Replies: 2 comments 4 replies
-
|
Have you checked https://github.com/dani-garcia/vaultwarden/blob/main/.env.template#L275-L278 ? |
Beta Was this translation helpful? Give feedback.
-
|
Thx - the logs are now being written. Also the organisation events (in the bitwarden documentation) in the web -interface just now appeared. The exports are events of the type INFO. additional info: Can the feature "limiting exports of an organisation to admins" be implemented? |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
as far as I have noticed, exports of the vault are not logged.
Probably the export is only done by the client software with the cached data -
but maybe Bitwarden clients do send an info to the server that an export was requested?
Yet, exports through the vaultwarden web interface could be traceable.
(Log Entry: YYYY-MM-DD hh:mm:ss -- User X exported his entries)
Also restricting the option to export passwort entries that belong to an organisation would be great.
(An option like "only admins can export organisation entries")
Background is a data breach by a user who (very likely) exported all his available entries - including the ones belonging to the organisation.
Would be great to see if there are possibilities to prevent theft by organisation users.
Kind regards
Alex
Beta Was this translation helpful? Give feedback.
All reactions