moved never active notice to template Kyattsukuro 2026-02-04 22:56:49 +0100
  • a407ea54b0 removed get_sso_user Kyattsukuro 2026-02-04 22:46:25 +0100
  • c6717ae896 moved SsoUser from get_user_or_404 to get_sso_user Kyattsukuro 2026-02-03 15:04:18 +0100
  • aa62a27a8d Resolves conflicts: src/static/templates/admin/users.hbs Kyattsukuro 2026-06-22 15:34:41 +0200
  • 428db6b23a pass formatting checks Kyattsukuro 2025-11-29 19:40:36 +0100
  • c915f5fc3e return same json object for all user queries Kyattsukuro 2026-05-08 13:01:15 +0200
  • c0579d05a4 adds sso_identifier to /admin/users Kyattsukuro 2025-11-24 19:41:12 +0100
  • 409031715f
    Merge branch 'main' into pr/3x8_improve-ci Denis Pisarev 2026-06-22 11:07:13 +0200
  • 995c96a55a Add `pm-26340-linux-biometrics-v2` feature flag pilotstew 2026-06-21 09:28:53 -0500
  • fb9e70b79f Use default to keep compatibility Timshel 2026-06-21 16:13:37 +0200
  • 649ed31aa7 enable rocket/mtls feature Simonas Kazlauskas 2026-06-20 16:11:51 +0300
  • 89dae0f082 fix: pin Debian MariaDB packages to 11.8.6 maxpetrusenkoagent 2026-06-18 16:36:13 -0400
  • 8450af2094 Prevent creating and editing a Send with email verification Timshel 2026-06-18 19:52:09 +0200
  • 4900b8fd81
    fix: use request-body OIDC auth Puria Nafisi Azizi 2026-06-18 03:02:12 +0200
  • 64d943b625 2026.6.0 send support Timshel 2026-06-16 20:48:12 +0200
  • dc82ad6d6c Pin Debian MariaDB client library maxpetrusenkoagent 2026-06-15 05:04:40 -0400
  • 2c97b41e87
    fix(sends): emit hideEmail as non-null boolean in sync response Kees van den Broek 2026-06-01 11:04:42 +0200
  • d0f6d297db Admin password recovery endpoint change Timshel 2026-05-28 14:11:07 +0200
  • ca446d46b2 Fix enforce blocked Timshel 2026-05-20 19:42:55 +0200
  • 00cc9f79b1 Registration request update Timshel 2026-06-03 15:12:21 +0200
  • 77283882e1 PutPolicy now using vnext format Timshel 2026-06-03 16:26:48 +0200