forked from dani-garcia/vaultwarden
-
-
Notifications
You must be signed in to change notification settings - Fork 13
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
20 changed files
with
8,883 additions
and
189 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,102 +1,56 @@ | ||
### Alternative implementation of the Bitwarden server API written in Rust and compatible with [upstream Bitwarden clients](https://bitwarden.com/download/)*, perfect for self-hosted deployment where running the official resource-heavy service might not be ideal. | ||
# Fork from [dani-garcia/vaultwarden](https://github.com/dani-garcia/vaultwarden) | ||
|
||
📢 Note: This project was known as Bitwarden_RS and has been renamed to separate itself from the official Bitwarden server in the hopes of avoiding confusion and trademark/branding issues. Please see [#1642](https://github.com/dani-garcia/vaultwarden/discussions/1642) for more explanation. | ||
Goal is to help testing code for the SSO [PR](https://github.com/dani-garcia/vaultwarden/pull/3899). | ||
Based on [Timshel/sso-support](https://github.com/Timshel/vaultwarden/tree/sso-support) | ||
|
||
--- | ||
[![Build](https://github.com/dani-garcia/vaultwarden/actions/workflows/build.yml/badge.svg)](https://github.com/dani-garcia/vaultwarden/actions/workflows/build.yml) | ||
[![ghcr.io](https://img.shields.io/badge/ghcr.io-download-blue)](https://github.com/dani-garcia/vaultwarden/pkgs/container/vaultwarden) | ||
[![Docker Pulls](https://img.shields.io/docker/pulls/vaultwarden/server.svg)](https://hub.docker.com/r/vaultwarden/server) | ||
[![Quay.io](https://img.shields.io/badge/Quay.io-download-blue)](https://quay.io/repository/vaultwarden/server) | ||
[![Dependency Status](https://deps.rs/repo/github/dani-garcia/vaultwarden/status.svg)](https://deps.rs/repo/github/dani-garcia/vaultwarden) | ||
[![GitHub Release](https://img.shields.io/github/release/dani-garcia/vaultwarden.svg)](https://github.com/dani-garcia/vaultwarden/releases/latest) | ||
[![AGPL-3.0 Licensed](https://img.shields.io/github/license/dani-garcia/vaultwarden.svg)](https://github.com/dani-garcia/vaultwarden/blob/main/LICENSE.txt) | ||
[![Matrix Chat](https://img.shields.io/matrix/vaultwarden:matrix.org.svg?logo=matrix)](https://matrix.to/#/#vaultwarden:matrix.org) | ||
:warning: Branch will be rebased and forced-pushed from time to time. :warning: | ||
|
||
Image is based on [Rust implementation of Bitwarden API](https://github.com/dani-garcia/vaultwarden). | ||
## Docker | ||
|
||
**This project is not associated with the [Bitwarden](https://bitwarden.com/) project nor Bitwarden, Inc.** | ||
Change the docker files to package both front-end from [Timshel/oidc_web_builds](https://github.com/Timshel/oidc_web_builds/releases). | ||
\ | ||
By default it will use the release which only make the `sso` button visible. | ||
|
||
#### ⚠️**IMPORTANT**⚠️: When using this server, please report any bugs or suggestions to us directly (look at the bottom of this page for ways to get in touch), regardless of whatever clients you are using (mobile, desktop, browser...). DO NOT use the official support channels. | ||
If you want to use the version which additionally change the default redirection to `/sso` and fix organization invitation to persist. | ||
You need to pass an env variable: `-e SSO_FRONTEND='override'` (cf [start.sh](docker/start.sh)). | ||
|
||
--- | ||
## To test VaultWarden with Keycloak | ||
|
||
## Features | ||
[Readme](test/oidc/README.md) | ||
|
||
Basically full implementation of Bitwarden API is provided including: | ||
## DB Migration | ||
|
||
* Organizations support | ||
* Attachments and Send | ||
* Vault API support | ||
* Serving the static files for Vault interface | ||
* Website icons API | ||
* Authenticator and U2F support | ||
* YubiKey and Duo support | ||
* Emergency Access | ||
ATM The migrations add an independant table `sso_nonce` and a column `invited_by_email` to `users_organizations`. | ||
|
||
## Installation | ||
Pull the docker image and mount a volume from the host for persistent storage: | ||
### Revert to default VW | ||
|
||
```sh | ||
docker pull vaultwarden/server:latest | ||
docker run -d --name vaultwarden -v /vw-data/:/data/ --restart unless-stopped -p 80:80 vaultwarden/server:latest | ||
Reverting to the default VW DB state can easily be done manually (Make a backup :) : | ||
|
||
```psql | ||
>BEGIN; | ||
BEGIN | ||
>DELETE FROM __diesel_schema_migrations WHERE version in ('20230910133000', '20230914133000'); | ||
DELETE 2 | ||
>DROP TABLE sso_nonce; | ||
DROP TABLE | ||
>ALTER TABLE users_organizations DROP COLUMN invited_by_email; | ||
ALTER TABLE | ||
> COMMIT / ROLLBACK; | ||
``` | ||
|
||
### FROM old PR Version | ||
|
||
:warning: Changed the past migration creating the `sso_nonce` table in a recent [commit](https://github.com/Timshel/vaultwarden/commit/afa26f3cf5a39ff0bc4c3cbe563cfcfaf91b40a0).:warning: <br> | ||
If you already deployed the previous version you'll need to do some manual cleanup : | ||
|
||
```psql | ||
>BEGIN; | ||
BEGIN | ||
>DELETE FROM __diesel_schema_migrations WHERE version = '20230201133000'; | ||
DELETE 1 | ||
>DROP TABLE sso_nonce; | ||
DROP TABLE | ||
> COMMIT / ROLLBACK; | ||
``` | ||
This will preserve any persistent data under /vw-data/, you can adapt the path to whatever suits you. | ||
|
||
**IMPORTANT**: Most modern web browsers disallow the use of Web Crypto APIs in insecure contexts. In this case, you might get an error like `Cannot read property 'importKey'`. To solve this problem, you need to access the web vault via HTTPS or localhost. | ||
|
||
This can be configured in [vaultwarden directly](https://github.com/dani-garcia/vaultwarden/wiki/Enabling-HTTPS) or using a third-party reverse proxy ([some examples](https://github.com/dani-garcia/vaultwarden/wiki/Proxy-examples)). | ||
|
||
If you have an available domain name, you can get HTTPS certificates with [Let's Encrypt](https://letsencrypt.org/), or you can generate self-signed certificates with utilities like [mkcert](https://github.com/FiloSottile/mkcert). Some proxies automatically do this step, like Caddy (see examples linked above). | ||
|
||
## Usage | ||
See the [vaultwarden wiki](https://github.com/dani-garcia/vaultwarden/wiki) for more information on how to configure and run the vaultwarden server. | ||
|
||
## Get in touch | ||
To ask a question, offer suggestions or new features or to get help configuring or installing the software, please use [GitHub Discussions](https://github.com/dani-garcia/vaultwarden/discussions) or [the forum](https://vaultwarden.discourse.group/). | ||
|
||
If you spot any bugs or crashes with vaultwarden itself, please [create an issue](https://github.com/dani-garcia/vaultwarden/issues/). Make sure you are on the latest version and there aren't any similar issues open, though! | ||
|
||
If you prefer to chat, we're usually hanging around at [#vaultwarden:matrix.org](https://matrix.to/#/#vaultwarden:matrix.org) room on Matrix. Feel free to join us! | ||
|
||
### Sponsors | ||
Thanks for your contribution to the project! | ||
|
||
<!-- | ||
<table> | ||
<tr> | ||
<td align="center"> | ||
<a href="https://github.com/username"> | ||
<img src="https://avatars.githubusercontent.com/u/725423?s=75&v=4" width="75px;" alt="username"/> | ||
<br /> | ||
<sub><b>username</b></sub> | ||
</a> | ||
</td> | ||
</tr> | ||
</table> | ||
<br/> | ||
--> | ||
|
||
<table> | ||
<tr> | ||
<td align="center"> | ||
<a href="https://github.com/themightychris" style="width: 75px"> | ||
<sub><b>Chris Alfano</b></sub> | ||
</a> | ||
</td> | ||
</tr> | ||
<tr> | ||
<td align="center"> | ||
<a href="https://github.com/numberly" style="width: 75px"> | ||
<sub><b>Numberly</b></sub> | ||
</a> | ||
</td> | ||
</tr> | ||
<tr> | ||
<td align="center"> | ||
<a href="https://github.com/IQ333777" style="width: 75px"> | ||
<sub><b>IQ333777</b></sub> | ||
</a> | ||
</td> | ||
</tr> | ||
</table> | ||
|
||
Then the new migration will play without issue. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.