mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-03-02 22:57:18 -05:00
"Breach accounts found" but... nothing on the HIBP website #1240
Labels
No labels
SSO
Third party
better for forum
bug
bug
documentation
duplicate
enhancement
future Vault
future Vault
future Vault
good first issue
help wanted
low priority
notes
question
troubleshooting
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/vaultwarden#1240
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @jducaud on GitHub (Mar 19, 2022).
Subject of the issue
My Vaultwarden account email address is said by the Web Vault to be linked to a breach but it does not seem to be.
Deployment environment
Machine: Synology DS218+ (OS: DSM 6.2.4-25556 Update 5)
Docker image: vaultwarden/server 1.24.0 (latest: 6 weeks ago / 187MB) (Web Vault 2.25.1)
Client: Firefox 98.0.1 (64-bit) (connection to the Web Vault) on Microsoft Windows 10 21H2
Reverse proxy and version (on DSM): nginx 1.16.1
Steps to reproduce
1 - Log in to my Vaultwarden account on the Web Vault
2 - Go to "Tools > Reports > Data breach report"
3 - Press the "Check breaches" button
4 - The message "BREACHED ACCOUNTS FOUND" (uppercased and red) is displayed, asking for a manual check on HIBP website
5 - Go to HIBP website (just click on the provided hyperlink by the Web Vault)
6 - See that my email address has not been pwned
Expected behaviour
I have no subscription running at HIBP, so I do not have an API key. I would expect the Web Vault to remind me that I have not an HIBP API key, but without warning me that I have been pwned (this supposed breach has even a date: August 18th 2019).
Actual behaviour
See above.
Troubleshooting data
Here are 2 relevant screenshots
Steps 1 to 4

Steps 5 to 6

@BlackDex commented on GitHub (Mar 19, 2022):
This is a feature.
Since you do not have a HIBP API-Key you normally would get an error message.
To make it a bit easier for people to check the mail address we added a custom error message noting that the API-Key is not set and we have added a link to HIBP with the mail addresses provided.
Just read the message carefully, and you would see that it states Manual HIBP Check and that the Key is not set.