Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cipher fields not disabled in view only collection #4554

Open
1 task done
ajasnz opened this issue Jan 11, 2025 · 2 comments
Open
1 task done

Cipher fields not disabled in view only collection #4554

ajasnz opened this issue Jan 11, 2025 · 2 comments
Labels

Comments

@ajasnz
Copy link

ajasnz commented Jan 11, 2025

Steps To Reproduce

  1. Create a collection
  2. Add a cipher to the collection
  3. Assign a member view only permissions to the collection
  4. Using the member with view only access open the cipher in edit mode
  5. Try to edit a field
  6. Click save

Expected Result

Cipher fields have a disabled state and the user cannot alter the field. A useful error message is displayed when clicking save to explain the item is view only

Actual Result

The user is able to change field contents (not saved) giving the impression they can edit the cipher and potentially leading to lost login details.
When clicking save the error message is "you must assign at least one collection" which is not an accurate representation of the issue

Screenshots or Videos

No response

Additional Context

No response

Build Version

2025.1

What server are you connecting to?

US

Self-host Server Version

No response

Environment Details

Device: Samsung galaxy s23+
OS: Android 15, one UI 6

Issue Tracking Info

  • I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
@ajasnz ajasnz added the bug label Jan 11, 2025
@bitwarden-bot
Copy link

Thank you for your report! We've added this to our internal board for review.
ID: PM-16963

@SergeantConfused
Copy link

Hello @ajasnz,

Thank you for your report. I was able to reproduce this behaviour and have flagged it to the Engineering department.
Please feel free to post additional information, such as screenshots or a screen video recordings, if you wish.

Thank you again,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants