[GH-ISSUE #5263] Master password re-prompt does not prevent viewing of note content on Android #8264

Closed
opened 2026-04-11 01:24:31 -05:00 by GiteaMirror · 2 comments
Owner

Originally created by @GideonBear on GitHub (May 24, 2025).
Original GitHub issue: https://github.com/bitwarden/android/issues/5263

Steps To Reproduce

  1. Go to "My vault"
  2. Click on "Secure note"
  3. Click on "+"
  4. Write a title and note
  5. Click on "Additional options"
  6. Enable "Master password re-prompt"
  7. Click "Save"
  8. Click the newly created note

Expected Result

The note content to be inaccessible before the master password is re-entered, in accordance to the "Master password re-prompt" option, and consistent with the browser extension.

Actual Result

The note content is visible without re-entering the master password. The master password is only required to edit the note.

Screenshots or Videos

No response

Additional Context

This is not a duplicate of #5153. #5153 is about hidden field history, this is about the secure note "Note" field. (nothing to do with the edit history)
This is not a duplicate of #4549. #4549 is about hidden fields (only directly after creation?), this is about the secure note "Note" field, being visible all the time.

I believe this is a bug and not a feature request, because:

  • The expected behavior is there on desktop
  • The current behavior is obviously harmful to privacy
  • The text "Master password re-prompt" does not convey that it is still possible to view the note, and this behavior can thus be unexpected for many users.

Even though this behavior is documented, not many people read this documentation.

Prior reports:
#5226
https://community.bitwarden.com/t/secure-notes-visible-in-view-even-when-master-pw-is-enabled-for-editing/47825/4

ping @StellarGuardian

Build Version

2025.4.0 (20100)

What server are you connecting to?

US

Self-host Server Version

No response

Environment Details

N/A

Issue Tracking Info

  • I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
Originally created by @GideonBear on GitHub (May 24, 2025). Original GitHub issue: https://github.com/bitwarden/android/issues/5263 ### Steps To Reproduce 1. Go to "My vault" 2. Click on "Secure note" 3. Click on "+" 4. Write a title and note 5. Click on "Additional options" 6. Enable "Master password re-prompt" 7. Click "Save" 8. Click the newly created note ### Expected Result The note content to be inaccessible before the master password is re-entered, in accordance to the "Master password re-prompt" option, and consistent with the browser extension. ### Actual Result The note content is visible without re-entering the master password. The master password is only required to edit the note. ### Screenshots or Videos _No response_ ### Additional Context **This is not a duplicate of #5153. #5153 is about hidden field history, this is about the secure note "Note" field. (nothing to do with the edit history)** **This is not a duplicate of #4549. #4549 is about hidden fields (only directly after creation?), this is about the secure note "Note" field, being visible all the time.** I believe this is a bug and not a feature request, because: - The expected behavior is there on desktop - The current behavior is obviously harmful to privacy - The text "Master password re-prompt" does not convey that it is still possible to view the note, and this behavior can thus be unexpected for many users. [Even though this behavior is documented](https://bitwarden.com/help/managing-items/#protect-individual-items), not many people read this documentation. Prior reports: #5226 https://community.bitwarden.com/t/secure-notes-visible-in-view-even-when-master-pw-is-enabled-for-editing/47825/4 ping @StellarGuardian ### Build Version 2025.4.0 (20100) ### What server are you connecting to? US ### Self-host Server Version _No response_ ### Environment Details N/A ### Issue Tracking Info - [x] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
GiteaMirror added the app:password-managerbug labels 2026-04-11 01:24:31 -05:00
Author
Owner

@bitwarden-bot commented on GitHub (May 24, 2025):

Thank you for your report! We've added this to our internal board for review.
ID: PM-21965

<!-- gh-comment-id:2906615694 --> @bitwarden-bot commented on GitHub (May 24, 2025): Thank you for your report! We've added this to our internal board for review. ID: PM-21965
Author
Owner

@rmcdowell-bitwarden commented on GitHub (May 26, 2025):

Hi there!

Thank you for your report, it seems like it is a duplicate of this one https://github.com/bitwarden/clients/issues/7799.

If you wish to add any further information/screenshots/recordings etc., please feel free to do so at any time in there - our engineering team will be happy to review these.

This issue will now be closed.

Thanks!

<!-- gh-comment-id:2908371872 --> @rmcdowell-bitwarden commented on GitHub (May 26, 2025): Hi there! Thank you for your report, it seems like it is a duplicate of this one https://github.com/bitwarden/clients/issues/7799. If you wish to add any further information/screenshots/recordings etc., please feel free to do so at any time in there - our engineering team will be happy to review these. This issue will now be closed. Thanks!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#8264