[GH-ISSUE #3206] TOTP code can be viewed without entering the master password when 'Master password re-promt' is enabled #49948

Closed
opened 2026-05-01 10:47:48 -05:00 by GiteaMirror · 1 comment
Owner

Originally created by @jonnykl on GitHub (Apr 29, 2024).
Original GitHub issue: https://github.com/bitwarden/android/issues/3206

Steps To Reproduce

  1. Enable 'Master password re-promt' for an item
  2. Save the item
  3. Open the item

Expected Result

The TOTP code should not be visible until the master password has been re-entered.

Actual Result

The TOTP code is shown without the need to re-enter the master password. But if you want to copy the TOTP code, you have to re-enter the master password. This makes no sense as the TOTP code is already visible at this point.

Screenshots or Videos

No response

Additional Context

I noticed the same behavior in the Chrome extension.

Operating System

Android

Operating System Version

Android 14 (Xiaomi HyperOS 1.0.3.0.UMOEUXM)

Device

Xiaomi Redmi Note 12 Pro 5G

Build Version

2024.4.0 (10172)

Beta

  • Using a pre-release version of the application.
Originally created by @jonnykl on GitHub (Apr 29, 2024). Original GitHub issue: https://github.com/bitwarden/android/issues/3206 ### Steps To Reproduce 1. Enable 'Master password re-promt' for an item 2. Save the item 3. Open the item ### Expected Result The TOTP code should not be visible until the master password has been re-entered. ### Actual Result The TOTP code is shown without the need to re-enter the master password. But if you want to copy the TOTP code, you have to re-enter the master password. This makes no sense as the TOTP code is already visible at this point. ### Screenshots or Videos _No response_ ### Additional Context I noticed the same behavior in the Chrome extension. ### Operating System Android ### Operating System Version Android 14 (Xiaomi HyperOS 1.0.3.0.UMOEUXM) ### Device Xiaomi Redmi Note 12 Pro 5G ### Build Version 2024.4.0 (10172) ### Beta - [ ] Using a pre-release version of the application.
GiteaMirror added the bug label 2026-05-01 10:47:48 -05:00
Author
Owner

@micahblut commented on GitHub (Apr 30, 2024):

@jonnykl thanks for reporting. We have a similar report here that we are tracking. I will go ahead and close this report.

<!-- gh-comment-id:2085538573 --> @micahblut commented on GitHub (Apr 30, 2024): @jonnykl thanks for reporting. We have a similar report [here](https://github.com/bitwarden/mobile/issues/2336) that we are tracking. I will go ahead and close this report.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#49948