Launch website from MacOS App did not ask for master password in browser
- Dominant language
- TypeScript
- Stars
- 13.8k
- Forks
- 2k
- Avg merge
- 3d 9h
- Merged PRs (30d)
- 397
Description
### Steps To Reproduce
1. Running MacOS client, I searched for my bank's entry
2. Clicked on launch
3. This Opens the bank login window in Duckduckgo, (default browser)
4. Clicked on username field, and the bitwarden entry for my user pops up
5. Clicked on the entry in the pop up, and the login name and password are filled in WITHOUT asking for the master password
### Expected Result
I should have gotten "This action is protected. To continue, please re-enter your master password to verify your identity." I do if I use Chrome, and I do if I click on show password in the MacOS app.
PS I know the passwords need to be accessible via the API, but do we really need to expose even a list of my accounts via the app. I would prefer to require a password every time I open the bitwarden window, while not requiring the password when using the duckduckgo browser, unless the entry is protected.
### Actual Result
Filled in username and password without asking for master password
### Screenshots or Videos
_No response_
### Additional Context
_No response_
### Operating System
macOS
### Operating System Version
15.3.1
### Installation method
Mac App Store
### Build Version
Version 2025.2.0 (37899)
### Issue Tracking Info
- [x] I understand that work is tracked outside of GitHub. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
Contributor guide
Research direction
Start by reproducing the flow on macOS 15.3.1 with the Mac App Store build: launch the bank entry in DuckDuckGo, then use the Bitwarden autofill pop-up. Done means protected entries trigger the stated master-password prompt before username and password are filled, matching the behavior seen in Chrome and when showing a password in the macOS app.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- electron, macos, typescript
- Domain
- authentication, desktop, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100