bitwarden / bitwarden/clients

**BUG REPORT** biometrics fails with safari browser extension.

Open
#5,407 8 comments 1 reaction 0 assignees View on GitHub
browser bug
Dominant language
TypeScript
Stars
13.8k
Forks
2k
Avg merge
3d 9h
Merged PRs (30d)
397

Description

### Steps To Reproduce

THIS IS A REPORT OF A BUG. CORE BIOMETRIC FUNCTIONALITY FAILS ON A MAJOR OS.

1. Go to Safari > Bitwarden extension > Settings
2. Toggle 'unlock with biometrics' to checked.
3. Lock or close/reopen browser to get login biometrics prompt
4. Fail to log in after successful biometrics authentication with error:

### Expected Result

Successful unlocking of vault.

### Actual Result

Failure to unlock vault with the exact error "Account missmatch The desktop application is logged into a different account. Please ensure both applications are logged into the same account." (yes including the typo)

### Screenshots or Videos

_No response_

### Additional Context

Tested OS macOS 13.3.1a (though all versions since at least macOS 11 have been affected)
Safari version 16.4 (though again, this has been broken for several years)
Bitwarden Desktop and Safari extension version 2023.4.0 (again broken for many versions though)

Broken across several physical machines including 2016 mbp 13, 2020 m1 air, and 2021 M1 Pro mbp.

Chromium browser extension works once desktop is running, but safari extension fails with or without Bitwarden desktop running.

This bug appears to affect a handful of others:

https://github.com/bitwarden/clients/issues/2522

https://www.reddit.com/r/Bitwarden/comments/11tj1wu/unlock_with_touch_id_on_mac/

Someone who closed this bug report with the explanation that GitHub is for bug reports [?] said the following:

> I attempted to reproduce this and was unable to do so.

The bug still affects myself and others. You not being affected does not fix the bug.

> I suspect that the desktop client is logged into a different account

This assumption is incorrect. This issue affects a single account, and it logs in successfully when using password, but fails when attempting biometric authentication.

> and/or another application is interfering with the communication between the extension and the desktop client;

Ok, so... a bug.

> I would test this in a different browser, such as Chrome, to check if it's isolated to Safari in order to know how to proceed.

It IS indeed isolated to Safari. Chrome, Edge, (and probably Firefox) extensions work fine with biometric authentication.

>To be clear, I tested this with Bitwarden 2023.4.0, Safari 16.4, and macOS 13.3.1 (a) whilst the desktop client was logged into a single account and it worked as expected.

I have all the same versions and 100% failure rate, along with others as reported for quite some time now.

> We use GitHub issues as a place to track bugs and other development related issues.

Glad to know this is in the right place.

> If this persists, please write us back using our contact form, so we can continue troubleshooting: https://bitwarden.com/help/ and please include a link to this report in the message content.

Done as well.

### Operating System

macOS

### Operating System Version

11, 12, 13

### Web Browser

Safari, Microsoft Edge

### Browser Version

16.4

### Build Version

2023.4

### Issue Tracking Info

- [X] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the Safari extension flow on macOS: enable “unlock with biometrics,” lock or reopen the browser, and compare it with the working Chromium extension behavior. Done means biometric authentication unlocks the vault for the same account without the account-mismatch error; no file or test is identified in the report.

Written by the indexing model from the issue text.

Assessment

Tech stack
electron, typescript
Domain
authentication, desktop-dev
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.