I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior.
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
Actual Result
I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior.
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
Actually, only I can do it as an admin. Why?
Thank you in advance.
Best regards.
Max
Logs
Screenshots or Videos
Additional Context
No response
Originally created by @extramatrix on GitHub (Sep 4, 2025).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/6270
### Prerequisites
- [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=)
- [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/)
### Vaultwarden Support String
### Your environment (Generated via diagnostics page)
* Vaultwarden version: v1.34.3
* Web-vault version: v2025.7.0
* OS/Arch: linux/x86_64
* Running within a container: true (Base: Debian)
* Database type: SQLite
* Database version: 3.50.2
* Uses config.json: true
* Uses a reverse proxy: true
* IP Header check: true (X-Real-IP)
* Internet access: true
* Internet access via a proxy: false
* DNS Check: true
* Browser/Server Time Check: true
* Server/NTP Time Check: true
* Domain Configuration Check: true
* HTTPS Check: true
* Websocket Check: true
* HTTP Response Checks: true
### Config & Details (Generated via diagnostics page)
<details><summary>Show Config & Details</summary>
**Environment settings which are overridden:** ADMIN_TOKEN
**Config:**
```json
{
"_duo_akey": null,
"_enable_duo": true,
"_enable_email_2fa": false,
"_enable_smtp": true,
"_enable_yubico": true,
"_icon_service_csp": "",
"_icon_service_url": "",
"_ip_header_enabled": true,
"_max_note_size": 10000,
"_smtp_img_src": "***:",
"admin_ratelimit_max_burst": 3,
"admin_ratelimit_seconds": 300,
"admin_session_lifetime": 20,
"admin_token": "***",
"allowed_connect_src": "",
"allowed_iframe_ancestors": "",
"attachments_folder": "data/attachments",
"auth_request_purge_schedule": "30 * * * * *",
"authenticator_disable_time_drift": false,
"data_folder": "data",
"database_conn_init": "",
"database_max_conns": 10,
"database_timeout": 30,
"database_url": "***************",
"db_connection_retries": 15,
"disable_2fa_remember": false,
"disable_admin_token": false,
"disable_icon_download": false,
"domain": "*****://***************************",
"domain_origin": "*****://***************************",
"domain_path": "",
"domain_set": true,
"duo_context_purge_schedule": "30 * * * * *",
"duo_host": null,
"duo_ikey": null,
"duo_skey": null,
"duo_use_iframe": false,
"email_2fa_auto_fallback": false,
"email_2fa_enforce_on_verified_invite": false,
"email_attempts_limit": 3,
"email_change_allowed": false,
"email_expiration_time": 600,
"email_token_size": 6,
"emergency_access_allowed": true,
"emergency_notification_reminder_schedule": "0 3 * * * *",
"emergency_request_timeout_schedule": "0 7 * * * *",
"enable_db_wal": true,
"enable_websocket": true,
"enforce_single_org_with_reset_pw_policy": false,
"event_cleanup_schedule": "0 10 0 * * *",
"events_days_retain": null,
"experimental_client_feature_flags": "",
"extended_logging": true,
"helo_name": null,
"hibp_api_key": null,
"http_request_block_non_global_ips": true,
"http_request_block_regex": null,
"icon_blacklist_non_global_ips": true,
"icon_blacklist_regex": null,
"icon_cache_folder": "data/icon_cache",
"icon_cache_negttl": 259200,
"icon_cache_ttl": 2592000,
"icon_download_timeout": 10,
"icon_redirect_code": 302,
"icon_service": "internal",
"incomplete_2fa_schedule": "30 * * * * *",
"incomplete_2fa_time_limit": 3,
"increase_note_size_limit": false,
"invitation_expiration_hours": 120,
"invitation_org_name": "Vaultwarden",
"invitations_allowed": true,
"ip_header": "X-Real-IP",
"job_poll_interval_ms": 30000,
"log_file": null,
"log_level": "info",
"log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
"login_ratelimit_max_burst": 10,
"login_ratelimit_seconds": 60,
"org_attachment_limit": null,
"org_creation_users": "",
"org_events_enabled": false,
"org_groups_enabled": true,
"password_hints_allowed": true,
"password_iterations": 600000,
"push_enabled": false,
"push_identity_uri": "https://identity.bitwarden.com",
"push_installation_id": "***",
"push_installation_key": "***",
"push_relay_uri": "https://push.bitwarden.com",
"reload_templates": false,
"require_device_email": false,
"rsa_key_filename": "data/rsa_key",
"send_purge_schedule": "0 5 * * * *",
"sendmail_command": null,
"sends_allowed": true,
"sends_folder": "data/sends",
"show_password_hint": false,
"signups_allowed": true,
"signups_domains_whitelist": "******",
"signups_verify": false,
"signups_verify_resend_limit": 6,
"signups_verify_resend_time": 3600,
"smtp_accept_invalid_certs": false,
"smtp_accept_invalid_hostnames": false,
"smtp_auth_mechanism": null,
"smtp_debug": false,
"smtp_embed_images": true,
"smtp_explicit_tls": null,
"smtp_from": "***************************",
"smtp_from_name": "Vaultwarden",
"smtp_host": "***********",
"smtp_password": null,
"smtp_port": 25,
"smtp_security": "off",
"smtp_ssl": null,
"smtp_timeout": 15,
"smtp_username": null,
"templates_folder": "data/templates",
"tmp_folder": "data/tmp",
"trash_auto_delete_days": null,
"trash_purge_schedule": "0 5 0 * * *",
"use_sendmail": false,
"use_syslog": false,
"user_attachment_limit": null,
"user_send_limit": null,
"web_vault_enabled": true,
"web_vault_folder": "web-vault/",
"yubico_client_id": null,
"yubico_secret_key": null,
"yubico_server": null
}
```
</details>
### Vaultwarden Build Version
1.34.3
### Deployment method
Official Container Image
### Custom deployment method
_No response_
### Reverse Proxy
haproxy
### Host/Server Operating System
Linux
### Operating System Version
Oracle Linux 9
### Clients
Web Vault
### Client Version
_No response_
### Steps To Reproduce
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. Click on '...'
5. Etc '...'
### Expected Result
I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior.
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
### Actual Result
I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior.
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
Actually, only I can do it as an admin. Why?
Thank you in advance.
Best regards.
Max
<img width="1226" height="722" alt="Image" src="https://github.com/user-attachments/assets/38fb6250-828b-4678-8be5-54813329e015" />
### Logs
```text
```
### Screenshots or Videos
<img width="1226" height="722" alt="Image" src="https://github.com/user-attachments/assets/1af0ecf0-628a-43f1-9af1-77807ba772c2" />
### Additional Context
_No response_
GiteaMirror
added the bug label 2026-04-25 21:38:09 -05:00
In Bitwarden there's a difference between folders and collections so I'm assuming you meant the latter. Because you don't need any special permissions to create folders (because folders pertain only to your personal account and are not shared).
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
I tried to reproduce the issue but I have not managed to create the error message. Could you please describe in more detail how to reproduce the issue? What role and permissions exactly did you give the user? What steps exactly produce the error? Because (since v1.34.2 or more specifically https://github.com/dani-garcia/vaultwarden/commit/25865efd799d0321428e1dff1489b834e1206021) a User role should not be able to manage a collection at all anymore (even with the Manage collection permission), and a Custom user cannot delete collections either (unless they also have been given the permission to manage all collections).
<!-- gh-comment-id:3272491836 -->
@stefan0xC commented on GitHub (Sep 9, 2025):
In Bitwarden there's a difference between [folders](https://bitwarden.com/help/folders/) and [collections](https://bitwarden.com/help/about-collections/) so I'm assuming you meant the latter. Because you don't need any special permissions to create folders (because folders pertain only to your personal account and are not shared).
> I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
I tried to reproduce the issue but I have not managed to create the error message. Could you please describe in more detail how to reproduce the issue? What role and permissions exactly did you give the user? What steps exactly produce the error? Because (since [v1.34.2](https://github.com/dani-garcia/vaultwarden/releases/tag/1.34.2) or more specifically https://github.com/dani-garcia/vaultwarden/commit/25865efd799d0321428e1dff1489b834e1206021) a `User` role should not be able to manage a collection at all anymore (even with the `Manage collection` permission), and a `Custom` user cannot delete collections either (unless they also have been given the permission to manage all collections).
The role is personalized, and you guessed right, they are collections. If I assign role User there's not menù on the left side of a collection. I also using Groups, and this user has Manage collection on the Collection.
By the way, with the personalized role, I see the three dots but no delete option. If I select the collection, and click on the three dots above the line i see Delete option, but clicking on it shows the message "You do not have the necessary permissions to perform this operation".
Thank you.
<!-- gh-comment-id:3274516098 -->
@extramatrix commented on GitHub (Sep 10, 2025):
The role is personalized, and you guessed right, they are collections. If I assign role User there's not menù on the left side of a collection. I also using Groups, and this user has Manage collection on the Collection.
By the way, with the personalized role, I see the three dots but no delete option. If I select the collection, and click on the three dots above the line i see Delete option, but clicking on it shows the message "You do not have the necessary permissions to perform this operation".
Thank you.
<img width="1218" height="236" alt="Image" src="https://github.com/user-attachments/assets/d1919f00-5552-44e9-9800-ba679a38a202" />
<img width="290" height="95" alt="Image" src="https://github.com/user-attachments/assets/20c55136-4a88-4d9b-be25-e65daf74fec2" />
<img width="616" height="69" alt="Image" src="https://github.com/user-attachments/assets/f75fd98d-c22a-4f51-a69e-883c9685432e" />
I noticed another strange behavior.
In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost!
Is this intended behavior or a bug?
<!-- gh-comment-id:3337188629 -->
@extramatrix commented on GitHub (Sep 26, 2025):
I noticed another strange behavior.
In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost!
Is this intended behavior or a bug?
I noticed another strange behavior. In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost! Is this intended behavior or a bug?
That's because if you delete a collect the contained items are not deleted but only not in a collection anymore. They should still show up in the Admin Console via the special Unassigned collection.
<!-- gh-comment-id:3381224969 -->
@stefan0xC commented on GitHub (Oct 8, 2025):
> I noticed another strange behavior. In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost! Is this intended behavior or a bug?
That's because if you delete a collect the contained items are not deleted but only not in a collection anymore. They should still show up in the Admin Console via the special `Unassigned` collection.
<img width="1147" height="92" alt="Image" src="https://github.com/user-attachments/assets/ebbaa0aa-0223-452a-8e55-1793b82a81fd" />
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @extramatrix on GitHub (Sep 4, 2025).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/6270
Prerequisites
Vaultwarden Support String
Your environment (Generated via diagnostics page)
Config & Details (Generated via diagnostics page)
Show Config & Details
Environment settings which are overridden: ADMIN_TOKEN
Config:
Vaultwarden Build Version
1.34.3
Deployment method
Official Container Image
Custom deployment method
No response
Reverse Proxy
haproxy
Host/Server Operating System
Linux
Operating System Version
Oracle Linux 9
Clients
Web Vault
Client Version
No response
Steps To Reproduce
Expected Result
I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior.
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
Actual Result
I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior.
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
Actually, only I can do it as an admin. Why?
Thank you in advance.
Best regards.
Max

Logs
Screenshots or Videos
Additional Context
No response
@stefan0xC commented on GitHub (Sep 9, 2025):
In Bitwarden there's a difference between folders and collections so I'm assuming you meant the latter. Because you don't need any special permissions to create folders (because folders pertain only to your personal account and are not shared).
I tried to reproduce the issue but I have not managed to create the error message. Could you please describe in more detail how to reproduce the issue? What role and permissions exactly did you give the user? What steps exactly produce the error? Because (since v1.34.2 or more specifically https://github.com/dani-garcia/vaultwarden/commit/25865efd799d0321428e1dff1489b834e1206021) a
Userrole should not be able to manage a collection at all anymore (even with theManage collectionpermission), and aCustomuser cannot delete collections either (unless they also have been given the permission to manage all collections).@extramatrix commented on GitHub (Sep 10, 2025):
The role is personalized, and you guessed right, they are collections. If I assign role User there's not menù on the left side of a collection. I also using Groups, and this user has Manage collection on the Collection.
By the way, with the personalized role, I see the three dots but no delete option. If I select the collection, and click on the three dots above the line i see Delete option, but clicking on it shows the message "You do not have the necessary permissions to perform this operation".
Thank you.
@extramatrix commented on GitHub (Sep 26, 2025):
I noticed another strange behavior.
In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost!
Is this intended behavior or a bug?
@stefan0xC commented on GitHub (Oct 8, 2025):
That's because if you delete a collect the contained items are not deleted but only not in a collection anymore. They should still show up in the Admin Console via the special
Unassignedcollection.