[GH-ISSUE #6249] Login error - can't access property "toLowerCase", e.message is undefined #11192

Closed
opened 2026-04-20 14:44:46 -05:00 by GiteaMirror · 0 comments
Owner

Originally created by @mrnetlex on GitHub (Aug 29, 2025).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/6249

Prerequisites

Vaultwarden Support String

Your environment (Generated via diagnostics page)

  • Vaultwarden version: v1.34.3
  • Web-vault version: v2025.7.0
  • OS/Arch: linux/x86_64
  • Running within a container: true (Base: Debian)
  • Database type: SQLite
  • Database version: 3.50.2
  • Uses config.json: false
  • Uses a reverse proxy: true
  • IP Header check: true (X-Real-IP)
  • Internet access: true
  • Internet access via a proxy: false
  • DNS Check: true
  • Browser/Server Time Check: true
  • Server/NTP Time Check: true
  • Domain Configuration Check: true
  • HTTPS Check: true
  • Websocket Check: true
  • HTTP Response Checks: false

Config & Details (Generated via diagnostics page)

Show Config & Details

Failed HTTP Checks:

HTTP error responses:
Response to: 404 (Not Found) HTML is invalid
Response to: 404 (Not Found) JSON is invalid
Response to: 400 (Bad Request) is invalid
Response to: 401 (Unauthorized) is invalid
Response to: 403 (Forbidden) is invalid

Config:

{
  "_duo_akey": null,
  "_enable_duo": true,
  "_enable_email_2fa": true,
  "_enable_smtp": true,
  "_enable_yubico": true,
  "_icon_service_csp": "",
  "_icon_service_url": "",
  "_ip_header_enabled": true,
  "_max_note_size": 10000,
  "_smtp_img_src": "***:",
  "admin_ratelimit_max_burst": 3,
  "admin_ratelimit_seconds": 300,
  "admin_session_lifetime": 20,
  "admin_token": "***",
  "allowed_connect_src": "",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "data/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": false,
  "data_folder": "data",
  "database_conn_init": "",
  "database_max_conns": 10,
  "database_timeout": 30,
  "database_url": "***************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "domain": "*****://******************",
  "domain_origin": "*****://******************",
  "domain_path": "",
  "domain_set": true,
  "duo_context_purge_schedule": "30 * * * * *",
  "duo_host": null,
  "duo_ikey": null,
  "duo_skey": null,
  "duo_use_iframe": false,
  "email_2fa_auto_fallback": false,
  "email_2fa_enforce_on_verified_invite": false,
  "email_attempts_limit": 3,
  "email_change_allowed": true,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": true,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "enable_websocket": true,
  "enforce_single_org_with_reset_pw_policy": false,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "http_request_block_non_global_ips": true,
  "http_request_block_regex": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "data/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "internal",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 3,
  "increase_note_size_limit": false,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "Vaultwarden",
  "invitations_allowed": false,
  "ip_header": "X-Real-IP",
  "job_poll_interval_ms": 30000,
  "log_file": "/data/vaultwarden.log",
  "log_level": "Info",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  "login_ratelimit_max_burst": 10,
  "login_ratelimit_seconds": 60,
  "org_attachment_limit": null,
  "org_creation_users": "",
  "org_events_enabled": false,
  "org_groups_enabled": false,
  "password_hints_allowed": true,
  "password_iterations": 600000,
  "push_enabled": false,
  "push_identity_uri": "https://identity.bitwarden.eu",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://api.bitwarden.eu",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "data/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "data/sends",
  "show_password_hint": false,
  "signups_allowed": false,
  "signups_domains_whitelist": "",
  "signups_verify": false,
  "signups_verify_resend_limit": 6,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": null,
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": null,
  "smtp_from": "*********************",
  "smtp_from_name": "Vaultwarden",
  "smtp_host": "**************",
  "smtp_password": "***",
  "smtp_port": 587,
  "smtp_security": "starttls",
  "smtp_ssl": null,
  "smtp_timeout": 15,
  "smtp_username": "*********************",
  "templates_folder": "data/templates",
  "tmp_folder": "data/tmp",
  "trash_auto_delete_days": null,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "yubico_client_id": null,
  "yubico_secret_key": null,
  "yubico_server": null
}

Vaultwarden Build Version

1.34.3

Deployment method

Official Container Image

Custom deployment method

Docker compose:

services:
  server:
    container_name: vaultwarden
    volumes:
      - /home/netlex/docker/vw:/data/
    ports:
      - 8889:80
    environment:
      - DOMAIN=REDACTED
      - LOG_LEVEL=Info
      - LOG_FILE=/data/vaultwarden.log
      - SIGNUPS_ALLOWED=false
      - INVITATIONS_ALLOWED=false
      - SHOW_PASSWORD_HINT=false
      - PUSH_INSTALLATION_ID=REDACTED
      - PUSH_INSTALLATION_KEY=REDACTED
      - PUSH_RELAY_URI=https://api.bitwarden.eu
      - PUSH_IDENTITY_URI=https://identity.bitwarden.eu
      - SMTP_HOST=REDACTED
      - SMTP_PORT=REDACTED
      - SMTP_FROM=REDACTED
      - SMTP_SECURITY=REDACTED
      - SMTP_USERNAME=REDACTED
      - SMTP_PASSWORD=REDACTED
    restart: unless-stopped
    security_opt:
      - no-new-privileges:true
    image: vaultwarden/server:latest
    labels:
      - traefik.enable=true
      - traefik.http.routers.vw.entrypoints=http
      - traefik.http.routers.vw.rule=Host(`REDACTED`)
      - traefik.http.middlewares.vw-https-redirect.redirectscheme.scheme=https
      - traefik.http.routers.vw.middlewares=ip-whitelist@file,vw-https-redirect
      - traefik.http.routers.vw-secure.entrypoints=https
      - traefik.http.routers.vw-secure.rule=Host(`REDACTED`)
      - traefik.http.routers.vw-secure.tls=true
      - traefik.http.routers.vw-secure.service=vw
      - traefik.http.routers.vw-secure.middlewares=ip-whitelist@file
      - traefik.http.services.vw.loadbalancer.server.port=80
      - traefik.docker.network=proxy
      - glance.name=Vaultwarden
      - glance.icon=si:vaultwarden
      - glance.url=https://REDACTED
      - glance.description=Password Manager
      - glance.hide=false
networks: {}

Reverse Proxy

traefik 3.5.1

Host/Server Operating System

Linux

Operating System Version

Ubuntu 24.04 x86

Clients

Web Vault

Client Version

Zen Browser 1.15b (Firefox 142.0), Brave 1.81.137, Chrome 139 Android

Steps To Reproduce

  1. Fill e-mail
  2. Fill password
  3. Click login in with a master password

Expected Result

Pop-up asking for FIDO2 authentication with key.

Actual Result

Error saying - can't access property "toLowerCase", e.message is undefined

Logs

[2025-08-29 00:16:47.100][request][INFO] GET /
[2025-08-29 00:16:47.101][response][INFO] (web_index) GET / => 200 OK
[2025-08-29 00:16:54.888][request][INFO] GET /
[2025-08-29 00:16:54.889][response][INFO] (web_index) GET / => 200 OK
[2025-08-29 00:16:55.831][request][INFO] GET /api/devices/knowndevice
[2025-08-29 00:16:55.835][response][INFO] (get_known_device) GET /api/devices/knowndevice => 200 OK
[2025-08-29 00:17:19.225][request][INFO] GET /api/devices/knowndevice
[2025-08-29 00:17:19.227][response][INFO] (get_known_device) GET /api/devices/knowndevice => 200 OK
[2025-08-29 00:17:22.376][request][INFO] POST /identity/accounts/prelogin
[2025-08-29 00:17:22.381][response][INFO] (prelogin) POST /identity/accounts/prelogin => 200 OK
[2025-08-29 00:17:23.579][request][INFO] POST /identity/connect/token
[2025-08-29 00:17:23.894][error][ERROR] 2FA token not provided
[2025-08-29 00:17:23.894][response][INFO] (login) POST /identity/connect/token => 400 Bad Request
[2025-08-29 00:17:37.984][request][INFO] GET /alive
[2025-08-29 00:17:37.985][response][INFO] (alive) GET /alive => 200 OK
[2025-08-29 00:17:37.988][vaultwarden::api::core::two_factor::duo_oidc][DEBUG] Purging Duo authentication contexts
[2025-08-29 00:17:37.988][vaultwarden::api::core::accounts][DEBUG] Purging auth requests
[2025-08-29 00:17:37.988][vaultwarden::api::core::two_factor][DEBUG] Sending notifications for incomplete 2FA logins

Screenshots or Videos

Image

Additional Context

From what I can tell it is connected to use of YubiKeys as FIDO (WebAuthn) 2FA. I'm not certain for how long this error is present - I mostly use extension and Android app. which still work fine.

What I checked:

  1. Tried to login on Windows 11, Linux (Fedora) and Android with different browsers on clean profile - behavior stays the same.
  2. Older images 134.2, 134.1
  3. Disabling Cloudflare proxy
  4. Disabling crowdsec bouncer (as traefik middlewear)

If deemed necessary I can just setup new instance as it is only for my personal use and I have vault backups.

Originally created by @mrnetlex on GitHub (Aug 29, 2025). Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/6249 ### Prerequisites - [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=) - [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/) ### Vaultwarden Support String ### Your environment (Generated via diagnostics page) * Vaultwarden version: v1.34.3 * Web-vault version: v2025.7.0 * OS/Arch: linux/x86_64 * Running within a container: true (Base: Debian) * Database type: SQLite * Database version: 3.50.2 * Uses config.json: false * Uses a reverse proxy: true * IP Header check: true (X-Real-IP) * Internet access: true * Internet access via a proxy: false * DNS Check: true * Browser/Server Time Check: true * Server/NTP Time Check: true * Domain Configuration Check: true * HTTPS Check: true * Websocket Check: true * HTTP Response Checks: false ### Config & Details (Generated via diagnostics page) <details><summary>Show Config & Details</summary> **Failed HTTP Checks:** ```yaml HTTP error responses: Response to: 404 (Not Found) HTML is invalid Response to: 404 (Not Found) JSON is invalid Response to: 400 (Bad Request) is invalid Response to: 401 (Unauthorized) is invalid Response to: 403 (Forbidden) is invalid ``` **Config:** ```json { "_duo_akey": null, "_enable_duo": true, "_enable_email_2fa": true, "_enable_smtp": true, "_enable_yubico": true, "_icon_service_csp": "", "_icon_service_url": "", "_ip_header_enabled": true, "_max_note_size": 10000, "_smtp_img_src": "***:", "admin_ratelimit_max_burst": 3, "admin_ratelimit_seconds": 300, "admin_session_lifetime": 20, "admin_token": "***", "allowed_connect_src": "", "allowed_iframe_ancestors": "", "attachments_folder": "data/attachments", "auth_request_purge_schedule": "30 * * * * *", "authenticator_disable_time_drift": false, "data_folder": "data", "database_conn_init": "", "database_max_conns": 10, "database_timeout": 30, "database_url": "***************", "db_connection_retries": 15, "disable_2fa_remember": false, "disable_admin_token": false, "disable_icon_download": false, "domain": "*****://******************", "domain_origin": "*****://******************", "domain_path": "", "domain_set": true, "duo_context_purge_schedule": "30 * * * * *", "duo_host": null, "duo_ikey": null, "duo_skey": null, "duo_use_iframe": false, "email_2fa_auto_fallback": false, "email_2fa_enforce_on_verified_invite": false, "email_attempts_limit": 3, "email_change_allowed": true, "email_expiration_time": 600, "email_token_size": 6, "emergency_access_allowed": true, "emergency_notification_reminder_schedule": "0 3 * * * *", "emergency_request_timeout_schedule": "0 7 * * * *", "enable_db_wal": true, "enable_websocket": true, "enforce_single_org_with_reset_pw_policy": false, "event_cleanup_schedule": "0 10 0 * * *", "events_days_retain": null, "experimental_client_feature_flags": "", "extended_logging": true, "helo_name": null, "hibp_api_key": null, "http_request_block_non_global_ips": true, "http_request_block_regex": null, "icon_blacklist_non_global_ips": true, "icon_blacklist_regex": null, "icon_cache_folder": "data/icon_cache", "icon_cache_negttl": 259200, "icon_cache_ttl": 2592000, "icon_download_timeout": 10, "icon_redirect_code": 302, "icon_service": "internal", "incomplete_2fa_schedule": "30 * * * * *", "incomplete_2fa_time_limit": 3, "increase_note_size_limit": false, "invitation_expiration_hours": 120, "invitation_org_name": "Vaultwarden", "invitations_allowed": false, "ip_header": "X-Real-IP", "job_poll_interval_ms": 30000, "log_file": "/data/vaultwarden.log", "log_level": "Info", "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f", "login_ratelimit_max_burst": 10, "login_ratelimit_seconds": 60, "org_attachment_limit": null, "org_creation_users": "", "org_events_enabled": false, "org_groups_enabled": false, "password_hints_allowed": true, "password_iterations": 600000, "push_enabled": false, "push_identity_uri": "https://identity.bitwarden.eu", "push_installation_id": "***", "push_installation_key": "***", "push_relay_uri": "https://api.bitwarden.eu", "reload_templates": false, "require_device_email": false, "rsa_key_filename": "data/rsa_key", "send_purge_schedule": "0 5 * * * *", "sendmail_command": null, "sends_allowed": true, "sends_folder": "data/sends", "show_password_hint": false, "signups_allowed": false, "signups_domains_whitelist": "", "signups_verify": false, "signups_verify_resend_limit": 6, "signups_verify_resend_time": 3600, "smtp_accept_invalid_certs": false, "smtp_accept_invalid_hostnames": false, "smtp_auth_mechanism": null, "smtp_debug": false, "smtp_embed_images": true, "smtp_explicit_tls": null, "smtp_from": "*********************", "smtp_from_name": "Vaultwarden", "smtp_host": "**************", "smtp_password": "***", "smtp_port": 587, "smtp_security": "starttls", "smtp_ssl": null, "smtp_timeout": 15, "smtp_username": "*********************", "templates_folder": "data/templates", "tmp_folder": "data/tmp", "trash_auto_delete_days": null, "trash_purge_schedule": "0 5 0 * * *", "use_sendmail": false, "use_syslog": false, "user_attachment_limit": null, "user_send_limit": null, "web_vault_enabled": true, "web_vault_folder": "web-vault/", "yubico_client_id": null, "yubico_secret_key": null, "yubico_server": null } ``` </details> ### Vaultwarden Build Version 1.34.3 ### Deployment method Official Container Image ### Custom deployment method Docker compose: ```yaml services: server: container_name: vaultwarden volumes: - /home/netlex/docker/vw:/data/ ports: - 8889:80 environment: - DOMAIN=REDACTED - LOG_LEVEL=Info - LOG_FILE=/data/vaultwarden.log - SIGNUPS_ALLOWED=false - INVITATIONS_ALLOWED=false - SHOW_PASSWORD_HINT=false - PUSH_INSTALLATION_ID=REDACTED - PUSH_INSTALLATION_KEY=REDACTED - PUSH_RELAY_URI=https://api.bitwarden.eu - PUSH_IDENTITY_URI=https://identity.bitwarden.eu - SMTP_HOST=REDACTED - SMTP_PORT=REDACTED - SMTP_FROM=REDACTED - SMTP_SECURITY=REDACTED - SMTP_USERNAME=REDACTED - SMTP_PASSWORD=REDACTED restart: unless-stopped security_opt: - no-new-privileges:true image: vaultwarden/server:latest labels: - traefik.enable=true - traefik.http.routers.vw.entrypoints=http - traefik.http.routers.vw.rule=Host(`REDACTED`) - traefik.http.middlewares.vw-https-redirect.redirectscheme.scheme=https - traefik.http.routers.vw.middlewares=ip-whitelist@file,vw-https-redirect - traefik.http.routers.vw-secure.entrypoints=https - traefik.http.routers.vw-secure.rule=Host(`REDACTED`) - traefik.http.routers.vw-secure.tls=true - traefik.http.routers.vw-secure.service=vw - traefik.http.routers.vw-secure.middlewares=ip-whitelist@file - traefik.http.services.vw.loadbalancer.server.port=80 - traefik.docker.network=proxy - glance.name=Vaultwarden - glance.icon=si:vaultwarden - glance.url=https://REDACTED - glance.description=Password Manager - glance.hide=false networks: {} ``` ### Reverse Proxy traefik 3.5.1 ### Host/Server Operating System Linux ### Operating System Version Ubuntu 24.04 x86 ### Clients Web Vault ### Client Version Zen Browser 1.15b (Firefox 142.0), Brave 1.81.137, Chrome 139 Android ### Steps To Reproduce 1. Fill e-mail 2. Fill password 3. Click login in with a master password ### Expected Result Pop-up asking for FIDO2 authentication with key. ### Actual Result Error saying - can't access property "toLowerCase", e.message is undefined ### Logs ```text [2025-08-29 00:16:47.100][request][INFO] GET / [2025-08-29 00:16:47.101][response][INFO] (web_index) GET / => 200 OK [2025-08-29 00:16:54.888][request][INFO] GET / [2025-08-29 00:16:54.889][response][INFO] (web_index) GET / => 200 OK [2025-08-29 00:16:55.831][request][INFO] GET /api/devices/knowndevice [2025-08-29 00:16:55.835][response][INFO] (get_known_device) GET /api/devices/knowndevice => 200 OK [2025-08-29 00:17:19.225][request][INFO] GET /api/devices/knowndevice [2025-08-29 00:17:19.227][response][INFO] (get_known_device) GET /api/devices/knowndevice => 200 OK [2025-08-29 00:17:22.376][request][INFO] POST /identity/accounts/prelogin [2025-08-29 00:17:22.381][response][INFO] (prelogin) POST /identity/accounts/prelogin => 200 OK [2025-08-29 00:17:23.579][request][INFO] POST /identity/connect/token [2025-08-29 00:17:23.894][error][ERROR] 2FA token not provided [2025-08-29 00:17:23.894][response][INFO] (login) POST /identity/connect/token => 400 Bad Request [2025-08-29 00:17:37.984][request][INFO] GET /alive [2025-08-29 00:17:37.985][response][INFO] (alive) GET /alive => 200 OK [2025-08-29 00:17:37.988][vaultwarden::api::core::two_factor::duo_oidc][DEBUG] Purging Duo authentication contexts [2025-08-29 00:17:37.988][vaultwarden::api::core::accounts][DEBUG] Purging auth requests [2025-08-29 00:17:37.988][vaultwarden::api::core::two_factor][DEBUG] Sending notifications for incomplete 2FA logins ``` ### Screenshots or Videos <img width="690" height="165" alt="Image" src="https://github.com/user-attachments/assets/3d156246-0896-4fdf-ac3d-662ca4a59817" /> ### Additional Context From what I can tell it is connected to use of YubiKeys as FIDO (WebAuthn) 2FA. I'm not certain for how long this error is present - I mostly use extension and Android app. which still work fine. What I checked: 1. Tried to login on Windows 11, Linux (Fedora) and Android with different browsers on clean profile - behavior stays the same. 2. Older images 134.2, 134.1 3. Disabling Cloudflare proxy 4. Disabling crowdsec bouncer (as traefik middlewear) If deemed necessary I can just setup new instance as it is only for my personal use and I have vault backups.
GiteaMirror added the bug label 2026-04-20 14:44:46 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/vaultwarden#11192