bitwarden / bitwarden/ios

[PM-35063] CXP importation from Apple Passwords does not include application autofill affiliations.

Open
#2,536 2 comments 0 reactions 0 assignees View on GitHub
app:password-manager bug
Dominant language
Swift
Stars
684
Forks
154
Avg merge
7d 2h
Merged PRs (30d)
32

Description

### Steps To Reproduce

As [`issues/2535`](https://github.com/bitwarden/ios/issues/2535#issue-4256410714) states:

1. I created an Apple Passwords item for {an account for} a TestFlight application.

1. I exported that entrant to Bitwarden, via CXP.

### Expected Result

Auto-fill should operate, because the affiliation should remain:

Image

### Actual Result

It is not transferred:

~~~YAML
- passwordHistory: []
revisionDate: "2026-04-13T17:09:06.139Z"
creationDate: "2026-04-13T17:09:06.139Z"
object: item
id: ef0502ae-5961-4201-9b60-b42b011aa6c5
type: 1
reprompt: 0
name: Patroniks
notes: null
favorite: false
fields: []
login:
uris: []
fido2Credentials: []
# username:
# password:
totp: null
passwordRevisionDate: null
collectionIds: []
attachments: []
~~~

### Additional Context

This is similar to [`ios/issues/1979`](https://github.com/bitwarden/ios/issues/1979#issue-3447024149). To demonstrate, the process is:

~~~YAML
Bitwarden iOS Flight Recorder
🕒 Log Start: 2026-04-13T18:08:47+01:00
⏳ Log Duration: 1h
📝 Bitwarden 2026.3.1 (3062)
📦 Bundle: com.8bit.bitwarden
📱 Device: iPhone12,1
🍏 System: iOS 26.4
🦀 SDK: 2.0.0-4735-26e2b10
🌩️ Server: 2026.3.2 @ US
🧱 Commit: bitwarden/ios/release/2026.3-rc45@38c8ad14567bf9aed197861bc1fcfcaa9b438e4d
💻 Build Source: bitwarden/ios/actions/runs/23565719717/attempts/1
👤 User ID: 37515fbb-ce2a-4342-9680-acaf00055b94

2026-04-13T18:08:47+01:00: [Navigation] View dismissed: EnableFlightRecorderView
2026-04-13T18:09:04+01:00: [Navigation] View appeared: ImportCXFView
2026-04-13T18:09:04+01:00: Request 0BEC5221-D46B-479E-9A02-A8168E50973D: GET https://api.bitwarden.com/accounts/revision-date
2026-04-13T18:09:04+01:00: Response 0BEC5221-D46B-479E-9A02-A8168E50973D: https://api.bitwarden.com/accounts/revision-date 200
2026-04-13T18:09:04+01:00: Request 815FF241-2492-410A-9E04-5DA29FAFBBBA: GET https://api.bitwarden.com/sync
2026-04-13T18:09:05+01:00: [Navigation] View appeared: VaultListView
2026-04-13T18:09:05+01:00: Request 3ED76691-F439-4E16-A19F-5895A23119A9: POST https://api.bitwarden.com/ciphers/import
2026-04-13T18:09:06+01:00: [Notification] Received push notification, type: syncVault
2026-04-13T18:09:06+01:00: Request B6961062-7A49-4BB1-B0F4-4960A64729CD: GET https://api.bitwarden.com/accounts/revision-date
2026-04-13T18:09:06+01:00: Response 3ED76691-F439-4E16-A19F-5895A23119A9: https://api.bitwarden.com/ciphers/import 200
2026-04-13T18:09:06+01:00: Request 96A1EAC2-D092-49DD-8DFE-3CB8392BCDDF: GET https://api.bitwarden.com/sync
2026-04-13T18:09:06+01:00: Request B30438F1-342E-473C-91C6-BA156DF91C71: PUT https://api.bitwarden.com/devices/identifier/2414E193-A665-4E2E-AA2F-A342AD0F3B5E/token
2026-04-13T18:09:06+01:00: Response B6961062-7A49-4BB1-B0F4-4960A64729CD: https://api.bitwarden.com/accounts/revision-date 200
2026-04-13T18:09:06+01:00: Request 87D7F6FB-B154-405D-A037-F103D2CE00B0: GET https://api.bitwarden.com/sync
2026-04-13T18:09:06+01:00: Response B30438F1-342E-473C-91C6-BA156DF91C71: https://api.bitwarden.com/devices/identifier/2414E193-A665-4E2E-AA2F-A342AD0F3B5E/token 200
2026-04-13T18:09:12+01:00: Response 815FF241-2492-410A-9E04-5DA29FAFBBBA: https://api.bitwarden.com/sync 200
2026-04-13T18:09:14+01:00: [AutofillCredentialService] Replacing all credential identities
2026-04-13T18:09:16+01:00: [AutofillCredentialService] Replaced 2946 credential identities
2026-04-13T18:09:17+01:00: Response 96A1EAC2-D092-49DD-8DFE-3CB8392BCDDF: https://api.bitwarden.com/sync 200
2026-04-13T18:09:18+01:00: Response 87D7F6FB-B154-405D-A037-F103D2CE00B0: https://api.bitwarden.com/sync 200
2026-04-13T18:09:20+01:00: [AutofillCredentialService] Replacing all credential identities
2026-04-13T18:09:24+01:00: [AutofillCredentialService] Replaced 2946 credential identities
2026-04-13T18:09:24+01:00: [Navigation] View dismissed: ImportCXFView
2026-04-13T18:09:25+01:00: [AutofillCredentialService] Replacing all credential identities
2026-04-13T18:09:26+01:00: [AutofillCredentialService] Replaced 2946 credential identities
2026-04-13T18:09:29+01:00: [Navigation] View appeared: AboutView
~~~

### Build Version

> 38c8ad14567bf9aed197861bc1fcfcaa9b438e4d

### What server are you connecting to?

US

### Self-host Server Version

> `2026.3.2` @ US

### Environment Details

- 1. ~~~sh
#!sh
ufetch
~~~

1.

~~~yaml
OS: iPhone OS 26.4
KERNEL: Darwin 25.4.0
DE: SpringBoard
~~~

- 1. ~~~sh
#!sh
uname -a
~~~

1. > Darwin `localhost` `25.4.0` Darwin Kernel Version `25.4.0`: Fri Mar 6 00:01:55 PST 2026; `root:xnu-12377.102.10~3/RELEASE_ARM64_T8030` `iPhone12,1`

[^1] [^2]

[^1]: [`gitlab.com/jschx/ufetch/-/issues/22`](https://gitlab.com/jschx/ufetch/-/issues/22)

[^2]: [`stackoverflow.com/revisions/54516296/1`](https://stackoverflow.com/revisions/54516296/1#content:~:text=Using%20plain%20interpreter%20may%20work%20sometimes%20%2D%20it%20means%20that%20shebang%20handling%20is%20done%20by%20something%20that%20is%20aware%20of%20the%20environment%2C%20most%20likely%20by%20the%20active%20shell%20itself%20and%20not%20by%20the%20kernel%2E)

### Issue Tracking Info

- [x] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.

Contributor guide

Open the contributing guide

Research direction

Start with the ImportCXFView flow and the ciphers/import request shown in the flight recorder, then trace how the imported login reaches AutofillCredentialService. Compare the Apple Passwords affiliation with the resulting CXP item, and use the related issues/2535 and ios/issues/1979 for expected behavior. Done means the affiliation is preserved and autofill works for the imported TestFlight credential.

Written by the indexing model from the issue text.

Assessment

Tech stack
swift
Domain
mobile-dev
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.